Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
maple3142
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
maple3142
4y ago
You can use this without root by using the rish provided by [Shizuku]( https://play.google.com/store/apps/details?id=moe.shizuku.pr... ), because it only need adb shell permission for this.
62.
▲
by
maple3142
4y ago
I get using docker is more painless, but I still prefer running things outside of a container when the setup isn't too complex. It is mostly because I have some heavily customized dev environment including zsh and all other tools insta
63.
▲
by
maple3142
4y ago
I think Python does allow you to play with closure itself by accessing __closure__. Although it is immutable by default, it is still easy to construct another function from code object and closure directly.
64.
▲
by
maple3142
4y ago
But single-file script is still more convenient than two files. e.g. It is easier to scp or copy just one file than two files. Sometimes even if people already know they want to solve X problem, it might still make sense to solve Y problem
65.
▲
by
maple3142
4y ago
I think the main problem is C modules. CPython only maintains ABI compatibility across minor releases (e.g. 3.10.0 and 3.10.8), so you may need a different binary compiled for CPython 3.9 and 3.10. https://docs.python.org/3&
66.
▲
by
maple3142
5y ago
Node.js had `http` in its standard library for a long time though.
67.
▲
by
maple3142
5y ago
Even escapeshellarg might not be enough, because the command you are executing might trying to parse it as options. Depends on which command you are using, it could be exploitable. For example, there is a CTF challenge where you need to get
68.
▲
by
maple3142
5y ago
I always wonder how do people develop in Docker entirely deal with their own shell configuration? Actually install all the tools needed by your .zshrc (or .bashrc) in the container or there is a better solution?
69.
▲
by
maple3142
5y ago
Sometimes, I find it is easier to make your base case broader and bruteforce it one by one when you couldn't get it right. For example, when I tried to exploit RSA parity oracle I couldn't find the right answer when it is narrowed
70.
▲
by
maple3142
5y ago
I wonder how hard is it to escape a unprivileged container as a non-root user in a container. It seems that many CTF organizers already host their RCE challenge this way.
71.
▲
by
maple3142
5y ago
I don't think this will work in JavaScript because that while loop will block the event loop and prevents callback from executing. For example, the following code will be blocked when running in Node.js: function delayedValue(val
72.
▲
by
maple3142
5y ago
Iuse AdGuard as a system-wide adblocker on Android, it works pretty well IMO.
73.
▲
by
maple3142
5y ago
JavaScript supports monkey patching by modifying prototype objects too. But it is considered to be bad practice because it modify the behavior globally, and some method name conflict may cause trouble. An example is Array.prototype.contains
74.
▲
by
maple3142
5y ago
You can have some basic configurable stuffs in an opinionated tool though, see Prettier. It allows tab/space, quote style, line length etc., to be modified.
75.
▲
Don’t try to sanitize input, escape output (2020)
(benhoyt.com)
128 points
by
maple3142
5y ago
|
128 comments
76.
▲
by
maple3142
5y ago
It might be confusing as it is different from some other languages, such as C++ and JavaScript. They both evaluate default parameter when the function are called.
77.
▲
by
maple3142
5y ago
I wonder if it is true that everything is O(1) if there is an upper bound? Even for an algorithm with O(n^n) complexity, it is still O(1) if n is bounded, just with a extremely large constant.
78.
▲
by
maple3142
5y ago
I think lodash fits this role?
79.
▲
by
maple3142
5y ago
I am not sure if Debian can really keep give packages security updates without feature updates. For example, Debian packaged Chromium seems really outdated and having many unpatched CVEs: https://security-tracker.debian.org/
80.
▲
by
maple3142
5y ago
I think this is worse because once you have a python 3 only syntax in your script (such as f-string), python 2 will simply throw syntax error because it need to parse the file to execute. The original solution looks hacky, but it can actual
81.
▲
by
maple3142
5y ago
Because DOMPurify is not perfect. Due to some problem of HTML parsing, there were some ways to bypass it: https://research.securitum.com/mutation-xss-via-mathml-mutat... Having a builtin XSS sanatizer means it could always
82.
▲
by
maple3142
5y ago
> Here's a sequence of outputs: 6,5,3,3,3,5. Does this information allow you to predict the next output? No. Your prng looks like a truncated LCG, it could be broken if enough outputs are known. For example, 16 bits could be brutefo
83.
▲
by
maple3142
5y ago
If you use vscode, maybe you could try this one: https://marketplace.visualstudio.com/items?itemName=pnp.pola...
84.
▲
by
maple3142
5y ago
I am not sure if parsing XML is better than parsing JSON. Many languages or libraries' XML parser are dangerous by default. You usually need to manually configure your XML parser to be secure from XML-related attacks. Fortunately, some
85.
▲
by
maple3142
5y ago
I think the main difference between OS kernel and browser is the former can decide what they need to support, but the latter need to be compatible in order to render existing website. IMO, Building a new browser is more similar to building
86.
▲
Maintainers Matter: The case against upstream packaging (2016)
(kmkeen.com)
2 points
by
maple3142
5y ago
|
0 comments
87.
▲
by
maple3142
5y ago
If you don't need to run `docker` command under Windows, install docker directly from distro repo is enough. No need to run another background service. Another benefit is it is faster to build docker images when the files are large, be
88.
▲
Futures of Distributions (2018)
(joeyh.name)
2 points
by
maple3142
5y ago
|
0 comments
89.
▲
by
maple3142
5y ago
I think you ultimately need to do something like Function(code)() in JSFuck, so it is always possible to remove the final function call and get the `code` directly.
90.
▲
Two types of package managers
(utcc.utoronto.ca)
5 points
by
maple3142
5y ago
|
1 comments
More ›