Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mkjones
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
mkjones
15y ago
Glad to see other people using vmtouch. It's also great for keeping large codebases in the filesystem cache on [shared] dev machines.
92.
▲
by
mkjones
15y ago
That's a good idea, and we actually thought about that. But assuming we need those APIs, what's to keep them from calling our wrappers around them? Put another way, how do we determine if the caller of some of our js is malicious or is us?
93.
▲
by
mkjones
15y ago
We've seen the same attack on a 3rd party site that pops up a facebook window that's minimized such that all you can see is the address bar, and has you paste into there. Perhaps a lower conversion rate, but still effective.
94.
▲
by
mkjones
15y ago
They could just tell the user that the captcha is part of the "security check" the user must do to see if they're in the 2% or whatever. Users will do almost anything if you instruct them well enough.
95.
▲
by
mkjones
15y ago
I'm not 100% sure, but I think the chrome console is essentially the same, but you needn't prepend with javascript: and it has like autocompletion and history and a bunch of other things. Not sure why anyone would legitimately use the addr
96.
▲
by
mkjones
15y ago
Agreed that it's unfortunate that flash can write to your clipboard. The only place I've seen that used legitimately is on bit.ly so they can copy the shortened link to your clipboard. Even there, I usually end up confused about what happ
97.
▲
Self-XSS attack explained
(facebook.com)
79 points
by
mkjones
15y ago
|
32 comments
98.
▲
by
mkjones
15y ago
Ah yes, you're right. I remember old versions of Spotify doing this, and it always confused me.
99.
▲
by
mkjones
15y ago
> If you're using multiple browsers in OS X all built on Webkit for instance, they share the same cookie store. Where are you getting this? Safari and Chrome (both built on webkit) definitely do not share cookie stores on OS X.
100.
▲
by
mkjones
15y ago
What makes you think thy've had a tough time scaling with early demand? I'd think that this scales horizontally pretty well, given that each request is largely stateless and there's no interaction between users.
101.
▲
by
mkjones
15y ago
I'm not that familiar with BeEF, but it is possible to set the location on child iframes, just not get it. It also looks like BeEF is running on your local machine, so they could presumably do whatever they want to bypass the browser's
102.
▲
by
mkjones
15y ago
Oh, sorry. Basically he had another endpoint that let you set an arbitrary cookie to an arbitrary value (with no csrf protection). So first I had it hit that endpoint, setting the JSESSIONID cookie to my value (off of which the csrf token
103.
▲
by
mkjones
15y ago
Sorry, didn't mean to put words in your mouth. I just wanted to point out that even when it seems like an XSS doesn't demonstrate a vulnerability, some of your assumptions may be wrong and it actually does. Security is hard, let's go shop
104.
▲
by
mkjones
15y ago
Isn't this basically a trie?
105.
▲
by
mkjones
15y ago
I don't think the particular clickjacking attack you suggest would work - you cannot read document.location on an iframe if that iframe has a different origin. However, a variant of the later attack you describe would work. You could get t
106.
▲
by
mkjones
15y ago
This should work: http://mkjon.es/xss.html (note that your server seems to hang if I put "<script>" in the GET params, but assuming that works and thus the page is vulnerable to XSS like you intended, then this works). Just prete
107.
▲
by
mkjones
15y ago
Actually, it looks vaguely Greek...? Or Elvish? http://www.elvish.org/gwaith/andries/andries_scribalhand.jpg
108.
▲
by
mkjones
15y ago
I think Mongolian often uses a Cyrillic alphabet, and that doesn't look particularly Cyrillic to me, just smudgy and hard to read (but the latin alphabet).
109.
▲
by
mkjones
15y ago
We have that: http://mkjon.es/friend.png . In addition to data from that, we also look at how many people click "not now" when someone adds them as a friend. These signals (and a number of other factors) are taken into account when classi
110.
▲
by
mkjones
15y ago
I don't know the specifics of that attack, and I'm not claiming that we have 100% recall. I just think we do pretty well against many attacks.
111.
▲
by
mkjones
15y ago
It's probably worth clarifying that a "compromised login" means "you know the username and password for an account, but we suspect you may not be the actual account holder." Basically, knowing someone's username and password is not enough t
112.
▲
by
mkjones
15y ago
In this case, "login" means roughly "we see a username / password pair and evaluate whether or not it is compromised given the current context." (I work on the team that does these classifications.)
113.
▲
by
mkjones
15y ago
I believe this is only true for undergrads, and they started doing this in 06-07 or 07-08. I was undergrad '09 and definitely had loans for the first year or two, but not in subsequent years after they instated the "no required loans" poli
114.
▲
by
mkjones
15y ago
This is untrue. From the left column of http://www.stanford.edu/admission/ : "Students are admitted on a need-blind basis, and the university ensures that no admitted student is unable to attend."
115.
▲
by
mkjones
15y ago
I wasn't involved with that situation at all, but I don't think it involved any responsible disclosure of a security vulnerability.
116.
▲
by
mkjones
15y ago
This becomes hard when you have many users behind one IP (corporate NATs, schools, entire countries, etc), and when attackers can hop proxies fairly easily.
117.
▲
by
mkjones
15y ago
Not sure what he meant, but it's usually possible to brute force even decent online auth systems. Since most of these systems are rate-limited per-account, instead of iterating over passwords for a given account, you can iterate over accoun
118.
▲
by
mkjones
15y ago
What attack can you make with the "remembered browsers" feature that you couldn't do without it? Stealing someone's computer and password and doing things with that?
119.
▲
by
mkjones
15y ago
I guess you have to trust that the company wouldn't go to the trouble of setting up a program (and making payouts) if it were going to treat vulnerability reporters poorly. I think treating them poorly is generally a pretty bad long-term p
120.
▲
by
mkjones
15y ago
It's worth mentioning that some places embrace responsible disclosure, even going so far as to offer bounties when people do: Facebook: https://www.facebook.com/whitehat/bounty/ (disclaimer: I work here). Tarsnap: http://www.tarsnap.com/
More ›