Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nbpoole
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
nbpoole
14y ago
From the homepage: "BuddyHack: Did a friend leave Facebook open? Mess with it now." It's an app designed to be authorized on someone else's account. You make that pretty clear.
32.
▲
by
nbpoole
14y ago
It is, the installer you're looking for is just hidden very well. ;-) You can find it by going to "Install Chrome for all user accounts" http://support.google.com/chrome/bin/answer.py?hl=en&ans... , which points to "Alternate (offline)
33.
▲
A Python Tutorial for Economists
(alexmbell.com)
3 points
by
nbpoole
14y ago
|
0 comments
34.
▲
by
nbpoole
14y ago
Oh wow, I wrote this post a while ago! :-) It was a neat little idea to play around with when I first wrote the post, since setting X-Requested-With on an arbitrary domain requires a violation of the same-origin policy. But as I point out a
35.
▲
by
nbpoole
14y ago
The blog post links to http://www.cs.brown.edu/~ambell/data.html , which in turn links to http://www.google.com/googlebooks/uspto-patents-pair.html as the source of the data. That page doesn't give a particular date range. The dataset al
36.
▲
Google Patents: Missing Data Before 2000?
(alexmbell.com)
3 points
by
nbpoole
14y ago
|
3 comments
37.
▲
Security Vulnerabilities in Popular Flash Applets (SWFUpload, Plupload)
(nealpoole.com)
2 points
by
nbpoole
14y ago
|
0 comments
38.
▲
by
nbpoole
14y ago
Not quite. From the original bug report: " Today I installed Debian google-chrome-unstable and it also exhibits this issue. " One commenter ( http://code.google.com/p/chromium/issues/detail?id=128339#c3 ) also claimed to have the issue on O
39.
▲
by
nbpoole
14y ago
The backdoor is a setuid-binary that gives a root shell when prompted with the correct "password." Deleting the binary removes the backdoor.
40.
▲
by
nbpoole
14y ago
fastcgi setups are explicitly not vulnerable to this attack ( http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/ ) Edit: Are you proxying to an Apache server that runs PHP-CGI?
41.
▲
by
nbpoole
14y ago
http://www.bbc.co.uk/news/uk-england-york-north-yorkshire-17... "Glenn Mangham, 26, had earlier admitted infiltrating the social networking website between April and May 2011." I just checked my old emails and found XSS vulnerabilities I
42.
▲
by
nbpoole
14y ago
https://www.facebook.com/note.php?note_id=10150270651335766 That's a discussion of it from back in August. It started prior to that. And before that Facebook redid its existing responsible disclosure policy ( https://www.eff.org/deeplinks
43.
▲
by
nbpoole
14y ago
(Note: this post represents my own opinions, not anyone else's) No, but they normally report the vulnerabilities they find. I participate in a lot of responsible disclosure programs (Google, Facebook, Mozilla, Dropbox, Twitter, Etsy, etc)
44.
▲
by
nbpoole
14y ago
There was some previous discussion on HN about this individual: http://news.ycombinator.com/item?id=3604623 This comment in particular was very relevant: http://news.ycombinator.com/item?id=3605343
45.
▲
by
nbpoole
14y ago
Potentially relevant: it seems like the WooThemes site was compromised recently. http://www.woothemes.com/2012/04/were-alive-and-kicking/
46.
▲
by
nbpoole
15y ago
> If I'm comparing two 53-digit barcodes, and they differ only by the last digit (checksum), then it's very important that comparing those two STRINGS comes up FALSE. Then use === and do a type-strict comparison. <?php
47.
▲
by
nbpoole
15y ago
It's not a matter of preference: it's a matter of secure or insecure. The mysql extension for PHP doesn't support prepared statements and as such is inherently less secure than any other mechanism for working with MySQL (The mysqli extensio
48.
▲
by
nbpoole
15y ago
Previous relevant discussions on HN: - http://news.ycombinator.com/item?id=3791281 - http://news.ycombinator.com/item?id=3789673 - http://news.ycombinator.com/item?id=3778158
49.
▲
by
nbpoole
15y ago
It's not nearly as simple as you make it seem: 1. What is "safe content"? That entirely depends on the context in which you're using a particular string. (See https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%... for a summary o
50.
▲
by
nbpoole
15y ago
The CORS standard for 'simple' POSTs is no different than what you can already submit via a form from a technological perspective. In that way, it actually makes a lot of sense. And the whole point of CORS is that some websites do want to
51.
▲
by
nbpoole
15y ago
The point that those blog posts make is that it's possible for a malicious attacker to log people out of a third-party site in multiple ways (specifically by messing with the user's cookies). Protecting one of those ways provides little to
52.
▲
by
nbpoole
15y ago
Standard caveat with checking the Referer header: there is software out there which strips out the header in the name of privacy. If you use the Referer as a source of validation, you have to be prepared to deal with users of Norton Interne
53.
▲
by
nbpoole
15y ago
" This will not work even without CSRF protection. " It actually will work. What you're describing is what's known as a "simple" request in XMLHttpRequest terms. That means there is no pre-flight necessary. Your browser will simply make t
54.
▲
by
nbpoole
15y ago
I think I know what site you're talking about. If I'm right, they do have a security bug bounty reporting program and you should take advantage of it: it will take maybe two minutes of your time and can net you a bit of cash! :-) (sorry for
55.
▲
by
nbpoole
15y ago
No it does not. --- https://developer.mozilla.org/en/http_access_control#Simple_... A simple cross-site request is one that: - Only uses GET or POST. If POST is used to send data to the server, the Content-Type of the data sent to the se
56.
▲
by
nbpoole
15y ago
There's a difference between complaining about a class of vulnerability and exploiting a particular instance of a vulnerability that you seem to be failing to grasp. If you find a major hole in a part of Git, you are by no means obligated t
57.
▲
by
nbpoole
15y ago
" The X-Frame-Options: SAMEORIGIN header, supported by all major browsers, can prevent the majority of these attacks " No it can not. I've seen this assertion popping up a few times on HN this past week: it's conflating two similar but very
58.
▲
by
nbpoole
15y ago
Except an attacker can strip a referer header: if you fail open like that, you leave yourself open to attack. See http://blog.kotowicz.net/2011/10/stripping-referrer-for-fun-... for examples
59.
▲
by
nbpoole
15y ago
To fire automatically, yes: getting people to click on a button of their own free will is easy though.
60.
▲
by
nbpoole
15y ago
That prevents the result from being displayed, it doesn't prevent the request from being made. The distinction is subtle but hugely important. In other words, the browser makes the request, gets the response, and doesn't render it. The serv
More ›