Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ovex
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
ovex
3y ago
But `eval()` does not violate a programmer's intuition as easily as an arithmetic expression resulting in code execution.
2.
▲
by
ovex
3y ago
From a security point of view, Python is better because it is less of a footgun. So if you expose an interface to untrusted users, you should use Python because its behavior is more intuitive. An arithmetic expansion or missing quotes do no
3.
▲
by
ovex
3y ago
Recently, I found a privilege escalation vulnerability in a shell script as a result of arithmetic expansion (similar to the one described at https://research.nccgroup.com/2020/05/12/shell-arithmetic-ex... ).
4.
▲
Tell HN: Bountysource seems to have shut down
2 points
by
ovex
3y ago
|
0 comments
5.
▲
by
ovex
4y ago
Now that it loaded again for me, I can see the /graphql endpoint. Caching GET requests to endpoints for a few minutes (or even just one minute) will likely suffice, given that the puzzle is the same for all users. If I am not overlooki
6.
▲
by
ovex
4y ago
Great puzzle. I liked it so much that I saw your message about going live a few days ago already. Is there any dynamic content generation involved? I am wondering because the Gateway timeout hints at something behind nginx being the bottlen
7.
▲
by
ovex
4y ago
I am not a brand ambassador or a living billboard and some random company is not part of my identity, which is why I dislike wearing t-shirts with company logos.
8.
▲
by
ovex
5y ago
Interesting. I would still insist on not doing it that way, especially when writing a library for universal use. First of all, string replacement on structured input is an immediate red flag. Second, even if you get handling the structured
9.
▲
by
ovex
5y ago
The problem is not only that types are not checked but that strings are simply replaced in structured input. Without having looked in detail, I would bet that the implementation also fails at queries which contain question marks inside stri
10.
▲
by
ovex
5y ago
I'd argue that the root mistake is that the server-side feature of prepared statements through the client/server binary protocol is not used as described in [1]. Instead, the question marks are replaced using a dirty hack. The who