Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pipeline_tux
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
pipeline_tux
3y ago
I haven't tested with either of those unfortunately, but I do regularly test when connected to a VPN using OpenVPN. From a PC/Mac, if you can reconfigure your browser to proxy traffic via Pākiki, it should work with them (and then
2.
▲
by
pipeline_tux
3y ago
Thanks for the kind words and feedback! There should be a real-time table when you're running a scan so that sounds like a bug. Having a real-time table is surprisingly light on resources. I haven't done a huge amount of testing o
3.
▲
by
pipeline_tux
3y ago
Thanks for the suggestion. I've added it to the todo list.
4.
▲
by
pipeline_tux
3y ago
Hi! Yeah, it seems like we've identified similar problems and addressed them in reasonably similar ways. Likewise, I've went with SQLite as the project file format, with the files being compressed when saving so that users can tra
5.
▲
by
pipeline_tux
3y ago
Thanks! Yeah, it was definitely an ambitious choice, but I think it results in a better product, and I'm really happy with how it's turning out. For now it's just me part time, but I'm hoping to go full time or near full
6.
▲
by
pipeline_tux
3y ago
Usability and performance (for example when deployed on lower-end customer machines) are two major ones. Admittedly they have been getting better over time. It's also not uncommon to have sites behave a bit differently when running via
7.
▲
by
pipeline_tux
3y ago
No, it doesn't unfortunately. In a professional testing world, we'd normally just ask clients nicely to disable that for our testing. If you're testing something where you don't have a relationship with the developers, t
8.
▲
by
pipeline_tux
3y ago
Correct. Burp is the main competitor, but it's been around a long time and I wanted to develop something from scratch to address a number of the problems myself and other pentesters have had with it.
9.
▲
by
pipeline_tux
3y ago
Thanks! The tool has a built in certificate authority (CA) to generate TLS certificates. So to intercept TLS traffic from a phone, you export the CA's root certificate and import it onto your phone. If you're on PC, you can also l
10.
▲
by
pipeline_tux
3y ago
Correct, ZAP is one of the main competitors, and the core functionality is the same. While there's a browser Head-up Display, the primary UI is still a Java desktop-based application.
11.
▲
by
pipeline_tux
3y ago
Thanks! There's a few points of difference in terms of approach/philosophy. Firstly, I really wanted to focus on usability. So there's a native UI on each platform, using GTK on Linux, and SwiftUI on MacOS. This means that we
12.
▲
Show HN: Pākiki Proxy – An intercepting proxy for penetration testing
(pakikiproxy.com)
97 points
by
pipeline_tux
3y ago
|
43 comments
13.
▲
by
pipeline_tux
10y ago
Torrents are filling the gap where the traditional media companies are still failing. Here in NZ there are 7 different streaming services that I can immediately think of, each with exclusive rights to some content. I'm not paying $80 a
14.
▲
by
pipeline_tux
11y ago
As someone who works in infosec, this doesn't surprise me at all. I've tested many applications which claim to be secure, designed for security/privacy sensitive tasks, yet are very easy to compromise (simple OWASP top 10 stu
15.
▲
by
pipeline_tux
13y ago
The OWASP testing guide is a very good start: https://www.owasp.org/images/5/56/OWASP_Testing_Guide_v3.pdf It covers the process of a web application test and explains 90% of the vulnerabilities you'll f
16.
▲
by
pipeline_tux
15y ago
I'm sure that the 911 operator won't mind, especially if it is or could be a genuine emergency.
17.
▲
by
pipeline_tux
15y ago
In which case the NSA say "Oops, it was a genuine mistake. Sorry." With 200,000 lines of code, there will almost certainly be unintentional security holes that haven't been found.
18.
▲
by
pipeline_tux
15y ago
I don't necessarily think there will be one, but I wouldn't be surprised either. Security flaws can be extremely subtle and 200,000 lines of code is a lot to review... Given that there's plausible deniability (we didn't do it intentionally,
19.
▲
by
pipeline_tux
15y ago
They provide a list of backup codes which you're meant to print and put in your wallet.
20.
▲
by
pipeline_tux
15y ago
> My reading is that you couldn't brute force it, you'd have one chance to set up the iframe with the cookie file in it which needs the username, or at least just one chance per clickjacked drag action that the user executes for you. Bu
21.
▲
by
pipeline_tux
15y ago
> Cookiejacking Exploit Hits Internet Explorer, Targets Your Login Info This makes it sound like they're going to be able to get your password... No major website will be storing your password in a cookie. At worst the attacker will h
22.
▲
by
pipeline_tux
15y ago
Mine cost me nothing. I got some wood scraps from a local kitchen factory and built a couple of tables, at the right height, to stand on top of my standard desk.
23.
▲
by
pipeline_tux
16y ago
Yep, that's pretty much how they work. I can't find the details of it now, but the "smart" ones also do some colour transformations on the image so detection will work irrespective of what race the people in the porn are.
24.
▲
by
pipeline_tux
16y ago
Relatively... The browsers themselves won't write anything to disk but this doesn't stop things like plugins (EG: Flash, Java, media players, etc) from writing to disk, or lower level operating system functions (IE: Swap) writing to disk.
25.
▲
by
pipeline_tux
16y ago
You'd be surprised at what your web browser and operating system cache... That one session where you forgot to switch to incognito mode could leave hundreds of images on the hard drive ;)
26.
▲
by
pipeline_tux
16y ago
There are two common approaches that forensics tools use: 1) It could be scanning the file system and looking for all files (both present on the drive and deleted), which have an image extension on the filename (.jpg, .gif, etc). The adv
27.
▲
by
pipeline_tux
16y ago
They're satellite dishes used for intercepting satellite communications, but they're covered in domes: http://en.wikipedia.org/wiki/GCSB_Waihopai
28.
▲
by
pipeline_tux
16y ago
From a security perspective, this is also a bad idea. One of the golden rules of security is to validate all input. Anything which the programmers didn't expect and check for can potentially be used as part of an exploit.
29.
▲
by
pipeline_tux
16y ago
I do this and the biggest issue I've had so far is trying to talk with people from the businesses in my target market, who only work from 9 until 5.
30.
▲
by
pipeline_tux
16y ago
Our University had one of these courses too. They were finding that without a course like this, too many students were taking the stage one computer science courses hoping to improve their general computer skills. After introducing this c
More ›