Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
plugnburn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
25 ms
·
91.
▲
by
plugnburn
11y ago
It's related to the intentions this guy had in his head. If someone would find this vulnerability in Updrop after plenty of files were uploaded and the service became popular, compromising the security with any evil intention would bri
92.
▲
by
plugnburn
11y ago
Then you should definitely give a try to Meteor framework ( https://www.meteor.com/ ). Using it, we have built and run a production-ready service + Android app for a local flower shop delivery-messengers in about 5 days.
93.
▲
by
plugnburn
11y ago
What's the real issue is: <navbar></navbar> Do you even know that this is invalid and the proper tag is called just <nav>? Do you know that <title> must not be empty in the initial page? Do you know that cu
94.
▲
by
plugnburn
11y ago
Was. 15 years ago.
95.
▲
by
plugnburn
11y ago
"Server-side HTML generation"... literally each word in this phrase shows how bad things are now in 99% of websites and - what's even worse - we still have to somehow follow these things for some sucky search engine bots that
96.
▲
by
plugnburn
11y ago
Why would anyone disable it these days?
97.
▲
by
plugnburn
11y ago
Are you on GPRS? Cause the page loads fine even on 7Mbit 3G (HSPA). The problem is it's still quite raw and full of demo-stuff. Not in the way it loads. Although... yes, isn't Angular a bit overkill here?
98.
▲
by
plugnburn
11y ago
Wow. Just wow. Not that I would need this IRL but it still deserves a thumbs-up in a way that this numeric type is not forgotten. Unfortunately, we lack even complex number support in most languages standard math APIs, let alone quaternions
99.
▲
by
plugnburn
11y ago
Nice one too. The concept of mine is entirely different though: to never deal with raw HTML strings, just logical blocks such as arrays and objects describing elements and their attributes and contents. With XT, I never need to escape conte
100.
▲
by
plugnburn
11y ago
My laptop has no separate number pad but its keyboard has a mode in which some keys are remapped as numpad keys. Sorry, it's a live-only demo for Samples.js, recording (and export) would require more in-depth Web Audio API usage, timin
101.
▲
by
plugnburn
11y ago
Ability for a user to link Twitter account to automatically tweet the stories they vote for.
102.
▲
by
plugnburn
11y ago
There still are some encryption schemes that can be run with nothing more than a pencil and paper. See SMSPP for example: https://gist.github.com/plugnburn/6b50ceee3a89893a9e48 You can also use straddling checkerboards
103.
▲
by
plugnburn
11y ago
Why doesn't a cheapest Android smartphone with a 3G modem (say Alcatel 4009D) fit? Because it's not 4G? Well, here's the real tradeoff: security, comfort, cheapness. Pick two.
104.
▲
by
plugnburn
11y ago
Here in Ukraine, we have the same problem. If you publicly don't agree with the government's policy of tightening the nuts, you may face a prison term under any fabricated accusations, including "work for russian spies".
105.
▲
by
plugnburn
11y ago
Absolutist view on Obama cannot prevail. Absolutist view on WWII cannot prevail. Absolutist view on current world order cannot prevail. Continue? Though absolutist view on our privacy, digital included, MUST prevail.
106.
▲
by
plugnburn
11y ago
Some explanations: - works everywhere where standard Web Audio API is supported; - based on Samples.js ( https://gist.github.com/plugnburn/75ce136bea973d8767e0 ) and is a reference demo for it; - supports loading custom
107.
▲
Show HN: numLaunchpad – a WebAudio-based drum pad
(numlp.apps.dj)
10 points
by
plugnburn
11y ago
|
6 comments
108.
▲
by
plugnburn
11y ago
So that's my feedback: at least remove the ability to upload PHP files onto Updrop. And then disable PHP for upload folder altogether.
109.
▲
by
plugnburn
11y ago
So Updrop wasn't made by you and you hired a dev to create it?
110.
▲
by
plugnburn
11y ago
I'm not interested in any paid work. I'm trying to say that your entire server is vulnerable to hacker attacks right now. It seems strange that you posted a vulnerable website on Hacker (!) News... Or do I need to post my message
111.
▲
by
plugnburn
11y ago
Well, I found what the server side is written in. In fact, I found everything about your server. Why? Because you, sir, do not know a thing about server security and configuration - this is the file I managed to upload: http://up
112.
▲
by
plugnburn
11y ago
Nice idea, nice design, horrible code behind it. Just a look at rtu.js made me cry. Never mix logic and presentation. Especially in such security-crucial projects. I don't know what is the server side written in but it seems horrible t
113.
▲
by
plugnburn
11y ago
Quite interesting (I was into esoteric programming about 2 or 3 years ago). Have three questions: - Is there any standard library (for common input/output/math etc)? Haven't found how to do 2 + 2 in Om. - Is there any way to
114.
▲
by
plugnburn
11y ago
Why would you? Web-based but untraditional: Make a website to offer russia to exchange him for Zhirinovsky.
115.
▲
by
plugnburn
11y ago
2 words: add auto-tweeting.
116.
▲
by
plugnburn
11y ago
Some explanations: - this is a companion to previously announced XT.js, but for dynamic CSS construction; - ES5 compatible; - no at-rule support at this point (as we are on JS, .matchMedia FTW, and dynamic @keyframes building is too specifi
117.
▲
Show HN: XS.js - an ultra-small CSS rule builder in 10 lines of JS
(gist.github.com)
1 points
by
plugnburn
11y ago
|
1 comments
118.
▲
by
plugnburn
11y ago
Challenge accepted! I plan to make a simpler dynamic CSS construction library (similar to XT.js - https://news.ycombinator.com/item?id=11260471 - which constructs DOM fragments) that's both smaller and targeted for ES5
119.
▲
by
plugnburn
11y ago
Faildows and Infernet Exploiter users must suffer. Period.
120.
▲
by
plugnburn
11y ago
I wonder if we could run a browser inside this thing. Imagine: a browser in a system emulated in an Emscripten-based emulator running in a browser...
More ›