Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
steakejjs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
91.
▲
by
steakejjs
12y ago
I would think this means you are not vulnerable. The js begins with a null byte and works on a lot of different versions. I think the vuln probably just had not been introduced at that time, but I obviously can't be certain without dig
92.
▲
by
steakejjs
12y ago
Absolutely critical to know. Thanks joev_. I see that now after reading the msfmodule. This is a good one!
93.
▲
by
steakejjs
12y ago
If you aren't familiar with SOP, this is about the worst "stupid web vuln" that can happen. SOP is the glue that kind of almost makes the web secure. The attack DOES work if X-Frame-Options is enabled (thanks joev. The msfmod
94.
▲
by
steakejjs
12y ago
What? I don't understand what you mean. PHP is not any more insecure than other languages. Some extremely secure sites run PHP....so security augmentations would not be obscurity. An example would be built in CSRF protections through s
95.
▲
by
steakejjs
12y ago
This looks awesome. PHP doesn't get a lot of love but it is really improving a lot and obviously still dominates the web... Glad the turkish bug is finally done with. Would be really nice to see security augmentations to the language.
96.
▲
by
steakejjs
12y ago
My biggest objection is the "approved VC" rule. Being from Washington DC, if I were to create a startup and get funding, am I on the approved list? I doubt they would have heard of the VCs out here (I don't know of many tech