Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
supakeen
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
supakeen
7y ago
They could invalidate the passwords making you use a 'forgot password' link to enter a new password instead of keeping the old compromised ones :)
62.
▲
by
supakeen
8y ago
I think it would've been nice if you had shown a UNION or OR 1='1 attack as well. Many database drivers/packages will block multiple queries in a single statement :)
63.
▲
by
supakeen
8y ago
No mention of shipping off logs to another place? It's probably good to assume someone will gain access and make after-the-fact forensics a primary concern as well. Something a lot of hardening guides seem to skip!
64.
▲
PHP's PEAR website compromised
(pear.php.net)
5 points
by
supakeen
8y ago
|
0 comments
65.
▲
by
supakeen
8y ago
Why the use of two different random number generators and drawing these images one pixel at a time? Why not swap the entire image colorspace to black/white for black/white? Why the choice of using imageio to create the gif when Pi
66.
▲
by
supakeen
8y ago
There are many languages that are very popular for prototyping and learning what makes JavaScript the best?
67.
▲
by
supakeen
8y ago
It's easy to point out that this is caused by 'the internet' or 'modern technology' replacing the need for human interaction. We feel less alone but are more selective about our friends, live in smaller echo chamber
68.
▲
by
supakeen
8y ago
The one the owner thinks was not used as he only saw database access not shell access but was mentioned by ZDNet as getting well known around the time this database was emptied.
69.
▲
by
supakeen
8y ago
Not a good example as it is currently 502'ing: https://i.imgur.com/sU8Zn5v.png
70.
▲
by
supakeen
8y ago
Fun, but outputs unprintable or non-used characters and only functions on the BMP?
71.
▲
by
supakeen
8y ago
I usually use the home and end keys on my keyboard.
72.
▲
by
supakeen
8y ago
For the English readers without Dutch sources, here is some additional information which might or might not be in the article: Police seized and operated a server of a company called Blackbox Security which offered 'crypto phones'
73.
▲
by
supakeen
8y ago
It was made public because the exposed operations of criminals led to threats being made against assumed 'leaky partners'. The police did not want these people to retaliate against other people and possibly endanger bystanders. Wh
74.
▲
by
supakeen
8y ago
A whois on the 35.241.245.36 returns a ownership by Google with the following comment: Comment: * The IP addresses under this Org-ID are in use by Google Cloud customers * He then uses the SSRF to issue a request to his own serve
75.
▲
by
supakeen
8y ago
An update is that on Reddit a Firefox employee has responded on my crosspost to reddit: https://www.reddit.com/r/firefox/comments/9cx8hk/on_firefox_... Clarifying that this is just an A/B test and t
76.
▲
by
supakeen
8y ago
And Android P is already gearing up to DNS over HTTPS as well with Android itself going with DNS over TLS. Don't know what the iOS stance on this is.
77.
▲
by
supakeen
8y ago
It's likely that the assumption is that in 'enterprise' or large organizations software installation and configuration is managed or that they fall back if they can't (but as the blog post says; DNS over HTTPS is hard to
78.
▲
On Firefox moving DNS to a third party
(blog.powerdns.com)
53 points
by
supakeen
8y ago
|
49 comments
79.
▲
Why subprocess is the safe way to execute commands in Python
(supakeen.com)
4 points
by
supakeen
8y ago
|
0 comments