Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tinix
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
181.
▲
by
tinix
7y ago
I receive vulnerability notifications for Jenkins, pretty much regularly... mostly XSS and RCE. https://www.cvedetails.com/vulnerability-list/vendor_id-1586... I'm just waiting for Apache to adopt it, and then it&
182.
▲
by
tinix
7y ago
Why not just refill the toner yourself for a few bucks?
183.
▲
by
tinix
7y ago
so "rub some dirt on it" isn't totally stupid. ;)
184.
▲
by
tinix
7y ago
The title is pretty inaccurate, perhaps they updated it since this was posted? "Amazon will no longer sell Chinese goods in China"
185.
▲
by
tinix
8y ago
Aren't you supposed to cover the bags with more clay or stucco or something? Much like doing a cobb house. Cobb is fireproof, and earthquake resistant. Cobb also resists UV degradation. If you're leaving the bags exposed, that
186.
▲
by
tinix
8y ago
Yeah if you dig you'd find this: https://github.com/gordol/ld_preload-sounds/issues/4#issueco... ;)
187.
▲
by
tinix
8y ago
micropython IS regular python, that's the point. i see no reason why this wouldn't work on cpython.
188.
▲
by
tinix
8y ago
audio generation from malloc and read: https://github.com/gordol/ld_preload-sounds also for OSX: DYLD_INSERT_LIBRARIES
189.
▲
by
tinix
8y ago
or reproductive organs?
190.
▲
by
tinix
8y ago
No, numpy and pandas break with every new release, support for them is constantly lagging behind. Other C libraries too...
191.
▲
by
tinix
8y ago
got a source for that? or was that a low gravity joke? haha
192.
▲
by
tinix
8y ago
this seems utterly pointless... what does this get you that tumbling the means doesn't? the beans will still need to be mixed to prevent scorching, and it's not like coffee beans are fragile things...
193.
▲
by
tinix
8y ago
We only support webkit based browsers for our web application. Multiple fortune 500 companies use it, meaning they are using neither IE/Edge nor Firefox... nuff said. I'm guessing the people complaining here haven't tried to
194.
▲
by
tinix
8y ago
Then how come an offline region of a national park in Google Maps is a larger download than the entire state in OsmAnd?
195.
▲
by
tinix
8y ago
You can use "online" maps and it only downloads the visible region on your screen. It's not a few hundred megs "just to show you where you are" that is utter nonsense. How about you just actually use the app before
196.
▲
by
tinix
8y ago
Huge? Not so much... OsmAnd uses vector maps, which are very small, compared to "offline" Google Maps tiles. A couple hundred megabytes for an entire country's road system is not "huge".
197.
▲
by
tinix
8y ago
to further elaborate, it would take 85 days of 4gbps network link being 100% saturated to leak a 256 bit key, assuming you know the memory locations, assuming no ASLR, assuming the key doesn't move or change, and assuming a vulnerable
198.
▲
by
tinix
8y ago
not really... this is only a vulnerability in so much as specific gadgets were intentionally placed in code. it's more of a danger for intentional data exfiltration covertly, not an issue of attacking random servers like ssh or web ser
199.
▲
by
tinix
8y ago
Oh my gosh, I was so annoyed by their utter lack of competency that I didn't even catch that they did call it an emulator. Classic.
200.
▲
by
tinix
8y ago
Tech journalists, especially, almost always fail to do even a tiny bit of research or due diligence. I mean... Crostini is not "new", it's been on dev channel for months[1]! But this article ending... hilarious icing on the c
201.
▲
by
tinix
8y ago
Yeah, so then you have to exploit nginx, not a web application. Good luck with that. If someone can get RCE through nginx alone, you're already toast.
202.
▲
by
tinix
8y ago
When this happened to me, I jumped to the same conclusion, that the PDFs must be a honeypot or something. But yes, PDFs are exploitable, like any file format. https://www.sans.org/security-resources/malwarefaq/pdf-
203.
▲
by
tinix
8y ago
If the author is truly a "ninja" they wouldn't be running their web application as the nginx www-data user in the first place, and then a web application exploit wouldn't inherently give anyone access to the nginx user e
204.
▲
by
tinix
8y ago
What does this have to do with anything even remotely related to this article, other than it being a webserver? Symlink takeover is not a new vulnerability, and if someone has a user account on your server, you're already owned anyway.
205.
▲
by
tinix
8y ago
Ha! One of my old staging subdomains had an old Digital Ocean address left in it for a bit while we migrated some servers, and Google indexed some random ebook pirate site too, here[1] is a snap of the logs for anyone who is curious. Once I
206.
▲
by
tinix
8y ago
Most "terminals" just use libvte, which, true, doesn't support most control commands, including OSC 52[1]. However, xterm supports it, alacritty supports it, hterm and many others... A stock Chromebook[2] supports OSC 52, and
207.
▲
by
tinix
8y ago
Clipboard control in terminals... yet.... not a single mention of OSC 52. <_< Then they are using /tmp to facilitate IPC... What a horrible thing.
208.
▲
by
tinix
8y ago
Installing "iptables" also installs ip6tables. https://linux.die.net/man/8/ip6tables
209.
▲
by
tinix
8y ago
Ehh... Maybe using eventlet isn't necessarily native "async" but... it works just fine in our use cases... http://eventlet.net/doc/modules/db_pool.html
210.
▲
by
tinix
8y ago
Latest trend? Haven't we all gone through this before? Back in 2012 I did a "homework assignment" too, just to get an interview with a game studio. The task? Build a SOAP client and server that do some silly little thing, I d
More ›