Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tmsbrg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
tmsbrg
3y ago
damn, you beat me to it. Was gonna write: http://localhost:8888/..../..../..../..../..../..../etc/host... mypc These regex substitutions are so easy to bypass :)
32.
▲
by
tmsbrg
3y ago
From my experience most of these defences take the form of limiting privileges and implementing the four eye principle. Consider the fact he could take over 15 Google developers systems within a few weeks with little effort. What if there&#
33.
▲
by
tmsbrg
4y ago
Ah good point. I didn't realise that. I need to look into MicroG again. Any Android running Play Services basically has a massive backdoor.
34.
▲
by
tmsbrg
4y ago
Thanks for finding that. The Ars Technica article is actually informative journalism. The The Register article just leaves you confused about what's real and seems to focus more on who's involved than what's happened. Really
35.
▲
by
tmsbrg
4y ago
Definitely seconding pup, love it and it's easy to use with css selectors. Often use it to parse HTML tables of data on random websites into usable CSVs / etc. xq looks interesting for pure XML, will add it to my notes. Regarding
36.
▲
by
tmsbrg
4y ago
On Android you can just install Firefox for mobile and install uBlock Origin as usual.
37.
▲
by
tmsbrg
5y ago
That would be Diplomacy [0] Worth trying out online for example through webDiplomacy [1]. It's my favourite game. [0] https://en.wikipedia.org/wiki/Diplomacy_(game) [1] https://webdiplomacy.net/
38.
▲
by
tmsbrg
5y ago
I'm willing to donate, but I don't have a Google account linked to my device, so Google pay is out of the question. Maybe Mobilecoin will be an alternative in the future that doesn't depend on Google services.
39.
▲
Diving into Userscripts
(thomasvanderberg.nl)
28 points
by
tmsbrg
5y ago
|
1 comments
40.
▲
by
tmsbrg
5y ago
It seems the trend lately for new services to be built with rather high monthly fees. From the FAQ: "We plan to offer entry level plans for as low as $10/month, unlimited plan at around $20/mo as well as make bundles (to incl
41.
▲
by
tmsbrg
5y ago
That doesn't protect your microphone from being exposed though.
42.
▲
by
tmsbrg
5y ago
I think what he means with historically is before ASLR, DEP, and other mitigations, where a buffer overflow meant you can simply overwrite the return pointer at ESP, jump to the stack and run any shellcode. Mitigations have made exploitatio
43.
▲
by
tmsbrg
5y ago
https://github.com/Dither/full-text-rss https://github.com/alrs/full-text-rss-docker
44.
▲
by
tmsbrg
5y ago
I never really got why people use `dig`. Its interface and output is awkward, and it seems all of its functionality can be more easily performed with `host`, which doesn't feel the need to print stuff like: ; <<>> DiG 9.16.
45.
▲
by
tmsbrg
5y ago
Another one of those articles that's too long for its own good. Thought at the title: Fraud, organic food, yes. This must be interesting. Reading through the start: Okay, here's the life story of someone who's going to do som
46.
▲
The Ratings Game, Part 2: The Hearing
(filfre.net)
1 points
by
tmsbrg
5y ago
|
0 comments
47.
▲
Pink, a botnet that competed with the vendor to control infected devices
(blog.netlab.360.com)
2 points
by
tmsbrg
5y ago
|
0 comments
48.
▲
by
tmsbrg
5y ago
I was curious about the LineageOS, so I checked and found: "On all of the other handsets the Google Play Services and Google Play store system apps send a considerable volume of data to Google, the content of which is unclear, not publ
49.
▲
Ruin Marble
(en.wikipedia.org)
75 points
by
tmsbrg
5y ago
|
4 comments
50.
▲
Game Theory 101: The Centipede Game (2012)
(youtube.com)
1 points
by
tmsbrg
5y ago
|
0 comments
51.
▲
by
tmsbrg
5y ago
Hmm, rlwrap[0] is a really nice tool when working with applications that are poor at handling terminal input. It basically handles your keystrokes in rlwrap and whenever you type enter it will send the input line to the application to handl
52.
▲
by
tmsbrg
5y ago
They don't need your session cookie either. An attacker can just use XmlHttpRequest to perform any actions as you on the website, and read the web page results. E.g. go to your profile and steal all your personal data. They can also se
53.
▲
John Romero on IRC (1995)
(doom2.net)
3 points
by
tmsbrg
5y ago
|
0 comments
54.
▲
by
tmsbrg
5y ago
Trying to load https://www.researchhub.com/hubs with Google domains disabled in uMatrix causes it to go into some infinite loop of constantly trying to reload everything until my Firefox uses 100% CPU and never loads :(
55.
▲
by
tmsbrg
5y ago
This is actually just a Go app which implements SSH using the Go standard library's SSH module. It's not like you're really SSH-ing into a server. See the source: https://github.com/hackclub/jobs
56.
▲
by
tmsbrg
5y ago
Sorry, but as someone who doesn't live in the USA, I have a hard time feeling bad for someone for not being able to earn "$11,000 per month as a baseline salary for working full-time on open source." Sure, it's nice to b
57.
▲
by
tmsbrg
5y ago
You can and should protect GraphQL on the backend. GraphQL will just forward requests to resolvers which actually get the data, these resolvers should see who's logged in and only return data this user has access to. I'd say the s
58.
▲
by
tmsbrg
5y ago
Considering he had already found and reported this vulnerability before, and then took the time to write this report about it, that's not what happened here. He knew it was a vulnerability, he used it purposely to download private data
59.
▲
by
tmsbrg
5y ago
Basically what you want is a Docker image static analysis tool in your CICD that rejects your pull request if it seems to contain a secret. I'm not really sure what would be the best tool for this, but googling got me to https:/&
60.
▲
Microsoft implemented and then removed a crucial Teams feature on Linux
(thomasvanderberg.nl)
2 points
by
tmsbrg
6y ago
|
0 comments
More ›