Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tsujamin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
tsujamin
2y ago
It is, similarly to how Microsoft Office documents can run legitimate/malicious executable code. Although, Office (and most other software) will at least warn you before executing code/malware in such documents originating from th
92.
▲
by
tsujamin
2y ago
This obviously reveals how public sector-brained I am, but I can’t imagine hitting revenue numbers in a company I wasn’t a financial partner in being that intoxicating. Definitely glad that it’s for some though, helps keep the industry movi
93.
▲
by
tsujamin
2y ago
Genuinely curious as to why? If it’s your work, information or copyright, should you not have a say in how it is used? If you want your site to be indexed and discoverable by your audience, but not used as a source in some LLM summary, is t
94.
▲
by
tsujamin
2y ago
VirtualProtect might be unhooked in userspace by the payload, and the payload might only be decrypted for a short moment (to run a task, do a beacon cycle) so you’d have to be quick capturing its unobfuscated form. Not sure if you can actua
95.
▲
by
tsujamin
2y ago
Sidecar/display mirroring from my macbook to my ipad is pretty low latency, so presumably this will be based on a similar technology stack
96.
▲
by
tsujamin
2y ago
Wonder if they could enclave it similar to Cred Guard
97.
▲
by
tsujamin
2y ago
Presumably the snapshots it takes and summarises are periodic, but at what interval I'm not sure. Alternatively (and this is a technical possibility) it could be hooked into WebViews and HWNDs to get notified when it's worth takin
98.
▲
by
tsujamin
2y ago
Presumably the endless run of civil litigations has delayed the criminal cases to date
99.
▲
by
tsujamin
2y ago
Looking forward to learning how a sub 1% rate of foreign property purchases is really the problem in Australia https://www.afr.com/politics/federal/overseas-investors-are-... https://foreigninvestment.g
100.
▲
by
tsujamin
2y ago
To be fair, OLE and malicious office macros aren't actually related except that they use a common file format sometimes. Rest of the point is solid though.
101.
▲
by
tsujamin
2y ago
The file format exists, its Compound Document Files which are effectively just a little FAT filesystem in a file from memory. both Microsoft and 3rd parties (...Autodesk maybe?) use them. My favourite example of seeing them is VBA macro pro
102.
▲
by
tsujamin
2y ago
I’m not sure how rust-analyser works, but presumably you’d make the macro a no-op and just return the original tokens in debug builds
103.
▲
by
tsujamin
2y ago
Having just finished watching evangelion rebuild today: it is definitely a robot anime
104.
▲
by
tsujamin
2y ago
There’s a whole load more checks for “../“ patterns in the web code since the bugs around 2020 :)
105.
▲
ArcaneDoor: New espionage-focused campaign targeting perimeter network devices
(blog.talosintelligence.com)
2 points
by
tsujamin
2y ago
|
0 comments
106.
▲
by
tsujamin
3y ago
Pretty disappointing that Guardian article also got quickly flagged after HN submission
107.
▲
by
tsujamin
3y ago
Super annoyingly iCloud Private Relay triggers this for me too
108.
▲
by
tsujamin
3y ago
Sydney taxis are extortionate and often operate illegally around the airport, but also taxi plates in Australia costed $100,000’s (on the market, not sure how much when released by the government) and that investment got trashed by ride-sha
109.
▲
by
tsujamin
3y ago
Heat stress is my trigger, although I went a couple years without an aura until I had one recently
110.
▲
by
tsujamin
3y ago
CVSS has consistent rules, but yeah then incentives that make people ignore particular rules (vulnerability chaining being the one that I’ve seen before) makes the public scores questionable sometimes. Still it’s a useful, if imperfect, too
111.
▲
by
tsujamin
3y ago
How do you calculate that? How does the fact it’s an over-the-internet vs. network adjacent only exploitable? This is what CVSS is good for when applied accurately
112.
▲
by
tsujamin
3y ago
Can’t speak for others, but I’m talking from some experience here triaging and reporting fwiw. Not that I’m notable :)
113.
▲
by
tsujamin
3y ago
CVSS as practiced sucks sometimes, the rules around not chaining vulnerabilities to up a score are rarely followed, but as specified it’s actually a good system. Undercutting my own point though, it doesn’t hurt to rerun a calculation if yo
114.
▲
by
tsujamin
3y ago
you’re missing the CVSS aspect which is intrinsically tied to CVE issuance (atleast when issued through the CNA-LR). It’s not _just_ an identifier, it’s a entirely valid and useful tool of triage and classification
115.
▲
by
tsujamin
3y ago
It does matter, because they are inputs into other processes, and the signal to noise has gone down. There’ll be a lot more time wasted in orgs triaging non-security-relevant bugs in the future.
116.
▲
by
tsujamin
3y ago
Yeah like all the above IMO the tool is already on the machine and it’s not a typical (read: looked for) technique
117.
▲
by
tsujamin
3y ago
This reminds me of the Australian National University hack, where the threat actor downloaded and spun up their own XP/Kali VMs on servers they compromised https://theuniguide.com.au/news/anu-releases-details-of-da
118.
▲
by
tsujamin
3y ago
Ran across some .re2c generated functions in some software I was reverse engineering recently. It probably speaks more to the compiler/source used but the generated code was incredibly verbose (400 odd nested error handling branches).
119.
▲
by
tsujamin
3y ago
Loved Seveneves and Fall, in particular the little slice of Ameristan in the Fall, but I feel like in both cases they are great books with a mediocre book attached to the end.
120.
▲
by
tsujamin
3y ago
My advice tends to be using SASE things like AppProxy - you can have your less-than-stellar enterprise business apps exposed outside of the LAN without putting them up as a target on the public internet
More ›