Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
a1a
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
a1a
2y ago
I didn't mean to trivialize the issue. You describe a problem that arise when multiple parties share data with "presumptions of trustworthiness" i.e. do not perform proper input validation. No?
2.
▲
by
a1a
2y ago
Wow, this is a Hyper-V breakout! I am amazed that it's 2024 and we still have problems with basic input validation.
3.
▲
How the Kaseya VSA Zero Day Exploit Worked
(blog.truesec.com)
2 points
by
a1a
5y ago
|
0 comments
4.
▲
by
a1a
6y ago
I looked briefly at the encoder and it looks like the ad names are truncated on the size 32. Not sure why the threat actor would do that do. I guess they need some size limitation and just picked an arbitrary number
5.
▲
by
a1a
7y ago
Yes, if I interpret your suggestion correctly. How would you know that the attacker have not manipulated the size parameter? That's the best case. Worst case you end up with a memory vulernability (see heartbleed https://xkc
6.
▲
by
a1a
8y ago
Think there is a need for a clarification. It says _member states_ of EU have trackers on their websites. Not EU itself.
7.
▲
by
a1a
8y ago
1) Is that really a bad thing? Isn't it generally a good thing that law enforcement finds law-breakers? 2) So do drunk drivers that crash. 3) You're arguing against yourself. Yes, it's bad that bad guys get notified so they c
8.
▲
by
a1a
8y ago
Author here. Thanks for your comment. I think you have a valid point about users clicking anything. However I would only say that's the case if you send around 20 phishing mails. In a targeted attack you want to send one or two phishin
9.
▲
Open redirects – a vulnerability class no one but attackers cares about
(stevetabernacle.github.io)
154 points
by
a1a
8y ago
|
42 comments
10.
▲
by
a1a
8y ago
Firstly, it is not possible to opt out of facebook. [1] And they do indeed collect private data that we didn't choose to share (shadow accounts, third party website trackers, etc). Facebook have broken "actual laws". There a
11.
▲
by
a1a
9y ago
So that's why there is no gravity over there? Seriously though, the statement is ignorant at best. Please help me understand the point of posting it?
12.
▲
by
a1a
9y ago
and Bloomberg https://www.bloomberg.com/news/articles/2017-11-20/uber-step...
13.
▲
ProtonVPN: VPN developed by the ProtonMail team
(protonvpn.com)
2 points
by
a1a
9y ago
|
0 comments
14.
▲
White House says Trump to sign broadband privacy repeal
(reuters.com)
3 points
by
a1a
9y ago
|
0 comments
15.
▲
Hacking static hosting services
(stevetabernacle.github.io)
2 points
by
a1a
10y ago
|
0 comments
16.
▲
by
a1a
10y ago
I'd recommend deleting all content associated with the account and removing the address from any third party site (recovery etc). I would however never actually delete the account. My concern with deleting the account is that it expose
17.
▲
by
a1a
10y ago
Just had to test what the other keys did. What i found: t = search file j/k = move down/down (selected file) w = select branch s = focus search field y = expands url Anyone know any more? EDIT: Found this https://help.g
18.
▲
by
a1a
10y ago
That's one of the main takeaways from the story tho. In an open office those who need silence cannot get it, even if there are private rooms available: "Some of us even feel that escaping to a quiet room is a sign of weakness"
19.
▲
by
a1a
10y ago
Most definitely. In my experience ideas are rarely valuable by themselves. Rather an idea is valuable when implemented by someone who have what it takes to see it through. Simply put, not a lot of people have what it takes just because they
20.
▲
Automated i3wm setups for Kali Linux
(stevetabernacle.github.io)
1 points
by
a1a
10y ago
|
0 comments
21.
▲
Duck Hacking – for fun and profit
(stevetabernacle.github.io)
1 points
by
a1a
10y ago
|
0 comments
22.
▲
by
a1a
10y ago
How? I bet most commercial VPN services rotates on billions of different IPv6 addresses (from completely different subnets that is).
23.
▲
by
a1a
10y ago
Better keep your real laptop at a safe distance unless you want VM escape --> Bluetooth propagation --> pwned.
24.
▲
JS trickery for in-browser HTML templating
(stevetabernacle.github.io)
1 points
by
a1a
10y ago
|
0 comments
25.
▲
by
a1a
10y ago
Any reliable source? This is quite the accusation
26.
▲
by
a1a
10y ago
I don't think they are comparable. I run both. NoScript is a security suite – besides blocking java, webgl, flash, silverlight, javascript, etc – it has additional defenses against XSS, ABE, clickjacking etc. uBlock was to my knowledge
27.
▲
by
a1a
10y ago
"Any headline that ends in a question mark can be answered by the word no." https://en.wikipedia.org/wiki/Betteridge%27s_Law_of_Headline...
28.
▲
by
a1a
10y ago
To be fair, if it was a con 1/2) Hijack identity of someone reputable 3) Create scam device 4) Film a video that looks like a DEFCON speech. Some simple video editing should fix the face. Voice likely doesn't matter. Start speech
29.
▲
by
a1a
10y ago
Technically speaking they could target VPN users by infecting uploaded files with a simple trojan that pings home to a server, I assume you disable VPN after the download is complete.
30.
▲
by
a1a
10y ago
I really dig the login system! I thought it should be vulnerable to 1. find hash on victim's profile, 2. login using the hash + username But it seems the hash is never actually submitted to the server, neither through the login form
More ›