Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dsekz
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
1.
▲
How I Broke the Anti-Bot Behind Nike, Kick, and Twitch
(emro.cat)
5 points
by
dsekz
5mo ago
|
0 comments
2.
▲
Chrome's hidden X-Browser-Validation header reverse engineered
(github.com)
3 points
by
dsekz
1y ago
|
0 comments
3.
▲
Chrome's hidden X-Browser-Validation header reverse engineered
(github.com)
380 points
by
dsekz
1y ago
|
129 comments
4.
▲
by
dsekz
1y ago
Dug into chrome.dll and figured out how the x-browser-validation header is generated. Full write up and PoC code here: https://github.com/dsekz/chrome-x-browser-validation-header Why do you think Chrome bothers with th
5.
▲
by
dsekz
1y ago
Plenty of improvements to mouse movement algorithms have already been made and they’re still evolving. While the blog post and the product it introduces offer some interesting ideas, they don’t yet reach the robustness of modern anti-bot so
6.
▲
by
dsekz
1y ago
You can look at my previous answer: > To clarify, If I disclose the exploit publicly, my concern is that the company could take legal action against me, even if I don’t share any technical details or information that would allow someone
7.
▲
by
dsekz
1y ago
To clarify, If I disclose the exploit publicly, my concern is that the company could take legal action against me, even if I don’t share any technical details or information that would allow someone to reproduce it. – Something I really don
8.
▲
Ask HN: A $1.5B company ignores a critical RCE for 9 months?
6 points
by
dsekz
1y ago
|
5 comments
9.
▲
by
dsekz
1y ago
In its current state, the protections are pretty weak. I’m sure they’ll update it, and we’ll see what changes they bring. If this header is meant to serve as an anti-bot measure, then there’s a lot more work they need to do both on the JS a
10.
▲
by
dsekz
1y ago
You’re right. In this case, just knowing the guest_id is enough to break down the header. Twitter’s main goal here is mostly to obfuscate the data and make the reverse engineering process more painful.
11.
▲
Reverse engineering Twitter's new WASM-based "X-XP-Forwarded-For" antibot header
17 points
by
dsekz
1y ago
|
4 comments