Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gwillem
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
OptinMonster supply chain attack hits 1.2M WordPress sites
(sansec.io)
2 points
by
gwillem
3mo ago
|
0 comments
2.
▲
by
gwillem
7mo ago
However, you pay 2.7% for that convenience
3.
▲
Claude finds 353 zero-days on Packagist
(sansec.io)
5 points
by
gwillem
8mo ago
|
1 comments
4.
▲
The billion-dollar security.txt problem
(sansec.io)
5 points
by
gwillem
8mo ago
|
1 comments
5.
▲
by
gwillem
1y ago
I built this for fun and my own notifications. I don't think there's much commercial value here since there's zero moat. But it would be nice if we could raise funds for Signal.
6.
▲
by
gwillem
1y ago
The bot has access to any sent messages to yourself, plus any chatter in group chats if you have enabled that. So don't use it for sensitive stuff, and use a dedicated group. It was developed to relay sensor data and such, not war plan
7.
▲
by
gwillem
1y ago
Contact me via the support link?
8.
▲
by
gwillem
1y ago
The URL that botmaster gave you is a page that lists your API endpoints (multiple if you have invited the bot to any group chats)
9.
▲
by
gwillem
1y ago
Messaging is internally rate limited and capped per recipient. And it uses a sender pool.
10.
▲
by
gwillem
2y ago
Some encodings add a prefix, which then get sanitised by the liberal base64_decode. https://www.synacktiv.com/en/publications/php-filters-chain-...
11.
▲
Hackers plant card-stealing malware on website that sells baron and duke titles
(therecord.media)
1 points
by
gwillem
5y ago
|
0 comments
12.
▲
LinkedIn breaks because of too many tracking cookies
(twitter.com)
46 points
by
gwillem
5y ago
|
14 comments
13.
▲
Iconic Bugtraq mailinglist now used for spam
(bugtraq.securityfocus.com)
2 points
by
gwillem
5y ago
|
0 comments
14.
▲
by
gwillem
9y ago
Thanks! Indeed a copy paste error, I updated the article.
15.
▲
Akamai blocks unordered HTTP request headers
(gwillem.gitlab.io)
43 points
by
gwillem
9y ago
|
11 comments
16.
▲
by
gwillem
10y ago
Gitlab CEO just called me and apologized, will restore data shortly. I am personally very sorry that GL got in a bad light here. They had misinterpreted my data and have acknowledged that. For comparison, I have heard nothing from GH over t
17.
▲
by
gwillem
10y ago
GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure
18.
▲
by
gwillem
10y ago
Github booted my data last night, not sure why. I've moved over to Gitlab.
19.
▲
Senate Republicans were skimmed for six months, quietly fix store
(gwillem.github.io)
5 points
by
gwillem
10y ago
|
0 comments
20.
▲
Credit card theft in the browser unnoticed for 6 months
(byte.nl)
2 points
by
gwillem
11y ago
|
0 comments
21.
▲
by
gwillem
11y ago
Which illustrates the risk of running "universe" packages.
22.
▲
Proftpd critical security leak hasn't been fixed on Ubuntu since May
(bugs.launchpad.net)
1 points
by
gwillem
11y ago
|
1 comments
23.
▲
Denmark is fastest fixer of critical security bug
(shoplift.byte.nl)
1 points
by
gwillem
11y ago
|
0 comments
24.
▲
by
gwillem
11y ago
Vuln tester @ https://shoplift.byte.nl I just did a global scan: still 100K shops are still unpatched today. According to builtwith.com, that's about 45% of the install base.
25.
▲
Analyzing the Magento vulnerability
(blog.checkpoint.com)
6 points
by
gwillem
11y ago
|
0 comments
26.
▲
Tester for critical Magento Shoplift bug
(shoplift.byte.nl)
10 points
by
gwillem
11y ago
|
0 comments
27.
▲
by
gwillem
12y ago
This is quite stealthy way to scan, as Accept headers are generally not logged: curl -H 'Accept: () { :;}; /usr/bin/curl -so /dev/null http://my.pingback.com' Found nothing so far thoug
28.
▲
Ask HN: How do I increase my SaaS specs without losing business?
2 points
by
gwillem
12y ago
|
0 comments
29.
▲
Ask HN: Physical status indicators in your office
1 points
by
gwillem
12y ago
|
0 comments
30.
▲
by
gwillem
13y ago
So Ansible has the disadvantage of unclear, implicit dependencies. The undeterministic declarative system (Puppet) has the disadvantage of unclear, missing dependencies. I would prefer a deterministic system, so that I can validate the outp
More ›