Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jsploit
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
jsploit
6y ago
They were banned after "repeated warnings". It's possible that those warnings began before these market movements.
32.
▲
by
jsploit
6y ago
What differences are there between rysolv and bountysource?
33.
▲
by
jsploit
6y ago
> I'm guessing they bank on a small % of "whale" consumers using all their allowance and everyone else being way under the limit Reminded me of this story [0] of a team with a 500TB account serving as a database and VCS. [
34.
▲
by
jsploit
6y ago
Any metric is nonsense if used improperly.
35.
▲
by
jsploit
6y ago
CVSS being used as a basis for bounty payments is certainly evidence that it is taken seriously. Of course there are details that have to be factored in after that calculation, since CVSS is simplified for general usage. I'm not awar
36.
▲
by
jsploit
6y ago
The authenticated one-click social engineering aspect of this significantly lowers exploit probability and overall risk.
37.
▲
by
jsploit
6y ago
Sure, some of it is open to interpretation, but I disagree with it not being taken seriously. This is the basis for CVEs, most bounty tables, and most audit reports (that I've seen).
38.
▲
by
jsploit
6y ago
Do you disagree with the severity? I assess it to have a 6.5 (medium) CVSS score. https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L...
39.
▲
by
jsploit
6y ago
Last crawl on Internet Archive, which used to hit blogspot.in almost daily, was May 21. [0] Domain deletion processes vary per TLD. For .in it appears to be a 30 day grace period + 5 day hold period. [1] [0] https://web.archive.o
40.
▲
by
jsploit
6y ago
> The firm worked with a Facebook engineer and wrote a program that would attach an exploit taking advantage of a flaw in Tails’ video player to reveal the real IP address of the person viewing the video. Doesn't Tails route all tra
41.
▲
by
jsploit
7y ago
One of the reasons I've stayed away from Node is the ridiculous attack surface brought by the npm ecosystem. It seems that even the simplest of projects end up with hundreds of dependencies - most having different maintainers and secur
42.
▲
by
jsploit
7y ago
Direct PDF link: https://cdn2.hubspot.net/hubfs/1753393/guides/Cloud_Report_2...
43.
▲
by
jsploit
7y ago
No need for personal attacks.
44.
▲
by
jsploit
7y ago
I wonder if having a name so similar to RocketChat will be problematic for you. Currently, Google even suggests correcting searches for RocketChart to RocketChat.
45.
▲
by
jsploit
7y ago
I think you're deviating from the topic of protecting against the vulnerability HackerOne encountered: using a leaked session cookie. In their case, let's say the victim analyst was based in the United States, and they have implem
46.
▲
by
jsploit
7y ago
> Attackers usually don't know the country of the user Nothing a little recon or social engineering can't solve. > it's not as easy as it sounds to find a VPN or an open proxy in any country Only for some small/nic
47.
▲
by
jsploit
7y ago
I don't understand how it's anything beyond a minimal defense-in-depth measure. 1. Target leaks session cookie 2. Attacker uses VPN to connect from target's country with the leaked session cookie 3. Attacker's se
48.
▲
by
jsploit
7y ago
Locking sessions to countries doesn't offer any security benefit - an attacker can quite trivially connect from an IP in any target country.
49.
▲
by
jsploit
7y ago
Could Amazon really have that many internal projects? That doesn't seem right.
50.
▲
by
jsploit
7y ago
Google indexes plenty of other binary filetypes.
51.
▲
by
jsploit
7y ago
Separate infrastructure restricted to TS/SCI w/ poly.
52.
▲
by
jsploit
7y ago
Unfortunately the UX of that feature isn't great, so it's only useful in some cases. Often I find the screenshot method easier/faster.
53.
▲
by
jsploit
7y ago
Had no idea, thank you!
54.
▲
by
jsploit
7y ago
Taking screenshots and zooming in on those... a very tedious process.
55.
▲
by
jsploit
7y ago
> maximum-scale is an automatic usability and accessibility fail I wish more people realized this. As somebody that's visually impaired, it makes mobile browsing quite painful for me.