Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
thricegr8
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Ruby on Rails Cross-Site Request Forgery
(seclists.org)
5 points
by
thricegr8
1y ago
|
0 comments
2.
▲
by
thricegr8
2y ago
Wow thought I was the only one my entire life. I can give lots of very weird and specific examples, but yes; N=2.
3.
▲
Zone Dumping via DNSSEC
(harrisonm.com)
5 points
by
thricegr8
2y ago
|
3 comments
4.
▲
Detecting Cross-Origin Authentication Credential Stuffing Attacks
(sec.okta.com)
1 points
by
thricegr8
2y ago
|
0 comments
5.
▲
by
thricegr8
2y ago
This is an awesome tool and something I've been trying to do for too long. I've been trying to find ways of "quasi-replicating" SPA's like this and then doing analysis on them. Can you talk a little bit about your a
6.
▲
by
thricegr8
3y ago
I know this seems the antithesis, but I've always wondered if you could fold and mangle cURL to actually act as a web server?
7.
▲
Ask HN: Reality is a simulation, what's the biggest indicator we missed?
1 points
by
thricegr8
3y ago
|
1 comments
8.
▲
by
thricegr8
3y ago
Can you expound on this?
9.
▲
by
thricegr8
4y ago
Cross-posting /r/bestof ( https://www.reddit.com/r/worldnews/comments/113casc/scientis... ) because it really does a nice job with history and breaking down the highlights (to me at least:) -----
10.
▲
Fearless CORS: Philosophy for CORS middleware libraries and a Go implementation
(jub0bs.com)
3 points
by
thricegr8
4y ago
|
2 comments
11.
▲
by
thricegr8
4y ago
Some of the best, most elucidating insights into CORS I've read.
12.
▲
by
thricegr8
4y ago
Looking more closely you are right, my apologies. Thank you so much. Have not seen this video before but it does cover what I'm after. Thanks again!
13.
▲
by
thricegr8
4y ago
Yes! You're right. Here is what I was after: https://www.youtube.com/watch?v=DlrHNKatHMc Thanks much!
14.
▲
by
thricegr8
4y ago
Unfortunately no dice. It's a more recent video, maybe 5-7 years old. Modern stage.
15.
▲
Ask HN: I'm looking for a hacking talk that discussed USGOV logos and satellites
2 points
by
thricegr8
4y ago
|
6 comments
16.
▲
Bvp47 – New NSA Implant Using BPF to Hide Network Traffic [pdf]
(pangulab.cn)
3 points
by
thricegr8
4y ago
|
0 comments
17.
▲
by
thricegr8
4y ago
I was wrong on this. See my comment above. I thought inspecting the certificate would be enough to tell you? I don't see the blob in any cert details. Where did I error?
18.
▲
by
thricegr8
4y ago
Ah yes, perhaps a bit more due diligence was required. Can someone help me out then here? I checked the domain here: https://phonebook.cz/ , but manually inspecting the certificate, I don't see the * in front of okta.co
19.
▲
by
thricegr8
4y ago
What's really concerning is if this turns out to be true, Okta has, at a minimum 26k (yes), customers right now. A simple enumeration of subdomains reveals this. I've put them here in a paste: https://ghostbin.com
20.
▲
Revisiting Phishing Simulations
(posts.specterops.io)
2 points
by
thricegr8
5y ago
|
0 comments
21.
▲
by
thricegr8
5y ago
I bought a few shares in May of 2021 so I'm feeling it a bit. May also just buy the dip :)
22.
▲
Ask HN: Where can I find a list of startups hiring that offer stock options?
1 points
by
thricegr8
5y ago
|
0 comments
23.
▲
Bug Alert: Rapid security notifications on high-impact and 0-day vulnerabilities
(bugalert.org)
1 points
by
thricegr8
5y ago
|
0 comments
24.
▲
by
thricegr8
5y ago
Ya know, you're right. I guess I assumed the OP meant more along the lines of "What was your favorite podcast episode you listened to this year" vs the more literal translation. I'll throw in an edit to clarify.
25.
▲
by
thricegr8
5y ago
Undoubtedly that personal award goes to Citations Needed Episode 73: Western Media’s Narrow, Colonial Definition of ‘Corruption’. You can read the transcript on Medium [1] or listen on Spotify [2]. It may seem a bit bromide for HN, but it r
26.
▲
by
thricegr8
5y ago
I agree so very much with not only your framing, but that of the original tweet(s) and the distillation formed by my own experience. I'm proximate to development (information security/penetration tester). After university, my jour
27.
▲
So you're a mediocre developer? Now what?
(twitter.com)
10 points
by
thricegr8
5y ago
|
6 comments
28.
▲
Never trust a programmer who says they know C++
(lbrandy.com)
3 points
by
thricegr8
5y ago
|
1 comments
29.
▲
by
thricegr8
5y ago
Human, I'm 28, been in InfoSec for ~10 years. Granted, I was lucky enough to be interested in and peruse this as a professional branch when I graduated college in 2016. I am also an adjunct professor at my local university, where I mak
30.
▲
by
thricegr8
5y ago
Woah - can you expand on this a bit? I don't have a system to test atm, but I'm curious how that works. Are you sure privileges/security boundaries are circumvented?
More ›