Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
vasuki
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Hackers are spreading ransomware as a distraction – to hide their cyber spying
(zdnet.com)
2 points
by
vasuki
4y ago
|
0 comments
2.
▲
by
vasuki
4y ago
I can relate to that very much. Your former friend sounds exactly like one of my friends with whom I am trying to not end friendship and be as empathetic and helpful as I can be. > while at the same time those same sources get used easil
3.
▲
Psychological and Emotional War: Digital Transnational Repression in Canada
(citizenlab.ca)
2 points
by
vasuki
5y ago
|
0 comments
4.
▲
by
vasuki
5y ago
Do you have any go-to public tools for fact-checking or any internal tools that you might have had access to in the past? More generally speaking, how do you defend yourself against PsyOp in this age with heavily degraded trust in the gover
5.
▲
Dependabot Alternative for Clojure
(github.com)
2 points
by
vasuki
5y ago
|
0 comments
6.
▲
by
vasuki
5y ago
I have not responded without listening to what he said, I followed him for quite some time to see what exactly he had to say. I do not like censoring by big tech as well, but when they take down outright lies which actually get viral and ch
7.
▲
by
vasuki
5y ago
It is misinformation because it is outright wrong. Follow Malone for a couple of weeks and you will see he has nothing else to share but: Vaccines are bad, Vaccines are killing people. - https://www.politifact.com/article&#x
8.
▲
by
vasuki
5y ago
WHO: "As a matter of global equity, as long as many parts of the world are facing extreme vaccine shortages, countries that have achieved high vaccine coverage in their high-risk populations should prioritize global sharing of COVID-19
9.
▲
by
vasuki
5y ago
This is definitely not precise. I confirmed that the lookup is also performed by Proton servers for mails sent to third party mail services, not just from third party mail services. Are they also scanned? Source IP I got in my test: 185
10.
▲
by
vasuki
5y ago
It might be because of path normalization by your http client. For example, with `curl` you will also need to use `--path-as-is` to correctly test traversal. Another reason could be path normalization by the reverse proxy/WAF. >
11.
▲
List of Ransomware Vulnerabilities being actively targeted
(securitythreatnews.com)
1 points
by
vasuki
5y ago
|
0 comments
12.
▲
by
vasuki
5y ago
Thank you for the detailed writeup. This is a topic which I think is not discussed much. > We will split public-facing CI from release infrastructure and internal CI infrastructure. (teleport#8268) Did you also consider some form of out-
13.
▲
Using Monday.com's project manager as a command and control server
(github.com)
2 points
by
vasuki
5y ago
|
0 comments
14.
▲
Unauthenticated Gitlab SSRF Through CI Lint API
(vin01.github.io)
2 points
by
vasuki
5y ago
|
0 comments
15.
▲
by
vasuki
6y ago
Not that we have public evidence to prove whether it was a nation-state or not, but in my experience as a vulnerability researcher, finding high-impact flaws in popular tools (closed + open source) and government services is much more easie
16.
▲
by
vasuki
6y ago
Pursuing research in different fields (especially computational physics, bioinformatics) in personal capacity. I had once asked the same question to a scientist friend who actually wanted to switch back from research to engineering to find
17.
▲
by
vasuki
6y ago
> regularhours.net and holdmydoor.com appeared on a Turkish CERT list in November 2019 > we observed MONARCHY and SNEAKY KESTREL continue to use these domain names in attacks through August 2020. Interesting to see that the malicious
18.
▲
by
vasuki
6y ago
> I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword So this endpoint simply allowed setting up a new password with a POST request for the specified email add
19.
▲
Windows 10, iOS 14, Chrome, and many others fall at China's top hacking contest
(zdnet.com)
1 points
by
vasuki
6y ago
|
0 comments
20.
▲
by
vasuki
7y ago
I have been trying to reach out via the contact email provided on the website but never received a response. How may I disclose a security vulnerability related to simplepay.cloud ? Thanks!