Do It by Code
54 subscribers
710 photos
99 videos
14 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
Do It by Code
Malicious VSCode extensions with installs discovered Article, Comments
all it takes to open a reverse shell to someone's computer with a vscode extension.....
Forwarded from Programmer Humor
[Other] whyIsntMyCodeWorking
https://redd.it/1dd84ih

by @programmer_humor
Backdoor in D-Link routers enables telnet access
Article, Comments
Luma Labs, an AI company, has unveiled DreamMachine, which allows users to move any image or graphics, generating prompt videos.

https://lumalabs.ai/dream-machine

#AI
Forwarded from vx-underground
People are paying thousands of dollars for educational courses on initial access vectors. We'll provide you a step-by-step guide on how to get initial access to companies with a budget of $0. All it requires is some time, effort, and the ability to grep

1. Go to Telegram
2. Get free stealer logs
3. Look for VPN creds
4. Hope no MFA
4.a If MFA, spam requests
4.b If fails, go back to Step 1.
5. Log into VPN
6. Go to Jira / Kanban board
7. Scrape everything when people are sleeping
8. Log out
9. ???
10. Profit!!!11

Congratulations, you're now the most dangerous hacker on the planet

Does this sound absurd? Of course it does. Does it work? Yes, literally every single day. Infostealers are a giant problem. They don't need to target enterprise environments with top-notch security – they only need to target lazy home users, with security settings probably disabled, downloading junk binaries.
Microsoft moment:

(yes, they fixed it now)
GitHub – Karpathy/LLM101n: LLM101n: Let's Build a Storyteller

this is still empty btw
so yeah, dont get your hopes high
idk why it got trended so much in hn, but anyway

Article, Comments
Do It by Code
I'm Switching from Laravel to Rails Article, Comments
Just search for sites using Livewire JS file on the internet, create accounts on those sites, and you will likely find many that allow you to access other users' resources by changing parameters in URL.
👍1
OWASP Top 10 Web App Security Risks.