Do It by Code
54 subscribers
710 photos
99 videos
14 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
Things we wish we didn't know.

https://immich.app/cursed-knowledge/

Long passwords are cursed:
The bcrypt implementation only uses the first 72 bytes of a string. Any characters after that are ignored.

JavaScript Data objects are cursed:
JavaScript date objects are 1 indexed for years and days, but 0 indexed for months.
Forwarded from Davide
those two are actually very cursed
the second one caused me serious problems once in a software I was paid for
Here's an opensource alternative of cursor i honestly think is gonna be a game changer since u can use ollama(locally hosted AI) to do ur AI shinanigans.

https://voideditor.com/

#opensource #alternative
This is a real response from Hetzner (shared by a user on Twitter)

Reddit Link
GitHub Notification Emails Hijacked to Send Malware

#Lumma

P.S: Lumma is one of many malware operations (read: gangs) that offer a "malware as a service" product. Their so-called "stealer" code searches through your system for cryptocurrency wallets, stored credentials, and other sensitive data. This data is then sent to their command-and-control (C2) servers where the gang can then move on to either stealing money from you, or profit from selling your data online.
Do It by Code
Photo
Step back for a moment and you'll recall that it's not the browser that is downloading this malicious exe, instead it's PowerShell - or, more specifically, it's the System.Net.WebClient class in .NET Framework.

This class has a method, DownloadFile which does exactly that - downloads a file to a local path, except this method does not set the MOTW (Mark of The Web) flag for the downloaded file.
Forwarded from Programmer Humor
[Meme] whenYouCantFindTheBugSoYouPrintEveryLine
https://redd.it/1fjwuwg

by @programmer_humor
Forwarded from woto-scp
woto-scp is updated

yt-dlp issue is now temporarily fixed; however, extra action is needed:
1. login to your server
2. do nano ~/yt-dlp.conf
3. put this line inside of it: --username oauth2 --password ''
4. save and close
5. try to run this command: yt-dlp https://www.youtube.com/watch?v=dQw4w9WgXcQ
6. you get prompted for oauth. do what they are told in the console.
7. if all goes well, you should be able to download it.
8. now cd to your woto-scp folder, do nano config.ini
9. if you have yt_cookies_file set, COMMENT IT
10. add these lines to the config, under the [woto-scp] section:
yt_dlp_username = oauth2
yt_dlp_password =

11. save and close. it should work now.

if it still ain't working, then it means your server's ip is blocked by youtube/google guys, rip (you can try to use a proxy or idk)
also make sure you have git pulled the latest commits as well (using .gitpull command in telegram, or git pull origin master in your terminal.
CVE-2024-46982: Next.js Cache Poisoning
High severity (8.7/10)

GitHub, NVD

By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.js to cache a route that is meant to not be cached and send a Cache-Control: s-maxage=1, stale-while-revalidate header which some upstream CDNs may cache as well.

Weaknesses:
CWE-349
CWE-639

Affected versions:
>= 13.5.1, < 13.5.7
>= 14.0.0, < 14.2.10

Patched versions:
13.5.7
14.2.10

References:
vercel/next.js@7ed7f12
vercel/next.js@bd164d5
Netlas
https://github.com/twitter/the-algorithm/issues

GitHub getting flooded by bots.
DO NOT click on any links / urls from these bots, they are all malware or phishing sites.
Geo-scale, next-generation peer-to-peer sharing platform built on top of OpenZiti.
Here's a cool ngrok alternative u can selfhost with pretty cool features.

https://zrok.io/
https://github.com/openziti/zrok

You can do tunneling, files and video sharing, and alot more.

#go #golang #opensource
the jail system call.


The jail() system call sets up a jail and locks the current process in
it.

The argument is a pointer to a structure describing the prison:

       struct jail {
uint32_t version;
char *path;
char *hostname;
char *jailname;
unsigned int ip4s;
unsigned int ip6s;
struct in_addr *ip4;
struct in6_addr *ip6;
};
RestorerRobot was updated.
Changes:
- Upgraded dependencies to their latest version.

An entirely free and automated bot for taking backups from certain databases in an interval.
(For now, only Postgresql and physical folders/files are supported. if I get in mood, I might add support for other types of databases as well.)

#go #golang #auomation #backup #bot
#opensource