Do It by Code
54 subscribers
710 photos
99 videos
14 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
Do It by Code
Photo
Step back for a moment and you'll recall that it's not the browser that is downloading this malicious exe, instead it's PowerShell - or, more specifically, it's the System.Net.WebClient class in .NET Framework.

This class has a method, DownloadFile which does exactly that - downloads a file to a local path, except this method does not set the MOTW (Mark of The Web) flag for the downloaded file.
Forwarded from Programmer Humor
[Meme] whenYouCantFindTheBugSoYouPrintEveryLine
https://redd.it/1fjwuwg

by @programmer_humor
Forwarded from woto-scp
woto-scp is updated

yt-dlp issue is now temporarily fixed; however, extra action is needed:
1. login to your server
2. do nano ~/yt-dlp.conf
3. put this line inside of it: --username oauth2 --password ''
4. save and close
5. try to run this command: yt-dlp https://www.youtube.com/watch?v=dQw4w9WgXcQ
6. you get prompted for oauth. do what they are told in the console.
7. if all goes well, you should be able to download it.
8. now cd to your woto-scp folder, do nano config.ini
9. if you have yt_cookies_file set, COMMENT IT
10. add these lines to the config, under the [woto-scp] section:
yt_dlp_username = oauth2
yt_dlp_password =

11. save and close. it should work now.

if it still ain't working, then it means your server's ip is blocked by youtube/google guys, rip (you can try to use a proxy or idk)
also make sure you have git pulled the latest commits as well (using .gitpull command in telegram, or git pull origin master in your terminal.
CVE-2024-46982: Next.js Cache Poisoning
High severity (8.7/10)

GitHub, NVD

By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.js to cache a route that is meant to not be cached and send a Cache-Control: s-maxage=1, stale-while-revalidate header which some upstream CDNs may cache as well.

Weaknesses:
CWE-349
CWE-639

Affected versions:
>= 13.5.1, < 13.5.7
>= 14.0.0, < 14.2.10

Patched versions:
13.5.7
14.2.10

References:
vercel/next.js@7ed7f12
vercel/next.js@bd164d5
Netlas
https://github.com/twitter/the-algorithm/issues

GitHub getting flooded by bots.
DO NOT click on any links / urls from these bots, they are all malware or phishing sites.
Geo-scale, next-generation peer-to-peer sharing platform built on top of OpenZiti.
Here's a cool ngrok alternative u can selfhost with pretty cool features.

https://zrok.io/
https://github.com/openziti/zrok

You can do tunneling, files and video sharing, and alot more.

#go #golang #opensource
the jail system call.


The jail() system call sets up a jail and locks the current process in
it.

The argument is a pointer to a structure describing the prison:

       struct jail {
uint32_t version;
char *path;
char *hostname;
char *jailname;
unsigned int ip4s;
unsigned int ip6s;
struct in_addr *ip4;
struct in6_addr *ip6;
};
RestorerRobot was updated.
Changes:
- Upgraded dependencies to their latest version.

An entirely free and automated bot for taking backups from certain databases in an interval.
(For now, only Postgresql and physical folders/files are supported. if I get in mood, I might add support for other types of databases as well.)

#go #golang #auomation #backup #bot
#opensource
Browse all public vulnerabilities
https://huntr.com/bounties/hacktivity

bug bounty platform
:
https://huntr.com

huntr provides a single place for security researchers to submit vulnerabilities, to ensure the security and stability of AI/ML applications, including those powered by Open Source Software (OSS).
EDIT:
it's just CUPS
they hyped it too much
https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/


A 9.9 CVE has been announced for Linux 👀 RCE (Remote code execution). No details yet. Heartbleed was 7.5, for reference. This is one of the worst in history. All GNU/Linux systems impacted.
Telegram's reporting options have been extended with new categories, including "I don't like it”, “Terrorism”, “Copyright” & “It's not illegal, but it must be taken down”, offering more detailed reporting choices.

#Telegram #Beta
Write your code as if the one to maintain it is a psychopath with an axe who knows your address.
Can You Get Root with Only a Cigarette Lighter?
Article, Comments