Do It by Code
54 subscribers
713 photos
99 videos
14 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
Randomness is extremely important for secure encryption. Each new key that a computer uses to encrypt data must be truly random, so that an attacker won't be able to figure out the key and decrypt the data. However, computers are designed to provide predictable, logical outputs based on a given input. They aren't designed to produce the random data needed for creating unpredictable encryption keys.

https://www.cloudflare.com/learning/ssl/lava-lamp-encryption/
WhatWeb identifies websites. Its goal is to answer the question, "What is that Website?". WhatWeb recognises web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1800 plugins, each to recognise something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more.

GitHub: https://github.com/urbanadventurer/whatweb
Live: https://www.whatweb.net/
Things we wish we didn't know.

https://immich.app/cursed-knowledge/

Long passwords are cursed:
The bcrypt implementation only uses the first 72 bytes of a string. Any characters after that are ignored.

JavaScript Data objects are cursed:
JavaScript date objects are 1 indexed for years and days, but 0 indexed for months.
Forwarded from Davide
those two are actually very cursed
the second one caused me serious problems once in a software I was paid for
Here's an opensource alternative of cursor i honestly think is gonna be a game changer since u can use ollama(locally hosted AI) to do ur AI shinanigans.

https://voideditor.com/

#opensource #alternative
This is a real response from Hetzner (shared by a user on Twitter)

Reddit Link
GitHub Notification Emails Hijacked to Send Malware

#Lumma

P.S: Lumma is one of many malware operations (read: gangs) that offer a "malware as a service" product. Their so-called "stealer" code searches through your system for cryptocurrency wallets, stored credentials, and other sensitive data. This data is then sent to their command-and-control (C2) servers where the gang can then move on to either stealing money from you, or profit from selling your data online.
Do It by Code
Photo
Step back for a moment and you'll recall that it's not the browser that is downloading this malicious exe, instead it's PowerShell - or, more specifically, it's the System.Net.WebClient class in .NET Framework.

This class has a method, DownloadFile which does exactly that - downloads a file to a local path, except this method does not set the MOTW (Mark of The Web) flag for the downloaded file.
Forwarded from Programmer Humor
[Meme] whenYouCantFindTheBugSoYouPrintEveryLine
https://redd.it/1fjwuwg

by @programmer_humor
Forwarded from woto-scp
woto-scp is updated

yt-dlp issue is now temporarily fixed; however, extra action is needed:
1. login to your server
2. do nano ~/yt-dlp.conf
3. put this line inside of it: --username oauth2 --password ''
4. save and close
5. try to run this command: yt-dlp https://www.youtube.com/watch?v=dQw4w9WgXcQ
6. you get prompted for oauth. do what they are told in the console.
7. if all goes well, you should be able to download it.
8. now cd to your woto-scp folder, do nano config.ini
9. if you have yt_cookies_file set, COMMENT IT
10. add these lines to the config, under the [woto-scp] section:
yt_dlp_username = oauth2
yt_dlp_password =

11. save and close. it should work now.

if it still ain't working, then it means your server's ip is blocked by youtube/google guys, rip (you can try to use a proxy or idk)
also make sure you have git pulled the latest commits as well (using .gitpull command in telegram, or git pull origin master in your terminal.
CVE-2024-46982: Next.js Cache Poisoning
High severity (8.7/10)

GitHub, NVD

By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.js to cache a route that is meant to not be cached and send a Cache-Control: s-maxage=1, stale-while-revalidate header which some upstream CDNs may cache as well.

Weaknesses:
CWE-349
CWE-639

Affected versions:
>= 13.5.1, < 13.5.7
>= 14.0.0, < 14.2.10

Patched versions:
13.5.7
14.2.10

References:
vercel/next.js@7ed7f12
vercel/next.js@bd164d5
Netlas
https://github.com/twitter/the-algorithm/issues

GitHub getting flooded by bots.
DO NOT click on any links / urls from these bots, they are all malware or phishing sites.
Geo-scale, next-generation peer-to-peer sharing platform built on top of OpenZiti.
Here's a cool ngrok alternative u can selfhost with pretty cool features.

https://zrok.io/
https://github.com/openziti/zrok

You can do tunneling, files and video sharing, and alot more.

#go #golang #opensource