Dolboeb-driven Development
727 subscribers
841 photos
134 videos
8 files
640 links
Мое личное ebanoe.it. Истории из первых (чаще всего кривых) рук.

Ваши примеры имплементации DDD => кидайте в чат

*все тексты в данном канале являются художественным вымыслом и не связаны с реальными людьми и компаниями, если не указано иное 😉
Download Telegram
Forwarded from mapgleos ✙ #УкрТґ
🔥11😁52
Forwarded from pakko’s place (раkkо)
💯111
Forwarded from vx-underground
Chat, today is a good day.

Look at this "Grand Theft Auto 6 BETA for FREE" advertisement that fell onto my lap. It delivers a .rar that has a .exe inside.

I am so happy. I am elated. It is free malware.
Forwarded from vx-underground
vx-underground
Chat, today is a good day. Look at this "Grand Theft Auto 6 BETA for FREE" advertisement that fell onto my lap. It delivers a .rar that has a .exe inside. I am so happy. I am elated. It is free malware.
Literally shaking, screaming, crying, THROWING UP.

The .exe is bundled with BUN (some Javascript bullshit). I deobfuscated the main goop inside of it, found the C2 configuration (where it downloads cool malware from), and ... it's dead.

Cloudflare KILLED THEIR C2. THE MALWARE IS DEAD. THEY KILLED THE MALWARE CAMPAIGN.

How are we supposed to get malware from fake Grand Theft Auto 6 advertisements if Cloudflare KILLS their infrastructure???

RIP NWHStealer campaign ID 202fdde5193b.
RIP NWHStealer c2 unauth-amper(.)cc
😁13🫡2
Подрубил к ИИшке скилл, она теперь использует маковскую say чтобы докладывать о прогрессе или проблемах, пока я чай пью) И не надо смотреть в монитор

Это охуенно
Forwarded from HN Best Comments
Re: Potential session/cache leakage between workspace instances or consumer accounts

This attack is called "HTTP desync" or "request smuggling". It's often done intentionally by a client to try and spy on other clients' responses.

Every time you multiplex requests from multiple clients onto one upstream connection, you are probably vulnerable to this, because (despite its superficial simplicity) HTTP is just too complex to reliably match the requests and responses to upstream.

For example a desync can be triggered in some systems by having more than one Content-Length header, by mixing Content-Length with chunked encoding, or by passing an HTTP/2 header called Content-Length that doesn't match the actual content length.

Here's a DEF CON talk (6 years ago) on this topic: https://www.youtube.com/watch?v=w-eJM2Pc0KI

The same attack has been applied to SMTP by messing up the line endings surrounding the end-of-message delimiter, where it's called SMTP smuggling. It may also apply to other protocols.

pocksuppet, 1 day ago
😁19🤡1
>Я тут подумав: міністр оборони в Україні це як викладач захисту від темних мистецтв в Хогварсті
😁10🥴1
this is where i post from
👀6😁41🤯1
Forwarded from mapgleos ✙ #УкрТґ
😱6😁1😭1