178 karma · joined November 30, 2020
ibrahim@l-shinnawi.com
Move DNS to Cloudflare and put a few WAF rules on your site (managed challenge if bot score less than 2 / attack score == x). I doubt you'll even pay anything, and it will resolve a lot of your problems. Just test it before moving it to production please (maybe setup a test domain). Remember, a WAF is not an end-all be all, it's more of a band-aid. If you app isn't hardened to handle attacks, no amount of advanced WAF/bot protection will save it.
Message/email me if you need help.
First, he delayed immersion; among those who went into the water that night, Joughin was the absolute last to get wet.
Second — and most important — he managed to stay calm and strategize a way out of the water. """
I'll consider this next time I'm in a shipwreck.
I have my local sync'd to my cloud storage and just pull it down if/when I need it. I'll just email/text people around me if they don't have airdrop compatibility.
Source: I work in ecommerce.
Also reverse props to the meta bug bounty program manager for not understanding the finding initially. I know it's difficult managing a program but it's not an excuse to brush something like this off.
Do they have 0 fraud prevention? I doubt the attackers cycled IPs.
It's super lame that the company doesn't enforce 2FA.
https://home.treasury.gov/news/press-releases/jy1925
""" ...Binance willfully failed to report well over 100,000 suspicious transactions that it processed as a result of its deficient controls, including transactions involving terrorist organizations, ransomware, child sexual exploitation material, frauds, and scams.
Terrorist Financing. Binance failed to report to FinCEN transactions associated with terrorist groups including Al Qaeda, the Islamic State of Iraq and Syria (ISIS), Hamas’ Al-Qassam Brigades, and Palestinian Islamic Jihad (PIJ).
Ransomware. Despite being one of the largest receivers of ransomware proceeds, and transacting in millions of dollars of ransomware proceeds from attacks involving at least 24 different strains of ransomware, Binance failed to report these transactions.
Child Sexual Abuse Materials. Binance never reported transactions with websites devoted to selling child sexual abuse materials, including Dark Scandals.
Darknet Markets, Scams, and Other Illicit Activity. Despite sending and receiving virtual assets proceeds from large-scale hacks, account takeovers, and darknet markets dealing in illegal narcotics, counterfeit and fraud-related goods and services, as well as other illegal contraband, Binance never reported any such transactions. """
I ran the numbers and it saves me a few hours a week on average, so it really pays for itself. If you don't use it then it doesn't make sense.