HNHacker News
TopNewBestAskShowJobs

bluetooth

514 karma · joined April 2, 2013

submissionscomments
bluetooth··on Liberty Reserve Founder Arrested, Site Shuttered
The central hub of script kiddies, Hackforums, recently moved to bitcoins as soon as word of the feds getting hold of LR went out.
bluetooth··on PayPal.com XSS Vulnerability
That is not what I am disputing. If there is a bug in paypal's search via POST only, you cannot link to paypal's search. You would need to link to a page you control that performs the POST automatically. If you send a link to the search that only takes parameters via POST, paypal will never receive the payload.
bluetooth··on PayPal.com XSS Vulnerability
> This link can be embedded on a different site, or sent via email, and because the link itself points to paypal.com - it is much more likely to be trusted by unsuspecting users.

Doesn't seem like that is the case here. The bug is in the search form, which is POST only. It wouldn't be enough to share the link to the search page, you'd need something that does the search on your behalf.

bluetooth··on PayPal.com XSS Vulnerability
MtGox, BTC-e, among other big bitcoin exchanges have been hacked before.
bluetooth··on PayPal.com XSS Vulnerability
Although the user has to place in the payload himself to exploit this vulnerability, there are a few ways the attacker can use this. The most obvious and simplest to do is to create a form that does the search for the user, and thus fills out the form for the user, exploiting this vulnerability. You could have the form submit automatically via javascript on page load, requiring no user interaction.

Once the form has been submitted on behalf of the user, you have javascript execution in the context of paypal.com, and can do pretty much anything. Send the contents of your account to another address, shut down the account, exfiltrate past transaction data, etc.

bluetooth··on Tarsnap – Online backups for the truly paranoid
Ah okay, thanks. Another question: Why wouldn't compression take care of that? Isn't the point of compression to compact as many repeating sequences as possible?
bluetooth··on Tarsnap – Online backups for the truly paranoid
Excuse my ignorance, but what does duplicated in this context mean? Multiple copies of the same file?
bluetooth··on Tim Cook tells Congress why Apple won’t move $100 billion back home
Guess conveying sarcasm over the internet is not one of my strengths. I suppose I meant more of a "your tax code allows this type of activity, yet you are still surprised it happens" type message.
bluetooth··on The fly-by, Wi-Fi hacking machine
I find it interesting they go over what's considered "insecure" yet completely left out whether any of these networks were WPS enabled, which is crucial when considering the security of a wireless network. Not even the pie-graph shows it.
bluetooth··on Tim Cook tells Congress why Apple won’t move $100 billion back home
The best part is that current tax code means Apple earning investment income through AOI is actually legal. Apple has paid their taxes and is playing by the rules - yet Levin is still upset.

Edit: I would appreciate it if someone told me what I said was incorrect or wrong in anyway.

bluetooth··on Unicode Character 'Slice of Pizza'
I find this unicode character more entertaining: 🏩

(It's a "love hotel", one character away from a regular hotel, 🏨)

bluetooth··on An eBook pricing model that resulted in $100,000 in sales
This is the same exact tactic employed by many of the e-book authors at Clickbank. You're basically forcing visitors into purchasing more than they originally wanted.
bluetooth··on Best Unsubscribe Ever
I wonder how likely someone is to watch that entire video after going through the effort of unsubscribing...
bluetooth··on Show HN: I built this (my first) Facebook application in 5 hours. Is that slow?
Why does it matter how long it took you to make your first application? And why do you care what others think about that?
bluetooth··on Anti-FB: I don't give a fuck
http://i.imgur.com/EwJjdcN.png
bluetooth··on [dead]
Please stop propagating these images. They're nothing more than speculation and could easily ruin the lives of these people.

http://www.boston.com/news/local/articles/2008/03/18/rush_ho...

Something from a few years back; I wouldn't be surprised if these photos end up causing even more trouble.

bluetooth··on Fuckyourcode.com
Oh look, another edgy developer thinks he's funny. At least it's a nice design.
bluetooth··on Own your own Bitcoin Exchange
Although this might not be the right way to do it, I think the goal of the project is to exemplify bitcoin's "distributedness" and minimize the reliance on a single exchange (ie MtGox).
bluetooth··on Security Notice: Linode Manager Password Reset
If a customer was hacked, why reset everyone's password? Unless there is something Linode is not telling us, there is no reason they should be doing this. Think about it like this: what if Google reset everyone's passwords whenever a gmail account got compromised? Ridiculous.
bluetooth··on Security Notice: Linode Manager Password Reset
What did I say wrong? I'm just stating my plans after hearing about another security blunder on Linode's part. Did what I say come off as sarcastic?
bluetooth··on Security Notice: Linode Manager Password Reset
But here, it's not a customer that was hacked. It was linode that was hacked, and used to access a specific customer's data.
bluetooth··on Security Notice: Linode Manager Password Reset
> It's good that Linode is taking security seriously

From what it seems, the only thing they take seriously is responding to incidents like these and letting customers know. If they were actually serious about security, these things wouldn't be happening. It was almost over a year ago since the last event.

bluetooth··on Security Notice: Linode Manager Password Reset
Welp, it looks like it's time to move to Amazon EC2. It's cheaper and hasn't (to my knowledge) been hacked yet.
bluetooth··on Don't Copy-Paste from Website to Terminal
Good point.
bluetooth··on Don't Copy-Paste from Website to Terminal
It won't work in this situation. Multiple commands here are separated by newlines (like pressing enter on your keyboard) and putting # will only comment out the first one.
bluetooth··on Don't Copy-Paste from Website to Terminal
This is really just an extension of clickjacking - modifying the UI to trick the user into performing an undesired action. This is a pretty novel idea, and considering how many websites make use of this to slap their permalinks into copied text (albeit with flash, usually), I'm surprised this hasn't been thought of before.

It would be an interesting experiment to sneak a harmless command after every snippet on a site like commandlinefu.com.

Edit: Also while playing around, I remembered irssi actually has a defense against this. If you try pasting multiple lines, it can detect this. It presents you with a prompt asking if you really intended to paste >5 lines into the text field. I wonder if something like this could be implemented in a shell?

bluetooth··on HTML5 Sandbox - a bad idea
Some of the new HTTP headers are just a mess. Did you know that X-Frame-Options' Allow-From option only allows you to whitelist one URL? Not a domain - a URL. The RFC actually expects you to communicate via another channel to determine whether or not a URL will be allowed to frame your page.

Luckily, this one is still a draft...

bluetooth··on HTML5 Sandbox - a bad idea
> For the same reason that we don't call out to JS to require HTTPS but rather use HSTS, XFO is right way to block CJ.

I think this is the best point in your argument. If you're going to half-assedly block framing (via JS, not using XFO), you will have problems. Either through sandboxed frames, or using XSSAuditor against it, it will break.

Besides this minor issue, there really is no other serious flaw with sandbox framing.

bluetooth··on HTML5 Sandbox - a bad idea
Ah okay, I didn't mean to belittle your work (I actually think it's quite great) I was just hoping you knew this wasn't exactly new material.
bluetooth··on HTML5 Sandbox - a bad idea
This is old news.

http://media.blackhat.com/bh-ad-11/Lundeen/bh-ad-11-Lundeen-...

These guys used html5 sandbox to break facebook's javascript frame breaker. Two years ago.

← PreviousPage 2 of 3Next →