I can see this will be tolerant of simple renames, but seems unlikely this hash will survive any real refactor of code
279 karma · joined December 21, 2017
[ my public key: https://keybase.io/bradleyjkemp; my proof: https://keybase.io/bradleyjkemp/sigs/KwwyqILJIyQV_L29WmWq8humB4VZlXA8abkWbzBNNm0 ]
I can see this will be tolerant of simple renames, but seems unlikely this hash will survive any real refactor of code
The code in the repo just seems to be connection code ("provides a way for anybody to test our Redis synchronization service on demand") rather than the sync service itself
But yeah, I wouldn't even know where to report those API keys for abuse
Victims just click through the captcha without thinking, but it makes automatic verdicting by security scanners a pain because they just see a captcha page: can't tell the brand being impersonated, or even if it's a phishing site
I wrote a post about a number of these which actually pretend to be Cloudflare! https://phish.report/blog/fake-cloudflare-interstitials
> BM25F (or the BM25 model with Extension to Multiple Weighted Fields) is a modification of BM25 in which the document is considered to be composed from several fields (such as headlines, main text, anchor text) https://en.wikipedia.org/wiki/Okapi_BM25
Some papers are linked in the references
Nothing more interesting than copy-paste I'm afraid
It's not perfect but it means rather than getting connection errors, browsers will just spin for a couple seconds.
The same technique is used by https://mrsk.dev/
It was definitely available to purchase when I commented
edit: No longer! Hopefully someone benevolent picked it up
From my testing, it works even if the window is in the background somewhere but generally it stops working if you switch to a different tab within the same window.
You should get a popup though if you do something that causes the page to lose its Wake Lock (which works by listening to the release event: https://developer.mozilla.org/en-US/docs/Web/API/Screen_Wake...)
This has a CVE number allocated (CVE-2022-29072) and the README mentions 7-zip disputing that this is their problem (rather, some underlying Windows component).
For your example, the fraudster could say "yes, your account is being targeted by criminals, that's why I'm calling you". The warning inadvertently backs up their story
You'll never get 100% of people remembering that advice 100% of the time. So how do you mitigate the situation when they forget?
That's an incredibly cool and generous offer
Deployment: Docker Compose. It's great to just set a DOCKER_HOST environment variable and I can deploy to any server with Docker installed.
Backend: a Go service. Could be any language really but that's what I know. Just takes requests, does some business logic and returns HTML templates.
Frontend: I'm not a frontend dev so I try to avoid it as much as possible. For UI, I use Bulma (a pretty comprehensive bunch of CSS components), with a tiny sprinkling of vanilla JS for small client-side animations (e.g. burger menu toggles). For any user action that hits the backend, I use https://htmx.org/ and just return a small HTML snippet as the API response. No point using client-side JS for that (no latency gains and makes the tech stack less homogenous).
They've also done the correlation with User Agent and it's surprisingly accurate.
Original post by Salesforce security team: https://engineering.salesforce.com/tls-fingerprinting-with-j...
Rather than do this manually every time, I wrote a small CLI to automate the lookups and even open pre-templated emails: https://github.com/bradleyjkemp/abwhose
I'm now redoing this as a web app so that I can do the entire reporting process without leaving the browser: https://phish.report
Kinda fun trying to "speedrun" the process down to as few clicks as possible. And I'm pretty pleased with how fast I've gotten the process.
Now I'm looking to add some more account/user features e.g. a history of sites you've submitted. Perhaps some stats on how many times you've been the first to report a given site.
As well as reporting to SafeBrowsing, etc. for each site you also need to look up the domain registrar and hosting provider (via WHOIS) and email them.
Rather than do this manually every time, I wrote a small CLI to automate the lookups and even open pre-templated emails: https://github.com/bradleyjkemp/abwhose
I'm now redoing this as a web app so that I can do the entire reporting process without leaving the browser: https://phish.report
Kinda fun trying to "speedrun" the process down to as few clicks as possible.
Would something like https://github.com/Yelp/detect-secrets be interesting to include? Either as a filtering step to weed out false positives or to find even more secrets (i.e. that aren't near "password" or "secret")
Indeed, on fast connections the request to Plausible gets cancelled before it can be completed. I've updated my code to use that `setTimeout` trick.
`navigator.sendBeacon` support would be amazing! I really like how simple Plausible has been to set up (having never really used analytics before) so removing even more pitfalls/hurdles would be cool
OAuth + calendar plugins are definitely on the roadmap though because it's a much nicer UX than having to dig around in calendar sharing menus
I'm planning to have a little SQL client on the homepage you can use to query against demo data (maybe the public holidays calendars from Google?) but I didn't get around to it yet.
It's a bit of a fun challenge locking it down: purposely putting unauthenticated SQLi on your homepage isn't usually recommended!
I don't have any worries about managing long-term schema migrations though because the per-user databases get blown away and reconstructed every time the calendars are refreshed.
At the moment there's just an `events` table but I might handle migrations by having: `events_v1`, `events_v2`, etc. and just have `events` be an SQL view onto the version you chose.
Managing as little persistent state myself was a specific goal so this project is perfect because apart from some authentication info and a list of iCal URLs, the source of truth for your calendar is always with Google/Microsoft/etc.
Yes, at the moment there's a batch job to download your calendars and convert them into a SQLite DB. Then, all queries are done directly on that concrete DB (read only).
Originally I was using https://github.com/dolthub/go-mysql-server which is quite similar to the virtual table feature (you just provide a struct which implements some getter methods). Unfortunately I found it a bit slow though (it had to call back into my table many times for even simple queries). Might just be a problem with that implementation and not a limitation of virtual tables themselves so thanks for pointing it out!
This is one of the queries I'm using to track a rolling average of how many times a week I've been cycling: WITH recursive dates(day) AS ( SELECT date($__unixepochfrom(), 'unixepoch') UNION ALL SELECT date(day, '+1 DAY') FROM dates WHERE day<date($__unixepochto(), 'unixepoch') ) SELECT day AS time, ( SELECT count(DISTINCT julianday(start)) FROM events WHERE summary = " Cycling" AND start <= date(day, '+1 DAY') AND start > date(day, '-7 DAY')) AS cycling, FROM dates ORDER BY day DESC
And yeah 100% admit the documentation is lacking. I'll be honest, I got to the 3 week mark of building and decided I need to validate the idea before putting any more work in. Going to be adding some more pre-done queries like this as inspiration.
Because so much is already automatically tracked in my calendar (e.g. the HR system adds calendar events for booked holiday), I just needed a way to query it to get the metrics I wanted.
Originally I used a Go MySQL implementation to evaluate queries but it was a bit buggy and didn’t support all the SQL I wanted. Now I’m using a full SQLite database for each user so you can really do some gnarly queries (recursive CTEs, window functions, the works).
Personally, I’m using QueryCal as a Grafana datasource to power a dashboard that’s displayed on an old Kindle on my desk (using this great project: https://github.com/pascalw/kindle-dash).
Without requiring any client/server changes, grpc-dump transparently intercepts traffic on your machine and logs a JSON stream of all gRPC(-Web) requests that are made. This stream/dump is already useful for debugging but I’ve also started adding tools like grpc-fixture which uses this dump and responds to future client requests with the saved server responses from the dump.