HNHacker News
TopNewBestAskShowJobs

cottenio

190 karma · joined November 14, 2018

[ my public key: https://keybase.io/cottenio; my proof: https://keybase.io/cottenio/sigs/FHkhO8bJqBOvI8sFnWQKQdswBumbSC916lTBEsoYOEE ]
submissionscomments
cottenio··on A Very Sleepy MySQL Attack
Heh, one of the most common things I see when reviewing code is PDO users realizing they can't "bindValue" or "bindParam" an array of values coming into an IN() clause.

Here's a decent example of doing it right:

https://stackoverflow.com/questions/14767530/php-using-pdo-w...

Here's one showing noobs how to do it wrong:

http://pdo.w3clan.com/tutorial/176/like-clause-in-clause-and...

Look at that blind implode function. Argh. It's the danger of copy/paste echo-chambers.

cottenio··on A Very Sleepy MySQL Attack
This is a valuable point: you can absolutely exfiltrate data this way based on timing, and it's fairly automated with tools at this point.
cottenio··on A Very Sleepy MySQL Attack
Correct. It's more valuable, especially when trying to exfiltrate data or when trying to inject XSS opportunities.

Plus, realistically, SLEEP allows you to scan for thousands of different test cases in a quick period and measure the hang time to figure out which vector worked.

cottenio··on Ghost Emails: Hacking Gmail's UX to Hide the Sender
Note: this isn't the same set of bugs I previously reported; this one let's you blank out the sender completely in the UX for all views, and affects mobile as well.
cottenio··on Hacking Gmail’s UX with 'From' Fields – Another Phishing Vector
As @romed notes above, it looks like it is intended as a feature. One which I think sacrifices majority-security for minority-utility.
cottenio··on Hacking Gmail’s UX with 'From' Fields – Another Phishing Vector
I'm shocked this hasn't been resolved in mobile yet. I opened it up on my phone, and heck, with a pretty HTML form emulation in the email you could really have a very effective phishing campaign.
cottenio··on Hacking Gmail’s UX with 'From' Fields – Another Phishing Vector
I'm on board with this style of thinking. After reviewing the comments with the linked tagging behavior it's clear that Google is ignoring the spirit of RFC 2822 3.6.2-3.6.3 in order to shoe-horn in a feature of some possible utility, at the expense of the average customer's security.
← PreviousPage 2 of 2