HNHacker News
TopNewBestAskShowJobs

internetwache

156 karma · joined October 5, 2014

submissionscomments
internetwache··on Finding an arbitrary file upload vulnerability in a filesharing script
Hi,

thanks for commenting!

I had cronjobs in mind, but as you said, they are not writeable.

I also thought about uploading a .py file with an import's name, but wouldn't that require a __init__.py (in a subdirectory?) to be regarded as a valid module/import by python?

internetwache··on Show HN: Get encrypted data from people that don’t know how to encrypt
Not sure if I understood it correctly, but in essence it lets your users enter some (secret) content which is then encrypted in the browser using PGP.

Except for the message signing and auto-emailing, I've implemented something similar:

Blogpost: https://0day.work/easy-pgp-composer-encrypting-pgp-messages-...

GitHub: https://github.com/gehaxelt/PHP-Easy-PGP-Composer

Demo: http://pgpcomposer.demo.0day.work/

internetwache··on Hacking with LaTeX
The abbreviations are defined with the `\def` in the same code snippet. So that aren't typos, but a way to build latex commands like `\immediate` by breaking it up in multiple parts.
internetwache··on Scanning Alexa's Top 1M for AXFR
Yeah, you're right. We've updated the blogpost.

Thanks!

internetwache··on Scanning Alexa's Top 1M for AXFR
Hi,

that's another good point!

Thanks for bringing it up.

internetwache··on Scanning Alexa's Top 1M for AXFR
Hi, thanks for the feedback!

We thought about putting some "example fixes/configurations" into the blogpost, but then abandoned the idea, because there are a lot of different DNS servers out there.

Only covering a few didn't seem useful to us.

So thank you for giving an example configuration for BIND :)