It did give me a battery boost though, so at least there's that.
184 karma · joined October 5, 2016
It did give me a battery boost though, so at least there's that.
I rather use Cyberchef, it’s open source, runs locally (browser client-side) and supports a gazillion encoding/decoding/hashing options.
But I do want to point out to people that https://github.com/domainaware/checkdmarc exists for quite a while. I use it often and have also integrated it in various automated tooling.
(It also does not require handing out email addresses to strangers.)
> The attacker could exploit this vulnerability by sending a specially crafted email which triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane.
> External attackers could send specially crafted emails that will cause a connection from the victim to an external UNC location of attackers' control. This will leak the Net-NTLMv2 hash of the victim to the attacker who can then relay this to another service and authenticate as the victim.
Microsoft has released a script to check for abuse: https://microsoft.github.io/CSS-Exchange/Security/CVE-2023-2...
While there are many other great web security-oriented blogs, what are your favorites? I want to expand my (preferably RSS) feeds.
The second ‘attempt’/flow allowed me to enter my IBAN. I will change my original comment to reflect that.
It directly presented me with the info that if I were to couple the account, Paypal will have 90 days of access to my balance and all my transactions. How about no.
Luckily there was a link on the bottom “link it in a different way”, when following this path (By manually entering my IBAN*) Paypal only stated I could then “easily transfer funds back and forth”. Sounded good, until my bank app opened again and stated that if I was pressing the ‘accept’ button, you guessed it, Paypal will have 90 days of access to my balance and all my transactions. This time I pressed ‘cancel’ and thought “I’ll just buy something random and donate the last Paypal cent I own to some random charity”. Got an error message after pressing ‘cancel’ in my bank app, but curiosity got the best of me, I refreshed the Bank Accounts page and there it was, my bank account number. I was able to transfer to it without coupling after all.
Once the funds are on my bank account I will avoid and evangelise avoiding Paypal.
Here's what it looks like: https://imgur.com/a/BkzEoGV
Edit: Restarting Slack does update the edited messages.
Edit 15:24 CET: Slack is back up.
If they’d build preview versions of all tools that Windows (11) contains, then release a new Windows 11 preview build any time a tool receives updates (after community feedback) and ask for more community feedback on all of these releases (probably talking a new Windows 11 version every single day) and release Windows only when all the tools and their changes have been deemed worthy/bug-free it will be 2029.
Without this cycle we would have never gotten out of the Stone Age.
Satoshi Nakamoto has great dreams, but basic human greed has struck again.
"Have Fun Staying Poor" is in my opinion a disgusting remark to make to complete strangers.
If this action can be performed using the hardware button it is likely that it can also be performed software-wise, it would be a nice addition for malicious software such as malware.
- I can inject any JavaScript in Titles, Tags and possibly other locations.
- By manually changing the value of the `userid` cookie, I can log in as any user ("1" for admin). This also allows me to access the admin section of the website.
- It's highly recommended to enable "HttpOnly" for session cookies. (Secure and SameSite should also be more strict if the application allows it)
Other remarks:
- There should be a limit on the length of submission titles, these are close to infinite it seems.
Edit: It seems others are completely defacing the board by using these tricks. I just want you to know that it's not me.