This was not a problem that was for sale
1,174 karma · joined June 17, 2011
This was not a problem that was for sale
An XSS is much harder to exploit quietly (the server can log everything), and can be closed immediately 100% with no long tail. At the push of an update the vulnerability is now worth zero. Someone paying to purchase an XSS is probably intending to use it once (with a large blast radius) and get as much as they can from it in the time until it is closed (hours? maybe days?)
Party A deposits 1 BTC into the exchange. Party B deposits $1000 into the exchange. Party A wants to sell a BTC for $1000 and party B wants to buy a BTC. They trade through the exchange, pay some fee to the exchange, and an entry in a database is changed such that the $1000 in the exchange now belongs to A and the 1BTC in the exchange's wallet now belongs to B.
Since actually holding cryptocurrency is inconvenient for users, many will just choose to keep the BTC on the exchange until they want to use it/sell it for cash or a different cryptocoin. Many crypto users are speculators who view it the same as holding stocks in brokerage accounts and not as just an exchange.
This money is held in the exchange platform but belongs to the users. They should in theory be able to withdraw it whenever they want.
Instead the crypto exchange decides to make use of these idle customer funds and invest in speculative funds/embezzle all the money and all of a sudden there is not enough funds in the exchange for all users to withdraw.
What you can do trivially is find 2 strings X1 and X2 such that md5(X1) == md5(X2). In this case seeding the way you described won't help because md5(X1+S) will equal md5(X2+S) due to the way MD5 works
1) Run tailscale --ssh on your server 2) A malicious SSO or tailscale add a new machine to your network and update your ACL such that the new machine can connect to your server 3) ssh from the new machine to run code on your server
The fact that the connection between the malicious machine and your server is double encrypted doesn't affect the attack here at all
Context for the uninitiated - as a crazy idea on the podcast Security Cryptography Whatever (hosted by tptacek and others less well known on HN) Avery and Brad of tailscale imagined an ssh client in the browser with QR code authentication to SSO to allow you to connect to your tailscale network (over tailscale SSH) from untrusted computers such as internet cafes. (Or mostly untrusted - safe from keyloggers but maybe not from a dedicated active malware that injects into your browser and tries to inject secret commands into your ssh session).
I created a silly PoC here (video instead of link because don't try it for real) https://twitter.com/jgeralnik/status/1487913797155233798 back when tailscale ssh was a secret binary in the tailscale github repo
To be clear I implicitly and explicitly trust tailscale not to tamper with my networks and if your threat model includes tailscale becoming a bad actor you should remember that in that case running their binary in the first place could already be game over.
https://github.com/cloudflare/cloudflared/issues/574
Cloudflare have ignored the github issue (which includes a solution) but at least 3 other people seem to have found my solution helpful.
You should still be blocking incoming requests for IPv6 endpoints and only open ports you intend to serve publicly.
Revealing so many digits of the factors actually allows easily factoring the original number using a version of coppersmith's method (easy as in under a second on my laptop instead of the 9 hours on a distributed cluster the authors used). This is actually a pretty classic CTF exercise.
If I'm still nerdsniped by this tomorrow I'll try my hand at implementing this and factoring the number myself
Here is a tool called Ragnarok that let's you edit values based on their name. You would open the reversed actionscript and could play with things based on the variable name:
Editing save files was big. The files were in a proprietary format called sol. All of the videos I see on that channel are just "download this save file with a completed game state", but there were tools for editing the save file yourself. Some games introduced obfuscation of data in the save file and the cat and mouse game began.
Oh, here's an example! Apparently the sol editor was a feature of Ragnarok, and maybe the disassembler too:
Here's a video of Niflheim, seems similar to Ragnarok. Maybe Ragnarok replaced it as a better tool?
Other than that it seems most of the cheats on that youtube channel are using cheat engine. While I definitely used that, I don't recall it being part of my go-to arsenal.