HNHacker News
TopNewBestAskShowJobs

maxrmk

699 karma · joined December 5, 2018

submissionscomments
maxrmk··on Buying a single character domain – and 3 character FQDN – for £15
I tried to go one character smaller, by using the combined unicode character "⒕", in an attempt to eliminate the ".". I combined it with the "ms" TLD, which can also be represented a the single character. Unfortunately all the browsers I tested refuse to treat it as a domain name without a full stop, so I'm stuck using the three character http://xn--1rh.xn--ryk/ instead of the two character http://xn--6sh056c/ I was hoping for.

On the bright side, even the three character version is unlinkable on facebook -- it just redirects me to http://invalid.invalid/. I'll take that as a win. I still managed to get a pretty cool domain name for around $40, and it was definitely fun to mess around with this idea.

EDIT:

Interestingly, HN has automatically punycoded the URLs. That should be ⑭.㎳ and ⒕㎳

maxrmk··on Show HN: Aperio Fuzzer – A mutational fuzzer for testing web APIs
Hey HN! Long time lurker here.

Aperio is a black-box mutational fuzzer for finding vulnerabilities in web applications. You feed it network captures of normal usage, and it tries to break your app.

The core of the fuzzer is a genetic algorithm for finding new behaviors (inspired by AFL). It takes a new approach to fuzzing by building sequences of requests, instead of just fuzzing the inputs to single requests in isolation.

I'm super stoked about the project (and just fuzzing in general) so feel free to drop a comment here if you have any questions!

maxrmk··on Ask HN: What projects are you working on now?
Love the github-style activity tracker. It seems like such a small thing, but it's been a huge help in keeping myself in the habit of making regular progress.
maxrmk··on Ask HN: What projects are you working on now?
I've been building a web api fuzzer for the last couple of months, and this weekend has been a good opportunity to make some progress.

I built it because I'd been participating in a couple of bug bounty program and felt like I was just trying random mutations to see what broke things.

There are other web fuzzers out there, but they're super limited. They test each piece of API functionality in isolation, whereas my fuzzer can test sequences of calls that depend on each other.

I'm also trying to improve my drawing skills. It's a bit of a struggle, as it takes a lot more patience than most things I do on a daily basis.

maxrmk··on LiquidText: A tool for academical note taking
Looks really cool! I'm going to see if I can get into the beta, then give it a shot.
maxrmk··on Chrome deploys deep-linking in latest build despite privacy concerns
Just to clarify, I do think there are real privacy concerns with a naive implement of this feature. Allowing sites to search across origin boundaries would be a huge issue!

I just don't think that the DNS query issue mentioned in the article is the thing to be worried about. It's just so much less severe than the fact that DNS isn't encrypted, and requires essentially the same fix.

maxrmk··on Chrome deploys deep-linking in latest build despite privacy concerns
Yeah -- it's frustrating that the privacy concerns brought up in the article are just blantantly wrong. Especially because there a legitimately interesting issues in the security write-up [1].

On the other hand, I suspect they probably won't get the mitigations for those real issues right the first time. It's a complicated system they're building, and I think someone will find a clever way to break it.

[1] https://docs.google.com/document/u/0/d/1YHcl1-vE_ZnZ0kL2alme...

maxrmk··on Kaboom: an unusual Minesweeper
If you read through the rest of the article, that's actually the end result! Ambiguous squares are guaranteed not to be mines iff guessing is the only possible move.

On the flip side, the game punishes you for guessing by guaranteeing ambiguous squares result in a mine iff there there are moves you could make without guessing.

maxrmk··on Ghidra Capabilities – Get Your Free NSA Reverse Engineering Tool [pdf]
I would join in if something like this existed. I'm still a beginner though, so I wouldn't be able to provide a lot of guidance on how to use anything.
← PreviousPage 4 of 4