HNHacker News
TopNewBestAskShowJobs

pizzeys

169 karma · joined February 3, 2013

submissionscomments
pizzeys··on Shopify, pulling strings at Ruby Central, forces Bundler and RubyGems takeover
'Download Github and look at the code'?
pizzeys··on Company named "><SCRIPT SRC=HTTPS://MJT.XSS.HT> LTD" forced to change it (2020)
The funniest thing about this (they also did this to my company) is that the name masking applies absolutely everywhere. So, for example, if they send you important mail about needing to take some regulatory action, the mail arrives addressed to 'NAME AVAILABLE ON REQUEST FROM COMPANIES HOUSE]' on the outside of the envelope, and inside it has a letter with a bunch of warnings about whatever is going to happen to the company, except it doesn't tell you the name of the company.
pizzeys··on A real case of Bobby Tables?
(Person who registered the company above here)

I suspect the actual reason for it coming up in law was because of the XSS company somebody registered some time after my meme went around. That one actually did work*, and as I understand it, there was no recourse available to companies house - they are legally obliged to accurately record company names, and the law specifies which characters can be in company names, meaning you could always serve XSS there, which they're not a fan of.

That said, they forced my company name to show as 'name available on request' now (even on letters they send me, which is kind of funny), so apparently they did find a workaround.

* On third party systems consuming the data*

pizzeys··on A real case of Bobby Tables?
for my next trick, i shall use brainfuck instead
pizzeys··on Drop Table “Companies”;– LTD (2016)
No comment
pizzeys··on Drop Table “Companies”;– LTD (2016)
I didn't know this, and have made the same snarky joke in dumb interviews about the company registration etc. - that's very cool and I will eat my words.
pizzeys··on Why is there a voltage on my HDMI and coaxial cables?
Wait until you're using it on your chest in bed and accidentally poke your lips with the corner! It's a surprisingly good zap for an allowed amount of stray

Not that I've ever done that

pizzeys··on Open RuneScape Classic
Yep, I used the nick 'Mopman' then, if you remember that name at all. Kind of appropriately for the name, I was mostly a janitor :D Admin @ Moparscape and the public Aryan channels, there's a few commits of mine in the bot but I definitely can't take credit for most of the bot itself, that was other peoples work. I did make few releases of it after the banwave incident you mention, though quickly passed that torch on (it was a lot of hassle, tbh).

Professionally nowadays I'm a pen tester/security consultant.

pizzeys··on Open RuneScape Classic
Interesting to see this story here, I didn't know enough of that info was public to even end up here. (You have to be someone I know/know of, right?)

Basically true, though:

- Aryan wasn't the first clientmod, not even the first to deob - probably the first to go fairly 'mainstream' and end up being well known outside the circle of people using it, though (being free probably helped here)

- No legal action, tbh. Well, the same amount of legal action that all of the cheating scene got (some C&D's, domain takedown attempt type stuff at various times, but not the scary kind of legal action in the way other bots got)

- The banwave backdoor did happen, and basically as you say (iirc it was the actual UID but negative, rather than -1) but was more of a conscious decision, there wasn't an 'agreement' beforehand - it was proactively taken. Jagex were informed about it in order to detect it though, as far as I'm aware.

pizzeys··on FireEye Shares Details of Recent Cyber Attack
Or no exploits at all, ie. post exploitation frameworks, control channels etc. only.

EDIT: Nevermind they added something to the countermeasures repo that goes against that.

pizzeys··on Drop Table Companies Ltd
Try making it an XSS payload - that one often works ;)
pizzeys··on Drop Table Companies Ltd
Haha! Yes, that reaction happens a lot - a friend tried to discourage me from doing it actually for that reason, but I told him I'd just rename it if it became burdensome. So far it has only been a little bit burdensome.

Bank account was actually incredibly easy, that is the one I expected to be difficult, too. I had no problems at all, I made an account with the usual process. Should note I'm using one of those new-fangled 'challenger banks' so they're probably quite tech savvy/their systems aren't 50 years old, that probably helped.

The worst one has been the domain name, oddly. I wanted to get the .ltd.uk domain name (only available to registered companies in the UK) to basically complete/highlight the joke. But, I have been waiting for over a year or something now for it to actually be registered, it keeps being rejected by the registrar (there is a weird validation process to make sure you're a real company, etc). I could have sped it up by trying with a better registrar who are more aggressive at getting things done, probably, I had a few offers from smaller registrars - but I just went for the .co.uk in the end instead.

pizzeys··on Drop Table Companies Ltd
It was online so no 'looks' but I did end up having a very odd phone call at one point.
pizzeys··on Drop Table Companies Ltd
Nah - brokenness is intentional. I'm sure Companies House application is secure, but I don't know if all the applications scraping it/using its feeds are, so I couldn't be /too/ real.
pizzeys··on Drop Table Companies Ltd
:)

Not that risky though - it looks more like an SQL injection than it actually is. I actually didn't think it would get this much attention - I went to bed!

pizzeys··on Quassel IRC: cross-platform, distributed IRC client
Weechat, the terminal based client, also supports a protocol like this. There aren't really any nice graphical clients for it, but there is a mobile one which is very usable, and there's an HTML5-y one, but I haven't tried that.

If you like irssi, but wish you had a better way to use it on mobile, you might like Weechat - that's how I use it currently, terminal over SSH on desktops, mobile client over the relay protocol on the go.

pizzeys··on Show HN: Encrypt and Destroy – Send dead simple encrypted messages on the web
This is, I assume, a social experiment in seeing whether people will use encryption products they should stay well away from? :)
pizzeys··on 'RuneScape' Can't Escape 2007
Absolutely agree with the sentiment but it should be illegal to call powerbot rs buddy etc the golden days :D the golden days were before the profiteering age...
pizzeys··on E-Cigarettes, as Used, Aren’t Helping Smokers Quit, Study Shows
Personal experience/anecdote alert.

I found that it took a few 'goes' at the vaping thing before I properly 'got it'. I enjoyed and saw the benefits of the vape from the first time I used it, but went through a few cycles of vaping-and-the-odd smoke, then a few weeks of only vaping, then back again, and almost gave up on the whole thing. Then for some reason last February, it clicked and I ditched the smokes completely. Not had one since then. No interest in smoking again, ever.

I've described it to friends and family as being a bit like I imagine methadone is to junkies, though no personal experience there. It doesn't initially fill all the holes in quite the right ways (for me anyway, some love it immediately but I suspect those are the 'odd ones out') but is 'good enough' that it can work - it does however take a little effort to make work, it's not a magic silver bullet.

It certainly was a lot more effective than any time I've tried to stop smoking using anything else, though.

pizzeys··on Why isn't HTTPS everywhere yet?
Shared webhost here: It's one of those complicated part-technical, part-user education issues.

Technical: SNI breaks older browsers (IE on XP, older mobiles). Also requires a modern (ish) OS on the server, if using CPanel, which like, every shared host in the world is pretty much.

User Education: Explaining exactly which clients will be broken is hard, etc.

#2 is basically gone now, because the users who would be broken are broken by the removal of SSLv3 and insecure crypto anyway - so we've now already killed them and can SNI without having to explain anything complicated to the user.

pizzeys··on Linode is suffering on-going DDoS attacks
Yes. We moved an IRC server that was under attack (and being dropped from DO/Linode) there, and it ate it fantastically well for the price. I've never seen anyone else do it that well for that cheap, to be honest.
pizzeys··on More people use Ubuntu than anyone actually knows
I don't think that's a good reason to choose CentOS over Ubuntu really, since Ubuntu can be installed sans UI overhead and Centos can be installed with UI overhead.
pizzeys··on Ask HN: What is a way of making residual income with $5K a month?
My favourite Branson quote, though it may well have been an old adage he repeated, of course.

"If you want to be a Millionaire, start with a billion dollars and launch a new airline."

pizzeys··on English has been my pain for 15 years (2013)
Watching? Reading it is even worse! :D (UK here not American, though.)
pizzeys··on English has been my pain for 15 years (2013)
I think this fact (and he's obviously not wrong, though I don't know if I'd label it a secret - everyone knows this about English, I thought?) is inevitable from any language which gains the reach English did, or at least, gained the reach English did at the time English did... whether it would be different now we have global communication all the time remains to be seen I suppose.

How do you have a language spoken by so many wildly different people, who bring in their own vocabulary with each generation, and not end up with irregularity in spelling and pronunciation?

English is a mongrel, certainly, but that is a product of it being so widely 'deployed', not an inherent feature of the language. Sure, Italian is regular. Italian also doesn't have germanic roots all over the place mixed in with the latin and chinese and whatever else.

pizzeys··on Non-photo blue
Apparently you remember a different 2005 to me!
pizzeys··on WordPress now runs a quarter of the web
I'd say it's actually the opposite - the users are comfortable with PHP and not the more complex solutions. I'd love for us to support other stuff, but anyone who is using anything else wants more control over their environment than the average shared host can offer. We have as many deployment issues etc. with PHP as we would anything else... possibly more.

That said, isn't 'IaaS' like Heroku basically 'shared hosting for other stuff'?

pizzeys··on Show HN: Twitch Installs Arch Linux – A cooperative text-based horror game
Actually, that's a feature... Ctrl-C exits insert mode. If it quit vim when in Normal mode, you'd accidentally quit Vim all the time. Less annoying to just show a helpful message in case you actually meant quit, than dump everyone who knows what Ctrl-C does back to a shell.
pizzeys··on Windows 7 Update appears to be compromised?
> Approximately nothing installed via Windows Update will protect most people from most threats they might find on web sites.

What about all the browser sandbox escapes that rely on kernel vulns?

pizzeys··on 6 Reasons Why Young Men Should Not Become Programmers
It's really easy to make a Facebook clone just like it's really easy to build a soap box car, thus, automotive engineers are doomed.
Page 1 of 3Next →