1,512 karma · joined December 22, 2011
I like breaking into things
x-whitehat: autopatch
which gives white-hats the opportunity to patch your system without exploiting. The why I see it, a malicious person is going to exploit your server anyway. This way white-hats could patch your system and not be prosecuted. With this, someone who discovered the patch could scan the internet, look for servers that say "yes, please patch me" and deploy a quick patch and nothing else.I can tell you that this is wrong, I've personally had months where I've used 100GB+ of data over 3G and had no problems (this is on a £15 top-up). I don't know if they throttle or not, I've never really noticed it.
> Tethering is disabled while roaming overseas on "feel at home", but not prevented at home.
I didn't get my handset from Three but I've been able to tether in Paris and used at least 2GB when I was there.
2. Don't pay it back
3. Ask debt collector friend to buy debt
4. Pay him off
Why would this not work?
However, I'm currently in the process of working with the Google Analytics API to provide free scans for verified websites where the user can prove ownership -- this should roll out in about a week or so. Would you like me to drop you a PM when I release this feature?
Current solutions to vulnerability scanning such as WPscan are good but not user-friendly -- which is what I believe what WordPress users want. I've already got my first 5 customers prior to launch that wanted this product which I think is a good start, hopefully there is a market for this stuff.
I would love to hear any sort of feedback.
I wonder how it will affect YHOO -- Probably worth buying Jan 2015 $40 calls since Yahoo owns 24% stake, maybe even short AMZN on day of IPO.
Simple logic: The defacement was amature at best. If the group has a 0-day in a hypervisor they would have gone to multiple hosting companies and multiple attacks would have taken place, there are many more targets that are worth much more than openSSL.
Most likely, the administration panel of the hosting company was comprimised through malware/phishing. Seriously, if a group like this had a 0-day in hypervisor then they would be doing much much more damage.
It worked for Google, it worked for Facebook and its working for Yahoo! Infact, it worked so well for Google that they recently increased the rewards. A venture-backed startup like Snapchat that stores private pictures (even temporarily) should have no trouble paying out $5k a few times for vulnerabities.
If they had any sort of system access they would have defaced the entire subdomain or the main site. So most likely, this is nothing to worry about. Your account data most likely still in safe hands.
The author thinks that this is a security issue because this option should be enabled by default. However, (I assume) it's not in Digital Oceans interest to do full disk scrub because it reduces the lifespan of their SSD.
If a user forgets to log out of Facebook on a public computer, is it Facebook's responsibility? Similarly, if a user does not correctly delete data on a budget host, is it the hosts fault?
I need more money for the servers so I'm currently waiting for my Google bug bounty to come through (it's been over 6 weeks!) so I can fund a security startup with security money from Google.
The admin, allegedly this Thomas guy, ran off with 17k BTC which is worth around $15M right now. Nobody is able to transfer their bitcoin out of sheep either. Everybody is pissed off so people are attacking his server and trying to "dox" the person. Here is the address where the money has gone:
https://blockchain.info/address/1Cwb33nqn4S2uDsXwhNrUNy7FPdi...
If anybody is interested, check out the sheep subreddit, lot's more information on the issue there.
>smoking weed
>wondering why you can't stay mentally on
https://scholar.google.co.uk/scholar?q=cannabis+depression