Skip to content

Threads is nearing X's daily app users, new data shows

Technology
23 18 0
  • 136 Stimmen
    29 Beiträge
    104 Aufrufe
    J
    Yeah, I was going to say that TV wasn't much of a news source to begin with. The real issue is that social media for news is probably worse - now everyone can be spoonfed the news they want.
  • Inside a Dark Adtech Empire Fed by Fake CAPTCHAs

    Technology technology
    1
    10 Stimmen
    1 Beiträge
    9 Aufrufe
    Niemand hat geantwortet
  • Programming languages

    Technology technology
    1
    1
    0 Stimmen
    1 Beiträge
    9 Aufrufe
    Niemand hat geantwortet
  • 215 Stimmen
    118 Beiträge
    212 Aufrufe
    A
    Outlook has search?!
  • 1 Stimmen
    8 Beiträge
    34 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • *deleted by creator*

    Technology technology
    1
    1
    0 Stimmen
    1 Beiträge
    14 Aufrufe
    Niemand hat geantwortet
  • 3 Stimmen
    9 Beiträge
    36 Aufrufe
    G
    So we need a documentary like Super Size Me but for social media. I think post that documentary coming out was the only time I've seen people's attitudes change in the general population about fast food.
  • YouTube’s ad blocker crackdown now includes third-party apps

    Technology technology
    2
    1
    0 Stimmen
    2 Beiträge
    14 Aufrufe
    G
    Honestly ads are not bothering me at all. I can wait now, we have to admit that those content creators making type of conent to earn money at first place and we have to support them if they are giving us a quality content. Else there are some modified tools which makes all this easy and effective. Especially there are gaming modifications which makes all the scenarios top notch.