Skip to content

Microsoft Came to Bargain: Use OneDrive for Device Backup, Opt into Loyalty Program and Use Their Products Till You Earn 1000 Points or Pay $30 and They Might Give You Security Updates till Oct 2026.

Technology
55 38 140
  • Dubai to debut restaurant operated by an AI chef

    Technology technology
    6
    26 Stimmen
    6 Beiträge
    34 Aufrufe
    G
    Huh, looks like my days of having absolutely zero interest in going to Dubai are coming to a middle
  • New Google AdSense Fill Empty In-Page Ads

    Technology technology
    2
    1
    22 Stimmen
    2 Beiträge
    25 Aufrufe
    S
    I've not seen an ad in years, so they can try to monetize me but will fail spectacularly
  • 68 Stimmen
    4 Beiträge
    30 Aufrufe
    O
    This is also going to be used against the general populace. Setting up the Techno-Fuedal Surveillance state. The Militaries of the future will be policing their own countries more and more. Very soon the regular police will all have masks and blacked out helmets.
  • Bill Atkinson, Who Made Computers Easier to Use, Is Dead at 74

    Technology technology
    1
    1
    0 Stimmen
    1 Beiträge
    13 Aufrufe
    Niemand hat geantwortet
  • Copy Table in Excel and Paste as a Markdown Table

    Technology technology
    2
    1
    23 Stimmen
    2 Beiträge
    23 Aufrufe
    ptz@dubvee.orgP
    That's based on https://github.com/jonmagic/copy-excel-paste-markdown Would be awesome to see some Lemmy clients incorporate that. I've had it requested but haven't had a chance to really dig into it yet.
  • Britain’s Companies Are Being Hacked

    Technology technology
    9
    1
    21 Stimmen
    9 Beiträge
    52 Aufrufe
    D
    Is that "goodbye" in Russian? Why?
  • 236 Stimmen
    80 Beiträge
    375 Aufrufe
    R
    Yeah, but that's a secondary attribute. The new ones are stupid front and center.
  • 1 Stimmen
    8 Beiträge
    40 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.