Skip to content

SpaceX's Starship blows up ahead of 10th test flight

Technology
165 110 437
  • YouTube is getting rid of its Trending page and Trending Now list

    Technology technology
    49
    160 Stimmen
    49 Beiträge
    0 Aufrufe
    S
    I do enjoy this but I didn't realize I had the EU to thank! After you watched a first video though it seems to have no problem remembering what your browser fingerprint has watched before.
  • The Death of the Student Essay—and the Future of Cognition

    Technology technology
    26
    1
    134 Stimmen
    26 Beiträge
    122 Aufrufe
    artisian@lemmy.worldA
    I would love to see the source on this one. It sounds fascinating.
  • Signal – an ethical replacement for WhatsApp

    Technology technology
    235
    1
    1k Stimmen
    235 Beiträge
    979 Aufrufe
    V
    What I said is that smart people can be convinced to move to another platform. Most of my friends are not technically inclined, but it was easy to make them use it, at least to chat with me. What you did is change "smart people" with "people who already want to move", which is not the same. You then said it's not something you can choose (as you cannot choose to be rich). But I answered that you can actually choose your friends. Never did I say people who are not interested in niche technologies are not smart. My statement can be rephrased in an equivalent statement "people who cannot be convinced to change are not smart", and I stand to it.
  • 238 Stimmen
    54 Beiträge
    38 Aufrufe
    P
    I was so confused when I saw your comment until I reread my own. It really is top notch technology I guess!
  • Tech Company Recruiters Sidestep Trump’s Immigration Crackdown

    Technology technology
    1
    1
    1 Stimmen
    1 Beiträge
    12 Aufrufe
    Niemand hat geantwortet
  • 75 Stimmen
    8 Beiträge
    35 Aufrufe
    L
    Police: Arrest you for having an open beer in public Judge: sentences you to prison The PIC:
  • 1 Stimmen
    8 Beiträge
    37 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 81 Stimmen
    8 Beiträge
    39 Aufrufe
    P
    I expect them to give shareholders and directors a haircut before laying off workers, yes. But we know Microsoft never does that, so they can go f themselves.