Skip to content

Here's your first look at the rebooted Digg | TechCrunch

Technology
59 38 589
  • WhoFi: Unique 'fingerprint' based on Wi-Fi interactions

    Technology technology
    11
    1
    45 Stimmen
    11 Beiträge
    59 Aufrufe
    N
    "Who's signal is this?" "Oh, it's that guy with the metal strips. His address is on a post-it note somewhere around here."
  • 590 Stimmen
    120 Beiträge
    2k Aufrufe
    chickenandrice@sh.itjust.worksC
    Building a linux phone: do you mean from scratch, or just installing one of the Linux phone OS's that already exist? I've been following Ubuntu Touch for several years now and, while they have made a lot of progress, its main hurdles have the same thing in common: mobile hardware is incredibly locked down. For example, Ubuntu Touch uses proprietary Android drivers for many low level functions. Even then, there's some features that aren't stable across all devices, like VOLTE. It sucks, I really want to use Ubuntu Touch (or any of the Linux alternatives) but I can't make phone calls or text in the US without VOLTE support. There are a few phones that support VOLTE, but the feature is either in beta, the phone is expensive, or the phone is not sold in the US. Anyways bringing that back to Graphene: In my case, I'm using this as a stopgap until Linux phones take off (assuming they ever do). For now I guess the best thing is to just be skeptic, keep things minimal, and bloat-free.
  • Palantir partners to develop AI software for nuclear construction

    Technology technology
    4
    33 Stimmen
    4 Beiträge
    48 Aufrufe
    T
    The grift goes nuclear. No surprise.
  • 31 Stimmen
    1 Beiträge
    17 Aufrufe
    Niemand hat geantwortet
  • Elon Musk’s SpaceX Starship explodes on test stand

    Technology technology
    51
    219 Stimmen
    51 Beiträge
    546 Aufrufe
    M
    Are the cars shitty, or are they ranked 3rd?
  • 25 Stimmen
    4 Beiträge
    44 Aufrufe
    roofuskit@lemmy.worldR
    At least the AI doesn't mean to lie to you, unlike the intention of the rest of the site.
  • 1 Stimmen
    8 Beiträge
    79 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 12 Stimmen
    3 Beiträge
    33 Aufrufe
    F
    The new Pebble watches look interesting. Relatively basic, but long battery life (they promise) and open-source operating system.