Skip to content

Is the U.S. Vulnerable to a Drone Sneak Attack?

Technology
28 16 0
  • 810 Stimmen
    136 Beiträge
    3 Aufrufe
    C
    Corporatism leads to imperialism by the need to seek profits in new markets. Wherever we see lots of defense of imperialism, there is corporate backing behind it. That's why I think lemmy.world is astroturfed. There's a strong anti-communist and pro "free market" capitalist tendency on there. Posts that attack the Global South as the world's villains. On the other hand, there are also many people on lemmy.world that speak out against imperialism and capitalistic exploitation. But the recurrent waves of reactionary politics on lemmy.world indicate to me the presence of astroturfing trolls. This makes sense even on a relatively small platform like Lemmy because it threatens to become a nucleus for organizing against capitalism.
  • 7 Stimmen
    6 Beiträge
    3 Aufrufe
    db0@lemmy.dbzer0.comD
    VC-backed OpenAI is the most valuable company in the world and is engaging in massive environmental destruction. The US state just went into cahoots with them to the tune of billions VC-backed Uber and AirBnb disrupted multiple estabilished industries for the worst by undercutting them through loss-leading. VC-backed Facebook killed or purchased all its rivals and consolidated almost all social media to the detriment of the whole world.
  • 11 Stimmen
    1 Beiträge
    1 Aufrufe
    Niemand hat geantwortet
  • Meta is now a defense contractor

    Technology technology
    54
    1
    362 Stimmen
    54 Beiträge
    4 Aufrufe
    B
    Best decision ever for a company. The US gov pisses away billions of their taxpayers money and buys all the low quality crap from the MIL without questions.
  • 1 Stimmen
    8 Beiträge
    5 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 87 Stimmen
    10 Beiträge
    3 Aufrufe
    T
    If you want to stay on the bleeding edge you've got to be a reversal of Europe, which means allowing innovation and competition. Hence why VT is nearly 70% US.
  • Nextcloud cries foul over Google Play Store app rejection

    Technology technology
    31
    1
    256 Stimmen
    31 Beiträge
    4 Aufrufe
    S
    I have the regular F-droid and it does automatic updates now.
  • WhatsApp provides no cryptographic management for group messages

    Technology technology
    3
    1
    17 Stimmen
    3 Beiträge
    5 Aufrufe
    S
    Just be sure to add only the people you want to be there. I've heard some people add others and it's a bit messy