Skip to content

Discord unveils Discord Orbs, a new in-app currency that users can earn by completing Quests, which reward participants who interact with ads

Technology
137 83 5
  • Google’s test turns search results into an AI-generated podcast

    Technology technology
    4
    1
    5 Stimmen
    4 Beiträge
    0 Aufrufe
    lupusblackfur@lemmy.worldL
    Oh, Google... Just eviler and eviler every day. Not only robbing creators of any monetization via clicking on links but now just blatantly stealing their content for an even more efficient theft model. FFS. I can't fucking wait to complete my de-googling project and get you the absolute fuck completely out of my life. I've developed a hatred for Google that actually rivals my hatred for Apple. ‍️
  • Amazon Doubles Prime Video Ads Per Hour

    Technology technology
    126
    1
    620 Stimmen
    126 Beiträge
    0 Aufrufe
    V
    Me too, except I didn't get the email saying my pro vpn was about to expire, which might be my fault ofc. Gotta check the oarameters It's really good IMO and I'd recommend it fullheartedly, Switzerland has some of the best laws out there too concerning privacy too.
  • Russian Lawmakers Authorize Creation Of National Messaging Service

    Technology technology
    13
    1
    33 Stimmen
    13 Beiträge
    0 Aufrufe
    C
    Are there substantial numbers of Russians who seriously wouldn't be wise to this?
  • 157 Stimmen
    12 Beiträge
    0 Aufrufe
    W
    that's not just useless defeatism, but also false. effective end to end encryption exists in multiple forms today. signal, maybe even with a custom server. matrix if the server is being ran on trusted hardware. XMPP too with the right extensions.
  • Hiring Developers in Eastern Europe

    Technology technology
    1
    0 Stimmen
    1 Beiträge
    1 Aufrufe
    Niemand hat geantwortet
  • 324 Stimmen
    18 Beiträge
    4 Aufrufe
    D
    Do you think a plumber dreams about being a plumber?
  • 1 Stimmen
    8 Beiträge
    3 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 0 Stimmen
    17 Beiträge
    5 Aufrufe
    F
    You seem to think we disagree on creation of a police state or massive surveillance system being a bad thing for some reason. None of which are stopped with regulations by the states that are funding and building said things ...