Skip to content

We Should Immediately Nationalize SpaceX and Starlink

Technology
436 187 0
  • 19 Stimmen
    12 Beiträge
    0 Aufrufe
    Q
    PSA OP "wikipediasuckscoop" seems to have a personal vendetta against wikipedia. All their posts are various articles bashing the site.
  • The Universal Tech Tree

    Technology technology
    1
    1
    21 Stimmen
    1 Beiträge
    0 Aufrufe
    Niemand hat geantwortet
  • 84 Stimmen
    12 Beiträge
    2 Aufrufe
    cupcakezealot@lemmy.blahaj.zoneC
    i like how ask photos is not just a dumb idea but it's also a dumb name
  • Uploading The Human Mind Could Become a Reality, Expert Says

    Technology technology
    12
    1
    7 Stimmen
    12 Beiträge
    2 Aufrufe
    r3d4ct3d@midwest.socialR
    what mustard is best for the human body?
  • 103 Stimmen
    102 Beiträge
    2 Aufrufe
    A
    Lost In Stupid Parenthesis.
  • Cory Doctorow on how we lost the internet

    Technology technology
    19
    145 Stimmen
    19 Beiträge
    0 Aufrufe
    fizz@lemmy.nzF
    This is going to be my goto example of why people need to care about data privacy. This is fucking insane. I'd fire someone for even throwing that out as a suggestion.
  • 1 Stimmen
    8 Beiträge
    3 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 163 Stimmen
    15 Beiträge
    5 Aufrufe
    L
    Online group started by a 15 year old in Texas playing Minecraft and watching extreme gore they said in this article. Were they also involved in said sexual exploiting of other kids, or was that just the spin offs that came from other people/countries? It all sounds terrible but I wonder if this was just a kid who did something for attention and then other perpetrators got involved and kept taking it further and down other rabbit holes. Definitely seems like a know what your kid is doing online scenario, but also yikes on all the 18+ members who joined and participated in such.