Skip to content

This new 40TB hard drive from Seagate is just the beginning—50TB is coming fast!

Technology
232 129 10
  • Anker is recalling over 1.1 million power banks due to fire risks

    Technology technology
    19
    1
    208 Stimmen
    19 Beiträge
    0 Aufrufe
    B
    Thanks man! Really appreciate the type up! Have a great weekend!
  • Unionize or die - Drew DeVault

    Technology technology
    3
    75 Stimmen
    3 Beiträge
    5 Aufrufe
    W
    and hopefully also elsewhere. as Drew said in the first part, tech workers will be affected by billionaire's decisions even outside of work, on multiple fronts. we must eat the rich, or they will eat us all alive.
  • 80 Stimmen
    14 Beiträge
    4 Aufrufe
    B
    Didn’t he pay a hitman to murder a couple of people?
  • Palantir’s Idea of Peace

    Technology technology
    12
    22 Stimmen
    12 Beiträge
    4 Aufrufe
    A
    "Totally not a narc, inc."
  • 20 Stimmen
    7 Beiträge
    2 Aufrufe
    A
    Fantastic! Me and my 7 legs tank you so much!
  • 1 Stimmen
    8 Beiträge
    3 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 109 Stimmen
    3 Beiträge
    4 Aufrufe
    M
    A private company is selling cheap tablets to inmates to let them communicate with their family. They have to use "digital stamps" to send messages, 35 cents a piece and come in packs of 5, 10 or 20. Each stamp covers up to 20,000 characters or one single image. They also sell songs, at $1.99 a piece, and some people have spent thousands over the years. That's also now just going away. Then you get to the part about the new company. Who already has a system in Tennessee where inmates have to pay 3-5 cents per minute of tablet usage. Be that watching a movie they've bought or just typing a message.
  • Apple Watch Shipments’ Continuous Decline

    Technology technology
    10
    1
    22 Stimmen
    10 Beiträge
    2 Aufrufe
    A
    i mean as a core feature of a watch/smartwatch in general. garmin is going above and beyond compared to the competition in that area, and that's great. But that doesn't mean every other smartwatch manufacturer arbitrarily locking traditional watch features behind paywalls. and yeah apple does fitness themed commercials for apple watch because it does help with fitness a ton out of the box. just not specifically guided workouts.