Skip to content

Menstrual tracking app data is a ‘gold mine’ for advertisers that risks women’s safety

Technology
144 74 125
  • YouTube’s new anti-adblock measures

    Technology technology
    57
    217 Stimmen
    57 Beiträge
    118 Aufrufe
    M
    I wish I could create playlists on Nebula.
  • AJWIN — A Revolução do Entretenimento Online em Suas Mãos

    Technology technology
    1
    1
    0 Stimmen
    1 Beiträge
    2 Aufrufe
    Niemand hat geantwortet
  • Acute Leukemia Burden Trends and Future Predictions

    Technology technology
    5
    1
    5 Stimmen
    5 Beiträge
    23 Aufrufe
    G
    Looks like the delay in 2011 was so big the data became available after the 2017 one
  • The British jet engine that failed in the 'Valley of Death'

    Technology technology
    16
    1
    40 Stimmen
    16 Beiträge
    58 Aufrufe
    R
    Giving up advancements in science and technology is stagnation. That's not what I'm suggesting. I'm suggesting giving up some particular, potential advancements in science and tecnology, which is a whole different kettle of fish and does not imply stagnation. Thinking it’s a good idea to not do anything until people are fed and housed is stagnation. Why do you think that?
  • Massaging the neck and face may help flush waste out of the brain

    Technology technology
    25
    1
    237 Stimmen
    25 Beiträge
    91 Aufrufe
    D
    Segue into sexy time
  • 72 Stimmen
    9 Beiträge
    34 Aufrufe
    M
    Mr President, could you describe supersonic flight? (said with the emotion of "for all us dumbasses") Oh man there's going to be a barrier, but it's invisible, but it's the greatest barrier man has ever known. I gotta stop
  • 1 Stimmen
    8 Beiträge
    24 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 0 Stimmen
    1 Beiträge
    10 Aufrufe
    Niemand hat geantwortet