Skip to content

How North Korea infiltrates its IT experts into Western companies

Technology
7 7 0
  • Microsoft extends updates for old Exchange and Skype servers

    Technology technology
    1
    1
    16 Stimmen
    1 Beiträge
    2 Aufrufe
    Niemand hat geantwortet
  • 198 Stimmen
    30 Beiträge
    198 Aufrufe
    D
    This guy gets it. And from my professional experience, Gen Z sucks at separating the two.
  • Microsoft to Lay Off About 9,000 Employees

    Technology technology
    30
    1
    284 Stimmen
    30 Beiträge
    193 Aufrufe
    D
    Actually you forgot about data mining or Spyware. Windows has literally become Spyware. I would switch faster than light if anticheat didn't gatekeep Linux. Edit: Microsoft products have literally become Spyware
  • 17 Stimmen
    2 Beiträge
    26 Aufrufe
    T
    Yeah, sure. Like the police need extra help with racial profiling and "probable cause." Fuck this, and fuck the people who think this is a good idea. I'm sure the authoritarians in power right now will get right on those proposed "safeguards," right after they install backdoors into encryption, to which Only They Have The Key, to "protect" everyone from the scary "criminals."
  • 105 Stimmen
    173 Beiträge
    679 Aufrufe
    smartmanapps@programming.devS
    the proper way is to group it as 1+(-2)+3 No it isn't. you can do it in any order You can do it in any order anyway left to right 1-2+3=-1+3=2 addition first 1+3-2=4-2=2 subtraction first -2+1+3=-1+3=2 right to left 3-2+1=1+1=2 What I meant with ““rule”” is the meme questions pray on people not understanding/remembering what the actual rules are And you showed that you were one of them. Every answer you got other than 4 was wrong, because you didn't understand the rules. spoiler alert: doing it in different orders never means add brackets to it. Addition first for 10-1+1 is 10+1-1, not 10-(1+1). See previous textbook example why “left to right” conventions exist They exist because people like you make mistakes when you try to do it in a different order. Either learn how the rules work or stop spreading disinformation. Well, you should stop spreading disinformation regardless.
  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

    Technology technology
    31
    1
    188 Stimmen
    31 Beiträge
    153 Aufrufe
    P
    Not to mention TeleMessage violated the terms of the GPL. Signal is under gpl and I can't find TeleMessage's code anywhere. Edit: it appears it is online somewhere just not in a github repo or anything https://micahflee.com/heres-the-source-code-for-the-unofficial-signal-app-used-by-trump-officials/
  • 1 Stimmen
    8 Beiträge
    40 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.
  • 588 Stimmen
    77 Beiträge
    273 Aufrufe
    F
    When a Lemmy instance owner gets a legal request from a foreign countries government to take down content, after they’re done shitting themselves they’ll take the content down or they’ll have to implement a country wide block on that country, along with not allowing any citizens of that country to use their instance no matter where they are located. Block me, I don’t care. You’re just proving that you can’t handle the truth and being challenged with it.