Skip to content

The IRS Tax Filing Software TurboTax Is Trying to Kill Just Got Open Sourced

Technology
145 79 624
  • Funny AI Love Calculator - try out it funny.

    Technology technology
    1
    2
    1 Stimmen
    1 Beiträge
    17 Aufrufe
    Niemand hat geantwortet
  • Grok, Elon Musk's AI chatbot, seems to get right-wing update

    Technology technology
    13
    1
    184 Stimmen
    13 Beiträge
    84 Aufrufe
    A
    Yep. Pretty sure that was deliberate on Musk's (or his cronies) part. Imagine working at X and being told by your boss "I'd like you to make the bot more racist please." "Can you convince it that conspiracy theories are real?"
  • The Complete History of Honda Acty: From Classic to Contemporary

    Technology technology
    1
    2
    1 Stimmen
    1 Beiträge
    14 Aufrufe
    Niemand hat geantwortet
  • 4 Stimmen
    6 Beiträge
    50 Aufrufe
    jimmydoreisalefty@lemmy.worldJ
    I wonder! They may be labeled as contractors or similar to a merc. Third-party contractors that don't have to follow the same 'rules' as government or military personnel. Edit: Word, merchs to merc, meaning mercenary
  • A receipt printer cured my procrastination [ADHD]

    Technology technology
    21
    1
    119 Stimmen
    21 Beiträge
    120 Aufrufe
    cygnosis@lemmy.worldC
    Good to know. Also an easy problem to fix. Just use phenol free paper.
  • 2 Stimmen
    1 Beiträge
    14 Aufrufe
    Niemand hat geantwortet
  • 2k Stimmen
    133 Beiträge
    574 Aufrufe
    S
    Tokyo banned diesel motors in the late 90s. As far as I know that didn't kill Toyota. At the same time European car makers started to lobby for particle filters that were supposed to solve everything. The politics who where naive enough to believe them do share responsibility, but not as much as the european auto industry that created this whole situation. Also, you implies that laws are made by politicians without any intervention of the industries whatsoever. I think you know that it is not how it works.
  • 1 Stimmen
    8 Beiträge
    40 Aufrufe
    L
    I think the principle could be applied to scan outside of the machine. It is making requests to 127.0.0.1:{port} - effectively using your computer as a "server" in a sort of reverse-SSRF attack. There's no reason it can't make requests to 10.10.10.1:{port} as well. Of course you'd need to guess the netmask of the network address range first, but this isn't that hard. In fact, if you consider that at least as far as the desktop site goes, most people will be browsing the web behind a standard consumer router left on defaults where it will be the first device in the DHCP range (e.g. 192.168.0.1 or 10.10.10.1), which tends to have a web UI on the LAN interface (port 8080, 80 or 443), then you'd only realistically need to scan a few addresses to determine the network address range. If you want to keep noise even lower, using just 192.168.0.1:80 and 192.168.1.1:80 I'd wager would cover 99% of consumer routers. From there you could assume that it's a /24 netmask and scan IPs to your heart's content. You could do top 10 most common ports type scans and go in-depth on anything you get a result on. I haven't tested this, but I don't see why it wouldn't work, when I was testing 13ft.io - a self-hosted 12ft.io paywall remover, an SSRF flaw like this absolutely let you perform any network request to any LAN address in range.