leds

joined 2 years ago
[–] leds@feddit.dk 1 points 1 day ago

Any news on the next book?

[–] leds@feddit.dk 4 points 3 weeks ago (1 children)

Isn't the point that it should have stopped because of the stop sing with flashing lights on the school bus?

[–] leds@feddit.dk 3 points 3 weeks ago

Yes that's it, they offer it for download. People click " I agree" and install. Then it phones home and oracle knocks on your door with huge license fee and or lawsuit.

[–] leds@feddit.dk 2 points 1 month ago* (last edited 1 month ago)

Not just support it but sometimes it's the only option, so you also have to support their business even if you just paying upfront. (and hand over your personal data)

[–] leds@feddit.dk 3 points 1 month ago (1 children)

Its been a day , this was their last comment...

[–] leds@feddit.dk 7 points 1 month ago

Would be amazing if this also works for other hiding viruses , maybe even long covid?

[–] leds@feddit.dk 7 points 1 month ago (1 children)

Yeah about that:

[–] leds@feddit.dk 10 points 1 month ago

Valuable lesson learned, trust yourself instead of authority ( I hope at least that was it and not start of self doubting ever after)

[–] leds@feddit.dk 36 points 1 month ago (2 children)

Also using 10GB memory ...

[–] leds@feddit.dk 0 points 1 month ago (5 children)

Threw out Gaiman's books , needs to be purged from history ( except Good Omens of course, because of Pratchett)

[–] leds@feddit.dk 2 points 2 months ago

No , then you become a therapist.

 

https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised

Harden-Runner detection: tj-actions/changed-files action is compromised We are investigating a critical security incident involving the popular tj-actions/changed-files GitHub Action. We want to alert you immediately so that you can take prompt action.

Your secrets are in the build logs

 

I dont know who needs to hear this bit qBittorrent has a nasty vulnerability ( and there are some older ones too)

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded.

To be exploitable, this bug requires either MITM access or DNS spoofing attacks, but under those conditions (seen regularly in some countries), impacts are severe.

The primary impact is single-click RCE for Windows builds from 2015 onward, when prompted to update python the exe is downloaded from a hardcoded URL, executed, and then deleted afterwards.

The secondary impact for all platforms is the update RSS feed can be poisoned with malicious update URLs which the user will open in their browser if they accept the prompt to update. This is browser hijacking and arbitrary exe delivery to a user who would likely trust whatever URL this software sent them to.

The tertiary impact is this means that an older CVE (CVE-2019-13640 https://www.cvedetails.com/cve/CVE-2019-13640/) which allowed remote command execution via shell metacharacters could have been exploited by (government) attackers conducting either MITM or DNS spoofing attacks at the time, instead of only by the author of the feed.

Full write up is here: https://sharpsec.run/rce-vulnerability-in-qbittorrent/

 

so.. i'm running lineageOS on my phone (a Oneplus 6T) , have been for a very long time. Usually i'm really happy with this but not tonight:

  • Phone suggest a update of OS , just a weekly build. Sure why not, so it does it thing and i reboot, all good.
  • Open a app to listen to some podcast: screen goes black flickers a couple of times showing empty launcher. thankfully power button long press shows shutdown menu (but looks different from normal?) and lets me restart
  • do same thing again , ok looks like latest update broke something
  • update app, same
  • go to settings , updates to try to revert to previous version: no option to install older version , only option is export. weird ok lets try to export old version . Now it lets me install that
  • installation loops , seems it failed
  • try app again, same black screen , hold power button to get boot menu again : now phone says ERASING .. wait what stop no .. (does lineage have a panic wipe my phone key combo i didn't know about?)
  • rebooting , rebooting again
  • welcome setup your phone screen :(
  • remember that my cloud server disk burned last week , no way to restore backups :( :(
 

Hi All, my fava beans are being eaten by black ants , no aphids. the ants themselves seem to be sucking the juice out of the leaves, leaving black spots where they have been nibling.

I thought they normally employed aphids to do the hard work for them but maybe they are skipping the middle man. Anyone seen this before?

Other leaves are full of holes but that looks more like snails , dont think the ants are capable of that.

Any good tips for encouraging the ants to move elsewhere ?

 

Merged

 

Last paragraph makes a good point

But now it’s been a decade. Everything he knows is old and out of date. Everything we know is old and out of date. The NSA suffered an even worse leak of its secrets by the Russians, under the guise of the Shadow Brokers, in 2016 and 2017. The NSA has rebuilt. It again has capabilities we can only surmise.

view more: next ›