the grugq's newsletter

Subscribe
Archives
October 6, 2023

October 6, 2023

October 6, 2023

Joe :fedora: :debian: :ferris:: "Today I found out that google docs infects html e…" - Fosstodon

Today I found out that google docs infects html exports with spyware, no scripts, but links in your document are replaced with invisible google tracking redirects. I was using their software because a friend wanted me to work with him on a google doc, he is a pretty big fan of their software, but we were both somehow absolutely shocked that they would go that far.


Another Angry Woman: "if you are human, answer me this" - Mastodon

Attached: 1 image if you are human, answer me this


Stephen Rees-Carter :laravel:: "One of my favourite (and oh so simple) hacker tri…" - PHP Community on Mastodon

Attached: 1 image One of my favourite (and oh so simple) hacker tricks is to abuse JSON support in APIs and pass TRUE instead of the actual API key. If the code does loose comparison, you don't need the key! 😎 😈 🍿 https://securinglaravel.com/p/security-tip-type-juggling #PHP #Laravel


People Exploited YouTube Bug to Upload “Undeletable” Porn Videos

Communities of YouTube hackers and YouTube porn searchers discovered a bug that broke the platform's interface and kept hardcore porn on the site for weeks.


Web Security vs. Binary Exploitation pic.twitter.com/poTMyPivwm

— LiveOverflow 🔴 (@LiveOverflow) October 5, 2023

I am cracking the fuck up over this. She may be the saltiest politician to ever live. https://t.co/mGwsh7xlBd pic.twitter.com/FZM3fSbLGX

— ethelred (@aethelred) October 5, 2023

my favorite part of using @matrixdotorg is being gaslit by the main messenger I'm using to communicate with those I care about

love to see a series of messages described as "delivered" and "seen", then compare screenshots and find out that many of them just never were

— Catherine (@whitequark) October 5, 2023

"No way to prevent this", says only chat program where this regularly happens

— Jonas Schievink (@sheevink) October 6, 2023

Do you have a bunch of GPUs and passphrase bruteforcing experience?

Crack the NSA’s five SHA-1 hashes at the heart of NIST's elliptic curves, solve a cryptographic mystery, and earn $8k (tripled if donated to charity)!https://t.co/kjRb8cNHSS

— Filippo Valsorda @filippo.abyssdomain.expert (@FiloSottile) October 5, 2023

another crappy CVE-2023-4911 (Looney Tunables, https://t.co/gZ8mONq0O0) PoC: https://t.co/qY5GsVPc29 -- might refine it later, might not

— blasty (@bl4sty) October 5, 2023

hey sorry i overreacted, i always do that whenever anything happens

— keely flaherty (@keelyflaherty) October 5, 2023

lol. lmao pic.twitter.com/CpH3s6Jyyw

— deathco.re on bsky (@SAMOYEDCORE) October 5, 2023

United Nations Secretary General and @ICRC chief call on States to create binding treaty/rules regulating the uses of autonomous weapons systems ("AI", but actually beyond that). "contribute to global instability and tensions" https://t.co/eZ115N2q4I pic.twitter.com/Di5ppMMIom

— Lukasz Olejnik (@LukaszOlejnik@Mastodon.Social) (@lukOlejnik) October 6, 2023

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X