home.social

Search

1000 results for “faker_js”

  1. Another service #killedbygoogle: "dark web report".
    One of the last few services I used by them. Oh well.

  2. Having had a cursory glance at Burp AI, there is just an instant dealbreaker: you have no control which requests it sends to your target.
    Let's say you tell it "find a RCE in this parameter", nothing stops it from injecting "rm -rf /*" or exfiltrating all ssh keys to pastebin because it learned that from some weird medium blog post or CTF write up.
    Not being able to review the requests before they are fired is insane.

    You might say, an active scan also does that. Sure, but they are curated and static. The payloads won't just change every minute.

    #BurpAI #BurpSuite

  3. Having had a cursory glance at Burp AI, there is just an instant dealbreaker: you have no control which requests it sends to your target.
    Let's say you tell it "find a RCE in this parameter", nothing stops it from injecting "rm -rf /*" or exfiltrating all ssh keys to pastebin because it learned that from some weird medium blog post or CTF write up.
    Not being able to review the requests before they are fired is insane.

    You might say, an active scan also does that. Sure, but they are curated and static. The payloads won't just change every minute.

    #BurpAI #BurpSuite

  4. Having had a cursory glance at Burp AI, there is just an instant dealbreaker: you have no control which requests it sends to your target.
    Let's say you tell it "find a RCE in this parameter", nothing stops it from injecting "rm -rf /*" or exfiltrating all ssh keys to pastebin because it learned that from some weird medium blog post or CTF write up.
    Not being able to review the requests before they are fired is insane.

    You might say, an active scan also does that. Sure, but they are curated and static. The payloads won't just change every minute.

    #BurpAI #BurpSuite

  5. Having had a cursory glance at Burp AI, there is just an instant dealbreaker: you have no control which requests it sends to your target.
    Let's say you tell it "find a RCE in this parameter", nothing stops it from injecting "rm -rf /*" or exfiltrating all ssh keys to pastebin because it learned that from some weird medium blog post or CTF write up.
    Not being able to review the requests before they are fired is insane.

    You might say, an active scan also does that. Sure, but they are curated and static. The payloads won't just change every minute.

    #BurpAI #BurpSuite

  6. Having had a cursory glance at Burp AI, there is just an instant dealbreaker: you have no control which requests it sends to your target.
    Let's say you tell it "find a RCE in this parameter", nothing stops it from injecting "rm -rf /*" or exfiltrating all ssh keys to pastebin because it learned that from some weird medium blog post or CTF write up.
    Not being able to review the requests before they are fired is insane.

    You might say, an active scan also does that. Sure, but they are curated and static. The payloads won't just change every minute.

    #BurpAI #BurpSuite

  7. That #Haveibeenpwned Synthient collection is great.
    You've been pwned!
    OK, now what? Which password? Which one should I change?
    ¯\_(ツ)_/¯

  8. @sebastianbasner ich habe ja auch schon einen Rant zu #iKFZ gepostet, immerhin soll das schon mit Blick auf EUDI entwickelt worden sein. Man kann hoffen, dass es besser wird.

    ec.europa.eu/digital-building-

  9. Digitalisation in Germany is such a pain. Today a new mobile App launched to store your car registration data.
    Let's not even talk about how to get the data in (ePA...), but how to get it out?

    Imagine you are getting pulled over, police wants to see it. There is no button to generate a QR code for the police to scan, there is no App for the police at all. They just... Read the screen?!
    So you hand over your unlocked mobile phone? Or you keep it and they read it out of your hand.
    A police person already said that the user "must scroll and click on buttons in the app, so that the police can be sure it is not just shown a screenshot".

    Yeah. That tracks. How else could you possibly be sure of that? Ever heard of... Signatures?!

    #i-kfz #ikfz

  10. This isn’t just a toy… it’s a hug in otter form 🧸💞
    Soothe your baby with love, light & lullabies 💫
    ✨ Gentle breathing motion
    ✨ Soft glowing light
    ✨ Sweet sounds that calm your little one

    💖 The perfect bedtime friend for your newborn!

    Available now Amazon 👉 amzn.to/4n6gZyi

    #FisherPrice #BabyComfort #NewbornLove #MomLife #BabySleep #AffiliateFinds #DreamStore #BabyEssentials #ParentingLove #amazon #onlineshoping

  11. The Workout App on watchOS 26 now reads out splits and other targets even if you are listening to music.
    Previously it only did that if no audio was playing.
    If you want to disable that, use the bell in the bottom right corner and then set splits or whatever to "none". Enjoy the silence again during your workouts.
    As far as I can tell splits are still being logged.

    #watchos26 #Apple #WorkoutApp #AppleFitness

  12. The Workout App on watchOS 26 now reads out splits and other targets even if you are listening to music.
    Previously it only did that if no audio was playing.
    If you want to disable that, use the bell in the bottom right corner and then set splits or whatever to "none". Enjoy the silence again during your workouts.
    As far as I can tell splits are still being logged.

    #watchos26 #Apple #WorkoutApp #AppleFitness

  13. The Workout App on watchOS 26 now reads out splits and other targets even if you are listening to music.
    Previously it only did that if no audio was playing.
    If you want to disable that, use the bell in the bottom right corner and then set splits or whatever to "none". Enjoy the silence again during your workouts.
    As far as I can tell splits are still being logged.

    #watchos26 #Apple #WorkoutApp #AppleFitness

  14. The true 2nd factor is knowing which factor to use. Not pictured: 15+ accounts in 5 MFA mobile apps. #ConsultingLife

  15. The true 2nd factor is knowing which factor to use. Not pictured: 15+ accounts in 5 MFA mobile apps. #ConsultingLife

  16. The true 2nd factor is knowing which factor to use. Not pictured: 15+ accounts in 5 MFA mobile apps. #ConsultingLife

  17. Another day, another AI is announced. This time its a cybersecurity AI by Google: Sec-Gemini v1 [1]. As always, lets look at the response of it that was included on their announcement post. Surely the response was vetted and confirmed by multiple people, right?

    The prompt asks about CVE-2024-3400, and at first glance this appears ok.

    But in the affected systems section it states:

    > Also Hitachi Energy RTU500 firmware and Siemens Ruggedcom APE1808 firmware.

    I cannot find any reference that this Hitachi device is vulnerable to that CVE. Hitachi has a nice interface to list all vulnerabilities of their devices [1], this CVE is not part of it.
    In the Mitigation section any mention of Hitachi is also missing. Almost as if this device is not vulnerable.

    [1] security.googleblog.com/2025/0
    [2] hitachienergy.com/products-and

    #secgemini

  18. Another day, another AI is announced. This time its a cybersecurity AI by Google: Sec-Gemini v1 [1]. As always, lets look at the response of it that was included on their announcement post. Surely the response was vetted and confirmed by multiple people, right?

    The prompt asks about CVE-2024-3400, and at first glance this appears ok.

    But in the affected systems section it states:

    > Also Hitachi Energy RTU500 firmware and Siemens Ruggedcom APE1808 firmware.

    I cannot find any reference that this Hitachi device is vulnerable to that CVE. Hitachi has a nice interface to list all vulnerabilities of their devices [1], this CVE is not part of it.
    In the Mitigation section any mention of Hitachi is also missing. Almost as if this device is not vulnerable.

    [1] security.googleblog.com/2025/0
    [2] hitachienergy.com/products-and

    #secgemini

  19. Another day, another AI is announced. This time its a cybersecurity AI by Google: Sec-Gemini v1 [1]. As always, lets look at the response of it that was included on their announcement post. Surely the response was vetted and confirmed by multiple people, right?

    The prompt asks about CVE-2024-3400, and at first glance this appears ok.

    But in the affected systems section it states:

    > Also Hitachi Energy RTU500 firmware and Siemens Ruggedcom APE1808 firmware.

    I cannot find any reference that this Hitachi device is vulnerable to that CVE. Hitachi has a nice interface to list all vulnerabilities of their devices [1], this CVE is not part of it.
    In the Mitigation section any mention of Hitachi is also missing. Almost as if this device is not vulnerable.

    [1] security.googleblog.com/2025/0
    [2] hitachienergy.com/products-and

    #secgemini

  20. Another day, another AI is announced. This time its a cybersecurity AI by Google: Sec-Gemini v1 [1]. As always, lets look at the response of it that was included on their announcement post. Surely the response was vetted and confirmed by multiple people, right?

    The prompt asks about CVE-2024-3400, and at first glance this appears ok.

    But in the affected systems section it states:

    > Also Hitachi Energy RTU500 firmware and Siemens Ruggedcom APE1808 firmware.

    I cannot find any reference that this Hitachi device is vulnerable to that CVE. Hitachi has a nice interface to list all vulnerabilities of their devices [1], this CVE is not part of it.
    In the Mitigation section any mention of Hitachi is also missing. Almost as if this device is not vulnerable.

    [1] security.googleblog.com/2025/0
    [2] hitachienergy.com/products-and

    #secgemini

  21. Another day, another AI is announced. This time its a cybersecurity AI by Google: Sec-Gemini v1 [1]. As always, lets look at the response of it that was included on their announcement post. Surely the response was vetted and confirmed by multiple people, right?

    The prompt asks about CVE-2024-3400, and at first glance this appears ok.

    But in the affected systems section it states:

    > Also Hitachi Energy RTU500 firmware and Siemens Ruggedcom APE1808 firmware.

    I cannot find any reference that this Hitachi device is vulnerable to that CVE. Hitachi has a nice interface to list all vulnerabilities of their devices [1], this CVE is not part of it.
    In the Mitigation section any mention of Hitachi is also missing. Almost as if this device is not vulnerable.

    [1] security.googleblog.com/2025/0
    [2] hitachienergy.com/products-and

    #secgemini

  22. Started to debug why the VPN suddenly doesn't work anymore just before #37c3.
    Turns out the CA expired.
    Judging by the timestamps when it was created, I probably set it up for #30c3 and thought "10 years is enough, I just use it temporarily on that server for now."

  23. Fazer por Fazer — A mentalidade da prática

    Você já parou pra pensar por que fazemos algumas coisas só pelo resultado? 🤔

    - Nessa outra forma de pensar: eles compreendem que não se deve fazer coisas só por conta do amanhã ou para o agora. 🌏
    - Você tem que fazer coisas que são simplesmente por fazer — porque é uma coisa da vida. ✨
    - Isso vale para yoga, arte marcial, meditação e qualquer prática: é disciplina, cultura e trabalho...

    #yoga #meditação #cultura #prática #disciplina #MorningCrypto

  24. Fazer por Fazer — A mentalidade da prática

    Você já parou pra pensar por que fazemos algumas coisas só pelo resultado? 🤔

    - Nessa outra forma de pensar: eles compreendem que não se deve fazer coisas só por conta do amanhã ou para o agora. 🌏
    - Você tem que fazer coisas que são simplesmente por fazer — porque é uma coisa da vida. ✨
    - Isso vale para yoga, arte marcial, meditação e qualquer prática: é disciplina, cultura e trabalho...

    #yoga #meditação #cultura #prática #disciplina #MorningCrypto

  25. Sehr viele werden darauf reinfallen, weil die #Fake News ja scheinbar von einer vertrauenswürdigen Person kommen, die Du kennst. So bekommt der #Russe die #AfD in DE deutlich über die 30% und schon ist eine Regierungsbildung ohne die #Nazis nicht mehr möglich. Denkt dran: Hitler hatte knapp 34%

  26. Sehr viele werden darauf reinfallen, weil die #Fake News ja scheinbar von einer vertrauenswürdigen Person kommen, die Du kennst. So bekommt der #Russe die #AfD in DE deutlich über die 30% und schon ist eine Regierungsbildung ohne die #Nazis nicht mehr möglich. Denkt dran: Hitler hatte knapp 34%

  27. Sehr viele werden darauf reinfallen, weil die #Fake News ja scheinbar von einer vertrauenswürdigen Person kommen, die Du kennst. So bekommt der #Russe die #AfD in DE deutlich über die 30% und schon ist eine Regierungsbildung ohne die #Nazis nicht mehr möglich. Denkt dran: Hitler hatte knapp 34%

  28. Fake Tomodachi Life apps are popping up like weeds on the Google Play Store

    TL;DR A number of Tomodachi Life: Living the Dream knock-offs are popping up in the Google Play Store.…
    #NewsBeep #News #Mobile #AU #Australia #gaming #Nintendo #NintendoSwitch #Technology
    newsbeep.com/au/694871/