home.social

Search

1000 results for “bug”

  1. I think they took a wrong turn at Albuquerque.

  2. Is this woodworm dust? That's my best guess - dust made by the larvae of woodworm beetles - but it's hard to get clear photos that match it for comparison, search being useless these days.

    It's in all the corners where the skirting board meets the bath. The first photo shows where I haven't tried to clean it up, the second where I have.

    I'm guessing I need to tell my Landlord about this?

    #bugs #woodworm #woodwork #insects #dust

  3. WebSocket Penetration Testing: How to Test for WebSocket Hijacking, IDOR, Injection & More
    This article discusses using the WSStrike extension in Burp Suite for comprehensive WebSocket penetration testing. The vulnerability class includes WebSocket hijacking, IDOR (Insecure Direct Object References), and injection attacks. The root cause lies in weak implementation of WebSocket security measures, such as lacking proper authentication or validation checks. Researchers exploited this by intercepting WebSocket traffic using WSStrike, injecting malicious payloads to manipulate application behavior. For instance, an IDOR issue was exposed when the researcher manipulated a user's session token to access another user's data. The technical details revolve around analyzing and interacting with WebSocket communication protocols and their security flaws. The impact of these vulnerabilities can range from unauthorized access to sensitive data, account takeover, or even complete system compromise. WSStrike helped reveal a bounty of $10,000 for finding multiple critical issues in a platform. To prevent such attacks, enforce strong authentication and authorization mechanisms, validate input data, and regularly audit WebSocket implementation. Key lesson: Always prioritize security when implementing WebSocket communication. #BugBounty #WebSecurity #WebSocket #IDOR #Injection

    medium.com/@exploitersorigin/w

  4. The Logic Flaw That Leads to Total Control: Mastering Account Takeovers in 2026
    This vulnerability falls under the Authentication Bypass class, specifically Logical Account Takeover. ZACK0X01's tutorial reveals that attackers can bypass multi-factor authentication (MFA) by exploiting subtle disconnects in authentication flows. The researcher manipulates responses and leverages Insecure Direct Object References (IDOR) to gain control of any user account. By observing patterns in error messages, the researcher found opportunities to intercept MFA codes or bypass MFA checks entirely. The critical severity (CVSS ~9.8) demonstrates the devastating impact: complete account takeover and unauthorized access to sensitive data. The tutorial offers actionable insights for finding this high-impact vulnerability class in web applications. Key lesson: Look beyond syntax errors, focus on business logic flaws to master account takeovers. #BugBounty #WebSecurity #AuthenticationBypass #IDOR #AccountTakeover

    infosecwriteups.com/the-logic-

  5. WebSocket Penetration Testing: How to Test for WebSocket Hijacking, IDOR, Injection & More
    This article discusses using the WSStrike extension in Burp Suite for comprehensive WebSocket penetration testing. The vulnerability class includes WebSocket hijacking, IDOR (Insecure Direct Object References), and injection attacks. The root cause lies in weak implementation of WebSocket security measures, such as lacking proper authentication or validation checks. Researchers exploited this by intercepting WebSocket traffic using WSStrike, injecting malicious payloads to manipulate application behavior. For instance, an IDOR issue was exposed when the researcher manipulated a user's session token to access another user's data. The technical details revolve around analyzing and interacting with WebSocket communication protocols and their security flaws. The impact of these vulnerabilities can range from unauthorized access to sensitive data, account takeover, or even complete system compromise. WSStrike helped reveal a bounty of $10,000 for finding multiple critical issues in a platform. To prevent such attacks, enforce strong authentication and authorization mechanisms, validate input data, and regularly audit WebSocket implementation. Key lesson: Always prioritize security when implementing WebSocket communication. #BugBounty #WebSecurity #WebSocket #IDOR #Injection

    medium.com/@exploitersorigin/w

  6. The Logic Flaw That Leads to Total Control: Mastering Account Takeovers in 2026
    This vulnerability falls under the Authentication Bypass class, specifically Logical Account Takeover. ZACK0X01's tutorial reveals that attackers can bypass multi-factor authentication (MFA) by exploiting subtle disconnects in authentication flows. The researcher manipulates responses and leverages Insecure Direct Object References (IDOR) to gain control of any user account. By observing patterns in error messages, the researcher found opportunities to intercept MFA codes or bypass MFA checks entirely. The critical severity (CVSS ~9.8) demonstrates the devastating impact: complete account takeover and unauthorized access to sensitive data. The tutorial offers actionable insights for finding this high-impact vulnerability class in web applications. Key lesson: Look beyond syntax errors, focus on business logic flaws to master account takeovers. #BugBounty #WebSecurity #AuthenticationBypass #IDOR #AccountTakeover

    infosecwriteups.com/the-logic-

  7. 💰 Assassin’s Greed

    danstonchat.com/quote/%f0%9f%9

    Lexoun: Mec tu sais que je taffe dans le jeu vidéo ? Ben je viens d’avoir 2 mecs d’Allemagne au studio
    Lexoun: Des fous furieux, ils ont fait le chemin juste pour visiter notre studio, apparemment ils sont ultra fans
    Lexoun: Ils avaient aucun rendez-vous ni rien, juste ils ont fait 800km pour venir voir
    Une_Gaufre: C’est des fous les gens
    Lexoun: Ouais en plus j’ai rien eu le droit de leur faire visiter, ils ont vu le hall d’entrée c’est tout xD
    Lexoun: Ils étaient en mode “bon bah tant pis on va kiffer la ville et se balader alors”
    Lexoun: Mais d’un côté ça fait grave plaisir pcq ça veut dire qu’ils kiffent vraiment nos jeux
    Lexoun: Mec aucun joueur au monde n’a dû faire ça pour genre Ubisoft mdr
    Lexoun: Alors qu’on est que quelques centaines et qu’ils sont littéralement plus de 14000 salariés
    Une_Gaufre: Oué mais ubisoft si tu va là bas et que tu sonne pour rentrer
    Une_Gaufre: La sonnerie bug mec
    Une_Gaufre: Elle freeze
    Une_Gaufre: Et il y a un rapport de crash sur l’afficheur
    Lexoun: Et pour réessayer de sonner ça serait payant 2€ à chaque tentative
    Une_Gaufre: Pour ouvrir un ticket ça te dirait “Rdv à l’accueil dans nos locaux”
    Une_Gaufre: Sauf que pour rentrer il faut SONNER
    Lexoun: Tu peux débloquer la voix pour parler à l’interphone mais c’est 0,10 centimes par mot prononcé, ça apprend à être succinct et direct dans ses demandes
    Une_Gaufre: Quel monde de brutes 🙁

    #bug #erreur #fans #jeuxVidéo
  8. CW: NSFW 18+ BDSM / sensitive content

    🧔 Siap bondage telanjang di gantungan?
    🧕 Kayak ini ya! vk.cc/cUiwaI

    #bdsm #wanita #diikat #bugil

  9. #FCP 12. Analysis for Visual Search fully completed. No search returns any matches. Upon restart of FCP and retrying, FCP hangs for a minute or two on search, and then returns nothing anyway. New install of Tahoe 26.2 on a new Mac Studio M4 Max 🤷

    #bugmagnet

  10. Our kids loved playing the video from Pangea that came free with the in the early 2000s. Developer Iliyas Jorio updated the code on GitHub, and our oldest child ported it to the web and added new mods like Dance Party reallyeli.com/bugdom/Bugdom.ht

  11. Our kids loved playing the #Bugdom video #game from Pangea that came free with the #iMac in the early 2000s. Developer Iliyas Jorio updated the code on GitHub, and our oldest child ported it to the web and added new mods like Dance Party reallyeli.com/bugdom/Bugdom.ht

  12. Our kids loved playing the #Bugdom video #game from Pangea that came free with the #iMac in the early 2000s. Developer Iliyas Jorio updated the code on GitHub, and our oldest child ported it to the web and added new mods like Dance Party reallyeli.com/bugdom/Bugdom.ht

  13. Our kids loved playing the #Bugdom video #game from Pangea that came free with the #iMac in the early 2000s. Developer Iliyas Jorio updated the code on GitHub, and our oldest child ported it to the web and added new mods like Dance Party reallyeli.com/bugdom/Bugdom.ht

  14. #Antgravity - an AI code editor from Google that has access to your entire codebase and terminal had a Remote Code Execution (#RCE) vulnerability - a great find and write-up by @HacktronAI earning them $10k #BugBounty!
    #BugBountyTips
    👇

    hacktron.ai/blog/hacking-googl

  15. Bugatti „Collection Four”. Inżynieria, którą możesz nosić, nawet jeśli Tourbillon nie mieści się w garażu

    Bugatti to jedna z niewielu marek, która nawet robiąc okulary, podchodzi do tego jak do budowy silnika W16. W Mediolanie zaprezentowano właśnie „Collection Four”. I choć to „tylko” oprawki, inżynierowie z Molsheim (i ich partnerzy) znowu pokazali, że dla nich luksus to przede wszystkim technologia, tytan i obsesyjna dbałość o detale.



    Inżynieria na nosie

    Nowa kolekcja to odwrót od krzykliwych logotypów na rzecz tzw. quiet luxury (cichego luksusu). Zamiast wielkiego napisu „BUGATTI” na pół twarzy, mamy tu architektoniczną precyzję i materiały żywcem wyjęte z hypercara. Kluczem jest tytan. To z niego wykonano skomplikowane, ale ultralekkie ramki (m.in. w modelu 111, który jest nową interpretacją „aviatorów”).

    Co ciekawe, nawet tak prozaiczny element jak „noski” został przemyślany inżynieryjnie. Są wymienne – możesz wybrać wersję silikonową dla komfortu lub… tytanową, jeśli wolisz chłód metalu. Zauszniki są ultracienkie i elastyczne, co ma zapewnić dopasowanie do każdego kształtu twarzy.

    Detale dla wtajemniczonych

    Kolekcja obejmuje 7 nowych koncepcji ramek. Mamy tu połączenia octanu (acetatu) z tytanem (modele 101 i 102), a także ręcznie malowane emalią detale, w tym subtelne logo „Macaron” Bugatti. Całość zaprezentowano w Bugatti Home Atelier w Mediolanie. To sygnał, że okulary te mają być naturalnym przedłużeniem samochodu – czymś, co leży na desce rozdzielczej obok kluczyka do auta za miliony euro.

    Dostępność? Wiosna 2026. Cena? Bugatti tradycyjnie o niej nie wspomina w informacji prasowej, co zazwyczaj oznacza: „jeśli musisz pytać, to nie jest produkt dla ciebie”.

    Miliony euro w kontrolowanym poślizgu. Bugatti zabrało swoje legendy na lód w St. Moritz [galeria]

    #BugattiEyewearCollectionFour #BugattiLifestyle #luksusoweOkulary #news #okularyBugatti #oprawkiTytanowe
  16. If Claude Can Find serious cybersecurity Bug, Who Collects the Bounty?

    Bug bounty programs vs. $20/month reasoning — when the brutal question becomes: why pay five-figure bounties if a Claude Code subscription already finds entire classes of bugs? #BugBounty #VulnerabilityResearch #OffSec #AppSec #Infosec #AI #LLM #SecurityResearch #CyberSecurity red.anthropic.com/2026/zero-da

  17. Cotton Harlequin Bug on an Illawarra Flame Tree seed pod. This one is a female, the males are blue. For some reason they seem to really like these pods and are often visible on them.

    #insect #bugsofmastodon

  18. Auch wenn es keine BUGA im Norden gibt: Der Staddrat unterstützt auf Antrag von @Lichdi einstimmig die Idee eines „Nordpark Dresden".
    #buga #dresden

    Die Ganze Rede unter:

    youtu.be/Fwccd2HKJS8

  19. Auch wenn es keine BUGA im Norden gibt: Der Staddrat unterstützt auf Antrag von @Lichdi einstimmig die Idee eines „Nordpark Dresden".
    #buga #dresden

    Die Ganze Rede unter:

    youtu.be/Fwccd2HKJS8