views.py

11.7K posts

views.py banner
views.py

views.py

@p_factorial01

In your face Katılım Haziran 2015
459 Takip Edilen473 Takipçiler
views.py
views.py@p_factorial01·
@no_stp_on_snek Let me guess, combination of Triattention and turboquant?
English
1
0
0
55
views.py retweetledi
Tom Turney
Tom Turney@no_stp_on_snek·
turboquant+ community momentum is real right now 6 independent researchers contributed findings in the last 24 hours on the llama.cpp research discussion. different hardware, different forks, different people, same conclusions. thread 🧵
Tom Turney tweet media
English
9
11
180
11.6K
views.py
views.py@p_factorial01·
@boye4christ2006 Accumulation of rent is not how you get your capital back. Selling the property is how you get your capital back
English
0
0
8
138
views.py
views.py@p_factorial01·
@boye4christ2006 You're looking at it wrongly The rent you collect - your maintenance expenses = pure profit The (house + land) still holds its value (and have probably appreciated in value) If you were to liquidate (sell) the property, you would have your 25m+ and the Collected rents
English
4
1
28
848
folowosele adeboye
folowosele adeboye@boye4christ2006·
I’m talking from experience. I am a landlord in Nigeria, and I invested over ₦25 million in building the house. Each tenant pays ₦350,000 per year, yet I have not recovered even ₦1 million of my investment. Many tenants leave after two years, and most of the time I end up spending the rent I collect on renovations, repairs and many things. As a result, I hardly make any profit.
folowosele adeboye@boye4christ2006

Building houses to rent in Nigeria wil NEVER be a profitable business.

English
454
341
2.1K
437.8K
views.py
views.py@p_factorial01·
Make we check everybody's old tweets abeg We need to know who is who 😂
English
0
0
0
21
views.py
views.py@p_factorial01·
@Kuro_Lytes Yep, the developer describes a very rookie mistake Backend validates all requests.
English
1
0
2
44
Chaos Magician
Chaos Magician@Kuro_Lytes·
All client side encryption can and will be bypassed. Easiest way: Setting breakpoints in a browser's developer tools How to prevent OTP bypass? 1. Enforce rate limits and/or increase complexity of OTP and/or reduce its lifespan ( 2 out of 3 is good for most cases) 2. Validation should be on the backend. On successful validation, the only change should be to the user's session (basically "mark" the current user's session as logged in). 302 redirect to the logged-in homepage if the OTP is correct (no response payloads, those can be spoofed)
P. Tech bro@ptech3net

So regarding the OTP bypass? To start with, the first and best approach is to stay calm and not take anything reported by a security tester as a personal attack or start arguing with them. 😂😂 Now, the second approach goes like this 🤭 since the response body from the backend that contains status field can also be manipulated, it means the frontend shouldn’t rely solely on either the HTTP status code or the response body alone. 😂🤲 Fear those people! What do you think about using encryption? I mean, don’t expose raw data from the backend , encrypt the response body and let the frontend decrypt it once it’s received. That way, the response can’t be tampered with because it’s encrypted (unless your encryption credentials are compromised). With that, the frontend can safely rely on both the status code and the response body. Let me know your approach , your contribution matters a lot. Thank you all! 🙏

English
1
0
7
640
views.py retweetledi
Tomi
Tomi@tomiwebstr·
102
1.3K
5.3K
156.2K
views.py retweetledi
stän
stän@prev_doxxed·
Imagine going to school then telling your classmates aero plane almost hit your daddy
English
1
0
0
98