zeØ_Øn256

1.9K posts

zeØ_Øn256 banner
zeØ_Øn256

zeØ_Øn256

@zeon256

🇸🇬 | software gangster. cs @NTUsg 25. 🦀 rust fan club | open to roles in sg/sf/lon

ap-southeast-1 Katılım Haziran 2015
430 Takip Edilen51 Takipçiler
mRr3b00t
mRr3b00t@UK_Daniel_Card·
there seems to be some fun debate about Edge and it's storing all the passwords in RAM in clear text, vs chrome which stores the passwords upon use (e.g. one at a time) in RAM.... but chrome also stores the passwords in an SQL Lite file and the keys are protected by DPAPI! Guess what a userland process can do? It can get the keys! It can decrypt! Now you might be thinking... that's not true.... so let's see: to D LAB!
mRr3b00t tweet media
English
19
28
233
24.3K
vx-underground
vx-underground@vxunderground·
The initial proof-of-concept was released in C-sharp. Using this method to dump credentials is iffy because it requires administrative access and some security access tokens which can raise some flags. First, Edge is Chromium based. This is a Chromium thing but (if my memory serves me correctly) a unique attribute to Edge exclusively. However, because it is Chromium based this may impact other Chromium bases. It requires more investigation. Edge is a primary target because it's the default Windows browser and used in enterprise environments. Secondly, as far as malware goes, this is yet another method to potentially dump credentials on a home users machine. There are a few different ways. This method doesn't surprise me. However, successfully using this method is an enterprise environment would be difficult to use. It would require administrative access and some security access tokens which would immediately raise some flags. In other words, this method is interesting, I like the research performed, however it isn't something super super critical. If you're using this method in an enterprise environment then that company has been completely compromised down to the bone and they've got much larger issues. The code and research is really cool though. I just wish it wasn't written in C-sharp (I have an irrational disdain to .NET, especially lately).
International Cyber Digest@IntCyberDigest

‼️🚨 Microsoft calls this "intended behaviour," so here we go. How to dump the credentials of every user stored in Microsoft Edge: 1. Open Edge. Don't browse anywhere, just open it. 2. Flip to Task Manager, find Edge, expand the task. 3. Highlight the "browser" sub-task, right-click, and choose "Create Memory Dump." 4. Open the dump file and look for credentials. The logged-in Windows user can dump every stored Edge credential with no additional rights. Which means any malware that user executes has those credentials for the asking. Thanks to Rob VandenBrink at SANS: isc.sans.edu/diary/32954

English
34
60
692
70.4K
HSVSphere
HSVSphere@HSVSphere·
Lunduke has apparently lost his account to an engagement farming Indian. Who do you think is most likely to lose his account next? - trish - kai_fall v3 - tetsuo - rjfleury
HSVSphere tweet media
English
40
11
555
20.7K
zeØ_Øn256 retweetledi
Zed
Zed@zeddotdev·
Code lens support lands in stable .... tomorrow! 🎉
English
45
54
1.7K
79.6K
zeØ_Øn256
zeØ_Øn256@zeon256·
This corpus is great, probably wanna try to do something with PGO with it to see if it can be optimised even further but I highly suspect not
English
0
0
0
11
zeØ_Øn256
zeØ_Øn256@zeon256·
Added real corpus benchmark for my robots.txt parser! Cant comment how fast it is against other libraries in other languages cos i havent run them on my machine, perhaps that will be the next thing i would do
zeØ_Øn256 tweet media
English
2
0
0
21
zeØ_Øn256
zeØ_Øn256@zeon256·
Surprised how fast the m1 macbook air is compared to my Ryzen 5800x3D. In fact it runs faster than my desktop lol for this particular benchmark
English
0
0
0
56
zeØ_Øn256
zeØ_Øn256@zeon256·
@glcst it’s always the users that pay the least that are the loudest 🙃
English
0
0
5
183
Glauber Costa
Glauber Costa@glcst·
Turso has the most generous plans on the market. We just announced unlimited databases on every plan yesterday. We give our users - and will continue giving them - lots for free. Because our architecture allows it. But I really dislike this level of entitlement. He needs help *urgently*. We *need to understand that his users will churn*. And now he is shitting on us on X. The reason ? He used up his very generous free tier quota. The solution ? Pay us $5.99 a month. I am in fact okay if this is considered too much and he decides to churn. But he can't pay 5.99 *now* to export his data and solve this very urgent problem that is taking his *production* down. And we need to stop everything we are doing to help him *now* Sorry bro. In situations like this we actually sometimes will just give you an export for free if you really want to go. Not for you. Here is the email that this person just sent to our support: "I am not able to access the production DB, manually. I am not even able to see the Data. I hope you understand that without the data, my customers are going to leave the product if this issue persists any longer. I wasn't aware of the free read limit clause, and now it is very uncomfortable for me as I am not even able to view/access my own product's data. All I want to do is access the db and make a copy of it. I need your help urgently."
English
4
2
61
10.7K
iamEvan
iamEvan@iamEvanYT·
@mitsuhiko wonder how much their cost is. opus can't be cheap
English
1
0
1
2.3K
Armin Ronacher ⇌
Armin Ronacher ⇌@mitsuhiko·
Five minutes after reporting a bun bug. Both cool and disturbing :D
Armin Ronacher ⇌ tweet media
English
12
7
374
34K
Goreng
Goreng@sudo_goreng·
@zeon256 tried it, too slooooooow.
English
1
0
0
60
Goreng
Goreng@sudo_goreng·
ah, I forgot to renew it :/ welp, I guess I have to deal with ollama's cloud speed for a while now
Goreng tweet media
English
4
0
6
1.1K
zeØ_Øn256
zeØ_Øn256@zeon256·
yo wtf chatgpt image is kinda lit
zeØ_Øn256 tweet media
English
0
0
0
22
Shaz
Shaz@shazcodes·
I interviewed a senior dev today. He wanted a $250k salary. I gave him a complex system design task. He had 30 minutes. He started drawing diagrams on the board and talking about scalability. I just opened a prompt. I fed it the requirements. I had the full boilerplate and unit tests in 15 seconds. I turned the monitor around. I asked him: Why would I pay you $250k when I just did your month's work for 2 cents? He didn't even answer. He just packed his bag and walked out. If you can’t outperform an API, you aren't an engineer. You’re just an expensive liability.
English
136
11
254
702.3K
zeØ_Øn256 retweetledi
Guido van Rossum
Guido van Rossum@gvanrossum·
Everybody is adding a feature where you can manage your agents from your phone. Don't use it. You'll just get even more addicted, and will burn out even quicker.
English
82
192
1.8K
251.4K
zeØ_Øn256 retweetledi
Bun
Bun@bunjavascript·
In the next version of Bun `Bun.Image` - fast builtin multi-format image processing library
Bun tweet media
English
201
302
5.3K
1.7M
zeØ_Øn256
zeØ_Øn256@zeon256·
Using AT protocol for code repo is quite an interesting idea
Tangled@tangled_org

The future of code collaboration should be federated. Host code on your own servers, and own the associated "metadata" (issues, pulls, artifacts, …)—all with a shared identity. Don't get burned by centralized platforms again! Join tangled.org today. We've got a ton of cool stuff on the horizon, *including* first-class vouching (@mitchellh pioneered this!), shipping next week.

English
0
0
0
8
zeØ_Øn256
zeØ_Øn256@zeon256·
Classic lunduke L
The Lunduke Journal@LundukeJournal

Remember the security firm that Ubuntu hired to audit the (ill-advised, highly buggy) Rust-rewrites of all of the GNU Coreutils? Turns out that security firm is run by @gf_256, who: - Appears to be a man who thinks he's a woman ("trans"). - Uses an anime cartoon of a girl as his avatar. - Appears to have an OnlyFans page. I repeat: Ubuntu hired a "Trans" man, with an anime girl avatar and an OnlyFans page... to audit Rust code. It's hard to get more on-the-nose than that.

English
0
0
1
73