HN user

SpikedCola

311 karma
Posts16
Comments113
View on HN

Ahhh very interesting! Thanks for pointing this out, I saw an attack against one of our sites this weekend using this exploit.

data: {'requests': [{'method': 'POST', 'path': 'http://:'}, {'body': {'requests': [{'method': 'GET', 'path': 'http://:'}, {'method': 'GET', 'path': '/wp/v2/widgets?author_exclude=1%29+AND+1%3D0+UNION+ALL+SELECT+0%2C1%2C0x323...

I would love to find a circular LCD (even down to 1 or 2 inches across) that has a hole in the center, to be able to use it with a needle/stepper motor.

If you wouldn't mind, I would be curious - if you run the above curl command, do you get the same error?

It could be a combination of IP + user agent (+ something else) that's causing me trouble.

I can't access virtualbox.org any more, they now show an error page saying "Payment Required", with status code 402.

Interestingly, if I change my user agent to "curl/7.70.0", I can browse virtualbox.org again.

They seem to be unhappy with my user agent specifically:

  curl -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" https://www.virtualbox.org 
  
  <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
  <html><head>
  <title>402 Payment Required</title>
  </head><body>
  <h1>Payment Required</h1>

Not sure why, but the text doesn't appear in Chrome 109: https://imgur.com/a/QyIdfax

If I disable "font-family: Atkinson" it comes back, so guessing it's font related. I do see the two .woff files load in the Network tab. Interestingly, when I preview either font file, I see the sample of the font (AaBbCc etc.) in a flash for just milliseconds, and then it disappears and I see nothing.

  // Vidrun, born of the sea-wind through the spruce
  // Vidrun, green-tinged offshoot of my bough, joy and burden of my life
  // Vidrun, fierce and clever, may our clan’s wisdom be yours:
  //
  //     Never read Hacker News
  // - Aphyr, "Hexing the technical interview"
  if (document.referrer.startsWith("https://news.ycombinator.com")) {
      document.location = "https://upload.wikimedia.org/wikipedia/commons/d/d4/Human_fart.wav"
  }
> https://www.boringcactus.com/assets/site.js

In the same way, Apple is equally difficult about forcing the use of Apple Maps.

If you receive an address in an iMessage, clicking/long-holding will always open in Apple Maps. There is no way to share to Google Maps (it doesn't appear in the list), and the default setting to use Google Maps doesn't affect iMessage.

You have to copy the address, switch to Google Maps, paste it in, and search. I would much prefer clicking the address to open in the app of my choice.

I did exactly this when I built my shed (with the same justification) - running fiber in the same conduit as the power to the shed.

But, I found out during inspection that the Canadian Electrical Code prohibits this, unless the fiber is functionally related to the power lines it is running with (section 56-200).

The explanation I received for the rule, was that someone like a telco installer could try and follow the fiber line, and find themselves in a dangerous situation (inside an electrical panel they aren't trained to handle).

I was able to get an exception since I am the only one who will ever open the cabinets/work on this fiber, since it was not the main internet feed to the house, but just to an outbuilding.

Guess this is a few weeks old, and I missed the news.

What a shame - this was the only place in recent memory where I could talk directly with "level 2+" tech support for my ISP.

Additional confirmation:

---

We have thoroughly checked the issue reported by you and we would like to confirm, that there is indeed a bug in our system. As a result, modification rights for the domain are not removed when the domain is sold or pushed to another Namecheap account. Regrettably, we do not have any ETA on the fix at the moment.

Today I recieved this response from Namecheap support, confirming that my account had unauthorized access to a domain after it was sold in the marketplace:

---

I can see that the domain you mentioned is still shared and can be managed by your account, even though it was sold via our Marketplace. It will take a while to investigate the case properly and fix the bug.

I'll ask the team to keep you updated on the progress. As for the domain itself, due to security reasons, we'll need to revoke your access to it.

---

Anyone who has bought a domain through the "sell domain" feature - you should immediately check for unauthorized access to your domain(s).

Hi tamar,

You have brought up what is precisely my concern, and what I couldn't convey to support.

If I open a ticket with the domain name, what's to stop the access being removed, and declaring "problem solved", without actually addressing the underlying issue?

Either delegated access remaining after a sale is a mistake (in which case there is now "unauthorized access"), or it's "by design" (in which case users should be made aware so they can remove this access after buying a domain). Regardless, I think you shouldn't need to know the specific domain in order to say which situation it is.

McMaster-Carr won’t sell to small companies, my friends and I have tried several times, only to have orders cancelled for the above-mentioned reason. It’s a shame because their website has a wealth of information (CAD drawings, measurements, etc.), one of the best I’ve seen.