HN user

xSwag

1,512 karma

I like breaking into things

Posts55
Comments180
View on HN
application.security 6y ago

How Directory Traversal Attacks Work (Real World Example)

xSwag
1pts0
application.security 6y ago

Show HN: Easy to Understand Software Security Training

xSwag
36pts3
github.com 11y ago

Rails is great! Thank you

xSwag
5pts0
krebsonsecurity.com 11y ago

Counterfeit U.S. Cash Floods Crime Forums

xSwag
3pts0
scanbeast.com 11y ago

Show HN: Vulnerability scans for WordPress. No installation or code required.

xSwag
12pts14
www.gq.com 12y ago

50 Cent Is My Life Coach

xSwag
3pts0
j2kun.svbtle.com 12y ago

You never did math in high school

xSwag
160pts176
blog.kotowicz.net 12y ago

XSS in Gmail through Rapportive

xSwag
110pts13
squid314.livejournal.com 12y ago

Epistemic learned helplessness

xSwag
2pts0
www.theatlantic.com 12y ago

Your Brain on Poverty: Why Poor People Seem to Make Bad Decisions

xSwag
2pts1
www.google.com 12y ago

Safe Browsing Diagnostic page for Google.com

xSwag
2pts0
terrytao.wordpress.com 12y ago

An improved Type I estimate

xSwag
1pts0
blog.practicalethics.ox.ac.uk 12y ago

There are no significant facts about human beings

xSwag
2pts0
en.wikipedia.org 12y ago

Ultrafinitism

xSwag
1pts0
boingboing.net 12y ago

Warren Buffet explains why you can't beat the market

xSwag
1pts1
www.theguardian.com 12y ago

It's the 21st century – why are we working so much?

xSwag
2pts0
blog.k3170makan.com 12y ago

NoNoScript : ByPassing NoScript's XSS filters via Error Basd SQLi (2012)

xSwag
1pts0
math.stackexchange.com 13y ago

If x is a fraction, x^x and x^x^x are irrational. But can x^x^x^x be rational?

xSwag
68pts42
www.joshcollie.com 13y ago

You do not understand

xSwag
2pts0
bostonreview.net 13y ago

New research shows undocumented immigrants don't hurt low-skill workers' wages

xSwag
1pts0
www.microsoft.com 13y ago

Enhanced Mitigation Experience Toolkit v4 Beta is out

xSwag
1pts0
www.economist.com 13y ago

Doctoral degrees: The disposable academic (2010)

xSwag
77pts88
www.dz.ru 13y ago

The Phantom Operating System

xSwag
2pts0
www.bbc.co.uk 13y ago

MPs challenge Google over UK tax reporting

xSwag
2pts0
www.theregister.co.uk 13y ago

LulzSec hackers jailed

xSwag
49pts24
www.wired.co.uk 13y ago

Wikipedia page views could predict stock market changes

xSwag
1pts0
www.bbc.co.uk 13y ago

Amazon beats Google in China with paid Android apps

xSwag
1pts0
www.bbc.co.uk 13y ago

UK households 'borrowing to eat'

xSwag
1pts0
seclists.org 13y ago

[CVE-2013-1601] An ASCII output of the live video stream can be accessed

xSwag
3pts0
www.thecrimson.com 13y ago

The economics of Game of Thrones

xSwag
2pts0

IMO there should be some sort of header like

    x-whitehat: autopatch
which gives white-hats the opportunity to patch your system without exploiting. The why I see it, a malicious person is going to exploit your server anyway. This way white-hats could patch your system and not be prosecuted. With this, someone who discovered the patch could scan the internet, look for servers that say "yes, please patch me" and deploy a quick patch and nothing else.

The all-you-can-eat is capped (small print) at a "fair usage" of 25 Gb/month.

I can tell you that this is wrong, I've personally had months where I've used 100GB+ of data over 3G and had no problems (this is on a £15 top-up). I don't know if they throttle or not, I've never really noticed it.

Tethering is disabled while roaming overseas on "feel at home", but not prevented at home.

I didn't get my handset from Three but I've been able to tether in Paris and used at least 2GB when I was there.

Hi, thanks for the feedback. I've asked for credit card details to prevent the abuse of this service since you can scan any website.

However, I'm currently in the process of working with the Google Analytics API to provide free scans for verified websites where the user can prove ownership -- this should roll out in about a week or so. Would you like me to drop you a PM when I release this feature?

Hi everyone, this is the MVP I have been working on. It's almost 5am in the UK right now and I just wanted to launch as soon as possible and stop procrastinating (and waiting for my A-level results). It's funded entirely by my Google bug bounties, so thank you Google. I have not done any design stuff for it yet -- the site is very bare bones but functional.

Current solutions to vulnerability scanning such as WPscan are good but not user-friendly -- which is what I believe what WordPress users want. I've already got my first 5 customers prior to launch that wanted this product which I think is a good start, hopefully there is a market for this stuff.

I would love to hear any sort of feedback.

I built a security scanner that scans WordPress installations for threats (plugin vulns, outdated installs, theme vulns, xss, sqli etc) without any installation or code knowledge required. I posted it on Reddit and got a few sign ups, after that I just got bored and I'm not sure what to do next. I'm thinking about partnering with WordPress tutorial websites and give them a recurring revenue cut or something. I really wish I was better at marketing products. Maybe I should just sell it or something. Any WordPress related websites with good amount of traffic please contact me if you're interested in partnering.

No.

Simple logic: The defacement was amature at best. If the group has a 0-day in a hypervisor they would have gone to multiple hosting companies and multiple attacks would have taken place, there are many more targets that are worth much more than openSSL.

Most likely, the administration panel of the hosting company was comprimised through malware/phishing. Seriously, if a group like this had a 0-day in hypervisor then they would be doing much much more damage.

Find Friends Abuse 13 years ago

There is an easier way to solve this issue: Bug Bounty.

It worked for Google, it worked for Facebook and its working for Yahoo! Infact, it worked so well for Google that they recently increased the rewards. A venture-backed startup like Snapchat that stores private pictures (even temporarily) should have no trouble paying out $5k a few times for vulnerabities.

Skype blog hacked 13 years ago

This blog is not hosted by the Skype but on WordPress VIP. This means that, most likely, the blog was not broken into using a software exploit of any sort since the security on VIP blogs is professional. Knowing that this is the Syrian Army, this attack was most likely done using phished credentials.

If they had any sort of system access they would have defaced the entire subdomain or the main site. So most likely, this is nothing to worry about. Your account data most likely still in safe hands.

TL;DR: In the DigitalOcean web panel you can check the "scrub data" checkbox when destroying a VM. When using the API this option is not ticked. This can lead to other customers being able to retrieve your data.

The author thinks that this is a security issue because this option should be enabled by default. However, (I assume) it's not in Digital Oceans interest to do full disk scrub because it reduces the lifespan of their SSD.

If a user forgets to log out of Facebook on a public computer, is it Facebook's responsibility? Similarly, if a user does not correctly delete data on a budget host, is it the hosts fault?

I'm working on a freemium SaaS which provides security for WordPress based websites. It remotely scans for vulnerabilites in your wordpress website the same way an attacker would and notifies you. Zero programming knowledge required. No installation required.

I need more money for the servers so I'm currently waiting for my Google bug bounty to come through (it's been over 6 weeks!) so I can fund a security startup with security money from Google.

[dead] 13 years ago

I assume most people on HN don't know whats going on so I'll chip in what I know:

The admin, allegedly this Thomas guy, ran off with 17k BTC which is worth around $15M right now. Nobody is able to transfer their bitcoin out of sheep either. Everybody is pissed off so people are attacking his server and trying to "dox" the person. Here is the address where the money has gone:

https://blockchain.info/address/1Cwb33nqn4S2uDsXwhNrUNy7FPdi...

If anybody is interested, check out the sheep subreddit, lot's more information on the issue there.