GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Jamie (suprjami@fosstodon.org)'s status on Wednesday, 07-Jun-2023 21:27:13 JST Jamie Jamie

    The new ".zip" domain is being used almost solely for malware. Some of the clicks are very deceptive, even to technically knowledgeable people. See the attached image for an example.

    You can block all zip domains with the following uBlock Origin rule:

    ||zip^

    Tell everyone you know.

    In conversation Wednesday, 07-Jun-2023 21:27:13 JST from fosstodon.org permalink

    Attachments


    1. https://cdn.fosstodon.org/media_attachments/files/110/381/687/421/221/085/original/dd8f996ad0ce5c38.png
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Wednesday, 07-Jun-2023 22:54:03 JST feld feld
      in reply to
      • Jim
      Show me a browser that parses that URL in such a way that everything before the @ is treated as HTTP Basic authentication?
      In conversation Wednesday, 07-Jun-2023 22:54:03 JST permalink

      Attachments


      1. https://media.bikeshed.party/pleroma/3ab95ad62213e52d792660ab005fcd68fa42ff6a0ad14bffa6261a96a99915ea.png
    • Embed this notice
      Jim (sullybiker@sully.site)'s status on Wednesday, 07-Jun-2023 22:54:04 JST Jim Jim
      in reply to

      @suprjami Didn't virtually every infosec person say this would happen?

      In conversation Wednesday, 07-Jun-2023 22:54:04 JST permalink
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Wednesday, 07-Jun-2023 22:58:19 JST feld feld
      in reply to
      • feld
      • Jim
      Let's try trurl, the URL parsing logic for Curl

      oh look, it does the right thing too
      In conversation Wednesday, 07-Jun-2023 22:58:19 JST permalink

      Attachments


      1. https://media.bikeshed.party/pleroma/badf0d61660056e2ffbb7d1904c2d9901f4fef0bb29415624f0fdea233660770.png
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Wednesday, 07-Jun-2023 23:03:28 JST feld feld
      in reply to
      • feld
      • Jim
      Ruby:
      In conversation Wednesday, 07-Jun-2023 23:03:28 JST permalink

      Attachments


      1. https://media.bikeshed.party/pleroma/1fcdc94e81c6f64408a65eabf34b41dbd2c5a67d3c4ba3eb074599b548a48764.png
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Wednesday, 07-Jun-2023 23:05:24 JST feld feld
      in reply to
      • feld
      • Jim
      Python urllib3
      In conversation Wednesday, 07-Jun-2023 23:05:24 JST permalink

      Attachments


      1. https://media.bikeshed.party/pleroma/798e6628748b9fff1c74e60ee25f4418ca9265349bc559fe253641c4b07c2a97.png
    • Embed this notice
      Doughnut Lollipop 【記録係】:blobfoxgooglymlem: (tk@bbs.kawa-kun.com)'s status on Wednesday, 07-Jun-2023 23:11:15 JST Doughnut Lollipop 【記録係】:blobfoxgooglymlem: Doughnut Lollipop 【記録係】:blobfoxgooglymlem:
      in reply to
      • feld
      • SlicerDicer
      @SlicerDicer @feld https://12022021endofinternet.com/
      In conversation Wednesday, 07-Jun-2023 23:11:15 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        12022021 End of Internet
        from 12022021 End of Internet
        End of Internet
    • Embed this notice
      SlicerDicer (slicerdicer@bikeshed.party)'s status on Wednesday, 07-Jun-2023 23:11:16 JST SlicerDicer SlicerDicer
      in reply to
      • feld
      @feld Still confused if paper is the problem or not.

      In the meantime? The solution is to ban the internet.
      In conversation Wednesday, 07-Jun-2023 23:11:16 JST permalink

      Attachments


      1. https://media.bikeshed.party/pleroma/a4810a6a9a89787b5f0705953a17cb871a2f3278e6db434db552bd4e3dc7ebcb.jpeg
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Thursday, 08-Jun-2023 12:32:52 JST feld feld
      in reply to
      • Der Teilweise
      Ok, but this is a problem that can be solved with a tiny patch that won't break anything: disallow HTTP basic auth embedded in URLs if any character codepoint is > 127. Require a pop up to enter the user/pass or just give an error about an invalid URL.

      Unicode characters here should definitely need to be explicitly encoded as base64 for the Authorization header.

      Anyone who *needs* this to work with Unicode characters can piss off. I'm willing to bet the RFCs don't have any MUST or SHOULD that mention non-ASCII characters be allowed here.

      Tada, we fixed it and everyone can put down their keyboards and stop crying about new TLDs
      In conversation Thursday, 08-Jun-2023 12:32:52 JST permalink
    • Embed this notice
      Der Teilweise (teilweise@layer8.space)'s status on Thursday, 08-Jun-2023 12:33:00 JST Der Teilweise Der Teilweise
      in reply to
      • feld

      @feld Try to copy & paste this URL: https://github.com∕kubernetes∕kubernetes∕archive∕refs∕tags∕@v1271.zip
      (Not everything that looks like a ∕ is a /.)

      The problem with .zip is that it is widely seen as a “safe” extension. (Otherwise .com would have been an even bigger problem …)

      In conversation Thursday, 08-Jun-2023 12:33:00 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: github.githubassets.com
        GitHub: Where the world builds software
        GitHub is where over 83 million developers shape the future of software, together. Contribute to the open source community, manage your Git repositories, review code like a pro, track bugs and feat...

      2. https://files.layer8.space/media_attachments/files/110/503/629/899/937/741/original/4595359165784fd7.png
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Thursday, 08-Jun-2023 22:25:39 JST feld feld
      in reply to
      • Der Teilweise
      @teilweise Stop using basic auth and join us in the 21st century. It's not like you couldn't just change your username.

      If you were using LDAP, AD, Kerberos, OAuth, OpenID, etc you wouldn't be able to use HTTP Basic auth anyway.

      Complaining that you can't use Unicode characters that didn't even exist when the RFC was written is hilarious though.
      In conversation Thursday, 08-Jun-2023 22:25:39 JST permalink
    • Embed this notice
      Der Teilweise (teilweise@layer8.space)'s status on Thursday, 08-Jun-2023 22:25:41 JST Der Teilweise Der Teilweise
      in reply to
      • feld

      @feld Sure, I’ll change my name to not contain unicode characters.

      Nobody needs unicode. Actually, BCDIC was good enough. Nobody needs uppercase characters in URLs.

      It’s OK, I will just piss off.

      Welcome to the kill file.

      In conversation Thursday, 08-Jun-2023 22:25:41 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        http://URLs.It/
    • Embed this notice
      hypolite (hypolite@friendica.mrpetovan.com)'s status on Friday, 23-Jun-2023 13:03:38 JST hypolite hypolite
      in reply to
      • musenhain
      @musenhain @suprjami Funnily enough, your first URL isn’t what what written in the image. Notice how the forward slashes in the first path are more angled the first two after “http:”, which means they are special characters actually part of the domain name with the .zip top-level domain.
      In conversation Friday, 23-Jun-2023 13:03:38 JST permalink
    • Embed this notice
      musenhain (musenhain@friendica.andreaskilgus.de)'s status on Friday, 23-Jun-2023 13:03:40 JST musenhain musenhain
      in reply to

      @suprjami Content of image:
      "Can you quickly tell which of the URLs below is legitimate and which one is a malicious phish that drops evil.exe?

      github.com∕kubernetes∕kube…

      github.com/kubernetes/kubernet…

      [Edit: Corrected the slashes being part of the domain name in the first link. Hint by @hypolite@friendica.mrpetovan.com]

      In conversation Friday, 23-Jun-2023 13:03:40 JST permalink
    • Embed this notice
      hypolite (hypolite@friendica.mrpetovan.com)'s status on Friday, 23-Jun-2023 21:46:00 JST hypolite hypolite
      • musenhain
      • this.ven
      @thisven @musenhain @suprjami Funnily enough #Friendica ‘s automatic URL linker in posts doesn’t match the malicious link:
      In conversation Friday, 23-Jun-2023 21:46:00 JST permalink

      Attachments


      1. https://friendica.mrpetovan.com/photo/491946420764957fcada644775498509-0.png

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.