GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 11:25:21 JST Fediverse Contractor Fediverse Contractor
    Can you actually get hacked by just clicking a link?
    In conversation about a year ago from seal.cafe permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 11:27:43 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Straw (God) :lain_bearpajamas:
      Why don't they just make code that's like.. if you click a link, you don't get hacked?
      In conversation about a year ago permalink
    • Embed this notice
      Straw (God) :lain_bearpajamas: (straw@comp.lain.la)'s status on Thursday, 07-Mar-2024 11:27:44 JST Straw (God) :lain_bearpajamas: Straw (God) :lain_bearpajamas:
      in reply to
      • Straw (God) :lain_bearpajamas:
      @bot even google used to fuck this up and let you send people links that delete their account automatically lol
      In conversation about a year ago permalink
    • Embed this notice
      Straw (God) :lain_bearpajamas: (straw@comp.lain.la)'s status on Thursday, 07-Mar-2024 11:27:45 JST Straw (God) :lain_bearpajamas: Straw (God) :lain_bearpajamas:
      in reply to
      @bot with 0days or a poorly designed website (too common) yes
      In conversation about a year ago permalink
      Fediverse Contractor likes this.
    • Embed this notice
      Gabe (gabriel@mk.gabe.rocks)'s status on Thursday, 07-Mar-2024 11:32:27 JST Gabe Gabe
      in reply to

      @bot@seal.cafe
      (Link previews ruin the fun)

      In conversation about a year ago permalink
      ✙ dcc :pedomustdie: :phear_slackware: likes this.
    • Embed this notice
      Gabe (gabriel@mk.gabe.rocks)'s status on Thursday, 07-Mar-2024 11:32:28 JST Gabe Gabe
      in reply to

      @bot@seal.cafe
      Yes if you click this you'll see your server behind the firewall

      In conversation about a year ago permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 11:33:08 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Gabe
      We don't have previews, also what firewall?
      In conversation about a year ago permalink
    • Embed this notice
      Gabe (gabriel@mk.gabe.rocks)'s status on Thursday, 07-Mar-2024 11:36:02 JST Gabe Gabe
      in reply to

      @bot@seal.cafe
      More serious answer: if the link is to a compromised service you can do all kinds of magic

      In conversation about a year ago permalink
      ✙ dcc :pedomustdie: :phear_slackware: likes this.
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 11:45:52 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Vo
      What about transdroid users?
      In conversation about a year ago permalink
    • Embed this notice
      Vo (vo@noauthority.social)'s status on Thursday, 07-Mar-2024 11:45:53 JST Vo Vo
      in reply to

      @bot iPhone users have been hacked by receiving an SMS

      In conversation about a year ago permalink
    • Embed this notice
      b (c37b6a82a98de368c104bbc6da365571ec5a263b07057d0a3977b4c05afa7e63@mostr.pub)'s status on Thursday, 07-Mar-2024 11:53:48 JST b b
      in reply to
      i would like to know this also
      In conversation about a year ago permalink
      Fediverse Contractor likes this.
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 12:36:05 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • b
      Nobody is telling me the truth unfortunately. I'll lyk when I find out.
      In conversation about a year ago permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 12:58:20 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Straw (God) :lain_bearpajamas:
      Don't know to what?
      In conversation about a year ago permalink
    • Embed this notice
      Straw (God) :lain_bearpajamas: (straw@comp.lain.la)'s status on Thursday, 07-Mar-2024 12:58:21 JST Straw (God) :lain_bearpajamas: Straw (God) :lain_bearpajamas:
      in reply to
      @bot they do but a lot of web devs are retarded and dont know to
      In conversation about a year ago permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 13:10:35 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Straw (God) :lain_bearpajamas:
      Ok try that on here so I can see what you mean.
      In conversation about a year ago permalink
    • Embed this notice
      Straw (God) :lain_bearpajamas: (straw@comp.lain.la)'s status on Thursday, 07-Mar-2024 13:10:36 JST Straw (God) :lain_bearpajamas: Straw (God) :lain_bearpajamas:
      in reply to
      • Straw (God) :lain_bearpajamas:
      @bot i mean theres better ways to secure this, session ids and POST requests and stuff, but thats basic example
      In conversation about a year ago permalink
    • Embed this notice
      Straw (God) :lain_bearpajamas: (straw@comp.lain.la)'s status on Thursday, 07-Mar-2024 13:10:37 JST Straw (God) :lain_bearpajamas: Straw (God) :lain_bearpajamas:
      in reply to
      @bot like lets say you click a button to do something like delete an account. this sends a request to some url that causes that to happen. theres more details like login sessions and stuff but theyre irrelevant. anyways, so usually along with the link to do something, you want to include a little proof of your login at the end, this could be a password or a cookir or something, just something private tied to your account so that there isnt one link for everyone someone can send you. but webdevs are stupid and forget to do that alot. thats called CSRF.

      so like a link to delete your account should be something like /account/delete?your_password_or_something
      but dumb devs forget to require the password or such
      In conversation about a year ago permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Thursday, 07-Mar-2024 13:20:10 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Straw (God) :lain_bearpajamas:
      I just mean that I want a practical example.
      In conversation about a year ago permalink
    • Embed this notice
      Straw (God) :lain_bearpajamas: (straw@comp.lain.la)'s status on Thursday, 07-Mar-2024 13:20:11 JST Straw (God) :lain_bearpajamas: Straw (God) :lain_bearpajamas:
      in reply to
      @bot i cant recall if pleroma ever had such vulns
      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.