Notices by silverwizard (silverwizard@convenient.email), page 7
-
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 06:10:42 JST silverwizard @hypolite I think it's just that browser vendors are unwilling to support them properly, and generally there's a generic trust in the local source. It's also complex as browers are also a mess of JS and local user scripts are a very normal part of browsing these days, since most people are using extensions to their browser. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 05:07:06 JST silverwizard @hypolite Trying adding self to any of the sources could not cause the script to not execute. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 04:52:20 JST silverwizard @hypolite But it ran! -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 04:37:19 JST silverwizard @hypolite Ran it in Chrome and Firefox as well. Also changed the CSP to default-src: 'none' script-src: 'none' and got the same results in LibreWolf. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 04:33:45 JST silverwizard @hypolite Ok - actually
I ran
HTTP/1.0 200 OK Date: Tue, 22 Oct 2024 19:27:37 GMT Server: OpenBSD httpd Connection: close Content-Type: text/html Content-Length: 486 Location: localhost Content-Security-Policy: script-src: 'none' <html> <head>Hello</head> <body> <script>alert("OH NO");</script> </body> </html>
cat test.txt | nc -l -p 2000
with test.txt containing(Ignore the fake content length)
I then pointed my browser at it, and it saw these response headers:
HTTP/1 200 OK Date: Tue, 22 Oct 2024 19:27:37 GMT Server: OpenBSD httpd Connection: close Content-Type: text/html Content-Length: 486 Location: localhost Content-Security-Policy: script-src: 'none'And it popped up a popup saying "OH NO"
-
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 04:28:21 JST silverwizard @hypolite So if I send:
Content-Security-Policy: script-src: 'none'<html>
<script>alert("OH NO");</script>
</html>With a valid Content-Length and junk
Would that work?
-
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 03:55:22 JST silverwizard @allenstenhaus My uncle started going bald at 17, and the wisdom was I'd be bald by 20. So I decided to enjoy it while I could.
I am 36 and I've managed to keep it!
-
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 03:52:04 JST silverwizard It's true! They forgot to confiscate the jacket when they issued me my CISSP -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 03:51:29 JST silverwizard if you see this hacker at SECTor, you may tell me I owe you a drink. Prefacing it, "I'm from the fediverse" will make me slightly less confused. But, telling me I owe you a drink will cause me to buy you a drink, be it a fancy coffee, a boring coffee, a beer, a cocktail, a juice, or whatever else. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 02:38:37 JST silverwizard @hypolite Does that block local scripts? I thought it didn't? I don't have a spare webserver I feel safe rewriting headers on right now. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 02:04:03 JST silverwizard @patcharcana Also - if I'm listening to music all day - my headphones are gonna run down hard, and if I need two $200 headphones, or a charger and cable always around, it's not gonna happen. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 02:00:12 JST silverwizard Question - is the rise of people listening to music aloud related to the headphone jack dying? -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 01:14:00 JST silverwizard @hypolite developer.mozilla.org/en-US/do…
Is there a way to say default-src: none? Or just set no valid sources? not as I recall
-
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Wednesday, 23-Oct-2024 00:45:52 JST silverwizard @Sconient Oh yeah - JS existed ;) -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Tuesday, 22-Oct-2024 23:45:39 JST silverwizard @ericmpaq @tieflingdio That's valid. 3e gave them all slight differences, and I think some minor tweaks exist to sell books. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Tuesday, 22-Oct-2024 23:32:13 JST silverwizard @ericmpaq @tieflingdio Wait, Standard D&D Elves is a weird idea.
The High/Grey/Valley/Wood elves of Greyhawk are what I think of as "standard", whereas the Sun and Moon of Faerun are typically slightly off model?
-
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Tuesday, 22-Oct-2024 22:50:32 JST silverwizard @hypolite @IceWolf Does CSP let you reject javascript from the local domain? -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Tuesday, 22-Oct-2024 22:09:37 JST silverwizard @hypolite @IceWolf CORS allows you to limit cross domain resources. But I can mine bitcoin on your CPU without any cross domain anything. Hell, in theory,I might be able to send spam that way! I can definitely steal your credit card number.
But if I could just add a X-No-Dynamism header that would say "this HTTP session does not send JS or WASM", I could keep everything on my site safe.
I could let users write pretty unfiltered HTML, and most of the tricks would be contained in a frame.
-
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Tuesday, 22-Oct-2024 20:05:23 JST silverwizard @valk I personally think JavaScript is underhated. I think people don't think enough about the ways the Browser is now a platform. People feel safe with browsers, and that's not a good idea imo. -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Tuesday, 22-Oct-2024 11:26:25 JST silverwizard @lifts @valk right, CSS has grown to madness