GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Rebane (rebane2001@infosec.exchange)

  1. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Monday, 25-May-2026 13:15:38 JST Rebane Rebane

    i made a new game called js crossword where you have to solve it by literally writing javascript code that eval()'s into the correct values!

    check it out if you're into ctfs or wanna challenge your javascript skills

    https://lyra.horse/fun/jscrossword/ <3

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/632/163/015/230/784/original/474d56775d4c4f95.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/632/163/848/594/940/original/92d867d8ca84014e.png

    3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/632/164/396/361/786/original/3470ab85a6b77cc9.png
  2. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Thursday, 21-May-2026 05:19:31 JST Rebane Rebane
    in reply to

    even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

    all from just visiting a single website once !!

    In conversation about a month ago from infosec.exchange permalink

    Attachments


  3. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Thursday, 21-May-2026 02:06:53 JST Rebane Rebane
    in reply to

    OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS 💀💀

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/606/835/033/827/884/original/402b20343a50e84c.png
  4. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Wednesday, 20-May-2026 22:29:46 JST Rebane Rebane

    back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

    in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

    today, almost 4 years later, the bug is finally public:
    https://issues.chromium.org/issues/40062121

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      Chromium
  5. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Saturday, 18-Apr-2026 02:52:19 JST Rebane Rebane

    135tb ram bitches

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/420/349/014/037/726/original/d8b14a5143b81b21.jpg
  6. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Sunday, 12-Apr-2026 03:31:14 JST Rebane Rebane

    "gotcha"ing an autistic person into eating something with an ingredient they don't like to prove they can't tell is like me spitting in your drink to prove you can't tell that you've just drank my spit

    In conversation about 2 months ago from infosec.exchange permalink
  7. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Sunday, 05-Apr-2026 06:24:36 JST Rebane Rebane

    the linkedin fingerprinting you and scanning your extensions thing is a pretty good example of just how much js leaks about your browser
    https://browsergate.eu/how-it-works/

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      The Attack: How it works
      Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. The entire process happens in the background. There is no consent dialog, no notification, no mention of it in LinkedIn’s privacy policy. This page documents exactly how the system works, with line references and code excerpts from LinkedIn’s production JavaScript bundle.
  8. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Tuesday, 17-Mar-2026 23:03:56 JST Rebane Rebane

    in linux you can use the evil bird emoticon (:>) to destroy files, eg `:> important_document.txt`

    the bird will eat the file and leave it completely empty!

    In conversation about 3 months ago from infosec.exchange permalink
  9. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Thursday, 12-Mar-2026 22:03:07 JST Rebane Rebane

    Discord is now cracking down on tools such as DiscordChatExporter that can be used to export your Discord chats.

    Some users are reporting getting logged out with a community guidelines violation as soon as they run an export with their token.

    While this has never been ToS compliant, it has not been enforced in the past like this. I'm guessing the reason for the change is motivated either by AI scrapers, or lots of people leaving Discord and exporting their old chats.

    https://github.com/Tyrrrz/DiscordChatExporter/issues/1497

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/215/687/636/516/903/original/fa507d822e9d9fcd.png
  10. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Tuesday, 10-Mar-2026 09:30:06 JST Rebane Rebane

    did you know that SSH has a little-known secret menu?

    i wrote a post about this on cohost a while back, but since that site shut down i'm posting it here too

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/200/035/509/605/989/original/a0ed7a4028eb7157.jpg

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/200/041/472/217/483/original/84cef1e14a4516b3.jpg

    3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/200/045/409/467/223/original/1e4755e92c930f4c.jpg
  11. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Friday, 27-Feb-2026 10:36:10 JST Rebane Rebane

    i just got a notification for my own project?

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/137/898/330/713/037/original/2e81eac3c3b46adb.jpg
  12. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Tuesday, 24-Feb-2026 12:38:35 JST Rebane Rebane

    i built an entire x86 CPU emulator in CSS (no javascript)

    you can write programs in C, compile them to x86 machine code with GCC, and run them inside CSS

    https://lyra.horse/x86css/

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


  13. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Friday, 20-Feb-2026 07:18:12 JST Rebane Rebane

    self-hosting my S3 bucket the right way

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/099/496/323/659/317/original/8e3edf02213ae783.jpg
  14. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Thursday, 12-Feb-2026 23:46:13 JST Rebane Rebane

    the joke of "cool feature, can't wait to be able to use it in 5 years" is now baseline widely available

    In conversation about 4 months ago from infosec.exchange permalink
  15. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Monday, 09-Feb-2026 02:20:08 JST Rebane Rebane

    Xikipedia, the Wikipedia doomscrolling "app", is now available as an actual app (PWA)!

    Also:
    - fully available offline
    - algorithm saving/persistence (optional)
    - multiple profiles
    - light theme (optional)
    - full english wikipedia links (optional)
    - statistics screen

    have fun!!

    https://xikipedia.org/?2

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


  16. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Wednesday, 04-Feb-2026 17:07:29 JST Rebane Rebane
    in reply to
    • SuperDicq

    @SuperDicq please give me a free software recommendation that can open up my after effects project from 5 years ago

    In conversation about 5 months ago from infosec.exchange permalink
  17. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Wednesday, 04-Feb-2026 12:35:53 JST Rebane Rebane

    did you know? if you're a paying adobe user, you can message the support and ask for offline installers for the software you pay for

    why would you do that? if they ever were to discontinue one of their products (*cough* animate), you could still install and activate it

    and while i do not publicly endorse piracy (for obvious reasons), i do want to note that installations made with these offline installers have way safer methods of patching them than downloading a pirated copy that's potentially malicious

    all i'm saying is, those installers are kind of annoying to get these days. if you pay for the software, ask for the installers and make backups of them.

    oh and last - you can ask for older versions too! even older than what the CC app shows you

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/007/882/815/175/426/original/5f16d0834b835b93.png
  18. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Monday, 02-Feb-2026 12:17:43 JST Rebane Rebane

    i made a version of wikipedia you can doomscroll
    https://xikipedia.org/

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      Xikipedia
      Wikipedia you can doomscroll
  19. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Sunday, 01-Feb-2026 18:31:25 JST Rebane Rebane

    Men eating female

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/994/665/574/740/572/original/366dfbae8f881c9c.jpg
  20. Embed this notice
    Rebane (rebane2001@infosec.exchange)'s status on Thursday, 22-Jan-2026 06:16:59 JST Rebane Rebane
    in reply to

    sort of a spiritual successor to foldy bird, i wanted to make a game people without a folding phone could play too :p

    i was inspired by defend your castle and bowmaster prelude (although my game is very basic)

    source code: right-click -> view source
    https://lyra.horse/fun/charchery/

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Charchery
      Phone charger archery
  • Before

User actions

    Rebane

    Rebane

    🇪🇪🏳️⚧️ | Archivist | 9 CVEs in Chrome | MapartCraft | Horse | rebane2001#3716 | Lyra 🦊

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          298510
          Member since
          20 Nov 2024
          Notices
          38
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.