Hacker Newsnew | past | comments | ask | show | jobs | submit | alaxapta7's commentslogin

Same, although I haven't seen this one for a while now. One way to fix the misbehaving explorer (which start menu, tray and others are part of) is to simply kill it and start it over from the task manager. Some applications failed to re-create their tray icons after this, but either all of them fixed it, or it got somehow fixed in Windows.


This still happens on my Windows 11 machines (the tooltip stays there unless you move the mouse over the same icon again), but only to a small number of applications. Makes me wonder if they are using a different set of API to set up their tray icons.


I've seen worse. Couple years back, there was an audit that included an internal system I've been working on. It was running on Debian oldstable because of a vital proprietary library I wasn't able to get working on stable at the time, but it had unattended upgrades set up and all that.

The company made some basic port scan and established that we're running outdated and vulnerable version of Apache. I found the act of explaining the concept of backports to a "pentester" to be physically painful.

They didn't get paid and another company was entrusted with the audit.


This is why I always attempt to turn off as much version information output as possible from any service. Make the pentester do their homework and not just look at "Apache 2.XX"

Hopefully you also have an internal control that looks at actual package versions installed on the server.


Normally I do that too, but this was fairly new and internal application that was still in development, so that's why it was there. And if it wasn't for this incident, they might actually trick our management into thinking they're somehow qualified to carry out such an audit.


This is actually a take away that I did implement. it's one of those that's not actively a vuln, but might provide info on what other attacks to try.


I use and recommend subhook[0].

[0] https://github.com/Zeex/subhook


You can take full control over the routing using router script, then none of the default rules will apply. To be honest, I really dislike how many applications are wired around some Apache configuration or at least assume some specific hostname or path to be used for no reason. If it works with the built-in webserver, then it will work just as well with pretty much any SAPI.


The built-in web server can only process one request at a time.


I used LD_PRELOAD for patching RCE vulnerability in PunkBuster[0]. They did patch the exploit, but that didn't involve many of the older games they dropped support for. The AC itself isn't effective or even operational for the most part in those, but it still serves as a reliable method of identifying players.

Even their server libraries are obfuscated, and hooking open() turned out to be just easier than trying to patch the binaries themselves.

[0] https://medium.com/@prizmant/hacking-punkbuster-e22e6cf2f36e


I thought this was the Passwordless account they implemented (EDIT: didn't realize you weren't talking about the Authenticator app), but I had it turned off. I somehow managed to make it stop by re-enabling/re-disabling both Passwordless and 2FA. So now they always ask me for a password and then I get the challenge.

To this day, I can't comprehend how this is supposed to be safe. So someone can just type in my username and wait until i eventually misclick in the Authenticator app? If it was from a browser I have used before at least, but I was getting these challenges from around the globe.


Kagi, location set to United States:

Page 1: Biden, Williamson and link to an article Google hides campaign sites of Trump, RFK Jr. and other Republican candidates

Page 2: Biden again, Pence

No further pages. 5th result contains an article that claims to be linking all presidental candidate websites, but it's a Medium, hidden behind sign-up. I haven't find any result with a comprehensive list of the websites of interest. Kagi does aggregate results from Google and Yandex, so this is probably not too surprising.


On Kagi (International) I got these results on the first page:

First result: Joe Biden

Further down: Bernie Sanders, Marianne Williamsson, Hillary Clinton

Further down: Article: "Google hides campaign sites of Trump, RFK Jr. and other Republican candidates"

Further down: Ron DeSantis

Between these results there are several links with lists of all candidates.


Did it give you a result leading directly to their canonical campaign website? I can see Sanders and Clinton with international, but can't see DeSantis nor any other Republican candidate (not even Pence).

I can definitelly see pages with lists of candidates, but I couldn't find a single one that would also link their websites and thus satisfy the query, at least indirectly.


The results seem to change as we speak. I no longer have any republican candidates on the first page of search results, but the links in the results are to the canonical campaign sites.


Yeah, that must have been my collegue. Usually he was in charge of implementing all the new stuff, because he was able to deliver fast. And then I had to refactor, or usually just rewrite and redesign the whole thing, because it was immediatelly unmaintenable. I didn't mind, since at the end of the day, he was really good and doing these prototypes and selling them to management. I was good at making the application last and stable, so it kinda worked out.


That caught my attention too. Right now, the cheapest option out there still seems to be getting a dumbphone and a few pre-paid SIM cards. Sadly, pre-paid cards are no longer an option in many EU countries. Even just the least expensive SMS gateways are like 10 €/month last time I checked.


The good news is that if you find a prepaid SIM in one EU country, you should be able to continue using it in every EU country as long as you top it up. I often wish I still had my Croatia SIM card that I bought at a Tisak kiosk for €10.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: