Cybersecurity professional with an interest/background in networking. Beginning to delve into binary exploitation and reverse engineering.

  • 0 Posts
  • 206 Comments
Joined 11 months ago
cake
Cake day: March 27th, 2024

help-circle
  • No. You can have control over specific parameters of an SQL query though. Look up insecure direct object reference vulnerabilities.

    Consider a website that uses the following URL to access the customer account page, by retrieving information from the back-end database: https://insecure-website.com/customer_account?customer_number=132355 Here, the customer number is used directly as a record index in queries that are performed on the back-end database. If no other controls are in place, an attacker can simply modify the customer_number value, bypassing access controls to view the records of other customers.




  • Just to be clear, I will absolutely create new domain users or add my own ssh keys to an authorized_keys file to escalate privs or move laterally through a network while I’m “hacking”.

    Also a malicious actor opening a reverse port forward tunnel with ssh allows them to punch a hole to them on the WAN side of the network when they’re dealing with NAT or firewall rules. If a system is truly airgapped then that accomplishes nothing. You’d need something plugged in to the airgapped system or airgapped network to bridge that air gap, like a usb adapter that has a SIM card in it.











  • I feel like I might get a ton of downvotes for this, but I kind of disagree. Maybe when it comes to things like texture detail, we certainly don’t need every single hair on Roach modeled with full physics or anything.

    That’s only a subset of what constitutes graphics in a game though. I think that while it is computationally expensive, the improvements in lighting that we’re seeing contribute to making graphics more realistic and do matter.

    I get that people meme on Ray Tracing and the whole RTX On thing, but lighting techniques like Path Tracing, Global Illumination, and Dynamic Illumination are just as much a generational shift as physics was in HL2. Output resolution and texture resolution got pushed to a point where any further gains are marginal improvements at best. Physics is getting to that point, although there’s still room for improvement. Look at how well the finals handles destruction physics, or the ballistics models used in Arma 3. Lighting is the next thing being refined, and it has a ways to go. I’d bet that in 10 years full, real time, dynamic, ray traced lighting will be taken for granted, and we’ll be arguing whether there’s any value or added realism benefit to increasing the number of individual rays cast by each light source, or how many bounces they take. I’d also not be surprised if people were memeing about RTX Sound On at that point and saying that game audio peaked with HRTF or Spatial Audio.




  • It is pretty easy. There’s tons of tutorials and walkthroughs for doing it, but anyone familiar with UIs will be able to work it out pretty quickly I think. Maybe a friction point in using the filter query, but again there’s tons of walkthroughs and guides for using it online.

    If you can’t conceptualize a packet, or sockets, or network flows, even with the help of online guides/manuals, I guess it wouldn’t be easy. In that case I’d be wondering why someone would want to use those tools in the first place though, as then they probably wouldn’t have the skills necessary to leverage the information gleaned from the tool in any useful way.

    Edit - As we’re in the self-hosted community, I’d argue that anyone who is self-hosting anything would probably be able to easily install wireshark and view http requests, both individual packets and the stream as a whole.


  • We’re reaching the end of the current season of THE FINALS, so I’ve been grinding for the last seasonal reward skin tier.

    I’ve been kind of down on myself for getting sucked in to the seasonal cycle of modern FPS games and letting my single player stuff lay neglected, but the finals is such a phenomenal shooter I can’t help myself. I alternate between wanting more people to play and experience it because of how good it is, to being happy it’s small and not inundated with people. While the community can be a bit toxic, I get matched with a lot more just generally chill people than not, and more people on mic communicating about the game than I can remember in a really long time.

    I need to get around to finishing bg3, and cp2077 now that I have a new gpu.

    I got psychonauts on a steam sale a few years ago and still need to get around to it also, thanks for the reminder.