Afficher/masquer le menu
Liens Ecyseo
  • Tags cloud
  • Daily
  • Pictures wall
  • Search
  • Display options
    • Links per page :
    • 20 links
    • 50 links
    • 100 links
  • RSS Feed
  • Login

J'ai besoin d'intimité. Non pas parce que mes actions sont douteuses, mais parce que votre jugement et vos intentions le sont.

5185 links 

page 129 / 260

Liste des liens

imgur.com thumbnail
fried shrimp  - Imgur
2017-07-13 15:43 - permalink -

C'est donc comme ça qu'ils font chez eux...

Humour
- https://imgur.com/gallery/k77jF6E
Selon l'OFCE, Macron va aggraver les inégalités - L'Obs - aurem:liens
2017-07-13 13:55 - permalink -

Sans blague ? On ne s'en serait pas douté...

- http://links.aurem.org/?iQozrw
TEN FOLD - Moving House - YouTube - Nono's Links
2017-07-13 11:26 - permalink -

C'est le principe des roulottes de forains dans les foires, en moins basique il faut bien l'admettre :D

- http://shaarli.m0le.net/?UJttYw
Comment un algorithme peut prédire le succès d’un film
2017-07-13 10:33 - permalink -

C'est l'ennemi de la créativité, ça ne sert qu'à répliquer ce qui a déjà marché et ne peut conduire qu'à un affadissement ou une homogénéisation des films.

Tout est dit. On est en train de s'orienter doucement mais surement vers une société fade, lisse, et uniforme dans la façon de penser.
Ajoutée à cela, la disparition du sens des mots (cf. la novlangue), l'utilisation massive de l'anglais dans de plus en plus d'aspect de nos vies (internet, sciences, rapports officiels...) et on obtient une pensée unique, lobotomisée...

société
- https://www.lesechos.fr/tech-medias/medias/030443601253-comment-un-algorithme-peut-predire-le-succes-dun-film-2101690.php#xtor=CS1-33
GitHub - dexteryy/spellbook-of-modern-webdev: A Big Picture, Thesaurus, and Taxonomy of Modern JavaScript Web Development
2017-07-13 10:29 - permalink -

Via Shazen

javascript tutoriels
- https://github.com/dexteryy/spellbook-of-modern-webdev#server-side
A Complete Guide To Switching From HTTP To HTTPS – Smashing Magazine
2017-07-13 10:18 - permalink -

À lire pour plus tard

Apache http https Linux
- https://www.smashingmagazine.com/2017/06/guide-switching-http-https/
Pandoc - About pandoc
2017-07-10 16:44 - permalink -
convertisseur doc html libreoffice markdown opendocuments pandoc pdf
- http://pandoc.org/index.html
The SQL Injection Knowledge Base
2017-07-10 14:15 - permalink -

Énorme ce site. Permet de faire des tests sur ses propres bases. C'est très formateur.

erreur failles injections MySQL
- http://www.websec.ca/kb/sql_injection
Respects Your Freedom hardware product certification — Free Software Foundation — working together for free software
2017-07-10 12:27 - permalink -

Matériel libre

informatique Libre matériel
- https://www.fsf.org/resources/hw/endorsement/respects-your-freedom
Comme Macron faites des discours creux avec le générateur de langue de bois
2017-07-10 12:25 - permalink -

On a retrouvé la source des discours de macron.

- http://www.perdre-la-raison.com/2016/07/-comme-macron-generateur-langue-bois.html
Tutoriel Vidéo JavaScript Créer une extension Chrome/Firefox pour Twitch
2017-07-10 12:19 - permalink -
extensions Firefox
- https://www.grafikart.fr/tutoriels/javascript/extension-chrome-firefox-twitch-900
Cinnamon Spices
2017-07-10 1:16 - permalink -

Site officiel pour les thèmes, addons etc. de cinnamon

cinnamon Linux thème
- https://cinnamon-spices.linuxmint.com/
How to defend your website with ZIP bombs
2017-07-7 16:55 - permalink -

If you have ever hosted a website or even administrated a server you'll be very well aware of bad people trying bad things with your stuff.

When I first hosted my own little linux box with SSH access at age 13 I read through the logs daily and report the IPs (mostly from China and Russia) who tried to connect to my sweet little box (which was actually an old ThinkPad T21 with a broken display running under my bed) to their ISPs.

Actually if you have a linux server with SSH exposed you can see how many connection attempts are made every day:

    grep 'authentication failures' /var/log/auth.log

Hundreds of failed login attempts even though this server has disabled password authentication and runs on a non-standard port

Wordpress has doomed us all

Ok to be honest, web vulnerability scanners have existed before Wordpress but since WP is so widely deployed most web vuln scanners include scans for some misconfigured wp-admin folders or unpatched plugins.

So if a small, new hacking group wants to gain some hot cred they'll download one of these scanner things and start testing against many websites in hopes of gaining access to a site and defacing it.

Sample of a log file during a scan using the tool Nikto

This is why all server or website admins have to deal with gigabytes of logs full with scanning attempts. So I was wondering..

Is there a way to strike back?

After going through some potential implementations with IDS or Fail2ban I remembered the old ZIP bombs from the old days.

WTH is a ZIP bomb?

So it turns out ZIP compression is really good with repetitive data so if you have a really huge text file which consists of repetitive data like all zeroes, it will compress it really good. Like REALLY good.

As 42.zip shows us it can compress a 4.5 peta byte (4.500.000 giga bytes) file down to 42 kilo bytes. When you try to actually look at the content (extract or decompress it) then you'll most likely run out of disk space or RAM.

How can I ZIP bomb a vuln scanner?

Sadly, web browsers don't understand ZIP, but they do understand GZIP.

So firstly we'll have to create the 10 giga byte GZIP file filled with zeroes. We could make multiple compressions but let's keep it simple for now.

Creating the bomb and checking its size

    dd if=/dev/zero bs=1M count=10240 | gzip > 10G.gzip

And for checking file size

    du -sh 10G.zip

As you can see it's 10 MB large. We could do better but good enough for now.

Now that we have created this thing, let's set up a PHP script that will deliver it to a client.

    <?php
    //prepare the client to recieve GZIP data. This will not be suspicious
    //since most web servers use GZIP by default
   header("Content-Encoding: gzip");
   header("Content-Length: ".filesize('10G.gzip'));
   //Turn off output buffering
   if (ob_get_level()) ob_end_clean();
   //send the gzipped file to the client
   readfile('10G.gzip');

That's it!

So we could use this as a simple defense like this:

    <?php
    $agent = filter_input(INPUT_SERVER, 'HTTP_USER_AGENT');

    //check for nikto, sql map or "bad" subfolders which only exist on wordpress
    if (strpos($agent, 'nikto') !== false || strpos($agent, 'sqlmap') !== false || startswith($url,'wp-') || startswith($url,'wordpress') || startswith($url,'wp/'))
    {
          sendBomb();
          exit();
    }

    function sendBomb(){
            //prepare the client to recieve GZIP data. This will not be suspicious
            //since most web servers use GZIP by default
            header("Content-Encoding: gzip");
            header("Content-Length: ".filesize('10G.gzip'));
            //Turn off output buffering
            if (ob_get_level()) ob_end_clean();
            //send the gzipped file to the client
            readfile('10G.gzip');
    }

    function startsWith($a, $b) { 
        return strpos($a, $b) === 0;
   }

This script obviously is not - as we say in Austria - the yellow of the egg, but it can defend from script kiddies I mentioned earlier who have no idea that all these tools have parameters to change the user agent.

Sooo. What happens when the script is called?

Client Result
IE 11 Memory rises, IE crashes
Chrome Memory rises, error shown
Edge Memory rises, then dripps and loads forever
Nikto Seems to scan fine but no output is reported
SQLmap High memory usage until crash
Safari Hight memory usage, then crashes and reloads, then memory rises again, etc..
Chrome (Android) Memory rises, error shown

(if you have tested it with other devices/browsers/scripts, please let me know and I'll add it here)

bombe spam sécurité web
- https://blog.haschek.at/post/f2fda
#danbennet - Framapiaf
2017-07-7 15:46 - permalink -

Il faut le lire "Ray parti" alors :)

- https://framapiaf.org/tags/danbennet
Android utilise 2 IP selon si les requêtes sortent du téléphone ou du partage de connexion - HowTommy | Liens et actu en vrac
2017-07-6 18:51 - permalink -
android
- http://liens.howtommy.net/?NJKP8w
LCP sur Twitter : "77 amendements étudiés, avec "un taux d'acceptation de 0%". "Evidemment", répond la présidente @BourguignonBrig. #DirectAN https://t.co/SFUqL7x4ij"
2017-07-6 18:18 - permalink -

Et en plus, elle sourit cette conne. Ça va péter, c'est sûr.
Réveillez-vous les gens !!!

levons-nous politique tous-pourris
- https://twitter.com/LCP/status/882694926579900416
GinolaFME 🇫🇷 sur Twitter : "Les blaireaux #LREM pris en flag à applaudir même quand le député n'a pas encore parlé. #Honte #lamentable #directan https://t.co/uZ7nQ0LfLT"
2017-07-6 18:16 - permalink -

Putain, quelle farce... :(

politique tous-pourris
- https://twitter.com/GinolaFME/status/882978623698939908
YouTube thumbnail
Macron propose le CDI... à durée déterminée - YouTube
2017-07-5 16:16 - permalink -

Pas ça con ! Mais c'est la fin de toute protection sociale. Tu seras une marchandise dont on pourra se débarrasser quand bon nous semble.
Au moins, avec un CDD, il y a une prime de précarité. Là, rien. Walou. Nada.
Je vous laisse un extrait des conférences de Franck LEPAGE, sur la notion de "Projet" dont les journalistes et invités des différentes émissions prises en exemple se gargarisent : http://www.dailymotion.com/video/xj0yxj_projet_fun

levons-nous politique société
- https://www.youtube.com/watch?v=uocC-KlJuEQ&feature=youtu.be
ClippyJS - Add Clippy or his friends to any website for instant nostalgia
2017-07-5 10:30 - permalink -

Clippy, le tombone de Microsoft vous manque ? Installer le sur votre site internet ;-)

Via Cochise
Github : https://github.com/smore-inc/clippy.js

animation gadget javascript
- https://www.smore.com/clippy-js
Anatomie d'une WebExtension - Mozilla | MDN
2017-07-4 18:14 - permalink -

via grolimur

chrome extensions Firefox mozilla
- https://developer.mozilla.org/fr/Add-ons/WebExtensions/Anatomy_of_a_WebExtension
page 129 / 260


Tags


  • shaarli
  • wikipedia

Tags cloud

Shaarli - The personal, minimalist, super-fast, database free, bookmarking service by the Shaarli community - Help/documentation
Affiches "loi aviva" créées par Geoffrey Dorne le 13 Mai, 2020 - Mastodon 1 - Mastodon 2