<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Bnshsysjab</title><link>https://news.ycombinator.com/user?id=Bnshsysjab</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 11 Jun 2026 04:49:31 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Bnshsysjab" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Bnshsysjab in "Opensnitch, application level interactive firewall, heading into Debian"]]></title><description><![CDATA[
<p>How does this work on a technical level? What stops an app bypassing the firewall?</p>
]]></description><pubDate>Mon, 23 Jan 2023 05:02:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=34485677</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=34485677</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34485677</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "Samsung Ads – Demand-Side Platform"]]></title><description><![CDATA[
<p>Because TVs rapidly get outdated and die. If nothing else the 2inch thick bezels are an eye sore.<p>Just because I don’t care about 4K doesn’t mean I don’t care about image quality. I’d prefer 1080p@60 over 4k@30.</p>
]]></description><pubDate>Fri, 02 Oct 2020 22:57:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=24667878</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24667878</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24667878</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "Samsung Ads – Demand-Side Platform"]]></title><description><![CDATA[
<p>720 to 4K is not the same as 480p to 720. The latter is far more noticeable. Most of the world hasn’t moved to 4K, I don’t see a huge amount of value in it personally.</p>
]]></description><pubDate>Fri, 02 Oct 2020 20:14:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=24666595</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24666595</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24666595</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "Luna – Cloud gaming service"]]></title><description><![CDATA[
<p>You’re missing the point. Most people don’t want to download a video instead of streaming directly, which is a far lower barrier than procuring equipment, dealing with compatibility issues, doing system updates etc. I doubt competitive gamers will ever move across but it hugely reduces the barriers for casual or time poor gamers.</p>
]]></description><pubDate>Fri, 25 Sep 2020 03:18:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=24586249</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24586249</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24586249</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "MalwareBazaar – Malware Sample Exchange"]]></title><description><![CDATA[
<p>That’s a fair point.</p>
]]></description><pubDate>Thu, 24 Sep 2020 04:52:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=24575362</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24575362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24575362</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "MalwareBazaar – Malware Sample Exchange"]]></title><description><![CDATA[
<p>As a side note, and I’ll create a separate thread: say my host is comprised by super sophisticated malware, aside from a reformat what other sanitisation practices can I do? Can I ever trust the hardware again? I don’t think we’re at a point where a firmware compromised graphics card can’t reinfect the processor?</p>
]]></description><pubDate>Wed, 23 Sep 2020 23:50:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=24573667</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24573667</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24573667</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "MalwareBazaar – Malware Sample Exchange"]]></title><description><![CDATA[
<p>If you wanna go a little bit more paranoid, use a dedicated host to virtualise those machines and connect to the host via RDP/whatever, that should create another layer of safety.</p>
]]></description><pubDate>Wed, 23 Sep 2020 23:47:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=24573633</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24573633</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24573633</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>No the risk is that somebody has decided to disregard security and general security process and create shadow IT, which if left unchecked will create massive problems within the organisation long term. If the culture is to disregard security, throw a waf infront and call it a day then they’ll pay for it financially (and possibly legally) in the long run and not something I’d want to associate with at all.</p>
]]></description><pubDate>Mon, 21 Sep 2020 01:38:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=24538961</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24538961</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24538961</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>Nah you pull it offline and tell them to follow correct procurement and development practices. If your development teams aren’t talking to your security teams you have bigger problems than Wordpress.</p>
]]></description><pubDate>Sun, 20 Sep 2020 12:15:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=24533551</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24533551</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24533551</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>You need to tweet your view of security requirements if you want to provide IT functions to users. Yes they are a nice to have, yes the cost of a data breach either to you or the user are highly damaging.<p>There’s nothing stopping most industries doing something stupid in the current state of things but I’m sure there will be in the future, you should be legally liable for your consumer data, irrespective of if you’re ‘nontechnical people running old versions of off the shelf software’ or not, mistakes happen, but failing the most obvious stuff in infosec is, IMO, criminally negligent. Waf or not.</p>
]]></description><pubDate>Sat, 19 Sep 2020 12:49:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=24527071</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24527071</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24527071</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>See comment on parent.</p>
]]></description><pubDate>Sat, 19 Sep 2020 12:45:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=24527042</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24527042</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24527042</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>I think ‘stop wasting time on dumb stuff and focus on actual security’ is a good take home for the HN crowd. Time and money is finite, so spend it wisely.</p>
]]></description><pubDate>Sat, 19 Sep 2020 10:15:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=24526392</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24526392</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24526392</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>No it’s not recommending snake oil and telling them to do things properly instead I don’t. Care if that makes the security industry dry up, my only hope is that if it does the snake oil salespeople die with it.</p>
]]></description><pubDate>Sat, 19 Sep 2020 09:10:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=24526183</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24526183</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24526183</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>I’ll ignore your condescending dribble but:<p>> Let’s also not forget that there is good money to be made off consulting for those companies that are “fucked”<p>Where the hell are your ethics?</p>
]]></description><pubDate>Sat, 19 Sep 2020 08:58:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=24526149</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24526149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24526149</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>Or maybe I’m just not scraping bottom of the barrel when it comes to security assessments.  If the software is at that point the organisation is well and truly fucked, waf or not.</p>
]]></description><pubDate>Sat, 19 Sep 2020 07:09:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=24525760</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24525760</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24525760</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>What if the payload is ‘a,b’ which renders as<p>Select a, b from foo;</p>
]]></description><pubDate>Fri, 18 Sep 2020 23:34:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=24522909</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24522909</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24522909</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>Right but I’m the context of antivirus you’re executing unconstrained data in an unconstrained environment, in appsec you can handle data correctly rather than rely on a third party product that can’t contextualise or assess the impact of a payload on your application. I work in appsec and think WAF filtering is snake oil.</p>
]]></description><pubDate>Fri, 18 Sep 2020 23:33:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=24522901</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24522901</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24522901</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "How I bypassed Cloudflare's SQL Injection filter"]]></title><description><![CDATA[
<p>I hate these kind of defenses. If your application is vulnerable to sqli, select is one of many tools an attacker can use and you’re pretty much screwed anyway.<p>Instead, use sane tooling, like modern ORMs and parameter izers, with some data sanitation if you’re really paranoid.</p>
]]></description><pubDate>Fri, 18 Sep 2020 23:29:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=24522876</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24522876</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24522876</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "Super Mario Bros. 3 in 3 Minutes – World Record Speedrun Explained [video]"]]></title><description><![CDATA[
<p>Also be sure to check out the super Mario world flappy bird code injection:<p><a href="https://youtu.be/hB6eY73sLV0" rel="nofollow">https://youtu.be/hB6eY73sLV0</a></p>
]]></description><pubDate>Sun, 13 Sep 2020 06:54:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=24458960</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24458960</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24458960</guid></item><item><title><![CDATA[New comment by Bnshsysjab in "The Unix timestamp will begin with 16 this Sunday"]]></title><description><![CDATA[
<p>2037 is a potential overflow, I believe. I imagine only pre 2000 systems would likely be affected.</p>
]]></description><pubDate>Sat, 12 Sep 2020 15:15:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=24453104</link><dc:creator>Bnshsysjab</dc:creator><comments>https://news.ycombinator.com/item?id=24453104</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24453104</guid></item></channel></rss>