Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. the rm -rf's will continue until morale improves

the rm -rf's will continue until morale improves

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
123 Indlæg 85 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

    the rm -rf's will continue until morale improves

    quinn@social.circl.luQ This user is from outside of this forum
    quinn@social.circl.luQ This user is from outside of this forum
    quinn@social.circl.lu
    wrote sidst redigeret af
    #13

    @neurovagrant well *someone* learned the value of offline back ups. 😁

    neurovagrant@masto.deoan.orgN 1 Reply Last reply
    0
    • quinn@social.circl.luQ quinn@social.circl.lu

      @neurovagrant well *someone* learned the value of offline back ups. 😁

      neurovagrant@masto.deoan.orgN This user is from outside of this forum
      neurovagrant@masto.deoan.orgN This user is from outside of this forum
      neurovagrant@masto.deoan.org
      wrote sidst redigeret af
      #14

      @quinn his twitter profile says he's a CTO...

      ...

      ...

      quinn@social.circl.luQ 1 Reply Last reply
      0
      • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

        @quinn his twitter profile says he's a CTO...

        ...

        ...

        quinn@social.circl.luQ This user is from outside of this forum
        quinn@social.circl.luQ This user is from outside of this forum
        quinn@social.circl.lu
        wrote sidst redigeret af
        #15

        @neurovagrant uhhhh better late than never I guess?

        neurovagrant@masto.deoan.orgN 1 Reply Last reply
        0
        • paco@infosec.exchangeP paco@infosec.exchange

          @neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran drop table users; via injection.

          Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.

          somevegancheeseisok@mastodon.socialS This user is from outside of this forum
          somevegancheeseisok@mastodon.socialS This user is from outside of this forum
          somevegancheeseisok@mastodon.social
          wrote sidst redigeret af
          #16

          @paco @neurovagrant 🫠

          1 Reply Last reply
          0
          • quinn@social.circl.luQ quinn@social.circl.lu

            @neurovagrant uhhhh better late than never I guess?

            neurovagrant@masto.deoan.orgN This user is from outside of this forum
            neurovagrant@masto.deoan.orgN This user is from outside of this forum
            neurovagrant@masto.deoan.org
            wrote sidst redigeret af
            #17

            @quinn 😂

            viss@mastodon.socialV 1 Reply Last reply
            0
            • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

              @jztusk @paco @neurovagrant

              A simple select * from users would've been fine just to prove the point.

              somevegancheeseisok@mastodon.socialS This user is from outside of this forum
              somevegancheeseisok@mastodon.socialS This user is from outside of this forum
              somevegancheeseisok@mastodon.social
              wrote sidst redigeret af
              #18

              @jrdepriest @jztusk @paco @neurovagrant no, drop tables *also* let's you demonstrate the presence or absence of effective backups. It's a two for one test!

              c_duv@piaille.frC 1 Reply Last reply
              0
              • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

                @jztusk @paco @neurovagrant

                A simple select * from users would've been fine just to prove the point.

                womble@infosec.exchangeW This user is from outside of this forum
                womble@infosec.exchangeW This user is from outside of this forum
                womble@infosec.exchange
                wrote sidst redigeret af
                #19

                @jrdepriest @jztusk @paco @neurovagrant "oh, it's only data exfil, that's not so bad" Some people have very limited imaginations, and need an unequivocal demonstration.

                jztusk@mastodon.socialJ drwho@masto.hackers.townD 2 Replies Last reply
                0
                • taffer@mastodon.gamedev.placeT taffer@mastodon.gamedev.place

                  @n_dimension @neurovagrant Doesn’t seem to matter: https://pivot-to-ai.com/2026/08/27/your-agents-md-file-doesnt-actually-do-anything/

                  n_dimension@infosec.exchangeN This user is from outside of this forum
                  n_dimension@infosec.exchangeN This user is from outside of this forum
                  n_dimension@infosec.exchange
                  wrote sidst redigeret af
                  #20

                  @Taffer @neurovagrant

                  Nobody writes a CLAUDE.md to raise their pass rate on code issues. They write it so the agent follows the project's conventions. The study scored the first and got quoted as debunking the second.

                  There is a token overhead on compliance (about 20%?), it works for me, though I never run a project without it.

                  Edit: Though its the weakest counterpoint, AGENTS.md =\= CLAUDE.md and the fact the author doesn't seem to know that, irks me more than it should.

                  1 Reply Last reply
                  0
                  • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                    @quinn 😂

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote sidst redigeret af
                    #21

                    @neurovagrant @quinn cool now we get to see how well he handles disaster recovery and business continuity

                    quinn@social.circl.luQ huronbikes@cyberplace.socialH 2 Replies Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      @neurovagrant @quinn cool now we get to see how well he handles disaster recovery and business continuity

                      quinn@social.circl.luQ This user is from outside of this forum
                      quinn@social.circl.luQ This user is from outside of this forum
                      quinn@social.circl.lu
                      wrote sidst redigeret af
                      #22

                      @Viss @neurovagrant Letsss goooooo

                      viss@mastodon.socialV drwho@masto.hackers.townD 2 Replies Last reply
                      0
                      • womble@infosec.exchangeW womble@infosec.exchange

                        @jrdepriest @jztusk @paco @neurovagrant "oh, it's only data exfil, that's not so bad" Some people have very limited imaginations, and need an unequivocal demonstration.

                        jztusk@mastodon.socialJ This user is from outside of this forum
                        jztusk@mastodon.socialJ This user is from outside of this forum
                        jztusk@mastodon.social
                        wrote sidst redigeret af
                        #23

                        @womble @jrdepriest @paco @neurovagrant

                        Exactly. "Well that's only showing they can read", whereas having an unrequested calculator sitting there on your desktop is very undeniable.

                        jrdepriest@infosec.exchangeJ 1 Reply Last reply
                        0
                        • jztusk@mastodon.socialJ jztusk@mastodon.social

                          @womble @jrdepriest @paco @neurovagrant

                          Exactly. "Well that's only showing they can read", whereas having an unrequested calculator sitting there on your desktop is very undeniable.

                          jrdepriest@infosec.exchangeJ This user is from outside of this forum
                          jrdepriest@infosec.exchangeJ This user is from outside of this forum
                          jrdepriest@infosec.exchange
                          wrote sidst redigeret af
                          #24

                          @jztusk @womble @paco @neurovagrant

                          Mission accomplished with the table drop, then?

                          jztusk@mastodon.socialJ paco@infosec.exchangeP drwho@masto.hackers.townD 3 Replies Last reply
                          0
                          • quinn@social.circl.luQ quinn@social.circl.lu

                            @Viss @neurovagrant Letsss goooooo

                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            wrote sidst redigeret af
                            #25

                            @quinn @neurovagrant someone rm'ing themselves because they gave claude too much access, who self-identifies as a cto, strikes me as one of those "php ceo" types, who does a lot of talking but never really produces stuff or makes anything interesting or worthwhile.

                            richlv@mastodon.socialR 1 Reply Last reply
                            0
                            • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                              the rm -rf's will continue until morale improves

                              kirakira@furry.engineerK This user is from outside of this forum
                              kirakira@furry.engineerK This user is from outside of this forum
                              kirakira@furry.engineer
                              wrote sidst redigeret af
                              #26

                              @neurovagrant apes gone

                              ciatmusings@raru.reC 1 Reply Last reply
                              0
                              • jztusk@mastodon.socialJ jztusk@mastodon.social

                                @paco @neurovagrant

                                I've always liked how the default demonstration of vulnerability on Windows was is opening calc.exe. isn't there a similar sensible SQL default?

                                paco@infosec.exchangeP This user is from outside of this forum
                                paco@infosec.exchangeP This user is from outside of this forum
                                paco@infosec.exchange
                                wrote sidst redigeret af
                                #27

                                @jztusk There are tons. Calculations or delays that indicate it was processed without doing anything to data.
                                @neurovagrant

                                1 Reply Last reply
                                0
                                • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

                                  @jztusk @womble @paco @neurovagrant

                                  Mission accomplished with the table drop, then?

                                  jztusk@mastodon.socialJ This user is from outside of this forum
                                  jztusk@mastodon.socialJ This user is from outside of this forum
                                  jztusk@mastodon.social
                                  wrote sidst redigeret af
                                  #28

                                  @jrdepriest @womble @paco @neurovagrant

                                  Well, you *can* then just close the calculator, though you can't deny that it was there.

                                  I was wondering if the was some standard, like you create a table named "tag_youre_it", and insert "boop" in a CHAR(4) field. Reversible, but undeniable.

                                  jrdepriest@infosec.exchangeJ womble@infosec.exchangeW 2 Replies Last reply
                                  0
                                  • viss@mastodon.socialV viss@mastodon.social

                                    @neurovagrant @quinn cool now we get to see how well he handles disaster recovery and business continuity

                                    huronbikes@cyberplace.socialH This user is from outside of this forum
                                    huronbikes@cyberplace.socialH This user is from outside of this forum
                                    huronbikes@cyberplace.social
                                    wrote sidst redigeret af
                                    #29

                                    @Viss @neurovagrant @quinn rizaster decovery and business kindakablooey?

                                    1 Reply Last reply
                                    0
                                    • jztusk@mastodon.socialJ jztusk@mastodon.social

                                      @jrdepriest @womble @paco @neurovagrant

                                      Well, you *can* then just close the calculator, though you can't deny that it was there.

                                      I was wondering if the was some standard, like you create a table named "tag_youre_it", and insert "boop" in a CHAR(4) field. Reversible, but undeniable.

                                      jrdepriest@infosec.exchangeJ This user is from outside of this forum
                                      jrdepriest@infosec.exchangeJ This user is from outside of this forum
                                      jrdepriest@infosec.exchange
                                      wrote sidst redigeret af
                                      #30

                                      @jztusk @womble @paco @neurovagrant

                                      Like leaving an empty file called pwned on /.

                                      jztusk@mastodon.socialJ drwho@masto.hackers.townD 2 Replies Last reply
                                      0
                                      • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

                                        @jztusk @womble @paco @neurovagrant

                                        Mission accomplished with the table drop, then?

                                        paco@infosec.exchangeP This user is from outside of this forum
                                        paco@infosec.exchangeP This user is from outside of this forum
                                        paco@infosec.exchange
                                        wrote sidst redigeret af
                                        #31

                                        @jrdepriest It’s a true story, but I tell it a certain way to get a reaction. It was in a UAT environment, not prod. To be fair, it was a precious UAT environment that hundreds of people count on. It was not quick to rebuild. The client was pissed. But it wasn’t deleting real users from the real web site.

                                        @jztusk @womble @neurovagrant

                                        1 Reply Last reply
                                        0
                                        • jztusk@mastodon.socialJ jztusk@mastodon.social

                                          @jrdepriest @womble @paco @neurovagrant

                                          Well, you *can* then just close the calculator, though you can't deny that it was there.

                                          I was wondering if the was some standard, like you create a table named "tag_youre_it", and insert "boop" in a CHAR(4) field. Reversible, but undeniable.

                                          womble@infosec.exchangeW This user is from outside of this forum
                                          womble@infosec.exchangeW This user is from outside of this forum
                                          womble@infosec.exchange
                                          wrote sidst redigeret af
                                          #32

                                          @jztusk @jrdepriest @paco @neurovagrant CREATE TABLE l33th4x0rs (pwned bool default true); does seem like the least intrusive way to demonstrate the acquisition of significant privileges.

                                          violetmadder@kolektiva.socialV 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper