remotelove

joined 1 year ago
[–] [email protected] 4 points 9 months ago

You can find payload lists out there in the wild. Here is a repository filled with them: https://github.com/payloadbox

We use lists like these, which are generally benign, to test websites for vulnerabilities. My theory is that the software they use to manage these text messages is probably web based and not designed for this kind of input. XSS like this, if executed, could cause an endless stream of popups on their side similar the days of the wild wild web. It's not going to hurt anything, but they won't want to reference my text logs any more.

Obviously, there are a ton of caveats. Depending on how the message is secured in transit, your carrier might block it. I dunno as I have never worked in the mobile security space. You might piss your own phone off. You might break your own message histories..

There are a ton of unknowns, btw. I personally don't give a fuck about any of them.

[–] [email protected] 31 points 9 months ago* (last edited 9 months ago) (2 children)

You are on the right track. Starting at 2x and increasing your price is awesome!

Most of them will want to "assess the value" first or something else to keep the conversation away from money, at first. They want to try and hook you, then low-ball the fuck out of you. You need to confuse their routine at all costs.

Flipping the script will usually confuse them. If you are familiar with high pressure sales, use everything in the book. Sob stories, FOMO, extreme sense of urgency, etc. Start pressuring the fuck out of them to buy and don't let them distract you with stupid shit.

Now that I am thinking about it, I haven't gotten one of those calls in months. I started dumping pages of XSS and SQL injection test scripts back at automated texts so there is a chance I broke something. Dunno.

[–] [email protected] 1 points 9 months ago* (last edited 9 months ago)

All cultures are weird as shit when you look at them from the outside.

(No, I am not excluding myself. There are plenty of people that could easily consider me weird as fuck. I rather enjoy that, so it kinda works out in the end.)

[–] [email protected] 2 points 9 months ago (1 children)

I got that part but I had just imagined someone giving a bit fat sloppy lick across a signature line. (My brain can be quite broken at times.)

[–] [email protected] 7 points 9 months ago (1 children)

Everyone else gives your data away for you. You don't even need to lift a finger.

[–] [email protected] 4 points 9 months ago (3 children)

That description makes weird pictures in my brain.

[–] [email protected] 13 points 9 months ago (6 children)

Oh, Japan! Don't you ever change.

[–] [email protected] 7 points 9 months ago (1 children)

You do what, now? Is tok'ing what the kids are calling it these days?

[–] [email protected] 55 points 9 months ago (3 children)

Short-form videos are basically a form of cancer that keeps you alive with shots of dopamine every 15-30 seconds. I avoid those things like the plague.

[–] [email protected] 2 points 9 months ago* (last edited 9 months ago)

Totally. Properly trained AI would probably just flood a country with misinformation to trigger a civil war. After it installs a puppet government, it can leverage that countries resources against other enemies.

[–] [email protected] 11 points 9 months ago

Even within AWS, many of their services still don't support ipv6. AWS fees for ipv4 addressing may end up being a comparatively big driver for adoption.

You just outlined a reason for AWS not to fully support IPv6 as well.

view more: ‹ prev next ›