I am but a cog in a machine. A lazy one though.
If you are new on Lemmy, check out: https://lemmyverse.net/communities for communities to join!
- 96 Posts
- 1.3K Comments
Lazycog@sopuli.xyzto Cybersecurity@sh.itjust.works•PyPI, npm, and AI Tools Exploited in Malware Surge Targeting DevOps and Cloud EnvironmentsEnglish1·4 days agoWhat the hell
Solders, on the other hand, has been found to incorporate a post-install script in its package.json, causing the malicious code to be automatically executed as soon as the package is installed.
“At first glance, it’s hard to believe that this is actually valid JavaScript,” the Veracode Threat Research team said. “It looks like a seemingly random collection of Japanese symbols. It turns out that this particular obfuscation scheme uses the Unicode characters as variable names and a sophisticated chain of dynamic code generation to work.”
Decoding the script reveals an extra layer of obfuscation, unpacking which reveals its main function: Check if the compromised machine is Windows, and if so, run a PowerShell command to retrieve a next-stage payload from a remote server (“firewall[.]tel”).
This second-stage PowerShell script, also obscured, is designed to fetch a Windows batch script from another domain (“cdn.audiowave[.]org”) and configures a Windows Defender Antivirus exclusion list to avoid detection. The batch script then paves the way for the execution of a .NET DLL that reaches out to a PNG image hosted on ImgBB (“i.ibb[.]co”).
“[The DLL] is grabbing the last two pixels from this image and then looping through some data contained elsewhere in it,” Veracode said. “It ultimately builds up in memory YET ANOTHER .NET DLL.”
Furthermore, the DLL is equipped to create task scheduler entries and features the ability to bypass user account control (UAC) using a combination of FodHelper.exe and programmatic identifiers (ProgIDs) to evade defenses and avoid triggering any security alerts to the user.
The newly-downloaded DLL is Pulsar RAT, a “free, open-source Remote Administration Tool for Windows” and a variant of the Quasar RAT malware.
Honestly, at this point the hacker deserves to empty my bank account.
same. Thankfully it wasn’t fathers day in my home country yet!
Oh god… You’ll have to learn IIS. Internet Inf🤮rmation Services.
In all seriousness Windows Server is much more enjoyable than Home/Pro/Enterprise or whatever the desktop versions are called. You have more control over the system and they don’t hinder you from configuring stuff unlike on the desktop version.
Someone already suggested to get a VPS and just get to know the system. A tip though if you have to spin up a windows server on Azure vs somewhere else: search for info with the keyword “azure”. Microsoft stuff seems to work worse on their own cloud than anywhere else. MS SQL Server and Azure’s version of MS SQL Server differs and lacks features.
Been a long time since I had to use any of the above so things might have changed.
Wikipedia explains some history of dates that are not on Saint Joseph’s day, but couldn’t find a detailed explanation for every country.
Also found out some wild stuff like:
In France lighter manufacturer Flaminaire introduced the idea of Father’s Day first in 1949 for commercial reasons. Director Marcel Quercia wanted to sell their lighter in France. In 1950, they introduced “la Fête des Pères”, which would take place every third Sunday of June (following the American example). Their slogan is “Nos papas nous l’ont dit, pour la fête des pères, ils désirent tous un Flaminaire” (Our dads told us, for Father’s Day, they all want a Flaminaire). In 1952, the holiday was officially decreed.
The write-up I’m referencing has some at the end. Maybe Delta chat?
Symbolic and actually very cool.
Lazycog@sopuli.xyzOPMto Language Learning@sopuli.xyz•How's your language learning going this week? - Weekly thread3·5 days agoYeah I haven’t found another fun replacement for Duolingo. The FOSS project “LibreLingo” has been abandoned long time ago too…
Lazycog@sopuli.xyzOPMto Language Learning@sopuli.xyz•How's your language learning going this week? - Weekly thread4·5 days agoHa, exact problem I had! Moved abroad and that fixed it ;)
Jokes aside, that’s a real problem for most people who work full time :(
Lazycog@sopuli.xyzOPMto Language Learning@sopuli.xyz•How's your language learning going this week? - Weekly thread4·5 days agoThis is kinda how I started my language learning journey as well, but realized after a year of no progress that I need a structured course to truly get that motivation and progress.
If you have a possibility to take a course somewhere in your town I highly recommend! Might meet new people and have fun too! :)
Views that seriously harm or endanger other people are dangerous.
If the founder would have opposing views in e.g. should we narrow down the car roads in cities and widen the pedestrian walks - ok. I think there’s a lot to this question, I think pedestrian walks should be wider, cars are dangerous, etc. But this is not as dangerous as:
“Do you deny scientific evidence that COVID is real and a real danger to a lot of humans”
SimpleX Chat – Many suggested this and I will explicitly recommend against it due to the founder’s positions on various topics. This includes being anti-vaxx, believing COVID-19 was a hoax, trans- and homophobia, climate denial; In the SimpleX Groupchat he’s also been seen basically bootlicking trump a couple times, but I’ve lost receipts to that.
I did not know this. I’ve seen people recommend SimpleX on lemmy too, but probably they didn’t know.
I did the same two years ago. All content still deleted.
Wanted to make sure my deletions are not caught by some automated system so deleted posts and comments manually over the span of two weeks whenever I was waiting for something / had time.
Edit: added that this was 2 years ago
Lazycog@sopuli.xyzto Castles - Migrating to feddit.online@lemm.ee•Will this community be moved to another instance?English2·7 days agoAwesome, thank you!
Without delving into this, Lemmy’s modlogs are public, you can see mod actions that are done to your posts/comments here:
https://lemm.ee/modlog?page=1&actionType=All&userId=20146219
Edit: edited words. Also, just incase you missed it: your instance (lemm.ee) is shutting down soon. You might want to export your settings and migrate to another instance soon (exporting an account means saved posts, settings and preferences). More info about lemm.ee shutting down here.
It’s a really nice app for openstreetmap data, beautiful even. I also find the UI really nice and uncluttered and intuitive to use. Best of all: allows you to contribute to openstreetmap directly inside the app!
Hope you enjoy it as much as I do :)
Glad I could answer!
Yeah I had no idea either how bad it was until another user on lemmy pointed out the company that has been set up by the owners, and then one day @Sunshine@lemmy.ca posted the open letter in !organicmaps@sopuli.xyz.
And other good news: the community fork developers (who also were trusted and long established contributors of OM) allowed us to make the lemmy community !CoMaps@sopuli.xyz an official community! They participate in that community too!
Lazycog@sopuli.xyzto Fediverse memes@feddit.uk•Anybody else kinda annoyed with this, or am I just being ridiculous lolEnglish1·7 days agoWhat the hell. That is kinda neat but annoying in this case.
Try to browse this community (on mastodon the hashtag #fedimemes) and find this post, then click on the post to see this thread:
https://mastodon.social/tags/fedimemes
I hope the tag search doesn’t also redirect to lemmy since its not specifying the lemmy instance in the url.
And sorry about answering you directly instead of editing the above. I believe lemmy pings the users i’ve tagged if I edit the post and I don’t wanna annoy everyone.
Edit: words
Lazycog@sopuli.xyzto Fediverse memes@feddit.uk•Anybody else kinda annoyed with this, or am I just being ridiculous lolEnglish20·8 days ago@metaStatic@kbin.earth @cm0002@lemmy.world @atro_city@fedia.io
They kinda have threads, it’s a bit of a different format and they don’t have communities really. check this current post out on mastodon: https://mastodon.social/@cm0002@lemmy.world/114678153485329034
If you don’t include the names your comment appears as a standalone toot under cm0002’s post.
The communities on lemmy are actually hashtags on mastodon. cm0002 made this post under their own profile and hashtagged the “community” (fedimemes).
Edit: corrected myself
Lazycog@sopuli.xyzto Fediverse memes@feddit.uk•Anybody else kinda annoyed with this, or am I just being ridiculous lolEnglish23·8 days agoI love it when you got mastodon, lemmy, and friendica users in the same thread all just having a discussion. Really feels like an open network and what internet should be.
Installed and in daily use! Thanks comaps team ❤️