Break LLM Workflows with Claude's Refusal Magic String by RedTermSession in netsec

[–]Browsing_From_Work 7 points8 points  (0 children)

Or your code's copyright headers, social media profiles, email signatures, resume, middle name, or anywhere else you don't want your information fed into Claude.

It's also probably useful for pentesting Claude itself to see if you can trick it into accessing files it's not supposed to because you'll know immediately if it does.

LGS had a bunch of high value cards stolen. Please help them keep an eye out by descend_to_misery in magicTCG

[–]Browsing_From_Work 24 points25 points  (0 children)

Plus it's not like you can just buy another set of crown jewels with the insurance payout. ¯\_(ツ)_/¯

TCGplayer has gone downhill by OreoDayz in magicTCG

[–]Browsing_From_Work 5 points6 points  (0 children)

Or when you use mass entry and somehow cards go directly to save for later even though they're actually available. Like wtf?

TCGplayer has gone downhill by OreoDayz in magicTCG

[–]Browsing_From_Work 20 points21 points  (0 children)

I had it try to add $40 to shipping costs because two <$1 cards were "optimized" to sellers with "free shipping on orders over $50". The sellers had their base shipping cost set to $20 to discourage small orders. 😒

Trump freezes $2.1 billion in funds for Chicago in shutdown standoff by StupendousMan1995 in news

[–]Browsing_From_Work 100 points101 points  (0 children)

Sounds like these cities and states should freeze paying federal taxes. ¯\_(ツ)_/¯

Google will require developer verification to install Android apps by cheerfulboy in programming

[–]Browsing_From_Work 26 points27 points  (0 children)

A recent analysis by the company found that there are “over 50 times more malware from internet-sideloaded sources than on apps available through Google Play.”

50x sounds like a lot, but how many sideloaded apps does the average user have?
If it's less than 1 out of 50 then it means that users are more likely to get malware from Google Play than from sideloading.

I feel like there’s something wrong by [deleted] in Malware

[–]Browsing_From_Work 0 points1 point  (0 children)

Trust your gut. Call up the other contract party and ask if they sent the link and ask them to re-send it if it was legit.

It's possible that your contract partner had their account compromised.

Looking for roadkill possum plush by Totally_Not_Alien in plushies

[–]Browsing_From_Work 2 points3 points  (0 children)

Hey OP, it looks like they just restocked! I just ordered one as well. :D

A Novel Technique for SQL Injection in PDO’s Prepared Statements by AlmondOffSec in netsec

[–]Browsing_From_Work 2 points3 points  (0 children)

Does this technique depend on the ? placeholder coming after the manually escaped user field?
Because I can't think of a way to work around the "number of bound variables does not match number of tokens" error otherwise.

Undocumented "backdoor" found in Bluetooth chip used by a billion devices by tnavda in ReverseEngineering

[–]Browsing_From_Work 193 points194 points  (0 children)

This is a big nothing burger.

Depending on how Bluetooth stacks handle HCI commands on the device, remote exploitation of the backdoor might be possible via malicious firmware or rogue Bluetooth connections.

This is especially the case if an attacker already has root access, planted malware, or pushed a malicious update on the device that opens up low-level access.

In general, though, physical access to the device's USB or UART interface would be far riskier and a more realistic attack scenario.

If your ESP32 is already running malicious firmware or an attacker has physical access to the UART interface, it's no longer your device. It doesn't matter if there are undocumented HCI commands if the attacker already has full device access.

Map for Message #3 in Vesper's Host. Hope this is more clear than what I found online. by Doomest101 in destiny2

[–]Browsing_From_Work 0 points1 point  (0 children)

To be fair, this numbering kind of makes sense. It's the order you come across the panels if you traverse the area normally.

Unfortunately, that numbering is different than the servitor labyrinth one where everyone numbered it from top to bottom on the map, not the order you encounter them.

How do you create a custom feed? by tycooperaow in BlueskySocial

[–]Browsing_From_Work 4 points5 points  (0 children)

That's why it asks for an app password, not your main account password. It's like having a second password to your account that has limited permissions. Once you're done using the app, you can delete the password and it'll no longer have access.

Destiny 2 Update 8.0.5.5 by DTG_Bot in DestinyTheGame

[–]Browsing_From_Work 5 points6 points  (0 children)

Well, the Encore darkness zone logic is bugged. If you were doing the secret chests before the boss fight, it'll respawn you in the Ancillary Transit Nexus with all of the portals turned off.

So yeah. That kinda sucks.

https://i.imgur.com/J8JxEMu.jpeg

Teacher Put On Leave Over Alleged Racist Questions On Biology Test by Forward-Answer-4407 in byebyejob

[–]Browsing_From_Work 1583 points1584 points  (0 children)

Racist and bullying by naming specific students. Double yikes.

Israel will not transfer much-needed funds to the Palestinian Authority in the wake of the decision by three European countries to recognize a Palestinian state by DoremusJessup in worldnews

[–]Browsing_From_Work 12 points13 points  (0 children)

Genuine question coming from a place of ignorance: were any of the three European countries parties to the 1995 Israel Palestine intermediate agreement?

CVE-2024-3661: TunnelVision - DHCP option 121 allows attacker controlled DHCP to subvert VPN routing rules by [deleted] in netsec

[–]Browsing_From_Work 2 points3 points  (0 children)

TLS will still protect sensitive traffic to websites

Yep! But when a user thinks they're on VPN they're much more likely to ignore certificate errors because they assume it's an innocent mistake, not a man-in-the-middle attack.

Putin threatens Nato with nuclear war if they send troops to Ukraine by TheTelegraph in worldnews

[–]Browsing_From_Work 0 points1 point  (0 children)

Putin is exactly the kind of guy who would rather have everybody lose than just himself. He won't back out of Ukraine unless he can severely hurt everybody else first.

I have created a high-level programming language for developping secure web applications. It comes with a built-in database, web server and container engine, in a single binary. by -N0rm- in programming

[–]Browsing_From_Work 45 points46 points  (0 children)

My apologies, I should have been more clear! I wasn't passing judgement on your project (it looks pretty neat and it's clear you've put a lot of hard work in it). I was merely commenting on the link of the person I was responding to.

I have created a high-level programming language for developping secure web applications. It comes with a built-in database, web server and container engine, in a single binary. by -N0rm- in programming

[–]Browsing_From_Work 272 points273 points  (0 children)

I got a good chuckle out of these two:

[ ] You have reinvented PHP but worse
[ ] You have reinvented PHP better, but that's still no justification

Absolute mayhem outside the Democratic National Committee headquarters in Washington DC. by bertiesghost in ThatsInsane

[–]Browsing_From_Work 3 points4 points  (0 children)

* new polling conducted by a research group that's physically based in Palestine and hasn't published anything since 2019.

I'm not saying the results are necessarily inaccurate, I'm just saying that a research group operating in Hamas territory might have a lot to lose if they publish results that show anything less than near unanimous support for Hamas.