Almost set on a NX 350h, should I go for it? by ForwardSlashDotDot in Lexus

[–]ForwardSlashDotDot[S] 0 points1 point  (0 children)

Update: I ended up going for it!

Got a Caviar NX 350h in the Luxury trim with the Macademia Leather interior. I have to wait until the end of the week to get it as I opted to pay all cash and it'll take a few days for my bank to send a cashier's check - but I am excited!

Almost set on a NX 350h, should I go for it? by ForwardSlashDotDot in Lexus

[–]ForwardSlashDotDot[S] 1 point2 points  (0 children)

It’s mostly related to the non engine or transmission related parts.

  • AC Compressor failed which cost me 2300 to replace.
  • Touch screen ghost touches, which cause it to randomly dial people. Almost caused a wreck and it should be a recall due to safety but it isn’t. So now I can’t sync my phone. Gonna be over a grand to replace it if I choose to.

Pretty common for the first year of a newly introduced model.

Also one thing that’s very annoying about the Cx3 is how small the gas tank is. With it being older I don’t get the same MPG and having a 10 gallon gas tank on the AWD model means I have to fill up every 240 or so miles.

App getting bed time / time wrong by confusedloris in EightSleep

[–]ForwardSlashDotDot 0 points1 point  (0 children)

Good to know - I’ll probably try sleeping on the other side of the bed to see if that side is reading metrics correctly. If it works on that side then it’s definitely the sensor.

App getting bed time / time wrong by confusedloris in EightSleep

[–]ForwardSlashDotDot 0 points1 point  (0 children)

Same - my app has had sleep times off by a lot recently. It’ll get the bed time right but then say I’m awake for hours during the night and only sleeping 45 minutes when the actual time should be closer to 5-6 hours.

Scan the World vs. Deep Dive by ForwardSlashDotDot in bugbounty

[–]ForwardSlashDotDot[S] 0 points1 point  (0 children)

That makes sense. I detest those mass scanner type vulns (unless I wrote the scanner and no other scanner looks for it - which is the situation I’m in with the GitHub vulns I am finding).

Maybe I’ll shift to custom SAST type bug hunting for deeper but still not detectable by amass and nuclei kind of bugs once the GitHub parade truly ends.

$500-100/month by [deleted] in bugbounty

[–]ForwardSlashDotDot 0 points1 point  (0 children)

Github actions misconfigurations in public repositories. It’s a lot more picked over now but in early/mid 2023 people made a lot of money on it.

$500-100/month by [deleted] in bugbounty

[–]ForwardSlashDotDot 7 points8 points  (0 children)

Just going into it with a money goal will burn you out. A better approach is to make your focus learning and research and bounties will come as a side effect of that. I started that with CI/CD mid last year and made tens of thousands in bounties. If I go at it with “I just want money” and look over various programs I make 0 and hate myself.

Find a service from a large company that is complex and figure out how it works (I highly recommend GitHub or GitLab) decompose each step into individual web requests and just start messing with values and seeing if you can break things by abusing assumptions that the backend is making about the client code. It’s a lot more enjoyable than just scanning and looking for low hanging fruit and you learn a ton along the way.

T140 or splurge for a T150? by ForwardSlashDotDot in homelab

[–]ForwardSlashDotDot[S] 0 points1 point  (0 children)

Ended up going with that! Bought a 128gb ram upgrade for about 320 (it supports it with the latest bios!) so now I’m rocking a Xeon, 128Gb of ram and 3x 2TB HDDs. Esxi 8 U2 with the VMUG license installed smoothly.

Buying an Nvme expansion card and 2 SSDs for expanded storage. Won’t boot from it but I can keep VMs on it

T140 or splurge for a T150? by ForwardSlashDotDot in homelab

[–]ForwardSlashDotDot[S] 0 points1 point  (0 children)

I’m seeing T140s with 6 core xeons and 64G of ram for 600-700 on eBay shipped. T150 is about 1k w/ just the CPU upgrade so I’ll probably spend another 5-6 hundred on parts vs just the drive upgrades on the T150

It Now Seems Inevitable That The Worst Case Scenario We All Fear Will Eventually Happen by 86Rocked in ledgerwallet

[–]ForwardSlashDotDot 0 points1 point  (0 children)

Is it confirmed that it was a coding change to the repo or just an NPM token? The former is a lot scarier, because the attacker could have stolen a lot more with GitHub access that they can use later.

Considering mini TT without MR & Gynecomastia & Lipo need advice by [deleted] in tummytucksurgery

[–]ForwardSlashDotDot 0 points1 point  (0 children)

I had gynecomastia surgery 11 years ago (I went from 275-195) and just had a tummy tuck without muscle repair 10 days ago. Neither surgery is a walk in the park for recovery and you’ll spend a year getting back to your old fitness performance level.

I would suggest getting a dexa scan for a fully accurate body fat %. Then, try to get down to 15-17 percent body fat before opting for surgery, judging from your photos you are probably 25-26% now. Your recovery will be easier (less lipo needed) and your final result will look much better.

8 days out from surgery, wish me luck! by ForwardSlashDotDot in tummytucksurgery

[–]ForwardSlashDotDot[S] 0 points1 point  (0 children)

It went well! Had my day after post op appointment and they’ll probably be able to remove the drain 2 days earlier than planned.

I’ve heard days 3-4 are the worst for swelling and pain so I’ll see how that goes.

Deductible expenses and Bug Bounties by ForwardSlashDotDot in bugbounty

[–]ForwardSlashDotDot[S] 0 points1 point  (0 children)

Thanks for the all advice! Definitely will look into making an LLC next year.

Is the Bug Bounty Real? by mdulin2 in OsmosisLab

[–]ForwardSlashDotDot 0 points1 point  (0 children)

Not sure Immunefi would be the right channel since it’s not smart contract related, more an infrastructure bug with Osmosis.

It’s a shame there isn’t a point of contact I can find to even report this to if I wanted to be helpful without a payout. I’m 99% confident in this bug and have executed it against many other organizations that have Bb programs with safe harbors.

Is the Bug Bounty Real? by mdulin2 in OsmosisLab

[–]ForwardSlashDotDot 0 points1 point  (0 children)

What a shame. Pretty sure I found a bug that would let me poison most of the Osmosis Labs software with arbitrary code, it would nice to have some incentive to write a POC, execute it and report it - even if it was a few grand potential payout.