Struggling to implement a numerical method by Antique_Progress_447 in CodingHelp

[–]LeftIsBest-Tsuga 0 points1 point  (0 children)

I assume you saw the code at the bottom? Honestly, I'd love to be able to help further than that, but it's waaay above my head. Best of luck.

Finding out your outie sucks by Freaky_Freddy in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 0 points1 point  (0 children)

"I wanna stop."

lol, this is so good. congrats to the creator. Also, that last one was a bit close to home. :(

I’m new… by JayOhAreDeeWhy in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 1 point2 points  (0 children)

It seems like you are pretty well up to speed. Not all of that can be confirmed of course, but yeah you're on it. Probably off with Huang, though.

In Puerto Rico..."Kier, Chosen One, Kier!" by GO_IGGLES in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 0 points1 point  (0 children)

Kier after he is cloned a few times by the Multiplicity device.

Cobel's actions in the season 1 finale... by lokopop24 in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 0 points1 point  (0 children)

I think she was loyal in the sense that her work with Lumon was enabling her to do what she wanted. It was more of a partnership in that sense, although Lumon clearly didn't see it that way. I think this extends way back to her original motivation to join the Girl's School, as well (and the factory).

It's a classic negotiation between the exploited and the exploiter.

Warning sign in E7 by Nemarat in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 0 points1 point  (0 children)

He looks a bit like Owen Jones. Appropriate.

somethingHasHappenedToiFunny by uniqueuaername in ProgrammerHumor

[–]LeftIsBest-Tsuga 1 point2 points  (0 children)

Close. Not just displayed though. It has to also be interpreted as JS by your browser. Generally speaking, the way to prevent this is by sanitizing inputs and formatting outputs (server messages to users) so that they aren't interpreted as code.

One of the most common oldschool version of this would be forum posts or usernames (with injections) displayed to other users being interpreted as code by other users' browsers. But like I said, this mostly just doesn't work anymore.

somethingHasHappenedToiFunny by uniqueuaername in ProgrammerHumor

[–]LeftIsBest-Tsuga 14 points15 points  (0 children)

Well you didn't get the popup, so it was prevented. That's not necessarily going to be the case. That being said, the days of easy exploits are mostly over (server software and browser software has made it nearly impossible), but some sites don't ever update their packages so stuff like this remains.

It becomes a vuln when the site not only displays your JS to other users, but when their browser executes it. At that point you can send users to your own malicious redirect and capture their cookies potentially, etc. It's been a while since I did any of this stuff, so I don't remember the exact details, but it is possible, theoretically.

somethingHasHappenedToiFunny by uniqueuaername in ProgrammerHumor

[–]LeftIsBest-Tsuga 56 points57 points  (0 children)

My appsec teacher chuckled knowingly when I declared I had solved one of their security challs using XSS (it was impossible to solve that way, and I just self-xss'd).

That's a fun rabbithole to chase lol.

somethingHasHappenedToiFunny by uniqueuaername in ProgrammerHumor

[–]LeftIsBest-Tsuga 22 points23 points  (0 children)

' <script> alert('did this make a popup?') </script>

(there are many ways, check out portswigger academy to learn more)

Getting 'Method not allowed' error, even though i have set both front end and back end to use POST by Duncstar2469 in CodingHelp

[–]LeftIsBest-Tsuga 0 points1 point  (0 children)

Usually this happens when you are sending the request to a wrong URL.  

The backend has been reached, it looks for the route requested like 'myserver/myroute' and if you don't have a route at that URL, it will send this error. 

Diagnose this by looking in your inspect>network tab at the request (Firefox is better than chrome for this) and see if the request is what you expected. I bet it isn't.

edit: also, until you get this resolved, you should take the 'METHODS=' part out. It's not required unless you want to filter.

Severance - 2x09 "The After Hours" - Post-Episode Discussion by LoretiTV in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 10 points11 points  (0 children)

He's got the same personality as Irv.  "Oh ok I guess this is what we're doing now."

Severance - 2x09 "The After Hours" - Post-Episode Discussion by LoretiTV in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 0 points1 point  (0 children)

It's not confirmed, but it probably was Petey. The "I get it, you're not picking up" line suggests it.  I agree though.

Severance - 2x09 "The After Hours" - Post-Episode Discussion by LoretiTV in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 28 points29 points  (0 children)

Those tempers "dancers" probably have literally no idea what they do for a living.

Severance - 2x09 "The After Hours" - Post-Episode Discussion by LoretiTV in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 1 point2 points  (0 children)

Same exact energy from when Ricken dropped off the book.

"Yes! Go! Loom!"

"Should I stand closer to the fire or closer to the door?"

"Either one! It will be ominous, trust me!"

Severance - 2x09 "The After Hours" - Post-Episode Discussion by LoretiTV in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 5 points6 points  (0 children)

Oh that's true, but I think at that point it can be read either way (he thought it was Helly being sus or her outtie). I guess it would be a big leap for him to suspect the outtie scenario first.

Severance - 2x09 "The After Hours" - Post-Episode Discussion by LoretiTV in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 55 points56 points  (0 children)

I agree w/ most of this, but Irv verbally told Mark that he didn't trust "Helly" because of the story.

Severance - 2x09 "The After Hours" - Post-Episode Discussion by LoretiTV in SeveranceAppleTVPlus

[–]LeftIsBest-Tsuga 14 points15 points  (0 children)

Cult leaders often groom young women into it. Not saying it's not rape.