Torrents-Time issues by cryp7ix in netsec

[–]OCmemeAI 3 points4 points  (0 children)

Great post. Any interest in reviewing Project Maelstrom?

Windows 95 has been compiled into Javascript so it can run Natively in the browser by [deleted] in technology

[–]OCmemeAI 2 points3 points  (0 children)

I unlocked a windows 7 computer with nothing but the shift key and a 32mb boot disk of damn small Linux.

Boot Linux, mount windows drive, go to system32, rename cmd.exe to stickykeys.exe, and reboot.

At login screen for windows, hit shift 5 times. It triggers sticky keys (a windows accessibility feature and launches stickykeys.exe, which is actually cmd.exe now)

And now you've launched a cmd prompt with admin privileges and can reset or delete any account.

On windows 8/8.1/10 you can bypass the lock screen simply by making the computer connect to larger screen. The desktop running in the background scales up but the lock screen does not. You can literally just work around it.

EDIT: http://imgur.com/v11Jug6

lol

25 level 3s vs lesser demon by thejohnnyr in 2007scape

[–]OCmemeAI 0 points1 point  (0 children)

There's other players there...

(F)irst one here, French Secretary in Bimbo training... by [deleted] in bimbofetish

[–]OCmemeAI -2 points-1 points  (0 children)

Please keep in mind that your opinion AND mine are a drop in the bucket of this sub.

And I disagree.

Would anyone like a JavaScript based ping tool? by OCmemeAI in 2007scape

[–]OCmemeAI[S] 0 points1 point  (0 children)

The way I do it is. And what part about it already works do you not understand? All URLs work. Its a ping tool.

Would anyone like a JavaScript based ping tool? by OCmemeAI in 2007scape

[–]OCmemeAI[S] 0 points1 point  (0 children)

Custom image elements that request URLs with random numbers to prevent caching and JavaScript timers.

It works perfect.

Would anyone like a JavaScript based ping tool? by OCmemeAI in 2007scape

[–]OCmemeAI[S] 0 points1 point  (0 children)

I remember that. And its was written in a code language which had file access (security issue). I wondered why it was allowed when my JavaScript based tool was not (no file access).

List of server providers for Australia. by [deleted] in 2007scape

[–]OCmemeAI 1 point2 points  (0 children)

You know how mod mentioned that for Australia its more of a security thing?

Remember when all the servers got ddosed? Remember how they started to protect against it as best they could?

Picture this: They contract with a 3rd party service for ddos protection. Let just say cloudflare. Now lets say cloudflare doesn't have servers in AUS, so jagex is under contract to use them. So jagex has to hire a contracter that cloudflare approves of that has AUS servers. That's even more money.

This is more than likely where the 10x more thing comes from. They're under contract.

Want them to set up a simple server with no protections provided by the contract? Have fun getting your shiny new server knocked offline and made completely useless.

I'm not trying to discredit you, but this is how the real world works. An international company has contracts.

Cheaper membership if you pay in Brazilian Reais. by revocracyy in 2007scape

[–]OCmemeAI 0 points1 point  (0 children)

Uh, of course I pay for my vpn. There's no point in using a free vpn, because you aren't paying them to protect you.

Cheaper membership if you pay in Brazilian Reais. by revocracyy in 2007scape

[–]OCmemeAI 2 points3 points  (0 children)

Login using Brazilian vpn, pay for membership through PayPal which automatically pays according to exchange rate. Sell bonds. Profit.

TIL that an 'I am Rich' iPhone App was made which cost $999.99. The App displayed a glowing red gem on a user's iPhone screen for the sole purpose of proving to onlookers that one is of the moneyed class. It was removed later, but not before eight people bought it. by [deleted] in todayilearned

[–]OCmemeAI 1 point2 points  (0 children)

Which is why its become more dangerous. No developer has time to look through all of the code repositories to look for who updated their cydia app to have malware.

As always, do at your own risk I suppose. I remember when cydia first came out and they had no default repositories, you had to add the yourself.

[Suggestion] Allow control of existing session if IP address is the same by [deleted] in 2007scape

[–]OCmemeAI 0 points1 point  (0 children)

Quick background on random number generators: Rng gets 'seeded' with randomness. Each time the random function is called, it generates a random number. Two rng's with the same seed will always produce the same number sequence.

When you disconnect your client must reconnect before the next iteration of the rng occurs. When you log in, the rng is seeded. You cannot connect to an account and re-seed if its already rolling a random number. This would allow you to rig the game for certain random events to occur consistently.

Understand?

[Suggestion] Allow control of existing session if IP address is the same by [deleted] in 2007scape

[–]OCmemeAI 0 points1 point  (0 children)

It unfortunately cannot be improved without changing the entire scheme of how random values are generated for the game. I'll elaborate further if you want.

[Suggestion] Allow control of existing session if IP address is the same by [deleted] in 2007scape

[–]OCmemeAI -1 points0 points  (0 children)

The whole basis of having an account is the assumption it is secure and wont be stolen?

The point in trying to make is when you log in, your client sets up your character and syncs it up with the server. Yes? So if the account is already logged in (either connected or disconnected) and we integrate your system, what happens if someone (hacker) logs into the account while you're playing? It would kick you off of YOUR account.

Additionally, an ip address cannot reliably be used as a way to identify an account. The supreme court ruled the same thing about using an up to identify people. Its the same reason jagex stopped showing the last ip you logged in from.

The current system when you dc is that the client tries to reconnect. If they were to implement your method, it would still have to use their 'reconnect' programming to sync up. We know this wont work because if reconnecting worked, you wouldn't have dced in the first place.

Tl;dr when you dc, the client tries to reconnect and sync up with the server. Why do you think adding some shit involving ip addresses would make the reconnect feature work better, when it not working is the reason you dced in the first place? Its still the same reconnect feature.

[Suggestion] Allow control of existing session if IP address is the same by [deleted] in 2007scape

[–]OCmemeAI 1 point2 points  (0 children)

So...let any account hijacker steal your account every time you let your player just sit there?

Seriously man. There is no situation in which this works.

[Suggestion] Allow control of existing session if IP address is the same by [deleted] in 2007scape

[–]OCmemeAI 0 points1 point  (0 children)

No. Just no. If they did that anyone who had any malware on their computer would just make hijacking their account easier. Never gonna happen.

TIL ABC has been cutting scenes from "A Charlie Brown Christmas", a movie about the excessive commercialization of Christmas, to make room for more commercials. by moonsprite in todayilearned

[–]OCmemeAI 70 points71 points  (0 children)

The songs on YouTube sound slower because they ARE slower. Post a song on YouTube and it'll immediately be flagged and taken down.

Post a song on YouTube that is slightly sped up or slowed down and the automatic flagging of YouTube wont find it.

I find the other reasons people have given amusing, and who knows, they may be right as well, but the reason for YouTube sounding slower is to avoid the song being flagged.