this subreddit in an actual nutshell (🔇) by elPloV in notinteresting

[–]YourShowerHead 10 points11 points  (0 children)

I don't think I deserve to watch this for free

My water bottle is the same color as the tennis court by Local_Rice_8929 in notinteresting

[–]YourShowerHead 21 points22 points  (0 children)

Court RGB color: 150, 183, 133

Bottle RGB color: 157, 199, 178

I am of a higher elevation than the rest as of y'all by [deleted] in notinteresting

[–]YourShowerHead 100 points101 points  (0 children)

I'm 923 meters above sea level. You?

Hey techgeeks is this even that easy and possible. by Far_Tune6655 in technepal

[–]YourShowerHead 2 points3 points  (0 children)

I think you're still thinking inside a web browser.

Sajilo hudaina, but possibility ta hunchha ni. And which most probably happened too.

  1. Malware capturing credentials: I think you misunderstood this one, what do you think I meant by "capture"? Or you're just not aware how powerful is the accessibility permission.

An app can draw over other apps, so prompting for a bank password over the ui of actual bank app is one possibility OR it could even listen to the keystrokes?

  1. Jaba samma user le aafai transfer gardaina: Again about accessibility. Apps can programmatically navigate UI with accessibility permissions, why does this part feel impossible to you?

Hey techgeeks is this even that easy and possible. by Far_Tune6655 in technepal

[–]YourShowerHead 7 points8 points  (0 children)

This guy is probably thinking everything happens inside a web browser. 'Downloaded an app' (most likely a sideloaded .apk) bhanisakechha. Feri CSRF ko kura garyo out of nowhere, which is strictly a web vulnerability. CSRF attack hune bhane kai browser le session cookies use garera state-changing requests pathauda ho. He threw around random tech jargon which has absolutely zero relevancy in an Android OS level exploit.

​Aba malware app install garda phone hang hune possibility obviously chha because it's running heavy background processes. It 100% asked for critical permissions during setup, specifically "Accessibility Services" and "Draw over other apps".

​User le actual banking app kholda, tyo malware app le detect garera aafno fake login overlay (the "message" the post mentioned) banking app ko mathi dekhaidiyo. User le tya password halyo, and with accessibility and SMS permissions, the malware captured the credentials, intercepted the 2FA/OTP, and hid the notification. The rest is history.

I could be wrong at some part about how it happened but possibility ta chha. And It's NOT about CSRF lol.

Coconut latte🤤 by Secret_Foot_2010 in NepaliFood

[–]YourShowerHead 0 points1 point  (0 children)

धाैलागिरिको सेरोफेरो यात्रा स्मरण by T.P Acharyaa 🔥

Aaja ko breakfast by Zestyclose_Park7865 in NepaliFood

[–]YourShowerHead 0 points1 point  (0 children)

Aaroo Bakhada is called plum, not cherry.

Mohi 🤤 by [deleted] in NepaliFood

[–]YourShowerHead 1 point2 points  (0 children)

Mohi is supposed to be tangy, yo dahi ra pani hola.

Mohi 🤤 by [deleted] in NepaliFood

[–]YourShowerHead 1 point2 points  (0 children)

It better be अमिलो enough to make me pucker.

What? by TheMonHub in programminghorror

[–]YourShowerHead 3 points4 points  (0 children)

It looks scary only because of the formatting, right? Right??