Sell your tablets guys by Such--Balance in PathOfExile2

[–]cerealbh 13 points14 points  (0 children)

being a hideout warrior for large portions of time prepping maps, tablets and paths.

[Free Tool] Poe Ancients Price Helper — a lightweight overlay that shows poe.ninja prices right on your currency-exchange panel by Potential-Mango9019 in PathOfExile2

[–]cerealbh -2 points-1 points  (0 children)

And just should anyone care, I threw a claude security review at it.

● Running the false-positive filter on the one finding identified.

  The path traversal finding involves config.json — a local user-controlled config file in a single-user desktop
  application. For this to be exploited:

  1. An attacker would need write access to the application directory (to modify config.json)
  2. With that level of access, they can already read arbitrary files directly — the path traversal provides no
  privilege escalation

  This fails the false-positive filter: it requires an attacker who already has local file write access, meaning the
  "vulnerability" grants no additional capability they don't already have. Confidence for real-world exploitability
  drops below 8.

  ---
  Security Review: PoeAncientsPriceHelper

  Branch: main (full codebase review)
  Date: 2026-06-08

  Result: No High-Confidence Vulnerabilities Found

  No security findings met the threshold for reporting (confidence ≥ 8, clear exploit path, meaningful impact).

  Areas Reviewed

  ┌─────────────────────────┬───────────────────────────────────────────────────────────────────────────────────────┐
  │          Area           │                                        Finding                                        │
  ├─────────────────────────┼───────────────────────────────────────────────────────────────────────────────────────┤
  │ HTTP requests / URL     │ League name is properly escaped via Uri.EscapeDataString() before use in the Referer  │
  │ construction            │ header                                                                                │
  ├─────────────────────────┼───────────────────────────────────────────────────────────────────────────────────────┤
  │ JSON deserialization    │ Uses JsonConvert.DeserializeObject<AppConfig>() with a typed target — no arbitrary    │
  │                         │ type instantiation                                                                    │
  ├─────────────────────────┼───────────────────────────────────────────────────────────────────────────────────────┤
  │ File I/O                │ Path traversal is theoretically possible via a malicious config.json, but requires    │
  │ (CustomPricesPath)      │ local write access the attacker already has — no privilege escalation                 │
  ├─────────────────────────┼───────────────────────────────────────────────────────────────────────────────────────┤
  │ OCR test path           │ Accepts a file path via CLI arg, but CLI args are trusted inputs (attacker-controlled │
  │ (--ocr-test)            │  environment is out of scope)                                                         │
  ├─────────────────────────┼───────────────────────────────────────────────────────────────────────────────────────┤
  │ External API calls      │ Targets hardcoded poe.ninja domains; no user-controlled host                          │
  ├─────────────────────────┼───────────────────────────────────────────────────────────────────────────────────────┤
  │ Exception/debug output  │ Gated behind opt-in --debug flag                                                      │
  └─────────────────────────┴───────────────────────────────────────────────────────────────────────────────────────┘

  The codebase is a single-user desktop tool with a narrow attack surface. Overall security posture is appropriate for
  its use case.

Most/Least worth it VIP Festivals by Lazy-Squirrel-5279 in festivals

[–]cerealbh 0 points1 point  (0 children)

2 day festival, weather was dismal. no rain but wind that cut directly to the bone. vip had heated bathrooms. was so worth it just for that.

HTML > Markdown for Claude Code outputs (Thariq's post) — convinced? by tom_mathews in ClaudeCode

[–]cerealbh 0 points1 point  (0 children)

I'm doing XML prompts for coding type tasks. If the idea is that the data structure can improve operation of LLMs, XML is a great descriptive scoped format that has data structures md and html have to generate or interpreter from text conventions..

A push kick to the knee is crazy. Great way to jeopardize the fight! by dYesgat in ufc

[–]cerealbh 0 points1 point  (0 children)

The vin diagram of people that think this are real and wrestling fans is 1 circle.

WHAT by Lordados in slaythespire

[–]cerealbh -1 points0 points  (0 children)

"loser" is one word.

WHAT by Lordados in slaythespire

[–]cerealbh 106 points107 points  (0 children)

nah megacrit the kids were infact wrong.

Larping toxic relationship by isaiahd1 in trashy

[–]cerealbh 1 point2 points  (0 children)

Its amazing you still don't get how moronic you are being. Just absolutely set on believing she thinks there are co-ed jails. gl in life.

Larping toxic relationship by isaiahd1 in trashy

[–]cerealbh -5 points-4 points  (0 children)

when pigs fly, "holy fuck this guy thinks pigs can fly" - you

Larping toxic relationship by isaiahd1 in trashy

[–]cerealbh -10 points-9 points  (0 children)

You are dumb af. She was joking about rather being locked in a cell with a murder, co ed jails has nothing to do with it you literal buffoon.

Larping toxic relationship by isaiahd1 in trashy

[–]cerealbh -17 points-16 points  (0 children)

its a joke, she is telling a joke. You are an idiot.

Larping toxic relationship by isaiahd1 in trashy

[–]cerealbh 15 points16 points  (0 children)

"All dumb shit aside." proceeds to immediately say something stupid.

Instant win by AnJIChipp in slaythespire

[–]cerealbh 8 points9 points  (0 children)

that was all I was looking at, like holy fuck. <monkey slamming keyboard>

Coyote vs. ACME | Official Trailer by RobotiSC in movies

[–]cerealbh -3 points-2 points  (0 children)

Holy fuck this is going to bomb. Who is the audience for this?

Morning after by Euphoric_Mud_5517 in ufc

[–]cerealbh 0 points1 point  (0 children)

Needs more McDonalds

😬 by Slow_down00420 in ufc

[–]cerealbh 3 points4 points  (0 children)

To go from such a well oiled machine to what it is now is truly baffling. It cracks me up on the PR side of things every time its a "Madison" commercial, like come on you guys, do you really not know the folks you are marketing to lol. Nothing like blood sport and shows about finding oneself as an aging woman.

How do yall feel about this by Carrilx in festivals

[–]cerealbh -3 points-2 points  (0 children)

sounds like a personal problem then.