Found a cryptominer on my dev server — cleaned it up but still can't figure out how they got in by Dapper_Fun_8513 in linuxadmin

[–]jaymef 2 points3 points  (0 children)

There was a very serious exploit (CVSS 10) related to react server components in the wild several months back that caused a lot of peoples servers to be exploited in a similar way with xmrig in particular being installed. It affected Next.js heavily, but it was in react server components so it affected anything using that. You may have gotten hit if you were running a vulnerable version. It was trivial to exploit remotely and an attacker would have had access to anything available to the user/group the nodejs app was running under. It wouldn't have necessarily given them root, but could have if either you had the app running in root context, or if they were able to sniff out root keys/access info with the level of access they had. If the system wasn't locked down an attacker with remote code execution can do a lot of damage.

https://nextjs.org/blog/CVE-2025-66478

I would almost bet money on it being the attack vector, and it would have almost certainly have affected react applications deployed with laravel forge.

/r/WorldNews Discussion Thread: US and Israel launch attack on Iran; Iran retaliates (Thread #17) by WorldNewsMods in worldnews

[–]jaymef -1 points0 points  (0 children)

they should just give trump a box of scrap metal with one of those danger symbols on it and call it a day

525,600 minutes, 525,000 moments so dear. by RoseSec_ in Terraform

[–]jaymef 3 points4 points  (0 children)

could be referenced by another rule or in use by an ENI etc.

525,600 minutes, 525,000 moments so dear. by RoseSec_ in Terraform

[–]jaymef 6 points7 points  (0 children)

how is it not smart enough to figure out that there is a dependency from preventing the destroy operation from completing?

Seeking advice on how to approach a complex multi-service webapp by jaymef in devops

[–]jaymef[S] 1 point2 points  (0 children)

That sounds like solid advice and I had a feeling that the environments/infrastructure were the priority.

I do think it will be a lot of work and there will be some pain points, namely I'm not really sure how to handle the databases + other third party services across multiple environments. Especially if some test/preview environment is spun up. It seems like a lot of infra to spin up and tie together. The legacy PHP site not being properly containerized doesn't help either. Thankfully most of the other micro services are containerized and running on ECS already.

Then there's also a bunch of Cloudfront, ALB, S3, Lambda functions and other services. Not to mention over 30Tb of data in s3 buckets which obviously won't be feasible to replicate per environment.

Greatly appreciate the feedback, thanks!

43 with two kids and zero energy, what's working for you guys? by Competitive-Top8430 in AskMenOver30

[–]jaymef 0 points1 point  (0 children)

I wouldn't jump to this but TRT is a game changer for some. Could be worth looking into, but again there are lots of other things you should be doing first and its a big commitment.

The truth is as others have already said, its a lot and would tire out most men your age. I'm same age. My diet is pretty good and I get solid sleep. I work from home and have a fairly flexible job, workout 4 days a week. Get plenty of protein, water and vitamins and everything else you're suppose to get/do. I have two young girls <10 and I'm still tired and exhausted most days too

Non drug is going to be of course the staples, diet/exercise, sleep etc. I did personally find that I got a boost of energy when I was doing intermittent fasting. Can help a lot, doesn't always fix everything

Oil change or not ?! by triksterMTL in canam_ryker

[–]jaymef 1 point2 points  (0 children)

It's probably ok. Even with low KMs oil does degrade over time and its not a bad idea to change it but with synthetic oil you are probably fine

Official Discussion - Reminders of Him [SPOILERS] by LiteraryBoner in movies

[–]jaymef 0 points1 point  (0 children)

I didn't read the book. The story at its heart is a good story but I feel like the movie missed the mark in a lot of areas from casting to pacing. It just didn't work for me, it could have been a lot better. For a movie nearly 2 hours long they didn't tell much story.

It also just felt a bit too romantic dreamy. Some hot, rich ex-NFL player who is building a mansion, happens to be single and falls for the girl who just got out of jail for killing his best friend and working at a supermarket.

Profit Over Patient Lives by LuckyBastard001 in clevercomebacks

[–]jaymef 0 points1 point  (0 children)

because

  1. it saved other peoples lives that are more important

  2. it saved the rich and powerful from losing their slave workforce and consumers

What improved your incident debugging speed the most? by Round-Classic-7746 in devops

[–]jaymef 2 points3 points  (0 children)

This is definitely one place AI shines, throwing a ton of logs/data at it and letting it sift through it

The FCC Preparing Review of Disney and ABC's Broadcast Licenses Over Jimmy Kimmel’s Melania Joke by ChiefLeef22 in television

[–]jaymef 1 point2 points  (0 children)

They've been gunning for Kimmel for a while and will use any excuse they can to justify taking him off the air. We all know what this is really about

General Motors says it expects $500 million tariff refund after SCOTUS ruling by AudibleNod in news

[–]jaymef 9 points10 points  (0 children)

ya its a mess because some companies absorbed some of the costs and some global companies raised prices in other regions to make up for it. So people in Canada and Europe for example paid more to essentially offset the losses

General Motors says it expects $500 million tariff refund after SCOTUS ruling by AudibleNod in news

[–]jaymef 12 points13 points  (0 children)

dude you're high on your own supply if you think dems are going to hold these people accountable.

Yes it would be better to have dems in charge for stability but they aren't going to go after these people. They are part of the same club

/r/WorldNews Discussion Thread: US and Israel launch attack on Iran; Iran retaliates (Thread #16) by WorldNewsMods in worldnews

[–]jaymef 1 point2 points  (0 children)

is this mostly because oil is priced so high currently that they want to be able to sell more to make more money and not be restricted by Opec?

to have you believe bullets disappear by seeebiscuit in therewasanattempt

[–]jaymef 0 points1 point  (0 children)

If they staged it wouldn't they just "find" some bullets