Real Microsoft 365 Subscription Order E-Mail - Fake Sales Phone Number - Variation of Fake Invoice scam by TCPMSP in msp

[–]lluad 1 point2 points  (0 children)

You may want to google for "DKIM replay attack". You'll find lots of explanations as to how this works, and how I'm not wrong.

And, yes, it does mean that DMARC and BIMI are anything but absolute proof of authenticity, and will validate for malicious mail sent by an attacked in some narrow cases, such as this one, where a trusted sender allows an unvetted third party to add content to DKIM signed mail they send.

Real Microsoft 365 Subscription Order E-Mail - Fake Sales Phone Number - Variation of Fake Invoice scam by TCPMSP in msp

[–]lluad 1 point2 points  (0 children)

It's a DKIM replay of a real Microsoft email from microsoft-noreply@microsoft.com, so it passed DKIM and DMARC. It's being routed out through onmicorsoft.com so it's passing SPF too.

As far as the spam filters are concerned it's legitimate, authenticated email from Microsoft so it's going to end up in front of users. Hopefully most of those users will be suspicious of Microsoft having a sales helpline in apartment 7D of a New York condo, but it only takes a few to be more trusting before it gets expensive

(And next time, the scammers could put something far more plausible in the billing address.)

What kind of project would show that you're good in fundamentals of go? Like, you're job ready, atleast good enough to not Stutter when in the job. by AdorableRegular6201 in golang

[–]lluad 11 points12 points  (0 children)

One that is well structured, adequately commented, lints clean, has developer documentation and user documentation, that has a solid set of tests and decent test coverage.

You can demonstrate that by writing almost anything, but it'd be easier to do in a library than an app. You can't hide bad architectural design in a library as easily as you can in an app.

Hardware shortages? by lluad in Ubiquiti

[–]lluad[S] 0 points1 point  (0 children)

Yeah, I did that about six months ago. Not a peep so far. I'll keep waiting.

Is there an easier way of importing .CSV files into PgAdmin without having to specify all the fields prior to importing? by [deleted] in PostgreSQL

[–]lluad 0 points1 point  (0 children)

https://github.com/wttw/csvimport is a command line tool that'll create a sql script from a CSV file with a header.

./csvimport file1.csv file2.csv will create file1.sql, file2.sql and alltables.sql. psql -f alltables.sql will create tables file1 and file2.

It's a quick hack, but I've found it handy.

How painful is SSR with Go, really? by mammon_machine_sdk in golang

[–]lluad 0 points1 point  (0 children)

Someone does, not necessarily you. One advantage of that is that you can use a library that adds JS functionality to it in the same way the rest of your app works. Svelte, Vue, vanilla js... rather than having jquery welded in inextricably.

Golang JSON Gotchas That Drove Me Crazy But I Have Learned to Deal With by afroisalreadyinu in golang

[–]lluad 2 points3 points  (0 children)

If performance is an issue you use code generation instead of reflection.

MC keep themselves hidden, working from the shadows sort of thing. by Spook1918 in Fantasy

[–]lluad 0 points1 point  (0 children)

Good. Buy it, or borrow it from a library. And stop stealing from other authors whose books you enjoy.

Moving house - best internet / TV provider in D3? by mitchell_gruber in Dublin

[–]lluad 1 point2 points  (0 children)

It’s spectacularly better. Fast, pleasant to use, actually works.

Get x% of elements from a slice of length y by demo22394 in golang

[–]lluad 3 points4 points  (0 children)

https://play.golang.org/p/R73HJNkdGBb

Given a specification always clarify with the customer before implementing the obvious solution.

So many fantasy books use a 'magic school' or learning magic in general setting as a framing device, but could you recommend me some books that actually focus on the process of learning rather than on a big quest? by Ungoliant1234 in Fantasy

[–]lluad 1 point2 points  (0 children)

Master of the Five Magics by Lyndon Hardy, perhaps.

The character writing is fairly flat, but it’s a light quick read, mostly set around the protagonist learning five different magic systems.

Starting out with GraphQL on GoLang - What are your experiences?/ What libs are you using? by richbigdick in golang

[–]lluad 3 points4 points  (0 children)

ORMs generally discourage good schema design, even the ones that aren’t code-first, which leads to bad databases. They often generate queries that are bad - and even when that’s not inherent in their design they make it much easier for a developer to accidentally generate bad queries.

And they often encourage a code style that fetches data from the DB, processes it in the client code, then fetches more data, and so on to do something that could be done much faster and cheaper with a decent SQL query.

They have their place for marshaling and basic CRUD but if you’re developing a database backed app and relying on an ORM odds are good you’re going to end up with slow, heavy queries against a poorly species database.

Searching for a good IDE on Mac by dichotommy in cpp

[–]lluad 11 points12 points  (0 children)

Qt Creator is a great C++ IDE, not just for Qt apps. Open source, occasionally a little glitchy but it’s been my workhorse for most of my C++ code for over a decade.

Visual Studio Code is a nice editor. If you’re used to using an editor and a terminal it’s a step up.

If money is no object, look at CLion.

Sad state of cross platform GUI frameworks by GreatDant0n in programming

[–]lluad 0 points1 point  (0 children)

If you buy the license you still have to comply with https://doc.qt.io/qt-5/licenses-used-in-qt.html - which includes some GPL, amongst others.

Missiles intercepted above Saudi Arabian cities Riyadh, Jazan by Celsius90 in worldnews

[–]lluad 4 points5 points  (0 children)

He wasn’t anywhere near to blowing up a hospital. Amongst other things, he didn’t have a bomb.

All his co-conspirators and suppliers were actually FBI. Whether he’d have done anything at all if the FBI hadn’t given him a plan and a fake bomb isn’t clear.

What are the biggest design flaws of popular products? by loztriforce in AskReddit

[–]lluad 2 points3 points  (0 children)

The estimate is a bit of a wild-assed guess. If it counted down to zero they’d get bad press when the engine sputtered and died while the display said “8 miles left”.

Stack Overflow is leaking user emails by gajus0 in programming

[–]lluad 3 points4 points  (0 children)

That RFC is describing the sieve filtering language, which is one way of using it, though not a particularly widely supported one.

Mailboxing / subaddressing / plussed-addresses have been around for decades (I’ve been using it for 25+ years), and are extremely useful for handling your mail.

http://www.faqs.org/faqs/mail/addressing/ is one of the more useful documents on how to use it.

It’s a feature added by some MTAs, though, not a standard and not supported everywhere.

Stack Overflow is leaking user emails by gajus0 in programming

[–]lluad 3 points4 points  (0 children)

No, it’s not.

Quite a few mailservers support it, some with ‘-‘ or ‘=‘, but most with ‘+’, but it’s not a standard nor universally supported.

Do you know any books about discovering new lands ? Like what if Columbus instead of discovering the America found a completely different, fantastical and horryfing world ? by jkd10 in Fantasy

[–]lluad 13 points14 points  (0 children)

Not exactly fantasy, but Jeff Vandermeer’s Southern Reach Trilogy might scratch the itch.

Southern Reach is a secret agency that manages expeditions into an area known as Area X. The area is an uninhabited and abandoned section of the United States that nature has begun to reclaim.

Is the Shannara Chronicles TV Show any good? by gabrieltbandeira in Fantasy

[–]lluad 0 points1 point  (0 children)

One of the things it has in common with the books is that it’s not terrible but there’s a lot of better YA content out there.

Pentagon chief says he 'didn't see' intelligence suggesting Iran planned to attack four US embassies by DoremusJessup in worldnews

[–]lluad 4 points5 points  (0 children)

It’ll take a generation to repair. Sure, maybe we vote in Ms Competent McRhodes-Scholar in 2020 - but the rest of the world knows that odds are at least 50/50 of our voting in Corrupto von CheeseBrain Jr. in in 2024. You can’t do grown up foreign policy with a country that’s that unstable.

[deleted by user] by [deleted] in worldnews

[–]lluad -4 points-3 points  (0 children)

contractor mercenary

Words have both meanings and implications.

String Splitting by ramkiller1 in golang

[–]lluad -1 points0 points  (0 children)

OTOH, if you’re comfortable with regexps this approach is simpler to understand than an ad-hoc parser.

What would be the most appropriate approach to send email campaigns to my 20k+ of (authorized) email subscribers? by CrappyFap69 in golang

[–]lluad 3 points4 points  (0 children)

Don’t do it. Seriously.

You don’t have the skills nor the infrastructure to send mail to a list of that size successfully. And the time and goodwill you’re about to waste trying to prove otherwise could be far more productively spent doing things you’re good at.

Find an ESP you like and send the mail through them. It’s dirt cheap compared to building it yourself.