techviator

@techviator@lemmy.ml

Tech Pro - Hobby Aviator - VR Enthusiast 🇵🇷🧑🏻‍💻🛩️🥽 techviator.com

This profile is from a federated server and may be incomplete. Browse more on the original instance.

On Monday morning we (Mozilla) detected a very large crash spike affecting Firefox users on Linux, specifically on an older version of a Debian-based distribution (fedia.io)

On Monday morning we (Mozilla) detected a very large crash spike affecting #Firefox users on Linux, specifically on an older version of a Debian-based distribution. It turned out to be an interesting bug involving the #Linux kernel and #Google JavaScript code so let me tell you about it. A thread 🧵

techviator,

Here’s the rest of the thread (should open entirely from the first link, but posting all 6 links just in case):

(1/6) fosstodon.org/@gabrielesvelto/110592904713090347

(2/6) fosstodon.org/@gabrielesvelto/110592906325095640

(3/6) fosstodon.org/@gabrielesvelto/110592907269834415

(4/6) fosstodon.org/@gabrielesvelto/110592908903430968

(5/6) fosstodon.org/@gabrielesvelto/110592909828889441

(6/6) fosstodon.org/@gabrielesvelto/110592910420926394

techviator,

Here’s the rest of the thread (should open entirely from the first link, but posting all 6 links just in case):

(1/6) fosstodon.org/@gabrielesvelto/110592904713090347

(2/6) fosstodon.org/@gabrielesvelto/110592906325095640

(3/6) fosstodon.org/@gabrielesvelto/110592907269834415

(4/6) fosstodon.org/@gabrielesvelto/110592908903430968

(5/6) fosstodon.org/@gabrielesvelto/110592909828889441

(6/6) fosstodon.org/@gabrielesvelto/110592910420926394

techviator,

I’m in the same boat! I have tried, really tried, the only things I like are the extensions support on mobile browser, and the sync with the Wolvic on the Quest VR, but it feels old and some websites render weirdly on it, plus the lack of support for PWAs really make it tough.

I like Brave best, with Edge as a second choice, as weird as that sounds. I miss Firefox when it was the modern and most secure browser.

techviator,

cnames do not point to IP address, they point to a resource on another domain, in this case azureresource.azure.-com for example.

Say you have a temporary webpage called flashsale.example.-com you created a cname pointing that subdomain to an azure resource that shows your desired content. Then you remove the azure resource, but leave the cname in place.

If a create another azure resouce with whatever public azure url you used before, and I make it look like your current website, say I impersonate your current login.example.-com on that azure resource, now your cname flashsale.example.-com os pointing to it, but you don't control the azure resource now, I do.

Now I can try to phish your customers by sending emails with real links, like: Dear customer, your account will be charged $900 for your last purchase, if this purchase was made in error or was not authorized by you, sign in to flashsale.example.-com immediately to cancel it. And now I have your customer's credentials.

And that is just one example, there are many more ways to exploit an orphaned cname subdomain, like using it to serve malware, using it to control bots without being blacklisted, etc.

techviator,

I don't share (or like) anything that I don't want made public, so I don't mind who follows my profiles on social media. But some people would rather keep a lower profile or be more selective of who can interact with them, so it's better to have the option available.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • mdbf
  • magazineikmin
  • InstantRegret
  • hgfsjryuu7
  • Durango
  • Youngstown
  • slotface
  • everett
  • thenastyranch
  • rosin
  • kavyap
  • khanakhh
  • PowerRangers
  • Leos
  • DreamBathrooms
  • vwfavf
  • ethstaker
  • tacticalgear
  • cubers
  • ngwrru68w68
  • modclub
  • cisconetworking
  • osvaldo12
  • GTA5RPClips
  • normalnudes
  • tester
  • provamag3
  • All magazines