Viewing profile — BillDemirkapi
BillDemirkapi
HN member- Joined
- Wed, May 01, 2019, 10:23 PM UTC
- HN karma
- 73
- Public activity
- 11 items
- HN profile
- View on Hacker News ↗
About BillDemirkapi
Recent public activity
-
comment
Comment #39135275
OP/bug finder here with some clarifying information. It's a common misconception that this issue can only be abused if you use HTTP boot. That is not the case at all, otherwise it …
- comment
-
comment
Comment #29861222
I can assure you the answer clicked before my research ever started. Unless I am using web server software that responds with one site for multiple host names, you generally need t…
-
comment
Comment #29857327
Yes, but at the time I already had an existing domain with a web server I could use. You are correct that I could have setup a separate site for hidusi[.]com and then point the dom…
-
comment
Comment #29857103
Author here. Yes simply editing my hosts file would have been much easier. The reason I went the longer approach of setting up the payload on a remote web server was because there …
- story
- story
-
comment
Comment #19804170
Dell SupportAssist comes pre-installed on most new Dell machines. The only reason it wasn't installed on my machine is because the drive I used was not prepared by Dell. Your avera…
-
comment
Comment #19802400
Unfortunately Dell doesn't pay bounties no matter how serious the bug is.
-
comment
Comment #19802397
Yep.
-
comment
Comment #19802393
There were a bunch of ways to bypass the check. For example another way would be to use "http:\\" which wouldn't get detected either. The new version isn't vulnerable.