Live data from Hacker News

If you’re trying to hack/deface a website, don’t submit a pull request

github.com

101–110 of 114 posts

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#101
In case anyone's curious and got down to the embedded YouTube video in the code, it's an Arabic-titled video of a screen recording of a Facebook video (further evidence of the author's technical prowess) of two Israelis in a place undergoing rocket fire from Gaza... definitely recent as well as they say "Where's the iron dome!?" in Hebrew. It's about a minute and a half of the rocket sirens blaring and them hearing rockets landing in the distance, screaming out of fright/being startled when they do.

Pretty disturbing stuff, to say the least. Combined with the english text about the Zionists leaving Palestine, I just wanted to shed some light on the intention of the defacement.

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#102
post #41

Earlier quoted context omitted.

Re: Skitch, there is a nice app I switched to lately: http://monosnap.com/

No Windows support :(

Yes there is - first link in the "Other Platforms" bar under the main image.

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#103
post #18

Earlier quoted context omitted.

In fact, I might go so far as to say that this was never intended to be merged. I'll assume whoever did this wants their message heard, and while it will never show up on CoderDojo, the hodgepodge of coding styles ensures that the "pull request" will go viral, thus possibly reaching a far greater number of people than it would have otherwise. /tinfoil

What message? I read through the thing and didn't see any message. There's some encoded arabic, but even if I could read arabic, I couldn't read it encoded.

Downloaded that file, removed the JS and took a look in a browser. The Arabic is here(I hope HN can handle the unicode -- I've translated inline -- editorial notes between brackets):

بسم الله رب المجاهدين والشهداء ،،~ In the name of God, lord of martyrs and Moujahidin[no idea how to translate that]

إن الرساله المراد توصيلها لكم .. The message that you are intended to receive is...

إن صواريخ المقاومه قد وصلت إلى تل أبيب والقدس الغربيه المحتله وإلى جميع التجمعات الإستيطانيه القريبه من قطاع غزه .. وإن طائراتكم التي تحلق في سماء قطاع غزه لن تحلق بعد اليوم . وألياتكم التي تتحرك على طول الخط الفاصل هيه تحت مرمى ضربات المجاهدين وسُفنكم الحربيه قُبالة شواطيء غزه أصبحت تحت الإستهداف The resistance[Hezbollah]'s rockets have reached Tel Aviv and the occupied West Jerusalem and to all colonies[or colonial compounds/groupings? not sure] in the Gaza district... And your planes that fly in Gaza's airspace will not fly after today. And your tanks[or armoured vehicles] that patrol the dividing line are within reach of the moujahidin and your warships facing the beaches of Gaza are now being targeted.

عليكم الإن الإختيار بين أمرين لا ثالث لهما You now have to choose between two options, you do not have a third.

( إما الرحيل عن فلسطين , أو أن تموتو على أيدي المقاومه ) Either you leave Palestine or you die at the hands of the Resistance[Hezbollah]

وسنوفر لكم خدماتنا السريعه بإرسالكم للموت بطيئأً .. We will be quick in giving you a slow death[you can just imagine that guy chuckling to himself as he came up with this pun]

هذا ونتمنى لكم النار منعمين فيها بإذن الله We wish you [something I don't know how to translate about fire and hell] god willing.

--

I'm Lebanese, so I've met quite a few Hezbollah/Amal people, I tend to sympathise more with the Palestinans than the Israelis in general, but shit like this makes me feel sad and unsure if I want to laugh or cry at the guy who wrote it. That is, if they were being serious and this not just a troll.

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#104

Earlier quoted context omitted.

What message? I read through the thing and didn't see any message. There's some encoded arabic, but even if I could read arabic, I couldn't read it encoded.

Downloaded that file, removed the JS and took a look in a browser. The Arabic is here(I hope HN can handle the unicode -- I've translated inline -- editorial notes between brackets): بسم الله رب المجاهدين والشهداء ،،~ In the name of God, lord of martyrs and Moujahidin[no idea how to translate that] إن الرساله المراد توصيلها لكم .. The message that you are intended to receive is... إن صواريخ المقاومه قد وصلت إلى تل أب…

Mujahideen has entered the English vocabulary quite a while ago, so don't worry about not finding a good translation, everyone knows it: https://en.wikipedia.org/wiki/Mujahideen

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#105
post #36

Hilarious. But if I ever need a jury of my peers to audit my coding style to see how good it is, now I know what to do - a pretend-attempted-defacement is bound to be more effective than finding some place on the net to ask 'Is this proper idiomatic javascript?'.

If you ever actually need a place to check whether your JavaScript is idiomatic, try Code Review Stack Exchange (http://codereview.stackexchange.com/).

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#106
post #100
post #98

Earlier quoted context omitted.

In the sense that it is a cultural artifact that is passed along from one individual to another, yes. In the sense that it is something annoying kids on the internet use that must be complained about, no, not necessarily.

I hate the abuse of the word "meme"...

Funnily enough, the abuse of the word "meme" is now a meme.

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#107
post #54

Earlier quoted context omitted.

Being sarcastic is puerile?

Also, "protip" has been in use for what, two decades now? When does something stop being a meme and just become an idiom?

GamePro is, as far as I know, the originator, so sometime between 1989 and 1994 (first time I remember it). So, yeah, about two decades. :)

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#109
post #99

Earlier quoted context omitted.

I assumed that was because of changes in Skitch. Everyone I know used to take screenshots with Skitch, upload them and Skitch would copy the URL into your clipboard and you could post into Github. But since Evernote bought them they closed things down and they're basically useless now, so I figured that was why Github was motivated to add this feature.

You can still download the old version (the real skitch) right there from evernote: http://evernote.com/skitch/ (small link at the bottom, "previous version"). Skitch supports FTP-upload, so if they turn off sharing in the future you can just switch to your own webspace. No need to mess with lesser tools (or the evernote-garbage) while Skitch still works!

yep this is what i did. But free FTP services online are hard-ish to come by =(

i wish there is a plugin or kernel extension that modified skitch so that you could upload it to say dropbox. The other method is to point skitch to the local machine and use dropbox to sync, but i think you lose the clipboard thingy.

May be i will just switch to monosnap. But it looks so ugly compared to skitch!

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#110

Earlier quoted context omitted.

Why not just find an exploit in the code. Spending months building trust while creating a giant trail of information that can be used to find you and then really pissing off the open-source community seems like a bad plan for someone that is attempting to quietly gain root. Might work if one project is attempting to discredit another project (think closed source vendor trying to steal clients who use opensourced gith…

Because it works even if you can't find a proper codepath to exploit. It might gain you anything you want: A quiet path to leak admin account info to a server of your choice. An attack vector into a system trusted by more than one person. You don't need to provide much information to get a github account, so the risk is not very much elevated.

or better yet, write some code in the same way like this coding contest (where you write some innocent looking code that contains a subtle bug that you can plausibly deny it was intentional...http://underhanded.xcott.com/?page_id=7). This way, the blame trail isn't useful in proving anything!
Post reply on HN