Earlier quoted context omitted.
Biggest mistake EVER. The Apache Foundation DOES NOT redistribute any money to actual contributors. All money donated to Apache gets spend on their own infrastructure and salaries, etc.
same problem with wikipedia / wikimedia foundation
Log4jmemes.com: for those of us that need a laugh
111–115 of 115 posts
Re: Log4jmemes.com: for those of us that need a laugh
#112Earlier quoted context omitted.
Spamhaus et al. (corporate subscription), but same thing. If there's a noteworthy new domain, we'll check and whitelist it but otherwise silently disables phishing attempts. The one we have (which I don't know which specific lists) also detect new GitHub, AWS (S3), Azure (Windows Blob), and Google (Appspot et al.) subdomains.
As a former red-teamer, we would have long registered but otherwise dormant domains that did usual activities that is expected, like get TLS certs, and show some mail and whatnot... It bypasses things of this nature ;-)
Re: Log4jmemes.com: for those of us that need a laugh
#113Earlier quoted context omitted.
same problem with wikipedia / wikimedia foundation
But wikipedia, being a top 10 website, does have significant infrastructure costs.
Re: Log4jmemes.com: for those of us that need a laugh
#114Earlier quoted context omitted.
Biggest mistake EVER. The Apache Foundation DOES NOT redistribute any money to actual contributors. All money donated to Apache gets spend on their own infrastructure and salaries, etc.
> own infrastructure and salaries Don't they contribute for the development? Or for what is that salary.
https://www.apache.org/foundation/how-it-works.html
> All participants in ASF projects are volunteers and nobody (not even members or officers) is paid directly by the foundation to do their job. There are many examples of committers who are paid to work on projects, but never by the foundation itself.
Mind you, the download mirrors are also free...
Re: Log4jmemes.com: for those of us that need a laugh
#115Earlier quoted context omitted.
The piece of paper LOL
I know it's a joke but since it's just a string any system that does character recognition of images and logs that with log4j could be hit. So posting images of paper with this string may indeed get hits. One of the most incredible vulnerabilities ever.