Live data from Hacker News

We spent $20 to achieve RCE and accidentally became the admins of .mobi

labs.watchtowr.com

311–320 of 391 posts

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#311

Earlier quoted context omitted.

Phone number portability is required by law in the US since 2003. See 47 U.S.C. § 251(b)(2) https://www.fcc.gov/general/wireless-local-number-portabilit...

What if you need to stop paying for a phone bill entirely though? Maybe you're living paycheck to paycheck and money is just too tight this month. That's what I think GP was talking about. Is it possible to "park" your phone number until you can start a new plan?

It's now possible. I work for a mvno that was recently acquired. We have a $5 pause plan. It has no data, voice or text, it just keeps your line active.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#312
post #129

Earlier quoted context omitted.

You're saying all big companies ban whole language ecosystem because somebody on the internet used one function in that language in knowingly unsafe manner contrary to all established practices and warnings in the documentation? This is beyond laughable.

Laughable, but accurate. Google for example does exactly this.

Does exactly what? Ban whole ecosystems because somebody on the internet used it wrong? Could you please provide any substantiation to this entirely unbelievable claim?

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#313
post #69

This is a fantastic exploit and I am appalled that CAs are still trying to use whois for this kind of thing. I expected the rise of the whois privacy services and privacy legislation would have made whois mostly useless for CAs years ago. > This is the approach taken by whois on Debian. Years ago I did some hacking on FreeBSD’s whois client, and its approach is to have as little built-in hardcoded knowledge as possib…

Wouldn't it be easy for those software project, or a single central authority, to expose that WHOIS list through DNS?

    mobi.whoisserverlist.info. IN CNAME whois.nic.mobi.
    org.whoisserverlist.info.  IN CNAME whois.publicinterestregistry.org.
The presence of a referral mechanism inside the WHOIS protocol strikes me as a little odd.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#316

Earlier quoted context omitted.

Do you have any references/examples of this?

tons rapid7 for example use LLMs to analyze code and identify vulnerabilities such as SQL injection, XSS, and buffer overflows. Their platform can also identify vulnerabilities in third-party libraries and frameworks from what i can see

Can you point me to a blog or feature of them that does this? I used to work at R7 up until last year and there was none of this functionality in their products at the time and nothing on the roadmap related to this. It was all static content.

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#317

Earlier quoted context omitted.

What if you need to stop paying for a phone bill entirely though? Maybe you're living paycheck to paycheck and money is just too tight this month. That's what I think GP was talking about. Is it possible to "park" your phone number until you can start a new plan?

It's now possible. I work for a mvno that was recently acquired. We have a $5 pause plan. It has no data, voice or text, it just keeps your line active.

Wow. I’d save ~$0.52 (tax included) over my current plan with unlimited voice, and texts, and 5GB data…

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#318
post #271

Earlier quoted context omitted.

I'd assume regulated in the sense of identity verification and transactions. There's no legal basis for needing a north American phone number, but good luck with any US obligations if you are without one.

Thankfully you can still get them without ID, for cash. Unlike in Germany, where you can’t get one without a passport or ID card.

I’m wondering how feasible would it be to just use a SIM card from another country (e.g. in Estonia, you can get a prepaid card for 1 € that works in EU roaming just fine, with domestic-like prices on local calls). How many services in Germany require you to use specifically German number?

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#319

Earlier quoted context omitted.

tons rapid7 for example use LLMs to analyze code and identify vulnerabilities such as SQL injection, XSS, and buffer overflows. Their platform can also identify vulnerabilities in third-party libraries and frameworks from what i can see

Can you point me to a blog or feature of them that does this? I used to work at R7 up until last year and there was none of this functionality in their products at the time and nothing on the roadmap related to this. It was all static content.

[deleted]

Re: We spent $20 to achieve RCE and accidentally became the admins of .mobi

#320

Earlier quoted context omitted.

tons rapid7 for example use LLMs to analyze code and identify vulnerabilities such as SQL injection, XSS, and buffer overflows. Their platform can also identify vulnerabilities in third-party libraries and frameworks from what i can see

Can you point me to a blog or feature of them that does this? I used to work at R7 up until last year and there was none of this functionality in their products at the time and nothing on the roadmap related to this. It was all static content.

must've been another company then which i got confused with the name
Post reply on HN