despotify - the open source Spotify client and library KaKaRoTo's Blog SELinux Exploiting Unexploitable XSS XSS that are protected by CSRF protection or where other mitigating factors are present are usually considered to be unexploitable or of limited exploitability. This post details real world examples of exploiting “unexploitable” XSS in Google and Twitter. While the XSS detailed in this post are site specific the methods that were used to exploit them could be applied to other websites with similar implementations. Alex’s (kuza55) Exploiting CSRF Protected XSS served as inspiration for this post. Google Google has services deployed across many different domains and subdomains and as a result requires a way to seamlessly authenticate members who are logged in to their Google Account. When called by a member who is logged in to their Google Account the URL generates an auth URL and redirects to the particular service. When the auth URL is loaded the service uses the auth token to log the member in.

sudo dpkg -i ~/netatalk_2*.deb Une version super-protégée d'Android développée par la NSA est disponible Les téléphones gadgets intelligents qui n'étaient autrefois que l'apanage des films d'espionnage sont maintenant devenus une réalité : avec un smartphone acheté à un prix raisonnable, vous pouvez pirater des réseaux informatiques, utiliser votre GPS, faire des recherches sur Internet, utiliser la sonnerie de Jack Bauer dans 24, etc. Que deviennent alors les super-téléphones des agences gouvernementales ? Ils doivent bien évoluer avec leur temps, et les gouvernements ne vont pas refaire un système d'exploitation complet pour téléphones (je vous laisse imaginer les failles de sécurité qu'il pourrait y avoir ^^). Ils sont donc partis de ce qui existe déjà en OpenSource, Android, et nous sortent aujourd'hui le fruit de leur travail : une version super-sécurisée du système d'exploitation pour smartphones de Google ! Le projet est basé sur SELinux, un autre projet soutenu par l'agence gouvernementale américaine. Et pas besoin d'être un agent secret pour en bénéficier !

OS X Lion Time Machine backup to Debian | Tristan Waddington When OS X Lion was released I was eager to try out the updated FileVault and Time Machine features. Moving from an encrypted home directory to true full-disk encryption was a dream. I was also quite excited to find out if the new implementation of FileVault would work well with Time Machine. I’d previously set up a Time Machine volume on my Debian file-server by installing netatalk and avahi. Unfortunately, it seems OS 10.7 (Lion) requires netatalk 2.2, which is currently in beta. To install netatalk 2.2~beta4-1 you’ll need to add the following line to your /etc/apt/sources.list file: You can also use any of the mirrors listed here if they’re closer. Then run the following commands to install or upgrade netatalk: If you had a previous install of netatalk it may detect changes to your local configuration files. After the install has finished run $ dpkg -s netatalk | grep -i version to ensure it was successful. The netatalk service will be restarted by the installer after it completes.