• 3 Posts
  • 151 Comments
Joined 9 months ago
cake
Cake day: January 24th, 2024

help-circle




  • None. Dashy’s authentication was famously literally security theatre even with Keycloak. You could just pause the load in browser and have full access to the config. Because it let you iframe whatever you could now do so with local services to enum. Somehow Jellyfin is unbustable though. So it’s a bit of a crapshoot. Look at past vulnerabilities. Stuff like XSS unless stored you don’t need to worry about, clickjacking, tab nabbing etc. On the other hand anything that’s arbitrary file read, SQLI, RCE, LFI, RFI, SSRF etc. I would look at seriously. E.g. don’t make your 13ft public because it can be used to literally enumerate your entire private network.











  • You can’t. You either go into work and learn to solve complex problems or pivot to something else. For me it was the latter, I’m IT brainlet now, but every time I come back to brushing up on programming there’s like no middle ground with projects, I don’t have the time or really energy to commit to building a 3D video game engine in C or an OS, and learning pointer arithmetic for multiple iterators all just to make a palindrome checker CLI feels lame and building a clone of Spotify but in some new webdev thing of the week to some tutorial is hard to be excited about.