lemmy.sdf.org

Cosmonauticus, to comicstrips in Cat & Girl in "One Man's 90s Trash"

Weren’t the 90s more influenced by the 70s?

FunkyMonk,

and the 60's were 'cooler'

rustyriffs,

global warming.

masquenox,

Nahh… I’d say the 90s felt more like, “Please God just be anything other than the 80s.”

Four_lights77,

Yes but Vietnam was the catalyst.

Maultasche, to risa in The Crossover No One Asked For or Remembered

Is that the USS Riker?

7of9,
@7of9@startrek.website avatar

No. The cockpit is at the wrong end.

altima_neo,
@altima_neo@lemmy.zip avatar

The whole ship is the cockpit

ininewcrow,
@ininewcrow@lemmy.ca avatar

Full of gladiators

ch00f, to comicstrips in They aren't boards, and they don't hover!

Relevant XKCD xkcd.com/1623/

Though don’t get me started on how many things are called “holograms.”

Pepper’s ghost isn’t a hologram. It’s just a reflection with more steps.

PolandIsAStateOfMind, to memes in PSL
@PolandIsAStateOfMind@lemmy.ml avatar

🤮🤮🤮https://lemmy.ml/pictrs/image/536354ad-9a3f-4b5d-829a-36b605d27948.png (Polskie Stronnictwo Ludowe, the most opportunist party in Poland which is an achievement considering the really high bar of political opportunism here).

patomaloqueiro,
@patomaloqueiro@lemmy.ml avatar

https://lemmy.ml/pictrs/image/34853822-efbf-4c58-801b-580a7bbbeeee.png (Partido Social Liberal) Same thing here in Brazil, it was the party that elected Bolsonaro 🤢 in 2018. Currently, it has merged with another party to gain more votes, opportunists.

EmpathicVagrant,

Fascists simply love their sleeper candidates, and almost always taint the social labels by running under it.

Tartas1995, to asklemmy in What are these comments on lemmy posts?

Hey, I can tell you want it does. While I don’t know if they try to download something too (while it really doesn’t look like it), they are trying to steal your browser cookies.

I haven’t removed the obfuscation yet as I am literally in bed but I can tell the general idea of the code.

Onload is a html attribute. Html attribute tell your browser more about what the browser should be doing. So basically onload is an instruction to your browser. By posting those comments, they try to run something called cross site scripting. Basically they want to run their code in your browser without them being the website owner. So now we know the intend of the post, let’s look into the details.

Onload is an attribute that tells the browser to do something once it is fully loaded.

Fetch is a function that allows your browser to request additional information from the server. Endless scrolling would be done with that.

String.fromcharcode is just there to hide a little bit. Think of it as a fancy way to say a word. they are saying a website to connect to there.

Then document.cookie are your cookies for that website.

The next thing is probably your username or something.

So what does that mean? They try to make your browser execute their code when the website is onloaded. The code sends your cookies and your username(?) To a server. They probably save the username and cookie and try to steal the account later.

You seeing the code is good evidence that your browser hasn’t execute the code as the browser didn’t understand it as code to be executed but code to display. So you are probably safe and don’t need to worry

Edit: ups sorry for not answering the question. I don’t know which client they are targeting. They might or might not be targeting wefwef. But they target you, the user, too. And it is probably for Webbrowser users, so chances are wefwef or other web clients.

Edit edit: some people pointed out that it is not the username but basically the admin status of the account.

Icarus,

so does this run automatically ? without the user doing anything ?

Tartas1995,

If it would work, which it seems like it doesn’t. Yes, it is intended to be automatical.

Xylight,
@Xylight@lemmy.xylight.dev avatar

Doesn’t Lemmy use HttpOnly cookies? This would fix any js based exploit.

Dirk,
@Dirk@lemmy.ml avatar

Also, strict CSP would prevent it entirely.

Xylight,
@Xylight@lemmy.xylight.dev avatar

out of curiosity, what CSP options would fix this?

Dirk,
@Dirk@lemmy.ml avatar

To prevent execution of scripts not referenced with the correct nonce:

<pre style="background-color:#ffffff;">
<span style="color:#323232;">script-src 'self' 'nonce-$RANDOM'
</span>

To make it super strict, this set could be used:

<pre style="background-color:#ffffff;">
<span style="color:#323232;">default-src 'self';
</span><span style="color:#323232;">script-src 'nonce-$RANDOM'
</span><span style="color:#323232;">object-src 'none';
</span><span style="color:#323232;">base-uri 'none';
</span><span style="color:#323232;">form-action 'none';
</span><span style="color:#323232;">frame-ancestors 'none';
</span><span style="color:#323232;">frame-src 'none';
</span><span style="color:#323232;">require-trusted-types-for 'script'
</span>

Especially the last one might cause the most work, because the “modern web development environment” simply cannot provide this. Also: form-action ‘none’; should be validated. It should be set to self if forms are actually used to send data to the server and not handled by Javascript.

The MDN has a good overview: developer.mozilla.org/…/Content-Security-Policy

Gellis12,

The encoded strings are https://zelensky(dot)zip/save/ and navAdmin

Trex202, to memes in But of course

It’s easy as 123, ABC, you and me, in the GMC, girl!

Dozzi92, to lemmyshitpost in Bible
@Dozzi92@lemmy.world avatar

“All I have in this world is my balls and my word.”

That’s as close to relevant as I can get.

perviouslyiner, to mildlyinteresting in This 9v battery contained six cells stacked like a layer cake

Better use of space - they used to be just six coin cells with a load of empty space for a wire to connect the top connector to bottom of the stack

TheAlbatross, to risa in I'm sorry, but it is true

There’s a part of me that wants to suggest recipes to save you from this nightmare, but your ignorance is your bliss and it comes from a readily available, cheap and easy to prepare cardboard box.

Truly, a conundrum.

jawa21,

In my 40 years, I have had many home made recipes. I have never found them comparable for one weirdly indulgent reason - salt. I think the salt content for better or worse is what drives me to the boxed stuff, especially now with the huge (and reasonable!) drive toward low sodium broth. I don’t know why, but boxed stuffing/dressing is my favorite food.

TheAlbatross, (edited )

You’re damn right that a lotta stuffings end up undersalted. And I’m not gonna tell you the boxed stuffing isn’t tasty. (My “nightmare” comment is totally hyperbolic and flippant, but we’re having fun here I hope)

But I have a friend who makes it with sausage and sage herbed brown butter and I’m confident it’s a box beater. Heck of a lot more work, though.

Naate,
@Naate@beehaw.org avatar

I’m with you. Maybe it’s because I’ve never had truly good homemade stuffing? It’s always a weird, damp, spongy mess. But that box of Stove Top, ready in minutes? I’ll eat the whole thing by myself. It’s also great to have an extra box to go with the leftovers, especially for the sandwiches.

be_excellent_to_each_other,
@be_excellent_to_each_other@kbin.social avatar

I think that's totally fine, as much as some might want to turn this into a "Ketchup on Steak" kind of holy war.

I grew up on StoveTop and I do think it's yummy.

My mother in law makes a stuffing that's essentially potatoes, bread, onions, whatever other seasonings, and yes a good bit of salt. (I haven't helped make it I admit, so I could be doing it a disservice to describe it that way)

She even cooks some of it inside the turkey and some of it outside, though it never really gets soggy.

As far as I'm concerned, you could throw out the entire rest of Thanksgiving dinner and just give me a big bowl of that.

FlyingSquid,
@FlyingSquid@lemmy.world avatar

Cooking it inside the turkey so it gets turkey drippings in it makes a huge difference. And adds to the salt content.

aeronmelon, to risa in As an Old Enemy

Janeway: “Come as you are…”

Tuvix comes

Janeway: “…as you were.”

LongbottomLeaf,

Yeah I was gonna say, “Next lyrics are…”

And don’t forget: ‘As I want you to be’

anarchrist, (edited ) to memes in Pope–memier showtime

ILL Papa

DahGangalang, to linuxmemes in Kinda accurate lol

I had (what felt like) an epiphany (but has seemed obvious to everyone I’ve shared it with) some time ago:

Electrical signals are serial; they’re connectionless, like UDP.

Underlying all these fantastic technologies is just aother connectionless protocol.

moosetwin, to piracy in HikariNoAkariOST Will be shutting down for good!
@moosetwin@lemmy.dbzer0.com avatar

My fellow archivists, go!

lambalicious,

Anime soundtracks site

Not using the line “Awaken my archivists!

meiko60,
@meiko60@lemmy.sdf.org avatar

hnA only provide redirect link to many file hosting sites. I wish someone can create new site that recreate those link too smilar like nyaa from .eu to .si.

TheMadnessKing,

But you dont know if they are going to nuke those hosters or not.

some_guy, to memes in Vaccine research vs. anti-vax research

What great ideas didn’t begin as a thought on the toilet? /s

trailing9,

Supposedly Newton’s idea of gravity but that story with the apple could just be a cover-up.

supercriticalcheese,

Well it was all downhill after that, so not sure it was great you know!

dudewitbow,

Well depends on how you define toilet. The flushing toilet was invented after issac newtons life so it definitely wasnt on what what would currently be considered a toilet.

TheaoneAndOnly27,

I mean. Maybe that's why he was squatting under the tree?

holycrap,

The ones that started in the shower?

WinterAir,

Flux capacitor was thought of on the toilet I believe.

some_guy,

I think it was thought of after falling off a toilet, so toilet-assisted?

WinterAir,

Yeah, toilet-assisted is the proper term

grayman,

It’s a little known fact that Newton was pooping under that apple tree when the apple fell on his head.

LeadSeason, to asklemmy in How many tabs do you have open?

5k tabs
SPd1wPOCpxgWVCF
At 1k tabs firefox was snappy and responsive, but at 5k tabs it was bad, very unstable, buggy and sluggish.
Firefox would crash often even doing simple tasks, some times it took 2 or 3 tries to open firefox. scrolling through all the tabs a couple of minutes.
But all good things must come to an end. Now I close any extra tabs, have 5 - 30 tabs open.

257m,

Who are you so wise in the ways of tabs?

ctag,
@ctag@lemmy.sdf.org avatar

I am in awe.

Th4tGuyII, (edited )
@Th4tGuyII@kbin.social avatar

Legitimate question - just how do you accumulate 5K tabs? Did you just never close any tabs, like ever?

LeadSeason,

Something like that. At first I opened tabs for ”This sounds interesting I will read / watch it later” or ”I’ll probably need it later” This got me to ~300 - 800 tabs but then it became a joke, I just left tabs open knowing full well where not needed. Some times keeping all tabs open payed off like, using the search feature to find back to a project I left off. This happened very rarely.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #