🤘 THC-RELEASE 🤘: Anonymous EMAIL FORWARDS. No Logz. No Limitz. FREE ✅
Grab your <USER>@reads.phrack.org or <USER>@segfault.net - and more.
Built by the legendary extencil
🤘 THC-RELEASE 🤘: Anonymous EMAIL FORWARDS. No Logz. No Limitz. FREE ✅
Grab your <USER>@reads.phrack.org or <USER>@segfault.net - and more.
Built by the legendary extencil
IT'S HAPPENING
GITHUB, THE FIRST ENTERPRISE CLOUD SOLUTION TO REACH ZERO NINES RELIABILITY
@gsuberland Storytime!
I was once working in this Ruby on Rails shop, meh product but overall great people to work with.
One day I was reviewing the Brakeman configuration shipped with the code base and noticed that they turned on the “use double quotes everywhere” option.
Because this happened way earlier than my time there, I bought this up in the engineering slack channel, explaining exactly this corner case, and asking about what was the origin story for this choice. Mostly because Brakeman by default is smart enough to request single quotes when there’s risk of interpolation and preferring double quotes everywhere else.
The Beakeman config author came in very hot with an explanation that boiled down to “I wrote a blog post about the importance of unifying the coding style for readability and you should really go through it”.
Luckily enough, regexps weren’t really used across the code base: the most impactful place was during the deployment process when the homegrown deployment service needed to figure out what to do on different hosts based on their hostname. So, anyway, limited blast radius and all under engineering control.
Because of all of this, I chose this wasn’t an hill worth of dying on. I reiterated it was a slightly dangerous choice in the current status of the code base and moved along on more interesting and burning problems.
Fast forward three months later, many code changes and, if memory serves right, even a Ruby/Rails version upgrade. More regexps in the code base.
Things are getting wonky, the SREs are having trouble with deployments and no one understands why some core components are not behaving as expected.
Luckily we had paid support so they open a ticket with a sample of the puzzling code. The answer comes in quick and dry: “you are using double quotes, the string gets interpolated before being sent to the regexp handler” 😬.
The incident and the root cause are posted in the engineering slack channel for awareness.
I’m laughing my arse off and resurrecting the old thread from a few months back.
The Brakeman configuration author is fuming.
We change the option back to the original default.
If your web service is protected by #cloudflare, your best course of action right this moment is to cancel the contract and inform your users that their passwords have been compromised.
You either reach out to your customers base now or scammers will do that for you.
So, there you go: a screenshot of the top 14, some xp growth graphs and three different ways of climbing the #d2r ladder.
D2Emu is this amazing community site that lets you explore the ladder race. Go give it a try: https://d2emu.com/
The graphs for the screenshots above are taken from the following links:
- MQT team https://d2emu.com/ladder/208992166_208993852_208986820_208987984_208991536_208992530_208986810_208988456
- top 3 https://d2emu.com/ladder/209146210_208988214_208987422
Have fun and see you in the next Baal run!
5/fin