Brutkey

K. Reid Wightman :verified: 🌻🌻 :donor: :clippy:
@reverseics@infosec.exchange

Gonna write a /cgi-bin handler that gives the result of the 20th prior OS command injection in its response message, just to mess with hackers.


K. Reid Wightman :verified: 🌻🌻 :donor: :clippy:
@reverseics@infosec.exchange

What if we wrote one of those weird crowdinputted /cgi-bin handlers, where it takes one parameter from each request (requests have to come from unique IP addresses and have a unique session cookie), and only after it receives N requests (where N is the number of parameters required) does it execute the handler.