Hacker News new | past | comments | ask | show | jobs | submit | hashx's comments login

Location: Bangalore, India

Remote: Yes

Willing to relocate: Yes

Technologies: Java, Javascript (Node, React, d3.js), Python, Machine Learning.

Résumé/CV: https://drive.google.com/file/d/0B6gMBxC04UxhZnQ1eVgwc0V0WDQ...

Email: rsyncf@gmail . com


> Heck, they even elected quite a few convicted criminals to lead the Government

Can you give an example of a "convicted" (not accused) elected member from India?

>For example, a small search on Amit Shah and his fake encounters

Amit Shah has not been convicted. The case is ongoing.

>To me all this showdown to ban Uber seems more like an attempt to squeeze a little extra dollars from an American company.

By banning Uber they are trying to squeeze more dollars from it?


Directly passing user data to the command line is highly dangerous.It allows an attacker to execute arbitrary commands on the command line [0]. escapehellarg [1] has to be used to Escape a string to be used as a shell argument

[0] http://gcattani.co.vu/2013/03/a-tale-of-a-php-shell/ [1] http://php.net/manual/en/function.escapeshellarg.php


Directly doing anything with attacker supplied data is generally a no-no.

Everything that may come from a user must be filtered, escaped or generally treated as hostile.

As an example on an IRC channel someone once made their chan bot log the channel to the web, all it took was pasting javascript into an IRC window, and typing "LOL look at this! http://stupidbot.com/ircweblog". Channel pwned.


Karma threshold for downvoting is around 500


Thanks.


Facebook blocks the console as it is supposedly used for " exploitation by people to post spam and even used to "hack" accounts"

http://stackoverflow.com/questions/21692646/how-does-faceboo...


When you consider Facebook's target audience, it's probably okay to make people like us jump through a hoop in order to stop Grandma from being completely p0wned by typing in some JavaScript.

Yes, maybe people should know that running arbitrary JavaScript is dangerous, but they don't.


If you turn on dim in the browser, the status isn't reflected in the phone.Thereafter off becomes on and vice-versa


Good catch. It's because I cheated. The command will be sent from the phone to the desktop, the phone on the other hand does not receive the state of the dim. Button text is just changed by click event. Gonna change soon.


[insert obligatory comment about Atwood's law here]


Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: