I’m @froztbyte more or less everywhere that matters

  • 12 Posts
  • 108 Comments
Joined 1 year ago
cake
Cake day: July 2nd, 2023

help-circle


  • and the “mirrors” bit is basically an open proxy

    could test this by setting up a simple example page and seeing the originating source for the traffic

    same technique as previous, using an http (not https) canary:

    geo_info: {'loc': '51.5085,-0.1257', 'org': 'AS13335 Cloudflare, Inc.', 'city': 'London', 'country': 'GB', 'region': 'England', 'ip': '141.101.98.196', 'timezone': 'Europe/London', 'postal': 'E1W', 'asn': {'route': '141.101.98.0/24', 'type': 'hosting', 'asn': 'AS13335', 'domain': 'cloudflare.com', 'name': 'Cloudflare, Inc.'}}
    useragent: (no user-agent specified)
    request_headers: {'Host': 'canarytokens.com', 'X-Real-Ip': '141.101.98.196', 'X-Forwarded-For': '2a06:98c0:3600::103, 141.101.98.196', 'X-Forwarded-Host': 'canarytokens.org', 'Connection': 'close', 'Accept-Encoding': 'gzip', 'Cf-Ray': '89f1a3a114752508-LHR', 'X-Forwarded-Proto': 'https', 'Cf-Visitor': '{"scheme":"https"}', 'Cf-Ew-Via': '15', 'Cdn-Loop': 'cloudflare; subreqs=1', 'Cf-Connecting-Ip': '2a06:98c0:3600::103'}
    request_args: {}
    

  • a quick check using a canary. test command:

    curl -H 'accept: application/dns-json' 'https://0ms.dev/dns-query?name={snip}.canarytokens.com'
    

    canary trigger:

    geo_info: {'loc': '51.5085,-0.1257', 'org': 'AS13335 Cloudflare, Inc.', 'city': 'London', 'country': 'GB', 'region': 'England', 'ip': '141.101.70.74', 'timezone': 'Europe/London', 'postal': 'E1W', 'asn': {'route': '141.101.70.0/24', 'type': 'hosting', 'asn': 'AS13335', 'domain': 'cloudflare.com', 'name': 'Cloudflare, Inc.'}}
    

    so, yeah, the actual resolve is being done by cloudflare servers too - it’s not even just a cf frontproxy to a different backend service. could be done with cf workers or something, I imagine, would need to test a bit further to know/try see



  • I’ve noticed something similar with a lot of folks on the younger side in tech, although I haven’t had the headspace to dig into it. the thing I noticed is a lot of folks still willing to go into this dysfunctional shit getting highly paid because of knowing how bad things are elsewhere. afaict it’s not quite so much fygm as “just” trying to hoarde in the wake of 2+ decades of multiple world once-in-a-lifetime economic clusterfuck, as well as in the face of the total existential disaster that exists otherwise

    (this is the impression I get in a wider sense. I’m not sure if it’s right, or applicable particularly here)

    (there’s also a form of that which is quite strong in USA-based folks, but I don’t think ludic hails from the states)