• 1 Post
  • 776 Comments
Joined 2 年前
cake
Cake day: 2023年7月2日

help-circle

  • You got two options. Both suck.

    1. Call support. Have fun. I’d rather rip out my eyeballs in this scenario because you’re not a paying customer. You will get the shit-tier service, will likely be hung up on, and reexplain the situation to 3+ individuals over the course of 4 hours and ultimately get nothing done.

    2. Resubscribe. Finish the job. The odds of your accounts db being wiped are kinda slim. Sucks because you do what you explicitly sought to avoid: pay Microsoft.






  • I think the bulk of users are running discarded junk and raspberry pis.

    That was me, I built a ~$5k rig and now some of what I’m doing is just nonsense of a typical self hoster, so the point is somewhat valid, but even those like me mostly started out with discarded junk and raspberry pis.

    Docker used to scare me until I tackled a project that required me to use it. Then I realized I learned it without knowing I’d learned it.








  • foggy@lemmy.worldtoSelfhosted@lemmy.worldAutograding tool
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    1 个月前

    I mean just for the love of God don’t spin up something on your company’s infrastructure that accepts file uploads.

    Just don’t.

    If you’re reading this and going “well, it’s just internal,” or “well, it doesn’t do much it just accepts this exact file type.” My god. Ask your CISA. And if they’re okay with it, cool. That’s on them.

    Unless your whole business is transferring files, don’t. And even then… Don’t.

    And if you’re still confused, the answer is to use another company’s infrastructure for this. Use Azure. Use AWS. Use Google cloud or even g suites. Don’t accept that liability. Let the trillionaires do it.


  • foggy@lemmy.worldtoSelfhosted@lemmy.worldAutograding tool
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    2
    ·
    edit-2
    1 个月前

    Why give your students a way to get RCE on your institutions servers through anything less than perfect file upload implementation.

    For a .tar? I wish you the best…

    Instead of that, simplify.

    Use unique salts for each assignment per student.

    Align hashes with those salts to check the outcome for each students assignment.

    Literally have them send you a CTF style sha256 string.

    Do it step by step where each step doesn’t depend on the next, grade as a percentage of flags accurately procured.


  • foggy@lemmy.worldtoMildly Infuriating@lemmy.worldI got out easy, I'm assuming
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    1
    ·
    edit-2
    1 个月前

    When I was 23, Obamacare had recently passed and it allowed me to remain on my father’s insurance as a recent college grad.

    I broke my talus (ankle sit-bone) into 3 pieces. Xray showed nothing. Cat scan showed nothing.

    Dads insurance covered the MRI. Broke in 3 pieces. I otherwise would’ve been told it was a sprain. I’d have suffered life long consequences (worse than what I’ve got).

    It didn’t cost me a dime. It cost my dad like $300. It would have literally cost me hundreds of thousands of dollars without Obamacare.

    EDIT: @Shalafi or whoever tf, I have blocked you ages ago and you’re tagged “needlessly argumentative over everything”

    I’m not going to unblock you to read what I already know is you being needlessly argumentative over everything.

    Also if I’m correct, do yourself a favor and maybe block them as well.


  • For getting your stuff available over the internet, y I recommend a secure tunnel with wire guard between your vps and servers running the services.

    Make your vps an authentication portal using stuff like Authelia and Fail2ban.

    If you’re really needing out, get ELK stood up for free and get agents on your containers/services to keep visibility into any potential… Anything