Hitbox

Hitbox

hitbox

biblically accurate version under cut

Hitbox

4 the one cyclers in this world :thumbsup:

More Posts from Sumactic and Others

2 weeks ago

its so windy my poor poor chickens are being blown around like dry leafs they look like this

Its So Windy My Poor Poor Chickens Are Being Blown Around Like Dry Leafs They Look Like This
4 weeks ago

reddit, how do I make my firstborn stop playing with the fans, the ornaments, and the makeup when he is supposed to be a warlord. I fear I shall raise a poet.

2 weeks ago
Night Wings Turning The Day Into The Night, The Sun Into The Moon This Print And More Are %15 Off On

Night Wings Turning the day into the night, the sun into the moon This print and more are %15 off on my website with code SPRING25


Tags
4 days ago
All Gmail users at risk from clever replay attack
Malwarebytes
All Google accounts could end up compromised by a clever replay attack on Gmail users abusing Google infrastructure.

Cybercriminals are abusing Google’s infrastructure, creating emails that appear to come from Google in order to persuade people into handing over their Google account credentials. This attack, first flagged by Nick Johnson, the lead developer of the Ethereum Name Service (ENS), a blockchain equivalent of the popular internet naming convention known as the Domain Name System (DNS). Nick received a very official looking security alert about a subpoena allegedly issued to Google by law enforcement to information contained in Nick’s Google account. A URL in the email pointed Nick to a sites.google.com page that looked like an exact copy of the official Google support portal.

As a computer savvy person, Nick spotted that the official site should have been hosted on accounts.google.com and not sites.google.com. The difference is that anyone with a Google account can create a website on sites.google.com. And that is exactly what the cybercriminals did. Attackers increasingly use Google Sites to host phishing pages because the domain appears trustworthy to most users and can bypass many security filters. One of those filters is DKIM (DomainKeys Identified Mail), an email authentication protocol that allows the sending server to attach a digital signature to an email. If the target clicked either “Upload additional documents” or “View case”, they were redirected to an exact copy of the Google sign-in page designed to steal their login credentials. Your Google credentials are coveted prey, because they give access to core Google services like Gmail, Google Drive, Google Photos, Google Calendar, Google Contacts, Google Maps, Google Play, and YouTube, but also any third-party apps and services you have chosen to log in with your Google account. The signs to recognize this scam are the pages hosted at sites.google.com which should have been support.google.com and accounts.google.com and the sender address in the email header. Although it was signed by accounts.google.com, it was emailed by another address. If a person had all these accounts compromised in one go, this could easily lead to identity theft.

How to avoid scams like this

Don’t follow links in unsolicited emails or on unexpected websites.

Carefully look at the email headers when you receive an unexpected mail.

Verify the legitimacy of such emails through another, independent method.

Don’t use your Google account (or Facebook for that matter) to log in at other sites and services. Instead create an account on the service itself.

Technical details Analyzing the URL used in the attack on Nick, (https://sites.google.com[/]u/17918456/d/1W4M_jFajsC8YKeRJn6tt_b1Ja9Puh6_v/edit) where /u/17918456/ is a user or account identifier and /d/1W4M_jFajsC8YKeRJn6tt_b1Ja9Puh6_v/ identifies the exact page, the /edit part stands out like a sore thumb. DKIM-signed messages keep the signature during replays as long as the body remains unchanged. So if a malicious actor gets access to a previously legitimate DKIM-signed email, they can resend that exact message at any time, and it will still pass authentication. So, what the cybercriminals did was: Set up a Gmail account starting with me@ so the visible email would look as if it was addressed to “me.” Register an OAuth app and set the app name to match the phishing link Grant the OAuth app access to their Google account which triggers a legitimate security warning from no-reply@accounts.google.com This alert has a valid DKIM signature, with the content of the phishing email embedded in the body as the app name. Forward the message untouched which keeps the DKIM signature valid. Creating the application containing the entire text of the phishing message for its name, and preparing the landing page and fake login site may seem a lot of work. But once the criminals have completed the initial work, the procedure is easy enough to repeat once a page gets reported, which is not easy on sites.google.com. Nick submitted a bug report to Google about this. Google originally closed the report as ‘Working as Intended,’ but later Google got back to him and said it had reconsidered the matter and it will fix the OAuth bug.

4 days ago
DEI Does Not Mean Lower Standards.

DEI does not mean lower standards.

You are thinking of white privilege.

1 month ago

Self-made tragedies have got to be one of my favorite genders. What if you woke up every morning and chose to keep marching towards the only outcome that would destroy you. What if you burned down your whole life and everyone around you to stay on that road, even if every one of its twists and turns try to shake you off. What if saving yourself could be the easiest thing in the world, but only in retrospect. What if you could have prevented this all along. What if you didn't until it was too late. What if this only happened because you were you.


Tags
1 week ago

stop i NEED that pic of the boy who took his cat to prom and she has a lil dress and is looking up at him with 100% love and tenderness……..

1 month ago

has anyone thought of writing a pacific rim au with feinberg and couriway sorry for being cringe does anyone see the vision


Tags
1 week ago
How Can Ppl Say Cats Are Heartless Tbh

how can ppl say cats are heartless tbh

Loading...
End of content
No more pages to load
  • thecraziestcomet
    thecraziestcomet reblogged this · 4 days ago
  • thecraziestcomet
    thecraziestcomet liked this · 4 days ago
  • raviolioliolio
    raviolioliolio liked this · 4 days ago
  • marchaprilmayhem
    marchaprilmayhem liked this · 5 days ago
  • tropicalgoose
    tropicalgoose liked this · 5 days ago
  • beelzebubs-titties
    beelzebubs-titties liked this · 5 days ago
  • dragonsmaybehere
    dragonsmaybehere reblogged this · 5 days ago
  • dragonsmaybehere
    dragonsmaybehere liked this · 5 days ago
  • shardagra
    shardagra liked this · 5 days ago
  • spectralsleuth
    spectralsleuth reblogged this · 5 days ago
  • gamingforeternity
    gamingforeternity liked this · 5 days ago
  • bwomsy
    bwomsy liked this · 5 days ago
  • brae08
    brae08 liked this · 6 days ago
  • maybermn
    maybermn liked this · 6 days ago
  • vixiyne
    vixiyne liked this · 6 days ago
  • unlikemarie
    unlikemarie liked this · 1 week ago
  • cl0akoffeathers
    cl0akoffeathers liked this · 1 week ago
  • that1strangedapple
    that1strangedapple liked this · 1 week ago
  • crowputer
    crowputer reblogged this · 1 week ago
  • bromblr
    bromblr liked this · 1 week ago
  • maidjor-organ-failure
    maidjor-organ-failure liked this · 1 week ago
  • owariomori
    owariomori liked this · 1 week ago
  • aviancolloid
    aviancolloid reblogged this · 1 week ago
  • aviancolloid
    aviancolloid liked this · 1 week ago
  • supraobsessed
    supraobsessed reblogged this · 1 week ago
  • kapable-of-shitpost
    kapable-of-shitpost liked this · 1 week ago
  • i-can-kazoo
    i-can-kazoo reblogged this · 1 week ago
  • i-can-kazoo
    i-can-kazoo liked this · 1 week ago
  • theoneicelady
    theoneicelady reblogged this · 1 week ago
  • theoneicelady
    theoneicelady liked this · 1 week ago
  • kazisonline
    kazisonline reblogged this · 1 week ago
  • kazisonline
    kazisonline liked this · 1 week ago
  • altashka
    altashka liked this · 1 week ago
  • vaguelyactive
    vaguelyactive reblogged this · 1 week ago
  • blitzcat-18
    blitzcat-18 liked this · 1 week ago
  • tii-nah
    tii-nah reblogged this · 1 week ago
  • tii-nah
    tii-nah liked this · 1 week ago
  • dolphinsaresilly
    dolphinsaresilly liked this · 1 week ago
  • frogfrogfrogfrog98
    frogfrogfrogfrog98 liked this · 1 week ago
  • fern-daysss
    fern-daysss liked this · 1 week ago
  • stuffnrandomshi
    stuffnrandomshi reblogged this · 2 weeks ago
  • senseikl
    senseikl reblogged this · 2 weeks ago
  • senseikl
    senseikl liked this · 2 weeks ago
  • a-strange-grey
    a-strange-grey liked this · 2 weeks ago
  • i-live-in--the-sea-promise
    i-live-in--the-sea-promise liked this · 2 weeks ago
  • unadulteratedstarlight0
    unadulteratedstarlight0 liked this · 2 weeks ago
  • renekoyuki
    renekoyuki reblogged this · 2 weeks ago
sumactic - plonk
plonk

mcsr and some other stuff

180 posts

Explore Tumblr Blog
Search Through Tumblr Tags