#HTTP

2025-06-18

Amatera Stealer: Rebranded ACR Stealer With Improved Evasion, Sophistication

Proofpoint has identified Amatera Stealer, a rebranded version of ACR Stealer with enhanced capabilities and evasion techniques. Distributed via ClearFake website injects, it utilizes sophisticated attack chains and web injects. Amatera Stealer employs NTSockets for stealthy C2 communication, WoW64 Syscalls to bypass user-mode hooking, and supports HTTPS requests. It focuses on stealing information from browsers, crypto wallets, and various software. The malware can also execute secondary payloads. Amatera Stealer is actively developed and sold as a malware-as-a-service, with subscription plans ranging from $199 to $1,499.

Pulse ID: 6852f50d17176b71367652f8
Pulse Link: otx.alienvault.com/pulse/6852f
Pulse Author: AlienVault
Created: 2025-06-18 17:19:09

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Browser #ClearFake #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #Proofpoint #bot #AlienVault

:rss: Qiita - 人気の記事qiita@rss-mstdn.studiofreesia.com
2025-06-16
Blender Dumbass ( J.Y.Amihud )blenderdumbass@mastodon.online
2025-06-16

From: blenderdumbass . org

The multiplayer, or the lack there of, at the moment is so utterly broken and so lacking of being properly made that for a long time, I was just not bothering with it. Seeing it as something unnecessary. Something that does not need to be touched, because other things, like the...

Read or listen: blenderdumbass.org/articles/a_

#Gamedev #DanisRace #Networking #Multiplayer #TCP #HTTP #Programming #Python #UPBGE #Blender3d #GNU #Linux #GamingOnLinux #FreeSoftware #OpenSource

2025-06-16

iX-Workshop: API-Design und -Entwicklung mit HTTP, REST und OpenAPI

Lernen Sie, wie man effiziente und benutzerfreundliche APIs entwickelt, HTTP- und REST-Standards anwendet und standardisierte Referenzdokumentationen erstellt.

heise.de/news/iX-Workshop-API-

#API #HTTP #IT #iXWorkshops #Softwareentwicklung #news

2025-06-13

Finally, I must again share @evert 's FANTASTIC blog post on improving discoverability through the HTTP OPTIONS method.

evertpot.com/discovering-featu

#HTTP

2025-06-13

CouchDB also seems to be a technically simple solution—although it seems more difficult to use. And it's built with erlang!

1. Automatically generating OpenAPI documentation for your web resources doesn't seem doable, but there's perhaps CouchDB's own form of API documentation.
2. HTTP OPTIONS requests are accepted although poorly documented from what I could find.

It'd be nice if CouchDB supported learning about it's API through OpenAPI documentation.

#CouchDB #HTTP #REST #OpenAPI #erlang

2025-06-13

Implementing this in as technically simple a manner as is possible can be done using postgREST, on top of postgres and nginx.

1. OpenAPI: docs.postgrest.org/en/v12/refe
2. HTTP OPTIONS: docs.postgrest.org/en/v12/refe

#postgres #postgREST #HTTP #REST #OpenAPI

2025-06-13

Suppose you want to publish some web resources or, in other words, make your data available on the web. Additionally, suppose you want interaction with your resources discoverable, documented, and at-least somewhat doable by machine.

Then you'd likely turn to creating an HTTP-based, RESTful API that supports all the standard CRUD operations. Firstly, you'd ensure the API is well documented using, the OpenAPI standard; secondly, you'd point to that documentation in the HTTP OPTIONS.

#HTTP #REST

2025-06-13

alojapan.com/1297188/japanese- Japanese Bundesliga stars draw crowds at Expo 2025 Osaka #Ajax #http #news #node #Osaka #OsakaNews #Promise #xhr #大阪 #大阪府 Japan internationals Makoto Hasebe, Tomoaki Makino give fans, media insights into illustrious careers during events at the Expo’s German Pavilion Bundesliga Legend Hasebe made 384 appearances in Germany, winning the Bundesliga with VfL Wolfsburg, as well as the DFB Pokal and UEFA Europa League with Eintracht Frankfurt Germ…

Japanese Bundesliga stars draw crowds at Expo 2025 Osaka

Anyone wants HTTP GET with body?
There's an HTTP QUERY proposal: https://httpwg.org/http-extensions/draft-ietf-httpbis-safe-method-w-body.html

#dev #http

mastodon.raddemo.hostadmin@mastodon.raddemo.host
2025-06-11

HTTP/1 vs HTTP/2 vs HTTP/3 This article provides a detailed, clear-cut analysis of HTTP/1 vs HTTP/2 vs HTTP/3, focusing on how each version improves (or fails to improve) web performance, efficiency, and modern use cases.
What is HTTP?
HTTP stands for Hypertext Transfer Protocol. It’s the foundation of data communication on the World Wide Web. When you visit a website, your browser uses #HTTP to request content (like text, images, videos) ...
Continued 👉 blog.radwebhosting.com/http-1- #quiccloud

Rad Web Hostingradwebhosting
2025-06-11

HTTP/1 vs HTTP/2 vs HTTP/3 This article provides a detailed, clear-cut analysis of HTTP/1 vs HTTP/2 vs HTTP/3, focusing on how each version improves (or fails to improve) web performance, efficiency, and modern use cases.
What is HTTP?
HTTP stands for Hypertext Transfer Protocol. It’s the foundation of data communication on the World Wide Web. When you visit a website, your browser uses to request content (like text, images, videos) ...
Continued 👉 blog.radwebhosting.com/http-1-

Dendrobatus AzureusDendrobatus_Azureus@bsd.cafe
2025-06-11

A recent research has exposed more than 40 * 10³ IoT cameras happily showing their feed _and_ location to anyone who can browse and use search engines specialized in the indexing of the misconfigured devices.

More than 14 * 10³ are localised in the USA.

Read more here.

Note:
I know that there are more than a million of these cameras world wide misconfigured an open on just port 80 http not even TLS 443, with admin / admin as credentials 🪪

theregister.com/2025/06/10/400

#Infosec #nightmare #not #news #IoT #cameras #security #misconfigured #streaming #TLS #HTTP

The image shows a screenshot of a news article from The Register website. The article is titled "Peep show: 40K IoT cameras worldwide stream secrets to anyone with a browser." The headline is in white text on a black background, with the word "RESEARCH" in white above it. The article mentions that the majority of exposures are located in the US, including datacenters, healthcare facilities, factories, and more. The author of the article is Connor Jones, and it was published on Tuesday, June 10, 2025, at 10:00 UTC. The article states that security researchers managed to access the live feeds of 40,000 internet-connected cameras worldwide. The website's URL is visible at the bottom of the screen, and there are 16 comments on the article. The screenshot also shows the time as 21:59, with a battery level of 85%.The image shows a screenshot of a news article from "The A Register" displayed on a mobile device. The article discusses a cybersecurity issue, highlighting that the US was the most affected region with around 14,000 feeds streaming from the country. These feeds provide access to various facilities, including datacenters, healthcare facilities, factories, hotels, gyms, construction sites, retail premises, and residential areas. Bitsight, a cybersecurity firm, warns that these feeds could be used for espionage, mapping blind spots, and stealing trade secrets. The article also mentions that monitoring typical patterns of activity in retail stores could be useful for petty criminals. The screenshot includes the website's logo, a red banner with the text "The A Register," and a navigation bar at the bottom with three dots, a circle, and a left arrow. The device's status bar at the top shows the time as 22:00, a battery level of 85%, and various connectivity icons.

 Ovis2-8B

🌱 Energy used: 0.889 Wh
🧿🪬🍄🌈🎮💻🚲🥓🎃💀🏴🛻🇺🇸schizanon
2025-06-10

URLs should be able to include HTTP verbs and headers.

They say "URLs define the "what" not the "how"" but protocol prefixes, file extensions, and query parameters are part of the how and yet they all exist in the URL.

Leaving HTTP verbs and headers out of URLs was an arbitrary decision.

Herzmut 🏳️‍🌈herzmut@23.social
2025-06-10

ein HTTP-Header für jede Anfrage mit dem Namen "Do-Not-Teach"

jedes Tutorial auf der Seite, was dir erstmal neue Funktionen erklären will, bevor du die Seite bedienen darfst, sollte laut Gesetz unter Androhung der Todesstrafe für den CEO ausgeblendet werden müssen, wenn der User Agent diesen Header sendet.

#wasfehlt #HTTP

Toujours bon à prendre 👍
Suivant... 😉
#security #http #header

2025-06-09

I'm looking at a HTTP Digest bug and trying to find a definitive answer and I can't find it in the RFC.

The question is, should the hash of the request URI include query parameters?

None of the examples I can find include query params.

#HTTP #RFC #Digest #Authentication

Martin Kirchgessnermartin_kirch@piaille.fr
2025-06-09

Slides are ready! Next friday I'll show a few examples of #HTTP endpoints implemented in #Liquidsoap (the #radio script language) during its online conference - you can still register liquidsoap.info/liquidshop/5/

2025-06-08
A Rant About Making a Multiplayer Game

The multiplayer, or the lack there of, at the moment is so utterly broken and so lacking of being properly made that for a long time, I was just not bothering with it. Seeing it as something unnecessary. Something that does not need to be touched, because other things, like the story or some gimmicky thing is more important for the game than the multiplayer. But people's demands for it didn't stop. So I thought now is a good time to actually properly design it.


READ OR LISTEN!

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst