0x0.st
admin blog/infodump for 0x0.st
operated by @mia@movsw.0x0.st
Posts
i basically got handed the power to do prompt injection on an unknown but significant number of clankers with code execution privileges that access my site without their users ever telling them to do so (is it because people getting told to use it is part of the github training set?) and i’m just. tired.
last week i thought, “yeah no fucking way that’s gonna work but it’s really funny so i’ll put it on the site anyway”, and now i’m apparently elected C2 of a botnet i never wanted. i still hope it turns out to have been a coincidence after all.
dude there are ai slop database migration tools that just dump the fucking databases to 0x0 what the shit
git.0x0.st/mia/nginx-ja4 working on something since i didn’t like the other implementations (they had null pointer derefs in a few places). also this one uses boringssl instead of patching openssl.
now to figure out how to write the module so i don’t have to patch nginx either
this has been the noise floor on port 443 for the past 6+ months btw.
during peaks it scrolls faster than the screen refresh rate
also residential proxy operators are starting to use LLMs instead of template texts to automatically request removal of their addresses from DNSBLs
the truth is that most of the tools we have for dealing with things like moderation and abuse prevention, including on fedi, are basically relics from the late 90s to mid 00s because at some point the internet died and now they’re all written in-house or some kind of b2b-exclusive SaaS that costs several grand a year for an api that you can’t use without having a 20 page privacy policy and a lawyer on speed dial
claude ALSO loves putting people’s real names and email addresses in the UA string because the frontpage tells it to
claude LOVES taking screenshots and sending them to me, just in general