Message from @shadowedROM

Discord ID: 225430244516036608


2016-09-14 01:29:36 UTC  

someone bought it

2016-09-14 01:29:46 UTC  

It's made to download spotify songs with a web interface

2016-09-14 01:30:06 UTC  

The input for the url is directly pipped into command line as root

2016-09-14 01:30:11 UTC  

without input santization

2016-09-14 01:30:23 UTC  

It's not pwned yet!

2016-09-14 01:32:11 UTC  

there's a laundry list of stuff you watch out for but yeah i mean, your rinkydink app probabilistically isn't an attractive target to anyone besides folks hunting for trophies right

2016-09-14 01:32:38 UTC  

there's xss stuff in addition to input sql / stack smash attacks or whatever

2016-09-14 01:32:57 UTC  

but i was actually referring to devs who push out malperforming code

2016-09-14 01:33:42 UTC  

it happens way too often, stupid race conditions esp with front end js these days, which is really frustrating because that's tough to run a test for; it's the halting problem etc

2016-09-14 01:34:09 UTC  

but yeah sometimes the old dumb use of ORM knocks down a DB and whoops there goes our weekend

2016-09-14 01:34:25 UTC  

oh so

2016-09-14 01:34:43 UTC  

with AWS there's a cheat code there in the form of being able to feed more horsepower to dynamoDB and such

2016-09-14 01:35:02 UTC  

and that's basically where people fuck themselves

2016-09-14 01:37:32 UTC  

it's enough to make someone want to stop doing tech stuff and go into ... marketing or something. :/

2016-09-14 01:37:42 UTC  

too many incompetents

2016-09-14 01:38:41 UTC  

where you from?

2016-09-14 01:38:51 UTC  

Temping to assume US

2016-09-14 01:38:58 UTC  

nyc

2016-09-14 01:39:11 UTC  

so my experience is likely colored

2016-09-14 01:39:11 UTC  

I keep hearing they got good devs in general in the US

2016-09-14 01:39:18 UTC  

hell no

2016-09-14 01:39:50 UTC  

we have a large sample space is all

2016-09-14 01:40:53 UTC  

there's a toxic work culture thing in tech the past few years where everyone wants their teams to work like it's a startup and put in 60 hours a week to push inane projects out

2016-09-14 01:41:12 UTC  

likely not going away

2016-09-14 01:41:29 UTC  

btw sorry to interrupt

2016-09-14 01:41:35 UTC  

but where tf is the php.ini file

2016-09-14 01:41:49 UTC  

which os? usually /etc/php/php.ini no

2016-09-14 01:41:54 UTC  

linux yea

2016-09-14 01:41:55 UTC  

ubuntu

2016-09-14 01:41:58 UTC  

it's not there

2016-09-14 01:42:04 UTC  

It was there like a month ago

2016-09-14 01:42:06 UTC  

find . | grep php

2016-09-14 01:42:10 UTC  

I remember editing it

2016-09-14 01:42:18 UTC  

are you using php-fpm

2016-09-14 01:42:50 UTC  

no i dont think so, i dont remember

2016-09-14 01:42:54 UTC  

using it with apache

2016-09-14 01:43:11 UTC  

on my machine it's /etc/php5/fpm/php.ini, but i'm using php-fpm

2016-09-14 01:43:38 UTC  

the non-fpm one is likely /etc/php5/cli/php.ini

2016-09-14 01:43:51 UTC  

that's on a debian box

2016-09-14 01:43:57 UTC  

should be the same.

2016-09-14 01:44:31 UTC  

anyways I'll find it someday... so you worked in on of those startups minus the fun?