Message from @cathy
Discord ID: 193739086341603328
inb4 Dawn is another 12 year old like Zombii
I don't have a non work box I can use to hit it with
so I can't test it
You got me.
Sucks to be you
I mean try injecting another header into the URL
then look at the response
I don't see how that would do anything, it gives youtube-dl the link and asks for the stream url
Uh you can use it to hit internal resources/send requests to any site with any data you want
It's open source so they can see for themselves.
youtube-dl, I mean.
We're just using someone else's bot
Yeah but someone here is hosting it
all I'm saying is it's worth checking so they don't get abuse complaints for someone using their shit in a bad way
If it was that much of a problem to you then you'd fix it. :^)
So you want to request cp links in here with !play or what?
What the fuck
All I did was suggest that your bot might be vuln to a public CVE
!play autism
I was about to say.
I don't know if ydl has any filters
... I already said I don't have a box I can tail -f logs for
And I don't particularly care about that
lol
Discord isn't going anywhere, try hitting it later
I don't have a box that isn't work related
itistimetostopposting.jpg
>poll is it time to stop posting;yes;no
📃**Comfy** from **/csg/** server has created a poll which requires your attention:
**is it time to stop posting**
`1.` **yes**
`2.` **no**
**Private Message me with the corresponding number of the answer.**
Mind elaborating what "hit it" means?
Make a request to my http server
Where I can see if it's actually working, it's HTTP header injection
It's an issue even if you just have private services running on your box
because smeone can use that to pivot to them
>pollend
📄 **Total votes cast**: 2
--------------**POLL CLOSED**--------------
📄 , here are the results:
`1.` **[yes]** has 1 votes.(50%)
`2.` **[no]** has 1 votes.(50%)
I thought Snowdenistas went out of fashion.
Like i'm only telling you because I like it here already. I'm not trying to make a big deal out of it
But you are.
>not making a big deal out of it