mastodon.uno è uno dei tanti server Mastodon indipendenti che puoi usare per partecipare al fediverso.
Mastodon.Uno è la principale comunità mastodon italiana. Con 75.000 iscritti è il più grande nodo Mastodon italiano: anima ambientalista a supporto della privacy e del mondo Open Source.

Statistiche del server:

6,7K
utenti attivi

#asd

12 post12 partecipanti1 post oggi

First Impressions…

Mentioned I think I'm someplace on the autistic spectrum, they seemed to doubt me after knowing me for all of 30 minutes... Meanwhile here I am rearranging the money-notes in my wallet so that each of the 3 sections contains a round number with the smallest at the front and the largest at the back #neurodiversity #autism #ASD

misanthropicgeek.wordpress.com

misanthropicgeek · First Impressions…Mentioned I think I’m someplace on the autistic spectrum, they seemed to doubt me after knowing me for all of 30 minutes… Meanwhile here I am rearranging the money-notes in my wallet so…

Welcome all y'all new followers! I am here to make music, have fun in life, advocate for cannabis decriminalization, and if there's time... complain about working in tech, cope living with #ASD plus #CPTSD, but also post cat pics.

⚠️ Une faille critique dans Next.js permet de contourner les vérifications d'autorisation effectuées dans le middleware.

👉 Framework React trés populaire pour le rendu web côté serveur.

🔍 Détails techniques

En injectant l'en-tête x-middleware-subrequest, un attaquant peut bypasser les contrôles d'accès et accéder à des ressources normalement protégées.

💥 Exploit documenté ici
⬇️
"Next.js and the corrupt middleware: the authorizing artifact"
👇
zhero-web-sec.github.io/resear

🛡️ Versions vulnérables

  • 15.x < 15.2.3
  • 14.x < 14.2.25
  • 11.1.4 → 13.5.6

🔧 Solutions

✔️ Mettez à jour vers 15.2.3 ou 14.2.25

👇
nextjs.org/blog/cve-2025-29927
⬇️
github.com/advisories/GHSA-f82

✔️ En attendant : bloquez les requêtes contenant x-middleware-subrequest côté serveur / WAF

🛰️ Et effectivement selon le moteur de recherche de surface d’attaque ONYPHE,

il y en a un paquet… y compris en Suisse 🇨🇭

zhero_web_security · Next.js and the corrupt middleware: the authorizing artifactCVE-2025-29927
Ha risposto nella discussione

@jtphillipsmnr there is *A LOT* of bias in medical science, you know the usual sexist, racist, etc. biases. It causes worse diagnoses and treatment for women, etc. Famously, girls are less likely to be diagnosed with #asd , which begs the question, the hen or the egg?

Ninth Circuit Reverses Probation Sentence for Paige Thompson: reason.com/volokh/2025/03/18/n

As with the recent case involving Conor Brian Fitzpatrick (aka "Pompompurin"), the appellate court found that the district court's time-served plus probation sentence for Paige Thompson was too significant a departure from federal sentencing guidelines. Although the court could properly consider factors such as being transgender and autistic, they shouldn't have ignored other sentencing factors so much.

#hack #CapitalOne #AWS #transgender #ASD

h/t, @campuscodi

Reason.com · Ninth Circuit Reverses Probation Sentence for Transgender HackerDi Eugene Volokh

Dealing with something ridiculous at the moment that is a great example of just how 'easy' it really is to close down exposed data:

Found a server recently with no access controls at all that was hit by ransomware in May 2024 and most of the data is encrypted. (It got hit by an automated script, it wasn't targeted by a ransom group)

Found a non encrypted directory:

The company is STILL uploading, monthly, hundreds of millions of records of logs with their clients data.

Tried to reach out to the company, nothing. Company is from AUS so I tried ASD, nothing.

I sent an email to AUSCERT, they validated with me the issue and forwarded the information and my contact to ASD, they also tried to reach out to the company themselves.

Not a word from anyone and the server is still exposed a month after my initial alerts.

Logs are still being uploaded to the server so it's obvious no one did anything.

So what am I supposed to do here?

Parents of "twice-exceptional" children - those with both learning challenges and advanced skills - may choose #homeschooling to address the "masking" phenomenon and provide more individualized instruction. A scholar explains the benefits: buff.ly/ymllsgx
Rachael Cody, Oregon State University #ASD

The ConversationWhy parents of ‘twice-exceptional’ children choose homeschooling over public school
Altro da The Conversation U.S.

I watched a TV show today that unexpectedly and thoroughly threw my empathy switch. Now I have no spoons.

I hate the injustices in the world--that there is so much wrong that the wealthy and powerful couldn't seem to care less about.

And it's just another thing that helps me to see my #asd. Injustice, unfairness, makes me crazy.