D2sage

Member
  • Content count

    493
  • Joined

  • Last visited

Everything posted by D2sage

  1. @something_elseOnly if he make it invisible. And it is clearly publicly visible. Yeah it should, but it isn't. Can't you see it is visible right here? https://actualized.org/phpinfo.php That version haven't got patched for 5 years and thus it is filled with security flaws. So why would the anti-CSRF work properly? It is the token that is being flagged aswell.
  2. @something_else You can clearly view it right here: https://actualized.org/phpinfo.php It says: PHP Version 5.6.40 So what are you even talking about? Ideal or not, it is running on a dead version. Admin must update it, it won't update itself. Maybe not a miner but it is a potental Cross-site request forgery. Common among forums and sites wiht old PHP. Anyone can make a profile here and upload files.
  3. @thepixelmonk The fact that it is an 8 year old php version that doesn't get updated since 5 years ago, I would be more alert on security alerts and not assume its false negative or whatever. If anything, it should me more likely that it is a positive. https://www.actualized.org/forum/uploads/javascript_core/front_front_profile.js.9e438f42c137b264a74ca2bedb278289.js?csrfKey=013e39e9da0b4445373c91cb3c9971e4&antiCache=6dcee3118d <-- This It flags 2 things at once. Reminds me of CSRF vulnerability. A token is generated and flagged as a script miner, which means there's a security flaw. It is most likely a possible Cross-site request forgery (CSRF). Might also explain why this site is unreachable at times. https://en.wikipedia.org/wiki/Cross-site_request_forgery It can also trick an user's browser into sending unauthorized requests to a web application (miner). Since the security flaw is discovered on the profile section, it is most likely something worth looking into. Actualized is running on a 8 year old PHP version, which is a security risk on its own. Outdated PHP versions, such as those prior to 7.1, are considered end-of-life and are no longer patched. Known security vulnerabilities for these versions exists right now. This alone makes Actualized an easy prey. https://actualized.org/phpinfo.php First of all, I would update php and take threat alerts more seriously, especially when the server is not in the current decade.
  4. Calm mind. Meditation deluxe
  5. Works especially well on young women. But if its the first time then wait. Texting for too long will risk another guy snatching her with a Phone call. I called someone and ended up talking for 8 hours.
  6. Call her randomly when texting. Text are for boy-scouts
  7. @thepixelmonk It Will not show up on actualized tab. It Will show as a legit thing inside task manager, hence the name trojan. it is also possible for a trojan to be hidden from task manager, but an engineer like you already knew that. and only a small percentage of resources Will be used for staying hidden.
  8. Anyone in Ohio? Does the government force you to wear mask now like they did for 3 years during the pandemic? I read that the authorities says the air in Ohio is safe to breath, two days after one of the largest hazmat releases in history. a yikes
  9. America sounds fun and progressive ? As a river-swimmer, this breaks my heart.
  10. No tiktok, no phone. We teach our kid to not point any finger at anyone. She aint the one twerking so pretty good from our side. She plays outdoor mostly and is a member of a football club. more responsible than most parents that I have seen nowadays. the father works too much so I am her role model. Thus far she is doing great at math in school. Speaks english almost fluently and she is born in Sweden.
  11. And also China's version of TikTok — offers a different version of the social media app that is unavailable to the rest of the world, especially for children. Kinda dynamic. Will be interesting to see in the future which cultures invents new and useful tech. I bet its some tiktoker with Donald Duck looking botox lips who comes up with a cure for cancer. And being a social media influencer is not bad. But if you look at most influential influencer, they portray a false view of reality. Everything is happy. Is not like that and this gives children also a false thing to seek. They basically chase an illusion, which leads to mental health issues. People with real talent are also suffering. They just don't get the same encouragement as a talentless tiktoker who lip sync and moves their head a bit, getting like 10m views. An artist who paints realistic art with his feet gets like 1k views. There are many layers of problems to this. Not just only that 6 years old twerking in school.
  12. Should it tho? When you're tripping on mushrooms you know that you can't drive. On alcohol, some idiots think they can. And experienced cannabis users can drive flawlessly while high. I have a friend who smokes for a living. He is more aware of whats going on around him, follows the rules and just drive safe. When sober, he speeds and drives like an idiot sometimes. Cannabis is also harmless, alcohol is not. So alcohol should be illegal. These substances are not for everyone, that's for sure. Not all minds are equal.
  13. A lot of money will be lost if a natural shroom can help people recover from addiction and more. Basically: Legal or not, you can pick shrooms almost everywhere on earth. Was doing some research on shrooms. Found this on the site https://nootroholic.com/psilocybin-mushrooms:
  14. @Danioover9000 Well, on my snapchat map now, I can see a 6-8 year old dancing like those girls on tiktok. This is good news for predators. The twerking is not being recorded. Even my 6 year old who never seen tiktok found it to be a wierd classmate behaviour
  15. I ordered from Nootropics Depot many times, and it even made it to Sweden. Good products. I had a blog on nootropics before and always recommended them on my site.
  16. Sounds like Sweden. Aren't these signs for most countries during regression? I am moving to Mallorca because of how stupid teachers are in my little sisters school. But in Portugal you guys have some nice, big waves to surf on so that's a big plus.
  17. Someone used AI to make a false Zelensky speech. Intel is developing an AI to spot this shit. https://www.intel.com/content/www/us/en/newsroom/news/intel-introduces-real-time-deepfake-detector.html#gs.prmk2g My guess would be that in the future, companies who use AI generated stuff must say so in the video. Like a logo somewhere. For example, in EU's cookie law, when you visist a website it tells you that the site has cookies and you must consent.
  18. So my computer is now hosted here on actualized.org/forum/uploads I run online servers, a kratom forum, and websites. My PC is cleaner than your vocabulary. It is classified as a Trojan because it is typically disguised as a legitimate file and is designed to deceive the victim into running it on their computer. Look, I know some of you guys here would drink Leos bathwater. You fail to realize one thing. I am not bashing Leo that he’s injected some code. On my old PC, I had poor security and did not care about alerts. Then I got my credit card stolen and Instagram hacked. I am just cautious nowadays and more alert online.
  19. @thepixelmonk Not all, just that one. Well, the path is https://www.actualized.org/forum/uploads/ Isn't that the same catalog where our uploaded media files are.
  20. @thepixelmonk I hope you're right. @Leo Gura You can delete the js file? The site will work just fine. Better safe than sorry.
  21. @thepixelmonk The point was: The code is not obvious that it is a miner. To view the tracked data you need another platform. So its 100% possible that the js. file on actualized.org can be a miner. Plus, the code here is trying to execute on my computer. Why am I only getting alerts when visiting profile? But nowhere else on the site? And you can clearly see the source right here: February 3rd. First time I visited this site on my new PC. But then I did not care, but now I think its worth mentioning.
  22. @thepixelmonk You don't sound credible at all, more like a fool tbh. "lmao" My system is clean. Why am I only getting alerts when visiting profile? But nowhere else on the site? And you can clearly see the source right here: February 3rd. First time I visited this site on my new PC. But then I did not care, but now I think its worth mentioning.
  23. @thepixelmonk My PC has a fresh Windows 11 installed and the source of the "malware" is from this site. Also, that's not the entire source of the file you linked hehe, here's the whole thing https://pastebin.com/raw/ZeBwZtvG You have no clue what you're talking about. Would be better if a Javascript developer could confirm. Here's how google analytic script look. The code itself (embedded JavaScript), it is not obvious that this will track your location, device, age etc? So the potential miner script here would not be so obvious.
  24. I did nofap for 1 year back in 2018 after many tries prior. Now I can't get aroused by porn and only real women can. I avoid speaking about this because most guys get defensive and want to save their precious free dopamine through pornography.