mouthporn.net
#again – @whitmerule on Tumblr
Avatar

whit merule

@whitmerule / whitmerule.tumblr.com

The theme of this blog is 'things that are making me happy'. If you're looking for my Cats content, it's at @junkyard_gifs.I am on AO3 under the name 'whit_merule'. This is a hatred-free blog, and a safe space for your identity and for your fandom preferences. (I am a bisexual ace in my thirties, with 'she' pronouns.) Ship who you ship, love who you love, be whoever you really are as hard as you damn well can, and tag as appropriate for anything that might make others uncomfortable.
Avatar
Avatar
elfgrove

New Things to Beware on the Internet

On May 3rd, Google released 8 new top-level domains (TLDs) -- these are new values like .com, .org, .biz, domain names. These new TLDs were made available for public registration via any domain registrar on May 10th.

Usually, this should be a cool info, move on with your life and largely ignore it moment.

Except a couple of these new domain names are common file type extensions: ".zip" and ".mov".

This means typing out a file name could resolve into a link that takes you to one of these new URLs, whether it's in an email, on your tumblr blog post, a tweet, or in file explorer on your desktop.

What was previously plain text could now resolve as link and go to a malicious website where people are expecting to go to a file and therefore download malware without realizing it.

Folk monitoring these new domain registrations are already seeing some clearly malicious actors registering and setting this up. Some are squatting the domain names trying to point out what a bad idea this was. Some already trying to steal your login in credentials and personal info.

This is what we're seeing only 12 days into the domains being available. Only 5 days being publicly available.

What can you do? For now, be very careful where you type in .zip or .mov, watch what website URLs you're on, don't enable automatic downloads, be very careful when visiting any site on these new domains, and do not type in file names without spaces or other interrupters.

I'm seeing security officers for companies talking about wholesale blocking .zip and .mov domains from within the company's internet, and that's probably wise.

Be cautious out there.

I really want to reiterate how this can go wrong frequently and fast, folks.

A malicious actor sets up a page with an auto-downloader squatting on a domain name that matches a common zip file name like photos DOT zip. This website is set up to start an auto downloader upon being visited, downloading a zip file with the same name as the URL which contains malicious software (virus, worm, keylogger, etc).

Scenario.

Someone you know well sends you an email or text with promised photos attached. The email even reads something like this.

Because .zip is now a TLD, that plain text is automatically formatted into a link to malicious actor's website without them having to send you anything.

Folk with family with iPhones or iPads that are sent multiple photos in one go might be familiar with iCloud's tendency to automatically compile them into zip file for the sender and less savvy tech users have trouble NOT doing that.

These same less savvy users, or even just someone just not thinking in the moment, will click that .zip link, not realizing it isn't the the same as clicking on the promised attachment.

They download a file that matches the name they expected. They open it because they were expecting that file and it's from a trusted source. Except the file they downloaded isn't the one that was sent by their trusted source and now they have malware.

Another Scenario.

An IT person tries to send you an email with instructions on how to resolve a problem with a commonly used filename like install-repair DOT zip or to install new software like microsoft-office DOT zip.

The email may start with instructions of where to go get the legitimate file to do the install or repair, but now a line later in the instructions is also has a link to a .zip URL. A user, already frazzled by IT problems, may click it to ensure they have the right file. Again, they download malicious code from a squatting website or it prompts them with a fake login and now the squatting website has stolen their login credentials for a legitimate site. All due to an expected email from a trusted source.

Above you can see microsoft-office DOT zip is already out there with a fake Microsoft login screen waiting to steal your credentials.

These risks are already out there now because the TLD has been activated.

Plain text on old post are already being resolved into links to the new websites.

Here you can see a tweet from 2021, long before .zip was a domain name, now resolves that plan text into a clickable link. You'll start seeing this everywhere, and malicious actors do not have to lift a finger to send it to you.

Yes, a lot of users aren't going to click that, but a lot of folk will. Whomever is squatting on photos DOT zip domain name has made a one time payment to have access to anyone that ever sees that file name typed out.

In an example of an existing squatter site, clientdocs DOT zip is exactly one such pre-setup .zip domain name that initiates an automatic download. This one may be harmless, but the set ups are already out there and waiting to catch folk.

It's an unnecessary and risky can of worms that's been opened up.

Holy Unforced Errors, Batman.

Thanks guys for getting me brownie points with my head of IT at work! This hasn't been circulated on the usual digital risk news alerts that most IT people are looped in on so as well as sharing it with your friends and family also share it at work!

Avatar
reblogged

*noot noots in here to post that part where pouncival tried to cut in on alonzo’s seduction and got iced*

That was hard to see @pouncifail

Avatar
pouncifail

why? I got to say two words :D

also dad has some really neat hip action thing going on??? way better than mine. mine doesn’t work even on jenny. 

Avatar
Supernatural writers: we did the right thing by killing off Cas for a few episodes
Sam: you fucked up a perfectly good Dean Winchester is what you did look at it it’s got anxiety.
Avatar
reblogged

Delivering the inaugural lecture at the three-day Sam Moyo Memorial Conference on “Land and Labour Questions in the Global South”, Utsa Patnaik said that the estimated drain from India to Britain over the period from 1765 to 1938 was a whopping 9.184 trillion pounds, several times the size of the UK’s GDP today.

Patnaik, who is Professor Emerita at the Centre for Economic Studies and Planning (CESP), JNU, said that the policies followed by Britain during its colonial rule in India were so disastrous that per capita food grains availability in India declined drastically from 197.3 kg per year in 1909-14 to 136.8 kg per year in 1946.

this was my immediate thought after reading the headline lol

Avatar
whitmerule

okay colonialism is bad but 'several times the size of' vs 173 years that's sort of... a long time. a bit more than 'several times' compared to a year.

Avatar

Far out in the uncharted backwaters of the unfashionable end of the western spiral arm of the Galaxy lies a small unregarded yellow sun.

Orbiting this at a distance of roughly ninety-two million miles is an utterly insignificant little blue green planet whose ape-descended life forms are so amazingly primitive that they still think digital watches are a pretty neat idea.

This planet has-or rather had-a problem, which was this: most of the people on it were unhappy for pretty much of the time. Many solutions were suggested for this problem, but most of these were largely concerned with the movements of small green pieces of paper, which is odd because on the whole it wasn't the small green pieces of paper that were unhappy.

And so the problem remained; lots of the people were mean, and most of them were miserable, even the ones with digital watches.

Many were increasingly of the opinion that they'd all made a big mistake in coming down from the trees in the first place. And some said that even the trees had been a bad move, and that no one should ever have left the oceans.

And then, one Thursday, nearly two thousand years after one man had been nailed to a tree for saying how great it would be to be nice to people for a change, one girl sitting on her own in a small cafe in Rickmansworth suddenly realized what it was that had been going wrong all this time, and she finally knew how the world could be made a good and happy place. This time it was right, it would work, and no one would have to get nailed to anything.

Sadly, however, before she could get to a phone to tell anyone about it, a terribly stupid catastrophe occurred, and the idea was lost forever.

This is not her story.

Avatar
Avatar
hopesetfree

This blog is on hiatus until further notice. There are still posts in my queue, but I will be absent for quite a while unless a miracle occurs (and I will queue this post a few times to be sure everyone gets the message).

Also, I am about to become homeless within the next two weeks (maybe sooner), so if you have anything to spare, even $1, I would be forever grateful (my PayPal is [email protected]). It’s so embarrassing to even have to ask this. I just need to survive until early August, when I’ll have a guaranteed place to stay.

A fuller, personal explanation is under the Read More if you care/want to read it.

Everyone who helps out will get a drawing from me

Sorry to spam you guys, since I already reblogged this once, but if y’all can help Sera out, right now you can get a drabble from aria-lerendeair, a drawing from tricksterangelgabriel or a drabble from me.

So, y’know… if you can.  If you can’t, just a reblog will help!

Avatar

I know you don’t know me well and I probably don’t know you well, but I’m going to leave this here. This is my 7-year-old niece, Phoenix, who was killed by a drunk driver the other night.

Even if you aren’t able to help, please signal boost to spread the word. My sister and her family could use every small ounce of help and good thoughts.

Thanks.

Avatar

.... Curses.

I am just re-reading March-Stalkers Mighty and realised why I have always been vaguely dissatisfied with the middle, and hence with the slightly saccharine atmosphere that crops up too often in the second half.

And I promise this isn’t just because of the season 9 finale, but….

After Gabriel, Sam, and Cas escape. When Dean stays behind and confronts the town. In those two months that follow.

They should have been keeping him locked up in the bull press. He should be the one treated like a monster. He needs a reason more solid than he currently has for wondering if there’s something wrong with him, for dreaming himself as Grendel, and for letting the demon possess him later on the hunt. Like Gabriel (but in his own way) he needs to start down that path.

And the shades of the monstrous should not just vanish as soon as Cas turns up again.

Basically, damn, I was holding back and not following through my OWN narrative cues. So much foreshadowing and I wimp out to protect my characters. And here I am repeatedly criticising the show’s creative team for the same.

Avatar
reblogged
Avatar
deancasotp

i really would like to reblog that congrats from the cw on fave tv bromance because FUCK YES TEAM FREE WILL (AND J2M OBVIOUSLY) !!!!!!!!

but the term bromance is actually highly offensive in this instance as it was used to “pacify” people because the peopleschoice awards refused to add dean and cas to the best chemistry category, even though lbr they’re basically the reason for the category, because we all know that two men cannot have great chemistry together on screen without their characters being in a romantic relationship right??????? //////heavy sigh

and the fact that the votes for dean and cas that people wrote in themselves in the best chemistry category (which is what the peopleschoice twitter told people to do) were instead put towards the fave bromance category is highly manipulative and deceiving and fucking gross tbh

so yeah, woo team free will!!! but fuck the pcas because that’s so messed up i cant even tell you

heteronormality prevails, surprise surprise

Avatar
whitmerule

Oh, is THAT what happened.

You are using an unsupported browser and things might not work as intended. Please make sure you're using the latest version of Chrome, Firefox, Safari, or Edge.
mouthporn.net