Загрузка видео...

Не удалось загрузить видео

На главную

How to find viable targets for client-side desync attacks: 1️⃣ Open Burp Suite and intercept requests. 2️⃣ Choose an endpoint that wouldn't usually expect a POST request (e.g GET) and send it to repeater. 3️⃣ Go to Inspector > Request Attributes > Protocol field > Upgrade to HTTP/2. 4️⃣...

16,569 просмотров • 1 год назад •via X (Twitter)

Комментарии: 0

Нет доступных комментариев

Здесь появятся комментарии из оригинального поста

Похожие видео

While working on a new video with solutions to the previous one, I found ChatGPT's new UI struggles even more with concurrent updates: entries lose state and stick around for too long (see video). If this was a LiveView app, we would be getting so much flak.😅 --- I believe part of the problem here is having separate mutate and fetch requests on every deletion. The first fetch is cancelled when the second one comes up, causing items to stick around for longer. Many said yesterday that you could do the mutation and fetch as a single request, but that leads to other problems, such zombie entries. For example, imagine you delete link1 and link2 within a brief period of time. There is no guarantee the deletion order in the database will match the order the client receives the response, so you may end up with this: 1. (client) request to delete link1 sent 2. (client) request to delete link2 sent 3. (server) deletes link1 and loads a new list (includes link2) 4. (server) deletes link2 and loads a new list (no link1 or link2) 5. (client) receives link2 response 6. (client) receives link1 response So if you choose to use the latest response (link1), you brought link2 back to life. If you say you will use the response from the last request, events 3-4 can be swapped, and now you bring link1 back to life. Another way to solve this is by basically not allowing concurrent requests at all but that can affect the user experience drastically in other ways. Next week I should publish a video explaining how LiveView tackles this. Stay tuned!

José Valim

22,976 просмотров • 2 лет назад

Did you know that in 1947, GE (General Electric) scientists were involved in a secret government program called Project Cirrus that seeded hurricanes to steer them? After seeding, the hurricane took an immediate sharp turn towards the southeast US. They did this 80 years ago... Did you also know there was another program called Project Stormfury from 1962-1983 that seeded hurricanes to a substantially higher degree to "learn whether the force of the storms can be diminished"? It's completely rational to think that they also learned more about how they can impact their trajectory towards landmass and increase it's destructive power. What if the government is just creating a human trauma farm and disaster economy so they can continue to make you more and more reliant on them and profit from it at the time? If still you're struggling to comprehend that kind of malice from these orgs, you must have been dead asleep for the past 4 years. To quote Richard Spinrad from a 2009 memo to HSARPA, who was the National Oceanic and Atmospheric Administration’s (NOAA) assistant administrator for the Office of Oceanic and Atmospheric Research (OAR). "While OAR recognizes that weather modification, in general, is occurring through the funding of private enterprises, NOAA does not support research that entails efforts to modify hurricanes" Read this part very slowly - "is occurring through the funding of private enterprises" Geoengineering and weather modification is reality and you have to be blind or dishonest not to believe it at this point. The government can create, diminish, and steer hurricanes, and they've had the capacity to do so for decades. So yet again, you must now ask yourself... Would they do such a thing and willfully cause destruction and harm to their own citizens for a nefarious or profit motivated purpose? The answer is a resounding and undeniable YES, they would.

Inversionism

1,580,005 просмотров • 1 год назад

Day 11/90 of Inference Engineering How does vLLM work and how is it used in production? Before we discuss how vLLM works internally, it helps to understand what vLLM is. At a high level, vLLM is an inference engine that is designed to serve LLMs to thousands of concurrent users efficiently while managing scarce compute and memory. The goal for vLLM is to maximize throughput and minimize latency; optimizing for the best inference economics and experience for end users. With every request from the end user, it eventually ends up in the engine core, gets scheduled alongside other requests from other concurrent users, executes on the GPU, and updates the KV cache with the new key and value vectors, and streams the tokens back to the user. The Scheduler decides what requests should execute next while continuously batching requests together to maximize GPU utilization. Continuous batching is an inference optimization that allows new requests to join a running batch as other requests finish generating tokens. This helps with keeping the GPU utilization high instead of letting it sit idle waiting for an entire batch to complete generating. After the scheduler dispatches the selected batch to the Model Executor, the Model Executor prepares the tensors and metadata required for inference, retrieves each request’s block table from KV Cache Manager, launches the optimized transformer forward pass on the GPU, computes the logits, updates the KV cache with the new key and value vectors, and finally returns the results for sampling and streaming. The KV Cache Manager uses the PagedAttention memory layout to allocate fixed-size cache blocks on demand and maintains a Free Block Queue on the CPU that tracks which blocks in the GPU’s Paged KV Cache are currently free. When a request needs additional KV cache space, the KV Cache manager takes a free block from the queue and assigns it to that request, thus avoiding an expensive search through GPU memory for available cache blocks. All of these components form the core of vLLM’s inference engine. The Scheduler determines what requests are executed, the Model Executor determines how those requests are executed, the KV Cache Manager determines where each request’s KV cache lives using the PagedAttention Memory Layout. This architecture enables vLLM to serve thousands of concurrent requests with high throughput, low latency, and efficient GPU memory utilization. Heres a little animation that visualizes everything! - I've also completed the forward pass for my mnist.c project. I had a nice chat with shrey birmiwal, such a knowledgeable guy. Excited to learn more about vLLM and implement a tiny-vLLM one day.

max fu

70,543 просмотров • 1 месяц назад

I have not seen enough about the decision from Mike Vrabel and Tim Kelly to go for 2 down by 8 last night. Here’s why I loved it: 1) NFL teams this season have been successful on 55% of two-point conversion attempts. The odds were in the Titans’ favor. 2) Will Levis was dealing in the 2nd half. 3) Titans still had all three timeouts and the two-minute warning. 4) Miami struggled to move the ball on offense all night. Their three scoring drives went for 12, 7, and 59 yards. 5) If successful on the two-point conversion, a stop on defense and a TD wins the game. If unsuccessful, you can still send it to OT. 6) Titans offense marched down the field, scored the TD to make it a one possession game and essentially told Miami, “we are going for two because we know you cannot stop us right now.” The odds are in your favor. It’s a good mathematical decision. You want to psych out an opposing offense? Give them the ball knowing they need to run the clock out, or you are going to have a chance to WIN the game, not send it to overtime. They saw what your offense just did to their defense. They saw your QB on the sideline screaming and hyping everyone up. Cutting the lead to six put WAY more pressure on the Dolphins offense. You want to hype up your defense? Put them back on the field knowing your offense just did their job. Put them back on the field knowing a stop and a TD wins it. At that point, they aren’t in the mindset of “we need a stop to have a chance to go to OT.” They are thinking, “let’s go out here, get a stop, and give our offense a chance to WIN.” There’s a fundamental difference in playing to WIN and playing NOT to LOSE. This was a decision by a coaching staff that was playing to WIN. Brilliant game by Vrabel and Kelly. Brilliant execution late in the game by the offense and the defense. Completely out-coached one of the best offensive minds in the game. #Titans

Jake!

36,853 просмотров • 2 лет назад

Guys will see this kind of thing and think it’s instruction, but they don’t read the fine print: 1️⃣ This girl is married yet still posting thirst traps online 2️⃣ She is clearly ADVERTISING herself for someone; someone who is NOT the husband (the husband already has her!) 3️⃣ Further, she is bragging about what she is able to get her husband to do and how easy she has it (i.e., he is way more invested in her than she is in him) Many men assume that, “The easier and more comfortable I make life for my woman, the more indebted to me she’ll be for all that comfort and ease, the more grateful she’ll be for how spoiled rotten I’ve made her, and the less motivation she’ll have than ever to look for other guys!” This assumption is based on one very WRONG misunderstanding of women, however: That what women really want is ‘stuff’. Material comforts. ‘Nice things’. It is easy for men to get this misunderstanding, because women will constantly tell you they DO want ‘stuff’. Just like how children will tell you they want stuff: • “I want this present!” • “Will you buy me that gift?” • “A new version of that came out! Can we get it?” But if you spoil a child rotten, that does not make the child ‘forever grateful’ to you. Likewise, spoiling a woman rotten does not make her forever grateful either. The harsh reality is a woman’s loyalty has NOTHING to do with how much or how little you spend on her. You can spend on her if you want to and if it makes you feel good. But you should treat it like charity; it is like giving alms to the poor. That is, it is not an action you should expect anything back from. You can spoil her rotten but still have her posting thirst traps online, showing herself off and advertising for other men. (In this chick’s other videos, she shows herself getting a nose job, and looking at the camera flirting and ignoring her man even when he is on camera next to her paying her attention. This husband is a placeholder.) Likewise, you can spend nothing on her at all yet have her be fiercely devoted to you. If you want a woman to actually be LOYAL to you: ✅ She needs to do things for YOU. She needs to work hard in the relationship. She needs to invest in it. She needs to be putting thought into how she is going to keep you satisfied. ✅ She needs to be getting it from you hard enough in the bedroom that she is so sexually sated she doesn’t even want to think about other men or feel any need to bother to act outwardly flirtatious in public to entice other men in. ✅ She needs to be at least a little more attentive to you than you are to her. There is no such thing as ‘true equality’ except in the imagined world of Platonic ideals. In reality, someone will always be working a little harder to gain the other’s attention. For an actual healthy relationship, the one working a little bit harder MUST BE the woman! Again: buy her stuff if you really want to. But, like spoiling a child rotten, don’t delude yourself thinking that, “If I keep her comfortable enough, she’ll be so happy and loyal!” There is ZERO relationship between “spending on her” and “keeping her in-love and loyal.” These two things are completely unrelated. Her devotion stems from her feeling invested in you, not the reverse.

Girls Chase 🏃‍♀️💨

37,276 просмотров • 8 месяцев назад

The Sabotaging Practice of Over Supply and Sameness in the NFT Space. The current zeitgeist of the NFT space is that the same artists are doing the same kind of work five times a year, with project after project leaving a trail of disappointment and discontent among collectors and all of us watching in disbelief as huge resources are extracted from the space over work that feels like it could be left as an "artist study." I understand that you can do what you want with your money as collectors, but we are killing the whole space with this incestuous practice. No artist is that prolific to be able to do 5 collections of 100+ pieces each every year and actually deliver innovation and some kind of creative evolution. Of course, they can pretend play that the work has something new, but there is no precedent nor proof that that has ever happened in the speed that it happens in the NFT space. Again, people are free to through away their resources on whatever they want but with this way of doing things, we more and more are going to start seeing the consequences. Oh! There are consequences? Yes. Maybe unintended, but there are. Let's see. Let's start with the loss of belief in the NFT space as somewhere where emerging artists can come and find support for their experiments. Why even bother to bring experiments, innovation, and new ways to think of art on the blockchain if the same people have all the collectors hypnotized with their magical flutes? Why even try to come to a space where taking risks and challenging the status quo (the mission of art!!!) is overlooked? This makes the NFT space a social club and not a space for art. I guess it is fine, but IMO it is a recipe for disaster. New collectors stay away because the art will slowly but surely become stale and un-challenging. Why even bother to come and see what is happening here if you can't, as a collector, see new weird and up-and-coming artists? The amount of noise emitted by the same artists doing the same art over and over, drowns out any new voices. Again. A recipe for disaster. The NFT space is becoming a space of disappointment and doubt. We think that collections going to zero one after the other, over and over, is not damaging? I feel we are kidding ourselves. Disappointment piles up, and again, the people who will hurt are the emerging artists, the new blood, the ones who are willing to risk the most and, in return, put fire in this cold space of sameness. I love this space—don't get me wrong—it has changed my life, and I believe it has a ton of potential, but things need to change for it to become a beacon of light in art. But we need to support new voices. We need to support new ideas. The challenge is huge. I hope to contribute all I can to this change. I hope more and more see how exciting it is to go out and try to discover what else is out there and move this space forward. But again, I understand the leaps of faith needed, but if there is a space that is based on that, it's the NFT space...so there is hope. We will see. 📺by Boldtron

alejandro cartagena

98,261 просмотров • 2 лет назад