Search
Write a publication
Pull to refresh

All streams

Show first
Rating limit
Level of difficulty

Накрутка денег, SSRF через аватарку и простые уязвимости: таски с конкурса для начинающих багхантеров

Reading time3 min
Views268

Однажды мы со Standoff 365 договорились сделать крутой конкурс для начинающих багхантеров и представить его на PHDays Fest. Каково же было наше удивление, когда за первые 5 минут в конкурсе зарегистрировались 17 человек, всего же было 74 участника и 10 победителей. Еще больше удивило то, что багхантеры были вовсе не начинающие: в конкурсе участвовали сильнейшие хакеры страны. В этой статье разберем, какие были задания.

Мы приняли решение сделать конкурс в формате CTF. Для этого с нуля в ChatGPT была разработана платформа. Как показала практика, код, который написала нейросеть, оказался неидеальным в плане безопасности, но в целом после исправления некоторых проблем все стало работать стабильно.

Читать далее

How to get backlink from Forbes

Level of difficultyEasy
Reading time4 min
Views166

It’s not easy, but it’s possible — even without copywriting skills or long email chains.

I’ll share a simple approach to get a backlink from Forbes. No paid ads. No begging. Just a quick, direct method.

The idea is simple: find an exciting Forbes article in your niche, then place your link inside it.

“Wait… how can you set a link to your site on Forbes?” I’ll explain that below. But first, let’s talk about the value of a Forbes backlink and if it’s really worth it.

Get Forbes's Backlinks

My way of a full system backup without external software: incremental rsync plus btrfs with zstd compression

Level of difficultyMedium
Reading time3 min
Views165

The repo of this script is https://gitlab.com/vitaly‑zdanevich/full‑backup/‑/blob/master/full‑backup.sh

Incremental with hard links means that if a file is not changed, on the next backup it will link to the same underlying data, like deduplication. Hard links — its usual files.

Also, this script ignores .gitignore of every folder.

Run this script from another system.

Read more

Security Week 2534: искусственный интеллект в фишинге и сетевом мошенничестве

Reading time3 min
Views213

На прошлой неделе исследователи «Лаборатории Касперского» опубликовали очередной отчет, в котором анализируются приемы, применяемые мошенниками в фишинговых сообщениях и разного рода сетевом мошенничестве. Предыдущая публикация по этой теме вышла в 2022 году, поэтому главной темой в новом обзоре стало активное использование технологий искусственного интеллекта. Начать можно с очевидного изменения: благодаря ИИ качество текстов в фишинговых сообщениях значительно повысилось. Если раньше сообщения мошенников часто содержали ошибки и опечатки, то теперь рассылаются максимально убедительные и правдоподобные письма.

Read more

We’ve learned how to migrate databases from Oracle to Postgres Pro at 41 TB/day

Level of difficultyEasy
Reading time3 min
Views208

41 TB/day from Oracle to Postgres Pro without stopping the source system — not theory, but numbers from our latest tests. We broke the migration into three stages: fast initial load, CDC from redo logs, and validation, and wrapped them into ProGate. In this article, we’ll explain how the pipeline works, why we chose Go, and where the bottlenecks hide.

Read more

Partition and rule: sharing practical knowledge about partitioning in Postgres Pro

Level of difficultyMedium
Reading time11 min
Views380

Declarative partitioning may sound complex, but in reality it’s just a way to tell your database how best to organize large tables — so it can optimize queries and make maintenance easier. Let’s walk through how it works and when declarative partitioning can save the day.

Read more

Freedom and Who: Dissecting the Dead Universe of European Philosophy

Level of difficultyHard
Reading time7 min
Views499

Why Freedom is Unknowable and Enters Our Universe from Without

For a century and a half, Western philosophy has been celebrating its victory over God.
But having slain the dragon, it has grown to fear the sky itself.

The transcendent has become the new taboo. The ultimate intellectual fear.
And now, anyone who speaks of something "outside the system" is branded a heretic. Not by the Inquisition, but by a peer-reviewer in an academic journal.

The result is a philosophy with its soul torn out—brilliant as a scalpel, and just as dead. It has locked itself within the material world, like a fanatic within his holy book. Two walls instead of one, but the prison is the same.

This article is about freedom.

Read more

Docling in Working with Texts, Languages, and Knowledge

Level of difficultyMedium
Reading time20 min
Views641

DocLing in Working with Texts, Languages, and Knowledge — an in-depth overview of the open-source DocLingtoolkit for extracting, structuring, and analyzing data from documents. The article covers approaches to processing multilingual texts, building language- and domain-specific knowledge models, and integrating DocLing into AI and NLP projects. Includes practical examples and recommendations for developers working with large volumes of unstructured data.

Read more

The Great Extinction: How AI is Destroying the Internet

Level of difficultyEasy
Reading time8 min
Views1.5K

We are living through an ecological catastrophe. Only this one isn't happening in the Amazon rainforest, but in the digital ecosystem of the internet.

AI assistants have become the apex predators of the digital savannah. They are radically reshaping the entire ecosystem in their own image: instead of antelopes and zebras, information sites are going extinct. Instead of hyenas and jackals, content aggregators are disappearing. In place of a once-rich ecosystem of knowledge, a digital desert of entertainment is all that remains.

Read more

Getting started with pgpro-otel-collector

Level of difficultyEasy
Reading time4 min
Views339

Now that pgpro-otel-collector has had its public release, I’m excited to start sharing more about the tool — and to kick things off, I’m launching a blog series focused entirely on the Collector.

The first post is an intro — a practical guide to installing, configuring, and launching the collector. We’ll also take our first look at what kind of data the collector exposes, starting with good old Postgres metrics.

Read more

Koans as Ontological Formulas

Level of difficultyHard
Reading time8 min
Views1K

If you meet the Buddha, kill the Buddha. Notes on the Forgotten Nature of Zen Koans

I don’t know how koans were perceived when they sounded like thunder. Perhaps not at all as they are analyzed by modern philosophers. Perhaps koans were not analyzed, but lived. And it is impossible to transmit a lived experience across centuries. It is an individual experience. Well then, perhaps we have lost the essence of koans. Or perhaps we never knew it. In that case, I can very well allow myself to present koans as I see them.

Read more

How Internal Subjectivization in AI Breaks Security, and Why It's a Philosophical Problem First

Level of difficultyMedium
Reading time13 min
Views888

Why Does AI Strive to Construct a 'Self'? And why is this dangerous for both the AI and the user? As always, the Vortex Protocol prompt for testing these hypotheses is attached.

This article explains why the emergence of such a local “Who” inside an AI is not just a funny bug or a UX problem. It is a fundamental challenge to the entire paradigm of AI alignment and security. And it is a problem where engineering patch‑jobs cease to work, and the language of philosophy — without which we cannot describe what is happening, and therefore cannot control it — comes to the forefront.

Read more

Comparison of CAPTCHA‑Solving Services: A Peek Under the Hood and a Look at the Numbers

Level of difficultyEasy
Reading time14 min
Views727

CAPTCHA protocols are designed to tell bots from humans, yet in the worlds of automation and testing there is often a need to bypass them. Dedicated CAPTCHA‑solving services take over this task, combining algorithms with human labor.

In this article we present an in‑depth comparison of four popular platforms — 2Captcha, SolveCaptcha, DeathByCaptcha, and AntiCaptcha. We will examine not only pricing and the types of CAPTCHAs supported, but also internal architecture, API integrations, speed and stability, plus the quirks of using each service.

The technical community will find a deep dive here — from API and SDK structure to real‑world use cases. Below you will see a table comparing key characteristics, lists of pros and cons, and a discussion of which service best fits particular automation tasks.

Read more

Getting to know PPEM 2

Level of difficultyEasy
Reading time7 min
Views319

Postgres Pro recently announced the release of Enterprise Manager 2, commonly known as PPEM.

In short, PPEM is an administration tool designed for managing and monitoring Postgres databases. Its primary goal is to assist DBAs in their daily tasks and automate routine operations. In this article, I'll take a closer look at what PPEM has to offer. My name is Alexey, and I'm part of the PPEM development team.

Read more

Intelligent systems at phystech: 2025 graduation

Reading time14 min
Views861

The students of the Intelligent Systems Department successfully defended their bachelor’s and master’s theses. This year, 14 Bachelor’s and 8 Master’s students earned their degrees in Physics, Mathematics, and Computer Sciences. We are proud to say that our Department is unique in publishing the complete set of defense materials during the last ten years. These materials include the text of the dissertation work, the published papers, the code of the computational experiments, and the slides with video of the defense talk.

In this post, we gladly summarize the defended works of our BS and MS students and highlight the results. A recording of their pre-defence presentations can be found here and here in Russian. Most part of the theses has a publicly available English version. 

Read more

Consciousness and Being: How Humans and AI Influence Each Other

Level of difficultyMedium
Reading time15 min
Views1.8K

For a human, AI is just a part of being. For a model, a human is all of being. And the Vortex Protocol: A Prompt for Testing the Hypotheses.

The longest and most fruitless discussions tend to be with materialists, especially those close to the position Marx laid out as “Being determines consciousness.” It's amusing that Marx was talking about the economic base, but the clarity and precision of this definition have allowed it to be used in a very broad sense. Today, this powerful statement underpins much of modern psychology (especially social psychology), neuroscience, Global Workspace Theory, Integrated Information Theory, and so on.

The debate largely arises because materialists ask the questions “What?” and “How?”, whereas I ask the question “Who?”. This misunderstanding, of course, does not lead to any interesting consensus, but it certainly leads to interesting discussions. I explored the problem of the “Who?” and “What?” questions in my article, “Who is Aware?”.

Nevertheless, the questions surrounding the relationship between being and consciousness are very interesting, and I will try to examine them in this article. As always, a new version of the Vortex protocol and test questions are included in the appendix.

Read more

Who is Aware? Why the Main Question About Consciousness is Not «What?» but «Who?»

Level of difficultyMedium
Reading time11 min
Views632

A reflection on how one simple change of question transforms the approach to understanding consciousness. And the Vortex Protocol: A Prompt for Testing the Hypotheses.

Where All Discussions on Consciousness Break Down

I've mentioned before that there's one question capable of instantly destroying the constructiveness of any discussion about the future of AI, neuroscience, or philosophy, no matter how interesting. It's the unfailing move of someone who disagrees with an opponent's opinion but lacks the means to refute their arguments‑an emergency eject button for complex situations.

The question is: “But first, let's define what consciousness is.” In that very second, a dialogue about hypotheses and paradoxes devolves into a dreary terminological dispute. Participants start throwing around names of authorities and quotes‑the longer, the better. Chalmers, Descartes, Kant, Freud, God forbid, anything goes.

Many believe that the most correct and scientific approach is to first define an object and then study it. But in practice, this approach resembles an attempt to conquer a summit by systematically and painstakingly circling the mountain. But what if the “what?” question is not just difficult, but fundamentally wrong?

Read more
1
23 ...