In what ways can malicious sites harm me if I don't download anything or input any details?

This page summarizes the projects mentioned and recommended in the original post on /r/AskNetsec

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • sonar.js

    A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and external resource fingerprinting.

  • Abuse a CSRF vulnerability on another site. If commenting on reddit is vulnerable to CSRF, and you visit my malicious website, then I could make you make reddit comments without your knowledge. There's a lot of interesting attacks that can be done with this in mind - maybe even fingerprinting your internal network.

  • Responder

    Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

  • I am pretty sure that there's a way to make an attack work with Responder and stealing network credential components via a webdav server. There's probably a few attacks that are specific to being on the same domain or LAN that we could come up with, but your scenario made it sound more like you were interested in a public website vs an arbitrary user visiting.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Regular Expression Matching Can Be Simple and Fast (2007)

    1 project | news.ycombinator.com | 21 May 2024
  • Python requests 2.32.0 (2024-05-20) breaks Docker-py

    1 project | news.ycombinator.com | 21 May 2024
  • Lamucal.ai: Vocal Remover, Real-Time chords and lyrics for music

    1 project | news.ycombinator.com | 21 May 2024
  • Local/LAN Tibber Pulse/Bridge Integration

    1 project | news.ycombinator.com | 21 May 2024
  • How to generate AI images in ChatGPT-3.5 (free)

    1 project | dev.to | 21 May 2024