frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Dssrf – A safe‑by‑construction SSRF defense library for Node.js

2•relunsec•2h ago
I built dssrf, a safe-by-construction SSRF defense library for Node.js apps.

Most existing SSRF libraries rely on blacklists or regex checks, which are easy to bypass. dssrf takes a different approach based on normalization, DNS resolution, redirect validation, and IP classification.

Key features: – URL normalization RFC compliant – DNS resolution + IP classification – Redirect chain validation – IPv4/IPv6 safety – Rebinding detection – Protocol restrictions – TypeScript types included

The goal is to eliminate entire classes of classic SSRF vulnerability and it bypasses rather than patching individual payloads.

GitHub: https://github.com/HackingRepo/dssrf-js npm: https://www.npmjs.com/package/dssrf

I love feedback, edge cases, and contributions from the community.

Show HN: tomcp.org – Turn any URL into an MCP server

https://github.com/Ami3466/tomcp
8•ami3466•48m ago•2 comments

Show HN: Tripwire: A new anti evil maid defense

https://github.com/fr33-sh/Tripwire
54•DoctorFreeman•1d ago•31 comments

Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

26•sanketsaurav•20h ago•8 comments

Show HN: Euporie-lite, Jupyter notebooks in terminal in the browser

https://euporie.readthedocs.io/en/latest/_static/lite.html
2•joouha•58m ago•1 comments

Show HN: Dbxlite – Query 100M+ rows in a browser tab, no install

https://sql.dbxlite.com/?share=gist:f0377982ccd68ac7f61a7faef8ff513e&run=true
2•hfmsio•1h ago•0 comments

Show HN: A zero-to-hero, spaced-repetition guide to WebGL2 and GLSL

https://github.com/GregStanton/webgl2-glsl-primer
2•HigherMathHelp•1h ago•1 comments

Show HN: AI system 60x faster than ChatGPT – built by combat vet with no degree

4•thebrokenway•1h ago•2 comments

Show HN: Sim – Apache-2.0 n8n alternative

https://github.com/simstudioai/sim
222•waleedlatif1•1d ago•55 comments

Show HN: Epstein's emails reconstructed in a message-style UI (OCR and LLMs)

https://github.com/Toon-nooT/epsteins-phone-reconstructed
30•toon-noot•5h ago•2 comments

Show HN: Jottings; Anti-social microblog for your thoughts

https://jottings.me/
18•vishalvshekkar•9h ago•11 comments

Show HN: Local Privacy Firewall-blocks PII and secrets before ChatGPT sees them

https://github.com/privacyshield-ai/privacy-firewall
103•arnabkarsarkar•3d ago•52 comments

Show HN: Open-source, offline voice typing and live captions for Android

https://github.com/notune/android_transcribe_app
3•leumon•4h ago•0 comments

Show HN: 360css CSS library inspired by the xbox360 dashboard

https://tarmo1.github.io/360css/
3•Tarmo362•5h ago•0 comments

Show HN: Dssrf – A safe‑by‑construction SSRF defense library for Node.js

2•relunsec•2h ago•0 comments

Show HN: Marmot v2.20 – A distributed SQLite server with MySQL wire compatbility

https://github.com/maxpert/marmot/releases/tag/v2.2.0
4•maxpert•2h ago•0 comments

Show HN: Workmux – Parallel development in tmux with Git worktrees

https://github.com/raine/workmux
4•rane•6h ago•0 comments

Show HN: Wirebrowser – A JavaScript debugger with breakpoint-driven heap search

https://github.com/fcavallarin/wirebrowser
64•fcavallarin•2d ago•15 comments

Show HN: A minimum viable Markov gibberish generator in 32 lines of Python

https://github.com/susam/mvs
3•susam•7h ago•0 comments

Show HN: GPULlama3.java Llama Compilied to PTX/OpenCL Now Integrated in Quarkus

22•mikepapadim•1d ago•5 comments

Show HN: An endless scrolling word search game

https://endless-wordsearch.com
23•marcusdev•1d ago•13 comments

Show HN: Gotui – a modern Go terminal dashboard library

https://github.com/metaspartan/gotui
38•carsenk•20h ago•13 comments

Show HN: Gemini Pro 3 imagines the HN front page 10 years from now

https://dosaygo-studio.github.io/hn-front-page-2035/news
3314•keepamovin•3d ago•957 comments

Show HN: A 2-row, 16-key keyboard designed for smartphones

https://k-keyboard.com/Why-QWERTY-mini
79•QWERTYmini•2d ago•67 comments

Show HN: Automated license plate reader coverage in the USA

https://alpranalysis.com
236•sodality2•2d ago•143 comments

Show HN: AlgoDrill – Interactive drills to stop forgetting LeetCode patterns

https://algodrill.io
177•henwfan•3d ago•105 comments

Show HN: I built a system for active note-taking in regular meetings like 1-1s

https://withdocket.com
173•davnicwil•3d ago•130 comments

Show HN: I want to democratise Bloomberg Terminal

https://www.aulico.com/workspaces/new
2•lalalerodas•14h ago•1 comments

Show HN: Search the lyrics of 500 HÖR Berlin techno sets

https://hor.greg.technology/
2•gregsadetsky•15h ago•2 comments

Show HN: The world's least deterministic programming language

https://github.com/andr3wV/VibeScript
4•andr3wV•15h ago•0 comments

Show HN: Forecaster Arena – Testing LLMs on real events with prediction markets

https://forecasterarena.com/
3•setrf•17h ago•0 comments