• 9 Posts
  • 253 Comments
Joined 2 years ago
cake
Cake day: August 15th, 2023

help-circle
















  • Thanks for the suggestions. Here is what I’m probably gonna do:

    • Upgrade BitWarden to premium
    • move my TOTP codes into there
    • Get a Yubikey for 2FA for it
    • Keep a second 2FA TOTP option available in case I lose the key

    Then all I’ll need to do is reinstall it, and log in with the master password and key and be good for any of my sites.





  • Yea good thing you didn’t. MSHTA is the app that lets you run Microsoft HTML Apps (usually used for their help articles). Those can contain JavaScript or VBScript code. And since you’re pasting it in a Run box it’ll happily execute it, even if it’s a remote source.

    Generally it would only run as your user (you’re not admin are you?), which would still be enough to make your life miserable, but it could also try to run known exploits and raise itself to admin and own your whole computer.