Correct, you can use JSON hijacking in XXS (Cross-Site Scripting) the same way you can infect websites. If the hacker is using a zero-day threat (not yet known, and therefore less chance for a classic "anti-virus" software to detect it), it can do much harm, just by a simple line of code.Teksonik wrote: Sun Mar 14, 2021 3:22 pm"JSON files may contain malicious code......Most programs by default analyze JSON files for malicious code".garryO wrote: Sat Mar 13, 2021 4:29 pm as said before vital skin files are .json and you can open them with a texteditor.
they should look like this: {"Background":"ff1b1a1e","Body":"ff2f2e33","Body Heading Background":"ff232226",...don´t think it´s possible to hide malicious code in there.
https://jsonfile.org/
Skins you're most impressed by
- KVRAF
- 2747 posts since 28 Feb, 2015
Mac Mini M4 Pro | 14 Cores (10P/4E) | 48GB RAM | Studio One | Reason | Bitwig Studio | Logic Pro | FL Studio | Cubase Pro | Waveform | Reaper | Renoise | ~1000 VSTs/AUs | ~350 REs
-
- KVRAF
- 12086 posts since 2 Dec, 2004 from North Wales
I really like that, is it available anywhere?AnX wrote: Tue Mar 09, 2021 6:50 am my default edit (crappy screen grab) because I hate when the knobs are the same colour as the background
X32 and 24C mixers, S88MK3, Live + PUSH 3, Osmose, RedShift 6, Pro3, S4, Tempera, Syntakt, Digitone, OP1-F, OPXY, TR-1000, Eurorack, TD27 Drums, Guitars, Basses, Amps and of course lots of pedals!
-
- KVRist
- 87 posts since 14 Sep, 2020
if a .json file look like this:starflakeprj wrote: Sun Mar 14, 2021 4:04 pmCorrect, you can use JSON hijacking in XXS (Cross-Site Scripting) the same way you can infect websites. If the hacker is using a zero-day threat (not yet known, and therefore less chance for a classic "anti-virus" software to detect it), it can do much harm, just by a simple line of code.Teksonik wrote: Sun Mar 14, 2021 3:22 pm"JSON files may contain malicious code......Most programs by default analyze JSON files for malicious code".garryO wrote: Sat Mar 13, 2021 4:29 pm as said before vital skin files are .json and you can open them with a texteditor.
they should look like this: {"Background":"ff1b1a1e","Body":"ff2f2e33","Body Heading Background":"ff232226",...don´t think it´s possible to hide malicious code in there.
https://jsonfile.org/
{"Background":"ff1b1a1e","Body":"ff2f2e33","Body Heading Background":"ff232226"}
everything is human readable easily.
can someone hide code here?
- KVRAF
- 19803 posts since 16 Sep, 2001 from Las Vegas,USA
Because malicious code is just text. Are you going to examine every vital skin file to see if every line of text is safe ?
No of course not, no one is going to do that. I'm not saying that vital skin files are infected I'm simply saying that they can be infected since they are .json files.
If you're concerned just run the files through VirusTotal.
No of course not, no one is going to do that. I'm not saying that vital skin files are infected I'm simply saying that they can be infected since they are .json files.
If you're concerned just run the files through VirusTotal.
None are so hopelessly enslaved as those who falsely believe they are free. Johann Wolfgang von Goethe
- Banned
- 10729 posts since 17 Nov, 2015
yeah, i could upload it. Just need to remove any parts that I haven't edited (just to be safe about redistribution)
afaik, when loading a skin, any parts missing will automatically be drawn from default skin.
note, this is default size only, no other sizes (and I have no intention of making any)
- Banned
- 7624 posts since 13 Nov, 2015 from Norway
- KVRian
- 591 posts since 1 Jan, 2021
-
- KVRAF
- 2685 posts since 14 Jul, 2005 from Australia
I'm afraid that this is just an image I pulled off Google, sorrymiddle_color wrote: Mon Mar 01, 2021 2:04 pmDo you have this colors palette? Default one is too bright.fgimian wrote: Sat Feb 27, 2021 12:20 pm As far as DAWs, I still feel that Cubase is the prettiest by far, but that's just me
![]()
-
- KVRAF
- 2685 posts since 14 Jul, 2005 from Australia
I think Replika XT looks great, but as someone who is colourblind, I absolutely hate the red on black; I can't see it at all. I literally have to use a color filter on Windows when using anything that has red on black, including Replika XT.
So for that reason alone, I'd have to say that I really dislike the colour choices on otherwise nice skin. I reported this to NI too, but sadly, it remains unchanged.
To all designers, red on black is an awful AWFUL choice if you care about anyone that has difficulty with colourblindness. I see it everywhere and it drives me nuts.
-
- KVRian
- 924 posts since 24 Sep, 2016
SoundCloud
"I believe every music producer inherently has something unique about the way they make music. They just have to identify what makes them different, and develop it" - Max Martin
"I believe every music producer inherently has something unique about the way they make music. They just have to identify what makes them different, and develop it" - Max Martin
- KVRAF
- 5641 posts since 15 Dec, 2011
Feels good in Serum's skin...
You do not have the required permissions to view the files attached to this post.
- KVRAF
- 5641 posts since 15 Dec, 2011



