• 0 Posts
  • 57 Comments
Joined 1 year ago
cake
Cake day: August 24th, 2023

help-circle






  • Maybe I’ve misunderstood how it works. I thought that when connecting to a matrix instance you would point to the domain name and the text file would be on a standard location (as with /robots.txt or all the files in /.well-known/) so it would be easily discoverable. In fact I just checked and matrix does use /.well-known/ so one should be able to identify matrix servers by querying these URLs. Unless their is a way to use a non-standard location, but that would require further configuration on the client I guess.

    And just to answer your question, the only way to find some hidden file would be to brute force. This could obviously be extremely time consuming if the URL is long and random enough, especially if you add rate limiting (this last thing could be circumvented by using multiple IPs to scan, which would be easy for a state actor).

    Edit: I’ve just realized I wasn’t answering to the same person, the first part of the message was more for @TarantulaFudge@startrek.website














  • That’s weird, something is definitely wrong. Are they set up in a similar way? The first thing that comes to my mind is: Are you using the same DNS server on both? Differences in DNS response time should be more noticeable than rendering time on most hardware. And I think Firefox doesn’t use the system DNS by default but I might be wrong. Do you mind checking? I’m curious now.