豆瓣 douban.com
1.28K subscribers
178K photos
36.3K videos
6.81K files
166K links
豆瓣最受欢迎的书评 豆瓣最受欢迎的影评 豆瓣最受欢迎的乐评
豆瓣网 WikiHow Skills Quora Books Movies Music
豆瓣 @doubancom
知乎 @zhihubaidu
微信 @weixinCN
谣言 @TruthRumors
微博 @weibonews
Download Telegram
第一集我非常满意 (评论: 绿灯军团)

Andy评论: 绿灯军团

评价: 力荐

via 豆瓣最受欢迎的影评 (author: Andy)
看了《牛来》结尾差点哭了。怎么回事谁能解释一下????? (评论: 牛来)

赵四评论: 牛来

评价:

via 豆瓣最受欢迎的影评 (author: 赵四)
永远年轻的梦想 (评论: 唐朝)

昔情难追评论: 唐朝

评价: 力荐

via 豆瓣最受欢迎的乐评 (author: 昔情难追)
不困世俗窠臼,做自己天地的掌舵人 所谓野生,不是桀骜乖张,是守住自我,把人生选择权握在自己手中。 (评论: 野生姑娘)

豆友17Q67r-4r4评论: 野生姑娘

评价: 还行

via 豆瓣最受欢迎的乐评 (author: 豆友17Q67r-4r4)
《龙餐馆》离杰作似乎还有挺远的距离 (评论: 欢迎来龙餐馆)

Baby Pluto评论: 欢迎来龙餐馆

评价: 还行

via 豆瓣最受欢迎的影评 (author: Baby Pluto)
集体暴力之下,谁该为暴民的罪行买单? (评论: 狂怒)

读读悟悟评论: 狂怒

评价: 力荐

via 豆瓣最受欢迎的影评 (author: 读读悟悟)
FIRST获奖!她把身上的痣拍成了一部家庭史诗 (评论: 一颗痣的自白)

抛开书本评论: 一颗痣的自白

评价: 力荐

via 豆瓣最受欢迎的影评 (author: 抛开书本)
真正的现代的人文主义的奥德赛之旅 (评论: 欢迎来龙餐馆)

辞水评论: 欢迎来龙餐馆

评价: 力荐

via 豆瓣最受欢迎的影评 (author: 辞水)
夜色温柔:表现主义为什么不再流行了 (评论: 卡里加里博士的小屋)

抛开书本评论: 卡里加里博士的小屋

评价:

via 豆瓣最受欢迎的影评 (author: 抛开书本)
重温影史杰作,未祛魅的个人反抗史 (评论: 铁皮鼓)

抛开书本评论: 铁皮鼓

评价: 推荐

via 豆瓣最受欢迎的影评 (author: 抛开书本)
当抽象沦为一场集体行为艺术狂欢——“烂”片真的无意义吗? (评论: 牛来)

从前峰评论: 牛来

评价: 较差

via 豆瓣最受欢迎的影评 (author: 从前峰)
Mary isn't emotionally well (评论: Forever Howlong)

有缺评论: Forever Howlong

评价: 推荐

via 豆瓣最受欢迎的乐评 (author: 有缺)
Sputnik‑star: 专辑封面背后的金属星故事 (评论: Automatic for the People)

都挺好评论: Automatic for the People

评价:

via 豆瓣最受欢迎的乐评 (author: 都挺好)
一颗不肯媚俗的心是非常难得的 (评论: 一颗不肯媚俗的心)

豆友17Q67r-4r4评论: 一颗不肯媚俗的心

评价: 力荐

via 豆瓣最受欢迎的乐评 (author: 豆友17Q67r-4r4)
年度华语最佳 (评论: 欢迎来龙餐馆)

萌之蚩蚩评论: 欢迎来龙餐馆

评价: 力荐

via 豆瓣最受欢迎的影评 (author: 萌之蚩蚩)
专辑:Ingrid Chavez —《May 19,1992》和Prince完整关系 (评论: May,19,1992)

孙同學评论: May,19,1992

评价: 推荐

via 豆瓣最受欢迎的乐评 (author: 孙同學)
GitHub Is Down

If you're trying (and failing) to access GitHub Monday morning, you aren't alone. According to Downdetector, the hosting provider has over 3,000 user reports indicating issues or downtime with the service. Whether you're a developer trying to update your repository, or you're a user trying to access one, GitHub may give you trouble.

If the comments on Downdetector are any indication, this is not the first time GitHub has had service issues. One comment reads: "Cmon [GitHub] get your sh*t together...this is getting old." (The user added their own asterisks.) Scrolling through the comment history, users reported errors one or twice a week throughout August. I'm not a regular GitHub user, so I can't attest personally to repeated downtimes, but it does seem as though this isn't wholly unusual.

As such, even though it isn't clear why GitHub is down right now, chances are good that the company will get the site up and running shortly. Assuming nothing catastrophic is happening behind the scenes, developers and users alike should be able to access the site sometime today. But I will continue to update this piece if GitHub's downtime extends longer than normal.

via Lifehacker (author: Jake Peterson)
This Malware Can Take Over Web Browsers on macOS, but You Can Protect Yourself

In a new ClickFix attack iteration, hackers are pushing an infostealing malware to macOS users that is capable of hijacking your sessions in Google Chrome, Microsoft Edge, and a number of other Chromium-based browsers. AmnesiaStealer grants remote control of your browser and access to plenty of personal data, so you should know how to spot the campaign and protect your device from compromise.

AmnesiaStealer hijacks your web browser on macOS

As BleepingComputer reports, AmnesiaStealer can copy a victim's Chromium profile, which allows it to collect data across 16 Chromium-based web browsers, access authenticated sessions, and control them remotely. This means threat actors can navigate across websites, export or import cookies, and access online portals as well as grab saved logins, history, bookmarks, extensions, and cryptocurrency wallet data. AmnesiaStealer can also capture your macOS password and gain access to keychain data, Apple Notes, Telegram sessions, documents, and system information.

Researchers at security company Jamf found that hackers are distributing the malware via a password-protected ZIP archive on a fake GitHub page and are gaining this level of access when users run a Terminal command that downloads and installs the payload. The campaign mirrors previously identified Atomic and MacSync infostealers.

How to avoid browser takeover attempts

The best way to protect yourself from AmnesiaStealer is to be vigilant against ClickFix attacks, which use social engineering tactics to deliver malware to your device. Common tricks include fake error messages, CAPTCHA forms, and, as in this case, command prompts that install malicious payloads that can then spy on your activity, steal your data, and take over your machine.

Threat actors count on you believing that these commands do something innocuous (like download legitimate software) or not understanding what you're executing on your device. That's why you should be highly skeptical of any prompts you find online and never execute commands in Terminal from non-official sources. Note that the fake GitHub page being used to distribute AmnesiaStealer has a "Verified Publisher" tag to gain user trust. Fraudsters will also try to impersonate legitimate companies—tech support scams are one example—so you should never copy and paste commands in your system dialogue even if you believe you're interacting with a trusted business or service.

via Lifehacker (author: Emily Long)