Footer

    Download on the App StoreGet it on Google Play

    About

    • About Us
    • Our Learning Services
    • Join Us
    • FAQ
    • Hot Tags

    Services

    • Pronunciation Challenge
    • Saved
    • Search Vocabulary
    • Blog

    Channels

    Levels

    • A1
    • A2
    • B1
    • B2
    • C1
    • C2

    Privacy˙Terms˙
    ©2026 VoiceTube Corporation. All rights reserved

    heuristic

    US /hjʊˈrɪstɪk/

    ・

    UK /hjuˈrɪstɪk/

    C1
    adj.AdjectiveAiding learning by experience or own discoveries
    She had a heuristic approach to her studies

    Video subtitles

    I'm 45. If you're in your 40s, watch this:

    18:46I'm 45. If you're in your 40s, watch this:
    • Number 35: a great heuristic in life is to always ask yourself if you will regret the decision that you are currently going to make.

      Number 35: a great heuristic in life is to always ask yourself if you will regret the decision that you are currently going to make.

    • A great heuristic in life is to always ask yourself if you will regret the decision that you are currently going to make.

      A great heuristic in life is to always ask yourself if you will regret the decision that you are currently going to make.

    A2

    Lec 1 | MIT 9.00SC Introduction to Psychology, Spring 2011

    49:44Lec 1 | MIT 9.00SC Introduction to Psychology, Spring 2011
    • But that's what we call a heuristic, a simple way to think about it, because your experience is kind of like that.

      But that's what we call a heuristic, a simple way to think about it, because your experience is kind of like that.

    • That's what we call a heuristic-- a simple way to

      That's what we call a heuristic-- a simple way to

    A2

    Let's Talk About Sister Krone

    15:51Let's Talk About Sister Krone
    • Offensiveness as a heuristic is overly focused on the individual impact, rather than the societal one.

      Offensiveness as a heuristic is overly focused on the individual impact, rather than the societal one.

    • Offensiveness as a heuristic is overly focused on the individual impact rather than the societal

      Offensiveness as a heuristic is overly focused on the individual impact rather than the societal

    B2

    How to Think Like Sherlock Holmes

    10:55How to Think Like Sherlock Holmes
    • That's called the availability heuristic.

      That's called the availability heuristic.

    • that's called the availability heuristic.

      that's called the availability heuristic.

    B1

    Let's Read Nietzsche's Beyond Good and Evil CC ASMR First Article

    58:31Let's Read Nietzsche's Beyond Good and Evil CC ASMR First Article
    • Thus we need sensualism at least as a regulative hypothesis if not as a heuristic principle.

      Thus we need sensualism at least as a regulative hypothesis if not as a heuristic principle.

    • Thus, we need sensualism at least as a regulative hypothesis, if not as a heuristic principle.

      Thus, we need sensualism at least as a regulative hypothesis, if not as a heuristic principle.

    B2

    Facts vs Fiction: What is Better for Learning?

    05:52Facts vs Fiction: What is Better for Learning?
    • Nonfiction provides our mind a theory, a heuristic and a framework that allows us to make assumptions and generalize.

      Nonfiction provides our mind a theory, a heuristic and a framework that allows us to make assumptions and generalize.

    • Nonfiction provides our mind a theory, a heuristic, and

      Nonfiction provides our mind a theory, a heuristic, and

    B1

    SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Ba…

    06:19SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Ba…
    • hello and welcome to the friday april 18th 2025 edition of the sands internet storm centers stormcast my name is johannes ulrich and today i'm recording from orlando florida today we got another guest diary by one of our undergraduate interns jacob clay camp did write about how to get started in malibu analysis of course we have plenty of diaries always about malibu analysis didier and xavier most notably are heavily contributing to this this is more the beginners view of malibu analysis and sort of how to get started with malibu analysis using a cloud-based system a couple interesting parts here first of all jacob is using aws a free instance and then uses chasm workspaces in order to essentially get a remote desktop into a container which then runs remnux this is lenny seltzer's reverse analysis environment all of this is linux-based and since it is set up in a container it's also easy to reset and the cloud deployment of course makes it nice and isolated from anything that you may have going on in your home network overall interesting setup and then jacob is going over a quick analysis of a red tail sample and how to apply this particular environment to the analysis of this particular matter interesting a write-up and nice step-by-step guide to help you get started and then we have a critical vulnerability affecting the erlang otp ssh library this affects any ssh servers written in this language the vulnerability was found by researchers at the ruhr university city in bochum now the otp here in erlang otp does not stand for one term one-time password instead it does stand for the open telecom platform this particular version of erlang was created and maintained initially by ericsson and is often used in telecom related devices routers and the like so certainly there is quite a number of affected devices out there the cbss score of the vulnerability is a perfect 10.0 because it does allow for arbitrary code execution without authentication the problem is that some ssh messages some ssh protocol messages can be sent and executed before authentication finishes due to this bug and that then leads to execution now the user this this code executes at depends on the user the ssh server is running at at the time it receives these messages definitely upgrade but of course since this is a vulnerability in the library used to create the ssh server you may have to wait for respective vendors to actually release updates here in the meantime the only alternative you have is to disable or firewall the ssh server and belgium security company inviso did release a report with details regarding some of their recent findings of the brickstorm backdoor brickstorm has been used in linux in in sort of vmware environments but now they also found a version of this backdoor on windows there are a couple interesting things to note here unlike most backdoors this backdoor actually does not have a remote code execution capability they say that typically rdp and such is used instead by the attacker and that they specifically didn't include a remote code execution capability to evade some heuristic and behavioral detection that you often find that would flag any code execution behavior instead this particular backdoor is able to read write files from the file system it also has some network components that would allow an attacker to essentially use an affected system as a pivot to scan other systems in the network so certainly a capable piece of malware also interesting as a command control channel they're using cloud flare workers and similar systems that again are less likely going to trigger alerts interesting report and it also includes some good indicators of compromise and the ways and techniques how you can actually find if you are affected by this particular backdoor and openai released its latest greatest model gpt 4.1 but this didn't happen amid some controversy around the security aspects here first of all this model was released without the usual safety reports or system cards which typically outline how this particular model was created to be safe meaning not for example allowing to create malware and apparently some of these safeguards that you often find in these models are missing from gpt 4.1 making it trivial to create malware with this model interesting problem here and not even sure if this will be something that the openai will fix in short notice but definitely we have seen malicious models of course before but not from major vendors like openai well that is it for today so thanks again for listening and thanks everybody who i met here i mean all of you listeners at the event here in orlando and well i'll talk to you again on monday bye

      hello and welcome to the friday april 18th 2025 edition of the sands internet storm centers stormcast my name is johannes ulrich and today i'm recording from orlando florida today we got another guest diary by one of our undergraduate interns jacob clay camp did write about how to get started in malibu analysis of course we have plenty of diaries always about malibu analysis didier and xavier most notably are heavily contributing to this this is more the beginners view of malibu analysis and sort of how to get started with malibu analysis using a cloud-based system a couple interesting parts here first of all jacob is using aws a free instance and then uses chasm workspaces in order to essentially get a remote desktop into a container which then runs remnux this is lenny seltzer's reverse analysis environment all of this is linux-based and since it is set up in a container it's also easy to reset and the cloud deployment of course makes it nice and isolated from anything that you may have going on in your home network overall interesting setup and then jacob is going over a quick analysis of a red tail sample and how to apply this particular environment to the analysis of this particular matter interesting a write-up and nice step-by-step guide to help you get started and then we have a critical vulnerability affecting the erlang otp ssh library this affects any ssh servers written in this language the vulnerability was found by researchers at the ruhr university city in bochum now the otp here in erlang otp does not stand for one term one-time password instead it does stand for the open telecom platform this particular version of erlang was created and maintained initially by ericsson and is often used in telecom related devices routers and the like so certainly there is quite a number of affected devices out there the cbss score of the vulnerability is a perfect 10.0 because it does allow for arbitrary code execution without authentication the problem is that some ssh messages some ssh protocol messages can be sent and executed before authentication finishes due to this bug and that then leads to execution now the user this this code executes at depends on the user the ssh server is running at at the time it receives these messages definitely upgrade but of course since this is a vulnerability in the library used to create the ssh server you may have to wait for respective vendors to actually release updates here in the meantime the only alternative you have is to disable or firewall the ssh server and belgium security company inviso did release a report with details regarding some of their recent findings of the brickstorm backdoor brickstorm has been used in linux in in sort of vmware environments but now they also found a version of this backdoor on windows there are a couple interesting things to note here unlike most backdoors this backdoor actually does not have a remote code execution capability they say that typically rdp and such is used instead by the attacker and that they specifically didn't include a remote code execution capability to evade some heuristic and behavioral detection that you often find that would flag any code execution behavior instead this particular backdoor is able to read write files from the file system it also has some network components that would allow an attacker to essentially use an affected system as a pivot to scan other systems in the network so certainly a capable piece of malware also interesting as a command control channel they're using cloud flare workers and similar systems that again are less likely going to trigger alerts interesting report and it also includes some good indicators of compromise and the ways and techniques how you can actually find if you are affected by this particular backdoor and openai released its latest greatest model gpt 4.1 but this didn't happen amid some controversy around the security aspects here first of all this model was released without the usual safety reports or system cards which typically outline how this particular model was created to be safe meaning not for example allowing to create malware and apparently some of these safeguards that you often find in these models are missing from gpt 4.1 making it trivial to create malware with this model interesting problem here and not even sure if this will be something that the openai will fix in short notice but definitely we have seen malicious models of course before but not from major vendors like openai well that is it for today so thanks again for listening and thanks everybody who i met here i mean all of you listeners at the event here in orlando and well i'll talk to you again on monday bye

    • They say that typically RDP and such is used instead by the attacker and that they specifically didn't include a remote code execution capability to evade some heuristic and behavioral detection that you often find that would flag any code execution behavior.

      They say that typically RDP and such is used instead by the attacker and that they specifically didn't include a remote code execution capability to evade some heuristic and behavioral detection that you often find that would flag any code execution behavior.

    B1

    Joseph Pine - 什麼是顧客真正想要的? (中英雙字幕)

    14:23Joseph Pine - 什麼是顧客真正想要的? (中英雙字幕)
    • And using the same heuristic, what happens when you customize a service?

      And using the same heuristic, what happens when you customize a service?

    • and use, in that same heuristic, what happens when you customize a service?

      and use, in that same heuristic, what happens when you customize a service?

    B1

    Stop Over-Explaining: The 3 S’s Rule For Projecting Authority

    19:47Stop Over-Explaining: The 3 S’s Rule For Projecting Authority
    • So confidence is actually a heuristic.

      So confidence is actually a heuristic.

    • So confidence is actually a heuristic.

      So confidence is actually a heuristic.

    B1

    The #1 Small Talk Rule That Makes People Like You (Stanford Communication Professor)

    46:10The #1 Small Talk Rule That Makes People Like You (Stanford Communication Professor)
    • But had I really listened and observed in that moment and not immediately jumped into that heuristic of feedback, I would have noticed he was looking down.

      But had I really listened and observed in that moment and not immediately jumped into that heuristic of feedback, I would have noticed he was looking down.

    • But had I really listened and observed in that moment and not immediately jumped into that heuristic of feedback, I would have noticed he was looking down.

      But had I really listened and observed in that moment and not immediately jumped into that heuristic of feedback, I would have noticed he was looking down.

    A2