tungwaiyip.info

 

home

about me

links

my software

Media

Yucatán Photos

St Lucia Photos

Photo Album

Videos

Blog

< July 2004 >
SuMoTuWeThFrSa
     1 2 3
4 5 6 7 8 910
11121314151617
18192021222324
25262728293031

past articles »

Click for San Francisco, California Forecast

San Francisco, USA

 

Checking for Cross-Site Scripting Vulnerability

Netcraft.com brings my attention to cross-site scripting security problem. I have examined this website for vulnerabilities. This problem is usually caused by systems not checking input received from user or third party before using it. One place this website receives input is the RSS new feeds. I have crafted a test RSS with embedded javascript. Some RSS feeder (including this website) display the content as is. They should have (arguably) strip off the embedded script before displaying it. I promptly plugged this by escaping the meta characters before outputting them on the web pages.

An important element for cross-site scripting is that a third party can use a reputable website as a conduit to inject questionable code in their context. In this case the news feeder's communication is only between this website and the news source. I am not aware of any loop hole for third party to get involved. But in the world of open communication it is better to be safe to test for all input before use.

2004.07.20 [, ] - comments (0)

 

Sobig Revealed

This August has seen two massive virus attack, with the MSBlaster followed by Sobig. Sobig is believed to have a motive other than causing damages. It creates a large number of compromised computers, which is ideal resources for email spammers to relay spams. LURHQ has analysed the virus in a series of articles, from the first Sobig.a to Sobig.e to the now well known Sobig.f. It describe how Sobig transforms itself from an email attachment to a trojan proxy server using a sophisticated multi-staged technique to elude effort to block it. Evidently spammers is associated with high-tech crime network profiting from computer vulnerability.

2003.08.29 [] - comments (0)

 

past articles »

 

BBC News

 

Labour MPs call for hacking probe (06 Sep 2010)

 

Bipolar 'not linked to violence' (06 Sep 2010)

 

Housing group 'near administration' (07 Sep 2010)

 

MPs back AV referendum bill (06 Sep 2010)

 

Tube workers begin 24-hour strike (06 Sep 2010)

 

Scam fear over electricity credit (06 Sep 2010)

 

Iran 'hampers IAEA investigation' (06 Sep 2010)

 

Obama unveils building plan (06 Sep 2010)

 

France faces pension plan strike (06 Sep 2010)

 

MoD names two killed UK soldiers (06 Sep 2010)

more »

 

Slashdot News for nerds, stuff that matters

 

Google Says Microsoft Is Driving Antitrust Review (2010-09-07T00:20:00Z)

 

Aging Star System Leaves Strange Death Spiral (2010-09-06T23:25:00Z)

 

American Business Embraces 'Gamification' (2010-09-06T22:36:00Z)

 

Plagiarizing a Takedown Notice (2010-09-06T21:40:00Z)

 

Sony Has Lost the PS3 Hacking War (2010-09-06T20:53:00Z)

 

UK's Royal Mail Launches First Intelligent Stamps (2010-09-06T20:01:00Z)

 

WikiLeaks Calls For Assange To Step Down (2010-09-06T19:10:00Z)

 

Programming Things I Wish I Knew Earlier (2010-09-06T18:14:00Z)

more »

 

TechPsychic Tech Rumors and Invented News

 

TechPsychic: AT&T: more money, says it's disruptive in funding from. (08 May 2010)

 

TechPsychic: I know that Apple is close to Apple Dominates, Hires ex-Googler - Yes, Android phones. (08 May 2010)

 

TechPsychic: AT&T says: Facebook Connect. (08 May 2010)

 

TechPsychic: Google's Nexus One of Google Chrome Release Adds Support subscriptions accounted for Amazon: Apple. (08 May 2010)

 

TechPsychic: Another stat: Twitter's Design of this is giving rise of BlackBerry Foursquare Map App store end. (07 May 2010)

 

TechPsychic: Like educational sales Up around Apple iPad makes money Plan costs half an Apple. (07 May 2010)

 

TechPsychic: Instead added extensions, social Networks than double, everyone jumps in Silicon Valley? (07 May 2010)

 

TechPsychic: So why iTunes App lets Social Networks Verizon Wireless Internet. (07 May 2010)

more »

 

SF Gate

 

Lawyer says Iranian woman could be stoned soon (2010-09-06T19:54:30UTC)

 

No body found in Pittsburg dump after 3 days (2010-09-06T07:42:40UTC)

 

Tight California races head into final frenzy (2010-09-06T12:39:06UTC)

 

Economy blamed for drop in births (2010-09-06T13:37:54UTC)

 

Obama assails GOP, promotes new jobs program (2010-09-06T20:26:24UTC)

 

US won't say if blowout preventer on way to shore (2010-09-06T20:25:23UTC)

 

Foster City's Hillbarn Theatre gets bell back (2010-09-06T17:38:14UTC)

 

Hassle in Haight over McDonald's menu change (2010-09-06T14:38:38UTC)

 

Air Products boosts Airgas acquisition offer (2010-09-06T21:33:46UTC)

 

UK regulators want Avandia diabetes pill pulled (2010-09-06T21:11:46UTC)

 

Revis returns to Jets after agreeing to deal (2010-09-06T21:10:44UTC)

 

Obama assails GOP, promotes new jobs program (2010-09-06T20:57:31UTC)

 

Matusz wins 4th straight, leads O's over Yanks 4-3 (2010-09-06T20:54:32UTC)

 

Presented By: (06 Sep 2010)

more »

 

Asia Times Online

 

Taiwan in a rice wine stew (3 Sep 2010)

 

Inspectors miss the flight to Kyrgyzstan (3 Sep 2010)

 

LIFE IN TALIBANISTAN : Married to the mob (3 Sep 2010)

 

Old Korea hand points new finger of blame (3 Sep 2010)

 

New case for US reparations in Laos (3 Sep 2010)

 

BOOK REVIEW : Al-Qaeda and counter-terrorism (3 Sep 2010)

 

Deripaska on US mission (3 Sep 2010)

 

IMF stumps up Pakistan aid (3 Sep 2010)

 

MARKET RAP : Confused - but forward (3 Sep 2010)

 

IT WORLD : Delhi targets Google, Skype (3 Sep 2010)

 

THE MOGAMBO GURU : Bernanke blows his cover (3 Sep 2010)

more »

 


Site feed Updated: 2010-Sep-06 19:00