|
|
![]() *Updated 8:29pm hacksden.com has been hacked and finalize 10 out of 10 domains as said by Contra located on Twitter @ContraHax out of Stockholm, Sweden. Seems as though some sys admins and web developers are going to have some work to do in the morning. Seems as though SEO.com and numerous other websites were was hacked recently by a hacker group calling themselves Contra. I found this out looking for a SEO company that my full time job uses. So sure enough I type in SEO company into Google, and what do you know...SEO.com... According to their Twitter account they are located out of Stockholm, Sweden and have gone on a hacking rampage possibly finding a flaw in a CMS or vulerability in PHP, current details are unknown. Some of those hacked websites by Contra include: 1. PrisonOfficer.com 2. SEO.com 3. Leetcoders.org 4. xscriptz.com 5. future-hackes.com 6. seoelite.com 7. codehacks.org 8. globalsecurity.org 9. patriotcouncil.com 10. hacksden.com The add on the hacked website a video of Dance Floor Dale, and leave a message: From Sweden with <3, along with a link to their Twitter Account. Seems as though the internet is on a hacking frenzy. Here is a .FLV of a video that they have posted. External Links 1. Dance Floor Dale Disclaimer: I would like to make every one aware that I am in no way affiliated directly, or in directly with any hacking groups. I am a small time blogger that posts technology related news, nothing more, nothing less. |
|
|
![]() Yes I was totally geeked to see a Google Car in San Antonio Texas! I was one of the lucky ones to see the Goog Car during my lunch hour. Yeah, sure everyone seems to see them going up and down all over the country, but to see and know what it is pretty damn cool. This afternoon I took at late lunch, probably around the hours of 2:30pm to 3:00pm or so when a co-worker and I noticed something funny pass us up as we were in a Bill Millers drive through. I made the assumption immediately that it was a Google car, and laughed, and he said yeah it is! Doing my best to catch up and making some abrasive maneuvers, I finally was able to pull up right behind the Googler in the Google Car. My location was at Wurzbach Pkwy and Perrin Beitel here in San Antonio, Tx. My co-pilot (no longer my co-worker) took some video footage on my iPod Touch, and the video below is what we have. I made a few edits, not many...and removed our audio, and replaced with with Party Ben's Mashup - Every Car You Chase. I felt the music was only appropriate, being we were chasing it down. Did you know: 1. The Google Street Car can driven by it's self. 2. The Google Street Car is monitored (driven) by an engineer. 3. The Google Street Cars are usually Toyota Prius hybrids and an Audi TT's. 4. The Google Street Car has multiple video cameras, radar and laser technology. 5. Google has developed a Google Trike for Parks and Trails. 6. Google has also developed a Street View Snowmobile that was used in the 2010 Winter Olympics. 7. Google has even developed a Street View Trolley used to examine museums. External Links: 1. Location at Wurzbach Pkwy and Perrin Beitel Road 2. Autonomously Driving Google Car by Robert Scoble 3. Google's Driverless Car: The Next Alternative Vehicle? Does any one else have any footage they would like to share, or any cool experiences? |
|
|
|
For years now I have participated in many coding Forums. Perhaps one of the biggest issues I see is people using $_GET or another unfiltered variable inside of an include, include_once, require or require_once statement. This is a major security risk, and in an attempt to help people stray away from this I have accumulated many different ways this can be done, "properly" (I quote properly because each person has their own preference). Let's get down to the nitty gritty, and see how we can do inclusions in PHP securely without opening ourselves up to being exploited through a remote file inclusion exploit. First Things First Most PHP hosts set the allow_url_fopen to be off by default, in an effort to help prevent these exploits. However, not every host does this, and not everyone uses a shared host. If you are on a VPS or Dedicated server, then you may inadvertently enabled this setting or never disabled it. So first things first, go and find your proper php.ini file, and turn this off. If you relied on fopen of remote files or file_get_contents, I would highly suggest switching over to CURL, as it will be much quicker, and allow for security in the event you did not code all the code on your site or using a mainstream item, like WordPress, where it may contain a vulnerability that anyone could see. Implementing a White List A common exploitable code that I have seen is basically something in the form of: include($_GET['page']); If your host has allow_url_fopen enabled, you are just asking to be exploited with a remote file inclusion exploit. Basically, anyone could type in something like: http;//www.yoursite.com/page.php?page=http;//theirsite.com/remote/code/to/execute.php and viola, their code remotely executed and basically just opened up your site fully to them. As you can see, this is a huge issue, and is how a lot of malware and virus's get passed around. Implementing a white list will probably be close to one of the sure fire ways this will never happen. The array can come from a number of sources you want it to, hard coded in the file, from a database setting etc. I am just going to write it in line for simplicity reasons. $whiteList = array('index' => 'index.php', 'about' => 'about.php', 'contact' => 'contact.php');As you can see, everything is hard coded, and there is no way for someone to inject their own URL into your site. This would prevent any type of remote file inclusion exploit from being able to be preformed. If you wanted more "security" you could change the names of the files to be something obscured, or include them from a different directory outside of the webroot, so that no one would access them directly. This is generally my preferred method, simply because there is a slim to none chance that you would get remotely exploited. Using Basename and file_exists Another method is using the basename and file_exists method. This method I find a bit less secure, given that they can include any file as long as it exists and in the current directory. What the basename does is remove everything but the name of the file. This prevents someone from entering in something like ../../somefile and having that file included, so if your permissions were not setup properly, it could give them access to various stuff, like SSH Keys, logs and other files that you do not want out in the open. The file_exists, make sure that the file exists on the server, this is just an extra precaution. Let's see the code used for this method: $file = 'your/path/to/file/' . basename($_GET['page']); For this method, I showed you an example of using a path other then the webroot to include the file. This would attempt to prevent people from just probing for different files, and you can place the pages into their own directory, so only pages meant to be included are included. IE, you could have a 'pages' directory and keep them organized in there. If you are using this method, I would highly recommend using the pages directory or similar. Other Methods I am sure there are plenty of other methods, I saw one guy using base64, however, this are the two primary methods I recommend to people for their simplicity. My preferred method overall would be the basename with the pages directory, outside of the webroot. This would mask the pages, and make it more difficult to probe for your pages and remove the risk of a file accidentally being included when it should not. If you have other methods, feel free to post them in the comments. Finishing Touch This is just one step you can take to secure your site from being exploited by what we call Script Kiddies and the likes of others. This alone, will not completely secure your site so of course you will need to take other precautions on every other aspect of your site. However, if pulling up pages dynamically using a URL intrigues you, this method will help you to secure yourself from being exploited with a remote file inclusion exploit. As always, I welcome non-trolling or flaming comments. I will remove any flaming or trolling comments, so please leave positive feedback as all that is being done here is attempting to educate users. If you feel I am wrong, tell me in a constructive way with proof and ways to fix it. Thanks, and hopefully this has helped you! |
|
0 Comments
Mood: splendid Music: php, exploit, script, kiddies, remote, file, inclusion, remote file inclusion, basename, file_exists, white list, list, include, require, require_once, include_once, allow_url_fopen, fopen, file_get_contents, prevention, precaution, security, help, howto |
|
|
![]() Stella Service which used a network of full time mystery shoppers to evaluate, and rate each Internet retailers customer response times. They made over 1,200 interactions via phone, and email to these companies regarding a product or service and here are the results of that survey. 1. Sierra Trading Post located at sierratradingpost.com ranked 1st when it came down to the shortest amount of time that customers had to wait on hold. 6 seconds! 2. Office Depot located at officedepot.com best at getting back to emails. 48 minutes! 3. Barnes and Noble located at barnesandnoble.com gets the worst support customer hold time 8 mins and 3 seconds. 4. Crate and Barrell located at crateandbarrel.com gets the worst email response time at 88 hours to get back to you. Keep in mind these are the averages. Only one company made it in to the top 10 for the speedway email and phone support and that was The Disney Store, at disneystore.com 12 seconds to answer the phone, and 1 hour and 47 minutes to respond to email. Would any one agree that response time under 1 hour is not bad to receive an email response? I know at where I work, we do our best to respond in the first 10 to 15 minutes. External Link: Top Response Times from the Top 100 E-Retailers |
|
|
![]() Entry remarks on the decline of text messaging in 2010 and how telecommunication companies plan on making that money back. A CTA report says that texting only grew 8.7% in the second half of 2010. That's the smallest increase in a really long time. If people aren't texting what are telecommunication companies to do? Will they just add data caps, and charge like crazy for that data? Will the make the consumer join a substadiesd plan? Would they introduce a data only plan that includes texting and increase rates? The answer is yes, yes, and yes. In fact you may already be experiencing limitations like these. So what can you do? Try finding another provider, use an instant messenger! Bits are bits, and paying for texting is the most expensive data plan out there. I have yet to experience texting outside of Google Voice, and refuse to pay for it. Guess I'm cheap like that. |
|
|
|
Harlan Coben is perhaps one of my favorite authors. I love Harlan's Myron Bolitar series as such I read any book he puts out. One of Harlan's more recent book, Caught, reached my eyes and I decided to give it a read. Immediately I became immense in the book, I love a good mystery and I knew that Harlan would produce. I also enjoy how Harlan uses familiar characters from his other previous books and as such it makes you smile just seeing the name when they read. Dislaimer, This review may contain a few hints and spoilers, if you know Harlan Coben and prefer not to know anything about the book, I suggest you stop here and just buy the book and read it. ![]() A Viral Marketing Thriller A mystery book about how Viral Marketing tear people's life apart hardly sounded interesting to me, but Harlan Coben was able to take the Internet Viral Marketing and make it into a great mystery. Wendy Tynes, who is a news reporter, has Caught yet another sick pedophile on her TV Show. However, Dan Mercer is not your average pedophile, and something about Dan has struck Wendy Tynes as being "off". While the trial for Dan Mercer is going on, a 17 year old girl comes up missing, Haley McWaid, who is a quiet girl, but also a perfectionist. Wendy decides to do some digging on Dan Mercer and some old school buddies, and what she finds will take you for one awesome ride. Is everything as it seems? It appears not, and Wendy Tynes is bound and determined to unravel the truth, no matter what road it takes her down. With a bit of help from Win (Windsor Home Lockwood the Third appeared in the Myron Bolitar series) Wendy digs as deep as she can, but will she dig too far? My Take I thoroughly enjoyed this novel. The characters were laid out, in my opinion, great. If you have read the Myron Bolitar series, you will love the few appearances by Win in this book and it put a smile on my face. You will also find some brief appearances by Hester Crimstein, who is a TV Show Judge now. The book, Caught, is far from being predictable, which I love about a mystery novel. Caught also has many twists and turns and takes you for a thrill ride all the way through. In the end, I do not want to go into great detail, as I hate spoiling books, so I would highly recommend if you are a Mystery / Thriller book junkie, or just love Harlan Coben, check out Caught and give it a read, I bet you will find it hard to put the book down (I know I did). External Resources If you would like to see what Harlan Coben thinks about Caught, here is a YouTube video of his review: |
|
0 Comments
Mood: glorious Music: thriller, mystery, book, review, myron, bolitar, win, windsor lockwood, wendy, caught, series, characters, familiar, fun, enjoyable, great, read, smile, immense, book, reading, author, favorite, harlan, coben, viral, marketing, trial, wendy, show, tv |
|
|
![]() This entry states that Windows 8 Developers are to Code in HTML5 and JavaScript for a more graphically pleasing interface. Wow, this must really rub Windows developers the wrong way, but is it a time for WC3 standards? Let's discuses! Microsoft has stated to developers if you wish to developer in a more immersive and Flashy front end, than you are going to have to code in HTML5 & JavaScript if you want those immersive apps that go full screen and stay in that experience you going to have to use HTML 5 and JavaScript. Most of us are probably thinking right now. FINALLY! Microsoft is going to adopt standards into it's platform. But developers are saying, "we have decades of experience in .NET, Windows platforms, in Silverlight, and now you want us to throw away all of that? None of us have done scripting languages before!" Microsofts rebuttal will probably be, HEY Developers! You can continue using .NET, Silverlight, etc, but everything else will be HTML5 and JavaScript coding for a more beautiful interface. Your thoughts? I was so happy to hear about Microsoft going HTML5 to stay compliant, but now I understand all of those that are hurt by it. Is it time for a change? Does all software need HTML5 scripting? Who cares if the UI is pretty, I am more concerned with it working and functioning at 100%, but is this possible? I suppose we will have to wait for the Microsoft Build Conference in September for developers. External Links: Microsoft confirms its Windows developer conference is named BUILD |
|
|
When looking for easier way to obtain meals, I often look at fresh solutions, so to speak. When I came across this Omaha Steaks Mailer, I decided to take a look into Omaha Steaks and give them a try. My results are kind of mixed pleasures, but overall I was pleased with the product. What does get annoying is the constant mailers and phone calls. Luckily I can disable the phone calls, however, I cannot control the snail mail mailers. This is a minor annoyance, and some people may not even consider it an annoyance at all. ![]() The Quality Overall the quality is decent. I mean you could do just as good with a frozen steak on your own. My wife seems to think it is great quality for a frozen steak / meat and it has a great flavor. I think it is kind of so-so, the quality seems to be by preference. The burgers were very nice and easy to grill. They ship out the times to cook them, however, since we live in Colorado at a higher altitude those times needed to be adjusted. As part of a package we received some twice baked potatoes. They are almost always my favorite part of a steak dinner, and Omaha Steaks did not disappoint me with their twice baked. For coming out of a freezer, they tasted delicious, at least as good as the ones you can buy from your store's Deli section. I am not a huge hot dog / franks, fan, and unfortunately their Gourmet Franks did nothing to change my mind. They looked great, but in the end, they still tasted like a hot dog. I may try marinating them next time and see if I cannot produce a bit better Frank. My wife enjoyed them also, however, my little girl did not, which should not be surprising as she is almost 2 and can be a very picky eater. In my little test run, the quality of the food seemed decent, especially for being frozen and shipped. The Ordering Experience From start to finish the Omaha Steak experience could not be called "enjoyable", as when is spending money, and seemingly a lot money upfront, enjoyable? However, the easy of ordering online (I hate talking to sales people on the phone) was pretty simple, like most online ordering. With the optional account setup, I chose to setup an account. The process was basically, select what you want (in my case I just entered a promo code from the mailing). Overall, the ordering experience was simple and what was to be expected by today's standard of online ordering. Breaking it Down I think Omaha tends to over price their products, to intentionally "knock" down the price to make you feel like you are getting a good deal. I saw through this and broke it down to what it cost per each serving. Overall it is a decent deal, however, a membership to Costco with a vacuum pack sealer, could easily compete with the cost, and you would probably come out much better going that route. But for a small family, in my case 3, with only 2 adults this seems to be a decent deal. Why for the small family, well everything comes in it's own individually wrapped package. This is awesome as I can easily just make myself a burger and my wife a steak, if we both feel like something different, or if I am home alone watching the kid while my wife is going out. This aspect of Omaha Steaks was very appealing to me. I would imagine this being great for a single person, a small family, or perhaps an older couple whose kids have all left / gone off to college. If you have a bigger family, I would probably go the Costco / Sam's Club route, and I think that you would get more bang for your buck. In the End In the end I am buying another item from Omaha Steaks right now to give them another go, and it is a Father's Day special. Hopefully, it is a similar if not better experience. I do really think that this solution is not very frugal for large families and I do not like how Omaha Steaks "knocks" their prices down all the time. I mean really, it does make you feel like you are getting a deal, but it also feels like a scam. I know it is not a scam now, but I think it would present their appearance better having "real" prices and do "real" specials, instead of these constant specials and in my opinion, if you buy anything from them for their "real" price, you are a moron and you deserve to be wasting your money. Hope this review helps you decide if you want to give Omaha Steaks a try or not! Good Eatings! |
|
0 Comments
Mood: smiley Music: omaha, steaks, review, decent, okay, mixed, pleasure, good, product, steaks, burgers, franks, hot dogs, online, ordering, experience, preference, test, trial, surprising, picky, food, frozen, delivered |
|
|
![]() Did you have the latest Simple Touch Reader by Barnes and Noble? If so you might be interested in knowing that it has a web browser. The Newest Nook, The Simple Touch Reader has a web browser in side of it's system, and you don't have to root it. Barnes and Noble does not list the browser has a feature. I do not have one but it is said you can navigate to websites using the search bar. Reviewers have been stating that the browser is a little buggy, so I suppose that is why Barnes and Noble does not list it as a feature. But is this the reason to get the Nook Simple Touch Reader? Black and white screen, with a slow refresh rate at 1 frame per second? Is the Nook cheaper than Amazon, or the Apple Bookstore? I guess if you want a reader, and browser you should get an iPad or Android Tablet. |
|
|
![]() This morning Gmail Now Allows Pasting Images into Email. So how does this work? Well first off you will need Google Chrome, so the idea is to simply copy the image from an email or from the web and paste it right into the message. It is also said that you can even post screenshots. If you are on an Apple iOS device. simply hitting: Apple iOS Devices Command-Control-Shirt-4 will save the screenshot to your clipboard. Windows Operating Systems Print Screen, CTRL+C CTRL+V Gmail states that while this currently only works in Google Chrome, they plan on releasing this features for other browsers. This is a great feature, and I can't wait to share it for others around the office. |