June Will Be Month of Search Engine Bugs
De Garmo writes "A Ukranian hacker known as "MustLive" has announced plans for a Month of Search Engine Bugs project in June 2007. The plan is to shake out cross-site scripting bugs in the most popular search engines (think Google, Yahoo, MSN, Ask.com) and publish details on these flaws. From the article: "[The] purpose of this Month of Bugs is a demonstration of real state with security in search engines, which are the most popular sites in Internet. To let users of search engines and web community as a whole to understand all risks, which search engines bring to them. And also to draw attention of search engines' owners to security issues of their sites.""
will we eventually be able to google for these bugs?
Here's a few to get off the ground with: http://sla.ckers.org/forum/read.php?3,44,page=47
Well, if it is "bugs" you are looking for (not just security exploits), here is one:
Try searching google for "\\.\"
You Windows driver programmers should know what it is about.
"When life gives you lemons, don't make lemonade. Make life take the lemons back!" -- Cave Johnson
By the way, before anyone jumps on me, the line should read:
* If you're going to make a declaration in English, please speak properly.
I'm not above fault myself. In my defense, however, I'm not trying to get the attention of a worldwide audience.
javascript is the bug. Input validation is no big deal for any programmer with a clue, perhaps that's also a bug :-o
How many foreign languages do you speak flawlessly?
Terrorists can't threaten a country's freedom and democracy. Only lawmakers and voters can do that.
Do not try to read the dupe, thats impossible. Instead, only try to realize the truth
What truth?
There is no dupe
"How many foreign languages do you speak flawlessly?"
A whole bunch.
can we have a month of free, good porn? i spend all day looking at bugs, i could do with something else for a change...
I don't claim to speak any foreign languages. I also don't attempt to speak them. The same way I don't attempt to do brain surgery.
Aww, shut the fuck up! Give the man a break. I'd be glad to read his broken English if he has something interesting to say, and it seems like he does. Just because he's not a native English speaker doesn't mean that you can't understand what he's trying to say. I'm not a native English speaker myself, but I do my best, and I'm pretty sure he did too.
A proud member of the Onion-in-Hand alliance
Mod parent way up.
Ignore this signature. By order.
Try this link. Google without any ads ? Ok we could configure our machines to bloack ads but I use different machines a lot, if that "backdoor" link becomes popular Google would be in trouble ! I picked up on this "bug" from here.
Yes strictly it isn't a bug in the sense that it harms the user but it is the same as a bug that allows you use a program for free.
Hmm, I wonder if it's going to be something like this...?
http://johnny.ihackstuff.com/ghdb.php
Beware: In C++, your friends can see your privates!
Based on how Apple completely turned around their company and the focus of their insecure product, I'm sure that the search compan... what? Apple didn't begin doing anything differently? Oh. How embarrassing.
Nevermind...
Brain surgery? What a comparison!
You'll have an extremely hard time convincing us Europeans to follow your rule. Lots of people here know several languages and use them all frequently, without knowing them well enough to speak flawlessly. We use foreign languages both for business and for fun. You'll have a very hard time convincing us to stop doing this.
In my opinion it would be a very boring world if people followed your rule. For example, I couldn't write this post. English isn't my first language, it's not even my second, so who knows what errors might sneak in without my noticing!?
Maybe I'd better shut up now, in case I'm subjecting you to painful language errors without noticing.
Terrorists can't threaten a country's freedom and democracy. Only lawmakers and voters can do that.
It's only a matter of time... I wonder how long 'till we have the Month of the Slashdot Bugs?
sounds like a load of pap to me, will have to wait and see.
Webmaster SEO Forum
Shouldn't June be the month or "June Bugs" ... damn things used to scare the hell out of me as a kid. And I don't even want to talk about Potato Bugs
Its not the years, its the mileage
Hell, most native speakers of English don't even do it right. The word is "ya'll" people.
Of course not. Regexes do NOT work in Google searches. Try searching for sla.*dot, and you will find, as expected, things with "sla" and "dot". The closest to slashdot you may come across could be a sla.dot Word template if
Let's hear your Ukrainian, then! Or any foreign language, for that matter. Come on, show us what you can do!
Oh, you don't speak any languages besides English? How unexpected.
butter the donkey
The government can't save you.
I pointed out the mistake before you did. Do I win a prize?
There's a big difference, by the way, between making a single mistake and pointing it out almost immediately in a lone Slashdot discussion (as I did), versus making multiple mistakes, while not bothering to correct any, in holding worldwide search engines for ransom.
In either case, I applaud your thoroughness in not bothering to read the replies to my post before flinging one of yours on the wall. (I'll leave the examination of the semantics of my last sentence as an exercise for the reader).
Nor do I attempt to speak them. As I mentioned, I don't attempt to engage in any exercise that I know will fail in. Not brain surgery, not holding search engines hostage, and not speaking Ukrainian.
o rly?
find / -name "*.sig" | xargs rm
Do not try to read the dupe, thats impossible. Instead, only try to realize the truth
What truth?
There is no dupe
Language is only a metaphor. Just add heurestic methods, discriminative bayesian, expectation maximization and other crap, that's called Google Translate, moron! Even not-so-fluent English speaker can become a president. So what's the cluck is for eh?
You really need a lobotomy, Chris.
So your search for foo.*baz is the same as a search for "foo *" baz. Because the phrase "foo bar baz" is common on programming sites, you're likely to see "bar" bolded because it matches the asterisk.
Paid Q&A/Research
Who said I was American?
Don't feed the trolls ppl. The guy speaks one language (not even flawlessly), you come along and make a damned fine effort with English as your nth language. Don't waste your time (unless you wanted to show of your linguistic prowess, in which case go right ahead).
Me lost me cookie at the disco.