Slashdot Mirror


User: MisterZimbu

MisterZimbu's activity in the archive.

Stories
0
Comments
49
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 49

  1. Re:We Got Hit By This on Mass SQL Injection Attack Hits Sites Running IIS · · Score: 4, Informative

    Just as a followup to this, it's not actually a fault or exploit in MSSQL or IIS; just that the SQL being injected is specific to MSSQL and completely valid. This can and will happen in any future version of IIS or MSSQL unless specific action is taken by Microsoft to prevent the underlying technique used to do it, which is unlikely as it will break a large percentage of perfectly legitimate applications.

    The same attack could probably be modified to hit Oracle, MySQL, or other DBMSes with minimal effort. I don't even really know why IIS is even mentioned as the actual server software is irrelevant. This attack would just as easily hit MSSQL databases with website front ends hosted on Apache or pretty much anything else, no code changes needed. This isn't even the first time this has happened. A couple years pretty much the exact same script was used to deface sites on about the same scale as this one did.

    The blame should be placed on the developers of the poorly written 3rd party software that doesn't sanitize its inputs or (preferably) use parameterized queries and stored procedures.

  2. Re:Sorry for troll, but FF has better UI? Seriousl on Google Updates Chrome Frame, Makes IE Better · · Score: 1

    As a web developer, I've always used the history window in Firefox as a base for my time tracking - gives me a pretty good idea of how many hours I spend browsing Slashdot and how many minutes I spend on customer websites.

  3. Re:At first I wondered if it was real... on Steak-Scented Billboard Entices Drivers · · Score: 1

    Seriously. Don't have a cow.

  4. Re:Call me a fanboi or whatever but... on Blizzard Boss Says Restrictive DRM Is a Waste of Time · · Score: 1

    It's an online multiplayer beta.

  5. Re:Do not tell me about this wave thing... on Google Wave Now Open To All · · Score: 4, Insightful

    This.

    Google Wave has to actually be forwards and backwards compatible with e-mails if it ever stands a chance of replacing it. That means people seamlessly being about to send e-mails to myaddress@googlewave.com and having them appear in my inbox, and having my replies (as waves) send out e-mails as replies if any of the participants in the wave is an "e-mail" participant.

    And bots really don't count. It has to be tightly integrated into the system.

  6. Re:What were the parents thinking ? on 3rd-Grader Busted For Jolly Rancher Possession · · Score: 1

    And that shit be quantum. Is she eating it now? Is she eating it later? Until you actually open her mouth and look inside, she's doing both.

    Schrodinger's Candy?

  7. Re:My wish on Top 10 Things Hollywood Thinks Computers Can Do · · Score: 1

    I was overjoyed to see a copy of Visual Studio running on Roy's monitor on an episode of The IT Crowd. He even uses the same color scheme I do!

  8. Re:Let's look at what JWZ said... on Cross With the Platform · · Score: 1

    That doesn't mean the developer or the framework was competent. Just that marketing was.

  9. Re:Ha. on Geohot Brings Other OS Support To PS3 With Custom Firmware · · Score: 1

    So the companies have to make cost analysis and decided what brings in more profit: screwing with your current costumers to gain some file sharers, or lose those file sharers that would pay but make your costumers happier. As long as the first option brings more money, they won't change.

    Much like Sony's hardware and software manufacturers, Sony's costumers are known for their wardrobe malfunctions.

  10. Re:Paint.NET on De Icaza Says Microsoft Has Shot .NET Ecosystem In Foot · · Score: 4, Insightful

    Paint.NET is far too usable to be compared to Gimp.

  11. Re:Online gambling is a bad idea. on Push To End Online Gambling Ban Gains Steam · · Score: 1

    I disagree with that last part - online gambling always tells you exactly how much you lose. It's much easier to put a value on the computer telling you that you lost $800 than it is to just toss another 8 black chips on a table.

  12. Re:Only 24 hours? on Sams Teach Yourself HTML and CSS In 24 Hours · · Score: 1

    This is more or less what I do. The tables I make typically aren't 5-level nested monstrosities with spacer gifs and col/rowspans all over the place. It's usually only one or two levels deep, with the content placed into properly-styled DIVs with margins and paddings as appropriate.

    It doesn't work perfectly (the DIVs wont grow vertically in any browser as they shouldn't, and the DIVs won't grow horizontally in IE6/7 with table cells like they should), but I refuse to deal with hacks like 100% heights, +1000000 paddings with -1000000 margins, and having to overflow a margined div to get clears inside the div to work properly and just accept that scrollbars will randomly pop up.

  13. Re:Only 24 hours? on Sams Teach Yourself HTML and CSS In 24 Hours · · Score: 2, Interesting

    I'm still a tables guy- to me, doing anything remotely complicated in CSS is completely unintuitive and backwards, and requires ridiculous hacks before you even get to IE (no vertical alignment? lack of proper columns?). The real problem with web layouts today is that neither HTML Tables nor CSS were designed with layout in mind, so everything requires far too much effort to set up properly. To me, I'd rather deal with the (much smaller) hassle of using tables for layout than deal with the significant hacks to get around the severe limitations of CSS.

    Hopefully when CSS3 gains some more widespread acceptance and some of the layout-oriented modules (the CSS3 table ascii-art module and/or the Flex Layout module) gain some traction, I'll be able to switch over.

  14. Re:paws on For GUIs, Just the Right Degree of Realism · · Score: 2, Informative

    The "paws" icon is from Lemmings. I could imagine it being in other games too, though.

  15. We shouldn't be cloning extinct animals! on Scientists To Breed the Auroch From Extinction · · Score: 1

    Only disaster could possibly occur when we do such thing.

    Haven't any of you learned anything from the movie, "Jurassic Pauroch?"

  16. Re:Damn you spaceballs! on A Hyper-Velocity Impact In the Asteroid Belt? · · Score: 1

    Please never spell "ludicrous" like that again.

  17. Re:I liked it when it was called Virtual Console on Microsoft Announces "Game Room," Confirms Natal For Late 2010 · · Score: 1

    Yes. Microsoft ripped of Virtual Console with XBLA so fast that it actually came out a year before the Wii.

  18. Re:The real problem on SQL Injection Attack Claims 132,000+ · · Score: 1

    This is actualy a stupid article, as it doensn't even bother to describe the platform which has the vulnerability in it. It's not a platform or database issue if it's a SQL Injection, so it must be some app that is common... like a CMS package or blog engine... something like that.

    It doesn't matter. It's not an attack on a specific web server, CMS, or even database engine. The ONLY thing that matters is if the underlying scripts driving the website are poorly written and vulnerable themselves.

    It's not difficult to write something that spiders websites and attempts injection attacks against querystring variables that that individual site commonly uses. The exact same thing happened either late last year or early this year. Now in that instance, that was specifically targeted for MS Sql Server, but it's not hard to imagine a completely platform-independent version.

  19. Re:15 minute lockouts and no solution on New WoW Patch Brings Cross-Server Instances · · Score: 1

    One of the major features of the patch was adding a new LFG system that literally makes finding a group trivial. If you're just looking for a random instance, you'll be in a group within minutes. If you're looking for something more specific how long it will take will obviously depend on what instance you're looking for.

    The key thing is that it's all automated now - it'll find 4 other people (with correct roles - 1 tank, 1 healer, 3 DPS) and automatically group them together for what they're looking for.

  20. Re:15 minute lockouts and no solution on New WoW Patch Brings Cross-Server Instances · · Score: 1

    By "try again" they mean "try teleporting to the instance again".

    There's an icon in the lower left corner of the minimap that you can click to try teleporting to the dungeon again. No need to drop group and look again.

  21. A permanent fix on Bizarre Droid Auto-Focus Bug Revealed · · Score: 2, Funny

    "'There's a rounding-error bug in the camera driver's autofocus routine (which uses a timestamp) that causes autofocus to behave poorly on a 24.5-day cycle,' said Morrill."

    Cool! The device will later be fixed to properly behave poorly only every 24.45 days!

  22. We never went to the moon! on Moon Mission Anniversary · · Score: 1

    Because we know of how high quality FOX specials are. Next on FOX- "When Moon Missions Attack!"

  23. What I haven't found... on What Isn't on the Internet? · · Score: 1

    Well, I haven't been able to find any boots that enable me to jump six feet in the air...

  24. It's fun... on U.S. First 2001 Competition Begins · · Score: 1

    As a two-year veteran of FIRST, I can say it's a fun experience and interesting to watch. This year's contest doesn't seem that competitive though, it's a 4v0, so i don't get to destroy Texan robots... :(