Slashdot Mirror


User: davidbrit2

davidbrit2's activity in the archive.

Stories
0
Comments
574
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 574

  1. Re:Why validate when you can sanitize? on New Attack Exploits "Safe" Oracle Inputs · · Score: 1

    I agree, but there are some situations where you simply can't. Take for instance dynamically specifying the database to use in an SQL Server query. You get various syntax errors if you try to do "SELECT * FROM @database.dbo.MyTable", so you have to concatenate. For all other situations, stick to stored procedure parameters.

  2. Why validate when you can sanitize? on New Attack Exploits "Safe" Oracle Inputs · · Score: 1

    Honestly, I never understand the people that constantly trumpet "Validate! Validate! Validate!" whenever they're dealing with a web/database app. If you're escaping/sanitizing your inputs properly, then you don't need to chase your tail making sure your users haven't entered something "evil".

    The specifics vary by platform, but if you're building a dynamic SQL statement in SQL Server, for instance, you'd use the Replace function on the concatenated values to change any occurrence of ' to ''. For MySQL, change ' to \'.

    It's very simple, very consistent, and very safe. This is what any decent parameterized query API will do behind the scenes. It's like the old anecdote: you can either spend a lot of time building an exhaustive filter list of offensive words that you don't want showing up in your tracking/order/confirmation codes, or you can just not use any vowels and be done with it.

  3. Punch "gmail xss" into your search bar... on Google Shares Its Security Secrets · · Score: 2, Interesting

    I get 1.6 million hits from Google themselves. They may be overestimating their security practices just a wee bit.

  4. So basically... on Alternate Baseball Universes · · Score: 2, Insightful

    They took a bunch of measured statistics, ran a simulation with outcomes biased using said statistics, and then acted surprised when the simulation results ended up pretty close to what actually happened?

  5. I prefer the traditional phrasing on Red Hat to Coax Code Contributions From Companies · · Score: 1

    "Can't rape the willing!"

  6. What's that old saying? on US To Shoot Down Dying Satellite · · Score: 1

    Life imitates art? Or I guess in this case, Ace Combat 5.

  7. Code excerpt for the curious... on OpenBSD Will Not Fix PRNG Weakness · · Score: 5, Funny

    http://xkcd.com/221/ Oh hush, you knew somebody would post it.

  8. Re:Yes on Trend Micro Sues Barracuda Over Open Source Anti-Virus · · Score: 1

    Some guy named Mario left a message for you at the front desk. He mentioned something about a license.

  9. I don't know what kind of flies they have in NY... on Robotic Fly to Descend on New York · · Score: 2, Insightful

    ...But a fly with a 1.2 inch wingspan would be pretty damn conspicuous where I come from.

  10. Not terribly surprising, given the track record on Long Term Effects of Gizmodo CES Prank · · Score: 1

    An editor from Gizmodo also posted Tubgirl prominently on the main page of Kotaku. (No, that's not a link to the tubgirl posting, obviously - it was deleted quickly afterward anyway.)

    Let's just say I don't read Gizmodo anymore.

  11. Re:You ever have that dream... on Dreams Actually Virtual Reality Threat Simulation? · · Score: 3, Funny

    Full-contact theological debate, evidently.

  12. Re:An analogy on Hands-On With The Kindle · · Score: 2, Funny

    So in other words, totally superfluous, and largely the laughing stock of its domain?

  13. Oh thank god on NPD Reverses Console Numbers Decision · · Score: 5, Funny

    For a minute there, I was afraid the console flame wars would have to rely on blind speculation.

  14. In future news... on Adobe Intends To Move All of Its Applications Online · · Score: 1

    "Adobe today filed for Chapter 11 bankruptcy after a shocking decline in sales following adoption of a web-based business model..."

  15. Re:Correction: on What if Google Had to Design For Google? · · Score: 1
  16. Ignoring a redundant "service" != stealing on Sony BMG Says Ripping CDs is Stealing · · Score: 1

    "I sell bottled water, so if you take water from a natural resource and use it, then I guess we could say you are stealing."

    Please. Just because someone's business model revolves around offering something completely redundant, it doesn't mean you're stealing if you tell them to piss off.

  17. My first ebay purchase on Know How To Use a Slide Rule? · · Score: 1

    Funny enough, the first thing I bought via ebay was a nice Pickett slide rule, around my senior year in high school. It was a pretty good find - it had the original slide case, and even the manual. I didn't use it for actual work, though I did fiddle with it enough to figure out the basic operations. I recall I even managed to approximate pi to a couple decimal places with it.

    Needless to say, I didn't go on many dates in high school. :P

  18. I know exactly what to do on Meteorite Causes Illness in Peru · · Score: 1
  19. Re:I think I'd prefer analog on Are You Being Cheated by Digital Cable? · · Score: 1

    I'm with you on this one. The compression is so bad around these parts, that the image quality of certain stations picked up with my set of rabbit ear antennas is noticeably better than that of the washed out block-fest seen on the MPEG-heavy digital channels.

  20. Congratulations! on Fox News' FTP Password Anyone? · · Score: 1

    You've won an all-expenses-paid trip to a federal PMITA prison! You'll be enjoying a 1,825 night stay at an all-inclusive resort featuring a mattress, a metal toilet with a sink in it, and evening turn-down service provided by your own personal bellhop named Scar. Travel and accommodations courtesy of the US Federal Bureau of Prisons.

  21. Watch out for... on Rewritable Song Lyrics · · Score: 1

    ...my next hit single, "I Just Want To [verb] You [adverb]".

  22. I've got one for you... on There Are No Games So Bad They're Funny · · Score: 1

    Hakai Oh: King of Crusher.

    It's an obscure Japan-only PS1 release. It is also HILARIOUSLY bad. From what I can tell, the story line revolves around your John Q Public character being bitten by some alien fly as a child. Then later in life, the fly returns. Said character then relapses, goes into a rage, and starts breaking everything, while his wife and child flee the house. And then, you break stuff. Seriously, that's it. But it gets worse (or better, depending on your point of view). Your character corners about as well as a city bus, desks and furniture explode into flat polygons as you "attack" them, trees tip over like cardboard stand-ups, and the "growl" that your character emits upon completing a stage is the icing on the cake.

    Seriously, if you have the means to obtain and play Japanese PS1 games, you need to try this one to marvel at its awfulness.

  23. Re:what am I missing? 850Mhz = slow? on IBM's Blue Gene Runs Continuously At 1 Petaflop · · Score: 5, Funny

    What am I missing?
    The other 4,095 of them.
  24. Re:Huh? on Games They'd Like Us To Forget · · Score: 1

    Yeah, for real. That game was completely awesome, and I spent many hours with it in my youth.

  25. Re:Small Red Button on Big Red Button Disasters? · · Score: 1

    The keyboard included with my (cheap) Compaq had a sleep button located not half an inch behind the Esc key. And we all know how daintily and precisely the average computer user reaches for the Esc key.

    I'm no longer using that keyboard.