But the original writer and now famous Security researcher is MSIA, CISSP, CISA... That must say something no ?
what do you mean Security Certification are worthless ?
This again? If I've said it once I've said it a thousand times:
Capital 'H's are not allowed in the middle of a word unless:
- it is an acronym (unless the acronym happens to spell a dirty word).
- it is used to directly reference the title of a showtune from Broadway's heyday which hasn't happened yet so this is moot anyway.
- it was something said by or to Yogi Berra.
What Open SORES or NIX has done what MS has here? Answer the question, don't evade it or try "Spin-CON-Troll" tactics. Your douchebaggish trollishness is showing in your reply as well as your low brow and sloping forehead, douche.
So Mr Shill is posting as AC and is getting personal and rather testy? If you don't like the view of/.ers about the security of MS products you have a few options:
A) Go post somewhere else
B) Tell your employer to get their shit together
C) Both A & B
D) All of the above
'xammp in some flavor' running in your desktop os, still means 'different from the production environment' you are going to run the thing on. xammp on mac will need to behave as xammp on a mac.
Then shouldn't he have known that he can only develop on a system configured identically to his production environment?
This kid has Aspergers syndrome and is making the most of it. Good for him. Hey kid, invent me a time machine dammit so I can warn myself about all the stupid stuff I did to end up where I am in life!!
Merely related ideas are not "ironic". Ironic is when one's words say one thing and one's actions another that contradict it. If MySQL.com claimed SQL injections in MySQL were impossible, then this attack's success would be ironic. If MySQL.com attacked some DB with a SQL injection, that would be ironic. Not all coinciding events are "ironic".
So it would be ironic if MySQL.com was hit with an SQL injection if they were using MS SQL for their server DB?
This article is a tad harsh on MySQL.com - and rightfully so:
* The domain's SSL expired a month ago
* Some of the passwords for the account 'sysadm' was “qa”
* Their website was obviously not properly secured
Please have a -1 Button
Since this is /. shouldn't we be asking for one or more of the following:
* ++i
* i++
* --i
* i--
Are you associated with the website?
Do you mean pureinfotech.com or google.com since it appears to be a very pro Google article.
I was trying to access www.AntiVirusPro2011.com when I got redirected here.
You should have been trying to get to lizamoon.com instead ... but it's not responding anymore. I guess it got overloaded (or shutdown).
So, what's the attack? What SQL servers/CMS/languages are vulnerable?
Neither article says ... so I guess the only way to find out is to hit the internet and find out for ourselves!
But the original writer and now famous Security researcher is MSIA, CISSP, CISA ... That must say something no ?
what do you mean Security Certification are worthless ?
I believe you forgot LOL, SOL and GTFO.
These two occurred after the discovered the first one. How does this stuff keep happening?
taH pagh taHbe'. DaH
mu'tlheghvam vIqelnIS.
This again? If I've said it once I've said it a thousand times:
Capital 'H's are not allowed in the middle of a word unless:
- it is an acronym (unless the acronym happens to spell a dirty word).
- it is used to directly reference the title of a showtune from Broadway's heyday which hasn't happened yet so this is moot anyway.
- it was something said by or to Yogi Berra.
Once it's got past this stage there is also a chance that Microsoft will veto against your game going on the platform.
This sounds different but similar to Apple's review process. Meet the new boss, same as the old boss.
Information is like water and it will always find a way to get through.
What Open SORES or NIX has done what MS has here? Answer the question, don't evade it or try "Spin-CON-Troll" tactics. Your douchebaggish trollishness is showing in your reply as well as your low brow and sloping forehead, douche.
So Mr Shill is posting as AC and is getting personal and rather testy? If you don't like the view of /.ers about the security of MS products you have a few options:
A) Go post somewhere else
B) Tell your employer to get their shit together
C) Both A & B
D) All of the above
Microsoft didn't create any problem to begin with. All OS's with billions of stupid users will get infected.
So MS (or rather one of their paid shills) is blaming the users for piss poor OS security on Windows?
It's pretty sad and pathetic that there are bandwidth limitations.
Very true, but the carriers here don't consider them 'limits', they prefer to treat them as 'billing milestones' ;)
I prefer my clouds to be in the sky. I also prefer not to go over my 250GB monthly cap.
Not to mention the 250MB or 2GB limits on cell data plans.
Ted Dziuba is a co-founder of Milo.com, which just sold to eBay for $75 million.
I'm guessing your leet Web skills brought in more than that last year, which is why you feel comfortable calling him an "amateur."
Founder != Professional Developer.
doesnt matter.
'xammp in some flavor' running in your desktop os, still means 'different from the production environment' you are going to run the thing on. xammp on mac will need to behave as xammp on a mac.
Then shouldn't he have known that he can only develop on a system configured identically to his production environment?
So McAfee's website is as secure as MySQL.com? This intertubes thing just keeps getting better and better.
Hi Michael! Nice to see you around these parts. What do you think of the 'Whiz Kid'?
What's the theory? How does it "expand" on relativity?
I think he made relativity object oriented.
This kid has Aspergers syndrome and is making the most of it. Good for him. Hey kid, invent me a time machine dammit so I can warn myself about all the stupid stuff I did to end up where I am in life!!
Really /.? I know that dupes happen, but this is ridiculous!
Don't blame me, I marked it as a 'Dupe' in the fire hose.
We call that a dupe.
It's like parking your car right next to a car that looks just like the story that was posted yesterday morning (or something like that).
Merely related ideas are not "ironic". Ironic is when one's words say one thing and one's actions another that contradict it. If MySQL.com claimed SQL injections in MySQL were impossible, then this attack's success would be ironic. If MySQL.com attacked some DB with a SQL injection, that would be ironic. Not all coinciding events are "ironic".
So it would be ironic if MySQL.com was hit with an SQL injection if they were using MS SQL for their server DB?
I'm in. Where can I buy these wonderful microsoft products?
I think you can buy them by calling 1-800-MS-SHILL
This article is a tad harsh on MySQL.com - and rightfully so:
That should have been This article . D'oh!
This article is a tad harsh on MySQL.com - and rightfully so:
* The domain's SSL expired a month ago
* Some of the passwords for the account 'sysadm' was “qa”
* Their website was obviously not properly secured