Slashdot Mirror


User: Slashcrap

Slashcrap's activity in the archive.

Stories
0
Comments
1,102
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 1,102

  1. Re:XMLHttpRequest on Cross-Site Scripting Worm Floods MySpace · · Score: 1

    Is there a way to force the object to use SSL?

    Yes, I'm sure that there is.

    Is there too much overhead in encrypting and decrypting the XML data with Blowfish or another algorithm?

    Probably not, for most sites and applications.

    But the point is that encrypting the network traffic between the client and the server would have done nothing to prevent this vulnerability. Or most others for that matter. The only thing encryption would prevent is the snooping of traffic between client & server.

  2. Re:What about the American Sanctions on Western Software Used to Support Censorship · · Score: 1

    They can get such software though piracy, or through 3rd parties, or through the internet!

    Doesnt mean that we actually sell it to them, by all means, I doubt they even bought it.


    That's right - those goddamn gooks stole your software (and hardware) so that they could opress their own people. Everyone knows that Uncle Sam would never get involved in anything like that.

    Is the above what you believe or is it just what you want to believe? I ask, because I can't help noticing that some Americans have trouble differentiating between the two. Specifically the religious right.

  3. Re:SATA on Ubuntu 5.10 "Breezy Badger" Released · · Score: 1

    Will it go straight onto an SATA drive?

    Only if you have a floppy disk with the correct driver on it to hand during the install.

    Oh sorry! I was thinking of the easy to install, desktop-ready Windows XP for a minute then.

    In all seriousness, why would it not install on an SATA drive? The driver for your SATA controller is probably already builtin to the kernel.

  4. Troll's a bit harsh don't you think? on Red Hat CEO Szulik on Linux Distro Consolidation · · Score: 0, Troll

    I think modding the parent "Troll" is a little harsh don't you? I thought it was quite funny.

    I know you Americans tend to be a bit sensitive about your president, but you really shouldn't. I think it reflects well on the American people that they are so confidently in favour of equality that they can demonstrate it be electing a retard as their leader. What other country would have the balls to do that?

  5. Re:You just now heard of Snort??? on CheckPoint Acquires Snort · · Score: 1

    Snort runs on my IPCop firewall and scans for baddies trying to get in.

    It runs on your firewall?

    Wouldn't you be better off running it inside your firewall where it is actually useful? Or does looking at huge logs of attacks bouncing off your firewall make you feel special in some way?

    You want to know about attacks that get through the firewall not all the script kiddie shit that gets blocked.

    And shall we talk about the security problems with your setup? No, let's not bother.

  6. Re:No sh*t Sherlock on Jamming Cellphones with Text Messages · · Score: 1

    You can actually manage the level of service you offer to get around this and give priority to 999 (911) calls and calls made by handsets owned by the emergency services (and network engineers).

    A point that a number of others have made (rightly or wrongly) is that SMS uses the control channel. If the control channel to any particular tower is flooded, how do you setup a call? Surely you can only give priority to certain calls once the calls have actually been setup?

    What you've done sounds like setting up QoS on a router. Which probably doesn't help much if the router is being DoS'ed out of existance.

    What am I missing?

  7. +5 WTF? on Jamming Cellphones with Text Messages · · Score: 1

    Everybody on the count of three! Start text messaging microsoft.com as fast as you can! From there we'll move on to Yahoo.com, and maybe even cnn.com for fun!

    I tell you what - if you can explain how one sends an SMS to microsoft.com, yahoo.com or anyotherfuckingsite.com then I'll laugh at your joke.

    Did you think we were talking about MSN Messenger or something? Because that doesn't make any fucking sense either.

    Also, could the person that modded this up please report for sterilization? Thanks in advance.

  8. Re:Gentoo users moms on Free Gentoo Technical Support · · Score: 1

    My job doesn't actually allow me to troubleshoot Linux but this customer was upset because she didn't know anything about linux, so I helped her get back online.

    Whereas if it had been running Windows she would surely have fixed the problem herself.

    I see two possibilities here. The first is that you really do work in an ISP's support department, are both knowledgable and experienced, and go out of your way to bend the rules and help people.

    The second is you're just trolling.

    Obviously, the first possibility is overwhelmingly likely to be correct and we can surely discount the second.

  9. Re:For firewalls and/or routers on Clustering vs. Fault-Tolerant Servers · · Score: 1

    OpenBSD is such a breath of fresh air in contrast to the moldy scent of Linux. I'll be firing-up my 3rd OpenBSD box here next week - Yeah, people...SUPRISE!!! I'm not an OSS bigot like 98% of you think I am!

    98% think you are? To get a figure like that assumes that there must be at least 50 people on Slashdot who have some sort of opinion about you. I think that you are massively overestimating your own significance.

    I have no doubt that you have constructed yourself an elaborate belief system in which your "controversial" views are suppressed by the liberal elite. The truth is that you're just rather dull. Have you considered starting a blog?

  10. Re:Microsoft Windows? on Heap Protection Mechanism · · Score: 2, Insightful

    Could this technology be implemented in the Microsoft Windows systems to be more secure than Linux?

    It certainly could be implemented, but it would have the slight drawback that a huge proportion of apps would stop working.

    It's going to break a lot of stuff on OpenBSD as well, but because of their audience they can get away with e.g telling you not to run Apache because it's insecure. Also, the OSS apps that break because they assume a specific memory management model will get fixed. No-one is going to be able to fix Windows apps except the developers. And if they even bother they will just expect you to buy the new version.

    And you seem to be saying that implementing this one feature on Windows will make it more secure than $OtherOS. I initially thought you might be trolling, but I've decided to give you the benefit of the doubt and just assume that you either know nothing about security or are making a lame attempt at humour.

  11. Re:bd-java on Blu-Ray Attacks Microsoft, Microsoft Bites Back · · Score: 0, Troll

    am i the only one who'd like to simply have a button on the remote-control called PLAY_THE_MOVIE ?

    There's another button you might be interested in. It's called "Shift" and you will find it on the keyboard in front of you if you look hard enough.

    It has a number of amazing capabilities, the most relevant one being its ability to increase your apparent mental age by at least ten years.

  12. Re:Coolant is toxic, avoid if you have pets/kids on Silent Water Cooling on the SLI · · Score: 1

    The ethylene glycol coolant included with this is very toxic.

    Unless I'm mistaken, ethylene glycol is just plain old anti-freeze isn't it?

    Since you're clearly "thinking of the children", doesn't it need to be banned from cars/garages as well? Why is it more dangerous when used in a computer? Did you know that ingesting petrol is also dangerous to children and animals? And yet there are still no safety devices on petrol pumps to stop children walking up and putting the nozzle in their mouths. Since you're clearly a concerned American, I suggest you launch a class action lawsuit against these evil child killers. The worldwide publicity this will generate will surely serve to reinforce America's reputation as the land of common sense.

    How about teaching your child that ingesting fluid that leaks from a machine is not such a good idea? Is that really so hard? And if they're too young to learn this, here's another idea you can use - try watching what they are doing.

  13. Note to posters on Apple to Replace Faulty Nano Screen · · Score: 1

    Admitting than an Apple product has a flaw of some kind does not automatically lead to shrinkage of your penis.

    I hope you don't think I'm trying to troll, I really just wanted to offer you all some reassurance on this point. Judging from some of the more defensive posts here, I am guessing that many of you are living in fear unnecessarily.

  14. Re:Bah! on Red Hat Seeks to Deliver Most Secure Linux · · Score: 1

    A 4-layer OS is the answer.

    Ha! Don't even bother releasing your pathetic 4 layer OS!

    My company is working on an 8 layer OS, so it will be twice as secure as yours.

    In all seriousness, if you wonder why you keep getting flamed, try and keep in mind the phrase "extraordinary claims require extraordinary evidence". People making extraordinary claims without evidence to back them up are filed in the drawer labelled "astroturfers".

    I will believe your OS is as secure as you say when :

    a) It has actually been released.
    b) It has been audited by someone other than you.
    c) It has been attacked and survived.

    Microsoft tell us that Windows is secure and frankly they have more credibility than you do currently.

    Although one point in your favour is that your OS is targeted at Itanium which is about the ultimate in "security through obscurity".

    How many Itanium servers are exposed to the Internet? This isn't a rhetorical question - I expect you to actually count them and report back with the numbers. Half an hour long enough?

  15. Re:The SELinux Devil... on Red Hat Seeks to Deliver Most Secure Linux · · Score: 1

    2. My experience turning on SELinux in FC was not good. I attempted to build a firewall with IDS and the IDS just didn't work. I'm not a coder, nor am I a really strong Linux Admin, so bye-bye SELinux and the firewall/IDS worked like it should.

    Yes - insecurely. You really shouldn't put an IDS on the same machine as a firewall. Ideally an IDS should be on an isolated box with a one-way network connection (there are HOWTOs that will tell you which of the wires in the ethernet cable you have to cut).

    The reason is that an IDS is by nature really prone to attack. Think about it - it spends all day dissecting and parsing every single packet that comes into your network. It takes a huge amount of code to be able to parse every type of packet and if there's a single buffer overflow in any of that code you've just potentially compromised your firewall.

    I suggest you look at the number of security advisories that Snort has had (that is what you're using isn't it?). Doesn't mean it isn't a great product but you shouldn't assume it isn't an attack vector. For an even better example, read up about the Witty worm which attacked a commercial IDS.

    Finally, an IDS is only useful if you have somebody experienced enough to interpret and filter the logs. I'm not trying to insult you, but the fact that you have put your IDS on the same machine as your firewall suggests that you don't yet have the level of experience to do this effectively.

  16. Re:Well, they do have a point... on SSH Claims Draw Open Source Ire · · Score: 1

    The OpenSSH developers don't have any problem pushing back enterprise features such as partial authentication. In fact, they aren't even SLIGHTLY interested in supporting it even though there are patches out there that implement such a feature.

    This is just a wild stab in the dark, but is it possible that they don't have a fucking clue what you're talking about because you didn't bother to explain it? You know, in the same way that nobody here has a clue what you're talking about because you didn't bother to explain it?

    Anyway, if partial authentication is such an important feature for your "enterprise", how about your enterprise gets off its fat corporate ass and does something about it?

    Actually, I've just done some research and it turns out that my employer has been asking the OpenSSH developers for a version with no authentication at all. And you're right - they're just not interested! They keep mumbling something about security. Fucking arrogant, lazy, self-interested open source bastards aren't they? What the fuck do they expect us to do? Get one of our programmers to do it? Do they not know how much that would cost us?

  17. Re:Poor research / lack of knowledge on ATI Launches Crossfire... Finally · · Score: 1

    Limited only if you read the original DVI spec. How does he think people run the HP and Apple 23" displays and the Dell 24" display over a single-link connection?

    The trouble is that the max resolution of the Crossfire solution isn't limited by the single DVI link - it's limited by the max bandwith that the compositing chip can deal with.

    So they were wrong to identify DVI as the source of the problem. And you have further muddied the waters by ranting about dual DVI as the solution. Hope this helps.

  18. Re:Am I the only one? on Poisoned Torrents Plague Mybittorrent · · Score: 1

    Thank you. Your single anecdotal account of your problems with Bittorrent have convinced me that it is a complete waste of time and energy. Usenet is a much better choice - BT has nothing to compare to the feeling you get when you near the end of a large download, only to find that part 1112/1512 has expired from the server.

    Your inability to use capital letters only helps to drive the point home.

  19. Re:Slightly OT question.... on Dell Launches Flash Music Player · · Score: 1

    So why on earth don't they include AM too?

    Size of aerial required due to wavelength used. Hope this helps.

    On an offtopic note, what about the amazing new look of Slashdot? It's almost like they've taken the old shitty look, changed a few fonts and...er, um.. hey! there's a border round the comment box! Gee, I wonder if the HTML is just as shitty?

  20. Re:DO NOT on Mars Orbiter Sees Changes · · Score: 1, Troll

    So, you've extrapolated all of the above from 3 years of indirect observation of a planet completely different from our own?

    Don't you think that says a lot about how desperate you are to believe those theories?

    Let's try something:

    Carbon Dioxide is a greenhouse gas (i.e it causes infra red radiation to be reflected back to Earth) - agree or disagree?

    We are releasing a lot of CO2 from burning fossil fuels - agree or disagree?

    If you disagree with those well proved theories you are a crank, plain and simple.

    If you agree, then how exactly have you convinced yourself that we will not eventually cause some degree of climate change? You can argue about the degree and the timescale, but your little rant seems to rule it out completely.

  21. Re:does that come with MMX? on Intel Developing Ultra-Low Power Chips · · Score: 1

    Just re-release the P66.

    You mean the original Pentium 66, one of the first Pentiums to be released, right?

    The one that had to be recalled, as it had a nasty habit of burning out due to excessive power consumption.

    I'd love to believe that you knew that and were being ironic. But this is Slashdot.

  22. Re:It's a scam on The Portable Linux Based GP2X is Here · · Score: 1

    No, they did not. I have been told by them not to mention any more here, but if you would email me, I can put you in touch with them.

    No one is going to e-mail you because this is the most transparently obvious and least skillful troll that Slashdot has ever seen.

    That is not your e-mail address - if it exists at all it is probably the address of somebody you are stalking. This kind of shit has been tried for years, mostly on Usenet. But you're too fucking dumb to use a Usenet client so instead we get stuck with your bullshit.

    There are easier ways to flood someone's inbox if you're not chronically retarded.

    For fucks sake, you're not even clever enough to open a new Slashdot account. Or have you not noticed that all your posts start at zero? That means you have been officially designated as a "fucktard". A fucktard is like a troll but without enough skill to actually annoy anyone.

    In summary, you are an attention seeker who has failed to attract much attention.

    Don't assume that this reply is attention. I am merely trying to encourage a higher standard of trolling. You have failed it so badly that your posts provide excellent examples of how not to do things. I hope they might serve as a warning to others.

  23. Right then. on IE More Secure Than Mozilla? · · Score: 2, Insightful

    Hands up anyone who has contracted spyware/adware/viruses through IE.

    Ok, now hands up anyone who has contracted spyware/adware/viruses through Mozilla/Firefox.

    Your honour, I rest my case.

  24. Should have used BSD.... on Linux-Powered Humanoid Robot on Sale Friday · · Score: 5, Funny

    ...like I am for my robot project.

    Basically, I have grown sick of the whole "BSD is dying" "Oh no it isn't!" arguments and have decided to settle the matter once and for all.

    As such, I am currently completing the construction of a 200 foot tall killer robot equipped with nuclear tipped missiles, dual chainsaw attachments and the obligatory friggin' laser beams coming out if its head.

    Once finished, I am going to set it to work tracking down every last BSD developer on the planet and executing them in a variety of colourful ways (starting with that asshole Theo of course). When the project is complete, we will all know that BSD is in fact dead.

    So why not use Linux I hear you ask? Simple - it's the GPL licence. Obviously my robot requires a lot of proprietary code - device drivers for the death rays and odour recognition software (I figure this is the easiest way to track down open source programmers) to name but two.

    If I had chosen the GPL, I would be forced to release this code back to the community. And then it's just a matter of time before some gawky twat with an Apple Newton somehow uploads a virus and foils my plans. The BSD licence enables me to keep this code secret which I'm sure you'll agree is a huge benefit to my project.

    Hooray for BSD! Goodbye karma!

  25. Of course it's responsive..... on BeOS Lives on in the Form of Zeta · · Score: 1

    ....because compared to modern Windows/Linux/OSX it doesn't fucking do anything!

    Multiuser? No.
    3D? Hardly.
    High performance networking? Dream on.
    Hardware support? Well, apparently it supports some hardware.
    Stability? About the same as a one armed alcoholic on a unicycle.
    Commercial software? I heard they were planning to port Cubase about 5 years ago.

    Look, it was technically impressive. About 7 or 8 years ago. And what stunning innovations have been introduced since then? Other than the fact that the price has gone up.

    There were some really stunning tech demoes on the Amiga a decade ago. Now they're a bit long in the tooth. See the connection?

    I contend that if you took a recent Linux kernel, stripped out everything that BeOS doesn't have, wrote a window manager with no features and used something simple like DirectFB (which still probably supports more graphics chips than BeOS) it would absolutely cream BeOS. And still have more features.

    I'm sure this sounds like a troll, but whenever I hear someone talking up BeOS as a viable modern OS, I consider them to be trolling. After all, someone might actually believe them and spend real money on a mid-nineties tech demo.

    PS. Zeta looks like a fucking train wreck, so don't give me this "simple and elegant" bullshit.

    PPS. I haven't even mentioned Zeta's business practices. I bet all those Germans that bought it off their shopping channel when it was advertised as "Windows XP without the viruses" are real fucking happy with their purchases.