Archive for September, 2009

EXPLOIT ALERT: Reddit Attacked By Javascript Comment Bomb

Monday, September 28th, 2009

Thanks again to Mashabul for this warning. The from an original article by them.



Reddit fans beware: a very effective XSS (cross site scripting) attack is currently live on the site: even hovering over a comment will cause your account to post scores of rogue comments. Turning off javascript before visiting may prevent the attack, or you may simply wish to avoid Reddit until the attack is brought under control.

The attacker appears to have figured out how to insert javascript into Reddit comments: thus, hovering over such a comment is all it takes to spread the exploit. We’re not aware of anything being downloaded to your machine at this point: only a XSS attack that posts the troublesome comments in your name.

At the time of writing, Reddit is offline.

Update: contrary to the first version of this post, it appears your old comments are not overwritten: the attack only spawns new ones. We’ll update as we learn more.

Thanks to @harknesslabs for the tip-off.

redditcommentbomb


Posted via email from scottherbert’s posterous

Now there is less excuse not to use something other than IE

Tuesday, September 22nd, 2009

I’ve complained a number of times about the attitude of some web professionals towards throes who are stuck using IE6 (or 7 or for that matter 8). The convert or your a moron attitude, will always fail to win converts, especially when the people your calling morons have no choose about what browsers they are stuck using.

Thankfully people are starting to lesion and start thinking how throes people who are stuck using old out-of-date browsers can still access high performance websites like Google wave.

First their was the “Hay IT” campaign which still used the same bully boy tactics but at least was targeting the right people.

Now Google have released Chrome Frame a plug in for IE 6, 7 or 8 on the PC (If your using Linux or a Mac and are using IE… then maybe you are a moron… as your default browser will be better) that will allow you to experience the power of a standards complaint web browser without having to upgrade yours.

Chrome Frame won’t over write IE and the Chrome engine is only called if a special meta tag is found on the web page, and it’s unknown if throes IT departments who won’t allow users to use a good browser will allow people to install Chrome Frame, but at least it’s a step in the right direction.

What your Facebook Friends say about you.

Monday, September 21st, 2009

In an as yet unpublished scientific study two MIT students have shown that you can predict a person’s sexuality and religion as well as other personally information not just by studding them, but their facebook friends as well.

This sounds shocking until you think about it… Gay men tend to have more gay friends than straight men… that are not unsurprising, nor is it unsurprising that people with similar political or religious views like to hang out together.

Anyone with an insight into network theory would be able to tell you that. What’s interesting is that you can put numbers on it.

The music industry is determined to kill… the music industry.

Friday, September 18th, 2009

What a tangled web we weave…

First there was shops and CD’s, and the music fans wanted to hear their favour bands on their computer, and so the .WAV file was born, but the .WAV file was huge and so the .MP3 file format was born, and music fans wanted to the their friends so they shared their MP3 files, and internet music piracy was born.

But the fat music moguls didn’t like the fact that music fans were not spending their money on music but getting it from their friends, so the sued the music fans. Then the business world stepped in, “hay” they said “You like music on your computers”, “YES” the fans screamed. “and you like money don’t you?”. “YES” screamed the moguls, “So I’ll SELL you music on-line and give some of the money to the moguls”, “Hurray!” they all screamed.

And so everyone was happy, but then the moguls said “ummm… we can make MORE money” and so they said to business, “Give us more of your MONEY!” and so the business said “err… OK” then the moguls saw that the business where letting the fans hear a whole 30 seconds of music and not pay for it. “OH! We want more money off you! For letting Fan’s her 30 seconds of our songs”, “but… but… we’ll have to pass the costs on to fans and the fan’s won’t like it!” “No excuses” Screamed the moguls.

And so the businesses started to put their prices up, and the fan’s said “We can’t pay that! My friend has it and I can get it from them… just don’t tell the moguls” and so they did… and so the businesses started to close down, and the moguls looked and cried and cried and cried….

A story based on a Mashabul article about the music industry going after licensing fees for the 30 second track previews used by iTunes and other music stores, this kids ant’ no fairy tale.

View article…

Posted via email from scottherbert’s posterous

Tag, your it! – How to tag people in your facebook status

Wednesday, September 16th, 2009

Facebook has long had the facility to tag photo’s of your friends and family, in fact it’s often cited as one of the main reasons people switched from MySpace to it. However until recently you haven’t been able to tag your friends in your status.

Now you can! Well maybe you can, it’s something that facebook have been rolling out over the last few week’s I believe however not everyone has the ability to tag their friends.

So why? Why would you want to tag them? Traditionally facebook’s status has been a fairly private thing, it tended to be just about what you where up to and what you did, that because it tended only to be a very few who read it. Then last year facebook had a big change, and when’t real time, allowing users to see and comment on their friends up-dates with ease, and with it the way we use facebook our status up-dates changed as well.

Just as the 2008 upgrade due in part to the explosion in use of a new social media tool, Twitter, so the ablity to tag status upgrade is lifted from the same tool. In twitter for throes who don’t know, you can tag your friends by prefixing their user name with an @ symbol (see below for how this looks in real life).

tag a person in facebook

tag a person in facebook

Facebook have taken this and ran with it, with this upgrade you can not only tag people but also events, fan pages, events and applications.

tag a fan page in facebook

tag a fan page in facebook

tag an application in facebook

tag an application in facebook

These messages are then posted to your wall as well as throes of everyone you’ve taged.

It will be interesting to see if re-tweeting (or RT’ing), the twitter practice of re-posting an update while citing the original author gets a facebook equivalent (re-facing maybe :)

Let us know what you think about this twitter inspired taging, will you use it? Is it too much like twitter? Or do you think it’s a waste of time?