• About Bipin 3 Upadhyay

    Proposal for a new Array Syntax in PHP

    by  • January 13, 2008 • news, php, programming • 0 Comments

    A new array syntax has been proposed (for quite some time) for defining arrays in PHP. Currently, we use array() construct to create an array. Some examples could be: $myArray = array(1, 2, 3, 4, 5); $yourArray = array(1 => “one”, 2 => “two”, “three”); $herArray = array(1, 2, 3, array(4 => “four”, “five”)); The [...]

    Read more →

    Yahoo!’s javascript based media player!

    by  • January 9, 2008 • code, demo, download, life, music, news, script, yahoo • 10 Comments

    Yahoo! launched it browser based media player written in javascript. All you have to do is link the javascript code (located at http://mediaplayer.yahoo.com/js) in a web page having links to audio file(s) . Although it takes a while for the “player” to load completely, yet I am pretty okay with it (for now). Moreover, it’s [...]

    Read more →

    What a new year Gift! :)

    by  • January 5, 2008 • news, review, security, w3af, webappsec • 0 Comments

    It brings me immense pleasure to inform you that w3af (web application attack and audit framework) has been named the Best Application Scanner in BEST IT Security and Auditing Softwares 2007 list prepared by Security Database. I had mentioned in a few previous articles that I see immense potential in w3af. I must, however, also [...]

    Read more →

    AdSense exploited by malware (Trojan.Qhost.WU)

    by  • December 22, 2007 • bug, education, google, irony, life, loophole, news, security, webappsec • 5 Comments

    1. Life & Code (The title of this section is taken from Johnny’s blog of the same name, Life and Code. Although my implementation of the phrase isn’t in terms with Johnny’s, yet I could resist using it. ) Life: Three days ago I found that there are some strange entries in my local Apache [...]

    Read more →

    Orkut Latest XSS Worm; and what it means for Indian Orkuteers

    by  • December 20, 2007 • cyberlaw, defacement, education, google, guide, irony, life, news, review, security, webappsec, xss • 16 Comments

    Update: Kishor reports a flaw in the implementation of “private” videos feature on Orkut. Although I am at office and I haven’t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. 1. YAWN [Yet Another Worm, Nanny] Orkut (Google’s MySpace and Facebook for Indian, Pakistan [...]

    Read more →

    Drive-by Download: Where Network Security Meets WebAppSec

    by  • November 2, 2007 • demo, education, hack, loophole, security, webappsec • 5 Comments

    DEMO This post was due since the Bank of India hack incident, and was fueled by PDP’s Drive-by Java post, which is a very simple, yet a well thought of extension (sort of) to the Drive-by Download attack. This post is aimed to provide a clearer understanding of the Drive-by Download attack (via a demo). [...]

    Read more →

    The Web is Broken

    by  • October 12, 2007 • csrf, defacement, google, hack, hackers, humour, life, review, script, security, webappsec, xss • 0 Comments

    Update: I somehow managed to make a blunder. A part of slide no. 12 was taken from David Kierznowski’s (of GNUCitizen and Blogsecurity group) presentation for OWASP Belgium Conf. I missed out on mentioning David’s name is the credits. Apologies David. I’ve updated and re-uploaded it. Yesterday, I presented my first Webinar (Seminar on Web). [...]

    Read more →

    Yahoo! gone Insane!

    by  • August 11, 2007 • humour, irony, news, review, yahoo • 0 Comments

    No Yahoo! hasn’t changed it’s name to Insane!. It’s just their behavior that has gone insane. If you’ve been a member of some online group for quite some time, chances are that the group is on Yahoo! Groups. Same with me. This story is concerned with my college batch online egroup. Yahoo! groups has a [...]

    Read more →

    Apache Headache: “no listening sockets available”

    by  • August 8, 2007 • apache, bug, education, guide, humour, life, microsoft, mysql, php • 5 Comments

    Update 1: I was unable to configure MySQL. Reason: It was installed in C:\(blah-blah) and , probably, do not have write rights in the directory. Installing it to D:\(bigBlah) solved the issue. Duh! Update 2: I see a fairly good traffic coming here searching for the same problem. So, in case you are in a hurry, [...]

    Read more →

    Fake Steve Jobs Revealed

    by  • August 6, 2007 • apple, humour, news • 0 Comments

    Arpit had a joint post on the probable revealation of FSJ (Fake Steve Jobs), along with the info on Exif Data revealations of the Harry Potter book images. Anyways, the new news is that FSJ has been busted for real. It’s work of a New York Times reporter Brad Stone. The FSJ is Daniel Lyons, [...]

    Read more →

    Java vulnerable to remote compromise

    by  • July 14, 2007 • bug, google, hack, hackers, Java, loophole, review, security, Sun • 0 Comments

    ZDNet Asia reports that Google Security team has discovered as “Dangerous Java Flaw that threaten’s Virtually Everything“. The interesting part of this news is that, apart from a few scary statements, it doesn’t inform you anything else. The Sun advisory page on this flaw, however, informs you about two flaws which are nothing but Buffer [...]

    Read more →

    TPM Boys withdraw paper from BlackHat USA

    by  • July 5, 2007 • bug, code, hack, hackers, irony, loophole, microsoft, news, review, security • 0 Comments

    I hope you remember the young Indian security researchers Vipin Kumar (22) and Nitin Kumar (23), the TPM Boys [I guess, that's the way they call themselves. At least their blog confirms that. ]They presented a Paper “Vboot Kit: Compromising Windows Vista Security” at Blackhat Europe – 2007. The talk explained the (different) booting process [...]

    Read more →