<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Code in my Bug! &#187; google</title>
	<atom:link href="http://projectbee.org/blog/archive/category/google/feed/" rel="self" type="application/rss+xml" />
	<link>http://projectbee.org/blog</link>
	<description>Bipin&#039;s experiments with life, society, programming, hacking, &#38; other stuff</description>
	<lastBuildDate>Mon, 23 Jan 2012 18:49:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>[How To] Implementing Shindig.</title>
		<link>http://projectbee.org/blog/archive/how-to-implementing-shindig/</link>
		<comments>http://projectbee.org/blog/archive/how-to-implementing-shindig/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 05:07:03 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[apache]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[opensocial]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[bcb7]]></category>
		<category><![CDATA[phpcamp]]></category>
		<category><![CDATA[phpcamppune08]]></category>
		<category><![CDATA[ppt]]></category>
		<category><![CDATA[shindig]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=146</guid>
		<description><![CDATA[I should have written an article/tutorial on how to implement/use Shindig to convert your SNS into and OpenSocial compliant SNS. Time, however, has prevented me from doing it so far. May be sometime later. For now, you can have a look at my presentation on the same topic. I had presented it at Barcamp Bangalore [...]]]></description>
			<content:encoded><![CDATA[<p>I should have written an article/tutorial on how to implement/use Shindig to convert your SNS into and OpenSocial compliant SNS. Time, however, has prevented me from doing it so far. May be sometime later.</p>
<p>For now, you can have a look at my presentation on the same topic. I had presented it at Barcamp Bangalore 7, and PHPCamp Pune. <strong>It was recommended by Dan Peterson, Google, on the Shindig developer&#8217;s mailing list. </strong> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>For those who don&#8217;t have an idea what I am talking about; I have been (officially) working on OpenSocial for quite sometime. OpenSocial is a specification developed by giants like Google, MySpace, Ning, etc. to provide a common platform (API) for social app developers. <a href="http://incubator.apache.org/shindig/">Shindig, an Apache incubator project,</a> is what can help your site become OpenSocial compliant.</p>
<div id="__ss_616171" style="width: 425px; text-align: left;"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" title="[Phpcamp]Shindig An OpenSocial container" href="http://www.slideshare.net/bipin/phpcampshindig-an-opensocial-container-presentation?type=powerpoint">[Phpcamp]Shindig An OpenSocial container</a><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=phpcampshindiganopensocialcontainer-1222280536661323-9&amp;stripped_title=phpcampshindig-an-opensocial-container-presentation" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=phpcampshindiganopensocialcontainer-1222280536661323-9&amp;stripped_title=phpcampshindig-an-opensocial-container-presentation" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View SlideShare <a style="text-decoration:underline;" title="View [Phpcamp]Shindig An OpenSocial container on SlideShare" href="http://www.slideshare.net/bipin/phpcampshindig-an-opensocial-container-presentation?type=powerpoint">presentation</a> or <a style="text-decoration:underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration:underline;" href="http://slideshare.net/tag/shindig">shindig</a> <a style="text-decoration:underline;" href="http://slideshare.net/tag/phpcamp">phpcamp</a>)</div>
</div>
<p>By the way, I am referring to the <a href="http://en.wikipedia.org/wiki/Six_degrees_of_separation"><strong>Six degrees of Separation</strong></a> in the initial slides. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/apache-mysqlphp-installation-configuration-tutorial-for-beginners/" rel="bookmark" title="February 25, 2006">Apache-MySQLPHP Installation &#38; Configuration Tutorial for Beginners :)</a></li>

<li><a href="http://projectbee.org/blog/archive/the-web-is-broken/" rel="bookmark" title="October 12, 2007">The Web is Broken</a></li>

<li><a href="http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/" rel="bookmark" title="May 26, 2007">An insight into Sun&#8217;s *crazy* strategy.</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-headache-no-listening-sockets-available/" rel="bookmark" title="August 8, 2007">Apache Headache: &#8220;no listening sockets available&#8221;</a></li>
</ul><!-- Similar Posts took 4.642 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/how-to-implementing-shindig/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Slashdot, uh! :&#124;</title>
		<link>http://projectbee.org/blog/archive/slashdot-uh/</link>
		<comments>http://projectbee.org/blog/archive/slashdot-uh/#comments</comments>
		<pubDate>Wed, 21 May 2008 07:31:56 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[rant]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cyberlaw]]></category>
		<category><![CDATA[dumb]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[orkut]]></category>
		<category><![CDATA[slashdot]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=99</guid>
		<description><![CDATA[Slashdot is supposed to be a respectable (news) portal for geeks and nerds. It&#8217;s punch line says News for nerds, Stuff that matters. I must admit that there was a time when I used to start my day with Slashdot, trying not to miss even a single news. That phase, however, is over. The two [...]]]></description>
			<content:encoded><![CDATA[<p>Slashdot is supposed to be a respectable (news) portal for geeks and nerds. It&#8217;s punch line says <em><strong>News for nerds, Stuff that matters</strong></em>. I must admit that there was a time when I used to start my day with Slashdot, trying not to miss even a single news. That phase, however, is over. The two biggest problems with Slashdot today are:</p>
<p>1. <strong>The Slashdot community</strong>, which is getting reduced to people who lurk around to post comic and sarcastic comments. It&#8217;s very seldom that you come across an intelligent and <em>insightful</em> comment.<br />
2. <strong>The news</strong>, if I may say so, <strong>itself</strong>.<br />
<!--start_raw--><br />
<br />
<!--end_raw--><br />
<img src="http://farm3.static.flickr.com/2113/2216511038_75f48a003d_d.jpg" alt="By flickr.com/photos/nesster/" width="421" height="279" /><br />
<!--start_raw--><br />
<br />
<!--end_raw--><br />
This rant is a direct result of a news titled <a href="http://tech.slashdot.org/article.pl?sid=08/05/19/148208">Google Assists In Arrest Of Indian Man</a>, posted on 19th. First of all this is <strong>an Old News</strong>. In fact I&#8217;d used the context to post <a href="http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/">a legal analysis of the impact of another Orkut worm</a>, as per my knowledge and belief. I have nothing against reading old news, but for God&#8217;s sake, don&#8217;t claim it to be new.</p>
<p>Secondly, the post cites Shivaji as a saint. He was not a saint. He was a king and a warrior. Do your homework before posting, or rather approving such news.</p>
<p>Thirdly, the tone in which the post is written is as vague, if not more, as the point the post tries to make. If you wish to blame Google, get proper info before doing that. Google has a pact with Indian law enforcement. They are bound to provide such info. If you wish to convey the news that a false person was convicted, say it. If you wish to bring about the role of Yahoo! and Google in such cases, do it properly.</p>
<p>Being said all that, I don&#8217;t think I&#8217;ll <strong>completely </strong>stop reading <strong>/.</strong> . However, the prestige of being Slashdotted now seems to be just about traffic now.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>

<li><a href="http://projectbee.org/blog/archive/how-to-implementing-shindig/" rel="bookmark" title="September 30, 2008">[How To] Implementing Shindig.</a></li>

<li><a href="http://projectbee.org/blog/archive/tpm-boys-withdraw-paper-from-blackhat-usa/" rel="bookmark" title="July 5, 2007">TPM Boys withdraw paper from BlackHat USA</a></li>

<li><a href="http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/" rel="bookmark" title="December 20, 2007">Orkut Latest XSS Worm; and what it means for Indian Orkuteers</a></li>

<li><a href="http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/" rel="bookmark" title="January 28, 2006">&#34;COLUKABKI &#8211; AOL &#8211; MSN &#8211; YAHOO &#8211; RED CROSS&#34;&#8230;.. aaah Comm&#8217;n Gimme a break.</a></li>
</ul><!-- Similar Posts took 6.732 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/slashdot-uh/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A Phish floating in Google Survey!</title>
		<link>http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/</link>
		<comments>http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/#comments</comments>
		<pubDate>Tue, 29 Jan 2008 16:24:26 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[demo]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/?p=68</guid>
		<description><![CDATA[Demo 1. Phizy-Phizy-Phizy I have always loved making this phizy-phizy-phizy sound purposelessly, which I once heard in a Rob Schneider movie (which, if I remember correctly, was a pathetic movie). Anyhoo! I, now, have a set of very strong reasons to move around repeating the same lines. First, we received a request to be involved [...]]]></description>
			<content:encoded><![CDATA[<h3><span style="color: #3366ff;"><strong><a href="http://yahoo-survey.99k.org/">Demo</a></strong></span></h3>
<h3><span style="color: #3366ff;"><strong><a href="http://yahoo-survey.99k.org/"></a></strong></span> <span style="color: #3366ff;"><strong>1. Phizy-Phizy-Phizy</strong></span></h3>
<p>I have always loved making this <em>phizy-phizy-phizy</em> sound purposelessly, which I once heard in a <a href="http://www.imdb.com/name/nm0001705/">Rob Schneider</a> movie (which, if I remember correctly, was a pathetic movie). Anyhoo! I, now, have a set of very strong reasons to move around repeating the same lines.<br />
First, we received a request to be involved in a discussion for a Risk Assessment Model for a Banking site. This model had to be focussed on Two Factor Authentication and <strong>Phishing</strong>. This brainstorming gave me a couple of interesting avenues to work on. Hopefully, I&#8217;ll be writing more in this pretty soon.<br />
Secondly, <a href="http://jtrac.info">Peter Thomas</a> (one of my amazing Bosses), forwarded me the link about the <a href="http://www.net-security.org/article.php?id=1110">latest research</a> by <a href="http://www.dhanjani.com/blog/2008/01/bad-sushi-beati.html/">Nitesh Dhanjani</a> &amp; Billy Rios. They virtually infiltrated the Phishers ecosystem and have come up with some very interesting information.<br />
Thirdly, my friend <a href="http://theaveragelife.wordpress.com/">Swen</a> called me up to let me know about a phishing mail, claiming to be a Google survey, that had landed in his mailbox. He was excited for two reasons:<br />
a) He had received a phishing mail for the first time, and I guess you all remember the excitement the first time you discovered your first phishing mail.<br />
b) He is one of the Google fans, and is worried about the safety of the vast majority of user-base Google has. Obviously, his concern isn&#8217;t without reasons.<br />
<img src="http://s3.amazonaws.com/projectbee/img/Phishes.jpg" alt="by-mcbeth www.flickr.com/photos/mcbeth/235875/" width="498" height="368" /></p>
<h3><span style="color: #3366ff;">2. A Phish named GoogleSurvey</span></h3>
<p>As I mentioned Swen informed me about the shiny phish called GoogleSurvey. It presents you a page that looks completely similar to the Google Login page and requests you to login in order to complete the survey. If you login, you are presented with 3 questions on by one. At the end you are thanked for completing the survey.</p>
<h3><span style="color: #3366ff;">3. Anatomy of Google-Survey-Phish gills</span></h3>
<p>The Google Survey Phish isn&#8217;t sophisticated y ANY standards. Clearly, it&#8217;s done by some n00b, and was probably deployed using a very cheap Phishing Kit. However, it&#8217;s really interesting to understand how it works.<br />
The first page the you encounter while analyzing is <a href="http://www.googlesurvey.co.nr/">http://www.googlesurvey.co.nr/</a>, which I must admit, looks very similar to the Google Mail login page. A look at the source code reveals that this is not the original page. The google mail look-alike page is alike page is actually located at <a href="http://googlesurvey.99k.org/">http://googlesurvey.99k.org/</a>. http://www.googlesurvey.co.nr/ only frames the page at with 100% width and 0px border.</p>
<p>Another interesting point to note is that the phisher used a free hosting service http://www.zymic.com/free-web-hosting/. Thus, theoretically he/she cannot be traced. Not via the hosting service, at least. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Now, when you enter your id and password, the data is sent to a php script on the server located at http://googlesurvey.99k.org/LoginAuth.php. Quite obviously, this script stores/mails your credentials for someone who&#8217;s not a very pleasing person.</p>
<h3><span style="color: #3366ff;">4. <a href="http://yahoo-survey.99k.org/">Demo: Farming your own Phishes for fun &amp; profit *cough*</a></span></h3>
<p>The world of Phishing is so dark, deep, safe, easy, and seductive that a person with even a slight malign would be tempted to this farm his/her own phishes and make easy money. I <a href="http://yahoo-survey.99k.org/">set up my phishing domain for educational purposes</a>. It also shows how quickly you can setup your very own phishing portal, sometimes even without a phishing kit. The domain I&#8217;ve setup has the following flaws (introduced to prevent me getting screwed by some half-witted law enforcer) :<br />
1. The domain points at Yahoo!, while the page displayed is similar to the GMail login page.<br />
2. The information entered is NOT stored. You can check it by entering garbage data.</p>
<p>I have used the same page used by the GoogleSurvey Phish, and also used the same free hosting service.</p>
<h3><span style="color: #3366ff;">5. Conclusion</span></h3>
<p>It&#8217;s almost impossible to prevent users from getting Phished. People will continue to click on links they receive in their inbox and &lt;/sarcasm&gt; proceed to win an ipod &lt;/sarcasm&gt;. Reducing phishing requires a number of things to be in place -sensible developers, well informed end user, smart browsers with phishing aware features (IE7, Fx2 etc.), a few toolbars like NetCraft to be installed, etc. etc. And even doing all this doesn&#8217;t guarantee to save a user ignorant of phshing. I mean how do you save a person who doesn&#8217;t even know that such a kind of fraud exists.<br />
Moreover, the URI vulnerabilities have added another dimension to the whole phishing scene. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/" rel="bookmark" title="January 28, 2006">&#34;COLUKABKI &#8211; AOL &#8211; MSN &#8211; YAHOO &#8211; RED CROSS&#34;&#8230;.. aaah Comm&#8217;n Gimme a break.</a></li>

<li><a href="http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/" rel="bookmark" title="May 19, 2007">Rediffmail Bug. Anyone Interested?</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>
</ul><!-- Similar Posts took 6.231 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>AdSense exploited by malware (Trojan.Qhost.WU)</title>
		<link>http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/</link>
		<comments>http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/#comments</comments>
		<pubDate>Sat, 22 Dec 2007 14:27:14 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[fraud]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/12/22/adsense-exploited-by-malware-trojanqhostwu/</guid>
		<description><![CDATA[1. Life &#38; Code (The title of this section is taken from Johnny&#8217;s blog of the same name, Life and Code. Although my implementation of the phrase isn&#8217;t in terms with Johnny&#8217;s, yet I could resist using it. ) Life: Three days ago I found that there are some strange entries in my local Apache [...]]]></description>
			<content:encoded><![CDATA[<h3><span style="color: #3366ff;"><strong>1. Life &amp; Code</strong></span></h3>
<p><img class="alignleft" style="float: left;" src="http://projectbee.org/blog/wp-content/uploads/2007/12/malware.jpg" alt="By http://www.flickr.com/photos/13798876@N02/1466880287/" width="187" height="184" align="left" /></p>
<p>(The title of this section is taken from Johnny&#8217;s blog of the same name, <a href="http://johnnyjacob.wordpress.com/">Life and Code</a>. Although my implementation of the phrase isn&#8217;t in terms with Johnny&#8217;s, yet I could resist using it. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  )</p>
<p><strong>Life:</strong> Three days ago I found that there are some strange entries in my local Apache web server logs. Something like:<br />
<code>127.0.0.1 - - [18/Dec/2007:19:39:26 +0530] "GET /iview/msnnkhac001160x600Xdig1600000185msn/direct;wi.160;hi.600/01 HTTP/1.1" 404 352<br />
127.0.0.1 - - [18/Dec/2007:19:42:19 +0530] "GET /pagead/show_ads.js HTTP/1.1" 404 320<br />
</code><br />
<strong>Code:</strong> <a href="http://www.bitdefender.com/VIRUS-1000239-en--Trojan.Qhost.WU.html">Bitdefender informs of a malware</a>, termed as Trojan.Qhost.WU, is redirecting all the requests made to the Google&#8217;s ad server (<em>page2.googlesyndication.com</em>) by the victims browser to a rougue ad server.</p>
<h3><span style="color: #3366ff;">2. Impact of the issue:</span></h3>
<p>Reportedly, a big part of Google&#8217;s earnings comes from it&#8217;s Ad services. Thus this trojan is not only depriving Google of it&#8217;s earning&#8217;s, but also the publishers who work hard and hope to make some quick buck for their evening coffee.</p>
<h3><span style="color: #3366ff;">3. The enigmatic &#8220;hosts&#8221; file:</span></h3>
<p>You all know that every system connected directly to the internet is assigned a unique IP address. The domain name (viz. <a href="http://projectbee.org">http://projectbee.org</a>) is nothing but a unique name assigned to a unique IP (although more than one domain name can  be mapped to an ip address, that is not our concern right now). This mapping is stored in DNS servers. Each time the browser tries to open up a site, a nearby DNS server is queried to find the ip address.<br />
However,  before all this, the <em>DNS server</em> of your local system, <strong><em>hosts</em></strong> file, is queried. (Don&#8217;t mistake me, this DNS server is just a metaphor <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). The hosts file stores a domain name to ip address mapping for domains that don&#8217;t need a query to DNS server. e.g., <strong>localhost</strong> is mapped to <strong>127.0.0.1</strong>, the loopback ip, i.e. the ip of local system.<br />
On your windows 2000/NT onwards system, it&#8217;s located at <em>%systemroot%\system32\drivers\etc\hosts</em> and on your *nix systems at <em>/etc/hosts</em>. More info on location can <a href="http://en.wikipedia.org/wiki/Hosts_file#Location_and_default_content">be found here</a>.</p>
<p>Now coming back to my problem; unable to find any satisfactory answer, I <a href="http://sla.ckers.org/forum/read.php?11,18461">posted it on Slackers</a>. (Giorgio) Maone, better known as author of the awesome <a href="http://noscript.net">NoScript plugin</a> for Fx, immediately responded, and asked me to check my hosts file.<br />
I had added a number of entries of ad serving sites to point to the local ip in my hosts file and forgotten. I did this to prevent ads from being loaded. Hence, each time any of these sites were called, the hosts file redirected the requests to my local server.<br />
So pretty obviously, I was/am not infected.<br />
&#8220;Why do you post the junk about your issue then?&#8221;, you ask.<br />
&#8220;Because it was a strange coincidence, and because I can, honey <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> &#8221;</p>
<h3><span style="color: #3366ff;">4. How the exploit works?</span></h3>
<p>It&#8217;s fairly simple, the malware modifies your hosts file and adds an entry for <em>page2.googlesyndication.com</em> to prevent DNS lookups and direct all the requests to the malicious server.</p>
<h3><span style="color: #3366ff;">5. How do I protect myself?</span></h3>
<p>1. Locate your hosts file and remove any entry for <em>page2.googlesyndication.com</em>. Alternately, you can even modify the entry to point to your local ip, in case you don&#8217;t wish to see those ads.<br />
2. Let your Antivirus/AntiSpyware do it for you.</p>
<h3><span style="color: #3366ff;">6. Conclusion</span></h3>
<p>What! Dump M$ Windows for Linux. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /><br />
Seriously, &#8220;Linux ain&#8217;t easy to use&#8221; is a myth. Moreover, if you are into flashy looks, try compiz-beryl package. It IS Awesome&#8230; (and consumes amazingly less resources than&#8230;uh Vista.)</p>
<h3><span style="color: #3366ff;">7. Bonus Tip</span></h3>
<p>In case you wish to prevent your kids, partner, (or even parents) from visiting some sites; or do not wish to see those crappy ads from being loaded, you might consider editing your hosts file. For more information or even sample hosts files, use <a href="http://search.yahoo.com/search;_ylt=A0oGknBwFW1HZj4B0StXNyoA?p=block+sites+with+hosts+file&amp;y=Search">Yahoo! search</a>.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-mysqlphp-installation-configuration-tutorial-for-beginners/" rel="bookmark" title="February 25, 2006">Apache-MySQLPHP Installation &#38; Configuration Tutorial for Beginners :)</a></li>

<li><a href="http://projectbee.org/blog/archive/amazing-interrupt-handling/" rel="bookmark" title="April 12, 2007">Amazing Interrupt Handling!</a></li>

<li><a href="http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/" rel="bookmark" title="July 3, 2007">Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>
</ul><!-- Similar Posts took 6.549 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Orkut Latest XSS Worm; and what it means for Indian Orkuteers</title>
		<link>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/</link>
		<comments>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/#comments</comments>
		<pubDate>Thu, 20 Dec 2007 10:14:39 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[cyberlaw]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[xss]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/12/20/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/</guid>
		<description><![CDATA[Update: Kishor reports a flaw in the implementation of &#8220;private&#8221; videos feature on Orkut. Although I am at office and I haven&#8217;t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. 1. YAWN [Yet Another Worm, Nanny] Orkut (Google&#8217;s MySpace and Facebook for Indian, Pakistan [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #3366ff;"><strong>Update: </strong></span>Kishor reports <a href="http://wasjournal.blogspot.com/2007/12/orkut-private-videos-are-not-private.html">a flaw in the implementation of &#8220;private&#8221; videos feature on Orkut</a>. Although I am at office and I haven&#8217;t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div>
<h3><span style="color: #3366ff;"><strong>1. YAWN [Yet Another Worm, Nanny]</strong></span></h3>
</div>
<h3><img src="http://farm3.static.flickr.com/2084/1735501790_18be4450be_d.jpg" alt="http://flickr.com/photos/aqlott/1735501790/" width="403" height="227" /></h3>
<p>Orkut (Google&#8217;s MySpace and Facebook for Indian, Pakistan and Brazil) has been hit by an XSS worm. It&#8217;s useless to say but I am not able to resist, so I&#8217;ll say it anyways. <em>It&#8217;s not the first time that a Social networking site has been attacked by an XSS worm.</em> In fact these sites are the primary target due to a number of reasons -easier gullibility level, exponential reach, huge amount of data waiting to be harvested, <strong>web 2.0</strong> etc. etc. etc. There&#8217;s good compilation of XSS worms going on <a href="http://sla.ckers.org/forum/read.php?2,14477,18504">at Slackers </a>(Social n/w worm, or no).<br />
Anyhoo. This incident has <a href="http://www.cgisecurity.com/2007/12/17">already been</a> <a href="http://antrix.net/journal/techtalk/orkut_xss.html" target="_blank">reported</a> <a href="http://tkhere.blogspot.com/2007/12/orkut-under-cross-site-scripting-xss.html">by a</a> <a href="http://www.marrowbones.com/commons/technosocial/2007/12/orkut_worm_code_and_why_was_go.html" target="_blank">number of</a> <a href="http://www.gnucitizen.org/blog/the-orkut-xss-worm" target="_blank">bloggers</a>, so I  won&#8217;t dive into the technical details. However, this worm seems to be harmless and fixed for now.</p>
<div>
<h3><span style="color: #3366ff;"><strong>2. What it did?</strong></span></h3>
</div>
<p>If you <strong>view</strong>ed a message <strong><em>2008 vem ai&#8230; que ele comece mto bem para vc</em></strong> in your scrapbook, there is a big probability that you&#8217;re infected. You were added to a community named <em><strong>Infectados pelo Vírus do Orkut</strong></em> at http://www.orkut.com/CommunityJoin.aspx?cmm=44001818. The worm then forwards itself to the scrapbook of all your contacts (on your behalf). Any doubts on it being exponential?</p>
<div>
<h3><span style="color: #3366ff;"><strong>3. </strong><a href="//www.mit.gov.in/download/itbill2000.pdf" target="_blank"><strong>IT Act 2000</strong></a><strong> </strong><strong>[pdf]</strong></span></h3>
</div>
<p>IT Act 2000 is India&#8217;s legal answer to the miscreants on the technological front. (I realize it&#8217;s a pathetic definition, so no flame on it please <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). The trouble with IT Act 2000 is that the majority of law enforcers aren&#8217;t really aware of the real life scenarios. I&#8217;ll give a real case to support the point, in a while. Although I am no law expert (just a little bit of interest), I guess I can safely say that the Act needs a few amendments to include/modify a number of issues (e.g., SPAM, etc.)</p>
<p>So what happens when the implementation is in nascent stage, and the enforcers  are not completely eductaed?<br />
Things get blown out of proportion. Things get painted in a completely new color. Things get&#8230; uh! fill them up yourself.</p>
<div>
<h3><span style="color: #3366ff;"><strong>4. <a href="http://www.indiacyberlab.in/cyberlaws/chapter11.htm">Chapter 11, IT Act 2000</a></strong></span></h3>
</div>
<p>Chapter 11 of the Act defines the <strong>Offences</strong> &#8211; section 65 to section 78.   For now, let&#8217;s have a look at Sections 65, and 67.<br />
<strong> Section 65: Tampering with computer source documents.</strong></p>
<blockquote><p><em> Whoever knowingly or intentionally conceals, destroys or    alters or intentionally or knowingly causes another to conceal, destroy or    alter any computer source code used for a computer, computer programme,    computer system or computer network, when the computer source code is required    to be kept or maintained by law for the time being in force, shall be    punishable with imprisonment up to three years, or with fine which may extend    up to two lakh rupees, or with both.</em><br />
<em> Explanation: For the purposes of this section, &#8220;computer  source code&#8221; means the listing of programmes, computer commands, <strong>design and  layout and programme analysis of computer resource in any form</strong>.</em></p></blockquote>
<p><strong>Section 67:Publishing of information which is obscene in electronic form.</strong></p>
<blockquote><p><em>Whoever publishes or transmits <strong>or causes to be published in the electronic form</strong>, any material which is lascivious or appeals to the prurient interest or if its effect is such as to tend to deprave and corrupt persons who are likely, having regard to all relevant circumstances, to read, see or hear the matter contained or embodied in it, shall be punished on first conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to one lakh rupees and in the event of a second or subsequent conviction with imprisonment of either description for a term which may extend to ten years and also with fine which may extend to two lakh rupees.</em></p></blockquote>
<p>I have mostly been interested in section 67 (which according to some in the law indsutry) also extends to sms service <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Anyhoo. If you are interested in punishmentsm, <a href="http://www.indiacyberlab.in/cyberlaws/computer-offenses-punishment.htm" target="_blank">here&#8217;s the link</a>.  Have a look. You might be serving one someday <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div>
<h3><span style="color: #3366ff;"><strong>5. Case Study</strong></span></h3>
</div>
<p>There have been quite a few cases revolving around Orkut, but the one that I&#8217;ll be talking about (and is the most relevant) is the one where <a href="http://timesofindia.indiatimes.com/articleshow/2513737.cms">wrong man (<span style="font-size: 14px; font-weight: normal; line-height: 18px; font-family: Arial,Helvetica,sans-serif; color: #000000;"><span style="font-size:8pt;"> named Lakshmana Kailash K) </span></span>was put behind bars for 50 freakin&#8217; days</a>.  He&#8217;s &#8220;reportedly&#8221;  involved in the defamation of Chhatrapati Shivaji, a highly revered historical figure.<br />
In case you aren&#8217;t aware, Orkut (Google) has <a href="http://economictimes.indiatimes.com/Orkuts_tell-all_pact_with_cops_/RssArticleShow/articleshow/1982584.cms" target="_blank">signed a pact with Indian Law Enforcement.</a> They pledge to &#8220;<em>block any &#8216;defamatory or inflammatory content&#8217;, or hand over IP address information to police if asked&#8221;</em>.</p>
<p>So what happened in the above case?<br />
Law enforcers are reported about the defamation of Shivaji, they contact Orkut, Orkut gives IP, law enforcers run to the ISP (Airtel in this case), Airtel provides address, Guy put in jail.<br />
Simple. Isn&#8217;t it?</p>
<p>The only trouble being that Airtel provided the wrong address.<br />
Whoops! And bang! The dude spends 50 days straight, for something he didn&#8217;t do.<br />
Neha Viswanathan, a blogger based in UK, <a href="http://www.withinandwithout.com/?p=1176" target="_blank">has a very nice write-up</a> on the incident. Further, there&#8217;s a very <a href="http://www.indiacyberlab.in/know_more/copawards2005-legal.htm" target="_blank">nice compilation of some Cyber Crime cases in India at the IndiaCyberLab portal</a>.</p>
<div>
<h3><span style="color: #3366ff;"><strong>6. Putting the pieces of puzzle together</strong></span></h3>
</div>
<p>Let&#8217;s first collect all the pieces together:<br />
1.  Orkut has a pact with Indian law Enforcement.<br />
2. Law enforcers are incompetent *cough*.<br />
3. Orkut (or any other similar site) still has XSS and CSRF flaws in them. Period.<br />
4. XSS and CSRF let you (among other thousand things) manipulate source code (section 65) and/or insert obscene/derogatory (section 67).<br />
5. XSS and CSRF <strong>let you post/manipulate data on some other person&#8217;s behalf</strong>. (Orkut/Samy etc. worms did not  require you to click anywhere. Just load the page and the payload in inserted in your friend&#8217;s scrapbook <strong>on your behalf</strong>).</p>
<p>Now combine them all, and you&#8217;ll realize that there might be a day when you just sent a &#8220;long time no scraps&#8221; scrap in your friends scrapbook and went to bed. The next day, a bunch of Cyber officers wake you up, and arrest you for defaming Bala Saheb Thakrey.</p>
<p>&#8230;and yes! Don&#8217;t talk about Democracy. You&#8217;ve already seen that the politicians can get away with a wrestling in parliament arena that will put WWE stars to shame. On the contrary, a chap is detained for 50 days just because the cops thought that they had enough evidence.</p>
<h3><span style="color: #3366ff;">7. Conclusion</span></h3>
<p>What!<br />
Stay away from social networking sites. Trust me, they are not worth the price.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/iframes-to-be-or-not-to-be/" rel="bookmark" title="September 10, 2007">IFrames &#8211; To be or not to be?</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/samy-a-hero-or-a-villian/" rel="bookmark" title="February 5, 2007">Samy: A hero or a villian!</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoo-gone-insane/" rel="bookmark" title="August 11, 2007">Yahoo! gone Insane!</a></li>

<li><a href="http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/" rel="bookmark" title="February 19, 2007">Vista!!! (3 Exclamations.) is here? (Why :-/)</a></li>
</ul><!-- Similar Posts took 8.990 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>The Web is Broken</title>
		<link>http://projectbee.org/blog/archive/the-web-is-broken/</link>
		<comments>http://projectbee.org/blog/archive/the-web-is-broken/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 12:54:19 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[csrf]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[xss]]></category>
		<category><![CDATA[iframe]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/10/12/the-web-is-broken/</guid>
		<description><![CDATA[Update: I somehow managed to make a blunder. A part of slide no. 12 was taken from David Kierznowski&#8217;s (of GNUCitizen and Blogsecurity group) presentation for OWASP Belgium Conf. I missed out on mentioning David&#8217;s name is the credits. Apologies David. I&#8217;ve updated and re-uploaded it. Yesterday, I presented my first Webinar (Seminar on Web). [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808000;">Update:</span><strong><span style="color: #808000;"> I somehow managed to make a blunder. A part of slide no. 12 was taken from <a href="http://gnucitizen.org/about/dk">David Kierznowski&#8217;s</a> </span></strong><strong><span style="color: #808000;">(of GNUCitizen and Blogsecurity group) </span></strong><strong><span style="color: #808000;">presentation for OWASP Belgium Conf. I missed out on mentioning David&#8217;s name is the credits. Apologies David. I&#8217;ve updated and re-uploaded it. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  </span></strong></p>
<p>Yesterday, I presented my first Webinar (Seminar on Web). It was titled, <strong><span style="color: #ff0000;">The Web is Broken</span> </strong><span style="color: #ff0000;">&#8211;Why every feature is, in fact, a loophole</span>. A great experience.</p>
<p>Although after listening to my own recording, I felt that a number of things went wrong (mostly because of problems in connectivity and slow internet speed). The issue I was worried about was that it was targeted at developers with beginner to intermediate level knowledge of web, but the topic was very broad. Fortunately, I received some good feedback along with requests to conduct more such sessions. The talk was scheduled for 1.5 hours, but it stretched for 2.5 hours. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Here is the presentation:</p>
<div id="__ss_206607" style="width: 425px; text-align: left;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=the-web-is-broken-by-bipin-3-upadhyay-1197983798366666-4" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=the-web-is-broken-by-bipin-3-upadhyay-1197983798366666-4" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;"><a href="http://www.slideshare.net/?src=embed"><img style="border:0px none;margin-bottom:-5px" src="http://static.slideshare.net/swf/logo_embd.png" alt="SlideShare" /></a> | <a title="View '" href="http://www.slideshare.net/bipin/the-web-is-broken-by-bipin-3-upadhyay?src=embed">View</a> | <a href="http://www.slideshare.net/upload?src=embed">Upload your own</a></div>
</div>
<p>I hope you like it too. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/what-a-new-year-gift/" rel="bookmark" title="January 5, 2008">What a new year Gift! :)</a></li>

<li><a href="http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/" rel="bookmark" title="May 9, 2007">Open JavaFX, an alternative to AJAX?</a></li>

<li><a href="http://projectbee.org/blog/archive/how-to-implementing-shindig/" rel="bookmark" title="September 30, 2008">[How To] Implementing Shindig.</a></li>

<li><a href="http://projectbee.org/blog/archive/samy-a-hero-or-a-villian/" rel="bookmark" title="February 5, 2007">Samy: A hero or a villian!</a></li>

<li><a href="http://projectbee.org/blog/archive/http-protocol/" rel="bookmark" title="December 15, 2011">HTTP protocol and other stuff that power the web</a></li>
</ul><!-- Similar Posts took 6.045 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/the-web-is-broken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Java vulnerable to remote compromise</title>
		<link>http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/</link>
		<comments>http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/#comments</comments>
		<pubDate>Sat, 14 Jul 2007 02:10:31 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/07/14/java-vulnerable-to-remote-compromise/</guid>
		<description><![CDATA[ZDNet Asia reports that Google Security team has discovered as &#8220;Dangerous Java Flaw that threaten&#8217;s Virtually Everything&#8220;. The interesting part of this news is that, apart from a few scary statements, it doesn&#8217;t inform you anything else. The Sun advisory page on this flaw, however, informs you about two flaws which are nothing but Buffer [...]]]></description>
			<content:encoded><![CDATA[<p>ZDNet Asia reports that Google Security team has discovered as &#8220;<a href="http://www.zdnetasia.com/news/security/printfriendly.htm?AT=62028389-39000005c">Dangerous Java Flaw that threaten&#8217;s Virtually Everything</a>&#8220;. The interesting part of this news is that, apart from a few scary statements, it doesn&#8217;t inform you anything else.</p>
<p>The <a href="http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102934-1">Sun advisory page </a>on this flaw, however, informs you about two flaws which are nothing but Buffer Overflows. Do not mistake me that I am undermining the impact of Buffer Overflow Attacks in any way. It&#8217;s just the ZD Net article&#8217;s title which&#8217;s bugging me. It makes the flaw look like an out of world ET attack scenario.</p>
<ol>
<li><em>A buffer overflow vulnerability in the image parsing code in the Java Runtime Environment may allow an untrusted applet or application to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.</em></li>
<li><em>A second vulnerability may allow an untrusted applet or application to cause the Java Virtual Machine to hang.</em></li>
</ol>
<p>Now firstly, Buffer Overflows are no new form of attacks. They have been here since the existence of man (I admit that&#8217;s a little much <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> ), and they are here to stay. Thus, articles like this are more like <strong>FUD</strong>, IMHO.<br />
Secondly, <strong>applet support is very limited in mobile devices</strong>. Not to mention that <a href="http://developers.sun.com/mobility/midp/questions/imagetype/">J2ME supports only PNG format</a>. Thus, not &#8220;virtually everything&#8221; is everything.<br />
Finally, <strong>image parsing library in Sun&#8217;s Java implementation is through a native library</strong>. It&#8217;s time that Sun writes a Java equivalent for it to avoid other similar issues. Further, since Java is now GPL, I also hope to see the code coming from some random, pimply, introvert teenage kid. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>The problems can be resolved by updating the packages. Detailed info provided on <a href="http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102934-1">the Sun&#8217;s advisory</a>.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/" rel="bookmark" title="May 26, 2007">An insight into Sun&#8217;s *crazy* strategy.</a></li>

<li><a href="http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/" rel="bookmark" title="May 9, 2007">Open JavaFX, an alternative to AJAX?</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/amazing-interrupt-handling/" rel="bookmark" title="April 12, 2007">Amazing Interrupt Handling!</a></li>

<li><a href="http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/" rel="bookmark" title="July 3, 2007">Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</a></li>
</ul><!-- Similar Posts took 9.820 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</title>
		<link>http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/</link>
		<comments>http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/#comments</comments>
		<pubDate>Tue, 03 Jul 2007 11:27:34 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[rating]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/07/03/month-of-search-engine-bugs-mission-accomplished/</guid>
		<description><![CDATA[The Month of Search Engine Bugs by MustLive has come to an end. MutLive reports: In the project took part 33 search engines (30 web engines and 3 local engines) of 19 vendors, some vendors have several engines. The list of project’s participants (in order of appearance): Meta, Yahoo, HotBot, Gigablast, MSN, Clusty, Yandex, Yandex.Server [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://websecurity.com.ua/1114/">Month of Search Engine Bugs </a>by <a href="http://websecurity.com.ua/">MustLive</a> has come to an end.</p>
<p>MutLive reports:</p>
<blockquote><p>In the project took part <strong>33 search engines</strong> (30 web engines and 3 local engines) of <strong>19 vendors</strong>, some vendors have several engines. The list of project’s participants (in order of appearance): <em>Meta, Yahoo, HotBot, Gigablast, MSN, Clusty, Yandex, Yandex.Server (local engine), Search Europe, Rambler, Ask.com, Ezilon, AltaVista, AltaVista local (local engine), MetaCrawler, Mamma, Google, Google Custom Search Engine (local engine), My Way, Lycos, Aport, Netscape Search, WebCrawler, Dogpile, AOL Search, My Search, My Web Search, LookSmart, DMOZ (Open Directory Project), InfoSpace, Euroseek, Kelkoo, Excite</em>.</p>
<p>Altogether there were published 104 vulnerabilities in mentioned engines. Including Cross-Site Scripting (as XSS, and as HTML Injection), Full path disclosure, Content Spoofing and Information disclosure vulnerabilities. It is without taking into account redirectors in search engines (altogether there were published 23 redirectors).</p>
<p><strong>Results of the projects:</strong> fixed 44 vulnerabilities from 104 (without taking into account redirectors). It is 42,31% fixed vulnerabilities. Owners of search engines have a place for improvements of their engines’ security.</p></blockquote>
<p>Over a period of 30 days, 104 and vulnerabilities/bugs were discovered out of which only 44 have been fixed. Out of these 19 vendors, only two (Rambler and Ezilon) have thanked him for his commendable hardwork.</p>
<p>Several researchers, including <a href="http://jeremiahgrossman.blogspot.com/2007/07/30-days-104-search-engine.html">Jeremiah</a>, <a href="http://ha.ckers.org/blog/20070701/month-of-search-engine-bugs-comes-to-a-close/">RSnake</a>, <a href="http://planet-websecurity.org/30+days%2C+104+Search+Engine+Vulnerabilities/">Christ1an</a> etc. blogged about it. Considering the complexities involved in the fixing a bug, they agree at some point that 44  is still a good number. However, there is one Big &#8220;Cheer&#8221; Leader<a href="http://websecurity.com.ua/1114/#comment-48778"> which isn&#8217;t fixing the bugs</a>. No points for guessing that the Leader believes  in &#8220;not doing evil things&#8221;.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>

<li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>

<li><a href="http://projectbee.org/blog/archive/idle-nights-devils-mind/" rel="bookmark" title="April 12, 2007">Idle Nights: Devil&#8217;s Mind</a></li>

<li><a href="http://projectbee.org/blog/archive/is-google-bomb-really-diffused/" rel="bookmark" title="April 28, 2007">Is Google Bomb REALLY Diffused?</a></li>
</ul><!-- Similar Posts took 8.961 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Lost Me!</title>
		<link>http://projectbee.org/blog/archive/google-lost-me/</link>
		<comments>http://projectbee.org/blog/archive/google-lost-me/#comments</comments>
		<pubDate>Sun, 17 Jun 2007 06:54:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[rating]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/06/17/google-lost-me/</guid>
		<description><![CDATA[It&#8217;s strange writing something like this using a service that&#8217;s owned by Google. But it was long overdue. There was a time when I used address Google as &#8220;Google God&#8221; .Used to believe a lot that they religiously follow their &#8220;Do no Evil&#8221; motto. I forgot that as companies grow, there are bound to be [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s strange writing something like this using a service that&#8217;s owned by Google. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> <br />But it was long overdue.</p>
<p>There was a time when I used address Google as &#8220;Google God&#8221; <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .<br />Used to believe a lot that they religiously follow their &#8220;Do no Evil&#8221; motto. I forgot that as companies grow, there are bound to be employs who are evil by nature.<br />It reminds me of my Pre-Placement Training during college days when I was &#8220;tutored&#8221; that, <span style="font-style:italic;">Honesty is not a strength. You are supposed to be honest</span>&#8221; This obviously isn&#8217;t true when people take the excuse of &#8220;everybody-is-doing-it-so-why-not-me&#8221;.<br />And lets face it.<br />Money matters!</p>
<p>Anyways, coming back to the topic; I mentioned in one my previous blogs when my Google AdSense account was disabled because of my own mistakes. I took the responsibility and had no complaints. However, when my AdSense account was disabled for the second time, I made a thorough study of their privacy policies. That&#8217;s when I came to know about their two-faces.<br />They allow several sites to utilize their services even when they falter with the terms and conditions. One thing common among all these sites was, &#8220;they all are High Traffic sites&#8221;.</p>
<p>As I mentioned, a post on the topic was long overdue. I stopped myself with one or other reason. The latest development, however, made me talk about it.<br />According to <a href="http://www.privacyinternational.org/article.shtml?cmd%5B347%5D=x-347-553961"><span style="font-weight:bold;">Privacy International&#8217;s</span> latest report</a> on Top 23 Internet Companies, Google held the last spot (even below M$). This topic, as Privacy International itself admits, is controversial. It&#8217;s report however, is substantially supported.<br />You might want to have a look at the post on the same topic <a href="http://ha.ckers.org/blog/20070612/google-ranked-worst-in-privacy/">on RSnake&#8217;s blog</a>. Do not miss out on <a href="http://ha.ckers.org/blog/20070612/google-ranked-worst-in-privacy/#comment-39022">the comments</a>.</p>
<p><span style="font-size:85%;"><span style="font-weight:bold;">Footnote:</span> This post is not an outlet to my anguish. I (mistakenly) had more faith in Google than most of you. Another post on <span style="font-style:italic;font-weight:bold;">innovativeness</span><span style="font-weight:bold;"> of Google technologies</span> is due.<br />And BTW, I do not mean to say that Google has turned evil. I believe as the company has grown, the motto has changed to &#8220;<span style="font-weight:bold;">Do no Evil. If there is any, close your eyes</span>&#8220;.<br /></span></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/bill-gates-wins-me/" rel="bookmark" title="June 19, 2007">Bill Gates wins me!</a></li>

<li><a href="http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/" rel="bookmark" title="July 3, 2007">Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</a></li>

<li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>

<li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/is-google-bomb-really-diffused/" rel="bookmark" title="April 28, 2007">Is Google Bomb REALLY Diffused?</a></li>
</ul><!-- Similar Posts took 5.040 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/google-lost-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An insight into Sun&#8217;s *crazy* strategy.</title>
		<link>http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/</link>
		<comments>http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/#comments</comments>
		<pubDate>Sat, 26 May 2007 11:25:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[apache]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[books]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/05/26/an-insight-into-suns-crazy-strategy/</guid>
		<description><![CDATA[I have been reading a lot of discussion on Sun&#8217;s current market position/revenue versus their *mad* strategy. I have simultaneously been working on Java&#8217;s history for my book. I thought it might be interesting to post my views on the topic and see what others are thinking. To justify/criticize Sun&#8217;s current modus operandi, I will [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span style="font-style:italic;"><span style="font-size:85%;">I have been reading a lot of discussion on Sun&#8217;s current market position/revenue versus their *mad* strategy. I have simultaneously been working on Java&#8217;s history for my book. I thought it might be interesting to post my views on the topic and see what others are thinking. To justify/criticize Sun&#8217;s current modus operandi, I will talk a little about their past strategies, and their respective outcomes.</span></span></p>
<p class="MsoNormal"><b>The Past</b></p>
<p class="MsoNormal">Most of the people know James Gosling as the father of Java. Only a few know that he was also the lead engineer of Gosmacs (gmacs or Gosling Emacs) and NeWS. Now, I won’t be talking about Gosmacs (which according to some people is/was the reason of some conflict between RMS and Gosling. Phew!)<br />However, NeWS (Network extensible Window System) is of a little concern, mostly because it was arguably superior to X Window System… and because it FAILED. The most important reason for its failure (and X Window’s success) is that Sun kept it proprietary.<br />Later on when Sun developed Java, some people, especially the genius Eric Schmidt (then CTO-Sun, now CEO-Google), were aware that keeping Java <span style="font-style:italic;">within enclosed fences</span> will lead to similar <span style="font-style:italic;">devastating</span> results. Not to mention that *7 (for which Java was developed) had already failed and Java was still in search of a viable market.</p>
<p class="MsoNormal">So what did he do?<br />He focused on making it as open as possible and tried building a *Java Community*. (Google SoC, IMHO, is also a “win-the-community-and-you-win-everything-else” approach. But then that’s a different topic altogether. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  )</p>
<p class="MsoNormal">Where were we?<br />Yeah! So he focused on building a Java Community.<br />Apart from organizing developer conferences like JavaOne, Sun also encouraged user groups (JUGs), which reached over a number of 400 in year 2000 itself. In fact they went a step further with JCP (Java Community Process) to make the development of Java *as open as possible*.<br />The  reality behind all this community building scene was the fact that the direct control remained with Sun (well mostly).</p>
<p class="MsoNormal">Everything, however, was running smooth; for Sun as well as the Java developers.</p>
<p class="MsoNormal"> <i></i></p>
<blockquote><p style="color:rgb(102, 102, 0);" class="MsoNormal"><i>“I envy you. But such a thing is not meant to last.”</i></p>
<p class="MsoNormal"><span style="color:rgb(102, 102, 0);">                                            &#8212; </span><b><span style="color:rgb(102, 102, 0);">Persephone, Matrix Reloaded</span></p>
<p></b></p>
</blockquote>
<p class="MsoNormal"><b></b><span>I guess the above statement is valid for every aspect of human existence.</span><br />In early 2004, Jonathan Schwartz, referenced Eric Steven Raymond’s “<a href="http://www.catb.org/%7Eesr/writings/cathedral-bazaar">The Cathedral and the Bazaar</a>” and compared JCP to the “Bazaar”, stating that development of Linux was more like a “Cathedral”. I would not expand on it but this was enough to infuriate ESR <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>ESR wrote an open letter addressed to Scott McNealy, CEO-Sun, with a subject line “<a href="http://www.catb.org/%7Eesr/writings/let-java-go.html">Let Java Go</a>”. He accused Sun on several fronts (for which I’d pursue you to read <a href="http://www.catb.org/%7Eesr/writings/let-java-go.html">the letter</a>) and appealed to Open Source Java. A few weeks later RMS wrote an essay on<a href="http://www.gnu.org/philosophy/java-trap.html"> <i>Java Trap</i></a> and appealed the developers to contribute and use open source projects like GCJ/Gnu Classpath etc. Several other appeals/open letters were published (Apache’s Geir Magnusson Jr., IBM, etc.)</p>
<p>A series of events followed before Sun announced that it will be open sourcing Java. There main concern was Microsoft forking Java and hence, destroying its cross platform compatibility (which shows that they really were clueless on how Open source model works/ can work).<br />They had no other option than to Open Source the *giant*, and they did it.</p>
<p class="MsoNormal"><b>The Present</b></p>
<p class="MsoNormal">The past unarguably affects, if not defines, the present. Sun’s experience since the NFS days to (forced) Open Sourcing Java days taught/reminded them of their most important lesson.<br /><span style="font-weight:bold;">The Community is fruitful!</span><br /><span style="font-weight:bold;">Build a community and everything else will follow, sooner or later.</span></p>
<p class="MsoNormal">So here they are.<br />Open sourcing EVERYTHING.<br />Building Community, and making it mutually encashable. It’s obviously not so profitable for them today, but the future holds immense potential.</p>
<p class="MsoNormal">The way they have been endorsing and promoting stuff is simply adorable. Even NetBeans has its own *arena*.<br />Not to mention the, so called, developer conferences organized all over the world in a distributed fashion to reach the most number of developers.<span>  </span>I, however, have several concerns regarding them. You may read some of them at<i><a href="http://angraze.wordpress.com/2007/05/18/sun-technology-summit-07-bangalore"> Amit’s blog</a>. </i>I hope Sun listens to the plea of developers and improves the quality of these summits.</p>
<p class="MsoNormal">Another amazing strategy, IMHO, is the <a href="http://blogs.sun.com/"><i>blogs</i> </a>that Sun employees post regularly. I have subscribed some of them and it’s really amazing to see that how important role these blogs are playing in binding people. They often link each other&#8217;s (Sun Employees, of course) blogs. You can have a look at the <a href="http://blogs.sun.com/">Sun-Blogging homepage</a> to get a feel of the number of hits the folks out there are getting. Now even if I read only one of these, I’d get to know about latest developments. I am not sure whether it’s a part of their strategy, but it’s definitely working as a powerful advertising medium.<br />Yup! I know that employees of other firms write blogs too and probably get bigger number of hits, but I haven’t seen anyone of them making so much of a difference on an organizational level. (Please correct me if I am wrong)</p>
<p class="MsoNormal"><b>The Future</b></p>
<p class="MsoNormal">I am no Nostradamus and I cannot predict future.<br />All I can say is the future is (mostly) Free &amp; Open. IBM (previously referred Satan) secured its place (with a Halo on head) by contributing to the Apache httpd project and winning the FOSS community. Now it’s Sun’s turn and they are playing pretty well.<br />Yes, their revenue might be a concern today; but I don’t really see a reason why there future shouldn’t be bright. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/" rel="bookmark" title="July 14, 2007">Java vulnerable to remote compromise</a></li>

<li><a href="http://projectbee.org/blog/archive/dreams-and-huh-reality/" rel="bookmark" title="June 4, 2007">Dreams&#8230; and (huh!) Reality.</a></li>

<li><a href="http://projectbee.org/blog/archive/bill-gates-wins-me/" rel="bookmark" title="June 19, 2007">Bill Gates wins me!</a></li>

<li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-mysqlphp-installation-configuration-tutorial-for-beginners/" rel="bookmark" title="February 25, 2006">Apache-MySQLPHP Installation &#38; Configuration Tutorial for Beginners :)</a></li>
</ul><!-- Similar Posts took 7.914 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Is Google Bomb REALLY Diffused?</title>
		<link>http://projectbee.org/blog/archive/is-google-bomb-really-diffused/</link>
		<comments>http://projectbee.org/blog/archive/is-google-bomb-really-diffused/#comments</comments>
		<pubDate>Sat, 28 Apr 2007 20:32:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[bomb]]></category>
		<category><![CDATA[rating]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/04/28/is-google-bomb-really-diffused/</guid>
		<description><![CDATA[I posted a very small article on Google Bombs; and quite co-incidentally few days later read that Google has started diffusing the bombs. Now &#8220;started diffusing&#8230;&#8221; makes sense when it has to be done manually, but aren&#8217;t we talking about terabytes and petabytes of data? We can never expect it to be done manually. Moreover, [...]]]></description>
			<content:encoded><![CDATA[<p>I posted a very small article on <a href="http://codeinmybug.wordpress.com/2007/01/22/google-bomb-update-diffused/">Google Bombs</a>; and quite co-incidentally few days later read that <a href="http://www.google.co.in/search?q=google+bomb+diffused">Google has started</a> <a href="http://googlewebmastercentral.blogspot.com/2007/01/quick-word-about-googlebombs.html">diffusing the bombs</a>. Now &#8220;started diffusing&#8230;&#8221; makes sense when it has to be done manually, but aren&#8217;t we talking about terabytes and petabytes of data? We can never expect it to be done manually. Moreover, <a href="http://googlewebmastercentral.blogspot.com/2007/01/quick-word-about-googlebombs.html">Google&#8217;s official announcement</a> said the same. It also admitted that <span style="font-style:italic;">&#8220;&#8230;the impact of this new algorithm is very limited in scope and impact&#8230;&#8221;. </span></p>
<p>The phrase, however, seems to make some sense to me now, that I&#8217;ve discovered that some <span style="font-weight:bold;font-style:italic;">bombs </span>are still lying around.<br />
Try making a search for the word &#8220;<a href="http://www.google.co.in/search?q=bad"><span style="font-weight:bold;">BAD</span></a>&#8220;.<br />
Who do you see as the topper?<br />
Quite interestingly, it was <a href="http://www.afdb.org/" class="l">African Development Bank</a> for me. Surprised?<br />
I first thought that BAD might be the acronym for the bank&#8217;s name, as in case of <a href="http://www.google.co.in/search?q=neha">NEHA</a>, which is an acronym for <a href="http://www.neha.org/" class="l">National Environmental Health Association</a>.<br />
After a little playing around, I  found that a few days ago, <a href="http://www.seomoz.org/blog/stephen-colbert-the-greatest-living-american-a-googlebombing-campaign">SEOmoz.org <span style="font-style:italic;">appealed</span> to make Stephen Colbert as the Greatest Living American</a>. And apparently, he has become the <a href="http://www.google.co.in/search?q=greatest+living+american">Greatest Living American</a> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Quite honestly, I am pretty happy that the algo is flawed.<br />
An attempt to diffuse the bombs, in my opinion, was more <span style="font-style:italic;">public image oriented</span> rather than <span style="font-style:italic;">result improvement oriented</span>.</p>
<p>Footnote: May be <span style="font-weight:bold;">BAD</span> is not linked willingly (I firmly believe that it&#8217;s not), but then who said Google Bombs are all about linking willingly. May be they have some <span style="font-style:italic;">process</span> which forms an acronym of the same name. But then how relevant is such and acronym if it doesn&#8217;t even appear on the home page?</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>

<li><a href="http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/" rel="bookmark" title="February 19, 2007">Vista!!! (3 Exclamations.) is here? (Why :-/)</a></li>

<li><a href="http://projectbee.org/blog/archive/slashdot-uh/" rel="bookmark" title="May 21, 2008">Slashdot, uh! :|</a></li>

<li><a href="http://projectbee.org/blog/archive/m-windowsxp-just-got-a-newer-version-of-update-with-new-components/" rel="bookmark" title="August 21, 2007">M$ WindowsXP just got a newer version of Update with new Components!</a></li>
</ul><!-- Similar Posts took 7.001 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/is-google-bomb-really-diffused/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Idle Nights: Devil&#8217;s Mind</title>
		<link>http://projectbee.org/blog/archive/idle-nights-devils-mind/</link>
		<comments>http://projectbee.org/blog/archive/idle-nights-devils-mind/#comments</comments>
		<pubDate>Thu, 12 Apr 2007 00:35:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/04/12/idle-nights-devils-mind/</guid>
		<description><![CDATA[I stay back in the office during night and return back at around 6-7 am, when everybody is coming . These nights are supposed to be LONELY as I am the only one in the building (actually in all the four buildings combined), apart from the security guards and office boys, of course. However, I&#8217;ve [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:georgia;"><span style="font-size:130%;">I stay back in the office during night and return back at around 6-7 am, when everybody is coming <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . These nights are supposed to be LONELY as I am the only one in the building (actually in all the four buildings combined), apart from the security guards and office boys, of course. However, I&#8217;ve found my companions, and ways to refresh myself. I&#8217;ll list some of them.</span></span></p>
<p>1. <span style="font-weight:bold;">Online Web/Security Cameras</span>: Some of you who know that Google provides an API for refining the search queries (with a capital &#8220;R&#8221;) also know that the giant&#8217;s database is like an ocean. And you never really know what&#8217;s inside an ocean unless and until you dive in it. As you dive deeper, your jaw drops in awe.<br />
Long story cut short, I use the query to discover (a part of) all AXIS cameras online.<br />
For curious lot, the query is: <span style="font-style:italic;color:#666600;">inurl:/view/view.shtml AXIS</span> and sometimes <span style="color:#666600;font-style:italic;">intitle:&#8221;Live View / &#8211; AXIS&#8221; | inurl:view/view.sht </span><br />
[As I am writing this, I wanted check the second query. So I chose one of the results and something spooky happened. Someone was already controlling the camera. hehe.<br />
I was moving it right, he/she was moving it left. We fought for a while but then I closed the window. I am nice guy you see <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> )</p>
<p>Okay let's proceed.<br />
So I have a bookmarked folder called "PastTime" on my browser, which has my favorite cameras bookmarked. My most fave are:<br />
i) A coffee/wine shop camera, which is more lively during the night. Luckily, the camera is provided officially, so I can provide the link without any worries. Find the link to the camera here:  <a href="http://www.buzzbeachbar.com/oludeniz_buzz_beach_bar_live_webcam.html">buzzjunction_webcam</a><br />
<a href="http://www.buzzbeachbar.com/bjn11.jpg"><img src="http://www.buzzbeachbar.com/bjn11.jpg" style="display:block;text-align:center;cursor:pointer;width:320px;margin:0 auto 10px;" border="0" /></a></p>
<p>ii) A camera in the study room of a Polytechnic school of NewYork. It's a small room with a coffee machine, a microwave oven (?), a printer, a sofa, a bookshelf, and an elliptical table with power connection for the laptops and notebooks.<br />
And that's the best part. People come here with there laptops, and sometimes I sit down looking at there screens, trying to figure out what they are doing. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /><br />
I have also become acquainted with some regular visitors.<br />
A spectacled guy with a cap and a laptop. (He is leaving right now. No kidding. What a coincidence [jawdrop])<br />
A black girl, who has the headphones exactly like mine.<br />
Two Muslim girls, with one Dell XPS laptop (probably).<br />
The bad part is, there are no visitors on sundays <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /><br />
iii) A micro/nano lab camera of one of the world&#8217;s most famous universities. There&#8217;s nothing engaging about this, apart from the fact that the guys (or girls) roam around in spacesuit sort of dresses.<br />
iv) A set of four surveillance cameras. Three of them pointing to car parking locations and one focussed inside some kind of room. I am still not able to get it yet. The only thing that makes me stick to it is the word &#8220;surveillance&#8221; <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>There are couple of others focussed on traffic, colleges, hostels (I guess), lake, parks&#8230; but they are pretty boring and pictures are not really clear.<br />
I&#8217;d like to try my hands on other cameras like linksys too. Let&#8217;s see when.</p>
<p>2. <span style="font-weight:bold;">Google Again</span>: Google queries can be real fun.<br />
Have you ever come across a search result when Google tells you that the original number of results is pretty large, however, most of them are sort of repetitions hence they have been truncated.<br />
Have a look at the following two pictures.</p>
<div style="text-align:center;"><span style="font-family:georgia;"><span style="font-size:130%;"> </span></span><a href="http://projectbee.org/blog/wp-content/uploads/2008/01/pic11.jpg" title="pic1.jpg"><img src="http://projectbee.org/blog/wp-content/uploads/2008/01/pic11.jpg" alt="pic1.jpg" height="390" width="804" /></a><span style="font-family:georgia;"><span style="font-size:130%;"></span></span></div>
<div style="text-align:center;"><span style="font-family:georgia;"><span style="font-size:130%;">This one&#8217;s the normal result.</span></span></div>
<p><span style="font-family:georgia;"><span style="font-size:130%;"><br />
</span></span></p>
<div style="text-align:center;"><a href="http://projectbee.org/blog/wp-content/uploads/2008/01/pic21.jpg" title="pic2.jpg"><img src="http://projectbee.org/blog/wp-content/uploads/2008/01/pic21.jpg" alt="pic2.jpg" height="292" width="808" /></a><span style="font-family:georgia;"><span style="font-size:130%;"></span></span></div>
<div style="text-align:center;"><span style="font-family:georgia;"><span style="font-size:130%;">Here I ask Google <span style="font-weight:bold;">NOT TO OMIT ANY RESULT.</span></span></span></div>
<p><span style="font-family:georgia;"><span style="font-size:130%;"><br />
You think that&#8217;s funny?<br />
I leave it up to you to decide.</span></span></p>
<p>3. <span style="font-weight:bold;">Slashdot, and blogs</span> of others friends (and their friends) and some geeks like de Icauza etc. Initially I was a Digg addict, but then got completely fed up.<br />
So guys, keep blogging. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>4. <span style="font-weight:bold;">Movies and Documentaries</span>: Net speed during the night is awesome (generally). So I don&#8217;t mind downloading them. Though I don&#8217;t get time to watch them.</p>
<p>5. Off late I&#8217;ve also found some <span style="font-weight:bold;">vulnerabilities </span>in the policies and network of my company. I try to keep the management informed.<br />
After all it&#8217;s my company. I&#8217;d definitely not like any jerk to poke his nose in.</p>
<p>That&#8217;s it.<br />
These five (along with the songs being played ALL the time) are currently more than enough to consume my free time (In fact more than JUST the free time).<br />
But even after all this, it gets freaking lonely sometimes&#8230; not that I am complaining <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/how-to-implementing-shindig/" rel="bookmark" title="September 30, 2008">[How To] Implementing Shindig.</a></li>

<li><a href="http://projectbee.org/blog/archive/slashdot-uh/" rel="bookmark" title="May 21, 2008">Slashdot, uh! :|</a></li>

<li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/a-program-called-3-om/" rel="bookmark" title="March 3, 2007">A program called &#34;3~&#34; (Om)</a></li>
</ul><!-- Similar Posts took 5.905 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/idle-nights-devils-mind/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google Bomb! [Update: Diffused]</title>
		<link>http://projectbee.org/blog/archive/google-bomb-update-diffused/</link>
		<comments>http://projectbee.org/blog/archive/google-bomb-update-diffused/#comments</comments>
		<pubDate>Mon, 22 Jan 2007 11:41:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[bomb]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/01/22/google-bomb-update-diffused/</guid>
		<description><![CDATA[Boom.I mean Hi I am not talking about something new. The term was coined by Adam Mathes on April 6, 2001 in uber.nu.talking about the topic, should I explain what Google Bomb is, or should i explain the consequences?Ummmm. Okay. Goto Google, type &#8220;misrable failure&#8221;, and click on &#8220;I am feeling Lucky&#8221;.What we get is [...]]]></description>
			<content:encoded><![CDATA[<p>Boom.<br />I mean Hi <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><span style="color:rgb(102, 102, 0);"></span>I am not talking about something new. The term was coined by Adam Mathes on April 6, 2001 in uber.nu.<br />talking about the topic, should I explain what Google Bomb is, or should i explain the consequences?<br />Ummmm.</p>
<p>Okay. Goto Google, type &#8220;misrable failure&#8221;, and click on &#8220;I am feeling Lucky&#8221;.<br />What we get is the President of America&#8217;s page <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> .</p>
<p>The reason being the way Google&#8217;s algo works.<br />While rating the web pages, Google employes several&#8230; ummmm  ways/methods (I could not get the right word <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> ).<br />Anyways. One of these ways is to rate the pages based on the number of links it has, and also the keyword that has been used to link it.<br />One of the reasons my blog appears [last time I checked it was 11th] for the name &#8220;bipin&#8221;, though there no &#8220;Bipin&#8221; on the blog. Some of my friends have links to my blog using my real name.</p>
<p>&#8230; and the most scary thing, it doesn&#8217;t take a lot of links.</p>
<p>Wish to DEFAME someone?<br />You&#8217;ve the way now <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><span style="color:rgb(102, 102, 0);font-weight:bold;">Update:<br /></span><span style="color:rgb(102, 102, 0);">Google has started diffusing it&#8217;s bomb.</span><br /><span style="color:rgb(102, 102, 0);">In a recent update Google inormed @ the official </span><a href="http://googlewebmastercentral.blogspot.com/2007/01/quick-word-about-googlebombs.html">Google Webmaster&#8217;s blog </a><span style="color:rgb(102, 102, 0);">informed that they have diifusing the bomb. [What the heck man? Were they waiting for my write-up <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ]</span></p>
<p><a href="http://digg.com/submit?phase=2&amp;url=http://code-in-my-bug.blogspot.com/2007/01/google-bomb.html"> <img src="http://www.digg.com/img/little-digg.gif" border="0" /></a></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>

<li><a href="http://projectbee.org/blog/archive/is-google-bomb-really-diffused/" rel="bookmark" title="April 28, 2007">Is Google Bomb REALLY Diffused?</a></li>

<li><a href="http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/" rel="bookmark" title="December 20, 2007">Orkut Latest XSS Worm; and what it means for Indian Orkuteers</a></li>

<li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/" rel="bookmark" title="May 19, 2007">Rediffmail Bug. Anyone Interested?</a></li>
</ul><!-- Similar Posts took 4.575 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/google-bomb-update-diffused/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top Rating in Google :D</title>
		<link>http://projectbee.org/blog/archive/top-rating-in-google-d/</link>
		<comments>http://projectbee.org/blog/archive/top-rating-in-google-d/#comments</comments>
		<pubDate>Thu, 18 Jan 2007 13:55:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[rating]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/01/18/top-rating-in-google-d/</guid>
		<description><![CDATA[I was in one of my &#8220;Saddy-Saddy-For-No-Reason&#8221; moods.And didn&#8217;t want to bother anyone so started playing with Google&#8217;s Webmaster Tools. I used them for the first time so I had to go through the usual &#8220;add site&#8221;, &#8220;verify&#8221;&#8230; blah blah.But after that I was surprised to see that my tech blog rates @ 1 for [...]]]></description>
			<content:encoded><![CDATA[<p>I was in one of my &#8220;Saddy-Saddy-For-No-Reason&#8221; moods.<br />And didn&#8217;t want to bother anyone so started playing with Google&#8217;s Webmaster Tools.</p>
<p>I used them for the first time so I had to go through the usual &#8220;add site&#8221;, &#8220;verify&#8221;&#8230; blah blah.<br />But after that I was surprised to see that my tech blog rates @ 1 for the search keyword <a href="http://www.google.co.in/search?q=colukabki&amp;ie=utf-8&amp;oe=utf-8">COLUKABKI.</a><br />I verified it and was really amazed&#8230; status [:surprised:] &amp; [:dead:]<br />It even features above www.colukabki.com :-O</p>
<p>Another surprise, which I am still not able to figure out is that my personal blog features @ 10 for my real name&#8230;&#8230;&#8230; however, I do not have my name ANYWHERE on the blog. [May be it's somewhere in the comments. Whatever....]</p>
<p>I know it&#8217;s not a BIG achievement&#8230;. but it&#8217;s just the beginning&#8230; <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p><span style="color:rgb(102, 102, 0);"><span style="font-weight:bold;">Update: </span>Looks like the &#8220;my-personal-blog-getting-on-top-10&#8243; has been a victim of &#8220;Google Bomb Diffusion&#8221;. I never intended to raise my blogs rating by any such activity. It&#8217;s probably because my friends linked my blog using my real name&#8230;. </span><br /><span style="color:rgb(102, 102, 0);">&#8230;and now when the so called Google Bomb is diffused, my site, one of genuine sites to get weightage is suffering.</span><br /><span style="color:rgb(102, 102, 0);">It&#8217;s time Google stops worrying about it&#8217;s public image and starts working on things that makes me address it as &#8220;<span style="font-weight:bold;">Google GOD</span>&#8220;</p>
<p></span><a href="http://digg.com/submit?phase=2&amp;url=http://code-in-my-bug.blogspot.com/2007/01/top-rating-in-google-d.html"> <img src="http://www.digg.com/img/little-digg.gif" border="0" /></a></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>

<li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/idle-nights-devils-mind/" rel="bookmark" title="April 12, 2007">Idle Nights: Devil&#8217;s Mind</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>
</ul><!-- Similar Posts took 4.437 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/top-rating-in-google-d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
