<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Code in my Bug! &#187; review</title>
	<atom:link href="http://projectbee.org/blog/archive/category/review/feed/" rel="self" type="application/rss+xml" />
	<link>http://projectbee.org/blog</link>
	<description>Bipin&#039;s experiments with life, society, programming, hacking, &#38; other stuff</description>
	<lastBuildDate>Mon, 23 Jan 2012 18:49:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>What a new year Gift! :)</title>
		<link>http://projectbee.org/blog/archive/what-a-new-year-gift/</link>
		<comments>http://projectbee.org/blog/archive/what-a-new-year-gift/#comments</comments>
		<pubDate>Sat, 05 Jan 2008 12:49:25 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2008/01/05/what-a-new-year-gift/</guid>
		<description><![CDATA[It brings me immense pleasure to inform you that w3af (web application attack and audit framework) has been named the Best Application Scanner in BEST IT Security and Auditing Softwares 2007 list prepared by Security Database. I had mentioned in a few previous articles that I see immense potential in w3af. I must, however, also [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://w3af.sourceforge.net/" target="_blank"><img src="http://w3af.sourceforge.net/images/w3af-logo.png" alt="W3AF Logo" width="63" height="128" align="left" /></a>It brings me immense pleasure to inform you that <a href="http://w3af.sourceforge.net/">w3af (web application attack and audit framework) </a>has been named the <a href="http://www.security-database.com/toolswatch/IT-Security-and-Auditing-Softwares.html?artpage=2#outil_sommaire_1">Best Application Scanner </a>in <a href="http://www.security-database.com/toolswatch/IT-Security-and-Auditing-Softwares.html?artpage=1">BEST IT Security and Auditing Softwares 2007 list prepared by Security Database</a>. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I had mentioned in a few previous articles that I see immense potential in w3af. I must, however, also admit that I wasn&#8217;t hoping something like this to happen so quickly. I am glad I was wrong <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Hoping that more people contribute to the project, and wishing that I get some time to make a few w3af dedicated posts (preferably targeted at developers), at least.</p>
<p>Have a great year ahead.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/the-web-is-broken/" rel="bookmark" title="October 12, 2007">The Web is Broken</a></li>

<li><a href="http://projectbee.org/blog/archive/securcamp-and-back/" rel="bookmark" title="July 12, 2008">SecurCamp and back.</a></li>

<li><a href="http://projectbee.org/blog/archive/securitycamp-is-here-where-are-you/" rel="bookmark" title="June 25, 2008">SecurityCamp is here, where are you?</a></li>

<li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-1/" rel="bookmark" title="August 21, 2008">OWASP AppSec Conf Delhi &#8211; Day 1</a></li>

<li><a href="http://projectbee.org/blog/archive/bittus-back/" rel="bookmark" title="June 12, 2008">Bittu&#8217;s back :)</a></li>
</ul><!-- Similar Posts took 4.901 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/what-a-new-year-gift/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Orkut Latest XSS Worm; and what it means for Indian Orkuteers</title>
		<link>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/</link>
		<comments>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/#comments</comments>
		<pubDate>Thu, 20 Dec 2007 10:14:39 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[cyberlaw]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[xss]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/12/20/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/</guid>
		<description><![CDATA[Update: Kishor reports a flaw in the implementation of &#8220;private&#8221; videos feature on Orkut. Although I am at office and I haven&#8217;t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. 1. YAWN [Yet Another Worm, Nanny] Orkut (Google&#8217;s MySpace and Facebook for Indian, Pakistan [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #3366ff;"><strong>Update: </strong></span>Kishor reports <a href="http://wasjournal.blogspot.com/2007/12/orkut-private-videos-are-not-private.html">a flaw in the implementation of &#8220;private&#8221; videos feature on Orkut</a>. Although I am at office and I haven&#8217;t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div>
<h3><span style="color: #3366ff;"><strong>1. YAWN [Yet Another Worm, Nanny]</strong></span></h3>
</div>
<h3><img src="http://farm3.static.flickr.com/2084/1735501790_18be4450be_d.jpg" alt="http://flickr.com/photos/aqlott/1735501790/" width="403" height="227" /></h3>
<p>Orkut (Google&#8217;s MySpace and Facebook for Indian, Pakistan and Brazil) has been hit by an XSS worm. It&#8217;s useless to say but I am not able to resist, so I&#8217;ll say it anyways. <em>It&#8217;s not the first time that a Social networking site has been attacked by an XSS worm.</em> In fact these sites are the primary target due to a number of reasons -easier gullibility level, exponential reach, huge amount of data waiting to be harvested, <strong>web 2.0</strong> etc. etc. etc. There&#8217;s good compilation of XSS worms going on <a href="http://sla.ckers.org/forum/read.php?2,14477,18504">at Slackers </a>(Social n/w worm, or no).<br />
Anyhoo. This incident has <a href="http://www.cgisecurity.com/2007/12/17">already been</a> <a href="http://antrix.net/journal/techtalk/orkut_xss.html" target="_blank">reported</a> <a href="http://tkhere.blogspot.com/2007/12/orkut-under-cross-site-scripting-xss.html">by a</a> <a href="http://www.marrowbones.com/commons/technosocial/2007/12/orkut_worm_code_and_why_was_go.html" target="_blank">number of</a> <a href="http://www.gnucitizen.org/blog/the-orkut-xss-worm" target="_blank">bloggers</a>, so I  won&#8217;t dive into the technical details. However, this worm seems to be harmless and fixed for now.</p>
<div>
<h3><span style="color: #3366ff;"><strong>2. What it did?</strong></span></h3>
</div>
<p>If you <strong>view</strong>ed a message <strong><em>2008 vem ai&#8230; que ele comece mto bem para vc</em></strong> in your scrapbook, there is a big probability that you&#8217;re infected. You were added to a community named <em><strong>Infectados pelo Vírus do Orkut</strong></em> at http://www.orkut.com/CommunityJoin.aspx?cmm=44001818. The worm then forwards itself to the scrapbook of all your contacts (on your behalf). Any doubts on it being exponential?</p>
<div>
<h3><span style="color: #3366ff;"><strong>3. </strong><a href="//www.mit.gov.in/download/itbill2000.pdf" target="_blank"><strong>IT Act 2000</strong></a><strong> </strong><strong>[pdf]</strong></span></h3>
</div>
<p>IT Act 2000 is India&#8217;s legal answer to the miscreants on the technological front. (I realize it&#8217;s a pathetic definition, so no flame on it please <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). The trouble with IT Act 2000 is that the majority of law enforcers aren&#8217;t really aware of the real life scenarios. I&#8217;ll give a real case to support the point, in a while. Although I am no law expert (just a little bit of interest), I guess I can safely say that the Act needs a few amendments to include/modify a number of issues (e.g., SPAM, etc.)</p>
<p>So what happens when the implementation is in nascent stage, and the enforcers  are not completely eductaed?<br />
Things get blown out of proportion. Things get painted in a completely new color. Things get&#8230; uh! fill them up yourself.</p>
<div>
<h3><span style="color: #3366ff;"><strong>4. <a href="http://www.indiacyberlab.in/cyberlaws/chapter11.htm">Chapter 11, IT Act 2000</a></strong></span></h3>
</div>
<p>Chapter 11 of the Act defines the <strong>Offences</strong> &#8211; section 65 to section 78.   For now, let&#8217;s have a look at Sections 65, and 67.<br />
<strong> Section 65: Tampering with computer source documents.</strong></p>
<blockquote><p><em> Whoever knowingly or intentionally conceals, destroys or    alters or intentionally or knowingly causes another to conceal, destroy or    alter any computer source code used for a computer, computer programme,    computer system or computer network, when the computer source code is required    to be kept or maintained by law for the time being in force, shall be    punishable with imprisonment up to three years, or with fine which may extend    up to two lakh rupees, or with both.</em><br />
<em> Explanation: For the purposes of this section, &#8220;computer  source code&#8221; means the listing of programmes, computer commands, <strong>design and  layout and programme analysis of computer resource in any form</strong>.</em></p></blockquote>
<p><strong>Section 67:Publishing of information which is obscene in electronic form.</strong></p>
<blockquote><p><em>Whoever publishes or transmits <strong>or causes to be published in the electronic form</strong>, any material which is lascivious or appeals to the prurient interest or if its effect is such as to tend to deprave and corrupt persons who are likely, having regard to all relevant circumstances, to read, see or hear the matter contained or embodied in it, shall be punished on first conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to one lakh rupees and in the event of a second or subsequent conviction with imprisonment of either description for a term which may extend to ten years and also with fine which may extend to two lakh rupees.</em></p></blockquote>
<p>I have mostly been interested in section 67 (which according to some in the law indsutry) also extends to sms service <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Anyhoo. If you are interested in punishmentsm, <a href="http://www.indiacyberlab.in/cyberlaws/computer-offenses-punishment.htm" target="_blank">here&#8217;s the link</a>.  Have a look. You might be serving one someday <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div>
<h3><span style="color: #3366ff;"><strong>5. Case Study</strong></span></h3>
</div>
<p>There have been quite a few cases revolving around Orkut, but the one that I&#8217;ll be talking about (and is the most relevant) is the one where <a href="http://timesofindia.indiatimes.com/articleshow/2513737.cms">wrong man (<span style="font-size: 14px; font-weight: normal; line-height: 18px; font-family: Arial,Helvetica,sans-serif; color: #000000;"><span style="font-size:8pt;"> named Lakshmana Kailash K) </span></span>was put behind bars for 50 freakin&#8217; days</a>.  He&#8217;s &#8220;reportedly&#8221;  involved in the defamation of Chhatrapati Shivaji, a highly revered historical figure.<br />
In case you aren&#8217;t aware, Orkut (Google) has <a href="http://economictimes.indiatimes.com/Orkuts_tell-all_pact_with_cops_/RssArticleShow/articleshow/1982584.cms" target="_blank">signed a pact with Indian Law Enforcement.</a> They pledge to &#8220;<em>block any &#8216;defamatory or inflammatory content&#8217;, or hand over IP address information to police if asked&#8221;</em>.</p>
<p>So what happened in the above case?<br />
Law enforcers are reported about the defamation of Shivaji, they contact Orkut, Orkut gives IP, law enforcers run to the ISP (Airtel in this case), Airtel provides address, Guy put in jail.<br />
Simple. Isn&#8217;t it?</p>
<p>The only trouble being that Airtel provided the wrong address.<br />
Whoops! And bang! The dude spends 50 days straight, for something he didn&#8217;t do.<br />
Neha Viswanathan, a blogger based in UK, <a href="http://www.withinandwithout.com/?p=1176" target="_blank">has a very nice write-up</a> on the incident. Further, there&#8217;s a very <a href="http://www.indiacyberlab.in/know_more/copawards2005-legal.htm" target="_blank">nice compilation of some Cyber Crime cases in India at the IndiaCyberLab portal</a>.</p>
<div>
<h3><span style="color: #3366ff;"><strong>6. Putting the pieces of puzzle together</strong></span></h3>
</div>
<p>Let&#8217;s first collect all the pieces together:<br />
1.  Orkut has a pact with Indian law Enforcement.<br />
2. Law enforcers are incompetent *cough*.<br />
3. Orkut (or any other similar site) still has XSS and CSRF flaws in them. Period.<br />
4. XSS and CSRF let you (among other thousand things) manipulate source code (section 65) and/or insert obscene/derogatory (section 67).<br />
5. XSS and CSRF <strong>let you post/manipulate data on some other person&#8217;s behalf</strong>. (Orkut/Samy etc. worms did not  require you to click anywhere. Just load the page and the payload in inserted in your friend&#8217;s scrapbook <strong>on your behalf</strong>).</p>
<p>Now combine them all, and you&#8217;ll realize that there might be a day when you just sent a &#8220;long time no scraps&#8221; scrap in your friends scrapbook and went to bed. The next day, a bunch of Cyber officers wake you up, and arrest you for defaming Bala Saheb Thakrey.</p>
<p>&#8230;and yes! Don&#8217;t talk about Democracy. You&#8217;ve already seen that the politicians can get away with a wrestling in parliament arena that will put WWE stars to shame. On the contrary, a chap is detained for 50 days just because the cops thought that they had enough evidence.</p>
<h3><span style="color: #3366ff;">7. Conclusion</span></h3>
<p>What!<br />
Stay away from social networking sites. Trust me, they are not worth the price.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/iframes-to-be-or-not-to-be/" rel="bookmark" title="September 10, 2007">IFrames &#8211; To be or not to be?</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/samy-a-hero-or-a-villian/" rel="bookmark" title="February 5, 2007">Samy: A hero or a villian!</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoo-gone-insane/" rel="bookmark" title="August 11, 2007">Yahoo! gone Insane!</a></li>

<li><a href="http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/" rel="bookmark" title="February 19, 2007">Vista!!! (3 Exclamations.) is here? (Why :-/)</a></li>
</ul><!-- Similar Posts took 8.571 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>The Web is Broken</title>
		<link>http://projectbee.org/blog/archive/the-web-is-broken/</link>
		<comments>http://projectbee.org/blog/archive/the-web-is-broken/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 12:54:19 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[csrf]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[xss]]></category>
		<category><![CDATA[iframe]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/10/12/the-web-is-broken/</guid>
		<description><![CDATA[Update: I somehow managed to make a blunder. A part of slide no. 12 was taken from David Kierznowski&#8217;s (of GNUCitizen and Blogsecurity group) presentation for OWASP Belgium Conf. I missed out on mentioning David&#8217;s name is the credits. Apologies David. I&#8217;ve updated and re-uploaded it. Yesterday, I presented my first Webinar (Seminar on Web). [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808000;">Update:</span><strong><span style="color: #808000;"> I somehow managed to make a blunder. A part of slide no. 12 was taken from <a href="http://gnucitizen.org/about/dk">David Kierznowski&#8217;s</a> </span></strong><strong><span style="color: #808000;">(of GNUCitizen and Blogsecurity group) </span></strong><strong><span style="color: #808000;">presentation for OWASP Belgium Conf. I missed out on mentioning David&#8217;s name is the credits. Apologies David. I&#8217;ve updated and re-uploaded it. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  </span></strong></p>
<p>Yesterday, I presented my first Webinar (Seminar on Web). It was titled, <strong><span style="color: #ff0000;">The Web is Broken</span> </strong><span style="color: #ff0000;">&#8211;Why every feature is, in fact, a loophole</span>. A great experience.</p>
<p>Although after listening to my own recording, I felt that a number of things went wrong (mostly because of problems in connectivity and slow internet speed). The issue I was worried about was that it was targeted at developers with beginner to intermediate level knowledge of web, but the topic was very broad. Fortunately, I received some good feedback along with requests to conduct more such sessions. The talk was scheduled for 1.5 hours, but it stretched for 2.5 hours. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Here is the presentation:</p>
<div id="__ss_206607" style="width: 425px; text-align: left;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=the-web-is-broken-by-bipin-3-upadhyay-1197983798366666-4" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=the-web-is-broken-by-bipin-3-upadhyay-1197983798366666-4" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;"><a href="http://www.slideshare.net/?src=embed"><img style="border:0px none;margin-bottom:-5px" src="http://static.slideshare.net/swf/logo_embd.png" alt="SlideShare" /></a> | <a title="View '" href="http://www.slideshare.net/bipin/the-web-is-broken-by-bipin-3-upadhyay?src=embed">View</a> | <a href="http://www.slideshare.net/upload?src=embed">Upload your own</a></div>
</div>
<p>I hope you like it too. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/what-a-new-year-gift/" rel="bookmark" title="January 5, 2008">What a new year Gift! :)</a></li>

<li><a href="http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/" rel="bookmark" title="May 9, 2007">Open JavaFX, an alternative to AJAX?</a></li>

<li><a href="http://projectbee.org/blog/archive/how-to-implementing-shindig/" rel="bookmark" title="September 30, 2008">[How To] Implementing Shindig.</a></li>

<li><a href="http://projectbee.org/blog/archive/samy-a-hero-or-a-villian/" rel="bookmark" title="February 5, 2007">Samy: A hero or a villian!</a></li>

<li><a href="http://projectbee.org/blog/archive/http-protocol/" rel="bookmark" title="December 15, 2011">HTTP protocol and other stuff that power the web</a></li>
</ul><!-- Similar Posts took 8.630 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/the-web-is-broken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yahoo! gone Insane!</title>
		<link>http://projectbee.org/blog/archive/yahoo-gone-insane/</link>
		<comments>http://projectbee.org/blog/archive/yahoo-gone-insane/#comments</comments>
		<pubDate>Fri, 10 Aug 2007 20:31:05 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[humour]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[yahoo]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/08/11/yahoo-gone-insane/</guid>
		<description><![CDATA[No Yahoo! hasn&#8217;t changed it&#8217;s name to Insane!. It&#8217;s just their behavior that has gone insane. If you&#8217;ve been a member of some online group for quite some time, chances are that the group is on Yahoo! Groups. Same with me. This story is concerned with my college batch online egroup. Yahoo! groups has a [...]]]></description>
			<content:encoded><![CDATA[<p>No <strong>Yahoo!</strong> hasn&#8217;t changed it&#8217;s name to <strong>Insane!</strong>. It&#8217;s just their behavior that has gone insane.</p>
<p>If you&#8217;ve been a member of some online group for quite some time, chances are that the group is on Yahoo! Groups. Same with me. This story is concerned with my college batch online egroup. Yahoo! groups has a very useful feature which let&#8217;s you specify ANY email address for your mails to be delivered (and receive mails from, obviously). I had configured it to my company mail id.</p>
<p>Now like a lot of people, I have two Yahoo! ids, NB and AS. The group is configured with NB. Today, I decided to change it to one of my other Yahoo! id AS, mostly because I use it as the primary id.</p>
<p>&#8230;.but it won&#8217;t get changed. The error</p>
<ul>
<li><span style="color: red;">Your email address &#8220;AS@yahoo.co.in&#8221; is in an invalid format.</span></li>
<li><span style="color: red;">Invalid <strong>Email Address</strong>.Your Email address of <strong>AS@yahoo.co.in</strong> belongs to <strong>yahoo.co.in</strong> which is restricted from use in Yahoo! registrations. Please choose a different email address.</span></li>
</ul>
<blockquote><p><a title="yahoogoneinsane.jpg" href="http://projectbee.org/blog/wp-content/uploads/2007/08/yahoogoneinsane1.jpg"><img src="http://projectbee.org/blog/wp-content/uploads/2007/08/yahoogoneinsane1.jpg" alt="yahoogoneinsane.jpg" width="254" height="119" /></a></p></blockquote>
<p>I thought, they might be allowing only &#8220;yahoo.com&#8221; addresses. So I changed my input to &#8220;AS@yahoo.com, hoping for an error message that the specified email address doesn&#8217;t exist&#8230; but what I get is:</p>
<ul>
<li><span style="color: #ff0000;">Invalid <strong>Email Address</strong>.Your Email address of <strong>AS@yahoo.com</strong> belongs to <strong>yahoo.com</strong> which is restricted from use in Yahoo! registrations. Please choose a different email address.</span></li>
</ul>
<blockquote><p><a title="yahoogoneinsane2.jpg" href="http://projectbee.org/blog/wp-content/uploads/2007/08/yahoogoneinsane21.jpg"><img src="http://projectbee.org/blog/wp-content/uploads/2007/08/yahoogoneinsane21.jpg" alt="yahoogoneinsane2.jpg" width="277" height="137" /></a></p></blockquote>
<p><strong>Now WHAT IN THE HELL are the Yahoo! developers thinking? They don&#8217;t think that it&#8217;ll stop people from creating more than one id&#8230; or do they?</strong></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/" rel="bookmark" title="January 28, 2006">&#34;COLUKABKI &#8211; AOL &#8211; MSN &#8211; YAHOO &#8211; RED CROSS&#34;&#8230;.. aaah Comm&#8217;n Gimme a break.</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-headache-no-listening-sockets-available/" rel="bookmark" title="August 8, 2007">Apache Headache: &#8220;no listening sockets available&#8221;</a></li>

<li><a href="http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/" rel="bookmark" title="May 19, 2007">Rediffmail Bug. Anyone Interested?</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoos-javascript-based-mp3-player/" rel="bookmark" title="January 9, 2008">Yahoo!&#8217;s javascript based media player!</a></li>

<li><a href="http://projectbee.org/blog/archive/reviving-owasp-bangalore-chapter/" rel="bookmark" title="June 29, 2008">Reviving OWASP Bangalore Chapter</a></li>
</ul><!-- Similar Posts took 5.176 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/yahoo-gone-insane/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Java vulnerable to remote compromise</title>
		<link>http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/</link>
		<comments>http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/#comments</comments>
		<pubDate>Sat, 14 Jul 2007 02:10:31 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/07/14/java-vulnerable-to-remote-compromise/</guid>
		<description><![CDATA[ZDNet Asia reports that Google Security team has discovered as &#8220;Dangerous Java Flaw that threaten&#8217;s Virtually Everything&#8220;. The interesting part of this news is that, apart from a few scary statements, it doesn&#8217;t inform you anything else. The Sun advisory page on this flaw, however, informs you about two flaws which are nothing but Buffer [...]]]></description>
			<content:encoded><![CDATA[<p>ZDNet Asia reports that Google Security team has discovered as &#8220;<a href="http://www.zdnetasia.com/news/security/printfriendly.htm?AT=62028389-39000005c">Dangerous Java Flaw that threaten&#8217;s Virtually Everything</a>&#8220;. The interesting part of this news is that, apart from a few scary statements, it doesn&#8217;t inform you anything else.</p>
<p>The <a href="http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102934-1">Sun advisory page </a>on this flaw, however, informs you about two flaws which are nothing but Buffer Overflows. Do not mistake me that I am undermining the impact of Buffer Overflow Attacks in any way. It&#8217;s just the ZD Net article&#8217;s title which&#8217;s bugging me. It makes the flaw look like an out of world ET attack scenario.</p>
<ol>
<li><em>A buffer overflow vulnerability in the image parsing code in the Java Runtime Environment may allow an untrusted applet or application to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.</em></li>
<li><em>A second vulnerability may allow an untrusted applet or application to cause the Java Virtual Machine to hang.</em></li>
</ol>
<p>Now firstly, Buffer Overflows are no new form of attacks. They have been here since the existence of man (I admit that&#8217;s a little much <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> ), and they are here to stay. Thus, articles like this are more like <strong>FUD</strong>, IMHO.<br />
Secondly, <strong>applet support is very limited in mobile devices</strong>. Not to mention that <a href="http://developers.sun.com/mobility/midp/questions/imagetype/">J2ME supports only PNG format</a>. Thus, not &#8220;virtually everything&#8221; is everything.<br />
Finally, <strong>image parsing library in Sun&#8217;s Java implementation is through a native library</strong>. It&#8217;s time that Sun writes a Java equivalent for it to avoid other similar issues. Further, since Java is now GPL, I also hope to see the code coming from some random, pimply, introvert teenage kid. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>The problems can be resolved by updating the packages. Detailed info provided on <a href="http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102934-1">the Sun&#8217;s advisory</a>.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/" rel="bookmark" title="May 26, 2007">An insight into Sun&#8217;s *crazy* strategy.</a></li>

<li><a href="http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/" rel="bookmark" title="May 9, 2007">Open JavaFX, an alternative to AJAX?</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/amazing-interrupt-handling/" rel="bookmark" title="April 12, 2007">Amazing Interrupt Handling!</a></li>

<li><a href="http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/" rel="bookmark" title="July 3, 2007">Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</a></li>
</ul><!-- Similar Posts took 5.546 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TPM Boys withdraw paper from BlackHat USA</title>
		<link>http://projectbee.org/blog/archive/tpm-boys-withdraw-paper-from-blackhat-usa/</link>
		<comments>http://projectbee.org/blog/archive/tpm-boys-withdraw-paper-from-blackhat-usa/#comments</comments>
		<pubDate>Thu, 05 Jul 2007 12:46:27 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Federico Biancuzzi]]></category>
		<category><![CDATA[Nitin Kumar]]></category>
		<category><![CDATA[reality]]></category>
		<category><![CDATA[slashdot]]></category>
		<category><![CDATA[Vipin Kumar]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/07/05/tpm-boys-withdraw-paper-from-blackhat-usa/</guid>
		<description><![CDATA[I hope you remember the young Indian security researchers Vipin Kumar (22) and Nitin Kumar (23), the TPM Boys [I guess, that's the way they call themselves. At least their blog confirms that. ]They presented a Paper &#8220;Vboot Kit: Compromising Windows Vista Security&#8221; at Blackhat Europe &#8211; 2007. The talk explained the (different) booting process [...]]]></description>
			<content:encoded><![CDATA[<p>I hope you remember the young Indian security researchers <strong>Vipin Kumar </strong>(22) and <strong>Nitin Kumar</strong> (23), the TPM Boys [I guess, that's the way they call themselves. At least <a href="http://tpmboys.blogspot.com">their blog </a>confirms that. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ]They presented a Paper &#8220;<span class="textgreenbold10"><a href="http://www.heise-security.co.uk/news/87709"><strong>Vboot Kit: Compromising Windows Vista Security</strong></a>&#8221; </span>at Blackhat Europe &#8211; 2007.</p>
<p>The talk explained the (different) booting process of Windows Vista. It also introduced the concept of manipulating an OS during its boot process using VBootkit. Finally, they gave a live demo of VBootkit in action (on Vista).</p>
<p>This event was <a href="http://it.slashdot.org/article.pl?sid=07/04/04/0047200">Slashdotted</a>. VBootkit was also <a href="http://www.schneier.com/blog/archives/2007/04/vbootkit_bypass.html">blogged by <strong>Bruce Schneier</strong></a>. Here is an <a href="http://www.securityfocus.com/print/columnists/442">interview of the &#8220;boys&#8221; at <strong>SecurityFocus</strong></a> by  		Federico Biancuzzi. In their own words, &#8220;<em><span class="body">Vbootkit is much like a door or a shortcut to access vista&#8217;s kernel&#8230;&#8230;. </span></em><span class="body"><em>since vbootkit becomes part of the kernel, it can do anything that Vista&#8217;s kernel can do</em>.&#8221;</span></p>
<p>This all, however, is a news of past. The current news stirred more vigour and controversy. They had yet another paper &#8220;<a href="http://www.networkworld.com/news/2007/062707-black-hat-abstract.html"><strong>TPMkit: Breaking the Legend of Trusted Computing (TC [TPM]) and Vista (BitLocker)</strong></a>&#8221; scheduled to be presented at Blackhat USA &#8211; 2007. They withdrew there paper last week without any comments. This news  was <a href="http://it.slashdot.org/article.pl?sid=07/06/29/1330201">Slashdotted</a> and resulted in a (typical) <em>slashdotian</em> variety of comments. Some even doubted if they really had any success in their research. Well, you cannot really blame them. That&#8217;s the fussy nature of our FOSS communities&#8230; errr&#8230; wait. Before you bash me, I&#8217;d like to remind you that it&#8217;s not (only) me who says that. It was originally cited by Mark Shuttleworth. An amazing number of people opposed Mark by creating a lot of Fuss. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Coming back to the story. A user, by the handle PoliTech, <a href="http://it.slashdot.org/comments.pl?sid=243259&amp;cid=19689291">commented on Slashdot </a>and reminded the <span class="body">Michael Lynn&#8217;s paper at Blackhat about his research on Cisco Routers. Cisco and ISS sued Lynn and the management of Black Hat conference. It&#8217;s worth noting that Lynn was an ISS employee. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></p>
<p>It should be also be noted that Vipin and Nitin&#8217;s previous presentation was in Amsterdam, Europe. This presentation, however, was scheduled in US&#8230; and the (stupid) US laws can screw things up. Based on Lynn&#8217;s case, it is quite apparent that Vipin and Nitin didn&#8217;t wish to get caught in any such <em>undesirable</em> situation.</p>
<p>I hope to see them present the paper at some other conference (or location) pretty soon. Best of luck guys.</p>
<p><em>OffTopic: Coincidentally, my younger brother&#8217;s name is Nitin. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </em></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/slashdot-uh/" rel="bookmark" title="May 21, 2008">Slashdot, uh! :|</a></li>

<li><a href="http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/" rel="bookmark" title="February 19, 2007">Vista!!! (3 Exclamations.) is here? (Why :-/)</a></li>

<li><a href="http://projectbee.org/blog/archive/the-web-is-broken/" rel="bookmark" title="October 12, 2007">The Web is Broken</a></li>

<li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-1/" rel="bookmark" title="August 21, 2008">OWASP AppSec Conf Delhi &#8211; Day 1</a></li>

<li><a href="http://projectbee.org/blog/archive/bittus-back/" rel="bookmark" title="June 12, 2008">Bittu&#8217;s back :)</a></li>
</ul><!-- Similar Posts took 6.365 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/tpm-boys-withdraw-paper-from-blackhat-usa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bill Gates no more The Richest</title>
		<link>http://projectbee.org/blog/archive/bill-gates-no-more-the-richest/</link>
		<comments>http://projectbee.org/blog/archive/bill-gates-no-more-the-richest/#comments</comments>
		<pubDate>Wed, 04 Jul 2007 10:09:53 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[Bill Gates]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/07/04/bill-gates-no-more-the-richest/</guid>
		<description><![CDATA[Slashdot updated today that Billy Boy is no more the Richest man in the world. The position is, however, not official. The standard is Forbes list. Billy Boy has been surpassed by Carlos Slim, the Mexican Telecom tycoon. Bill&#8217;s current estimated wealth is $ 59.2 billion, while slims estimated wealth is $67.8 billion. Reasons: Two [...]]]></description>
			<content:encoded><![CDATA[<p>Slashdot updated today that Billy Boy is no more the Richest man in the world. The position is, however, not official. The standard is Forbes list.</p>
<p>Billy Boy has been surpassed by Carlos Slim, the Mexican Telecom tycoon. Bill&#8217;s current estimated wealth is $ 59.2 billion, while slims estimated wealth is $67.8 billion.</p>
<p><strong> Reasons</strong>:<br />
Two of the most obvious reasons are:</p>
<ol>
<li>A surge of 27% in the stock price of Slim&#8217;s wireless company, America Movil, in the second quarter</li>
<li>Bill reduced his net wealth by more than $30 billion, which he put in the Bill and Melinda Gates Foundation. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ol>
<p><strong>What Next?</strong><br />
Nothing really. To a question asked to him at the Microsoft conference last year, whether he&#8217;d be upset if someday he wasn&#8217;t the richest <em>creature </em> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> , <a href="http://blog.seattlepi.nwsource.com/microsoft/archives/117497.asp">he responded</a>, &#8220;&#8221;I wish I wasn&#8217;t. &#8220;There&#8217;s nothing good that comes out of that.&#8221;<br />
Moreover, he&#8217;d be retiring in a year&#8217;s time and would be dedicating he&#8217;s time, energy, and money to the Bill &amp; Melinda Gates Foundation. <a href="http://projectbee.org/blog/archive/bill-gates-wins-me/">I wish him luck.</a> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/bill-gates-wins-me/" rel="bookmark" title="June 19, 2007">Bill Gates wins me!</a></li>

<li><a href="http://projectbee.org/blog/archive/ot-the-rant-of-a-republic-indian-hacker/" rel="bookmark" title="January 26, 2009">[OT] The Rant of a &#8220;Republic&#8221; Indian Hacker</a></li>

<li><a href="http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/" rel="bookmark" title="January 28, 2006">&#34;COLUKABKI &#8211; AOL &#8211; MSN &#8211; YAHOO &#8211; RED CROSS&#34;&#8230;.. aaah Comm&#8217;n Gimme a break.</a></li>

<li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/adieu-billy-boy/" rel="bookmark" title="June 30, 2008">Adieu, Billy Boy!</a></li>
</ul><!-- Similar Posts took 8.043 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/bill-gates-no-more-the-richest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</title>
		<link>http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/</link>
		<comments>http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/#comments</comments>
		<pubDate>Tue, 03 Jul 2007 11:27:34 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[rating]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/07/03/month-of-search-engine-bugs-mission-accomplished/</guid>
		<description><![CDATA[The Month of Search Engine Bugs by MustLive has come to an end. MutLive reports: In the project took part 33 search engines (30 web engines and 3 local engines) of 19 vendors, some vendors have several engines. The list of project’s participants (in order of appearance): Meta, Yahoo, HotBot, Gigablast, MSN, Clusty, Yandex, Yandex.Server [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://websecurity.com.ua/1114/">Month of Search Engine Bugs </a>by <a href="http://websecurity.com.ua/">MustLive</a> has come to an end.</p>
<p>MutLive reports:</p>
<blockquote><p>In the project took part <strong>33 search engines</strong> (30 web engines and 3 local engines) of <strong>19 vendors</strong>, some vendors have several engines. The list of project’s participants (in order of appearance): <em>Meta, Yahoo, HotBot, Gigablast, MSN, Clusty, Yandex, Yandex.Server (local engine), Search Europe, Rambler, Ask.com, Ezilon, AltaVista, AltaVista local (local engine), MetaCrawler, Mamma, Google, Google Custom Search Engine (local engine), My Way, Lycos, Aport, Netscape Search, WebCrawler, Dogpile, AOL Search, My Search, My Web Search, LookSmart, DMOZ (Open Directory Project), InfoSpace, Euroseek, Kelkoo, Excite</em>.</p>
<p>Altogether there were published 104 vulnerabilities in mentioned engines. Including Cross-Site Scripting (as XSS, and as HTML Injection), Full path disclosure, Content Spoofing and Information disclosure vulnerabilities. It is without taking into account redirectors in search engines (altogether there were published 23 redirectors).</p>
<p><strong>Results of the projects:</strong> fixed 44 vulnerabilities from 104 (without taking into account redirectors). It is 42,31% fixed vulnerabilities. Owners of search engines have a place for improvements of their engines’ security.</p></blockquote>
<p>Over a period of 30 days, 104 and vulnerabilities/bugs were discovered out of which only 44 have been fixed. Out of these 19 vendors, only two (Rambler and Ezilon) have thanked him for his commendable hardwork.</p>
<p>Several researchers, including <a href="http://jeremiahgrossman.blogspot.com/2007/07/30-days-104-search-engine.html">Jeremiah</a>, <a href="http://ha.ckers.org/blog/20070701/month-of-search-engine-bugs-comes-to-a-close/">RSnake</a>, <a href="http://planet-websecurity.org/30+days%2C+104+Search+Engine+Vulnerabilities/">Christ1an</a> etc. blogged about it. Considering the complexities involved in the fixing a bug, they agree at some point that 44  is still a good number. However, there is one Big &#8220;Cheer&#8221; Leader<a href="http://websecurity.com.ua/1114/#comment-48778"> which isn&#8217;t fixing the bugs</a>. No points for guessing that the Leader believes  in &#8220;not doing evil things&#8221;.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>

<li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>

<li><a href="http://projectbee.org/blog/archive/idle-nights-devils-mind/" rel="bookmark" title="April 12, 2007">Idle Nights: Devil&#8217;s Mind</a></li>

<li><a href="http://projectbee.org/blog/archive/is-google-bomb-really-diffused/" rel="bookmark" title="April 28, 2007">Is Google Bomb REALLY Diffused?</a></li>
</ul><!-- Similar Posts took 11.350 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bill Gates wins me!</title>
		<link>http://projectbee.org/blog/archive/bill-gates-wins-me/</link>
		<comments>http://projectbee.org/blog/archive/bill-gates-wins-me/#comments</comments>
		<pubDate>Tue, 19 Jun 2007 20:13:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[humour]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[dreams]]></category>
		<category><![CDATA[reality]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/06/19/bill-gates-wins-me/</guid>
		<description><![CDATA[I realized that the title of this post has a contrast with my previous post, only after I wrote the topic. Thus, I feel that it is obligatory to mention that I am still Anti-M$. I still do not support there business model. Phew!&#8230;and yes. The contrast in the names is just a mere coincidence. [...]]]></description>
			<content:encoded><![CDATA[<p>I realized that the title of this post has a contrast with <a href="http://code-in-my-bug.blogspot.com/2007/06/google-lost-me.html">my previous post</a>, only after I wrote the topic. Thus, I feel that it is obligatory to mention that <span style="font-weight:bold;"><a href="http://code-in-my-bug.blogspot.com/2006/03/wileys-best-selling-comp-book.html">I am</a> <a href="http://code-in-my-bug.blogspot.com/2007/02/vista-3-exclamations-is-here-question.html">still</a> <a href="http://code-in-my-bug.blogspot.com/2007/04/amazing-interrupt-handling.html">Anti-M$</a></span>. I still do not support there business model. Phew!<br />&#8230;and yes. <span style="font-weight:bold;">The contrast in the names is just a mere coincidence</span>. I know it&#8217;s tough to believe, but then I don&#8217;t lie.</p>
<p>Now coming to the topic.<br />I have always appreciated the way Bill Gates (and, of course, his wife) has spent time and money on Melinda Foundation. I remember posting<a href="http://www.clazh.com/bill-gates-vs-steve-jobs-whos-the-better-person/#comment-1108"> my views</a> a few days ago <a href="http://www.clazh.com/bill-gates-vs-steve-jobs-whos-the-better-person">on Arpit&#8217;s blog</a>.</p>
<p>A few minutes ago, I read <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi">Bill Gates speech transcript that he delivered at Harvard</a>.<br />He starts the speech on a light note and calls himself a &#8220;bad influence&#8221; by reminding that he made Steve Ballmer drop out of B-School (Oh! How I wish that Gates had failed in convincing Ballmer <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ).<br />He continues his speech by talking about how ignorant he was about the socio-economic and health problems of the developing nations, when he joined Harvard (and even later.)<br />The thing that blew me was that for the most part of his speech, he talked about how technology can and should be used for the help of these people.</p>
<p>I won&#8217;t mention the details.  I&#8217;d pursue you to <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi">read it</a>. I hate to say, but Bill seems to be a bright candidate for my future plans (after he drops out of M$, of course).</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/bill-gates-no-more-the-richest/" rel="bookmark" title="July 4, 2007">Bill Gates no more The Richest</a></li>

<li><a href="http://projectbee.org/blog/archive/dreams-and-huh-reality/" rel="bookmark" title="June 4, 2007">Dreams&#8230; and (huh!) Reality.</a></li>

<li><a href="http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/" rel="bookmark" title="May 26, 2007">An insight into Sun&#8217;s *crazy* strategy.</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>

<li><a href="http://projectbee.org/blog/archive/is-google-bomb-really-diffused/" rel="bookmark" title="April 28, 2007">Is Google Bomb REALLY Diffused?</a></li>
</ul><!-- Similar Posts took 5.229 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/bill-gates-wins-me/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Google Lost Me!</title>
		<link>http://projectbee.org/blog/archive/google-lost-me/</link>
		<comments>http://projectbee.org/blog/archive/google-lost-me/#comments</comments>
		<pubDate>Sun, 17 Jun 2007 06:54:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[rating]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/06/17/google-lost-me/</guid>
		<description><![CDATA[It&#8217;s strange writing something like this using a service that&#8217;s owned by Google. But it was long overdue. There was a time when I used address Google as &#8220;Google God&#8221; .Used to believe a lot that they religiously follow their &#8220;Do no Evil&#8221; motto. I forgot that as companies grow, there are bound to be [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s strange writing something like this using a service that&#8217;s owned by Google. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> <br />But it was long overdue.</p>
<p>There was a time when I used address Google as &#8220;Google God&#8221; <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .<br />Used to believe a lot that they religiously follow their &#8220;Do no Evil&#8221; motto. I forgot that as companies grow, there are bound to be employs who are evil by nature.<br />It reminds me of my Pre-Placement Training during college days when I was &#8220;tutored&#8221; that, <span style="font-style:italic;">Honesty is not a strength. You are supposed to be honest</span>&#8221; This obviously isn&#8217;t true when people take the excuse of &#8220;everybody-is-doing-it-so-why-not-me&#8221;.<br />And lets face it.<br />Money matters!</p>
<p>Anyways, coming back to the topic; I mentioned in one my previous blogs when my Google AdSense account was disabled because of my own mistakes. I took the responsibility and had no complaints. However, when my AdSense account was disabled for the second time, I made a thorough study of their privacy policies. That&#8217;s when I came to know about their two-faces.<br />They allow several sites to utilize their services even when they falter with the terms and conditions. One thing common among all these sites was, &#8220;they all are High Traffic sites&#8221;.</p>
<p>As I mentioned, a post on the topic was long overdue. I stopped myself with one or other reason. The latest development, however, made me talk about it.<br />According to <a href="http://www.privacyinternational.org/article.shtml?cmd%5B347%5D=x-347-553961"><span style="font-weight:bold;">Privacy International&#8217;s</span> latest report</a> on Top 23 Internet Companies, Google held the last spot (even below M$). This topic, as Privacy International itself admits, is controversial. It&#8217;s report however, is substantially supported.<br />You might want to have a look at the post on the same topic <a href="http://ha.ckers.org/blog/20070612/google-ranked-worst-in-privacy/">on RSnake&#8217;s blog</a>. Do not miss out on <a href="http://ha.ckers.org/blog/20070612/google-ranked-worst-in-privacy/#comment-39022">the comments</a>.</p>
<p><span style="font-size:85%;"><span style="font-weight:bold;">Footnote:</span> This post is not an outlet to my anguish. I (mistakenly) had more faith in Google than most of you. Another post on <span style="font-style:italic;font-weight:bold;">innovativeness</span><span style="font-weight:bold;"> of Google technologies</span> is due.<br />And BTW, I do not mean to say that Google has turned evil. I believe as the company has grown, the motto has changed to &#8220;<span style="font-weight:bold;">Do no Evil. If there is any, close your eyes</span>&#8220;.<br /></span></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/bill-gates-wins-me/" rel="bookmark" title="June 19, 2007">Bill Gates wins me!</a></li>

<li><a href="http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/" rel="bookmark" title="July 3, 2007">Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</a></li>

<li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>

<li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/is-google-bomb-really-diffused/" rel="bookmark" title="April 28, 2007">Is Google Bomb REALLY Diffused?</a></li>
</ul><!-- Similar Posts took 4.913 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/google-lost-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An insight into Sun&#8217;s *crazy* strategy.</title>
		<link>http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/</link>
		<comments>http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/#comments</comments>
		<pubDate>Sat, 26 May 2007 11:25:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[apache]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[books]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/05/26/an-insight-into-suns-crazy-strategy/</guid>
		<description><![CDATA[I have been reading a lot of discussion on Sun&#8217;s current market position/revenue versus their *mad* strategy. I have simultaneously been working on Java&#8217;s history for my book. I thought it might be interesting to post my views on the topic and see what others are thinking. To justify/criticize Sun&#8217;s current modus operandi, I will [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span style="font-style:italic;"><span style="font-size:85%;">I have been reading a lot of discussion on Sun&#8217;s current market position/revenue versus their *mad* strategy. I have simultaneously been working on Java&#8217;s history for my book. I thought it might be interesting to post my views on the topic and see what others are thinking. To justify/criticize Sun&#8217;s current modus operandi, I will talk a little about their past strategies, and their respective outcomes.</span></span></p>
<p class="MsoNormal"><b>The Past</b></p>
<p class="MsoNormal">Most of the people know James Gosling as the father of Java. Only a few know that he was also the lead engineer of Gosmacs (gmacs or Gosling Emacs) and NeWS. Now, I won’t be talking about Gosmacs (which according to some people is/was the reason of some conflict between RMS and Gosling. Phew!)<br />However, NeWS (Network extensible Window System) is of a little concern, mostly because it was arguably superior to X Window System… and because it FAILED. The most important reason for its failure (and X Window’s success) is that Sun kept it proprietary.<br />Later on when Sun developed Java, some people, especially the genius Eric Schmidt (then CTO-Sun, now CEO-Google), were aware that keeping Java <span style="font-style:italic;">within enclosed fences</span> will lead to similar <span style="font-style:italic;">devastating</span> results. Not to mention that *7 (for which Java was developed) had already failed and Java was still in search of a viable market.</p>
<p class="MsoNormal">So what did he do?<br />He focused on making it as open as possible and tried building a *Java Community*. (Google SoC, IMHO, is also a “win-the-community-and-you-win-everything-else” approach. But then that’s a different topic altogether. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  )</p>
<p class="MsoNormal">Where were we?<br />Yeah! So he focused on building a Java Community.<br />Apart from organizing developer conferences like JavaOne, Sun also encouraged user groups (JUGs), which reached over a number of 400 in year 2000 itself. In fact they went a step further with JCP (Java Community Process) to make the development of Java *as open as possible*.<br />The  reality behind all this community building scene was the fact that the direct control remained with Sun (well mostly).</p>
<p class="MsoNormal">Everything, however, was running smooth; for Sun as well as the Java developers.</p>
<p class="MsoNormal"> <i></i></p>
<blockquote><p style="color:rgb(102, 102, 0);" class="MsoNormal"><i>“I envy you. But such a thing is not meant to last.”</i></p>
<p class="MsoNormal"><span style="color:rgb(102, 102, 0);">                                            &#8212; </span><b><span style="color:rgb(102, 102, 0);">Persephone, Matrix Reloaded</span></p>
<p></b></p>
</blockquote>
<p class="MsoNormal"><b></b><span>I guess the above statement is valid for every aspect of human existence.</span><br />In early 2004, Jonathan Schwartz, referenced Eric Steven Raymond’s “<a href="http://www.catb.org/%7Eesr/writings/cathedral-bazaar">The Cathedral and the Bazaar</a>” and compared JCP to the “Bazaar”, stating that development of Linux was more like a “Cathedral”. I would not expand on it but this was enough to infuriate ESR <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>ESR wrote an open letter addressed to Scott McNealy, CEO-Sun, with a subject line “<a href="http://www.catb.org/%7Eesr/writings/let-java-go.html">Let Java Go</a>”. He accused Sun on several fronts (for which I’d pursue you to read <a href="http://www.catb.org/%7Eesr/writings/let-java-go.html">the letter</a>) and appealed to Open Source Java. A few weeks later RMS wrote an essay on<a href="http://www.gnu.org/philosophy/java-trap.html"> <i>Java Trap</i></a> and appealed the developers to contribute and use open source projects like GCJ/Gnu Classpath etc. Several other appeals/open letters were published (Apache’s Geir Magnusson Jr., IBM, etc.)</p>
<p>A series of events followed before Sun announced that it will be open sourcing Java. There main concern was Microsoft forking Java and hence, destroying its cross platform compatibility (which shows that they really were clueless on how Open source model works/ can work).<br />They had no other option than to Open Source the *giant*, and they did it.</p>
<p class="MsoNormal"><b>The Present</b></p>
<p class="MsoNormal">The past unarguably affects, if not defines, the present. Sun’s experience since the NFS days to (forced) Open Sourcing Java days taught/reminded them of their most important lesson.<br /><span style="font-weight:bold;">The Community is fruitful!</span><br /><span style="font-weight:bold;">Build a community and everything else will follow, sooner or later.</span></p>
<p class="MsoNormal">So here they are.<br />Open sourcing EVERYTHING.<br />Building Community, and making it mutually encashable. It’s obviously not so profitable for them today, but the future holds immense potential.</p>
<p class="MsoNormal">The way they have been endorsing and promoting stuff is simply adorable. Even NetBeans has its own *arena*.<br />Not to mention the, so called, developer conferences organized all over the world in a distributed fashion to reach the most number of developers.<span>  </span>I, however, have several concerns regarding them. You may read some of them at<i><a href="http://angraze.wordpress.com/2007/05/18/sun-technology-summit-07-bangalore"> Amit’s blog</a>. </i>I hope Sun listens to the plea of developers and improves the quality of these summits.</p>
<p class="MsoNormal">Another amazing strategy, IMHO, is the <a href="http://blogs.sun.com/"><i>blogs</i> </a>that Sun employees post regularly. I have subscribed some of them and it’s really amazing to see that how important role these blogs are playing in binding people. They often link each other&#8217;s (Sun Employees, of course) blogs. You can have a look at the <a href="http://blogs.sun.com/">Sun-Blogging homepage</a> to get a feel of the number of hits the folks out there are getting. Now even if I read only one of these, I’d get to know about latest developments. I am not sure whether it’s a part of their strategy, but it’s definitely working as a powerful advertising medium.<br />Yup! I know that employees of other firms write blogs too and probably get bigger number of hits, but I haven’t seen anyone of them making so much of a difference on an organizational level. (Please correct me if I am wrong)</p>
<p class="MsoNormal"><b>The Future</b></p>
<p class="MsoNormal">I am no Nostradamus and I cannot predict future.<br />All I can say is the future is (mostly) Free &amp; Open. IBM (previously referred Satan) secured its place (with a Halo on head) by contributing to the Apache httpd project and winning the FOSS community. Now it’s Sun’s turn and they are playing pretty well.<br />Yes, their revenue might be a concern today; but I don’t really see a reason why there future shouldn’t be bright. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/" rel="bookmark" title="July 14, 2007">Java vulnerable to remote compromise</a></li>

<li><a href="http://projectbee.org/blog/archive/dreams-and-huh-reality/" rel="bookmark" title="June 4, 2007">Dreams&#8230; and (huh!) Reality.</a></li>

<li><a href="http://projectbee.org/blog/archive/bill-gates-wins-me/" rel="bookmark" title="June 19, 2007">Bill Gates wins me!</a></li>

<li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-mysqlphp-installation-configuration-tutorial-for-beginners/" rel="bookmark" title="February 25, 2006">Apache-MySQLPHP Installation &#38; Configuration Tutorial for Beginners :)</a></li>
</ul><!-- Similar Posts took 5.412 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Rediffmail Bug. Anyone Interested?</title>
		<link>http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/</link>
		<comments>http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/#comments</comments>
		<pubDate>Sat, 19 May 2007 08:52:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[rating]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/05/19/rediffmail-bug-anyone-interested/</guid>
		<description><![CDATA[The title may lure you to assume that I am going to talk about some security bug. Well, I am not&#8230; or I&#8217;d rather say I haven&#8217;t yet thought of any ways to exploit it. If you come up with something, do let us know. Now back to the topic. Almost all the huge players [...]]]></description>
			<content:encoded><![CDATA[<p>The title may lure you to assume that I am going to talk about some security bug. Well, I am not&#8230; or I&#8217;d rather say I haven&#8217;t yet thought of any ways to exploit it. If you come up with something, do let us know.</p>
<p>Now back to the topic.<br />
Almost all the huge players are now moving to the AJAX arena. They are in fact coming up with new technologies like Silverlight, Apollo, JavaFx. I am personally not a very big fan of AJAX, but then it doesn&#8217;t make any difference.  I am, however, interested in these new athletes, particularly JavaFx.</p>
<p>One of the major concerns of any AJAX programmer, IMHO, should be to take care of a situation where the user DOES NOT HAVE or DOES NOT WISH to use Javascript. It should be  a growing concern when we have plugins like <a href="http://noscript.net">NoScript </a>(Oh! I Love it.) and we have reasons to use it. Apart from the security concerns, it blocks most of the stupid ads that I am not interested in.</p>
<p>Bottom line, there should be a minimal interface to fall back to (like the one GMail has). The rediffmail coders have done the same and provided a&#8230;. ummmm  BackUpInterface thingy. However, they probably forgot that the *thingy* is there because the person&#8217;s browser DOES NOT SUPPORT Javascript.</p>
<p><span style="font-weight:bold;">My Story, My Words:</span><br />
I used the NoScript plugin to forbid rediff.com domain, opened the site rediffmail.com, entered userid and password&#8230; and said&#8230; <span style="font-style:italic;">Khul Ja Sim Sim</span>. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Bingo I was in and was able to read my mails without any fuss. Then I decided to delete some mails&#8230; wait a sec! What the heck!<br />
I am not able to.<br />
Move mails??? Nopes.<br />
Compose? Okay.<br />
Send?? Sorry.<br />
Save Draft? Sorry.<br />
Cancel??? Sorry. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>I concluded that all that looks like a Button uses javascript. However, the links were, fortunately or unfortunately, working.<br />
The <span style="font-weight:bold;">Logout</span>&#8216;s like a link. So it&#8217;d obvoiusly work.<br />
<span style="font-style:italic;">click.. click.. </span><span style="font-style:italic;">click</span><span style="font-style:italic;">click</span><span style="font-style:italic;">click.<br />
</span>What the Heck!.<br />
<span style="font-weight:bold;">Logout </span>operation calls some javascript function <span style="font-weight:bold;font-style:italic;">do_logout()</span><span style="font-style:italic;"><span style="font-weight:bold;">.</span><br />
</span><br />
So basically, if I am an average internet user and do not have javascript, I&#8217;d log into my rediffmail account, read mails, try composing but won&#8217;t be able to send&#8230; and worse, I won&#8217;t be able to logout.  Not understanding anything, I might close the browser  window.<br />
And what if I am at a cybercafe???</p>
<p>I am sure there is way to revive the session even if the browser window is closed (I remember reading of some similar old Yahoo! bug). If you&#8217;re interested, take on from here. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Now for the other people. I would really like to know how many people actually have a rediff aaccount and actually use it .<br />
I have one too&#8230; and I login in&#8230; say a month.<br />
I am not at all blaming rediffmail service (Okay! A little <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> ), I am just interested in the figures.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/" rel="bookmark" title="May 9, 2007">Open JavaFX, an alternative to AJAX?</a></li>

<li><a href="http://projectbee.org/blog/archive/iframes-to-be-or-not-to-be/" rel="bookmark" title="September 10, 2007">IFrames &#8211; To be or not to be?</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoo-gone-insane/" rel="bookmark" title="August 11, 2007">Yahoo! gone Insane!</a></li>

<li><a href="http://projectbee.org/blog/archive/an-insight-into-suns-crazy-strategy/" rel="bookmark" title="May 26, 2007">An insight into Sun&#8217;s *crazy* strategy.</a></li>

<li><a href="http://projectbee.org/blog/archive/noscript-for-guaranteed-protection-from-evil-iframes/" rel="bookmark" title="September 13, 2007">NoScript: For Guaranteed Protection From Evil IFrames</a></li>
</ul><!-- Similar Posts took 9.585 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Open JavaFX, an alternative to AJAX?</title>
		<link>http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/</link>
		<comments>http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/#comments</comments>
		<pubDate>Wed, 09 May 2007 12:24:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[slashdot]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/05/09/open-javafx-an-alternative-to-ajax/</guid>
		<description><![CDATA[Strange things happen to me all the time.When I came to the office a few hours ago, I came across JavaFX scripting language while reading random blogs. I found it pretty interesting and decided to check it out.So I added the module in my NetBeans IDE and started playing with it. Though I could not [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:georgia;">Strange things happen to me all the time.<br />When I came to the office a few hours ago, I came across <a href="https://openjfx.dev.java.net">JavaFX scripting language</a> while reading random blogs.</p>
<p>I found it pretty interesting and decided to check it out.<br />So I added the module in my NetBeans IDE and started playing with it. Though I could not fiddle for quite long, I found it pretty good. In fact, it looks to be amazing through the initial glances (though I haven&#8217;t done any serious coding in it yet). I have bookmarked some of the pages with a motive to get back to the kid.<br /></span><span style="font-family:georgia;">However, I  must mention that it was pretty slow. I am not sure if office&#8217;s system has something to do with it.]</span><br /><span style="font-family:georgia;"><br />I then resumed my other tasks; little did I know that the language has already created waves.<br />Slashdot is running an article: </span><a href="http://it.slashdot.org/article.pl?sid=07/05/08/2033255"><span style="font-weight:bold;">Sun Debuts JavaFX As Alternative To AJAX</span></a></p>
<p>That was a real surprise to me. JavaFX was unveiled at <a href="http://www.internetnews.com/dev-news/article.php/3676226">JavaOne today</a>. I initially thought that the language has been there for quite sometime and I was stupid enough to have missed it somehow.</p>
<p>Finally, I too hope that it turns out to be an AJAX killer; not just because I have never been a javascript fan, but also because it&#8217;ll hopefully reduce the dangers of XSS, which according to <a href="http://jeremiahgrossman.blogspot.com">Jeremiah Grossman </a>is the <a href="http://jeremiahgrossman.blogspot.com/2007/04/xss-attacks-book.html">next Buffer Overflow (and Javascript, the new ShellCode <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </a> ).</p>
<p>Footnotes: Hopefully, I&#8217;ll get some time from my official work to play with JavaFX and update on the same.<br />&#8230;and by the way, if it turns out to be an AJAX killer; will we rename it to AJilla??? [For the uninformed, Mozilla = Mosaic + killer <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ]</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/" rel="bookmark" title="May 19, 2007">Rediffmail Bug. Anyone Interested?</a></li>

<li><a href="http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/" rel="bookmark" title="July 14, 2007">Java vulnerable to remote compromise</a></li>

<li><a href="http://projectbee.org/blog/archive/dreams-and-huh-reality/" rel="bookmark" title="June 4, 2007">Dreams&#8230; and (huh!) Reality.</a></li>

<li><a href="http://projectbee.org/blog/archive/grabbing-video-from-youtube/" rel="bookmark" title="January 6, 2007">Grabbing Video from Youtube.</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoos-javascript-based-mp3-player/" rel="bookmark" title="January 9, 2008">Yahoo!&#8217;s javascript based media player!</a></li>
</ul><!-- Similar Posts took 5.077 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vista!!! (3 Exclamations.) is here? (Why :-/)</title>
		<link>http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/</link>
		<comments>http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/#comments</comments>
		<pubDate>Mon, 19 Feb 2007 20:34:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[apple]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[rating]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/02/19/vista-3-exclamations-is-here-why/</guid>
		<description><![CDATA[I don&#8217;t intend to post any review of the vista. There are some neatly written essays on the topics by experts, like this one. I was going through the article and stumbled on this page, which has the picture given below. What happened was due merely due to fast glance and my mouse cursor covering [...]]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t intend to post any review of the vista.<br />
There are some neatly written essays on the topics by experts, like <a href="http://www.securityfocus.com/columnists/436/1">this one</a>.<br />
I was going through the article and stumbled on <a href="http://windowshelp.microsoft.com/Windows/en-US/community/default.mspx">this page</a>, which has the picture given below.</p>
<div style="text-align:center;"><a href="http://projectbee.org/blog/wp-content/uploads/2008/02/vista2.jpg"><img src="http://projectbee.org/blog/wp-content/uploads/2008/02/vista2.jpg" alt="Vista Malware" height="326" width="529" /></a></div>
<p>What happened was due merely due to fast glance and my mouse cursor covering a part of the word; the <span style="font-weight:bold;">hardware</span> appeared to me as <span style="font-weight:bold;">malware</span>, making it <span style="font-weight:bold;">Is it time to upgrade your <span style="font-style:italic;">malware?</span></span></p>
<p>Now that&#8217;s wrong on my part to ridicule someone because of my own mistake&#8230; but honestly. Is there any difference?</p>
<p><span style="font-weight:bold;">UPDATE</span>:<br />
Very very honestly. I had read only the first two pages the security focus review before writing the above lines. However, the third page contains the following para:</p>
<blockquote><p><span style="font-style:italic;">So, one craplet pops up demanding to be enabled; you exit that, and a different one pops up telling you that you really ought not to have done that. Now, my definition of malware is pretty straightforward: malware is any code that causes my computer to behave in a way I don&#8217;t intend, or any code that prevents my computer from behaving in a way that I do intend. Thus the Vista Security Centre is, quite simply, malware. </span></p></blockquote>
<p>Wohoooo!<br />
I am a genius.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/" rel="bookmark" title="December 20, 2007">Orkut Latest XSS Worm; and what it means for Indian Orkuteers</a></li>

<li><a href="http://projectbee.org/blog/archive/tpm-boys-withdraw-paper-from-blackhat-usa/" rel="bookmark" title="July 5, 2007">TPM Boys withdraw paper from BlackHat USA</a></li>

<li><a href="http://projectbee.org/blog/archive/is-google-bomb-really-diffused/" rel="bookmark" title="April 28, 2007">Is Google Bomb REALLY Diffused?</a></li>

<li><a href="http://projectbee.org/blog/archive/java-vulnerable-to-remote-compromise/" rel="bookmark" title="July 14, 2007">Java vulnerable to remote compromise</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-mysqlphp-installation-configuration-tutorial-for-beginners/" rel="bookmark" title="February 25, 2006">Apache-MySQLPHP Installation &#38; Configuration Tutorial for Beginners :)</a></li>
</ul><!-- Similar Posts took 5.272 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&quot;COLUKABKI &#8211; AOL &#8211; MSN &#8211; YAHOO &#8211; RED CROSS&quot;&#8230;.. aaah Comm&#8217;n Gimme a break.</title>
		<link>http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/</link>
		<comments>http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/#comments</comments>
		<pubDate>Sat, 28 Jan 2006 16:16:00 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[education]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[reality]]></category>
		<category><![CDATA[strategy]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2006/01/28/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/</guid>
		<description><![CDATA[It&#8217;s really interesting that even enginieering students, who are supposed to have a very ANALYTIC are least bothered in verifying anything before believing it&#8230;&#8230; and that too when they have access to GOOGLE. This blog of mine is in response to the hundreds and thousands of mails that are forwarded so that somewhere, somebody&#8217;s LIFE [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s really interesting that even enginieering students, who are supposed to have a very <span style="font-style:italic;">ANALYTIC</span><span> are least bothered in verifying anything before believing it&#8230;&#8230; and that too when they have access to <a href="http://www.google.com">GOOGLE</a>.</span></p>
<p><span>This blog of mine is in response to the hundreds and thousands of mails that are forwarded so that somewhere, somebody&#8217;s <span style="font-weight:bold;">LIFE COULD BE SAVED BY FORWARDING THE BLOODY MAIL</span>.<br />
AOL, Yahoo, Red Cross, MSN etc. etc .etc. donated certain amount of money <span style="font-weight:bold;">FOR EACH TIME THE MAIL IS FORWARDED</span> (generally 1 cent).<br />
Isn&#8217;t that interesting???? I mean what these sites could do generously (if they wished to), do it when some <span style="font-weight:bold;">BIG HEARTED</span> person forwards the mail.<br />
And guess what??? They do it without attaching any kind of tracker in the mail&#8230; Not to mention that doing any thing even near to attaching a tracker would be a threat to an individuals privacy&#8230; <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></p>
<p><span>I cannot stop myself from sharing one other similar interesting mail. The mail said that an <span style="font-weight:bold;">INDIAN BOY HAS CHALLENGED BILL GATES BY DEVELOPING AN O/S CALLED &#8220;O! YES&#8221;</span>, which very Robust, Secure, blah blah blah&#8230; And HP has proposed to purchase it.<br />
Now, the first thing&#8230; making such an O/S is no joke. This has nothing to do with the crappy nature of <a href="http://www.windows.com/Passion/index_enu.html">WINDOWS</a> (hehehhe), it&#8217;s just means that it&#8217;s very difficult for a young child to do so.<br />
Secondly, if someone succeeds in doing so, this news would be the hottest one around&#8230;. not one which has to be informed via email. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />   And the most interesting part&#8230;.. This mail has been doing rounds since 5 years (at least) <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> )</span></p>
<p><span>These mails are generally used for two reasons:<br />
</span></p>
<ol><span><span><span><span><span><span><span><span><span><span></span></span></span></span></span></span></span></span></span></span> <span><span><span><span><span><span><span><span><span><span><span></span></span></span></span></span></span></span></span></span></span></span></p>
<p><span><span><span><span><span><span><span><span><span><span><span><span></p>
<li>For fun&#8230;. or to make mockery of someone.</li>
<li>For stealing your mail id for spamming&#8230;&#8230;. I know this is strange, but it&#8217;s true. If you have any such mail in your mail box, just try to count the number of email ids in it&#8230;. and then imagine what would you do with them if you were a spammer. These mails are infact sent by spammers so that they can have a reasonably beautiful number of such mail ids.</li>
<p></span></span></span></span></span></span></span></span></span></span></span></span></ol>
<p><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></p>
<p><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span>JUNTA, please don&#8217;t feel bad if you have been forwarding such mails.<br />
Obviously, nobody knows everything&#8230; but you can be a little careful when you recieve such mails.<br />
</span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></p>
<ol><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></p>
<li>Ignore such mails.</li>
<li>If you really feel that the mail is genuine and need to be forwarded, GOOGLE some keywords contained in the mail,</li>
<li>or  forward it after removing all the previous email addresses.</li>
<li>ALTERNATELY, YOU MAY ALSO DISTRIBUTE THE <a href="http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break">LINK OF THIS ARTICLE</a> FOR SPREADING AWARENESS <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ol>
<p><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span><span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/yahoo-gone-insane/" rel="bookmark" title="August 11, 2007">Yahoo! gone Insane!</a></li>

<li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/idle-nights-devils-mind/" rel="bookmark" title="April 12, 2007">Idle Nights: Devil&#8217;s Mind</a></li>

<li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-2-and-more/" rel="bookmark" title="September 4, 2008">OWASP AppSec Conf Delhi &#8211; Day 2; and more</a></li>
</ul><!-- Similar Posts took 10.284 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
