Tag Archives: security

Something weird in trackbacks.

Earlier today I received a trackback to one of my older posts.
“Woo”, thought I, all excited. “Somebody linked to me.” Then, after a moment, “But why did it go into the moderation queue?” (I use the Simple Trackback Validator in the hope of reducing any trackback spam that might, eventually, come this way. A valid [...]

Trading security for convenience

Imagine being able to pay your grocery bill by just waving your credit card in the general direction of the card reader. No swiping, no signing, perhaps you wouldn’t even have to pull the card out of your wallet or purse.
Sounds very convenient, doesn’t it? Well, you already can, if you have a contactless credit [...]

IE7: is this going to hurt?

For all the IE diehards out there: your favourite browser is back.
Microsoft releases new Internet Explorer (CNN)
And it brought along a fresh new bug with it. How darling!
IE7 unleashed…as researchers identify first bug (The Register)
Information disclosure bug blights IE7 release (The Register)
MS and researchers split hairs over first IE7 flaw (The Register)
OK, I’m being a [...]

WGA = What?? Get Attorneys!

Time for Microsoft to change their corporate motto. “Who do you want to falsely accuse of piracy today?” sounds like a winner.
Microsoft hides under duvet | The Register
Makes me wonder about the sanity of those Royal Navy and US Navy warships which are controlled by Windows boxes. Would kind of stink to be in the [...]

Secure your SSHd

Every day our webserver’s logfiles were stuffed with failed SSH logins - long lists of random usernames and repeat attempts to brute-force the root account.
The invalid logins are a minor nuisance, but it just feels wrong to let these little script kiddies keep on knocking at the door anyway. The attempts on root, or where [...]

How not to be a spam relay - avoiding contact form email injection attacks

The last couple of evenings we received a handful of odd-looking messages sent through our contact form which were attempting to use email injection techniques to relay mail through us.