Dec 25
Post Image Posted by mark.

Avoiding cross site request forgery in your web apps

4

Google recently fixed a glaring vulnerability in gmail that allows an attacker to forward copies of all or some of your email to themselves by adding a filter to your gmail account. But not before someone lost their domain name to an attacker who then proceeded to try to sell it back to them for cash.
The gmail bug was a cross site request forgery exploit. The attack is incredibly simple. If a user is authenticated to a website, an attacker …

Read on »

Dec 23
Post Image Posted by mark.

The importance of not knowing what isn’t possible

0

A Microsoft quote from an NY Times article I’ve already cited has been bugging the crap out of me. It bugged me when I first blogged about this article and it bugged me as I wandered around B&N last night doing the last of my xmass shopping. I wound up in the management section and picked up a book on the top 10 mistakes leaders make. Staring at me as I flipped open chapter 5 was confirmation that I wasn’t …

Read on »

Dec 19
Post Image Posted by mark.

The 6th most viewed video on MySpace?!

1

I don’t get it.

Read on »

Dec 16
Post Image Posted by mark.

Microsoft Buzzquotes

1

“My machine overnight could process my in-box, analyze which ones were probably the most important, but it could go a step further,” he said. “It could interpret some of them, it could look at whether I’ve ever corresponded with these people, it could determine the semantic context, it could draft three possible replies. And when I came in in the morning, it would say, hey, I looked at these messages, these are the ones you probably care about, you probably …

Read on »