<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: United Nations, I Hate to Say I Told You So</title>
	<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sun, 06 Jul 2008 19:55:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: hackademix.net » PayPal XSSed, Redmondmag.com SQL Injected</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7960</link>
		<dc:creator>hackademix.net » PayPal XSSed, Redmondmag.com SQL Injected</dc:creator>
		<pubDate>Sat, 17 May 2008 14:03:34 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7960</guid>
		<description>[...] the party of the ASP/MS SQL Server sites SQL Injected to serve JavaScript malware. Considering the wide coverage this epidemics enjoyed in the past week, I wonder what a “Certified Professional” [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] the party of the ASP/MS SQL Server sites SQL Injected to serve JavaScript malware. Considering the wide coverage this epidemics enjoyed in the past week, I wonder what a “Certified Professional” [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7919</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 13 May 2008 22:15:18 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7919</guid>
		<description>@&lt;b&gt;NH&lt;/b&gt;:
&lt;a href="http://hackademix.net/2008/04/15/cia-operation-ponies/" rel="nofollow"&gt;OMG Commies!&lt;/a&gt;
&lt;a href="http://www.darknet.org.uk/2007/08/the-homeland-security-department-suffered-more-than-800-successful-hack-attacks/" target="_blank" rel="nofollow external" rel="nofollow"&gt;Department of Hacked Security&lt;/a&gt; at rescue...</description>
		<content:encoded><![CDATA[<p>@<b>NH</b>:<br />
<a href="http://hackademix.net/2008/04/15/cia-operation-ponies/" rel="nofollow">OMG Commies!</a><br />
<a href="http://www.darknet.org.uk/2007/08/the-homeland-security-department-suffered-more-than-800-successful-hack-attacks/" target="_blank" rel="nofollow external" rel="nofollow">Department of Hacked Security</a> at rescue&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NH</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7918</link>
		<dc:creator>NH</dc:creator>
		<pubDate>Tue, 13 May 2008 19:39:49 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7918</guid>
		<description>Um and your point is?

If any site should be hacked it's the UN. They are the enemies of the USA.

Why would you want to help our mortal enemies?

Third world Marxists and despots, looking to conquer the world.

I guess if they can't even run a website, I have hope for our freedom.</description>
		<content:encoded><![CDATA[<p>Um and your point is?</p>
<p>If any site should be hacked it&#8217;s the UN. They are the enemies of the USA.</p>
<p>Why would you want to help our mortal enemies?</p>
<p>Third world Marxists and despots, looking to conquer the world.</p>
<p>I guess if they can&#8217;t even run a website, I have hope for our freedom.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: m3rlin23</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7815</link>
		<dc:creator>m3rlin23</dc:creator>
		<pubDate>Sat, 03 May 2008 20:42:27 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7815</guid>
		<description>It is true, the UN have done nothing to secure their database. It took me no more than a few minutes using a simple perl script to enumerate every column of every table of quite a few of their databases. We know the sql username, server type, hostname etc.I am always harassing our web developers at work over sloppy input validation but they design sites for small web startups. This is the UN for Christ's sake!</description>
		<content:encoded><![CDATA[<p>It is true, the UN have done nothing to secure their database. It took me no more than a few minutes using a simple perl script to enumerate every column of every table of quite a few of their databases. We know the sql username, server type, hostname etc.I am always harassing our web developers at work over sloppy input validation but they design sites for small web startups. This is the UN for Christ&#8217;s sake!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Offbeatmammal</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7759</link>
		<dc:creator>Offbeatmammal</dc:creator>
		<pubDate>Mon, 28 Apr 2008 01:21:04 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7759</guid>
		<description>Hey Giorgio - sorry, should have been clearer ... I'd added the &#34;fix&#34; as a comment to my original post (wasn't at home and hate using the web interface to edit posts but pasting into disqus was easy!)
our solutions look functionally the same - I suspect yours is more elegant/reliable (it's been a while since I didn't much development in the real world)

ironically I first found (and started following) your site a while ago when trying to explain to some folks in a previous job why security actually mattered... this has gone to prove that they should have listened a bit more at the time!</description>
		<content:encoded><![CDATA[<p>Hey Giorgio - sorry, should have been clearer &#8230; I&#8217;d added the &quot;fix&quot; as a comment to my original post (wasn&#8217;t at home and hate using the web interface to edit posts but pasting into disqus was easy!)<br />
our solutions look functionally the same - I suspect yours is more elegant/reliable (it&#8217;s been a while since I didn&#8217;t much development in the real world)</p>
<p>ironically I first found (and started following) your site a while ago when trying to explain to some folks in a previous job why security actually mattered&#8230; this has gone to prove that they should have listened a bit more at the time!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7737</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 26 Apr 2008 08:02:33 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7737</guid>
		<description>@&lt;b&gt;Offbeatmammal&lt;/b&gt;:
I couldn't actually see any removal instruction in your post (but I may be blind).
Anyway I posted some &lt;a href="http://hackademix.net/2008/04/26/mass-attack-faq/#iis" rel="nofollow"&gt;disaster recovery advices for affected IIS administrators&lt;/a&gt; yesterday.</description>
		<content:encoded><![CDATA[<p>@<b>Offbeatmammal</b>:<br />
I couldn&#8217;t actually see any removal instruction in your post (but I may be blind).<br />
Anyway I posted some <a href="http://hackademix.net/2008/04/26/mass-attack-faq/#iis" rel="nofollow">disaster recovery advices for affected IIS administrators</a> yesterday.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Offbeatmammal</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7736</link>
		<dc:creator>Offbeatmammal</dc:creator>
		<pubDate>Sat, 26 Apr 2008 04:15:46 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7736</guid>
		<description>at least the current nihaorr1 attack is easy to remove once you know you're infected - http://tinyurl.com/6g2a95 - but in this day and age anyone maintaining a site open to this sort of attack really does need to spend some time and money on a code and security review!</description>
		<content:encoded><![CDATA[<p>at least the current nihaorr1 attack is easy to remove once you know you&#8217;re infected - <a href="http://tinyurl.com/6g2a95" rel="nofollow">http://tinyurl.com/6g2a95</a> - but in this day and age anyone maintaining a site open to this sort of attack really does need to spend some time and money on a code and security review!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Mass Attack FAQ</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7730</link>
		<dc:creator>hackademix.net » Mass Attack FAQ</dc:creator>
		<pubDate>Fri, 25 Apr 2008 22:52:49 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7730</guid>
		<description>[...] United Nations, I Hate to Say I Told You So      26 04 2008 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] United Nations, I Hate to Say I Told You So      26 04 2008 [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: redlab</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7726</link>
		<dc:creator>redlab</dc:creator>
		<pubDate>Thu, 24 Apr 2008 12:45:58 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7726</guid>
		<description>It's prolly just all politics. I wouldn't be surprised that they have to fill in a form and twenty copies and send it to each member of the UN for approval before anything can be changed on the site's code. (at least that's what they do in the EU)</description>
		<content:encoded><![CDATA[<p>It&#8217;s prolly just all politics. I wouldn&#8217;t be surprised that they have to fill in a form and twenty copies and send it to each member of the UN for approval before anything can be changed on the site&#8217;s code. (at least that&#8217;s what they do in the EU)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7723</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 24 Apr 2008 07:50:47 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/23/united-nations-i-hate-to-say-i-told-you-so/#comment-7723</guid>
		<description>@&lt;b&gt;me&lt;/b&gt;:
should we republish those events back? You know that we could ;)</description>
		<content:encoded><![CDATA[<p>@<b>me</b>:<br />
should we republish those events back? You know that we could ;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
