Create an Account
username: password:
 
  MemeStreams Logo

Curiouser and Curiouser

search

Acidus
Picture of Acidus
My Blog
My Profile
My Audience
My Sources
Send Me a Message

sponsored links

Acidus's topics
Arts
Business
Games
Health and Wellness
Home and Garden
(Miscellaneous)
Current Events
Recreation
Local Information
Science
Society
Sports
Technology

support us

Get MemeStreams Stuff!


 
Current Topic: Miscellaneous

10 Most Amazing Ghost Towns
Topic: Miscellaneous 11:36 am EDT, Jul 24, 2008

The Kowloon Walled City was located just outside Hong Kong, China during British rule. A former watchpost to protect the area against pirates, it was occupied by Japan during World War II and subsequently taken over by squatters after Japan’s surrender. Neither Britain nor China wanted responsibility for it, so it became its own lawless city.

Its population flourished for decades, with residents building labyrinthine corridors above the street level, which was clogged with trash. The buildings grew so tall that sunlight couldn’t reach the bottom levels and the entire city had to be illuminated with fluorescent lights. It was a place where brothels, casinos, opium dens, cocaine parlors, food courts serving dog meat and secret factories ran unmolested by authorities. It was finally torn down in 1993 after a mutual decision was made by British and Chinese authorities, who had finally grown wary of the unsanitary, anarchic city and its out-of-control population. null

Wow, Kowloon looks like something out of Blade Runner. Kind of like the alleys of of Shinjuku if you turned the power off!

10 Most Amazing Ghost Towns


glumbert - Guess what's in my pants
Topic: Miscellaneous 10:11 am EDT, Jul 23, 2008

Wow! Jimmy puts various things in his pants (king crab leg, racket balls, etc), and women try to guess by feel alone...

Jimmy: How old are you?
Girl: 18.
Jimmy: Are you sure? Uncle Jimmy doesn't need to go to jail!

glumbert - Guess what's in my pants


The Dark Knight
Topic: Miscellaneous 4:24 pm EDT, Jul 18, 2008

See this. See this right. freaking. now. The awesomeness is... awesome.


Construction and cats
Topic: Miscellaneous 10:28 am EDT, Jul 17, 2008

Today I'm having a fence installed. This process has taught me 2 things:

1- I have become a grumpy old man.
2- Cats are fascinated by concrete mixers. Like, unhealthily fascinated.


on the iPod
Topic: Miscellaneous 10:33 am EDT, Jul 14, 2008

Like a rock,
like a planet,
Like a fucking atom bomb,
I remain unperturbed by the joy and the madness
That I encounter everywhere I turn,

Bad Religion on an iPod is remarkably effective at getting your ass up the hills around Riverside park while jogging.

on the iPod


Impossible things
Topic: Miscellaneous 12:25 pm EDT, Jul 13, 2008

I am always doing things I can't do. That's how I get to do them.

--Pablo Picasso.


Alkaline Trio: Agony & Irony
Topic: Miscellaneous 11:59 am EDT, Jul  9, 2008

Well do you find you like to fall in love with people that you're never gonna meet?
It's easier then breaking up and crying in the street
Do you curse the happy couple?
Do you cringe at wedding bells?
Do you drink up all the punch while you wish 'em all to hell

Love Love, Kiss Kiss.... Blah blah blah
You're making me sick
I wish you'd just stop showing off
For the rest of us that no one wants to love.
It's hard enough trying to drink another winter all alone
Love Love, Kiss Kiss.... Blah blah blah

Alkaline Trio has a new album. I've mentioned them before and while there sounds has changed with recent albums like Crimson from there more punk sound of songs like Private Eye, and Radio, I'm enjoying this new album so far.

Alkaline Trio: Agony & Irony


Venture Bros. Season 3
Topic: Miscellaneous 9:28 am EDT, Jul  7, 2008

The problem with TiVo is that you never see commercials. So I almost missed that the The Venture Bros. returned for a 3rd season.

If you aren't watching this show you are a fool.

From last night's episode:

Dean: She's the Wereodile!
Dr Venture: I almost f@$&ed a wereodile?
Dean: Don't worry dad [grab chair]... [smacks Dr Quymn] The power of Christ compels you!

and of course:

Henchman 24: Come on! They have one female servicing a large group of males. That implies a species that lays eggs.
Henchman 21: Oh my God, you're crazy! They're so obviously mammals!
Henchman 24: Please! She'd be in estrus 24/7 if she didn't lay eggs.
Henchman 21: Smurfs don't lay eggs! I won't tell you this again! Papa Smurf has a fucking beard! They're mammals!

Venture Bros. Season 3


Whoops!: Or we are paid to be researchers not QA professionals
Topic: Miscellaneous 5:27 pm EDT, Jun 26, 2008

Start at bottom for maximum effect...

update: patched

_____________________________________________
From: Hoffman, Billy
Sent: Thursday, June 26, 2008 5:27 PM
To: Wood, Matt (); Millar, Steve A
Subject: RE: uhhhh does Scrawlr really have a limit?

This is too great. I'm posting this to Memestreams.

Billy Hoffman
--
Manager, HP Web Security Research Group
HP Software – Application Security Center
Direct: 770-343-7069

_____________________________________________
From: Wood, Matt ()
Sent: Thursday, June 26, 2008 5:27 PM
To: Wood, Matt (); Hoffman, Billy; Millar, Steve A
Subject: RE: uhhhh does Scrawlr really have a limit?

Stivo! you crazy! Change-set 27173. 6/21 @ 6:37pm in SimpleUrlCrawler.cs 

I guess the build-box is building with the debug symbols in it?

So the crawl limit is 2.1 billion right now  2^31-1

_____________________________________________
From: Wood, Matt ()
Sent: Thursday, June 26, 2008 5:19 PM
To: Hoffman, Billy; Millar, Steve A
Subject: RE: uhhhh does Scrawlr really have a limit?

Whoops! Here:

private void buildCrawlLimit()
{
crawlLimit = 1500;
#if DEBUG
crawlLimit = int.MaxValue;
#endif
}

Pretty sure the Labs build box is pumping out debug builds...

_____________________________________________
From: Hoffman, Billy
Sent: Thursday, June 26, 2008 5:19 PM
To: Wood, Matt (); Millar, Steve A
Subject: RE: uhhhh does Scrawlr really have a limit?

... ... STFU! Are you telling me the limit most people are bitching about doesn’t even exist? Haha, Should we even patch that?

Billy Hoffman
--
Manager, HP Web Security Research Group
HP Software – Application Security Center
Direct: 770-343-7069

_____________________________________________
From: Wood, Matt ()
Sent: Thursday, June 26, 2008 5:15 PM
To: Hoffman, Billy; Millar, Steve A
Subject: RE: uhhhh does Scrawlr really have a limit?

Haha… scrawlr may not have a limit…

I just set a break point in the function that checks it and it never gets called… apparently it got lost somehow…

_____________________________________________
From: Hoffman, Billy
Sent: Thursday, June 26, 2008 5:10 PM
To: Wood, Matt (); Millar, Steve A
Subject: RE: uhhhh does Scrawlr really have a limit?

Then explain this:
[Screen shot removed]

Billy Hoffman
--
Manager, HP Web Security Research Group
HP Software – Application Security Center
Direct: 770-343-7069

-----Original Message-----
From: Wood, Matt ()
Sent: Thursday, June 26, 2008 5:07 PM
To: Hoffman, Billy; Millar, Steve A
Subject: RE: uhhhh does Scrawlr really have a limit?

Nah, just a lot of parameters. We will only crawl 1500 pages, but we will audit more.

-----Original Message-----
From: Hoffman, Billy
Sent: Thursday, June 26, 2008 5:09 PM
To: Wood, Matt (); Millar, Steve A
Subject: uhhhh does Scrawlr really have a limit?

Guys,

I noticed a Chinese site offer Scrawlr for download. Its classic ASP so I decide to scan it with Scrawlr.

Site is: [Site Removed]

The only thing is, Scrawlr is saying it has visited 3879 pages so far and is still going. Perhaps a bug in our limiting?

Billy Hoffman
--
Manager, HP Web Security Research Group
HP Software – Application Security Center
Direct: 770-343-7069


Matasano Chargen » And Now For A Few Words About HP’s “Scrawlr”
Topic: Miscellaneous 4:54 pm EDT, Jun 26, 2008

Matasano gives some love, which is nice.

Some of my favorite reads (there are others) have recently written about about Scrawlr and some of what I have read has been critical. Critical enough? Depending on your level of pedantry with respect to webapp security and/or free software, probably not.

Stop that. Right now. Overlook the limitations of the tool that was released, realize that this is a closely targeted thing designed to help alleviate a specific problem. Go back and think a little harder about what is going on and why this is actually A Good Thing(tm).

[snip]

The scanner is built to look for things being indexed by search engines. If those sites are fixed, 99.999% of the problem should go away.

Trying to compare Scrawlr to a full blown SQL Injection scanning tool is like comparing a letter opener to a Swiss Army Knife. Sure, you can do other things with a letter opener (and some of you probably want to slit my throat for that simile. That’s fine, use the knife) —- but its stated purpose is to open letters.

The feedback we've been getting from developers has been "Thanks for the tool, I didn't understand [other tool]/couldn't make it work." Not surprising. These are people 5 years behind the security curve, with only a passing understanding of SQL injection and still believing XSS is all alert boxes and cookie theft. You average classic ASP dev can no more use Burp than my mom can use a methane digester. In both cases the fundamental concept of what the tool does is lost on the end user.

The feedback I've gotten from security folks is "why isn't this WI Lite. I'm sick of paying you guys $30k a year." Well, not exactly, but the subtext is there. :-)

Believe me, I really wish I could talk about the challenges of writing modern web crawlers. The fact I got to do it once was a bit of a fluk and was extremely limited in scope. So if I cannot even talk about it publicly, do you really think I would be allowed to manage a team to write a free one?

Matasano Chargen » And Now For A Few Words About HP’s “Scrawlr”


(Last) Newer << 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 ++ 22 >> Older (First)
 
 
Powered By Industrial Memetics
RSS2.0