<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" 
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    
    xmlns:content="http://purl.org/rss/1.0/modules/content/">

  <channel>
    <title>Miscellaneous category of Luke Hutteman's public virtual MemoryStream</title>
    <link>http://www.hutteman.com/weblog/cat_miscellaneous.html</link>
    <description>Get a complete rss feed (all categories) at &lt;a href="http://www.hutteman.com/weblog/rss.xml"&gt;http://www.hutteman.com/weblog/rss.xml&lt;/a&gt;</description>
    <dc:language>en-us</dc:language>
    <dc:creator>luke@hutteman.com</dc:creator>
    <dc:rights>Copyright 2008</dc:rights>
    <dc:date>2006-10-02T21:21:07-05:00</dc:date>
    <admin:generatorAgent rdf:resource="http://www.movabletype.org/?v=3.33" />
    <admin:errorReportsTo rdf:resource="mailto:luke@hutteman.com"/>
    <sy:updatePeriod>hourly</sy:updatePeriod>
    <sy:updateFrequency>1</sy:updateFrequency>
    <sy:updateBase>2000-01-01T12:00+00:00</sy:updateBase>
    

    <item>
      <title>Firefox vulnerability</title>
      <link>http://www.hutteman.com/weblog/2006/10/02-251.html</link>
      <description>A few weeks ago, Microsoft had its VML zero day exploit; this week, it's Firefox's turn. Obviously, as more people are switching from Internet Explorer to Firefox, hackers are doing the same. The thing that struck me about this particular problem was that the hackers gave no advance warning to Mozilla prior to their presentation, and The hackers claim they... (224 words)</description>
      <guid isPermaLink="false">251@http://www.hutteman.com/weblog/</guid>
      <content:encoded><![CDATA[<p>A few weeks ago, Microsoft had its <a href="http://www.microsoft.com/technet/security/advisory/925568.mspx">VML zero day exploit</a>; this week, it's <a href="http://news.zdnet.com/2100-1009_22-6121608.html">Firefox's turn</a>. 
</p><p>
Obviously, as more people are switching from Internet Explorer to Firefox, hackers are doing the same.
</p><p>
The thing that struck me about this particular problem was that the hackers gave no advance warning to Mozilla prior to their presentation, and 

<blockquote>
The hackers claim they know of about 30 unpatched Firefox flaws. They don't plan to disclose them, instead holding onto the bugs.
</blockquote>

why are they holding on to them? one of the hackers explains:

<blockquote>
what we're doing is really for the greater good of the Internet. We're setting up communication networks for black hats
</blockquote>

for the greater good of the Internet? yeah right. 
</p><p>
The scary thing is though that one of the hackers works for <a href="http://www.sixapart.com/">Six Apart</a>, the company behind popular blogging software like <a href="http://www.movabletype.com/">Movable Type</a>, <a href="http://www.livejournal.com/">Live Journal</a> and <a href="http://www.typepad.com/">Typepad</a>. 
</p><p>
Six Apart needs to do some major damage control, fire this guy immediately and review all code he may have had access to. It doesn't exactly ease my mind to know my weblog is running on code this guy may have had access to. Maybe it's time to move to <a href="http://wordpress.com/">WordPress</a>...
</p><p>
<b>UPDATE:</b> it looks like this may have just been <a href="http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/">a hoax</a>. Still not exactly good publicity for six apart though...
</p>]]></content:encoded>
              <category>Miscellaneous</category>
      
      <dc:date>2006-10-02T21:21:07-05:00</dc:date>
            <comments>http://www.hutteman.com/weblog/2006/10/02-251.html#comments</comments>
      
    </item>
    <item>
      <title>Spammers using Google links</title>
      <link>http://www.hutteman.com/weblog/2006/05/05-249.html</link>
      <description>In my &quot;Spam Suspects&quot; email folder today, I noticed some spam which used Google as a redirection service, by linking to http://www.google.com/url?q=http://www.somespamsite.com. When trying this technique with some other site, I found that google responds to this query with a 302 redirect to the site in question. Clearly, the spammer was using this system to lure people who trust Google... (176 words)</description>
      <guid isPermaLink="false">249@http://www.hutteman.com/weblog/</guid>
      <content:encoded><![CDATA[<p>In my "Spam Suspects" email folder today, I noticed some spam which used Google as a redirection service, by linking to http://www.google.com/url?q=http://www.somespamsite.com. When trying this technique with <a href="http://www.google.com/url?q=http://www.microsoft.com">some other site</a>, I found that google responds to this query with a <a href="http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10.3.3">302</a> redirect to the site in question. Clearly, the spammer was using this system to lure people who trust Google into visiting their site.</p>

<p>What I don't understand is why Google needs a public redirect system like this that is so obviously open to abuse. The google.com/url?q=... page doesn't seem to accept anything but already fully specified urls, so the sole purpose of this page is to do redirects.</p>

<p>The only reason I can think of for them needing a service like this is if they serve up one in a thousand search-results pages with redirect links, in order to log what people actually click on. If this were the case though, why not at least check the referrer to see if the user actually came from a google.com page? Am I missing something here?</p>]]></content:encoded>
              <category>Miscellaneous</category>
      
      <dc:date>2006-05-05T21:13:41-05:00</dc:date>
            <comments>http://www.hutteman.com/weblog/2006/05/05-249.html#comments</comments>
      
    </item>
    <item>
      <title>Support the fight against diabetes</title>
      <link>http://www.hutteman.com/weblog/2006/03/26-248.html</link>
      <description>Scott Hanselman and his wife will be joining the walk for diabetes on May 6 2006. They've set a goal of raising $10,000 for this event and could use your help in reaching that goal. I encourage all of you to go to Scott's blog to find out more about this worthy cause, or go directly to diabetes.org to make... (64 words)</description>
      <guid isPermaLink="false">248@http://www.hutteman.com/weblog/</guid>
      <content:encoded><![CDATA[<p>Scott Hanselman and his wife will be joining the walk for diabetes on May 6 2006. They've set a goal of raising $10,000 for this event and could use your help in reaching that goal. I encourage all of you to go to <a href="http://www.hanselman.com/blog/TeamHanselmanAndDiabetesWalk2006.aspx">Scott's blog</a> to find out more about this worthy cause, or go directly to <a href="http://walk.diabetes.org/site/TR?pg=personal&fr_id=3418&px=2784611">diabetes.org</a> to make your donation. Thank you.</p>]]></content:encoded>
              <category>Miscellaneous</category>
      
      <dc:date>2006-03-26T23:41:36-05:00</dc:date>
            <comments>http://www.hutteman.com/weblog/2006/03/26-248.html#comments</comments>
      
    </item>
    <item>
      <title>Xbox 360</title>
      <link>http://www.hutteman.com/weblog/2006/01/08-243.html</link>
      <description>After seeing it in stock through their inventory locator, I drove by Circuit City yesterday to try and get myself an xbox 360. Since the store is about 20 minutes from my home, there was a pretty big chance they'd be gone by the time I got there, and they were indeed nowhere to be found in the showroom by... (374 words)</description>
      <guid isPermaLink="false">243@http://www.hutteman.com/weblog/</guid>
      <content:encoded><![CDATA[<p><a href="http://live.xbox.com/member/aMillionMonkeys"><img align="right" border="0" src="http://card.mygamercard.net/aMillionMonkeys.jpg"></a>After seeing it in stock through their <a href="http://www.circuitcity.com/ccd/howToGetItTab.do?c=1&zip=28215&oid=137824">inventory locator</a>, I drove by Circuit City yesterday to try and get myself an xbox 360. Since the store is about 20 minutes from my home, there was a pretty big chance they'd be gone by the time I got there, and they were indeed nowhere to be found in the showroom by that time. Then I noticed an employee carrying two to a counter, so I followed him, asked if they had more in stock (the ones he carried were spoken for), and was finally able to get me one.</p>

<p>When I asked the guy why they hadn't put them on the floor, he responded "<i>we can't - there would be fights</i>", suggesting this had actually occurred before. Then again, in an attempt to sell me their $70 extended warranty, he also told me half of them were returned to the store because of defects, so he wasn't exactly that trustworthy I guess.</p>

<p>First impressions:<br />
<ul><br />
<li>While it looks pretty good on a standard TV, it's clearly designed for HDTV. Some of the in-game text can be hard to read at times on a regular TV, and the Need for Speed most wanted demo looked better on my PC with 20" monitor than it does on my 52" projection TV. Since I won't be buying a HDTV any time soon, I might just end up getting the VGA cable and connect it to my monitor instead.<br />
<li>Having finished Need for Speed Underground 1 & 2 on my PC, I thought I was pretty good at racing games. PGR proved me wrong - I've got a lot to learn (like: you should actually let go off the gas and brake before turns).<br />
<li>The built in PC connectivity is very cool, allowing me to access my entire music collection from the living room. There's also supposed to be iPod connectivity, but I don't think I'll even need to try that since the PC connectivity works so well.<br />
</ul></p>

<p>For people still looking for one: Best Buy also has an <a href="http://www.bestbuy.com/site/olspage.jsp?id=pcat17006&type=page&sourceId=1099395571979&sourceType=product&skuId=999947300050001&productId=1099395571979&itemId=847033<br />
">inventory locator</a> (though it's a bit buggy), or you could subscribe to <a href="http://www.xbox360tracker.com/">xbox360tracker</a>'s RSS feed to be notified of availability at dozens of online stores.</p>

<p>Gamertag: aMillionMonkeys</p>]]></content:encoded>
              <category>Miscellaneous</category>
      
      <dc:date>2006-01-08T18:12:37-05:00</dc:date>
            <comments>http://www.hutteman.com/weblog/2006/01/08-243.html#comments</comments>
      
    </item>
    <item>
      <title>Outage problems</title>
      <link>http://www.hutteman.com/weblog/2005/10/23-234.html</link>
      <description>My hosting company ran into some issues this weekend that, besides causing a two day outage for both my blog and for sharpreader.net, also potentially caused some email to get lost. If you sent me anything on Friday, Saturday or Sunday, you may need to resend it - I'm not sure how much is lost for good and how much... (331 words)</description>
      <guid isPermaLink="false">234@http://www.hutteman.com/weblog/</guid>
      <content:encoded><![CDATA[<p>My <a href="http://www.netrillium.com">hosting company</a> ran into <a href="http://helpdesk.netrilliumclients.com/?_a=announcements&_m=details&_i=16">some issues</a> this weekend that, besides causing a two day outage for both my blog and for <a href="http://www.sharpreader.net">sharpreader.net</a>, also potentially caused some email to get lost. If you sent me anything on Friday, Saturday or Sunday, you may need to resend it - I'm not sure how much is lost for good and how much will be redelivered later :-(</p>

<p>Also, if anyone has any positive experiences with hosting a 50+ Gb/month site at a reasonable price (I currently only pay $17/month), please let me know. This wasn't the first outage I've had, nor do I expect it to be the last. Maybe it's time to move on.</p>

<p><b>update:</b> looks like my hosting company still has some issues to be worked out; I can't send any emails through outlook for getting some weird "503 valid RCPT command must precede DATA" error (though sending through the web-based interface seems to work fine), and for some reason my movable type install is not showing any of your comments. Comments have not been lost though, as I can see them through the MT admin interface, and am also getting the email notifications (i'm actually getting those twice now... weird) - I just need to figure out why it's not rebuilding the pages correctly...</p>

<p><b>update 2:</b> email issue has been fixed - for some reason I had to use some outlook setting that wasn't needed before their servers crashed... now all I need is to figure out what's going on with MT...</p>

<p><b>update 3:</b> turned out that all comments were in a pending status and needed to be manually approved (the email notifications conveniently failed to mention this though). My <a href="http://www.jayallen.org/projects/mt-blacklist/">MT-Blacklist</a> was setup to only force moderation on old posts, but since the crash-recovery it now seems to force it on new ones as well. Oh well - I'm long overdue for an upgrade to <a href="http://www.sixapart.com/movabletype/news/2005/08/movable_type_3_2.html">MT 3.2</a> + SpamLookup anyway; guess it's time to stop procrastinating (but not tonight).</p>]]></content:encoded>
              <category>Blogging</category>
              <category>Miscellaneous</category>
              <category>SharpReader</category>
      
      <dc:date>2005-10-23T22:59:14-05:00</dc:date>
            <comments>http://www.hutteman.com/weblog/2005/10/23-234.html#comments</comments>
      
    </item>


  </channel>
</rss>
