<?xml version="1.0" encoding="iso-8859-1"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
  <title>Serial: Java .Net Mono FreeBSD Erlang</title>
  <link rel="alternate" type="text/html" href="http://www.dudeforce.net/" />
  <modified>2008-12-06T16:12:37Z</modified>
  <tagline>Covering Java and .Net software development, FreeBSD and other fun nerdy stuff. On a technical documentation mission.</tagline>
  <id>tag:www.dudeforce.net,2008://1</id>
  <generator url="http://www.movabletype.org/" version="3.01D">Movable Type</generator>
  <copyright>Copyright (c) 2008, 0xFF3300</copyright>
  <entry>
    <title>Erlang, I&apos;m Diving In</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2008/12/erlang_im_divin_1.html" />
    <modified>2008-12-06T16:12:37Z</modified>
    <issued>2008-12-06T07:59:42-08:00</issued>
    <id>tag:www.dudeforce.net,2008://1.216</id>
    <created>2008-12-06T15:59:42Z</created>
    <summary type="text/plain">I&apos;ve recently become interested in learning Erlang, it&apos;s a functional language, high performance and much different than your average C based languages. That being said, it&apos;s going to be a steeper learning curve for me....</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>erlang</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>I've recently become interested in learning Erlang, it's a functional language, high performance and much different than your average C based languages. That being said, it's going to be a steeper learning curve for me. </p>]]>
      <![CDATA[<p>Here are a couple of great jumping off points:</p>

<p><a href="http://erlang.org">erlang.org</a></p>

<p><a href="http://www.vimeo.com/2007411">Tutorial to Start Developing Web Applications on Erlang</a></p>

<p><a href="http://erlang.org/course/course.html">Erlang Course</a><br />
</p>]]>
    </content>
  </entry>
  <entry>
    <title>New Audi Godfather Commercial</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2008/03/new_audi_godfat.html" />
    <modified>2008-03-11T14:17:26Z</modified>
    <issued>2008-03-11T06:14:44-08:00</issued>
    <id>tag:www.dudeforce.net,2008://1.214</id>
    <created>2008-03-11T14:14:44Z</created>
    <summary type="text/plain">I found the new Audi Superbowl commercial on WikiRides amusing: Audi_R8_Truth_in_The_Godfather_-_Super_Bowl_2008...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>video</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>I found the new Audi Superbowl commercial on WikiRides amusing:<br />
<a href="http://wikirides.com/Audi_R8_Truth_in_The_Godfather_-_Super_Bowl_2008">Audi_R8_Truth_in_The_Godfather_-_Super_Bowl_2008</a></p>]]>
      
    </content>
  </entry>
  <entry>
    <title>Dark Web Designs</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2008/02/dark_web_design_1.html" />
    <modified>2008-02-26T14:31:45Z</modified>
    <issued>2008-02-26T06:27:34-08:00</issued>
    <id>tag:www.dudeforce.net,2008://1.213</id>
    <created>2008-02-26T14:27:34Z</created>
    <summary type="text/plain">I have an appreciation for darker web designs, for one it&apos;s easier on the eyes. Vandelay creates an article reviewing some of the better ones: http://vandelaydesign.com/blog/galleries/dark/...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>design</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>I have an appreciation for darker web designs, for one it's easier on the eyes. Vandelay creates an article reviewing some of the better ones:</p>

<p><img src="http://vandelaydesign.com/images/dark/hydra.jpg"></p>

<p><a href="http://vandelaydesign.com/blog/galleries/dark/">http://vandelaydesign.com/blog/galleries/dark/</a></p>]]>
      
    </content>
  </entry>
  <entry>
    <title>Chyrp Installed</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2008/02/chyrp_installed.html" />
    <modified>2008-02-05T07:53:44Z</modified>
    <issued>2008-02-04T23:51:39-08:00</issued>
    <id>tag:www.dudeforce.net,2008://1.212</id>
    <created>2008-02-05T07:51:39Z</created>
    <summary type="text/plain">Just installed Chyrp (http://chyrp.net). It&apos;s simple, minimal and uses plugins called feathers....</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>webapps</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>Just installed Chyrp (http://chyrp.net). It's simple, minimal and uses plugins called feathers.  </p>]]>
      
    </content>
  </entry>
  <entry>
    <title> .NET Framework Library Source Code Available</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2008/01/_net_framework.html" />
    <modified>2008-01-17T16:03:00Z</modified>
    <issued>2008-01-17T08:00:11-08:00</issued>
    <id>tag:www.dudeforce.net,2008://1.211</id>
    <created>2008-01-17T16:00:11Z</created>
    <summary type="text/plain">An interesting move by Microsoft, the .NET Framework Library has been made open source. Here are the libraries available: * .NET Base Class Libraries (including System, System.CodeDom, System.Collections, System.ComponentModel, System.Diagnostics, System.Drawing, System.Globalization, System.IO, System.Net, System.Reflection, System.Runtime, System.Security, System.Text, System.Threading, etc)....</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>.net</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>An interesting move by Microsoft, the .NET Framework Library has been made open source. Here are the libraries available:</p>

<p>    *  .NET Base Class Libraries (including System, System.CodeDom, System.Collections, System.ComponentModel, System.Diagnostics, System.Drawing, System.Globalization, System.IO, System.Net, System.Reflection, System.Runtime, System.Security, System.Text, System.Threading, etc).</p>

<p>    * ASP.NET (System.Web, System.Web.Extensions)</p>

<p>    * Windows Forms (System.Windows.Forms)</p>

<p>    * Windows Presentation Foundation (System.Windows)</p>

<p>    * ADO.NET and XML (System.Data and System.Xml)</p>]]>
      <![CDATA[<p>http://weblogs.asp.net/scottgu/archive/2008/01/16/net-framework-library-source-code-now-available.aspx</p>]]>
    </content>
  </entry>
  <entry>
    <title>CodeIgniter - a Rails-like PHP framework</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2008/01/codeigniter.html" />
    <modified>2008-01-09T05:59:58Z</modified>
    <issued>2008-01-08T19:24:49-08:00</issued>
    <id>tag:www.dudeforce.net,2008://1.210</id>
    <created>2008-01-09T03:24:49Z</created>
    <summary type="text/plain">I haven&apos;t been this excited about a framework since Groovy. CodeIgniter is a rails-like php framework that allows for rapid development using a REST Model-View-Controller, comes with a basic scaffolding, an assort of core classes and excellent documentation. Although many...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>framework</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>I haven't been this excited about a framework since <a href="http://groovy.codehaus.org">Groovy</a>. CodeIgniter is a rails-like php framework that allows for rapid development using a REST Model-View-Controller, comes with a basic scaffolding, an assort of core classes and excellent <a href="http://codeigniter.com/user_guide/toc.html">documentation</a>. Although many of the implementation may simply skip the model, consisting of only View-Controller.</p>

<p>Each RESTful request may be called as:<br />
www.{domain-name}.com/class/function/ID</p>

<p>The existing CI components can be expanded using:</p>

<p>* Helpers<br />
* Plugins<br />
* Libraries<br />
* Classes<br />
* Hooks</p>

<p>Also of note is a handy authentication module <a href="http://www.4webby.com/freakauth/">FreakAuth</a>, I'm not sure why they chose GD2 as the image library of choice for CAPTCHA.<br />
</p>]]>
      <![CDATA[<p>Core CodeIgniter Classes</p>

<p>    * Benchmarking Class<br />
    * Calendaring Class<br />
    * Config Class<br />
    * Database Class<br />
    * Email Class<br />
    * Encryption Class<br />
    * File Uploading Class<br />
    * FTP Class<br />
    * HTML Table Class<br />
    * Image Manipulation Class<br />
    * Input and Security Class<br />
    * Loader Class<br />
    * Language Class<br />
    * Output Class<br />
    * Pagination Class<br />
    * Session Class<br />
    * Trackback Class<br />
    * Template Parser Class<br />
    * Unit Testing Class<br />
    * URI Class<br />
    * User Agent Class<br />
    * Validation Class<br />
    * XML-RPC Class</p>

<p>Core CodeIgniter  Helpers</p>

<p>    * Array Helper<br />
    * Cookie Helper<br />
    * Date Helper<br />
    * Directory Helper<br />
    * Download Helper<br />
    * File Helper<br />
    * Form Helper<br />
    * HTML Helper<br />
    * Inflector Helper<br />
    * Security Helper<br />
    * Smiley Helper<br />
    * String Helper<br />
    * Text Helper<br />
    * Typography Helper<br />
    * URL Helper<br />
    * XML Helper<br />
</p>]]>
    </content>
  </entry>
  <entry>
    <title>The Future...</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2007/12/the_future.html" />
    <modified>2007-12-29T20:21:24Z</modified>
    <issued>2007-12-29T12:08:23-08:00</issued>
    <id>tag:www.dudeforce.net,2007://1.209</id>
    <created>2007-12-29T20:08:23Z</created>
    <summary type="text/plain"> The future is already here....</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>tech</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p><img src="http://img441.imageshack.us/img441/4113/dual1nd6.jpg"></p>

<p><img src="http://tides.ws/wp-content/uploads/images/futureimages/skylift.jpg"></p>

<p>The future is already <a href="http://tides.ws/2007/11/06/the-future-of-technology-its-here/">here</a>.</p>]]>
      
    </content>
  </entry>
  <entry>
    <title>Greasemonkey Darken Script</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2007/12/greasemonkey_da.html" />
    <modified>2007-12-28T06:09:40Z</modified>
    <issued>2007-12-27T22:01:07-08:00</issued>
    <id>tag:www.dudeforce.net,2007://1.208</id>
    <created>2007-12-28T06:01:07Z</created>
    <summary type="text/plain">I just love Greasemonkey scripts for Firefox. I happened to stumble upon this basic script to &apos;Darken&apos; a web page, it&apos;s simple but a start. Now I&apos;ll make some tweaks to invert colors....</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>javascript</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>I just love <a href="http://www.greasespot.net/">Greasemonkey</a> scripts for Firefox. I happened to stumble upon this basic script to '<a href="http://lifehacker.com/software/lifehacker-code/invert-web-page-colors-with-the-darken-bookmarklet-259456.php">Darken</a>' a web page, it's simple but a start. Now I'll make some tweaks to invert colors. </p>]]>
      <![CDATA[<p>It's really nothing special, just switching back and forth from a shell console to a bright white page can be a little harsh on the eyes.</p>]]>
    </content>
  </entry>
  <entry>
    <title>del.icio.us blocking IP addresses</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2007/12/delicious_block.html" />
    <modified>2007-12-25T00:15:36Z</modified>
    <issued>2007-12-24T16:13:00-08:00</issued>
    <id>tag:www.dudeforce.net,2007://1.207</id>
    <created>2007-12-25T00:13:00Z</created>
    <summary type="text/plain">I&apos;ve built more than one web application with del.icio.us integration, now it appears they (yahoo) are blocking certain IP ranges:...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>I've built more than one web application with del.icio.us integration, now it appears they (yahoo) are blocking certain IP ranges:</p>]]>
      <![CDATA[<p>Re: del.icio.us blocking IP addresses?<br />
Subject: 	Re: del.icio.us blocking IP addresses?<br />
List-id: 	discuss.del.icio.us</p>

<p>we've been getting severe abuse from that network. i have been trying to resolve the issues with the ISP (but not getting very far...) as well as putting in more code to deal with the abuse, but getting paged all through the night has not been making this any easier.</p>

<p>Joshua</p>

<p>On Jan 11, 2006, at 4:28 PM, Markus Spath wrote:</p>

<p><br />
Hi,</p>

<p><br />
    I can't access del.icio.us anymore for the last 3 days, others don't seem to experience any problems - is del.icio.us blocking IP addresses? (mine are randomly assigned in 84.58.x.x)</p>

<p>    (I can access http://blog.del.icio.us/ and http://lists.del.icio.us/ cgi-bin/mailman/listinfo/discuss but not http://del.icio.us/)</p>

<p>    Sorry if this is the wrong place for this, but I'm not able to check the site for a more appropriate addressee and maybe others are affected as well.</p>

<p>    If you need any kind of information on my setup or if there is a better place to post my problems, please let me know.</p>

<p>thanks,<br />
Markus</p>

<p>_______________________________________________<br />
discuss mailing list<br />
discuss@xxxxxxxxxxx<br />
http://lists.del.icio.us/cgi-bin/mailman/listinfo/discuss</p>

<p><br />
--<br />
joshua schachter<br />
joshua@xxxxxxxxxxx</p>]]>
    </content>
  </entry>
  <entry>
    <title>Groovy or JRuby? That is the question.</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2007/12/groovy_or_jruby.html" />
    <modified>2007-12-24T18:47:18Z</modified>
    <issued>2007-12-24T10:19:42-08:00</issued>
    <id>tag:www.dudeforce.net,2007://1.206</id>
    <created>2007-12-24T18:19:42Z</created>
    <summary type="text/plain">As for myself, I can&apos;t speak for JRuby, as I&apos;ve only had experiences with Groovy. And I have nothing but good things to say about Groovy. It&apos;s easy to setup, implement and deploy and has much faster performance than just...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>language</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>As for myself, I can't speak for JRuby, as I've only had experiences with Groovy. And I have nothing but good things to say about Groovy. It's easy to setup, implement and deploy and has much faster performance than just Ruby alone. Hundreds of times of faster in some <a href="http://shootout.alioth.debian.org/gp4/benchmark.php?test=all&lang=ruby&lang2=java">benchmarks</a> .</p>

<p>And so onto the comparison, Martin Fowler creates yet another thought provoking computer language article:</p>

<p><a href="http://martinfowler.com/bliki/GroovyOrJRuby.html">GroovyOrJRuby</a></p>]]>
      
    </content>
  </entry>
  <entry>
    <title>Amazon Releases EC2 Public AMI Images</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2007/12/amazon_release.html" />
    <modified>2007-12-24T18:18:45Z</modified>
    <issued>2007-12-24T10:04:47-08:00</issued>
    <id>tag:www.dudeforce.net,2007://1.205</id>
    <created>2007-12-24T18:04:47Z</created>
    <summary type="text/plain">Amazon has released public AMIs for use with the EC2 computing service. And there are quite a few tutorials cropping up around the web, regarding rolling your own AMI image....</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>grid computing</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>Amazon has released <a href="http://developer.amazonwebservices.com/connect/kbcategory.jspa?categoryID=101">public AMI</a>s for use with the <a href="http://www.amazon.com/b/ref=sc_fe_l_2?ie=UTF8&node=201590011&no=3435361">EC2</a> computing service. </p>

<p>And there are quite a few tutorials cropping up around the web, regarding rolling your own AMI image.</p>]]>
      <![CDATA[<p>Creating your own FC6 instance for EC2<br />
http://www.ioncannon.net/system-administration/115/creating-your-own-fc6-instance-for-ec2/<br />
</p>]]>
    </content>
  </entry>
  <entry>
    <title>Yes, Folks MT Here</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2007/11/yes_folks.html" />
    <modified>2007-11-30T04:00:41Z</modified>
    <issued>2007-11-29T19:12:04-08:00</issued>
    <id>tag:www.dudeforce.net,2007://1.204</id>
    <created>2007-11-30T03:12:04Z</created>
    <summary type="text/plain">I&apos;m still here using Movable Type, Version 3.01D to be exact. That may be changing very soon. I set up a blog on wordpress.com, but it&apos;s entirely too limiting. It&apos;s either going to be a local wordpress installation or else...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>this blog</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>I'm still here using Movable Type, Version 3.01D to be exact. That may be changing very soon. I set up a blog on wordpress.com, but it's entirely too limiting. It's either going to be a local wordpress installation or else i'm going with Drupal. </p>]]>
      
    </content>
  </entry>
  <entry>
    <title>Mono:FreeBSD (BSD#)</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2005/10/monofreebsd_bsd.html" />
    <modified>2005-10-15T23:08:38Z</modified>
    <issued>2005-10-15T16:04:13-08:00</issued>
    <id>tag:www.dudeforce.net,2005://1.203</id>
    <created>2005-10-16T00:04:13Z</created>
    <summary type="text/plain">This is awesome. The BSD# Project is devoted to porting and maintaining the Mono .NET framework for FreeBSD. The Mono framework consists of not only the Mono Runtime environment and compiler but the XSP web server for handling ASP.NET applications,...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>mono</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>This is awesome.</p>

<p>The BSD# Project is devoted to porting and maintaining the Mono .NET framework for FreeBSD. The Mono framework consists of not only the Mono Runtime environment and compiler but the XSP web server for handling ASP.NET applications, the IKVM Java virtual machine for handling Java within the framework, and numerous data providers to provide common library functions in C# or integration with existing C libraries.</p>

<p>The BSD# project is hosted on Novell Forge (http://forge.novell.com). The project's CVS repository (http://forge.novell.com/modules/xfmod/cvs/cvsbrowse.php/bsd-sharp/) currently contains FreeBSD ports for all Mono packages released by Novell. It also includes ports for applications and libraries from third parties as well with the intent that they be integrated into the standard FreeBSD ports tree. The project aims to act as a central testing point for porting new releases from Novell, for introducing new applications, and for testing framework wide changes that will affect all applications that rely on Mono before they reach the FreeBSD ports tree.</p>

<p><a href='http://www.mono-project.com/Mono:FreeBSD' target='_blank'>Mono:FreeBSD</a></p>]]>
      
    </content>
  </entry>
  <entry>
    <title>Whois Spam</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2005/06/whois_spam.html" />
    <modified>2005-06-20T20:21:06Z</modified>
    <issued>2005-06-20T13:13:30-08:00</issued>
    <id>tag:www.dudeforce.net,2005://1.202</id>
    <created>2005-06-20T21:13:30Z</created>
    <summary type="text/plain">Looks like whois is now even prone to spam. Look at what google.com returns: me@server$ whois google.com Whois Server Version 1.3 Domain names in the .com and .net domains can now be registered with many different competing registrars. Go to...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>suck</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>Looks like whois is now even prone to spam. Look at what google.com returns:</p>

<p>me@server$ whois google.com</p>

<p>Whois Server Version 1.3</p>

<p>Domain names in the .com and .net domains can now be registered<br />
with many different competing registrars. Go to http://www.internic.net<br />
for detailed information.</p>

<p>GOOGLE.COM.ZZZZ.DNSW.COM<br />
GOOGLE.COM.VN<br />
GOOGLE.COM.SUCKS.FIND.CRACKZ.WITH.SEARCH.GULLI.COM<br />
GOOGLE.COM.IS.NOT.HOSTED.BY.ACTIVEDOMAINDNS.NET<br />
GOOGLE.COM.IS.APPROVED.BY.NUMEA.COM<br />
GOOGLE.COM.HAS.LESS.FREE.PORN.IN.ITS.SEARCH.ENGINE.THAN.SECZY.COM<br />
GOOGLE.COM.AU<br />
GOOGLE.COM</p>

<p>To single out one record, look it up with "xxx", where xxx is one of the<br />
of the records displayed above. If the records are the same, look them up<br />
with "=xxx" to receive a full display for each record.<br />
</p>]]>
      
    </content>
  </entry>
  <entry>
    <title>Wordpress 1.5 SQL-Injection Attack</title>
    <link rel="alternate" type="text/html" href="http://www.dudeforce.net/archives/2005/06/wordpress_15_sq.html" />
    <modified>2005-06-01T14:32:25Z</modified>
    <issued>2005-06-01T07:21:37-08:00</issued>
    <id>tag:www.dudeforce.net,2005://1.201</id>
    <created>2005-06-01T15:21:37Z</created>
    <summary type="text/plain">The most critical vulnerability in the 1.5 release of wordpress is an SQL-Injection in `wp-trackback.php&apos;. It&apos;s not easily exploitable because you do not get a result when you inject a valid query but it&apos;s possible to bruteforce values in the...</summary>
    <author>
      <name>0xFF3300</name>
      
      <email>juliansitke@hotmail.com</email>
    </author>
    <dc:subject>this blog</dc:subject>
    <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.dudeforce.net/">
      <![CDATA[<p>The most critical vulnerability in the 1.5 release of wordpress is an<br />
SQL-Injection in `wp-trackback.php'. It's not easily exploitable<br />
because you do not get a result when you inject a valid query but it's<br />
possible to bruteforce values in the tables - for example the password<br />
hashes.</p>

<p>Here some details:<br />
The parameter `tb_id' in `wp-trackback.php' is not validated correctly<br />
and there are no quotes in the SQL-query so an attacker is able to<br />
insert sql commands.</p>

<p>$pingstatus = $wpdb->get_var("SELECT ping_status FROM $wpdb->posts<br />
WHERE ID = $tb_id");<br />
        <br />
Example: (I converted the POST-request into a GET-request.)</p>

<p>> $tb_id = 1 union select user_pass,0 from wp_users<br />
> $url = bla<br />
> $title = bla</p>

<p></wp-trackback.php?tb_id=1%20union%20select%200,user_pass%20from%20<br />
wp_users&url=bla&title=bla></p>

<p>By injecting this query I get following databae error:</p>

<p>> WordPress database error:<br />
> [The used SELECT statements have a different number of columns]<br />
> SELECT ping_status FROM wp_posts WHERE ID = 1 union select 0,<br />
> user_pass from wp_users</p>

<p>When I insert "1 union select user_pass from wp_users" as value for<br />
`tb_id' I get no error message because the query was well-formed -<br />
logical. Through the possibility to insert any sql-command it's<br />
possible to 'reconstruct' values of the tables. </p>

<p>o XSS:<br />
=====</p>

<p></wp-admin/edit.php?s=[XSS]&submit=Search><br />
</wp-admin/post.php?action=confirmdeletecomment&comment=1&p=[XSS]> </p>]]>
      <![CDATA[<p>o Disclosure Timeline:<br />
=====================</p>

<p>17 Apr 05 - Security flaws discovered.<br />
19 Apr 05 - Vendor contacted.<br />
10 May 05 - Vendor released bugfixed version.<br />
17 May 05 - Public release.</p>

<p>o Solution:<br />
==========</p>

<p>Upgrade to wordpress 1.5.1 [1]</p>

<p>o Credits:<br />
=========</p>

<p>Thomas Waldegger <bugtraq@morph3us.org><br />
BuHa-Security Community - http://buha.info/board/ </p>]]>
    </content>
  </entry>

</feed>