Another IE security Issue

Yet another Inter­net Explorer exploit has been dis­covered. This one is ripe for many of the phish­ing scams that have been going around.

Secunia have a good, detailed advis­ory.

The vul­ner­ab­il­ity is caused due to an input val­id­a­tion error, which can be exploited by includ­ing the “%01″ URL encoded rep­res­ent­a­tion after the user­name and right before the “@” char­ac­ter in an URL.
Suc­cess­ful exploit­a­tion allows a mali­cious per­son to dis­play an arbit­rary FQDN (Fully Qual­i­fied Domain Name) in the address bar, which is dif­fer­ent from the actual loc­a­tion of the page.

Steve Minutillo has an example. Andy at absob­log­gin­lutely has another example.

Remem­ber, these only ‘work’ as inten­ded in Inter­net Explorer.

Olive Berkon

Jan’s mum, Olive, passed on six years ago today. We still miss her.

When I must leave you
For a little while
Please do not grieve and shed wild tears
And hug your sor­rows to you through the years
But start out bravely with a gal­lant smile
And for my sake and in my name
Live on and do all things the same
Feed not your loneli­ness on empty days
But fill each wak­ing hour in use­ful ways
Reach out your hand in com­fort and in cheer
And I in turn will com­fort you and hold you near
And never, never be afraid to die
For I am wait­ing for you
In the sky
– Helen Steiner Rice

Good Luck Jamie

My daugh­ter Jamie has her open­ing night of her first pan­to­mime tonight. The stage school she attends has a pan­to­mime every year. This year Jamie will be per­form­ing about 6 songs as part of the chorus in the show and she has sev­eral dances too. I will be going to see her tomor­row. I’m really look­ing for­ward to it. If her singing around the house is an indic­a­tion she will be great!

Good luck Jamie.
Lots of Love,

Mum and Dad
XOXOXOXOX

BlogShares — Closed Down

It looks like Seyed has finally thrown in the towel. BlogShares has offi­cially closed down.

I am sorry to announce that BlogShares will not be reopen­ing after the cur­rent tech­nical dif­fi­culties are resolved. Cur­rently, the data­base server is dead and looks to be for the next few days.

It was fun while it las­ted. But as Seyed him­self says there has been a decline of qual­ity ser­vice, new fea­tures and ulti­mately income for the site in the last couple of months.

I’m glad to have been part of it from quite early on (I was mem­ber num­ber 341, joined at the end of March).