web application security lab

fthe net - The name says it all.


Best Definition Ever

August 31st, 2009 by RSnake

Thank you, PGP, for being so very extremely helpful:

PGP: Message is blocked by policy - recipient key not found. This message is triggered if the message is blocked because the recipient’s key is not found.

I guess this all depends on what the definition of is is.

-RSnake

F* Rankings

August 13th, 2009 by RSnake

So, yeah, spam sucks, but every once in a while you get something that makes you choke on your own spit when you read it, you’re laughing so hard:

… Vintage IT Services has earned the position of 3,457 on the 2009 Inc. 5000, Inc.’s annual ranking of the fastest-growing private companies in America. …

Wow! I’m sure your mother was very proud of you. There must have been quite a fierce race there at the 3,400 level mark. Retards.

-RSnake

Sales At It’s Finest Hour

July 27th, 2009 by RSnake

I believe this Topsec company sounds like it’s going right into the crapper, or at least that’s what Kerna wants me to believe:

Good morning, as you may have heard Topsec Security may be wound down in the near future and have been brought to court by thier Creditors.

We are contacting you to make you aware of this development as it may effect your business.

We also understand that many of our clients are not aware that Kerna provide a similar Email filtering service called Mailsecure.

If you have been affected by the closure of Topsec or would like to inquire regarding the Kerna Mailsecure product please contact Chris Dooley on 01 664 7244.

Thank you for your time.

Chris

Chris Dooley
Kerna Communications
Citrix Certified Sales Professional (CCSP) & Network Security Consultant

This Chris guy is a killer sales guy! But then I realize, no, it’s just speculative libel, as his co-worker Bob pulls his company out of the gutter:

To whom it may conern.

It has come to our attention that a draft email was sent in error to a small number of companies last Friday (24th July).

As you may be aware, there is a dispute currently between Topsec Technologies (trading name of Systemhouse) and Commtech which is being pursued in the High Court.

As part of an internal discussion in Kerna regarding this case a possible mailshot was being considered in the event of that case impacting on customers of Topsec Technologies.

It is not our intention, nor would we wish to imply that customers of Topsec Technologies should consider their relationship with that company to be impaired. We would encourage customers of Topsec Technologies to continue to use their services and only to consider alternatives should the business environment require it.

We would like to apologize to you for any confusion resulting from this email.

Sincerely,

Bob Curran
Kerna Communications
Citrix Certified Sales Professional (CCSP) & Network Security Consultant

Maybe you should lay off the “send” key, Chris. Sucks to be you! Way to clean up the mess, Bob!

-RSnake

oh hai pls to hack?

August 21st, 2008 by RSnake

This email needs no introduction:

hai i want to give a presentation on hacking i know some want about hacking but i need the breif informaion on hacking please send me the some of the sites of the hacking or give me the papers of the hacking thanking you………………

This super hacker found me by searching for “paper on hacking.” Ph33r the skillz!

-RSnake

F* Full Tilt Poker

August 12th, 2008 by thrill

Last year I read an article that detailed the events of a particular tournament. In this tournament, it was extremely obvious, once you read what each player started out with and what came on the board after, that there was some serious cheating going on. And while I understand that on-line poker sites are filled with extremely lucky idiots, the logs clearly showed insider knowledge, for example, why would a player go all in with 7-2 off suit, pre-flop, yet fold ak suited?

The method behind it is actually very simple.

On-line poker sites use pre-dealt hands. The computer generated hands are first created, then they have to be verified that the winning hand is actually correct (it’s a bit tough for the computer to understand the concept of face cards). Then, these pre-dealt hands are entered into a database which then in turn deals to real players.

Now, FTP operators need to have access to these databases and each individual hand for the purposes of having a record in case a dispute comes in. Of course, these disputes could be in the case where 4 10’s beat a straight flush (the verification process could have missed the real winning hand).

So let’s say my good friend Bob is now a part of the operators at full tilt, I’m sitting on the button with 7-2 off suit, I tell him the hand number, he looks it up on the database, he sees that the big blind has A K off suit, but knows that two 7’s and a 2 will make their way on the board. He tells me that I have the winning hand and to bet big because the fool on the big blind is likely going to not only call, but go all-in.

Unfortunately for me, I was the fool with AK on the big blind, and the player on the button with his 7 2 was the one with the friend at FTP.

How can FTP prevent this type of abuse? Easy, deny access to hands that have not been played and put a 5 minute delay before the hands can be looked up through the database.

Of course, it is quite plausible that FTP has a room full of ‘players’ that pick up hands from bots to give it the realism of having someone actually type into the chat window, and as far as they’re concerned, they want the cheating to go on because they’re making more money by cheating anyway..

So in short, F* Full Tilt Poker.

-thrill

F* Wind chimes

February 20th, 2008 by id

You take something mildly annoying and make it extremely annoying, what good could that possibly be? If you’re alone in the middle of nowhere, go chime all you fucking want, but if you’re in earshot of me, SHUT THE FUCK UP. Do you really need something to alert you the fucking wind is blowing? The howling just isn’t enough and you need to hear some clattering and banging as well? How fucking deranged are you to think to yourself “my, that blowing sound isn’t any good, I’ll add the sound of metal randomly hitting metal to spice it up”???

Yahoo returns 3,590,000 hits for “wind chimes”, that’s over 3,590,000 sites trying to make the world a more annoying place, and 3,590,000 webmasters that need to die by having metal and glass shoved through their eardrums.

F* you Mr make noise noisier man.

-id

Retarded MMS

April 21st, 2007 by RSnake

So I get an MMS on my phone. Although my phone is running the Windows operating system, apparently it is incapable of getting MMSs. Here’s where my troubles begin. So I get a username and password and a website to log into. The website address does not contain a www (although that is necessary for it to function). Easily figured out. Next is the username and password.

So I look at the username, and I swear to you, it is something like “a1j4ufi3j2″ and the password is something super easy like “stats8bang”. So it takes me half a dozen times typing in the username to get it right, but the password is plaintext anyway (doesn’t even use the password type on the input box). Don’t ask me why they have utterly useless security. So I finally manage to log in and it just sits there. Oh, apparently this requires JavaScript. So I turn that on, hit refresh - sorry, no worky, gotta log in again… it continues to sit there. Uhh… switch browsers… log in half a dozen times… still sitting there… uhh… oh, I guess it’s loading something. Here I sit waiting, like a frozen idiot waiting for some stupid application to start loading…

Five fucking minutes later it loads a Flash movie for a stupid 30k image my girlfriend took of a funny sign. Ugh! So I try to download the picture embedded in the Flash movie using the hand dandy little download image button they have there. No, I’m sorry, that throws a JS error. Why? Why must you do this to me? I’m going to go punch my neighbor now - just cuz.

-RSnake

Best Advice Ever

March 16th, 2007 by RSnake

So there I am on a conference call with one of the world’s leading experts in UI design. Oh he just fucking rocks. He is so bad ass no one can hold a candle to him in his respective microscopic part of UI that he works on. So I am there, prepared to be stunned and amazed by his utter brilliance and then he hits me with the best advice ever:

“I think you should create a UI that is the best possible UI you can build.”

God, I’m glad there are people out there to do this big thinking for me. Where would we be without such brilliant scholars? Wait, how much are we paying this guy?

-RSnake

The wing man

January 20th, 2007 by id

Women don’t get it, men suffer through it, you know when you’ve lost and all you have left is to make sure your buddy comes through with the win.

It’s not fun, but it’s your duty, you’re the wingman. The one half to one hour it costs you is irrelevant. SUCK IT UP NANCY BOY!

So what does it mean to be the wing man? If you’re a guy with any sense of decency, and of course don’t give a fuck what women think (you are a guy right???), you know you’re not getting laid tonight, but your buddy just might…IF not for her cockblocking, jaba the hut, satanic guardian angel. You see her walking for the door, motioning her drunk and horny friend to follow her into the pit of self denial of her longings. She knows the only guy that will pay attention to her is the 52 year old drunk guy at the end of the bar; drinking southern comfort to the point of bobbing his head off the edge of the bar. So to “make things fair for herself” she tries to deny her friend the fruits of a drunken encounter with the man of her sloshed dreams, YOUR buddy.
Your duty, your honor as a man, your cruel punishment for not picking up the other hot chick is to play interference. You know what you have to do, though despising it, you must deflect, mesmerize and possibly sleep with the “Friend”.
You fucked up, but now you have to do the right, but oh so wrong thing.

So….
She’s fat:

Think of the HUGE tits, close your eyes and play with em.

She’s dumb:

You suck at being a wingman, if you can’t just put a sock in her mouth and fuck her to help out a friend…man.

She’s the ugliest women you’ve ever laid eyes on:

Close you’re eyes and pretend it’s not your freshmen year of college in the dorm hall on the 5th floor of Corbet hall at CSU, but it’s your birthday man, and she doesn’t give such bad head as you pretend she’s the sorority chick you saw earlier at the party and DON’T JUDGE ME MAN. Deny ever meeting her the next night, it’s going to take a while to come to terms with shit, but forget, just forget.

-id

F* Contracts

November 9th, 2006 by RSnake

I could barely believe this section of a contract I was asked to sign with a straight face:

Contractor agrees to perform, during and after the term of this Agreement, all acts that Company deems necessary or desirable to permit and assist Company, at its expense, in obtaining, perfecting and enforcing the full benefits, enjoyment, rights and title throughout the world in the Company Innovations as provided to Company under this Agreement. If Company is unable for any reason to secure Contractor’s signature to any document required to file, prosecute, register or memorialize the assignment of any rights under any Company Innovations as provided under this Agreement, Contractor hereby irrevocably designates and appoints Company and Company’s duly authorized officers and agents as Contractor’s agents and attorneys-in-fact to act for and on Contractor’s behalf and instead of Contractor to take all lawfully permitted acts to further the filing, prosecution, registration, memorialization of assignment, issuance and enforcement of rights under such Company Innovations, all with the same legal force and effect as if executed by Contractor. The foregoing is deemed a power coupled with an interest and is irrevocable.

In case you can’t read legal-eze this is sorta the legal equivalent of being sodomized with a telephone pole. No, I’m not signing it - not without the KY.

-RSnake