<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>justSayBAD</title>
	<atom:link href="http://www.justsaybad.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.justsaybad.com</link>
	<description>I'm really easy to get along with once you people learn to worship me</description>
	<lastBuildDate>Fri, 02 Jul 2010 14:51:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SELECT * FROM internet</title>
		<link>http://www.justsaybad.com/select-from-internet/</link>
		<comments>http://www.justsaybad.com/select-from-internet/#comments</comments>
		<pubDate>Fri, 02 Jul 2010 14:51:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Development]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=21</guid>
		<description><![CDATA[Am lucrat de curand cu Yahoo! Query Language .
Pentru cei ce  nu stiu ce este :
The Yahoo! Query Language is an expressive SQL-like language that lets you query, filter, and join data across Web services. With YQL, apps run faster with fewer lines of code and a smaller network footprint.
Este un serviciu genial si free, cu [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/select-from-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ban pe IP</title>
		<link>http://www.justsaybad.com/ban-pe-ip/</link>
		<comments>http://www.justsaybad.com/ban-pe-ip/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 11:37:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ban]]></category>
		<category><![CDATA[securitate]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=20</guid>
		<description><![CDATA[Foloseam pana de curand o metoda pentru a bana un IP chiar daca foloseste proxy transparent. Solutia pe care am folosit-o era urmatoarea functie :

function getip() {
if (isset($_SERVER["HTTP_X_FORWARDED_FOR"]))
foreach (explode(",",$_SERVER["HTTP_X_FORWARDED_FOR"]) as $ip) {
if (baseMod::validip(trim($ip))) {
return $ip;
}
}
$ipsl=array("HTTP_CLIENT_IP","HTTP_X_FORWARDED","HTTP_FORWARDED_FOR","HTTP_FORWARDED","HTTP_X_FORWARDED");
foreach ($ipsl as $tp)
{
if (isset($_SERVER[$tp]))
if (baseMod::validip($_SERVER[$tp]))
return $_SERVER[$tp];
}return $_SERVER["REMOTE_ADDR"];
}

IP-ul returnat in treceam in baza de date ca fiind banat&#8230; problema aici este [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/ban-pe-ip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Si daca totusi uitam!</title>
		<link>http://www.justsaybad.com/si-daca-totusi-uitam/</link>
		<comments>http://www.justsaybad.com/si-daca-totusi-uitam/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 18:44:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[securitate]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[tutorial]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=19</guid>
		<description><![CDATA[Scriam in postul trecut cat de important este sa verifici tot input-ul de la utilizatori. Este de ajuns doar unu sa fie sarit si site-ul poate fi vulnerabil.
Dar daca totusi gresim si uitam sa validam un input ? Ce putem face in cazul in care site-ul este vulnerabil la SQL Injection?
Pentru astfel de cazuri folosesc [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/si-daca-totusi-uitam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securitate? ce e aia ?</title>
		<link>http://www.justsaybad.com/securitate-ce-e-aia/</link>
		<comments>http://www.justsaybad.com/securitate-ce-e-aia/#comments</comments>
		<pubDate>Sun, 08 Mar 2009 20:02:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[securitate]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=18</guid>
		<description><![CDATA[Dupa o lunga perioada de timp am revenit cu un nou post.. si sper ca de acum in colo sa scriu mai des.
Astazi va voi vorbi cum sa incepeti sa va asigurati site-ul si ce sa face ti pentru o mai multa siguranta la codare.
Pentru inceput ar trebui sa fie stiut ca absolut tot ceea [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/securitate-ce-e-aia/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cat mai costa un vot ?</title>
		<link>http://www.justsaybad.com/cat-mai-costa-un-vot/</link>
		<comments>http://www.justsaybad.com/cat-mai-costa-un-vot/#comments</comments>
		<pubDate>Sat, 29 Nov 2008 18:31:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[cost]]></category>
		<category><![CDATA[psd]]></category>
		<category><![CDATA[vot]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=17</guid>
		<description><![CDATA[Astazi sa intamplat o chestie care nu as fi crezut-o daca nu vedeam cu ochii mei. In timpul odihnei de dupa masa (somn)  aud soneria de la usa. Uimit cine ma deranjeaza la ora asta de odihna&#8230; ma ridic cu greu si ma indrept spre usa. Fiind mai rapid fratele ajunge inaintea mea si intr-o [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/cat-mai-costa-un-vot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQL injection site fancourier</title>
		<link>http://www.justsaybad.com/sql-injection-site-fancourier/</link>
		<comments>http://www.justsaybad.com/sql-injection-site-fancourier/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 17:15:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[fancourier]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=15</guid>
		<description><![CDATA[Astazi la indemnul unui coleg&#8230; am gasit din &#8220;greseala&#8221; posibilitatea de a face un SQL injection la search-ul pt. AWB la site-ul celor de la fancourier.
Mi se pare anormal ca site-ul unei firme de curierat destul de mare(22,4 milioane de EURO dupa 9 luni) sa aiba o securitate asa de proasta. Acest exploit fiind unul [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/sql-injection-site-fancourier/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>flash upload &#8211; problema cu session id-urile</title>
		<link>http://www.justsaybad.com/flash-upload-problema-cu-session-id-urile/</link>
		<comments>http://www.justsaybad.com/flash-upload-problema-cu-session-id-urile/#comments</comments>
		<pubDate>Sat, 30 Aug 2008 17:53:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[phpsessid]]></category>
		<category><![CDATA[sessionid]]></category>
		<category><![CDATA[upload]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=13</guid>
		<description><![CDATA[Zilele trecute am avut nevoia intr-un protiect de a folosi un flash pentru upload-ul de fisiere.
Nu prea imi place flash-ul dar alta solutie mai buna nu am gasit asa ca am optat pt. varianta asta. Aveam persoana potrivita care sa rezalizeze asta (nu stiu o boaba de flash) si am trecut la munca. Trebuie sa [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/flash-upload-problema-cu-session-id-urile/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hug a developer</title>
		<link>http://www.justsaybad.com/hug-a-developer/</link>
		<comments>http://www.justsaybad.com/hug-a-developer/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 12:59:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[developer]]></category>
		<category><![CDATA[funny]]></category>
		<category><![CDATA[hug]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=12</guid>
		<description><![CDATA[Un filmulet super tare&#8230; developerii&#8230; saracii&#8230; prin ce trec&#8230;

Sper ca toti ce i care nu sunt/fost developeri sa inteleaga prin ce trecem  
]]></description>
		<wfw:commentRss>http://www.justsaybad.com/hug-a-developer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>stiri.. 01 phone&#8230; cand nu se verifica sursele.. fals</title>
		<link>http://www.justsaybad.com/stiri-01-phone-cand-nu-se-verifica-sursele-fals/</link>
		<comments>http://www.justsaybad.com/stiri-01-phone-cand-nu-se-verifica-sursele-fals/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 09:53:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[01phone]]></category>
		<category><![CDATA[stiri]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=10</guid>
		<description><![CDATA[Am citit zilele trecute o stire pe go4it.ro in care se vorbea de posibila aparitie a unui telefon a carui producator este necunoscut . Site-ul(The01Phone.com) unde telefonul este prezentat(cateva imagini) are un timer care la fiecare refresh porneste de la aceasi valoare&#8230; Dupa putin citit pe net se observa ca este o stire falsa. Pacat [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/stiri-01-phone-cand-nu-se-verifica-sursele-fals/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>MySql trunc exploit</title>
		<link>http://www.justsaybad.com/mysql-trunc-exploit/</link>
		<comments>http://www.justsaybad.com/mysql-trunc-exploit/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 07:28:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[mysql]]></category>

		<guid isPermaLink="false">http://www.justsaybad.com/?p=9</guid>
		<description><![CDATA[Acest tip de exploit poate avea loc cand lungimea input-ului nu este verificata .
Sa presupunem ca avem in baza de date un user &#8216;admin&#8217; . Daca incercam sa facem o cautare dupa acest user atunci &#8216;admin&#8217; si &#8216;admin    &#8217; sunt returnate ca fiind la fel. MySql nu face o cautare binara.
Astfel un atacator ar putea la crearea  unui [...]]]></description>
		<wfw:commentRss>http://www.justsaybad.com/mysql-trunc-exploit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
