web application security lab

fthe net - The name says it all.


Asshole Business Ideas

August 16th, 2010 by RSnake

RSnake: Okay, you know how I’m a shitty son

RSnake: like really crap

wife: yes

RSnake: I barely remember to return calls, I’m hard to pin down on dates… not to mention travel! No one can count on me for birthday’s x-masses, etc…

wife: yep

RSnake: Okay, what about a site, where the people who WANT my time, pay me (and the site takes a small cut) to be a good son. So my folks put in, let’s say, $10 every time they want to talk on the phone. If I live up to my end and talk for an hour, I get the money. If they want me to show up for Xmas - boy, that’s going to cost like $100 each day.

RSnake: You tally it up, and I’m finally getting compensated for my family.

wife: hahahaha

wife: thats a terrible idea

wife: youre a bad person

RSnake: And if I’m like an executive I could set my rate higher

RSnake: But for college kids - it teaches their parents that the kids’ time is money

RSnake: Plus it makes the family happy because they get exactly what they pay for.

RSnake: I think it’s a win win!

RSnake: I just don’t think a lot of people would sign up.

RSnake: hahah

wife: what an ass

RSnake: Yeah, but still, I’m a funny ass.

wife: thats an asshole idea

RSnake: hahahahhah

wife: hah

wife: man o man

wife: youre going to hell

RSnake: yes

RSnake: Definitely

wife: :/

RSnake: Man, I’m awesome

wife: awesomely asshole

RSnake: hahah

RSnake: Come to think of it I could put that price on there for when you want to talk to me about buying houses too.

wife: no

F* Changing of Severity Ratings

February 28th, 2010 by RSnake

So one of our clients decided that this whole severity rating system was just way too confusing. Here’s what he’s confused by:

  • High
  • Medium
  • Low

I know… super extremely confusing, with all of the highs and lows. So he decided it would be far better to upgrade the system to a more “intuitive” system:

  • Foul
  • Nasty
  • Ugly

Yes, that’s much better… now I can spend five minutes trying to decipher which one of those things is high, medium and low, instead of… you know… just seeing that it says high medium or low. Because I can’t for the life of me figure out which is which now unless I see it in order next to a key that describes which one is high, medium and low. Yes, how didn’t I think of that? So much better. I’d like to offer a slight modification, because I think this would be even more intuitive. The emoticon version:

  • >:-0
  • :-(
  • :-/

-RSnake

Best Definition Ever

August 31st, 2009 by RSnake

Thank you, PGP, for being so very extremely helpful:

PGP: Message is blocked by policy - recipient key not found. This message is triggered if the message is blocked because the recipient’s key is not found.

I guess this all depends on what the definition of is is.

-RSnake

F* Rankings

August 13th, 2009 by RSnake

So, yeah, spam sucks, but every once in a while you get something that makes you choke on your own spit when you read it, you’re laughing so hard:

… Vintage IT Services has earned the position of 3,457 on the 2009 Inc. 5000, Inc.’s annual ranking of the fastest-growing private companies in America. …

Wow! I’m sure your mother was very proud of you. There must have been quite a fierce race there at the 3,400 level mark. Retards.

-RSnake

Sales At It’s Finest Hour

July 27th, 2009 by RSnake

I believe this Topsec company sounds like it’s going right into the crapper, or at least that’s what Kerna wants me to believe:

Good morning, as you may have heard Topsec Security may be wound down in the near future and have been brought to court by thier Creditors.

We are contacting you to make you aware of this development as it may effect your business.

We also understand that many of our clients are not aware that Kerna provide a similar Email filtering service called Mailsecure.

If you have been affected by the closure of Topsec or would like to inquire regarding the Kerna Mailsecure product please contact Chris Dooley on 01 664 7244.

Thank you for your time.

Chris

Chris Dooley
Kerna Communications
Citrix Certified Sales Professional (CCSP) & Network Security Consultant

This Chris guy is a killer sales guy! But then I realize, no, it’s just speculative libel, as his co-worker Bob pulls his company out of the gutter:

To whom it may conern.

It has come to our attention that a draft email was sent in error to a small number of companies last Friday (24th July).

As you may be aware, there is a dispute currently between Topsec Technologies (trading name of Systemhouse) and Commtech which is being pursued in the High Court.

As part of an internal discussion in Kerna regarding this case a possible mailshot was being considered in the event of that case impacting on customers of Topsec Technologies.

It is not our intention, nor would we wish to imply that customers of Topsec Technologies should consider their relationship with that company to be impaired. We would encourage customers of Topsec Technologies to continue to use their services and only to consider alternatives should the business environment require it.

We would like to apologize to you for any confusion resulting from this email.

Sincerely,

Bob Curran
Kerna Communications
Citrix Certified Sales Professional (CCSP) & Network Security Consultant

Maybe you should lay off the “send” key, Chris. Sucks to be you! Way to clean up the mess, Bob!

-RSnake

oh hai pls to hack?

August 21st, 2008 by RSnake

This email needs no introduction:

hai i want to give a presentation on hacking i know some want about hacking but i need the breif informaion on hacking please send me the some of the sites of the hacking or give me the papers of the hacking thanking you………………

This super hacker found me by searching for “paper on hacking.” Ph33r the skillz!

-RSnake

F* Full Tilt Poker

August 12th, 2008 by thrill

Last year I read an article that detailed the events of a particular tournament. In this tournament, it was extremely obvious, once you read what each player started out with and what came on the board after, that there was some serious cheating going on. And while I understand that on-line poker sites are filled with extremely lucky idiots, the logs clearly showed insider knowledge, for example, why would a player go all in with 7-2 off suit, pre-flop, yet fold ak suited?

The method behind it is actually very simple.

On-line poker sites use pre-dealt hands. The computer generated hands are first created, then they have to be verified that the winning hand is actually correct (it’s a bit tough for the computer to understand the concept of face cards). Then, these pre-dealt hands are entered into a database which then in turn deals to real players.

Now, FTP operators need to have access to these databases and each individual hand for the purposes of having a record in case a dispute comes in. Of course, these disputes could be in the case where 4 10’s beat a straight flush (the verification process could have missed the real winning hand).

So let’s say my good friend Bob is now a part of the operators at full tilt, I’m sitting on the button with 7-2 off suit, I tell him the hand number, he looks it up on the database, he sees that the big blind has A K off suit, but knows that two 7’s and a 2 will make their way on the board. He tells me that I have the winning hand and to bet big because the fool on the big blind is likely going to not only call, but go all-in.

Unfortunately for me, I was the fool with AK on the big blind, and the player on the button with his 7 2 was the one with the friend at FTP.

How can FTP prevent this type of abuse? Easy, deny access to hands that have not been played and put a 5 minute delay before the hands can be looked up through the database.

Of course, it is quite plausible that FTP has a room full of ‘players’ that pick up hands from bots to give it the realism of having someone actually type into the chat window, and as far as they’re concerned, they want the cheating to go on because they’re making more money by cheating anyway..

So in short, F* Full Tilt Poker.

-thrill

F* Wind chimes

February 20th, 2008 by id

You take something mildly annoying and make it extremely annoying, what good could that possibly be? If you’re alone in the middle of nowhere, go chime all you fucking want, but if you’re in earshot of me, SHUT THE FUCK UP. Do you really need something to alert you the fucking wind is blowing? The howling just isn’t enough and you need to hear some clattering and banging as well? How fucking deranged are you to think to yourself “my, that blowing sound isn’t any good, I’ll add the sound of metal randomly hitting metal to spice it up”???

Yahoo returns 3,590,000 hits for “wind chimes”, that’s over 3,590,000 sites trying to make the world a more annoying place, and 3,590,000 webmasters that need to die by having metal and glass shoved through their eardrums.

F* you Mr make noise noisier man.

-id

Retarded MMS

April 21st, 2007 by RSnake

So I get an MMS on my phone. Although my phone is running the Windows operating system, apparently it is incapable of getting MMSs. Here’s where my troubles begin. So I get a username and password and a website to log into. The website address does not contain a www (although that is necessary for it to function). Easily figured out. Next is the username and password.

So I look at the username, and I swear to you, it is something like “a1j4ufi3j2″ and the password is something super easy like “stats8bang”. So it takes me half a dozen times typing in the username to get it right, but the password is plaintext anyway (doesn’t even use the password type on the input box). Don’t ask me why they have utterly useless security. So I finally manage to log in and it just sits there. Oh, apparently this requires JavaScript. So I turn that on, hit refresh - sorry, no worky, gotta log in again… it continues to sit there. Uhh… switch browsers… log in half a dozen times… still sitting there… uhh… oh, I guess it’s loading something. Here I sit waiting, like a frozen idiot waiting for some stupid application to start loading…

Five fucking minutes later it loads a Flash movie for a stupid 30k image my girlfriend took of a funny sign. Ugh! So I try to download the picture embedded in the Flash movie using the hand dandy little download image button they have there. No, I’m sorry, that throws a JS error. Why? Why must you do this to me? I’m going to go punch my neighbor now - just cuz.

-RSnake

Best Advice Ever

March 16th, 2007 by RSnake

So there I am on a conference call with one of the world’s leading experts in UI design. Oh he just fucking rocks. He is so bad ass no one can hold a candle to him in his respective microscopic part of UI that he works on. So I am there, prepared to be stunned and amazed by his utter brilliance and then he hits me with the best advice ever:

“I think you should create a UI that is the best possible UI you can build.”

God, I’m glad there are people out there to do this big thinking for me. Where would we be without such brilliant scholars? Wait, how much are we paying this guy?

-RSnake