2006/07/09

Query string vulnerability found on a website of DVD software vendor

I wanted to play a disc with CPRM copyright protection mechanism and tried to activate CPRM feature of my software online. The website showed my account, including my name, my address and my password reminder (my mother's name). Then I found by accident that the site exposes GET-based query string on the URL and that by changing that string then we can see other persons' personal data. I soon requested to the vendor first to delete my personal datum and then to stop that site. My datum was deleted, but the site remains alive. You should make sure that the vendor of the software that you want to buy has enough knowledge of web security.

2006/05/21

The controversial Da Vinci Code did not refer to Marcel Proust. The etymology of Louvre is watchtower.

2006/03/12

Arabic language course - NHK Educational TV

هل تعلم أن اليابان أيضا وشهورة بفن الخط

2006/02/24

Figure Skating: Arakawa's misleading peace sign, not a victory sign

Torino 2006. Shizuka Arakawa won the gold medal, when she flashed a `"V" for victory sign' (Arkansas Democrat Gazette)
It's one of typical misleading hand signals. In Japan, the V sign with two fingers does not mean victory at all. Asians use that sign with no particular meaning. See : http://en.wikipedia.org/wiki/V_sign