<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Techhawking</title>
	<atom:link href="http://www.royans.net/rant/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.royans.net/rant</link>
	<description>@royans.net</description>
	<pubDate>Mon, 04 Aug 2008 15:55:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Self-signed SSL certificate warnings in Mozilla</title>
		<link>http://www.royans.net/rant/2008/08/04/self-signed-ssl-certificate-warnings-in-mozilla/</link>
		<comments>http://www.royans.net/rant/2008/08/04/self-signed-ssl-certificate-warnings-in-mozilla/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 15:51:33 +0000</pubDate>
		<dc:creator>royanswork</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2008/08/04/self-signed-ssl-certificate-warnings-in-mozilla/</guid>
		<description><![CDATA[Mozilla Firefox 3.0 throws a warning for self-signed certificate, and makes you do a couple of extra clicks to see the contents. Though some think its bad, I&#8217;m not sure what the fuss is all about. There are two reasons for the certificates. One is to encrypt the traffic, and the other to make sure [...]]]></description>
			<content:encoded><![CDATA[<p>Mozilla Firefox 3.0 throws a warning for self-signed certificate, and makes you do a couple of extra clicks to see the contents. Though <a href="http://tech.slashdot.org/tech/08/08/04/0058217.shtml">some think its bad</a>, I&#8217;m not sure what the fuss is all about. There are two reasons for the certificates. One is to encrypt the traffic, and the other to make sure no one intercepted your traffic using some kind of <a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack">man-in-the-middle attack</a>. One cant guarantee the second objective until a respected third party can sign/vouch the certificate. This is why these organizations exist. </p>
<p><a href="http://www.royans.net/rant/wp-content/uploads/2008/08/image.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="123" alt="image" src="http://www.royans.net/rant/wp-content/uploads/2008/08/image-thumb.png" width="244" align="left" border="0"></a>If this is such a big issue, the right approach should be for someone to setup a free certificate registry. There are few out there today like <a href="http://cert.startcom.org/">startcom</a>, but the browser support on such registries is currently unimpressive. </p>
<p>Speaking on behalf of the 99% of the Internet population who doesn&#8217;t understand the significance of SSL certificates, I think the decision Mozilla took is courageous and admirable, and other browsers should do something similar if they don&#8217;t already.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2008/08/04/self-signed-ssl-certificate-warnings-in-mozilla/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Webtrace.info - Traceroute on steroids</title>
		<link>http://www.royans.net/rant/2008/06/04/webtraceinfo-traceroute-on-steroids/</link>
		<comments>http://www.royans.net/rant/2008/06/04/webtraceinfo-traceroute-on-steroids/#comments</comments>
		<pubDate>Wed, 04 Jun 2008 13:54:36 +0000</pubDate>
		<dc:creator>royanswork</dc:creator>
		
		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2008/06/04/webtraceinfo-traceroute-on-steroids/</guid>
		<description><![CDATA[There are a lot of traceroute programs out there. This one called WinMTR was recently recommended by Akamai support during one of the troubleshooting sessions. Its based of another Linux tool called mtr (Matt&#8217;s traceroute) which is another one I had never heard off.
I liked it so much, that ended up making an enhanced web [...]]]></description>
			<content:encoded><![CDATA[<p>There are a lot of traceroute programs out there. This one called <a href="http://winmtr.sourceforge.net/">WinMTR</a> was recently recommended by Akamai support during one of the troubleshooting sessions. Its based of another Linux tool called mtr (Matt&#8217;s traceroute) which is another one I had never heard off.</p>
<p>I liked it so much, that ended up making an enhanced web interface to it. Check it out here at <a href="http://blogofy.blogsite.org/traceroute/www.techmeme.com">Webtrace.info</a>. </p>
<p><a href="http://blogofy.blogsite.org/traceroute/www.techmeme.com"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="149" alt="image" src="http://www.royans.net/rant/wp-content/uploads/2008/06/image.png" width="450" border="0" /></a></p>
<p>Webtrace provides extra networking information which is really helpful for folks who are trying to investigate networking issues. There are a lot of hyper links which allows them to quickly drill down into issues (like who is loosing packets). </p>
<div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:9e804ba3-0d6e-4dcc-9061-62bcbf7e6ae9" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/traceroute" rel="tag">traceroute</a>, <a href="http://technorati.com/tags/network" rel="tag">network</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2008/06/04/webtraceinfo-traceroute-on-steroids/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Custom search engine to search your OPML and Delicious bookmarks</title>
		<link>http://www.royans.net/rant/2007/09/16/custom-search-engine-to-search-your-opml-and-delicious-bookmarks/</link>
		<comments>http://www.royans.net/rant/2007/09/16/custom-search-engine-to-search-your-opml-and-delicious-bookmarks/#comments</comments>
		<pubDate>Sun, 16 Sep 2007 11:05:59 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/09/16/custom-search-engine-to-search-your-opml-and-delicious-bookmarks/</guid>
		<description><![CDATA[Zoppr is a Custom Search engine  which allows you to create custom Google search engine on the fly, by appending  your bookmark page, wikipage, or any other kind of page with lots of interesting bookmarks/links on it. Once setup, google will search  only across your bookmarks/links. For example this URL will help [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.zoppr.com/cse/">Zoppr</a> is a Custom Search engine  which allows you to create custom Google search engine on the fly, by appending  your bookmark page, wikipage, or any other kind of page with lots <a href="http://www.zoppr.com/cse/"><img align="right" src="http://farm2.static.flickr.com/1130/1391579772_b8bfc5b33c.jpg?v=0" /></a>of interesting bookmarks/links on it. Once setup, google will search  only across your bookmarks/links. For example this URL will help you search  across an OPML file published somewhere on the internet <a href="http://www.zoppr.com/cse/http://share.opml.org/">http://www.zoppr.com/cse/http://share.opml.org/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/09/16/custom-search-engine-to-search-your-opml-and-delicious-bookmarks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Scalable web architectures</title>
		<link>http://www.royans.net/rant/2007/09/15/scalable-web-architectures-2/</link>
		<comments>http://www.royans.net/rant/2007/09/15/scalable-web-architectures-2/#comments</comments>
		<pubDate>Sun, 16 Sep 2007 04:12:19 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[internet]]></category>

		<category><![CDATA[web20]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/09/15/scalable-web-architectures-2/</guid>
		<description><![CDATA[If you haven&#8217;t noticed already there is a second blog which I maintain which is currently more busy than this particular blog. &#8220;Scalable web architectures&#8221; is a collection of posts about how web architectures which scale and technologies which make it happen.
Here are some of the posts on that blog

Scaling Powerset using Amazonâ€™s EC2 and [...]]]></description>
			<content:encoded><![CDATA[<p>If you haven&#8217;t noticed already there is a second blog which I maintain which is currently more busy than this particular blog. &#8220;<a href="https://www.royans.net/arch/">Scalable web architectures</a>&#8221; is a collection of posts about how web architectures which scale and technologies which make it happen.</p>
<p>Here are some of the posts on that blog</p>
<ul>
<h4><a href="http://www.royans.net/arch/2007/09/13/scaling-powerset-using-amazons-ec2-and-s3/">Scaling Powerset using Amazonâ€™s EC2 and S3</a></h4>
<blockquote><p>Powerset could have gone the way most dot-com companies have gone, but instead they decided to try out Amazonâ€™s EC2 (Elastic Cloud Computing) and S3(Simple Storage Service) to augment their computational needs.</p></blockquote>
<h4><a href="http://www.royans.net/arch/2007/09/11/p2p-network-scalability/">P2P network scalability</a></h4>
<blockquote><p><a href="http://www.youtube.com">Youtube</a> is said to be <a href="http://willy.boerland.com/myblog/youtube_bandwidth_usage_25_petabytes_per_month">pushing about 25 petabytes per month</a> which is about 77 Gbps sustained data rate on an average. The bandwidth usage at the peaks would be even higher. Thanks to <a href="http://www.limelightnetworks.com/">Limelight networks</a>, Youtube doesnâ€™t really need to scale or provision for that kind of bandwidth and based on the <a href="http://blog.forret.com/2006/05/youtube-bandwidth-terabytes-per-day/">some reports from 2006</a> it had cost them close to 4 million a month back then. Youtube and services like that have to invest a lot in their infrastructure before they can really launch their service and though using shared Content delivery networks is not ideal, its probably not a bad deal. In Youtubeâ€™s case, it helped them survive until Google bought it out.</p></blockquote>
<h4><a href="http://www.royans.net/arch/2007/09/09/sharding-different-from-partitioning-and-federation/">Sharding: Different from Partitioning and Federation ?</a></h4>
</ul>
<ul>
<blockquote dir="ltr" style="margin-right: 0px"><p>Theo Schlossnagle, the author of â€œ<a href="http://astore.amazon.com/royansnet02/detail/067232699X/104-4476874-8763135">Scalable internet architecutres</a>â€ argues that federation is form of partitioning, and that sharding is nothing but a form of <a href="http://en.wikipedia.org/wiki/Partition_%28database%29">partitioning</a> and <a href="http://www.ibm.com/developerworks/db2/library/techarticle/0304lurie/0304lurie.html">federation.</a> Infact, according to him, <a href="http://www.lethargy.org/%7Ejesus/authors/1-Theo-Schlossnagle">Sharding has already been in use use for a long time</a>.</p></blockquote>
<h4><a href="http://www.royans.net/arch/2007/09/07/adventures-of-scaling-einsde/">Adventures of scaling eins.de</a></h4>
</ul>
<ul>
<blockquote dir="ltr" style="margin-right: 0px"><p>Eins.de site serves about 1.2 million dynamic pages a day. He wrote a series of articles describing how they redesigned the site to scale for growth. I found these articles very informative with a extreemly mature discussion of the colorful world of scalability.</p></blockquote>
<h4><a href="http://www.royans.net/arch/2007/09/02/session-state-and-scalability/">Session, state and scalability</a></h4>
</ul>
<ul>
<blockquote dir="ltr" style="margin-right: 0px"><p>If I could only give one recommendation to anyone building a brand new web application, Iâ€™d say â€œ<a href="http://www.wikipedia.org/wiki/Stateless_server">go stateless</a>â€œ. But going stateless is not the same as going session-less. One could implement a perfectly stateless web architecture which still uses sessions to authenticate, authorize and track user activity. And to complicate matters further, when I say stateless, I really mean that the server should be stateless, not the client.</p></blockquote>
<h4><a href="http://www.royans.net/arch/2007/08/28/loadbalancer-for-horizontal-web-scaling-what-questions-to-ask-before-implementing-one/">Loadbalancer for horizontal web scaling: What questions to ask before implementing one.</a></h4>
</ul>
<ul>
<blockquote dir="ltr" style="margin-right: 0px"><p>Loadbalancers, by definition, are supposed to solve performance bottlenecks by distributing or balancing load between different components its managing. Though you would normally find loadbalancers in front of a webserver, a lot of different individuals have found other interesting ways of using it.</p></blockquote>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/09/15/scalable-web-architectures-2/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Feature or a bug ?</title>
		<link>http://www.royans.net/rant/2007/08/26/feature-or-a-bug/</link>
		<comments>http://www.royans.net/rant/2007/08/26/feature-or-a-bug/#comments</comments>
		<pubDate>Sun, 26 Aug 2007 08:39:10 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/08/26/feature-or-a-bug/</guid>
		<description><![CDATA[Dratz asks: Feature or a bug ?

]]></description>
			<content:encoded><![CDATA[<p>Dratz <a href="http://www.flickr.com/photos/dratz/1045336659/">asks</a>: Feature or a bug ?</p>
<p><img src="http://www.royans.net/files/featureorbug.jpg" style="" title="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/08/26/feature-or-a-bug/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Web storage for backups</title>
		<link>http://www.royans.net/rant/2007/08/20/web-storage-for-backups/</link>
		<comments>http://www.royans.net/rant/2007/08/20/web-storage-for-backups/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 04:47:13 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/08/20/web-storage-for-backups/</guid>
		<description><![CDATA[
I&#8217;m contemplating using S3 for backups. Paul Stamantiou has a script ready to go. The thing which convinced me was this chart Paul showed. For 10GB of space he paid under 3 dollars per month. Thats really cheap&#8230;
GMail, Microsoft and yahoo all provide extra storage as well. However none of them have stable company supported [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://paulstamatiou.com/wp-content/uploads/2007/07/amazons3_bill.jpg" align="right" /></p>
<p>I&#8217;m contemplating using S3 for backups. <a href="http://paulstamatiou.com/2007/07/29/how-to-bulletproof-server-backups-with-amazon-s3/">Paul Stamantiou</a> has a script ready to go. The thing which convinced me was this chart Paul showed. For 10GB of space he paid under 3 dollars per month. Thats really cheap&#8230;</p>
<p>GMail, Microsoft and yahoo all provide extra storage as well. However none of them have stable company supported APIs to allow users to upload data in this form.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/08/20/web-storage-for-backups/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Getting ready for Social Network portability</title>
		<link>http://www.royans.net/rant/2007/08/18/getting-ready-for-social-network-portability/</link>
		<comments>http://www.royans.net/rant/2007/08/18/getting-ready-for-social-network-portability/#comments</comments>
		<pubDate>Sun, 19 Aug 2007 03:25:31 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/08/18/getting-ready-for-social-network-portability/</guid>
		<description><![CDATA[
Brad Fitzpatrick and  David Recordon, kicked off another round of discussions on aggregating, decentralizing and Social network portability in a post called &#8220;Thoughts on the Social Graph&#8220;. The post is long, but he summarized the problem statement into a few lines..

Users and developers alike are going crazy. There&#8217;s too many social networks out there [...]]]></description>
			<content:encoded><![CDATA[<ul>
<li>Brad Fitzpatrick and  David Recordon, kicked off another round of discussions on aggregating, decentralizing and Social network portability in a post called &#8220;<a href="http://bradfitz.com/social-graph-problem/">Thoughts on the Social Graph</a>&#8220;. The post is long, but he summarized the problem statement into a few lines..</li>
</ul>
<blockquote><p>Users and developers alike are going crazy. There&#8217;s too many social networks out there to keep track of. Developers want to make more, and users want to join more, but it&#8217;s all too much work to re-enter your friends and data. We need to lower the amount of pain for both users and developers and let a thousand new social applications bloom.</p></blockquote>
<p>I&#8217;ve <a href="http://www.royans.net/rant/2007/07/23/aggregation-consolidation-and-information-summarization/">mentioned this problem </a>in the past as well and feel like this is long overdue. Sites like <a href="http://www.plaxo.com">Plaxo </a>and <a href="http://www.facebook.com">Facebook </a>have taken a step in the right direction, but its not the solution. As I see it the real solution should be something similar to the <a href="http://www.xmpp.org/">XMPP </a>standard which opened up the chat protocol to allow decentralized chat networks work with <a href="http://www.google.com/talk/otherclients.html">each</a> <a href="http://www.jabber.org/">other</a>.</p>
<p>Also read</p>
<ul>
<li><a href="http://www.feld.com/blog/archives/2007/08/social_graph_th.html">Feld Thoughts<br />
</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/08/18/getting-ready-for-social-network-portability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Microsoft Live ID out : Google going to support OpenID soon&#8230;  I predict</title>
		<link>http://www.royans.net/rant/2007/08/17/microsoft-live-id-out-google-going-to-support-openid-soon-i-predict/</link>
		<comments>http://www.royans.net/rant/2007/08/17/microsoft-live-id-out-google-going-to-support-openid-soon-i-predict/#comments</comments>
		<pubDate>Fri, 17 Aug 2007 07:24:40 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[internet]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[web20]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/08/17/microsoft-live-id-out-google-going-to-support-openid-soon-i-predict/</guid>
		<description><![CDATA[The other day I briefly mentioned the pain point of the web2.0 world and how consolidation, aggregation and summarization will help reduce some of it.  Microsoft today formally announced the availability of Microsoft Live ID as a contender for the providing SSO (single sign on) services in the web 2.0 world. Live ID, incase [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.royans.net/rant/2007/07/23/aggregation-consolidation-and-information-summarization/">other day I briefly mentioned</a> the pain point of the web2.0 world and how consolidation, aggregation and summarization will help reduce some of it. <a href="http://dev.live.com/liveid/"><img border="0" align="right" src="http://dev.live.com/img/id_banner.jpg" /></a> Microsoft today <a href="http://www.liveside.net/blogs/developer/archive/2007/08/16/windows-live-id-web-authentication-is-final.aspx">formally announced the availability of Microsoft Live ID</a> as a contender for the providing SSO (single sign on) services in the web 2.0 world. Live ID, incase you didnt know,Â  is the repackaged version of <a href="http://en.wikipedia.org/wiki/Windows_Live_ID">Microsoft Passport Network</a>, which had <a href="http://news.zdnet.co.uk/security/0,1000000189,39184873,00.htm">failed so badly</a> that it forced Microsoft to pull it out of the market. Here are <a href="http://msdn2.microsoft.com/en-us/library/bb676635.aspx">some examples</a> of how to use other languages like php, perl, python, ruby etc to do authentication using Live ID. Microsoft is not the first one to openly come out with a SSO technology. <a href="http://en.wikipedia.org/wiki/Liberty_Alliance">Liberty Alliance</a> and <a href="http://openid.net/">OpenID</a> are other opensource competitors which <a href="http://openiddirectory.com/">have some foothold</a> in this market already.</p>
<p>The move to SSO, in the web 2.0 world, (Single sign on) is bound to happen regardless of how scary some people might find it to be. If you can trust your online bank with 100000 dollars and trust 3 companies you don&#8217;t really know with your entire credit history, then this shouldn&#8217;t be that much of a concern. The real question is whether you trust the technology leaders Microsoft, Google, YahooÂ  or others like Verisign enough to provide these critical services for you.</p>
<p>In my opinion the reason why OpenID and Liberty Alliance have failed is because of fragmentation of standards and lack of leadership. While Microsoft failed the commercial venture into Authentication services (Microsoft Passport network) it might actually do well as long as it doesn&#8217;t screw up this time. Not because the they have done a great job in the past, but because the pain is now so unbearable that people are willing to give almost anything a try. But the real kicker is that almost everyone has a microsoft account anyway, so if I had an option to use my Microsoft account to login to a new web 2.0 product, I&#8217;ll do that in a heart beat. Creating yet another account with a new password and doing the email confirmation thing is not an adventure anymore&#8230; ( or may be I&#8217;m getting old ).</p>
<p>I predict that Google or Yahoo will soon jump into this with its own suite of authentication services (probably using OpenID or Liberty Alliance)  which will then become the next battleground in the web2.0 world. I also predict that in a couple of years after that many of the web services will move towards supporting these forms of authentication services so that users are not forced to create new user accounts with new passwords every single time.</p>
<p>And if my predictions don&#8217;t really come true&#8230; hey, at least I know that I can dream.</p>
<p>References</p>
<ul>
<li><a href="http://www.readwriteweb.com/archives/openid_vs_bigco.php">OpenID and Identity Systems of Yahoo , Google and MSN</a></li>
<li><a href="http://blog.javia.org/?p=44">Google OpenID</a></li>
<li><a href="http://video.google.com/videoplay?docid=-7463164786703060643">How to use OpenID</a></li>
<li><a href="http://openiddirectory.com/">OpenID enabled Sites</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/08/17/microsoft-live-id-out-google-going-to-support-openid-soon-i-predict/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DNS Rebinding what ?</title>
		<link>http://www.royans.net/rant/2007/08/13/dns-rebinding-what/</link>
		<comments>http://www.royans.net/rant/2007/08/13/dns-rebinding-what/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 04:40:32 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/08/13/dns-rebinding-what/</guid>
		<description><![CDATA[Everyone who knows what a &#8220;DNS Rebinding attack&#8221; is please raise your hands. I&#8217;m so glad I can&#8217;t see yours, because I&#8217;m ashamed of myself for not knowing this one. For those who are &#8220;pretending&#8221; not to know please read on.
Browsers use domain names to enforce same-domain policy for a lot of security features. Interestingly [...]]]></description>
			<content:encoded><![CDATA[<p>Everyone who knows what a &#8220;DNS Rebinding attack&#8221; is please raise your hands. I&#8217;m so glad I can&#8217;t see yours, because I&#8217;m ashamed of myself for not knowing this one. For those who are &#8220;pretending&#8221; not to know please read on.<br />
Browsers use domain names to enforce same-domain policy for a lot of security features. Interestingly depending on which client you are using its possible to set a low DNS TTL and change the IP address such that without a change in domain name a script could interact with another website as long as browser can be made to believe that its still the same domain. To do this, all that the client needs to do is initially server contents from its own server and while the javascript is running, update the DNS such that the javascript can interact with a new domain from where it could steel information for the attacker.</p>
<p>There are some safe gaurds to stop these kinds of attacks, but for most part these kinds of attack can be done easily on the internet today. The browsers are getting smarter though. And the &#8220;DNS Rebinding attack&#8221; isn&#8217;t new anyway&#8230; its been known for years at least. The way browsers try to defeat this is by limiting the minimum DNS TTL which can be set.</p>
<p>All was well and good until an attacker realized that the browser and plugins inside the browser each have different minimum DNS TTL set. So as long as the browser and plugin can talk to each other, there could be a point in time when the plugin could be talking to the attackers server and the browser could be connected to the real server streaming the information to the attacker through the plugin.<br />
References</p>
<ol>
<li><a href="http://crypto.stanford.edu/dns/dns-rebinding.pdf">Protecting browsers from rebinding attacks</a></li>
<li><a href="http://www.doxpara.com/?q=node/1154">XSRF^2</a></li>
<li><a href="http://www.dslreports.com/forum/r18803772-AntiDNS-pinning-DNSrebinding-attacks">Anti-DNS pinning and DNS-rebinding attacks</a></li>
<li><a href="http://www.circleid.com/posts/070809_defending_networks_dns_rebinding_attacks/">Defending network against DNS Reminding attacks</a></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/08/13/dns-rebinding-what/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Facebook code leaked.. but was it Hacked too ?</title>
		<link>http://www.royans.net/rant/2007/08/11/facebook-code-leaked-but-was-it-hacked-too/</link>
		<comments>http://www.royans.net/rant/2007/08/11/facebook-code-leaked-but-was-it-hacked-too/#comments</comments>
		<pubDate>Sun, 12 Aug 2007 05:26:28 +0000</pubDate>
		<dc:creator>royans</dc:creator>
		
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://www.royans.net/rant/2007/08/11/facebook-code-leaked-but-was-it-hacked-too/</guid>
		<description><![CDATA[ Everyone would be talking about this soon. Someone leaked the source of the index page of facebook on a website called facebook secrets.
Update: Brandee Barker from Facebook responded to Nic on Techcrunch.
Hi Nic-
I wanted to clarify a few things in your story. Some of Facebookâ€™s source code was exposed to a small number of [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" src="http://static.ak.facebook.com/images/welcome/welcome_3.gif" /> Everyone would be talking about this soon. Someone leaked the source of the index page of <a href="http://www.facebook.com/">facebook</a> on a website called <a href="http://facebooksecrets.blogspot.com/">facebook secrets</a>.</p>
<p>Update: Brandee Barker from Facebook responded to Nic on Techcrunch.</p>
<blockquote><p>Hi Nic-</p>
<p>I wanted to clarify a few things in your story. Some of Facebookâ€™s source code was exposed to a small number of users due to a bug on a single server that was misconfigured and then fixed immediately. It was not a security breach and did not compromise user data in any way. The reprinting of this code violates several laws and we ask that people not distribute it further.</p>
<p>Thanks to you and the TC readers for helping us out on this one.</p>
<p>Brandee Barker<br />
Facebook</p></blockquote>
<p><strike>What is not clear is whether this was a hack or was someone inside involved.</strike> This is what <a href="http://www.techcrunch.com/2007/08/11/facebook-source-code-leaked/">Nik Cubrilovic</a> from TechCrunch has to say&#8230;</p>
<blockquote><p>&#8220;There are a number of clear ramifications here. The first is that the code can be used by outsiders to better understand how the Facebook application works, for the purposes of finding further security holes or bugs that could be exploited. Since Facebook is a closed source application, without access to the code security holes are usually found through a process of black-box testing, whereby an external party will probe the application in an attempt to work out how the application behaves and to try and find potential race conditions. In closed source applications it is common that developers rely on the closed nature of the application to obfuscate poor design elements and the structure of the application. An attacker getting access to the source code more often than not leads to further security holes being discovered. It is for these reasons that it is often claimed that open source software is more secure than closed source software, since there are many more eyes auditing the code and obfuscation canâ€™t be used as a security measure.</p>
<p>The second implication with this leak is that the source code reveals a lot about the structure of the application, and the practices that Facebook developers follow. From just this single page of source code a lot can be said and extrapolated about the rest of the Facebook application and platform. For instance, the structure doesnâ€™t follow any object oriented development practices, and it seems that the application is one large PHP file with a large number of custom functions living in the same namespace (they also seem to be using the Smarty templating engine).  &#8220;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.royans.net/rant/2007/08/11/facebook-code-leaked-but-was-it-hacked-too/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
