» tagged pages
» logout

sorted by: recent | see : popular
Content Tagged with Kellan-Elliot-Mcrea + Security

DoS vulnerability in REXML

That *any* parser could still be vulnerable to million laughs attack 8 years after being identified highlights how terrible REXML is. And how desperately Ruby needs a decent XML parser.

Kellan-Elliot-Mcrea: del.icio.us/kellan

Flickr: Beehive Launches without Phishing

Overview of relationships between groups, removing highly redundant groups

Congrats to waferbaby, mroth, and ph for totally owning on today’s friend importing feature (aka beehive).

We’re a little late to the game but its awfully nice to be able to launch with zero screenscraping, and zero phishing-creepy-give-us-your-password. This is what data-portability-open-data-delegated-trust future looks like.

update: and yes, we’re cheating, because Yahoo’s addressbook API is still internal+partners only. We’re working on it.

Kellan-Elliot-Mcrea: Laughing Meme

How to calculate a Base64 encoded HMAC-SHA1 in PHP for OAuth

How to calculate a Base64 encoded HMAC-SHA1 in PHP for OAuth.

HMAC-SHA1 is the suggested default signing algorithm for OAuth 1.0 Core. This is a code snippet showing how to calculate a valid OAuth HMAC-SHA1 signature using PHP4 without any PEAR dependencies.

Kellan-Elliot-Mcrea: Laughing Meme

Facebook Application Smashing

Facebook Application Smashing.

Blog chronicling the new field of exploiting 3rd party FB apps security vulnerabilities. (via aaron)

Kellan-Elliot-Mcrea: Laughing Meme