Flosse’s IT corner

Why Corporates Hate Perl

August 20, 2008 1:36 am

Anti-Globalism recommends a posting up at O’Reilly’s ONLamp on reasons that some companies are turning away from Perl. “[In one company] [m]anagement have started to refer to Perl-based systems as ‘legacy’ and to generally disparage it. This attitude has seeped through to non-technical business users who have started to worry if developers mention a system that is written in Perl. Business users, of course, don’t want nasty old, broken Perl code. They want the shiny new technologies. I don’t deny at all that this company (like many others) has a large amount of badly written and hard-to-maintain Perl code. But I maintain that this isn’t directly due to the code being written in Perl. Its because the Perl code has developed piecemeal over the last ten or so years in an environment where there was no design authority.. Many of these systems date back to this company’s first steps onto the Internet and were made by separate departments who had no interaction with each other. Its not really a surprise that the systems don’t interact well and a lot of the code is hard to maintain.”

Read more of this story at Slashdot.

Adobe Flash Ads Launching Clipboard Hijack Attacks

1:36 am

bullyBEEF writes “Malicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks. In the Web attacks, which affect Mac, Windows, and Linux users running Firefox, IE, and Safari, bad guys are seizing control of the machine’s clipboard (probably using the Flash command setClipboard) and inserting a hard-to-delete URL that points to a fake anti-virus program. A number of legitimate sites have been seen to host acs carrying the attack — including Newsweek, Digg, and MSNBC.com. Researcher Aviv Raff offers a harmless demo of how it’s done.”

Read more of this story at Slashdot.

Why One-time Passwords Suck For MITM Attacks

August 18, 2008 8:33 pm

whitehartstag writes “Black Hat 08 disclosed several SSL VPN and DNS vulnerabilities that caused several people to sit up and take notice. Some of these new exploits performed a brilliant Man-In-The-Middle attack on SSL VPN tunnels. This article walks you through how using certificates, instead of OTP tokens for second-factor authentication can increase the security of your SSL VPN against these new types of attacks.”

Read more of this story at Slashdot.

Photographing Nature

3:02 pm

It’s hard to find the right spot to photograph nature and a lot of time you will end up looking where there is nothing to be found… Meaning you think it looks good, yet the images do not tell anything to the viewer.

This past weekend I walked through a forest and a large part of the path through the forest was laid with boards.

The reason was that the area was a hidden swamp. I dodn’t notice at first but then lush moss covered little mounds came into view with water all around.

The trick is not wanting to find something to photograph but to let it come to you.

I put the images up on a small gallery called swamp here .

I would love some comments on them. Some of the shots looks like a fairy world. or totally forgotten wild. considering that less then a kilometer away a city center is of a town with 40000+ people is hard to believe.