how not to get your myspaced hacked

2 January 2008

This is a public service announcement. Jan 2, 2008

one of your friends appears to send you a stupid thing to post as a comment. you know its spam, because your friends would never post anything that stupid.

when you get the request to post the comment and myspace asks you to deny/approve, deny it. then

then when you are on the SECOND screen when myspace asks you to confirm , hover the mouse over the deny/submit area and if it says a URL in your status bar at the bottom, then DON'T CLICK. just leave it.

the comment is already denied. myspace shouldn't be asking us twice anyway.

the spammers hide a link on top of that (the CSS extends the click area of the image) so that when you click on it some javascript gets executed and injects a message into myspace as though it were you. and it then sends that to all of us. its something like that, some cross site scripting attack. fascinating if you are into web tools, but ...

oh, and grow up and stop using myspace. that's just for kids and musicians.


  1. 1 Web developer says...

    That was inspiring,

    it's not good to say but I like their Idea, truely some of these hackers a not only ginious but have a sence of humor as well

    Keep up the good work

  • more posts in tech notes
    • django.db.utils.DatabaseError: relation "django_content_type" does not exist

      p.p1 {margin: 0.0px 0.0px 0.0px 0.0px; font: 11.0px Monaco} I was getting an error while running unit tests and the test database was failing to be created.django.db.utils.DatabaseError: relation "django_content_type" does not existeventually found the problem.  I had the following in a file that was imported to a models.py:hrd_type = ContentType.objects.get_for_model(HttpReferrerDomain)The idea being that it can just set the var when it loads up and after that its always there.  But this means for creating a fresh database, the db is ...

    • django has two classes called ValidationError

      There is one in django.core.exceptions and one in django.forms.util Using that space age IDE Eclipse I have to say I'm enjoying how much time I've saved just going shift-command-O to organize and resolve all of my imports.  But today I've just lost a few hours due to my ok-ing the wrong class. Quite mysterious it was, I raised a ValidationError (core exceptions one) in my form's clean() and watched as the try: except ValidationError: in django's full_clean() completely ignored my ...

    • GDAL fails to build: `.rodata' can not be used when making a shared object; recompile with -fPIC

        libtool: link: g++ -shared -nostdlib /usr/lib/gcc/x86_64-linux-gnu/4.4.1/../../../../lib/crti.o /usr/lib/gcc/x86_64-linux-gnu/4.4.1/crtbeginS.o .libs/libgdal.la.lnkscript  -L/usr/local/lib /usr/local/lib/libgeos_c.so /usr/local/lib/libgeos.so /usr/local/lib/libexpat.so -L/usr/lib -lpq -lrt -ldl /usr/lib/libcurl.so -lssl -lcrypto -lz -L/usr/lib/gcc/x86_64-linux-gnu/4.4.1 -L/usr/lib/gcc/x86_64-linux-gnu/4.4.1/../../../../lib -L/lib/../lib -L/usr/lib/../lib -L/usr/lib/gcc/x86_64-linux-gnu/4.4.1/../../.. -lstdc++ -lm -lc -lgcc_s /usr/lib/gcc/x86_64-linux-gnu/4.4.1/crtendS.o /usr/lib/gcc/x86_64-linux-gnu/4.4.1/../../../../lib/crtn.o         -Wl,-soname -Wl,libgdal.so.1 -o .libs/libgdal.so.1.13.2 /usr/bin/ld: /usr/local/lib/libz.a(crc32.o): relocation R_X86_64_32 against `.rodata' can not be used when making a shared object; recompile with -fPIC /usr/local/lib/libz.a: could not read symbols: Bad value collect2: ld returned 1 exit status make[1]: *** [libgdal.la] Error 1 make[1]: Leaving directory `/home/crucial/tmp/gdal-1.6.2' ...

    • installing MySQLdb on Ubuntu (mysql-python)

      MySQLdb is the python support bindings for MySQL.  Not that the name would lead you to beleive that. Its sourceforge page calls it http://sourceforge.net/projects/mysql-python/ which makes more sense. you need setuptools, which you usually already have:     sudo aptitude install python-setuptools You need MySQL-devel to compile, but its not called that, its called: libmysql++-dev on Ubuntu     sudo apt-get install libmysql++-dev download MySQLdb itself from:     http://sourceforge.net/projects/mysql-python/     # the version you download will be more recent     tar xfz ...

    • Full index for tech notes
  • more posts in currently
    • Maga Bo - Ransom EP

      p.p1 {margin: 0.0px 0.0px 10.0px 0.0px; line-height: 34.0px; font: 14.0px Arial; color: #3e3e3e} p.p2 {margin: 0.0px 0.0px 0.0px 0.0px; line-height: 21.0px; font: 14.0px Arial; color: #3e3e3e; min-height: 16.0px} p.p3 {margin: 0.0px 0.0px 10.0px 0.0px; line-height: 34.0px; font: 34.0px Arial; color: #141414} p.p4 {margin: 0.0px 0.0px 0.0px 0.0px; line-height: 21.0px; font: 14.0px Arial; color: #3e3e3e} span.s1 {font: 14.0px Lucida Grande} span.s2 {font: 12.0px Arial} RansomRansom (Pacheko Remix) Ransom (Filastine Remix) Ransom (Teleseen Remix) Ransom (Fletcher Remix) Ransom (Timeblind Remix) Gondar   ...

    • hmmmmmmm...

      its cold up here. and dark

    • Kid Kameleon in the loop

      The very ungrumpy Kid Kameleon just dropped his loops mix built entirely from loops from the likes of us:Asura, BD1982, Beatbully, Black Chow, Bop, Boreta, Coco Bryce, Disrupt, DJ G, Downliners Sekt, Dr. Strangeloops, Ganucheau, Geiom, Ghislain Poirier, Girl Unit, Hatti Vatti, Hungry Ghost, Illyah & Ltd. Candy, Indigo, LV, Michna, Mono/Poly, Mr. Gasparov, NastyNasty, Om Unit, Pacheko, Paul White, Phosho, Rekordah, Robot Koch, Rx, Schlachthofbronx, Self Evident, Sines, Skyence, Sub Swara, Taylor, Teleseen, Timeblind, Tinker, Untold, Uproot Andycop it ...

    • pirates need to keep it on the D/L

      Soundcloud started issuing takedown notices to people posting unauthoried remixes and mixtapes.A few thoughts in response to the Ripley's post:http://djripley.blogspot.com/2010/12/walling-off-another-garden-is.htmlhave you all chosen and publicly displayed a CC license ?  http://creativecommons.org/choose/I need to do that too.If it was widespread then all artists would have this, it could be easily checked to ensure a mix is free to go.  Only artists on restrictive labels would get flagged.  Mixcloud could scan and ok the mix automatically.  All artists should have URLs where ...

    • Full index for currently
Backwardation : Version 12"
coltan and cassiterite Timeblind : Solar Life Raft Ingredients