Join the DCS Blog Network! (Tara Na, CS Tayo!)

January 20, 2007 · 1 comment

DCS Blog Network

The DCS Blog Network has officially launched! Here’s a snippet of the hear ye! hear ye! we distributed last night:

Calling all members of the UP Diliman Department of Computer Science community: students, alumni, and faculty alike! You are cordially invited to join the DCS Blog Network, a site that brings together all blogs from its DCS members. The purpose of the DCS Blog Network is to bring together everyone who is, has, and will be part of the Department, and what better way to do that than through the Internet?

You can read the full details at Sir Feria’s blog. He suggested we (Phillip, Sir Rom, and I) set this up in preparation for the Alumni Homecoming.

Continue reading

The Z-List Meme

January 18, 2007 · 8 comments

Z-List Blogger

Rather than passing around surveys and quizzes, electronic chain letters and wishmakers that are all self-centered and petty, I found a great meme that will benefit those who deserve it. And it’s up to you to decide who gets the hat tip(s). The Viral Garden calls it the Revenge of the Z-Lister.

It’s some sort of a whine against how the A-listers (are you one?) are getting all the link love. Time to turn the tables on them. This is The Long Tail at work here, people! Rather than have a select few pick what they think is good, how about we do the picking? It was our year, after all; now, more than ever, do we have the greatest freedom to decide.

Continue reading

Friends + Fireworks

January 14, 2007 · 5 comments

Friends + Fireworks

This is my attempt at a personal entry for reasons you shall soon find out. Alas, I failed.

Aimee, one of four high school friends I finally met after four long years at the SM Mall of Asia last Friday, asked me why I didn’t like to use LiveJournal and why I didn’t write about personal things there, or anywhere else.

The first question is easy. Here’s a partial answer. The second, on the other hand, led me to this writing this. It practically implied that whether or not she had visited Stellify (I plastered announcements all over the place that I was not there but here), this whole website wasn’t enough! It also made it clear to me that many people don’t understand non-diary style blogging, and that an LJ account was not just another blogging service but obviously a journal service.

Continue reading

Another Reason Apple iPhone Will Suck—For Filipinos

January 12, 2007 · 21 comments

Apple fans the world over are probably having parties to celebrate the announcement of the Apple iPhone (not the Cisco one). The status messages of my buddies on Yahoo! Messenger are babbling about doing anything they can to get their paws on one (even if it takes a lap dance, one of them said!).

But I’ve already read several shortcomings of the iPhone as well as counterarguments to those. And I’ve noticed another reason why, specifically for Filipinos.

It’s very simple, really.

Continue reading

Selling Out and Dumb Wi-Fi: Build Social Networks to Revolt, But Is That Enough?

January 10, 2007 · 7 comments

Smart Bro/Smart Wi-Fi logo. Hideous.

Interesting anecdote about a social network built as leverage against an almighty company before the term “social network” was even coined. Short story is that the company crashed, the stocks were no good, and the shareholders were outraged. So Ronald Lewis and his friends turned to the Internet and built XOShareholders.com, bringing together over 23 million worth of shares from 2,700 shareholders. More importantly, the news of this injustice spread even to the media. This was in 2001, way before the Web 2.0 and one of its favorite buzzwords, social networking, were born.

Change gears—to the Philippines. One must ask, has anybody done something like that in this country?

Continue reading

The UP Department of Computer Science Holds Its First Alumni Homecoming

January 8, 2007 · 2 comments

The CS Firefox Coat of Arms

Twenty-six years since its creation, the UP Diliman Department of Computer Science (DCS) is finally holding an alumni homecoming on the 24th of February 2007 at its new home, the College of Engineering Library and Computer Science Building. (FYI, that building is right in front of National Institute of Geological Sciences (NIGS) and the College of Science Library and Administration building.) Registration starts at 3, while the program will begin at 4pm.

You can read the invitation letter from Prof. Evangel Quiwa that’s been passed around to the alumni in Sir Rom’s blog. Actually, there are two more versions of the invitation letter: one reiterated by the Department Chair, Dr. Cedric Festin, and another detailing of a very special surprise for the Department’s most-loved teacher—guess who! (I’ve already mentioned him here!)

Continue reading

WordPress XSS vulnerability in templates.php

January 3, 2007 · 6 comments

WordPress

An important heads-up to all WordPress fans—that’s pretty much the whole blogosphere*, isn’t it? There’s been a recently-discovered security flaw with the blog software’s templates.php file. It’s called XSS, i.e. cross-site scripting, a vulnerability that permits malicious code injection into web pages.

David Kierznowski explains what part of the WP file is causing this:

When editing files a shortcut is created titled “recently accessed files”. The anchor tag text is correctly escaped with wp_specialchars(); however, the link title is not sanitised. Instead, it is passed to get_file_description($file). The only restriction or limitation here is that our text is passed through basename. This means standard script tags will fail when ending with “˜/”. We can get around this by using “open” IMG tags; this works under FF and IE.

In pseudo-English, that would mean:

WordPress is prone to a HTML-injection scripting vulnerability because the application fails to properly sanitize user-supplied input.

Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

TechBuzz lists all WordPress versions that are in danger of this exploit, but the short story is unless you’re using 2.0.6 you’re not safe. And as far as I know that one hasn’t been released officially yet. It’s advised you patch the culprit file in the meantime. (Make sure to back those files up first!) WP 2.0.6 has just been released yesterday. You might want to upgrade instead of patching.


* It’s so popular, in fact, that sneaky people are making money off of hinting at how you can use it to make your money. They obviously haven’t head of WP’s support community.

Update: It’s templates.php, with an s. oKs this!

What, No Holiday Post?

January 2, 2007 · 7 comments

A Neighbor's Fireworks

Still, a belated Merry Christmas and Happy New Year to y’all!

I seem to have been too distracted by other things to come up with a post for this blog. I do have some things in mind but they’re too short for full length posts, so I stared at my blog for several days and pondered on whether to install some sort of asides (side-blogging) feature. Obviously, I haven’t (I tweaked and added other features anyway). So I shall resort to what I usually do, and that is unload a bunch of disjointed topics in one go.

Continue reading

Technology & Computers - Top Blogs Philippines