Security

共 294 篇文章。

blog heavily spammed

Blogging

So I am now target of blog spamming. I’m ready to fight back.

More blobs would be closed before they get spammed.

More IPs would be blocked because they spam.

I will utilize anti-spam techniques that I am using in my mail system to defeat blog spamming.

I will set up some blacklist for URLs that appears in my friends’ blogs.

Spam sucks, don’t spam, and I _WILL_ fight back.

参与评论

有点难过

Diary Excerpt

多大个事儿啊?我对自己说。

有点难受,想一个人冷静地呆一会。想起了今天看的书,错只是在我自己,一个搞安全这么多年的人,居然忘记了最基本的道理。

有些时候,人们要为别人的愚蠢付出巨大的代价。我不想用愚蠢这个词,但是,我想不出更好的词。这不是第一次,也许也不是最后一次。而原因,一直以来都是完全一样的原因。

阅读全文… ( 本文约 447 字,阅读大致需要 1 分钟 )

Fighting against spamming

Security

It seems that my blog get spammed by various parties. I hereby declare a war against spamming, also for e-mails.

You’re being watched and identified from this point on. Once you spam my blog, I guarantee that your activations are being tracked and analyzed with my knowledge base system and finally I will be able to keep everything from you off my site.

参与评论

不按RFC走?那你必然会遇到麻烦

Security

RFC也许有时让人觉得过分冗长,但是如果你没有耐心去完全实现它,它就会在不经意间突然咬你一口。

可怜的端木就被咬了……

今天这家伙发了一封邮件给我。

嗯?3.5分?

阅读全文… ( 本文约 273 字,阅读大致需要 1 分钟 )

为什么我反对从头编写操作系统的个人努力(1)

Development

此文章版权归 李鑫 所有。版权声明如下:

版权所有 © 2004 李鑫,保留所有权利。转载必须完整地复制这些文字,不允许修改,并附上其原始连接:


我在许多场合公开地发表过类似的意见,有时言辞比较激烈,有时只是委婉地反对。

这种意见,同意也好,不同意也好,我希望其他人能够把它当作一种意见,而不是某种强加于人的意志。我只是说出自己的看法,并不要求任何人接受——如果他们认为这是对的,愿意接受,我当然很高兴;但如果他们觉得我说的有道理而不愿意接受,那是他们的问题;如果他们觉得我说的没道理,我很希望看到反驳的意见。我始终相信,真理越辩越明。

其实,最关键的问题就在于,我们没有必要重新发明轮子。在阐述这个观点之前,我希望大家能够接受一个密码学界的常识,即安全不能建立在别人不知道的基础上。另一个常识是,安全总是从最薄弱的环节被突破的,不要去尝试解决最强点上的问题——因为那不解决问题。

阅读全文… ( 本文约 1674 字,阅读大致需要 4 分钟 )

Solving issue appeared after Windows XP SP2

Security

Windows XP SP2 is an important update and have introduced many security improvements. However, after installing Windows XP SP2, some graphical identity systems will be rendered to be useless.

The root cause is that these systems makes use of a special MIME type: x-xbitmap, or so called “XBM”.

XBM is originally developed by the X community. Presently it is uncommon on the web. However, banks like China Merchant Bank utilizies this format for authentication.

阅读全文… ( 本文约 130 字,阅读大致需要 1 分钟 )