HNHacker News
TopNewBestAskShowJobs

ddbb

213 karma · joined May 7, 2009

submissionscomments
ddbb··on ASK HN: Review our new product: WordPress Module: Security, Auditing and Backup
Much needed for WP :) But I am biased, since I helped with this work...
ddbb··on GPL and the Wordpress x Thesis theme issue (Why Chris is right)
To summarize:

Thesis integrates with Wordpress, it is not derivative from it. Same way Linux modules integrate with the Linux kernel (and many of them are closed source).

If someone is using a public/open API, and not distributing any part of the software, it means they are not based on the other.

ddbb··on Automattic caught A/B testing pricing for Vaultpress
http://sucuri.net is a good one :) (by fellow HN members)
ddbb··on Honeypot analysis - Looking closer at SSH scans (user and passwords used)
You know, lots of people talk about using keys instead of passwords... By doing that if you box is compromised, the attacker will get access to ALL your boxes.

So, the best option is to use an encrypted ssh key (so you have the type the pass everytime) or a good/different password for every box.

ddbb··on PHP functions you (probably) never use
Make sense... I was just looking at the bottom and couldn't find your answer :)
ddbb··on Honeypot analysis - Looking closer at SSH scans (user and passwords used)
Good job researching those pesky brute force scans. Is there anyway you can post the complete list with all the data collected instead of just the top 50?
ddbb··on PHP functions you (probably) never use
You mean at the top?
ddbb··on PHP functions you (probably) never use
That is what I love about PHP... Always making my life easier.
ddbb··on Closer look at IIScan - Traces a web scan leaves in your logs
I was going to say the same thing...

I expected a scan to go through the site looking at every possible bug, not just that 200/300 checks.

Looking at the full disclosure archives, lots of users mentioned that it is actually common for web scans to be that simple. I guess the technology is still new and most people don't care (as long as the result is a BIG GREEN - no bugs found).

ddbb··on Things You Probably Didn’t Know About PHP
I agree with you. But beginners need to learn from somewhere and most advanced programmers are busy at work and not writing articles :)

Plus, did you ever read a PHP book? Most of them give bad examples and bad code practices too... I just read one that said to disable all apache logging (including error logging) for performance reasons.

ddbb··on Things You Probably Didn’t Know About PHP
The reason they write poor code is because they are beginners and beginners always make mistakes, use functions incorrectly, etc. In any language they code, not just PHP.

PHP is often more visible because it is more used and easier to write... But if PHP wasn't that popular, we would see the same issue with Perl, Python, etc.

ddbb··on PHP Bug: #50696: number_format when passed a 0, returns null
Interesting discussion in there, but I think the PHP guys are right on this one. You should never rely on undefined behavior of any API for mission critical code.

Always use what is documented so you don't have to cry later..

ddbb··on Twitter Hacked by "Iranian Cyber Army"
Some details in here too:

http://blog.sucuri.net/2009/12/twitter-defacement.html

Seems a DNS hijacking for sure.

ddbb··on Twitter down; hacked by "Iranian cyber army"?
Some details in here too:

http://blog.sucuri.net/2009/12/twitter-defacement.html

ddbb··on Ask HN: How do you handle server security/intrusion monitoring?
Using OSSEC (open source).

Seriously, it puts rkhunter, logcheck and all these old tools in their toes..

Check http://www.ossec.net

It monitors your logs, file changes, etc all by default, simple to install, etc.. I love it.

ddbb··on Twitter localized Trend topics (only from the people you follow)
Good stuff, but you need to add OAuth in there... Not everyone likes to post their twitter pass onto other sites.
ddbb··on Matasano hacked. A humbling lesson, even the pros are vulnerable.
Who says it was a 0-day attack? Looking at the output,it seems they brute force the password of user adam...

So yes, even the pros sometimes can make mistake.

ddbb··on Web usability guidelines
That's exactly what I thought. It took me a while to understand how their information was organized...

I guess they don't take their own advice :)

ddbb··on Ask HN: Free or very cheap marketing suggestions for startups
Most people who post anonymously are afraid of doing something wrong (or saying something stupid) and losing respect for that. Either that, or they are trolls.

But thanks for the tip. I will update my HN profile and hope to do not say stupid things :)

ddbb··on Poll: Which server monitoring tool do you use?
I use quite a few monitoring tools, one for each "kind" of monitoring...

-For server uptime, stats, etc I use nagios

-For security monitoring, I mix the open source OSSEC + Snort: http://www.ossec.net

-For availability+integrity remote monitoring of my sites/domains I use sucuri: http://sucuri.net

ddbb··on If you build it, they will ignore it (unless you promote it)
That's a very good eye opening article, seriously. Most developers think that if the code is good and well designed, people will use it, but marketing is so important, that sometimes a worse product is picked up instead of the better, just because of the exposure..
ddbb··on 30 Artistic and Creative Résumés
Those are beautiful, but I think some companies might frown upon them. Anyone here have a fancy resume? :)
ddbb··on Ask HN: Review my POC to detect spam accounts on twitter
The problem I think is that DMs are not public information... You can only know yours, not from the others.
ddbb··on Here's a Hacker News Feed with the main link being the comments
In here the destination article is showing up just as text without the link to it. Maybe you can add it too? Just to avoid cutting/paste...

Besides that, I like the idea. I generally prefer to read the comments (even though I don't post often) more than the articles itself.

[ddbb]