substitute: (Default)
[personal profile] substitute
  • A young guy in a ball cap and sweatshirt and jeans, very typical OC college student type, showed up on the patio and sat outside. He produced from somewhere a bird, a small green one, something similar to a parakeet. Odessa, who was sitting next to me inside, pointed him out. We watched him talk to the bird, who wandered around on the table in front of him and periodically sat on his hand or let him skritch it. He was smoking but keeping the cigarette away from the bird. They appeared to be friends. And then later he walked off towards Wendy's and we couldn't see the bird any more. Where'd the bird go? He didn't look like someone who'd have a bird! What is going on?

  • Jared sent me a Tori Amos video. Yes, that Jared.

  • The apostrophe in "McDonald's" temporarily broke the large, professional website of the company for whom I work.

  • I read a whole book today. It's been a while since I did that.

(no subject)

Date: 2005-11-09 12:31 pm (UTC)
From: [identity profile] jessef.livejournal.com
> Yes, that Jared.

Fogel?

(no subject)

Date: 2005-11-09 08:19 pm (UTC)
From: [identity profile] substitute.livejournal.com
Nah, I bet that guy is a big Tori fan. This Jared likes Tool and Meshuggah.

(no subject)

Date: 2005-11-09 03:08 pm (UTC)
From: [identity profile] travisd.livejournal.com
The apostrophe in "McDonald's" temporarily broke the large, professional website of the company for whom I work.

Sounds like some cross-site-scripting waiting to happen there... That or SQL injection :) Someone's not scrubbing their input...


(no subject)

Date: 2005-11-09 03:33 pm (UTC)
From: [identity profile] petdance.livejournal.com
Never mind scrubbing input, they should be using bind variables. For example, if they're using Perl, instead of
$dbh->do("insert into visitor (name) values ('$field');"

they should be using

my $sth = $dbh->prepare( "insert into visitor(name) values (?)");
$sth->execute($name);

That way, it because $name is never interpolated into a SQL string, it doesn't matter what's in $name. PHP has support for bind variables as well.

Way sadder than you think!

Date: 2005-11-09 08:18 pm (UTC)
From: [identity profile] substitute.livejournal.com
It's Java munching on XML. And the sad part is, we have proven totally functional code that makes this impossible, and people just... don't... USE it.

(no subject)

Date: 2005-11-09 07:50 pm (UTC)
From: [identity profile] brianenigma.livejournal.com
Was it "'" or " '' "?

(no subject)

Date: 2005-11-09 08:18 pm (UTC)
From: [identity profile] substitute.livejournal.com
the apostrophe, not a double quote :)

(no subject)

Date: 2005-11-09 09:18 pm (UTC)
From: [identity profile] brianenigma.livejournal.com
That was an HTML-encoded apostrophe versus a SQL-encoded apostrophe.

(no subject)

Date: 2005-11-09 09:28 pm (UTC)
From: [identity profile] substitute.livejournal.com
oh okay, I spaced.

Profile

substitute: (Default)
substitute

May 2009

S M T W T F S
      1 2
3 456 78 9
10111213141516
17181920212223
24252627282930
31      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags