Monday, 12 January 2009

virtual box 2.1.0 issues

OK so this morning I had some issues with my bridge/tap interface network with the old virtual box, and in my travels around the net I soon discovered that the latest version of virtualbox removes all the hassle of tap and bridge interfaces! wooohoo I think, and swiftly upgrade!

ok so a minute later all my virtual pcs are fucked :(

"Assertion failed: [!name.isNull()] at '/home/vbox/vbox-2.1.0/src/VBox/Main/NetworkAdapterImpl.cpp' (1068) in nsresult NetworkAdapter::loadSettings(const settings::Key&). Please contact the product vendor!."

woopee...seems the new virtual box breaks because if you have virtual machines that are set to use the tap interface, and you upgrade it cant convert the config for you.

So the simple solution is to goto your virtualbox config file eg
/home/freakyclown/.VirtualBox/Machines/windows/windows.xml
and delete everything between and

so that something like this...













becomes something like this



save and restart virtual box and problem should be solved, you will just have to goto the config and select "host" and start the box.

Monday, 15 December 2008

My friend NapalmTheElf has launched his own blog over at http://napalmtheelf.wordpress.com/
go visit it for his wit, his charm, his forthright opinion and because I said so!

Thursday, 11 December 2008

So google released their zeitgeist for 2008, the fastest growers this year are:

1. sarah palin
2. beijing 2008
3. facebook login
4. tuenti
5. heath ledger
6. obama
7. nasza klasa
8. wer kennt wen
9. euro 2008
10. jonas brothers

It's been a big year for the Internet.
From BBC's iPlayer to Facebook to YouTube, many of the top searches in Britain this year have been for our favourite websites. We also see three web-savvy politicians come tops in searches
Fastest Rising

1. iplayer
2. facebook
3. iphone
4. youtube
5. yahoo mail
6. large hadron collider
7. obama
8. friv
9. jogos
10. wiki

Most Popular

1. facebook
2. bbc
3. youtube
4. ebay
5. games
6. news
7. hotmail
8. bebo
9. yahoo
10. jobs

Politicians (Most Popular)

1. gordon brown
2. david cameron
3. barack obama
4. tony blair
5. sarah palin
6. john mccain
7. george osborne
8. alistair darling
9. boris johnson
10. nicolas sarkozy

Recipes (Fastest Rising)

1. cupcake
2. meatballs
3. rocky road
4. crumble topping
5. eaton mess
6. pork belly
7. rhubarb fool
8. lemon posset
9. honey comb
10. beer batter

Finance terms (Fastest Rising)

1. icesave
2. hot uk deals
3. natwest
4. hmrc
5. hbos
6. money saving expert
7. halifax
8. barclays
9. rbs
10. lloyds tsb

Hottest tickets (Fastest Rising)

1. oasis
2. leonard cohen
3. ac/dc
4. the ashes
5. steve coogan
6. sos
7. oliver
8. gladiators
9. tina turner
10. nickleback

Thursday, 20 November 2008

Official Gmail Blog: Spice up your inbox with colors and themes

G mail launched their new Built in themes today, still haven't shown up yet on my g mail account (even though I was one of the first to get one when they launched)

Official Gmail Blog:
Spice up your inbox with colors and themes

Thursday, 2 October 2008

CSRF

CSRF as it will be known as from now on also known as Cross site request forgery is, in my opinion, an underestimated bug that may occur in quite a lot of web applications.The reason for this is because a lot of web devs assume users will be logged in when they view a given page. So unless they are practically wary will not require a user name and password for every single action the user does. Lets face it, this would get really annoying, really fast and make people less likely to want to bother using this site in the future because of all the hassle.


This attack works by submitting data from an attacker defined form to a form of a target site. After a site I often frequent, decided to fix the XSS bug in one of their pages that I used to annoy people with, I decided to sit down for awhile and try to break it again.


Basically what I did was craft a HTML page hosted on a remote server, that submitted a form using JavaScript. It changed the users email address (which coincidentally resets their password ;)) This code is pretty self explanatory, it runs myform.submit() which submits the form with the name "myform" (duhhhh), stick the target target page in the action parameter and the name of the text box you want to send data for (currently set to targetfield) and its content (newvalue).


Unfortunately blogger won't let me include the html (even when converted to html entities) so here's a pastebin link