September 2005 Entries

De-lear-ious

It's a terrible pun I know but Janey and I finally got to see King Lear at Chichester's Minerva Theatre, four months after I booked the tickets and boy was it worth the wait. You know how when you watch a film and all you can think about by the end is how uncomfortable the seat is? The seats in the Minerva are not that comfy and Lear is three and a half hours long, but neither of us noticed. It was the best thing we've seen in theatre or film this year. I know David Warner, who played Lear...

posted @ Monday, September 05, 2005 10:52 PM | Feedback (-1)

Email Injection Attacks

We've recently had a spate of attacks on our live websites from zombie PCs trying to inject email headers into the page's viewstate. At our end, the resultant error comes back as a System.Web.HttpUnhandledException : Invalid Viewstate along with a dump of Viewstate that looks remarkably like a Multi-part MIME email message but contains invalid Base64 characters. ViewState: gpsq@directory.coop Content-Type: multipart/mixed; boundary="===============0113959725==" MIME-Version: 1.0 Subject: 1d2fb280 To: gpsq@directory.coop bcc: jrubin3546@aol.com From: gpsq@directory.coop This is a multi-part message in MIME format. --===============0113959725== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit vzljo --===============0113959725==-- According to this article, this attack is more subtle than you think, but easy to thwart. If you're using .NET, it seems to be...

posted @ Monday, September 05, 2005 12:20 PM | Feedback (3)