<?xml version="1.0" encoding="utf-8"?>
			
			<rss version="2.0">
			<channel>
			<title>The blog of Russ (snake) Michaels - News & Gossip</title>
			<link>http://russ.michaels.me.uk/index.cfm</link>
			<description>This is the blog of Russ Michaels. Here you will find lots of stuff about ColdFusion, tech support and hosting, but the occasional random ramblings about motorcycles, tattoos, the state of the world, rogue traders, product reviews and other stuff that makes me rant.</description>
			<language>en-gb</language>
			<pubDate>Wed, 08 Sep 2010 03:00:05 --0100</pubDate>
			<lastBuildDate>Wed, 04 Aug 2010 19:40:00 --0100</lastBuildDate>
			<generator>BlogCFC</generator>
			<docs>http://blogs.law.harvard.edu/tech/rss</docs>
			<managingEditor>russ@michaels.me.uk</managingEditor>
			<webMaster>russ@michaels.me.uk</webMaster>
			
			<item>
				<title>Sign into multiple Gmail accounts at once</title>
				<link>http://russ.michaels.me.uk/index.cfm/2010/8/4/Sign-into-multiple-Gmail-accounts-at-once</link>
				<description>
				
				&lt;p&gt;Do you have multiple Gmail accounts? Then you will be happy to hear that Google is rolling out a new feature that lets you sign into multiple Google accounts at once. This is a pretty great feature, and one that will save many people a lot of time.&lt;/p&gt;  &lt;p&gt;As far as multiple login goes right now, you can currently be signed into only two separate accounts at once &#xe2;?? one Gmail Account, and one Google Apps account. This lets you be logged into your personal stuff, and your work stuff at the same time.&lt;/p&gt;  &lt;p&gt;Until now though, there was no way for you to be signed into multiple Google Accounts &#xe2;?? say, three Gmail accounts. People maintain multiple accounts for various reasons, now switching between them is a whole lot easier.&lt;/p&gt;  &lt;p&gt;In supported applications, like Gmail, Google Calendar, Google Sites, Google Reader, Google Voice, App Engine and Google Code, there will be a dropdown that lets you choose which account you want to look at. I suspect it will be something like Google Analytics, where you can choose which account you want to view.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;To set up this functionality, you have to visit your &lt;a href=&quot;https://www.google.com/accounts/b/0/ManageAccount&quot;&gt;Google Account page&lt;/a&gt;, and enable multiple logins &#xe2;?? you may not see it yet, but &lt;a href=&quot;http://googlesystem.blogspot.com/2010/08/google-multiple-sign-in-now-available.html&quot;&gt;according to Google Operating System&lt;/a&gt;, it&#xe2;??s on the way.&lt;/p&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Wed, 04 Aug 2010 19:40:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2010/8/4/Sign-into-multiple-Gmail-accounts-at-once</guid>
				
			</item>
			
			<item>
				<title>What OS are web developers using?</title>
				<link>http://russ.michaels.me.uk/index.cfm/2010/7/20/What-OS-are-web-developers-using</link>
				<description>
				
				&lt;p&gt;The open source PHP dynamic language is one of the most widely deployed languages on Web servers today. But what operating systems are PHP developers using to develop and deploy their applications? It&apos;s a question that has been asked before and now it&apos;s being answered with a new &lt;a href=&quot;http://www.developer.com/lang/php/article.php/3865581/PHP-Developers-Prefer-Using-Windows-to-Build-Enterprise-Apps-Study.htm#&quot;&gt;study&lt;/a&gt; from Zend, one of the lead commercial backers behind PHP. &lt;/p&gt;  &lt;p&gt;The study surveyed 2,000 PHP developers in December and found that 85 percent reported that Linux was their primary operating system as a production environment for PHP. &lt;/p&gt;  &lt;p&gt;Windows came in at a distant second at 11 percent while Mac OS X came in third at just 2 percent. However, when Zend drilled down into which platforms respondents prefer for their development, the rankings change dramatically. &lt;/p&gt;  &lt;p&gt;According to the study, 42 percent of respondents reported that Windows was their primary operating system for development. Linux came in as No. 2 at 38.5 percent while Mac OS X remained in third place at 19.1 percent. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The findings indicate that while Microsoft Windows remains the top platform for developing in PHP, its lead may be narrowing. Back in 2006, &lt;a href=&quot;http://www.internetnews.com/dev-news/article.php/3632136&quot;&gt;a Microsoft executive reported that 85 percent of PHP developers were developing on Windows&lt;/a&gt;, but only 20 percent deployed on a Windows machine. The change comes despite joint work by Zend and Microsoft to &lt;a href=&quot;http://www.internetnews.com/dev-news/article.php/3704156/Zend+Brings+Microsoft+Into+the+PHP+Fold.htm&quot;&gt;improve the capabilities of PHP on Windows servers&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;that the new study was based on over 2,000 completed surveys conducted in December 2009, some of which came from Zend customers. The survey was made public through the Zend Framework website, the Zend monthly &lt;a href=&quot;http://www.developer.com/lang/php/article.php/3865581/PHP-Developers-Prefer-Using-Windows-to-Build-Enterprise-Apps-Study.htm#&quot;&gt;newsletter&lt;/a&gt;, Twitter and &lt;a href=&quot;http://devzone.zend.com/public/view&quot;&gt;DevZone&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I have also noticed recently from reading blogs and lists that the majority of CFML open source developers seem to deploy Railo or Open BlueDragon on Linux, which is a major paradigm shift from ColdFusion developers who primary use Windows. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I don&apos;t think this is a matter of preference but rather one of necessity as pretty much all the PHP documentation is for Linux, most PHP apps are written for Linux/Apache and are not supported on windows even if you can get them working.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If you have tried to install Railo then will have discovered this can also be quite a task and a challenge to get working, especially on windows/IIS7, and there are far more blog posts and docs explaining how to get it running on Linux, as well as ready made virtual disk images, which I suspects encourages people to take the path of least resistance and install Linux.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In the case of CFML this does however tend to be done using virtualisation software such as virtualbox or vmware to run a linux development servers on windows, so cfml developers do still seem to be using windows as their primary desktop OS, so I do wonder if Zend took this into consideration with their study and if many of those who listed Linux as their primary development OS may in fact be running it as a virtual machine on windows. This feeling is further extrapolated by the fact that developers are mainly using servers distros like CentOS.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;You also need to consider all the obvious facts as well:- While Linux has a lot going for it and plenty of software, most of the best/popular software, especially web dev/design products like Dreamweaver and the rest of the Adobe line is not available on Linux. Sure there are alternatives, but they are certainly not in the same league and you can&apos;t walk into PC World and buy any of it. For those who have always been running a Linux desktop this will of course not matter at all, but for the rest this will be a big issue, especially if it is software you have spent a lot of money on, so running a virtual machine makes sense.&lt;/p&gt;  &lt;p&gt;Of course it could be the other way round entirely and developers are running a windows VM on linux, but this would seem an off way of doing it if their primary tools are on windows.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Before the Linux fanboys start ranting, let me make it 100% clear that this is not a linux vs windows slanging match and I will delete all churlish comments attempting to turn it into one. If you comment keep it on-topic and professional.&lt;/p&gt; 
				</description>
				
				<category>WEBBY STUFF</category>				
				
				<category>Jibber Jabber</category>				
				
				<category>News &amp; Gossip</category>				
				
				<category>BlueDragon and Railo</category>				
				
				<pubDate>Tue, 20 Jul 2010 17:58:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2010/7/20/What-OS-are-web-developers-using</guid>
				
			</item>
			
			<item>
				<title>FREE Railo hosting is now available at CFMLDeveloper.com</title>
				<link>http://russ.michaels.me.uk/index.cfm/2010/6/29/FREE-Railo-hosting-is-now-available-at-CFMLDevelopercom</link>
				<description>
				
				&lt;p&gt;As of today, &lt;a href=&quot;http://www.getrailo.org/&quot;&gt;Railo &lt;/a&gt;3.1 is now available at &lt;a href=&quot;http://www.cfmldeveloper.com/&quot;&gt;CFMLdeveloper.com&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;If you already have an account then simply login to &lt;a href=&quot;http://helm.cfmldeveloper.com/&quot;&gt;HELM &lt;/a&gt;and go to Packages -&amp;gt; add new and choose one of the new Railo Plans. Please note that the SETUP fee still applies for all new packages, but is still a one-time fee for fraud validation purposes and your hosting is then FREE forever. For more info please refer to the &lt;a href=&quot;http://www.cfmldeveloper.com/page.cfm/hosting/resources&quot;&gt;HELP pages&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If you do not yet have an account then simply SIGNUP from the &lt;a href=&quot;http://www.cfmldeveloper.com/page.cfm/hosting&quot;&gt;hosting page&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Please don&apos;t forget to check the Hosting support pages if you get stuck, most common questions can be found there.&lt;/p&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<category>ColdFusion</category>				
				
				<pubDate>Tue, 29 Jun 2010 16:41:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2010/6/29/FREE-Railo-hosting-is-now-available-at-CFMLDevelopercom</guid>
				
			</item>
			
			<item>
				<title>Photoshop CS5 demonstrates its stunning new party piece</title>
				<link>http://russ.michaels.me.uk/index.cfm/2010/3/24/Photoshop-CS5-demonstrates-its-stunning-new-party-piece</link>
				<description>
				
				&lt;p&gt;I just had to share this as it is totally awesome. So many times I could have used this.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;The now-familiar release cycle of Adobe&amp;#39;s Creative Suite is signalled by two things: the hype and expectation of&amp;nbsp; those who rely on Adobe&amp;#39;s applications and prices that, especially for UK users, seem to soar further into the stratosphere with every new version.&lt;/p&gt;  &lt;p&gt;A single new feature, though, has awed the &lt;i&gt;PC Pro &lt;/i&gt;office and suddenly made CS5 seem like fantastic value for money. It&amp;#39;s been dubbed the Content-Aware Fill, and has been shown off in a YouTube video narrated by Bryan O&amp;#39;Neil-Hughes, a product manager on the Photoshop team.&lt;/p&gt;  &lt;p&gt;The dull, businesslike name hides a potentially revolutionary feature: if you&amp;#39;re not happy with an item in your picture, select it, delete it, and Photoshop will analyse the surrounding area and plug the gap as if it never existed.&lt;/p&gt;  &lt;div style=&quot;text-align: center&quot;&gt;&lt;object classid=&quot;clsid:D27CDB6E-AE6D-11cf-96B8-444553540000&quot; codebase=&quot;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,29,0&quot; width=&quot;425&quot; height=&quot;385&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/NH0aEp1oDOI&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;hl=en_US&amp;amp;feature=player_embedded&amp;amp;fs=1&quot; /&gt;&lt;param name=&quot;quality&quot; value=&quot;high&quot; /&gt;&lt;param name=&quot;menu&quot; value=&quot;false&quot; /&gt;&lt;param name=&quot;wmode&quot; value=&quot;&quot; /&gt;&lt;embed src=&quot;http://www.youtube.com/v/NH0aEp1oDOI&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;hl=en_US&amp;amp;feature=player_embedded&amp;amp;fs=1&quot; wmode=&quot;&quot; quality=&quot;high&quot; menu=&quot;false&quot; pluginspage=&quot;http://www.macromedia.com/go/getflashplayer&quot; type=&quot;application/x-shockwave-flash&quot; width=&quot;425&quot; height=&quot;385&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;  &lt;p align=&quot;center&quot;&gt;It seems easy to use and incredibly proficient: O&amp;#39;Neil-Hughes used it to remove lens flare, turn patchy and litter-strewn grass into a perfectly manicured lawn. He quickly removed entire trees and let Photoshop stitch together the grass and sky that would take their place. It&amp;#39;s a testament to the new tool&amp;#39;s proficiency that we couldn&amp;#39;t tell that the image had been modified.&lt;/p&gt;  &lt;p&gt;He didn&amp;#39;t stop there: a simple click removed a dusty track and replaced it with desert, and a panoramic image&amp;#39;s clumsy borders were filled out within seconds. Best of all, Photoshop handled these modifications without fuss and quickly delivered picture-perfect results.&lt;/p&gt;  &lt;p&gt;Without this feature, making these edits could take hours or, in more complicated cases, even days. The Content-Aware Fill, though, took just seconds and has got us even more excited about the impending release of CS5. We&amp;#39;ll have a full review available when the software is released but, for now, this demo should be more than enough to whet your appetite.&lt;/p&gt; 
				</description>
				
				<category>Jibber Jabber</category>				
				
				<category>News &amp; Gossip</category>				
				
				<category>Product Reviews</category>				
				
				<pubDate>Wed, 24 Mar 2010 21:36:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2010/3/24/Photoshop-CS5-demonstrates-its-stunning-new-party-piece</guid>
				
			</item>
			
			<item>
				<title>Firefox &amp;amp; Abobe rated as most bugiest software</title>
				<link>http://russ.michaels.me.uk/index.cfm/2010/1/7/Firefox-amp-Abobe-rated-as-most-bugiest-software</link>
				<description>
				
				&lt;p&gt;Firefox was the application that had the most reported vulnerabilities this year, while holes in Adobe Reader more than tripled from a year ago, according to statistics compiled by Qualys, a vulnerability management provider. &lt;/p&gt;  &lt;p&gt;Qualys tallied 102 vulnerabilities that were found in &lt;a href=&quot;http://www.cnet.com/firefox-3/&quot;&gt;Firefox&lt;/a&gt; this year, up from 90 last year. The numbers are based on running totals in the &lt;a href=&quot;http://nvd.nist.gov/&quot;&gt;National Vulnerability Database&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style=&quot;display: inline; margin-left: 0px; margin-right: 0px&quot; alt=&quot;&quot; align=&quot;left&quot; src=&quot;http://i.i.com.com/cnwk.1d/i/bto/20091217/Firefoxlogo_90x86.png&quot; width=&quot;90&quot; height=&quot;86&quot; /&gt;&lt;/p&gt;  &lt;p&gt;However, the high number of Firefox vulnerabilities doesn&apos;t necessarily mean the Web browser actually has the most bugs; it just means it has the most &lt;i&gt;reported&lt;/i&gt; holes. Because the software is open source, all holes are publicly disclosed, whereas proprietary software makers, like Adobe and Microsoft, typically only publicly disclose holes that were found by researchers outside the company, and not ones discovered internally, Qualys Chief Technology Officer Wolfgang Kandek said late on Wednesday.&lt;/p&gt;  &lt;p&gt;Meanwhile, Adobe took the second place spot from Microsoft this year. The number of vulnerabilities in Adobe Reader rose from 14 last year to 45 this year, while those in &lt;a href=&quot;http://www.cnet.com/microsoft-office/&quot;&gt;Microsoft Office&lt;/a&gt; dropped from 44 to 41, according to Qualys. Internet Explorer had 30 vulnerabilities. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;A shift in focus&lt;/b&gt;    &lt;br /&gt;The numbers illustrate the trend of attackers turning their focus away from operating systems and toward applications, Kandek said.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style=&quot;display: inline; margin-left: 0px; margin-right: 0px&quot; alt=&quot;&quot; align=&quot;left&quot; src=&quot;http://i.i.com.com/cnwk.1d/i/bto/20091217/Adobelogo_90x122.png&quot; width=&quot;90&quot; height=&quot;122&quot; /&gt;&lt;/p&gt;  &lt;p&gt;&amp;quot;Operating systems have become more stable and harder to attack and that&apos;s why attackers are migrating to applications, he said. &amp;quot;Adobe is a huge focus for attacks now, around 10 times more than Microsoft Office. However, other widely used targets like Internet Explorer and Firefox are still far from secure.&amp;quot;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;http://www.f-secure.com/weblog/archives/00001676.html&quot;&gt;Research from F-Secure earlier this year&lt;/a&gt; provides further evidence that holes in Adobe applications are being targeted more than Microsoft apps. During the first three months of 2009, F-Secure discovered 663 targeted attack files, the most popular type being PDFs at nearly 50 percent, followed by Microsoft Word at nearly 40 percent, Excel at 7 percent, and PowerPoint at 4.5 percent. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;That compared with Word representing nearly 35 percent of all 1,968 targeted attacks in 2008, followed by Reader at more than 28 percent, Excel at nearly 20 percent, and PowerPoint at nearly 17 percent. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;As a result, Adobe needs to respond the way Microsoft did in 2002 when it &lt;a href=&quot;http://news.cnet.com/Gates-Security-is-top-priority/2100-1002_3-816880.html&quot;&gt;launched its Trustworthy Computing initiative&lt;/a&gt;, and make securing its software a company-wide priority, &lt;a href=&quot;http://news.cnet.com/8301-27080_3-10304455-245.html&quot;&gt;researchers say&lt;/a&gt;. F-Secure even &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10224449-83.html&quot;&gt;recommended&lt;/a&gt; that people stop using Reader and use an alternative PDF reader. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style=&quot;display: inline; margin-left: 0px; margin-right: 0px&quot; alt=&quot;&quot; align=&quot;right&quot; src=&quot;http://i.i.com.com/cnwk.1d/i/bto/20091217/Microsoftlogo.png&quot; width=&quot;141&quot; height=&quot;41&quot; /&gt;&lt;/p&gt;  &lt;p&gt;Adobe has taken some action, announcing &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10245931-83.html&quot;&gt;in May&lt;/a&gt; that it would release its security updates on a regular schedule, quarterly and coinciding with every third Microsoft Patch Tuesday.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Another study released this week focuses on which applications are the riskiest to users. Based on the most severe vulnerabilities in popular applications that run on Windows and which are not updated automatically, Firefox again tops the list, followed by Adobe Reader and Apple QuickTime, according to Bit9, a provider of application white listing technology. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The list of risky software compiled by Bit9 based on the National Vulnerability Database also includes Java, Flash Player, &lt;a href=&quot;http://download.cnet.com/mac/browsers/2001-2137_4-0.html&quot;&gt;Safari&lt;/a&gt;, Shockwave, Acrobat, Opera, Real Player, and Trillian. Last year, the Bit9 list of the most risky apps included Skype, Yahoo IM, and AOL IM, but those three were not on this year&apos;s list. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Not included on the list are programs from Microsoft and Google because of the ability for users of their software to have patches installed automatically. Microsoft software can be automatically and centrally updated via the Microsoft Systems Management Server and Windows Server Update Services, and Google Chrome is automatically updated when users are on the Internet, Bit9 said. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The lists do not take into account the amount of time it takes for companies to release patches, particularly when there is an exploit in the wild. Bit9 noted that Microsoft Internet Explorer was given an &amp;quot;honourable mention&amp;quot; because of a zero-day vulnerability related to ActiveX that went un-patched for three weeks &lt;a href=&quot;http://news.cnet.com/8301-27080_3-10297328-245.html&quot;&gt;in July&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Microsoft isn&apos;t alone in taking longer than customers would like to fix holes. &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10193218-83.html&quot;&gt;In March&lt;/a&gt;, Adobe released a patch for a zero-day vulnerability in Reader and Acrobat--about two weeks after it was disclosed to users and nearly two months after exploits had been discovered in the wild. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Adobe customers will have to wait about a month for a fix to the latest critical zero-day hole in Reader and Acrobat. The company announced &lt;a href=&quot;http://news.cnet.com/8301-27080_3-10416816-245.html&quot;&gt;on Wednesday&lt;/a&gt; it would not patch the vulnerability until its next scheduled quarterly security update release on January 12. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;For those looking for a secure alternative to Adobe PDF reader, try Foxit Reader.&lt;/p&gt;  &lt;p&gt;&lt;a title=&quot;http://www.foxitsoftware.com/pdf/reader/&quot; href=&quot;http://www.foxitsoftware.com/pdf/reader/&quot;&gt;http://www.foxitsoftware.com/pdf/reader/&lt;/a&gt;&lt;/p&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Thu, 07 Jan 2010 11:50:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2010/1/7/Firefox-amp-Abobe-rated-as-most-bugiest-software</guid>
				
			</item>
			
			<item>
				<title>Security Alert! Sites hacked via upload scripts</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/9/18/Security-Alert-Sites-hacked-via-upload-scripts</link>
				<description>
				
				&lt;p&gt;SECURITY ALERT!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;There has been an increase in the past few days of sites being hacked via file upload scripts, particularly a number of high profile ColdFusion based sites.&lt;/p&gt;  &lt;p&gt;The hacker gets in by uploading a CFM, ASP, PHP or other supported file type to the server and executing the file, thus escalating his access.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If you have any publicly accessible areas of your site where files can be uploaded then you should make sure you are not vulnerable, make sure that you are validating allowed uploaded file types and not allowing executable files to be uploaded. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In particular you should pay attention to things like image uploads on forums or other applications which people seem to think are safe because it only allows images to be upload. Many scripts will actually accept the uploaded file to the final destination folder before validating it and then deleting it if it is not valid, thus giving a window of opportunity for the file to be executed.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;What happens is that the hacker uses a load testing tool that constantly executes the URL on your site where he knows his file will be uploaded (e.g. mysite.com/files/xyz.cfm), this is done many times a second, so when he then uploads the file it will get executed in those few milliseconds before it is deleted.&lt;/p&gt;  &lt;p&gt;To avoid this scenario you should perform checks prior to accepting the upload, or upload the file to a temp location first that the hacker cannot access and then move it to the destination folder once it has been verified.&lt;/p&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<category>ColdFusion</category>				
				
				<pubDate>Fri, 18 Sep 2009 11:33:45 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/9/18/Security-Alert-Sites-hacked-via-upload-scripts</guid>
				
			</item>
			
			<item>
				<title>WPA Protocol hacked</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/9/7/WPA-Protocol-hacked</link>
				<description>
				
				&lt;p&gt;I guess this has been inevitable for some time, but the the WPA wireless security protocol has now been effectively hacked. A Japanese group have developed a hack for the WPA protocol and will be presenting their findings in Hiroshima on Sept 25th (&lt;a href=&quot;http://www.ieice.org/ken/paper/20090925faPH/eng/&quot;&gt;http://www.ieice.org/ken/paper/20090925faPH/eng/&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;See here for their full report:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;http://jwis2009.nsysu.edu.tw/location/paper/A%20Practical%20Message%20Falsification%20Attack%20on%20WPA.pdf&quot;&gt;http://jwis2009.nsysu.edu.tw/location/paper/A%20Practical%20Message%20Falsification%20Attack%20on%20WPA.pdf     &lt;br /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;If you are using WEP(already hacked) or WPA, I would strongly encourage you to switch to the WPA2 protocol as soon as possible. If you are using WPA with AES, you should be fine, for now. This hack currently affects WPA using TKIP. But if you have to switch things up might as well go to WPA2 with its newer version of AES. It&apos;s only a matter of time before this exploit is actively used, so time is critical.&lt;/p&gt;  &lt;p&gt;Here&apos;s also a report on this from Network World:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;http://www.networkworld.com/news/2009/082709-new-attack-cracks-common-wi-fi.html&quot;&gt;http://www.networkworld.com/news/2009/082709-new-attack-cracks-common-wi-fi.html&lt;/a&gt;&lt;/p&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Mon, 07 Sep 2009 12:34:37 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/9/7/WPA-Protocol-hacked</guid>
				
			</item>
			
			<item>
				<title>Five Kids Rescued From Sex Abuse Gangs</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/9/1/Five-Kids-Rescued-From-Sex-Abuse-Gangs</link>
				<description>
				
				&lt;h4&gt;Police have rescued five children who were being kept as sex slaves by paedophiles who broadcast the abuse on the internet.&lt;/h4&gt;  &lt;p&gt;&lt;img style=&quot;display: block; float: none; margin-left: auto; margin-right: auto&quot; alt=&quot;Computer keyboard&quot; src=&quot;http://news.sky.com/sky-news/content/StaticFile/jpg/2009/Sep/Week1/15372601.jpg&quot; /&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The boys and girls, aged from seven to 13 years old, were snatched from the suspects in a series of raids across the UK.&lt;/p&gt;  &lt;p&gt;Three of the youngsters were discovered at addresses in Scotland, and two in England.&lt;/p&gt;  &lt;p&gt;The children were being attacked on a daily basis, and footage of the abuse was streamed live on websites.&lt;/p&gt;  &lt;p&gt;All are now receiving counselling and support.&lt;/p&gt;  &lt;p&gt;Officers said a number of suspects were arrested in the operation.&lt;/p&gt;  &lt;p&gt;Scotland&apos;s National Sex Crimes Unit, which was set up in March this year, said legal proceedings have begun against them.&lt;/p&gt;  &lt;p&gt;Senior prosecuting counsel Derek Ogg QC, who heads the unit, praised police for the &amp;quot;good old-fashioned detective work&amp;quot; that led to the arrests.&lt;/p&gt;  &lt;p&gt;Officers began the operation after a man was arrested for other alleged sex offences.&lt;/p&gt;  &lt;p&gt;Children were identified and the raids were launched across the UK.&lt;/p&gt;  &lt;p&gt;Mr Ogg told Sky News Online: &amp;quot;When you discover this going on in your own back yard, in your home country, it really brings it home to people.&lt;/p&gt;  &lt;p&gt;&amp;quot;This was all down to good old-fashioned police detective work.&amp;quot;&lt;/p&gt;  &lt;p&gt;He added: &amp;quot;It was carried out by incredibly dedicated officers who worked night and day to put an end to these children&apos;s daily ordeal.&lt;/p&gt;  &lt;p&gt;&amp;quot;I can&apos;t stress enough the credit that the police take in these cases.&lt;/p&gt;  &lt;p&gt;&amp;quot;It takes amazing dedication sifting through the evidence to get success like this.&amp;quot;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I can only hope that our dismal justice system for once does the right thing and a sensible judge puts these evil bastards away for the rest of their lives and while inside they get their genitals amputated.&lt;/p&gt;  &lt;p&gt;As a father of 3 myself, I can only imagine how the parents of these children must be feeling right now, it is certainly a heart wrenching decision when you have to decide between what you want to do and what you should do in the best interest of your kids, when sadly vengeance, no matter how much you want it or deserve it will only make the situation worse.&lt;/p&gt; 
				</description>
				
				<category>Kids &amp; Parenting</category>				
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Tue, 01 Sep 2009 15:35:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/9/1/Five-Kids-Rescued-From-Sex-Abuse-Gangs</guid>
				
			</item>
			
			<item>
				<title>55,000 Web sites hacked to serve up malware cocktail</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/8/25/55000-Web-sites-hacked-to-serve-up-malware-cocktail</link>
				<description>
				
				&lt;div style=&quot;margin: 0px; display: inline; float: none; padding: 0px&quot; id=&quot;scid:0767317B-992E-4b12-91E0-4F059A8CECA8:b80fad52-c646-410b-a4e0-2cc75b6378d6&quot; class=&quot;wlWriterEditableSmartContent&quot;&gt;Technorati Tags: &lt;a rel=&quot;tag&quot; href=&quot;http://technorati.com/tags/web&quot;&gt;web&lt;/a&gt;,&lt;a rel=&quot;tag&quot; href=&quot;http://technorati.com/tags/malware&quot;&gt;malware&lt;/a&gt;,&lt;a rel=&quot;tag&quot; href=&quot;http://technorati.com/tags/spyware&quot;&gt;spyware&lt;/a&gt;,&lt;a rel=&quot;tag&quot; href=&quot;http://technorati.com/tags/adaware&quot;&gt;adaware&lt;/a&gt;,&lt;a rel=&quot;tag&quot; href=&quot;http://technorati.com/tags/hacked&quot;&gt;hacked&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin: 0px; display: inline; float: none; padding: 0px&quot; class=&quot;wlWriterEditableSmartContent&quot;&gt;&lt;/div&gt;&lt;p&gt;Security researchers are raising an alarm for a potent malware cocktail&amp;nbsp;- backdoor Trojans and password stealers being pushed to Windows users from about 55,000 hacked Web sites.&lt;/p&gt;&lt;p&gt;According to Mary Landesman, a researcher in ScanSafe&amp;#39;s security threat alert team, the cybercriminals have embedded a malicious iFrame into tens of thousands of Websites to fire exploits at unsuspecting PC users who surf to one of the rigged sites.&lt;/p&gt;&lt;p&gt;The iFrame points to an intermediary exploit site which in turn loads additional exploits and malware from up to seven different malware domains, &lt;a href=&quot;http://blog.scansafe.com/journal/2009/8/21/up-to-55k-compromised-by-potent-backdoordata-theft-cocktail.html&quot;&gt;Landesman said&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;She ran a &lt;a href=&quot;http://www.google.com/search?q=%22script%20src%3Dhttp%3A%2F%2Fa0v.org%2Fx.js%22&amp;amp;hl=en&amp;amp;client=firefox-a&amp;amp;rls=org.mozilla:en-US:official&amp;amp;tbo=1&amp;amp;tbs=qdr:y&quot;&gt;Google search on the iframe script tag&lt;/a&gt; and found it embedded on about 54,900 sites, many&amp;nbsp; of them legitimate online destinations.&lt;/p&gt;&lt;p&gt;Victim sites include www.feedzilla.com, latindiscover.com, and a number of charitable and nursing facilities, including howellcarecenter.com, sweetgrassvillagealf.com, www.foodsresourcebank.org, and morningsideassistedliving.com.&lt;/p&gt;&lt;p&gt;At the time of writing this blog post, the number of hacked sites listed in Google results climbed to 56,000.&lt;/p&gt;&lt;p&gt;It is not yet clear which vulnerabilities are being exploited in this attack but, judging from recent history, end users should ensure that operating system and desktop software programs are fully patched.&lt;/p&gt;&lt;p&gt;The most common programs under attack include Adobe Flash, Adobe PDF Reader, Apple&amp;#39;s QuickTime, WinZip and RealPlayer.&amp;nbsp; In addition to Microsoft Windows patches, these desktop applications should be updated to the newest version immediately.&lt;/p&gt;&lt;p&gt;If you run a website then I would suggest you do a file search for the aforementioned code and make sure your site has not been hacked, especially if you use 3rd party scripts that may be vulnerable.&lt;/p&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Tue, 25 Aug 2009 15:37:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/8/25/55000-Web-sites-hacked-to-serve-up-malware-cocktail</guid>
				
			</item>
			
			<item>
				<title>Secret of Monkey Island comes to XBox</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/7/23/Secret-of-Monkey-Island-comes-to-XBox</link>
				<description>
				
				&lt;p&gt;&lt;img src=&quot;/enclosures/bannerdefault_5.jpg&quot; alt=&quot;bannerdefault&quot; title=&quot;bannerdefault&quot; style=&quot;border-width: 0px; display: inline&quot; border=&quot;0&quot; height=&quot;119&quot; width=&quot;565&quot; /&gt; &lt;/p&gt;&lt;p&gt;One of my all time favourite games, Monkey Island, is now available on XBox Live.&lt;/p&gt;&lt;p&gt;Forgoing the history lesson on an almost-20-year-old game, The Secret of Monkey Island is a point-and-click adventure in which you assume the role of a wannabe pirate named Guybrush Threepwood. In order to become a pirate, Threepwood must prove himself as a swordsman, a treasure hunter, and a thief, which means you must prove that you can both solve puzzles &lt;i&gt;and&lt;/i&gt; move a cursor around a screen--often simultaneously. You can expect to hit a few brick walls when you encounter some of the more baffling puzzles, but the all-new hints system does a great job of pointing you in the right direction if you choose to use it (although I would advise only rto use it as a last resort), and the writing is entertaining enough to keep you interested during extended periods of head-scratching if you don&amp;#39;t. An option to play the game in its original form or with greatly enhanced audio and visuals is the foamy head on this Special Edition pint of Grog, and you won&amp;#39;t want to stop drinking until you can see the bottom of your tankard. &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table class=&quot;commentAlt&quot; border=&quot;0&quot; width=&quot;100%&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Why choose just one art style when you can have both? &lt;br /&gt;&lt;/td&gt;&lt;td&gt;[&lt;a href=&quot;http://uk.gamespot.com/pc/adventure/thesecretofmonkeyislandspecialedition/video/6213422&quot;&gt;&lt;u&gt;&lt;font color=&quot;#0000ff&quot;&gt;Comment on this video&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;]&lt;a href=&quot;http://uk.gamespot.com/pc/adventure/thesecretofmonkeyislandspecialedition/video/6213422?hd=1&quot;&gt; &lt;br /&gt;&lt;u&gt;&lt;font color=&quot;#0000ff&quot;&gt;[Watch this video in HD 540p&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;] &lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.adobe.com/go/getflashplayer&quot;&gt;&lt;u&gt;&lt;font color=&quot;#0000ff&quot;&gt;Flash Player 9&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; is required to watch this video&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style=&quot;clear: both&quot; align=&quot;center&quot;&gt;&lt;div style=&quot;clear: both&quot; align=&quot;center&quot;&gt;&lt;textblock label=&quot;monkeyvideo&quot;&gt;&lt;/textblock&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;The Secret of Monkey Island is an easy game to pick up, regardless of whether or not you&amp;#39;ve played this kind of adventure game before. You can use either analogue stick to move a cursor around the screen, and when you&amp;#39;re pointing at something you want to interact with or a location you want to move to, you push the A button. Other actions, such as &amp;quot;speak to,&amp;quot; &amp;quot;pull,&amp;quot; &amp;quot;use,&amp;quot; and &amp;quot;give,&amp;quot; are assigned to onscreen buttons that, depending on whether or not you&amp;#39;re playing with the updated visuals, either appear at the bottom of the screen at all times or in a pop-up window mapped to a shoulder button. Items in your inventory also appear onscreen at all times when playing with the original graphics, but they are mapped to a second pop-up window in the new interface. It&amp;#39;s great that you can switch between the two modes on the fly because there are pros and cons to both. The Special Edition looks much better and is the only way to play if you want to hear, as well as read, what characters are saying, whereas the original game&amp;#39;s interface is less clunky. &lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&amp;nbsp;&lt;/div&gt;&lt;p align=&quot;justify&quot;&gt;Monkey Island isn&amp;#39;t a game that wastes any time throwing seemingly useless items and satisfying puzzles at you. Shortly after starting out on Melee Island, you visit a bar where pirate leaders drunk on Grog (a drink so acidic that you have to consume it before it eats through the tankard) give you three challenges to complete; a surly chef refuses you entry to his kitchen; and a hungry seagull makes it difficult for you to pick up what may or may not be a red herring. Before you know it, you&amp;#39;re walking around the island with all manner of items stuffed into Threepwood&amp;#39;s physics-defying pockets, and you&amp;#39;ll spend the majority of your time figuring out how to combine or use those items. Using the &amp;quot;look at&amp;quot; option on an item will afford you an amusing description that often doubles as a clue to its intended purpose. You might still end up solving some puzzles through trial and error, but you&amp;#39;ll also kick yourself for not spotting the clues to the puzzle&amp;#39;s solution before resorting to that time-tested technique.&lt;/p&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;/div&gt;&lt;div class=&quot;embscreen_large&quot;&gt;&lt;a href=&quot;http://uk.gamespot.com/xbox360/adventure/thesecretofmonkeyislandspecialedition/images/6213425/2/?path=2009%2F195%2Freviews%2F960369_20090715_embed002.jpg&amp;amp;caption=This%2Bconversation%2Bwas%2Bamusing%2Bin%2B1990...&amp;amp;cvr=DtI%2F&quot; target=&quot;_blank&quot;&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;http://image.com.com/gamespot/images/2009/195/reviews/960369_20090715_embed002.jpg&quot; class=&quot;thumb&quot; /&gt;&lt;/div&gt;&lt;/a&gt;&lt;p class=&quot;commentAlt&quot;&gt;This conversation was amusing in 1990...&lt;/p&gt;&lt;/div&gt;&lt;p align=&quot;justify&quot;&gt;When you&amp;#39;re not attempting to combine a staple remover with a banana or wondering how to get past a group &lt;/p&gt;&lt;p align=&quot;justify&quot;&gt;of deadly piranha poodles, much of your time is spent navigating dialogue trees with characters that include belligerent buccaneers, cholesterol-conscious cannibals, and a used boat salesman named Stan. Some of the conversations are laugh-out-loud funny, and while the actors&amp;#39; delivery isn&amp;#39;t always up to the standard of the writing, the voice work is such a great addition to the game that it&amp;#39;s difficult to go back to the original edition. Lengthy conversations with the aforementioned salesman can be a little irritating when you have to listen to--as well as read--his persistent patter, but he&amp;#39;s still an amusing and memorable character in a cast composed almost entirely of amusing and memorable characters. &lt;/p&gt;&lt;p align=&quot;justify&quot;&gt;In The Secret of Monkey Island: Special Edition, meeting and interacting with these characters is every bit as enjoyable as it was almost 20 years ago. The puzzles, the humor, and the Caribbean-sounding tunes that keep you company as you ponder your next move continue to defy their age, and even the original visuals still have plenty of pixel-perfect charm. The Special Edition update employs a colorful art style that&amp;#39;s more reminiscent of the style in The Curse of Monkey Island (the third game in the series) than other games, but it retains the primitive (but pleasing) animation of the first game. Switching between the two available art styles is something that you&amp;#39;ll almost certainly do from time to time just because you can, and it&amp;#39;s interesting to see how faithfully and brilliantly such locations as the Scumm Bar and the cannibal village have been updated. &lt;/p&gt;&lt;a href=&quot;http://uk.gamespot.com/xbox360/adventure/thesecretofmonkeyislandspecialedition/images/6213425/3/?path=2009%2F195%2Freviews%2F960369_20090715_embed003.jpg&amp;amp;caption=%2585and%2Bit%2527s%2Beven%2Bbetter%2Bin%2B2009%2Bbecause%2Byou%2Bcan%2Bhear%2Bit.&amp;amp;cvr=SnA0&quot; target=&quot;_blank&quot;&gt;&lt;div class=&quot;embscreen_large&quot; style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;http://image.com.com/gamespot/images/2009/195/reviews/960369_20090715_embed003.jpg&quot; class=&quot;thumb&quot; /&gt;&lt;/div&gt;&lt;/a&gt;&lt;p class=&quot;commentAlt&quot; align=&quot;center&quot;&gt;and it&amp;#39;s even better in 2009 because you can hear it.&lt;/p&gt;&lt;p align=&quot;justify&quot;&gt;It&amp;#39;s possible to beat The Secret of Monkey Island in just a couple of hours if you go into the game armed with a complete solution. However, if you take the time to enjoy it and solve the puzzles yourself, it should last you anywhere between five and 10 hours. If you have a rubber chicken with a pulley in the middle, two sticks of cinnamon, a length of rope, and 800 Microsoft points in your pocket right now, the best advice I can give you is this: Spend the points on The Secret of Monkey Island: Special Edition and then figure out for yourself what to do with the rest of that stuff. &lt;/p&gt;&lt;p align=&quot;justify&quot;&gt;Even after all these years it seems I still remembered enough about this game to plough through certain parts quickly, but I had also forgotten enough to make me resort to using the hint system far too quickly just because it is there.&lt;/p&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<category>Gaming</category>				
				
				<pubDate>Thu, 23 Jul 2009 11:16:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/7/23/Secret-of-Monkey-Island-comes-to-XBox</guid>
				
			</item>
			
			<item>
				<title>Knight Rider Reboot</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/7/22/Knight-Rider-Reboot</link>
				<description>
				
				&lt;p&gt;&lt;a href=&quot;/enclosures/knight_rider_2.jpg&quot;&gt;&lt;img height=&quot;451&quot; width=&quot;563&quot; src=&quot;/enclosures/knight_rider_thumb.jpg&quot; alt=&quot;knight_rider&quot; border=&quot;0&quot; title=&quot;knight_rider&quot; style=&quot;display: block; float: none; margin-left: auto; margin-right: auto; border: 0px&quot; /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p&gt;Have you been watching the new series of Knight Rider? It is actually rather cool I have to say. I was sorely disappointed after watching the pilot, as were many others judging by the online chatter, Kitt had none of the cool features from the original series other than being bullet proof, and the only new feature was his ability to morph, which was also rather lame in the pilot, and quite frankly the car just didn&amp;#39;t look anywhere near as cool as the old trans-am, and I really wasn&amp;#39;t feeling at all excited about the new series based on this.&lt;/p&gt;&lt;p&gt;Thankfully it seems the producers have listened to the complaints and things are vastly better in the new series, Kitt can now turbo boost, shoot lasers and rockets, emit emp&amp;#39;s, xray and all manner of other scanning and computer wizardry. He can also generate just about anything it seems from a 3D molecular imaging device, has a super pursuit mode (now called attack mode) and the morphing is truly cool even if totally unbelievable allowing Kit to transmogrify into all manner of different vehicles to match the terrain or simply to blend in.&lt;/p&gt;&lt;p&gt;I still do not think the car looks as cool as the original trans-am, but this is far less of an annoyance now that everything else is cool and you can accept the fact that the car is meant to be able to blend in and not stick out like a sore thumb.&lt;/p&gt;&lt;p&gt;The car aside, the cast are also pretty good, the new Michael Knight (it is explained why he has the same name) is a proper ass kicking ex-marine agent type, so the fight scenes are far more exciting and action film like instead of the lack lustre unrealistic fights from the old 80&amp;#39;s series that just made Hasslehoff seem like a smooth talking James Bond wannabe. &lt;/p&gt;&lt;p&gt;Back at HQ there are the genius geeks who keep Kitt up and running and help Mike on his missions with all their gadgetry and ability to remotely hack into just about anything, as well us providing us with eye candy as most of them just happen to be extremely hot babes who of course all lust after Michael Knight, lucky guy.&lt;/p&gt;&lt;p&gt;Everything in this new series is totally unbelievable and technically impossible by any stretch of the imagination, but as long as you are not anal about this and are not one of those people that needs to over analyse everything instead of simply enjoying it, it is great fun to watch whether you were a fan of the original series or not and is I think a great reboot of a classic series for the 21st century and is at least for me a must watch programme each week.&lt;/p&gt; 
				</description>
				
				<category>Jibber Jabber</category>				
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Wed, 22 Jul 2009 13:53:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/7/22/Knight-Rider-Reboot</guid>
				
			</item>
			
			<item>
				<title>ColdFusion 9 Tutorials and Resources</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/7/17/ColdFusion-9-Tutorials-and-Resources</link>
				<description>
				
				&lt;p&gt;I was about the start compiling a list of useful links to info and tutorials for CF9 and CFBuilder, but it seems someone has beat me to it, so rather than re-invent the wheel I will just link to this chaps page and save myself some work :-) If you are looking for find out what is new in CF9 and how to do it, this is worth reading.&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#CFLanguageEnhancement&quot;&gt;CFML Language Enhancements Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#CFScriptEnhancement&quot;&gt;CFScript Enhancement Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#CFSAAS&quot;&gt;ColdFusion As a Serveice Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#ORM&quot;&gt;Hibernate-based ORM Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#CFANDMS&quot;&gt;Microsoft SharePoint &amp;amp; Office Interoperability Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#JEEPortlets&quot;&gt;Native JEE Portlets Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#UIControls&quot;&gt;Enhance and New UI Controls Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#Caching&quot;&gt;Advance Caching Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#SolrLucene&quot;&gt;Apache Solr / Lucene Integration Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#ServerManager&quot;&gt;Server Management Tool Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt;    &lt;li&gt;&lt;b&gt;&lt;a href=&quot;http://www.akbarsait.com/cf9tutorials.cfm#FlexAndAIR&quot;&gt;Flex/AIR Integration Tutorials&lt;/a&gt;&lt;/b&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;A few of my favourite new features are below, of course I tend to look at things from a hosts perspective these days rather than a developer seeing as I don&amp;#39;t do a lot of coding anymore.&lt;/p&gt;  &lt;p&gt;Most of these improvements are especially great for me because I actually had discussion with Adobe some years ago about about what improvements needed to be made to ColdFusion to make it more suitable for shared hosting and explained how they needed to work, and these are areas I specifically addressed, so it seems that finally they did listen to me.&lt;/p&gt;  &lt;p&gt;&amp;nbsp;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href=&quot;/enclosures/cf9undl.png&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;/enclosures/cf9undl_image_thumb.png&quot; style=&quot;display: inline&quot; title=&quot;image&quot; alt=&quot;image&quot; align=&quot;right&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;b&gt;View Undelivered Mail        &lt;br /&gt;&lt;/b&gt;This new feature allows you to browse mail sitting in the undelivered folder and then delete or respool them. This is handy for manual checking or on a dev machine. Currently my company has a custom script that automatically respools all undelivered mail for 24 hours, and then deletes them, which is very useful in a shared hosting environment otherwise the undelivered folder regularly fills up. It is a shame Adobe didn&amp;#39;t have the foresight to add this kind of automation as well, but at least the viewer allows an easy way to find missing emails. &lt;/li&gt;    &lt;li&gt;&lt;b&gt;Application Specific Datasources        &lt;br /&gt;&lt;/b&gt;This is a real code saver and somewhat of a security benefit as well. With this new &amp;quot;this.datasource&amp;quot; application property to can set an application wide datasource, thus negating the need to specify the DSN in every query. A full review of this feature can be found on &lt;a href=&quot;http://www.bennadel.com/blog/1642-learning-coldfusion-9-application-specific-data-sources.htm&quot; target=&quot;_blank&quot;&gt;Ben Nadel&amp;#39;s blog&lt;/a&gt;. &lt;/li&gt;    &lt;li&gt;&lt;b&gt;Server Manager        &lt;br /&gt;&lt;/b&gt;ColdFusion 8 introduced server monitoring for single and multiple servers via a Flex based app which provided access to all sorts of ColdFusion internals, alerts, proactive problem management, and more.       &lt;br /&gt;ColdFusion 9 takes this a big step further with a new tool called &amp;quot;ColdFusion Server Manager&amp;quot;. This AIR based application allows you to monitor as many servers as needed (including individual ColdFusion instances on a multi-instance configuration) and even offers pop-up alerts when issues occur, it allows for remote server configuration (define a data source, for example), it also allows for settings to be applied to multiple servers at once, it can clear the template caches, it can upload hot-fixes to one or more servers, and it even allows you to select two ColdFusion servers to compare their configuration settings, highlighting any differences between them.       &lt;br /&gt;Oh, and before you ask, here are answers to the three most commonly asked questions.       &lt;br /&gt;      &lt;br /&gt;      &lt;ol&gt;       &lt;li&gt;No, this is not a separately sold utility, it is part of ColdFusion itself (and installed via a link in the ColdFusion Administrator). &lt;/li&gt;        &lt;li&gt;ColdFusion Server Manager uses APIs added to ColdFusion 9, so no, this will not work with ColdFusion 8 or earlier. &lt;/li&gt;        &lt;li&gt;Adobe have not made any decisions yet as to product edition, so no decision as to whether this is an Enterprise only feature or not. &lt;/li&gt;     &lt;/ol&gt;   &lt;/li&gt;    &lt;li&gt;&lt;b&gt;Server Security&lt;/b&gt;      &lt;br /&gt;One of my big issues has always been ColdFusion&amp;#39;s security, or rather lack thereof. You need the enterprise edition to get security sandboxes and these only sandbox CFML code, if someone writes some Java code into their CFML pages they can completely bypass the sandbox and do whatever they like, which actually makes ColdFusion one of the most insecure application servers out there in a shared hosting environment as PHP, ASP and .NET do not suffer from this problem.      &lt;br /&gt;This has supposedly now been addressed with ColdFusion 9 now allowing you to restrict access to certain JAVA functionality. I have not yet looked into this, and as no-one else seems to have written an article on particular area yet I may as well do so, so a more detailed tutorial ont his subject will be coming soon.&lt;/li&gt;    &lt;li&gt;&lt;b&gt;64bit ColdFusion for all&lt;/b&gt;      &lt;br /&gt;Up till now, 64bit ColdFusion has only been available to ColdFusion Enterprise customers. This will (thankfully) change in &lt;a href=&quot;http://labs.adobe.com/wiki/index.php/Centaur&quot;&gt;ColdFusion 9&lt;/a&gt;, and all customers will have access to 32bit or 64bit versions, regardless of edition. Groovy!&lt;/li&gt; &lt;/ul&gt; 
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<category>ColdFusion</category>				
				
				<pubDate>Fri, 17 Jul 2009 15:33:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/7/17/ColdFusion-9-Tutorials-and-Resources</guid>
				
			</item>
			
			<item>
				<title>Windows Live Writer overwrites images</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/7/2/Windows-Live-Writer-overwrites-images</link>
				<description>
				
				&lt;p&gt;I have just noticed a very annoying bug in Live Writer, thus why you have have received multiple copies of my last posts. After I had posted those last 2 articles, I noticed they both had the same images, even though they clearly didn&apos;t when I posted them. It seems that if you paste in an image from the clipboard Live Writer will name it image.png by default and the thumbnail will be image_thumb.png, it will not create a unique filename, thus will simply overwrite any existing images with the same name, thus messing up all your previous blog posts with images not to mention if you have multiple images in your current post, they will all end up as the same image. &lt;/p&gt;  &lt;p&gt;I presume this bug must have been added to the latest release (2009) as I have not noticed it previously.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I have however found the following temporary fix on the &lt;a href=&quot;http://www.live-writer.net/&quot; target=&quot;_blank&quot;&gt;Windows Live Writer Blog&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;div style=&quot;border-bottom: gray 1px solid; border-left: gray 1px solid; padding-bottom: 4px; line-height: 12pt; background-color: #f4f4f4; margin: 20px 0px 10px; padding-left: 4px; width: 97.5%; padding-right: 4px; font-family: consolas, &amp;#39;Courier New&amp;#39;, courier, monospace; max-height: 200px; font-size: 8pt; overflow: auto; border-top: gray 1px solid; cursor: text; border-right: gray 1px solid; padding-top: 4px&quot;&gt;   &lt;pre style=&quot;border-bottom-style: none; padding-bottom: 0px; line-height: 12pt; border-right-style: none; background-color: #f4f4f4; margin: 0em; padding-left: 0px; width: 100.16%; padding-right: 0px; font-family: consolas, &amp;#39;Courier New&amp;#39;, courier, monospace; border-top-style: none; height: 88px; color: black; font-size: 8pt; border-left-style: none; overflow: visible; padding-top: 0px&quot;&gt;Open HKCU\Software\Microsoft\Windows Live\Writer\Weblogs\{blog-id}\UserOptionOverrides\, where {blog-id} is a GUID. You will have several of these, but should be able to tell the right one by looking at the contents of the key.

Add a new String value with name &#xe2;??fileUploadNameFormat&#xe2;?? (case matters!!) and the value e
{WindowsLiveWriter}/{PostTitle}/{Randomizer}/{AsciiFileName}&lt;/pre&gt;
&lt;/div&gt;

&lt;p&gt;&amp;#160;&lt;/p&gt;

&lt;p&gt;hopefully they will fix this annoying bug very soon.&lt;/p&gt; 
				</description>
				
				<category>Jibber Jabber</category>				
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Thu, 02 Jul 2009 12:27:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/7/2/Windows-Live-Writer-overwrites-images</guid>
				
			</item>
			
			<item>
				<title>Email archiving UK law, regulations and implications for business</title>
				<link>http://russ.michaels.me.uk/index.cfm/2009/2/24/Email-archiving-UK-law-regulations-and-implications-for-business</link>
				<description>
				
				&lt;p&gt;The use of business email has grown exponentially over a relatively short period of time, bringing with it the huge advantages of worldwide, cost-effective, easy and near-instantaneous communication. But as all those involved in the management of IT systems know, the growth in email usage has brought its own challenges.&lt;/p&gt;&lt;p&gt;  [More]
				</description>
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Tue, 24 Feb 2009 10:08:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2009/2/24/Email-archiving-UK-law-regulations-and-implications-for-business</guid>
				
				<enclosure url="http://russ.michaels.me.uk/enclosures/emailarchiving.pdf" length="54994" type="application/pdf"/>
				
			</item>
			
			<item>
				<title>Firefox tops list of 12 most vulnerable windows apps</title>
				<link>http://russ.michaels.me.uk/index.cfm/2008/12/16/Firefox-no1-most-vulnerable-windows-app</link>
				<description>
				
				&lt;p align=&quot;justify&quot;&gt;&lt;img src=&quot;http://blogs.zdnet.com/security/images/firefox_mozilla.jpg&quot; style=&quot;margin: 0px 15px 0px 0px&quot; alt=&quot;Firefox tops list of 12 most vulnerable apps&quot; align=&quot;left&quot; border=&quot;0&quot; height=&quot;115&quot; hspace=&quot;17&quot; width=&quot;104&quot; /&gt;Mozilla&amp;#39;s Firefox browser has earned the undesirable title of the most vulnerable software program running on the Windows platform. Something that will probably dismay most web developers, as it is the browser of choice for most of them due to its superior debugging capabilities. I would imagine this is also a shock to most of you Internet Explorer haters as well, especially as IE is not even on the list.&lt;/p&gt; &lt;p align=&quot;justify&quot;&gt;According to application white-listing vendor Bit9, Firefox topped the list of 12 widely deployed desktop applications that suffered through critical security vulnerabilities in 2008.&amp;nbsp; These flaws exposed millions of Windows users to remote code execution attacks. &lt;/p&gt;&lt;p align=&quot;justify&quot;&gt;The other applications on the list are all well-known and range from browsers to media players, to VOIP chat and anti-virus software programs.&amp;nbsp; Here&amp;acirc;&amp;euro;&amp;trade;s Bit9&amp;acirc;&amp;euro;&amp;trade;s dirty dozen: &lt;/p&gt;&lt;p align=&quot;justify&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt; &lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Mozilla Firefox:&lt;/b&gt;&amp;nbsp; In 2008, Mozilla patched 10 vulnerabilities that could be used by remote attackers to execute arbitrary code via buffer overflow, malformed URI links, documents, JavaScript and third party tools. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Adobe Flash and Adobe Acrobat:&lt;/b&gt;&amp;nbsp; Bit9 listed 14 flaws patched this year that exposed desktops of arbitrary remote code execution via buffer overflow,&amp;acirc;&amp;euro;&amp;oelig;input validation issues&amp;acirc;&amp;euro;? and malformed parameters. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;EMC VMware Player,Workstation and other products:&lt;/b&gt;&amp;nbsp; A total of 10 bugs introduced risks ranging from privilege escalation via directory traversal, ActiveX buffer overflows leading to arbitrary code execution and denial of service. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Sun Java JDK and JRE, Sun Java Runtime Environment (JRE)&lt;/b&gt;:&lt;br /&gt;Inability to prevent execution of applets on older JRE&amp;nbsp; release could allow remote attackers to exploit vulnerabilities of these older releases. Buffer overflows allowing creation, deletion and execution of arbitrary files via untrusted applications.&amp;nbsp; 10 patched vulnerabilities listed. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Apple QuickTime, Safari and iTunes: &lt;/b&gt; In QuickTime, the list includes nine vulnerabilities that allow remote attackers to execute arbitrary code via buffer overflow, or cause a denial of service (heap corruption and application crash) involving malformed media files, media links and third party codecs.&amp;nbsp; The Safari for Windows browser was haunted by three flaws that could be lead to arbitrary code execution and&amp;nbsp; denial of service involving JavaScript arrays that trigger memory corruption.&amp;nbsp; Apple&amp;acirc;&amp;euro;&amp;trade;s iTunes software was susceptible to a remote improper update verification that allowed man-in-the-middle attacks to execute arbitrary code via a Trojan horse update. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Symantec Norton products (all flavors 2006 to 2008):&lt;/b&gt; Stack-based buffer overflow in the AutoFix Support Tool ActiveX exposed Windows users to arbitrary code execution. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Trend Micro OfficeScan:&lt;/b&gt; A total of four stack-based buffer overflows that opened doors for&amp;nbsp; remote attackers to execute arbitrary code. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Citrix Products:&lt;/b&gt; Privilege escalation in DNE via specially crafted interface requests affects Cisco VPN Client, Blue Coat WinProxy, SafeNet SoftRemote and HighAssurance Remote. Search path vulnerability, and buffer overflow lead to arbitrary code execution. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Aurigma Image Uploader, Lycos FileUploader:&lt;/b&gt;&amp;nbsp; Remote attackers can perform remote code execution via long extended image information. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Skype:&lt;/b&gt;&amp;nbsp; Improper check of dangerous extensions allows user-assisted remote attackers to bypass warning dialogs.Cross-zone scripting vulnerability allows remote attackers to inject script via Internet Explorer web control. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Yahoo Assistant:&lt;/b&gt; Remote attackers can execute arbitrary code via memory corruption. &lt;/div&gt; &lt;/li&gt;&lt;li&gt; &lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Microsoft Windows Live (MSN) Messenger:&lt;/b&gt; Remote attackers are allowed to control the Messenger application, &amp;acirc;&amp;euro;&amp;oelig;change state,&amp;acirc;&amp;euro;? obtain contact information and establish audio or video connections without notification. &lt;/div&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p align=&quot;justify&quot;&gt;&amp;nbsp; &lt;/p&gt;&lt;p align=&quot;justify&quot;&gt;See Bit9&amp;acirc;&amp;euro;&amp;trade;s &lt;a href=&quot;http://www.bit9.com/files/Vulnerable_Apps_DEC_08.pdf&quot;&gt;full report&lt;/a&gt; (.pdf) for information on how the list was put together, including criteria for inclusion.&lt;/p&gt; 
				</description>
				
				<category>Jibber Jabber</category>				
				
				<category>News &amp; Gossip</category>				
				
				<pubDate>Tue, 16 Dec 2008 17:05:00 --0100</pubDate>
				<guid>http://russ.michaels.me.uk/index.cfm/2008/12/16/Firefox-no1-most-vulnerable-windows-app</guid>
				
			</item>
			</channel></rss>