İşte benim hoşuma giden bazı dilbert'lerden seçmeler:
Diğer favori Dilbert'lerime buradan bakabilirsiniz.
Yazılım ölçümü (İng. software metric) bir yazılımın yada yazılım projesinin ölçebildiğimiz herhangi bir özelliği olarak tanımlayabiliriz.
Peki insanlar ne gibi şeyleri ölçmeyi anlamlı bulmuşlar?Böyle bir çok ölçüm üretmek mümkün.
- Yazılan satır sayısı
- Kodun karmaşıklığı (İng. cyclomatic complexity)
- Her bin satır (KLOC) başına düşen hata (bug) sayısı
- Bir hata tespit edildiğinde onu düzeltmenin ne kadar zaman aldığı
- Testler toplam geliştirme zamanının ne kadarını alıyor?
http://www.benimsitem.com/haber.html?id=156Açık bulunanan site name değişkenini okuyup hiçbir filtreleme yapmadan sayfaya yazdırıyorsa, o zaman bu değerde istenilen kod çalıştırılabilir.
http://www.benimsitem.com/haber.html?id=<script>alert(document.cookie)</script>Genelde cross site scripting açıkları, saldırganın sistemi deneme-yanılma yaparak bulması ile ortaya çıkıyor. Açığın bulunması ile saldırgan, başka bir domainden, açığın bulunduğu domain ve sayfanın bilgilerini, session bilgilerini ve diğer obje değerlerini çalmasına olanak sağlar. (1)
public static String filterForSpecialCharacters( String inputStr ){
String outputStr = inputStr + "";
outputStr = outputStr.replace ( "'", " " );
outputStr = outputStr.replace ( "\"", " " );
outputStr = outputStr.replace ( "%", " " );
outputStr = outputStr.replace ( ";", " " );
outputStr = outputStr.replace ( "(", " " );
outputStr = outputStr.replace ( ")", " " );
outputStr = outputStr.replace ( "&", " " );
outputStr = outputStr.replace ( "+", " " );
outputStr = outputStr.replace ( "<", " " );
outputStr = outputStr.replace ( ">", " " );
return outputStr;
}
1- Introduction
Cross-Site Scripting is one of the main problems of any Web-based service. Since Web browsers support the execution of commands embedded in Web pages to enable dynamic Web pages attackers can make use of this feature to enforce the execution of malicious code in a user’s Web browser. JavaScript is the most commonly used command language in this context. If misused, stealing of authentication information may be possible thus allowing attackers to act under a stolen identity. The attack is based on the possibility to insert malicious JavaScript code into pages shown to other users. Therefore filtering malicious JavaScript code is necessary for any Web application. This paper describes the overall problem and elaborates on the possibilities to filter JavaScript in Web applications. Also a filtering architecture is presented that allows Web application developers to filter JavaScript depending on the application need to reduce the danger of successful Cross-Site Scripting attacks. (1)
2 - Avoiding an Attack
2.1 - Filtering
The basis of this approach is never trust user input and always filter metacharacters ("special" characters) that are defined in the HTML specification. Each input field, including link parameters will be validated for script tags. When found and dependent on the context, the input will be rejected and thus prevent the malicious HTML from being presented to the user. (3)
2.2-) Encoding
Cross-site scripting attacks can be avoided when a Web server adequately ensures that generated pages are properly encoded to prevent unintended execution of scripts. Each character in the ISO-8859-1 specification can be encoded using its numeric entry value. Server side encoding is a process where all dynamic content will go through an encoding function where scripting tags will be replaced with codes in the chosen character set. Generally speaking, encoding is recommended because it does not require you to make a decision about what characters could legitimately be entered and need to be passed through. Unfortunately, encoding all untrusted data can be resource intensive and may have a performance impact on some Web servers.
For More Information:
http://www.ibm.com/developerworks/tivoli/library/s-csscript/
http://www.developer.com/java/article.php/883381
Citation
-----------
(1) http://tr.wikipedia.org/wiki/Cross_site_scripting
(2) Filtering JavaScript to Prevent Cross-Site Scripting - Created by:
EUROSEC GmbH Chiffriertechnik & Sicherheit
(3) http://www.ibm.com/developerworks/tivoli/library/s-csscript/
Linux'de dosyalar içinde toplu "find and replace" işlemi yapmak için oldukça kullanışlı bir komut:
You can do a find and replace on files from the Linux shell using the
findandsedcommands. The first example below shows doing a find and replace only in the current directory while the second example below shows doing a find and replace recursing into subdirectories…
- Replace “www.trendics.com” with “tools.trendics.com” in all html files in the current directory…
find .-maxdepth 1-name "*.html" -type f -exec sed -i 's/www.trendics.com/tools.trendics.com/' {} \;- Replace “www.trendics.com” with “tools.trendics.com” in all text files and all subdirectories…
find . -name "*.txt" -type f -exec sed -i 's/www.trendics.com/tools.trendics.com/' {} \;Here is how this works…
- The dot after the find command specifies to start in the current directory
- The
-maxdepth 1specifies to only include the current directory- The
-name "*.txt"switch specifies to only find txt files- The
-type fspecifies to only match files- The
-exec xyz {} \;specifies to execute xyz for each file where xyz is a sed command specifying to substitute “tools.trendics.com” for “www.trendics.com”
Kaynak: Trendics Blog
// Sistemdeki default seçili dil ne ise ona göre büyük harfe çevrilir.
"illaki".toUpperCase();
// İngilizceye göre büyük harfe çevrilir, bu durumda i->I çevrimi yapılacaktır
"illaki".toUpperCase( Locale.ENGLISH );
// Türkçeye göre çeviri yapılır, bu durumda i->İ çevrimi yapılır.
"illaki".toUpperCase( new Locale("tr","TR") );
Locale.setDefault(new Locale("tr","TR"));
Converts all of the characters in this String to upper case using the rules of the default locale. This method is equivalent to toUpperCase(Locale.getDefault()).
Note: This method is locale sensitive, and may produce unexpected results if used for strings that are intended to be interpreted locale independently. Examples are programming language identifiers, protocol keys, and HTML tags. For instance, "title".toUpperCase() in a Turkish locale returns "T?TLE", where '?' is the LATIN CAPITAL LETTER I WITH DOT ABOVE character. To obtain correct results for locale insensitive strings, use toUpperCase(Locale.ENGLISH).
Yazılımcılar. Sistem yöneticileri. Ayrıca bilgisayarın tuşlarına iyi basan bir takım başka arkadaşlar.
Bunlar modern çağın büyücüleri. İçinden "yahu amma salladın, bu adamların yaptığı gayet gerçek ve bilimsel, büyüyle hokkabazlıkla işleri olmaz" diye geçirenler varsa, haklılar elbet. Ama anlatmaya çalıştığım o değil.
Büyücü dediğiniz adam, herkesin bilmediği şeyleri bilir. Anlaşılmaz dev kitapları vardır. Garip lisanlarda, acayip şeyler konuşur. Bu anlaşılmaz lafları kullanıp "büyü"ler yapar, böylece normal insanların yapmak isteyip de yapamadığı, bazen aklına bilegetiremediği şeyleri yapar. Kendisinden duruma göre az ya da çok korkulur; itiraf edilmese de böyledir.
Yazılımcılar da böyle değil mi? Dev kitaplarımız var... Bizden başkası anlamaz. İş veya sosyal bir toplantıda, iki yazılımcı muhabbete başlarsa, diğerleri hemen muhabbetten kopar. Klavyelerimizin tuşlarına basarak, büyücü, pardon, yazılımcı olmayanların yapmak isteyip de yapamadıkları şeyleri yaparız. Bazen akıllarına gelmeyen şeyleri de. Tek harfinin yanlış söylenmesi felakete yol açan efsanevi büyüler gibi, bizim yazılımların da tek harfinin yanlış olması felaketlere yol açar...
Büyücüyüz yani.
Tabii, işin bir de içyüzü var. O da efsanenin büyücülerine benziyor. Yazılımcı, sistem yöneticisi falan olabilmek için, şöyle yerden başlasa adam boyunu geçecek kadar kitap okumuş olmak gerekiyor. Okumak da yetmiyor. Deneyim gerekiyor. Pek çok büyünün elde patlamış olması gerekiyor. Daha fenası, gün geçtikçe işler kolaylaşmıyor, zorlaşıyor. Bugün itibarıyla bilinmesi gereken teknoloji miktarı, on yıl öncesine göre kat kat daha fazla.
İş zor iş. Yanlış yapıldığından falan da değil. Tanım gereği zor iş. Bunu söyleyen ben değilim. (Yani ben de söylüyorum da, tek söyleyen ben değilim.) Bu işi 30 yıl, 40 yıl yapmış, halen yapan büyücü abiler. Elbette, herkes kendi işini zor sayar. Ama bu işin zor olduğunun matematiksel delilleri var!
Yazılımcıları yönetmek de zordur. Entreesan insanlardır bunlar. Pek çok insanın aksine, tipik bir yazılımcı, işten, hatta çok işten kaçmaz. Fakat, yaptığı işe inanması gerekir. Kaliteli bir şeyler üretebildiği zaman mutlu olur. Başını sallayıp maaşını almaktan hoşlanmaz, doğru yerde, doğru sebeplerden çalıştığını bilmek, gittikçe daha iyi bir "büyücü" olduğunu hissetmek çoğu zaman maaştan daha büyük ağırlık taşır. Yine para için değil! İyi büyücü olmak için.