Kelly's Twits

End of American manned presence in space…

The last shuttle mission has flown and, with nothing to replace it, the U.S. manned presence in space has ended with it.  The shuttle astronauts in the picture below are the last ones we will ever see.

shuttle_astro.jpg

Continue reading End of American manned presence in space…

Mad skillz…

I watched this video today, and am once again amazed at what “ordinary” humans can do if they put their minds to it:

I particularly liked the “open the Pringles can, bounce the lid off two corners of the room while eating a chip from the container, and catch the lid when it bounces [...]

Robots may be fast, but humans still amaze me

I was watching a demonstration video of a robotic vibraphone today on Gizmodo. It plays “Flight of the Bumblebee”, which is already a pretty fast piece, but does it a bit faster than normal. Impressive, but when you realize that it accomplishes this with independent actuators for each note (effectively having dozens of “hammers” where a [...]

Newsflash: people who don’t like computers prefer non-geeky workspaces

According to a recent study at the University of Washington, people who aren’t really interested in computing science are even less interested if asked about it in a room with science fiction paraphernalia, games, and soft drink cans. Apparently some of these non-technically-inclined people are women. Glory be, we have a great discovery!

Actually, not really, at least not in my uneducated opinion, with which you are free to disagree…   

Continue reading Newsflash: people who don’t like computers prefer non-geeky workspaces

The internet is… a man… with strange thumbs

After years of thinking the Internet was a collection of tubes, we now have a more definitive explanation, in video form…

This video is created, as it says, based on snippets extracted out of context from a BBC program…amazing how something so basically childish can be so [...]

Ewoks gone mad

The folks on the Today Show have discovered a little known fact about the Ewoks from Star Wars. They really can’t handle their booze very well…

Apparently the folks inside the Ewok costumes really were drunk and, as it was a live TV program, the producers decided to just go with it. Credit where credit is due, [...]

Apple really likes those adjectives…

I found this on Gizmodo today, and when I watched the video I couldn’t help laughing out loud…

It is really awesomely incredibly great and unbelievable!

The video is extracted from the most recent (September 9th) Apple event, which was focussed on what I can only describe as a completely boring list of iPod announcements. There was nothing [...]

WordPress SQL injection hack: watch for=> %&({${eval(base64_decode($_SERVER[HTTP_REFERER]))}}|.+)&%/

If you are running a WordPress based blog like I am and suddenly notice your post URLs have something “extra” appended (see the subject line), your blog has been hacked.

You can read more about it here (thanks, UCLABoyz, thanks schang!), where you will also find guidance regarding cleaning the problem up. Unfortunately, it appears that the hack works on all versions of WordPress up to and including the most recent.

I have BadBehavior installed on my blog, and so it was rejecting the URLs with this addition which I *think* would be thwarting the hackers involved: they hadn’t been able to create an administrative user. Unfortunately, it also meant none of my blog posts were working properly until I noticed the problem and corrected it.

Hopefully WordPress will issue a fix for this soon- in the mean time, keep an eye on your URLs, WordPress bloggers!

UPDATE: Another link to a lengthy thread regarding this hack on the WordPress.org site. What is interesting here is the apparent vector: a weakness in the WordPress code, apparently up to and including the most recent release, that permits an ordinary subscriber (i.e.: not an administrative user) to run some administrator features e.g.: changing the permalinks.

UPDATE #2: it appears that updating to the most recent version of WordPress (2.8.4) removes the “double slash” vector for running some admin commands (notably permalink.php). This fix was apparently added somewhere between WordPress version 2.8 and 2.8.4.

I’ve included some extracts from my server logs and further thoughts below…

  

Continue reading WordPress SQL injection hack: watch for=> %&({${eval(base64_decode($_SERVER[HTTP_REFERER]))}}|.+)&%/

Do you wanna date my avatar?

I have caught a number of episodes of The Guild, a web-based video series since it first appeared a year or so ago. Imagine a soap opera based on the web-camera confessions of a young woman geek who is a member of a massively multiplayer online game guild, and you have the basic idea.

Recently The Guild [...]

Robotic dexterity

The progress of robotics over the last few decades has seemed fairly slow to me. Robots today at their best seem to shuffle or stumble along like zombies, their movements more scripted and controlled than dynamic or lively. I watched a video today, however, that makes me feel like some real progress is actually being made.

Here [...]