<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Djarot Studio &#187; Internet &amp; Technology</title>
	<atom:link href="http://www.djarot.com/category/internet-technology/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.djarot.com</link>
	<description>Art of Simplicity</description>
	<lastBuildDate>Thu, 09 Feb 2012 00:29:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>		<item>
		<title>WordPress 2.8.6 is OUT, with the Newest Security Release</title>
		<link>http://www.djarot.com/wordpress-286-is-out-with-the-newest-security-release/</link>
		<comments>http://www.djarot.com/wordpress-286-is-out-with-the-newest-security-release/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 05:20:04 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Programming Stuff]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[2.8.6]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[cms]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploited]]></category>
		<category><![CDATA[sanitize]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[wordpress 2.8.6]]></category>
		<category><![CDATA[XSS vulnerability]]></category>

		<guid isPermaLink="false">http://www.djarot.com/?p=350</guid>
		<description><![CDATA[Just got a buzz from a buddy of mine about wordpress 2.8.6 release. My first impression was whoa.. already? I still can feel the feels in my fingers &#8211; I coded a project built on wordpress 2.8.5, and it is now in the past! Well yea, wordpress known as one of the open source cms [...]]]></description>
			<content:encoded><![CDATA[<p>Just got a buzz from a buddy of mine about wordpress 2.8.6 release. My first impression was whoa.. already? I still can feel the feels in my fingers &#8211; I coded a project built on wordpress 2.8.5, and it is now in the past! </p>
<p>Well yea, wordpress known as one of the open source cms vendor with really really good care of their security, so if they release something new, it must&#8217;ve been a security fix, or features improvements. Version 2.8.6, is one of its release from their security fix outlet.</p>
<p><strong>There are 2 Security Fixes:</strong></p>
<p>From official wordpress blog regarding this <a href="http://wordpress.org/development/2009/11/wordpress-2-8-6-security-release/" target="_blank" rel="nofollow" title="WordPress 2.8.6 Security Release">WordPress 2.8.6 Security Release</a> :</p>
<blockquote><p>2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.</p></blockquote>
<p>Plain english would be read like this : There re 2 security problems which could be exploited by one of your registered user &#8211; with posting privileges and logged in. So actually, this security problem is an exploitable problem by someone who&#8217;s already in (logged in as a registered user), and has posting privilege (authors, editors, or other user with custom privileges with posting ability in it.) Long story short : Exploitable by inside man.</p>
<p><strong>The 2 Security Problems Are</strong><br />
<span id="more-350"></span><br />
1. An XSS vulnerability in Press This discovered by Benjamin Flesch.<br />
2. An issue with sanitizing uploaded file names that can be exploited in certain Apache configurations, discovered by Dawid Golunski. </p>
<p>Be advise, IF you guys have a blog with multiple authors, and there&#8217;s a possibility one of them has a possibility to go &#8220;bad&#8221;, this release is definitely recommended for you.<br />
Alrite.. catch up with you later! <img src='http://www.djarot.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/wordpress-286-is-out-with-the-newest-security-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>One Way Link Versus Reciprocal Link</title>
		<link>http://www.djarot.com/one-way-link-versus-reciprocal-link/</link>
		<comments>http://www.djarot.com/one-way-link-versus-reciprocal-link/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 15:20:28 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Internet & Technology]]></category>
		<category><![CDATA[SEO]]></category>
		<category><![CDATA[Backlinks]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[link building]]></category>
		<category><![CDATA[offpage seo]]></category>
		<category><![CDATA[one way links]]></category>
		<category><![CDATA[onpage seo]]></category>
		<category><![CDATA[Pagerank]]></category>
		<category><![CDATA[reciprocal link]]></category>
		<category><![CDATA[serp]]></category>

		<guid isPermaLink="false">http://www.djarot.com/?p=299</guid>
		<description><![CDATA[The best link building practice would always be the natural way. Create some quality contents, created for the people and not search engines, and if it add values and people who read it find 'em useful, you 'll get a link vote for your site. The second best is, link exchange that avoid scheme #3. Reciprocal part and the most important, the excessive part. It 's the one way link building. It always is being considered as natural links, and won 't be counted as an attempt to manipulate search engine rankings. The why is, it works just exactly the natural way.  […] <a href="#" title="" rel="bookmark">[ &#8594; ]</a>]]></description>
			<content:encoded><![CDATA[<p>I got a text message from a buddy this morning, asking for something that kinda short in length &#8211; in a matter of sentences &#8211; but not exactly short in efforts. He said, &#8220;Could you help my site to be atleast at page 5 of google search result for this keyword?&#8221; He included the keyword on that message. Pretty short message. Not even 3 sentences.</p>
<p>I &#8216;m not really an SEO expert, and never wanna be, though I can&#8217;t help if someday I &#8216;m becoming one. But this kind of text messages keep coming at my cell atleast once a month. It triggered me to start thinking, an SEO consultant would be one great income stream for me. Nah, I &#8216;ll keep that as a lending hand sake as usual. Well, SEO is a self doable thingy. It &#8216;s just took time, and lotsa efforts. I never believe if I met someone who always saying it out loud, SEO is a hard thing to do. Nope. It &#8216;s not. Keeping up the effort is the hard part.</p>
<p><strong>Getting in to SEO</strong></p>
<p>Okay so, getting into first page for certain keyword on search engine result position is always been the struggle of the century for most webmasters. Me, no exception. The real core of this are always 2 things. </p>
<p>First, On site &#8211; or some say &#8211; On page optimization. Last is Off page optimization. The first is the part when you &#8216;re optimizing your site &#8216;s composition from top to toe, to be optimized for certain keyword. There &#8216;re some parts of your site pages that need to be optimized. Title, meta keywords and descriptions, Headings, where to bold italized or underlined, how to play with alt attribute for image tag, and so on. I &#8216;ve mentioned this once, in my previous post, you &#8216;d find it in related resources just below this post. </p>
<p>Last, would be the Off site optimization. It &#8216;s all about the link building. How to get as much votes as possible for your site, or site &#8216;s pages. You should &#8216;ve heard link exchange, reciprocal link exchange, one way links, three way links, and such terms. Those are some link building practices all in all to get as much votes as possible from others.</p>
<p><strong>Link Building and Quality Guidelines</strong></p>
<p>Just for your real basic consideration, the volume war was over. Wake up buddy, It is 2009. The one who gets the most backlinks not always win. The one who got the most relevant does. You should always refer to G&#8217;s Quality Guidelines before you take it into an action.<br />
<span id="more-299"></span></p>
<blockquote><p>Your site&#8217;s ranking in Google search results is partly based on analysis of those sites that link to you. The quantity, quality, and relevance of links count towards your rating. The sites that link to you can provide context about the subject matter of your site, and can indicate its quality and popularity. However, some webmasters engage in link exchange schemes and build partner pages exclusively for the sake of cross-linking, disregarding the quality of the links, the sources, and the long-term impact it will have on their sites. This is in violation of Google&#8217;s webmaster guidelines and can negatively impact your site&#8217;s ranking in search results.</p></blockquote>
<p><u>Here &#8216;re the Link Schemes you should all avoid</u> :</p>
<ol>
<li>Links intended to manipulate PageRank</li>
<li>Links to web spammers or bad neighborhoods on the web</li>
<li>Excessive reciprocal links or excessive link exchanging (&#8220;Link to me and I&#8217;ll link to you.&#8221;)</li>
<li>Buying or selling links that pass PageRank</li>
</ol>
<p><strong>So, Which is Best?</strong></p>
<p>The best link building practice would always be the natural way. Create some quality contents, created for the people and not search engines, and if it add values and people who read it find &#8216;em useful, you &#8216;ll get a link vote for your site.</p>
<p>The second best is, link exchange that avoid scheme #3. Reciprocal part and the most important, the excessive part. It &#8216;s the one way link building. It always is being considered as natural links, and won &#8216;t be counted as an attempt to manipulate search engine rankings. The why is, it works just exactly the natural way.</p>
<p>Not much I could say for y &#8216;all why one way links is best then reciprocal as it&#8217;s pretty obvious, straight forward and self explanatory, right after you read that quality guidelines. So what you should really take into an account is start to out your links off of some bad neighborhoods if it &#8216;s already out there by requesting a removal, and start to build your linking the natural way by writing great quality contents meant for this internet community, taking a look at free one way links services offer, and create your own related link neighborhood cleanly.</p>
<p>Lastly, but it always is not the least, it &#8216;s a self doable thingy. <em>So why bother to pay somebody else to do so?</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/one-way-link-versus-reciprocal-link/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Optimizing Credit and Debt Consolidation Site for 1st page of SERP?</title>
		<link>http://www.djarot.com/optimizing-credit-and-debt-consolidation-site-for-1st-page-of-serp/</link>
		<comments>http://www.djarot.com/optimizing-credit-and-debt-consolidation-site-for-1st-page-of-serp/#comments</comments>
		<pubDate>Sun, 24 May 2009 16:33:39 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Internet & Technology]]></category>
		<category><![CDATA[SEO]]></category>
		<category><![CDATA[The Mind]]></category>
		<category><![CDATA[debt consolidation site optimization]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[optimize]]></category>
		<category><![CDATA[Search Engine]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.djarot.com/?p=303</guid>
		<description><![CDATA[This evening pretty much the same as any other evening I have all this time. A pack of cig, a can of cold nescafe original, my wireless keyboard and mouse, my 1920x1200 screen, another codes to write, Satriani or Vai 's songs all around my desk atmosphere. Somebody knocked on the front door and it happened to be one of my favorite bone-head buddy. He 's a coder and a search engine marketer, yet always talk like there 's no tomorrow. ]]></description>
			<content:encoded><![CDATA[<p>This evening pretty much the same as any other evening I have all this time. A pack of cig, a can of cold nescafe original, my wireless keyboard and mouse, my 1920&#215;1200 screen, another codes to write, Satriani or Vai &#8216;s songs all around my desk atmosphere. Somebody knocked on the front door and it happened to be one of my favorite bone-head buddy. He &#8216;s a coder and a search engine marketer, yet always talk like there &#8216;s no tomorrow. </p>
<p style="float:right;margin:0 0 0 10px;padding:0;"><img src="http://www.djarot.com/images/not-when-im-awake.jpg" alt="Deadpool" title="" /></p>
<p>You guys know Wade Wilson, right? Which later becoming Deadpool &#8211; which is the Weapon XI, from X-men Origin &#8211; Wolverine 2009 big screen? This buddy of mine got the exact speedy tongue just like Wade. Sorta make me dizzy hearing &#8216;em mumbling around about everything and anything that just floated out of his mind. He &#8216;s even got this same answer as Wade every time ones got tired of it and shout to shut him up. &#8220;Not When I &#8216;m awake&#8221;. </p>
<p>But, this evening is a different story. I wont get tired of his speaky thingy he &#8216;d shoot. As I &#8216;d keep him busy with this some sorta challenge I got this morning in my mailbox. I &#8216;ve mentioned previously, I &#8216;m not really into Search engine optimization and such, not even an SEO analyst or make a living hourly by it. But these kind of emails keep coming in and yeah, I always try to do my best to respond &#8216;em. This email was asked my service &#8211; while I never really offer any SEO or SEM service &#8211; to optimize his Credit and debt consolidation site. I giggled a bit when this one coming in this morning. Not that this subject is my fave, no, it&#8217;s just.. it finally arrives, the real &#8211; like real real &#8211; moment to give this Weapon XI buddy of mine a real play. Well he &#8216;s always mumbling around about this mojo thingy he &#8216;s got to optimize any type of site quoted to his desk &#8211; while I never really see any live prove of &#8216;em. Ha, this is it.</p>
<p>He sit, grabbed my cig pack, I quickly grab my nescafe-original-can to avoid him grabbing it.<br />
<span class="talk">&#8220;So bud, what&#8217;s goin on with ya this evening with Vai&#8217;s Lotus Feet inside your head?&#8221;</span> Hah, he shoot me first.<br />
<span class="talk">&#8220;You know, same old same old, code this code that, kinda sorta..&#8221;</span> I shoot back,<br />
<span class="talk">&#8220;Hey, you know what, I got this exact cup-of-coffee of yours, thought you &#8216;d interested. SEO thingy, a Credit and debt consolidation site owner wanna make his site to the first page search engine position result for this debt consolidation keyword. Wanna take a look at it?&#8221; </span><br />
He replied quickly, <span class="talk">&#8220;Hell yea I wanna look at it.&#8221;</span></p>
<p>I shoot back perfectly, one bullet only, a head-shot.</p>
<p style="float:left;margin:0 5px 0 0;padding:0;"><img src="http://www.djarot.com/images/seo-for-credit-niche-site2.jpg" alt="SEO for Credit Niche site" title="" /></p>
<p>I show him the email, he read it really-really carefully, while behind him, I can&#8217;t help my giggles. <span class="talk">&#8220;Yup, this one definitely my daily cup.&#8221;</span> He finally sat back to his chair. </p>
<p><span class="talk">&#8220;Wanna work on it? I &#8216;ll deal with the pricing and stuff with the client. Will make sure you get enough cut. I know your price.&#8221;</span> I &#8216;m sitting back to my chair. <span class="talk">&#8220;Sure thing, on it.&#8221;</span> He replied.</p>
<p><span class="talk">&#8220;So what &#8216;s the plan? Wanna share your tipsy tricks? You know you &#8216;re way way above my ceiling in a matter of SEO thingy. Is it hard? Optimizing Credit and Debt Consolidation Site?.&#8221;</span> I &#8216;m starting the spread of my spider web with his fave bait &#8211; flattery. </p>
<p>He bite, and here comes his secret to optimize credit and debt consolidation site.</p>
<p><strong>1. SEO is Ain&#8217;t an Overnight Service.</strong><br />
<span id="more-303"></span><br />
&#8220;We ll, not really. First thing you need to definitely bold and underlined for this client is, there &#8216;re no such thing as instant in SEO. Everything should be done in a natural way. And that, took times and efforts. If he ain&#8217;t got both, that &#8216;s exactly why my service is around.</p>
<p><strong>2. There &#8216;re Only 3 Search Engines in Planet Earth.</strong></p>
<p>&#8220;Have you ever heard about some services that offer this auto submit to 1000 search engines and such?&#8221; He asked and light up another cig. &#8220;Uh huh, heard &#8216;em over and over again.&#8221; I replied lightly. &#8220;Alrite, mark this one&#8221;, he said, &#8220;In this planet there &#8216;re only 3 Search engines only. Which is Google, Yahoo and Live &#8211; some still mentioned it as its old name, MSN. While it&#8217;s common public miss-understand thing.&#8221; I &#8216;m a bit shocked with this one. Seriously, I do. He saying it out loud, plus, no paused. &#8220;So what about the others, such as askdotcom, answersdotcom, aol blah blah blah? Aren&#8217;t they also search engines.&#8221;</p>
<p>&#8220;Nope. They &#8216;re all using the same data center, which is either its Google&#8217;s, Yahoo&#8217;s, or Live&#8217;s. And do notice I always mentioned this big 3 on the same exact order. It &#8216;s the exact order or those 3 in a matter of how strong they are dominating this planet&#8217;s search queries.&#8221; He said it with a flat face. I was like, huh? And then completely numb. Well, he got the point. So he &#8216;s not making it up if in his ops search engine in this planet earth is Google, Yahoo and Live. Not really interested to ask him about what he call for the others.</p>
<p><strong>3. On site / On Page Optimization is the Base</strong></p>
<p>&#8220;Okay, the next buddy, would be your thing. The on-site codes. All things SEO should be started from the site. The site it self should be coded to optimize and maximized to help search engine&#8217;s crawlers to read and collect data from our site. I wont tell you the how on this, as in a matter of web coding, you &#8216;re the man &#8211; I &#8216;m not. Still see some websites being coded wrongly from the seo point of view, titles not maximized and static, headers being coded with no heading, and stuff. Really bad. So Not Bold. So I guess, the very first step for this credit card debt site is yours to re-code it.&#8221; He explained. &#8220;Gotcha,&#8221; I replied shortly. The whole onsite coding to optimize the seo thingy not really amazed me. I &#8216;m on this field for a long long time. I got it on my fingers already. What amazed me the most is, he tells me all those above with one single breath! Sorta reminds me how Ace Ventura do his thing when he concluded one case.</p>
<p><strong>4. Unique Content, was and Still IS the King.</strong></p>
<p>From this point I &#8216;ll cut the conversation style of writing to skip all of his real words and all of our activities while we &#8216;re on it to save the space. He then explaining what &#8216;s next after the site is done coded. It &#8216;s the content. He bold &#8211; highlite &#8211; and underline it. This credit and debt consolidation site should have unique contents, not copies from others, written for visitors and internet people around the globe, not for the search engine. Yup you might &#8216;ve heard this one also as in Google guidelines.</p>
<p><strong>5. Link Building</strong></p>
<p>This would be the closing part which is the part which conclude all the works. Included within are socializing, building social reputation, creating new link neighborhood, connecting to the same niche such debt consolidation loans, credit card debt relief solution, debt consolidation, loans, personal loans and other related niches, keeping this site linking within this safe and related neighborhood, and manage it for some certain time period to analyze how the link network created and grows.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/optimizing-credit-and-debt-consolidation-site-for-1st-page-of-serp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Quick Tips Designing Your Booklet Printing Cover</title>
		<link>http://www.djarot.com/5-quick-tips-designing-your-booklet-printing-cover/</link>
		<comments>http://www.djarot.com/5-quick-tips-designing-your-booklet-printing-cover/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 15:24:25 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Graphic Design]]></category>
		<category><![CDATA[Internet & Technology]]></category>
		<category><![CDATA[Booklet]]></category>
		<category><![CDATA[Booklet Printing]]></category>
		<category><![CDATA[Catalog]]></category>
		<category><![CDATA[Cover Design]]></category>
		<category><![CDATA[Pamphlet]]></category>

		<guid isPermaLink="false">http://www.djarot.com/?p=301</guid>
		<description><![CDATA[When it comes to design stuff, it always has this need to be unique. Text, layout, graphics, shapes, colors, and such thing. It applies also to booklet printing cover design. Each type has each own uniqueness. It should. For booklets, cover always reveal its professionalism level. And this pretty much the part that would determine consumers interested to read all information carried inside or put it away. […] <a href="#" title="" rel="bookmark">[ &#8594; ]</a>]]></description>
			<content:encoded><![CDATA[<p>You know what this tiny lil thing called booklet printing, right? A small book, pretty similar to a catalog, informational pamphlet, training manuals, program overviews, travel guides, or operational manual? We live our life everyday with this kind of thing. I bet not much of us know exactly what this tiny little thingy called. </p>
<p style="float:right;text-align:right;margin:0 0 0 10px;padding:0;"><img src="http://www.djarot.com/images/booklet-cover-design.jpg" alt="Booklet Printing" title="" /></p>
<p><em>My neighbors don&#8217;t.</em></p>
<p>When it comes to design stuff, it always has this need to be unique. Text, layout, graphics, shapes, colors, and such thing. It applies also to booklet printing cover design. Each type has each own uniqueness. It should. For booklets, cover always reveal its professionalism level. And this pretty much the part that would determine consumers interested to read all information carried inside or put it away.</p>
<p>No, I &#8216;m not gonna write about how to create high quality fancy graphics and some techniques on how to do that. It &#8216;s about how to create your Booklet printing cover that would catch the consumer &#8216;s eyes and interest. Which would lead them to un-cover the cover and get all things carried inside un-covered. Yeah, I mean to read it.</p>
<p><strong>1. Spend the Time.</strong></p>
<p>All things design need its own milestone. Regardless what type of design you &#8216;re working on. Each ideas, the seek of the perfect colors, the catchiest layouts, yet strongest typography possible. It needs time. So spend as much time as it needs. Don&#8217;t create things half perfect. Always work your best.</p>
<p><strong>2. Typographical Thingy</strong></p>
<p>Other than all the fancy graphic stuff, Typography still RULE. Choose letters with flags which joining the letter such Times New Roman, Georgia or serif fonts, for your cover. Less fancier, but for the goal of easier to read and eye catchy, this would be your first choose. Make it large, and stands out from other smaller texts.</p>
<p><strong>3. Engaging Image</strong></p>
<p>It would be useless creating a booklet cover with no image on it. You need to. Always add image element to your cover design which would be the accurate portrays of the booklet subject. SO it need to be engaging and accurately accurate. Feature items, for example. Some related animal photos if the booklet is all about protecting the almost extinct species. Include some tags for your images, that would encourage readers to found out more, look inside, and read the booklet.</p>
<p><strong>4. Back Cover Matters</strong><br />
<span id="more-301"></span><br />
Yeah, I type it right, and you read it right. Back cover matters. Readers often glance it before they decide to read or not to read. So, never leave it blank! Don&#8217;t ever. What to put? Well, you know.. a lot. More photos of items or products, some other related images to the subjects, your photograph, your company bio, author &#8216;s bio, organization &#8216;s bio. You can also include contact point for more information, quotations from other supporters or customers, or synopsis of the written subject. See? A lot.</p>
<p><strong>5. Professional Printing Service</strong></p>
<p>Do consider to use professional booklet printing company. It always help to increase your booklet attractiveness. Why so? Well the why would be more into how a commercial printer can always produce smooth images and vivid color printing. Which would always make your booklet the more eye catchy than using a regular office printer. Strong binding, is another plus point of using printing company. The booklet need it strong to hold up some repeated page turning over and over and over again. Something you can&#8217;t find at regular office or home.<br />
hing that a printing company offers.</p>
<p>So, you &#8216;re aiming the spot where clients or consumers would see for the very first sight. The exterior. Design it and design it good, to build the passion of the consumer to come inside and checking out the interior. </p>
<p>What do you think? Thoughts?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/5-quick-tips-designing-your-booklet-printing-cover/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>10 Things You Must Know to Find the Best Web Hosting</title>
		<link>http://www.djarot.com/10-things-you-must-know-to-find-the-best-web-hosting/</link>
		<comments>http://www.djarot.com/10-things-you-must-know-to-find-the-best-web-hosting/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 07:10:14 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Internet & Technology]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Domain]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Unix Server]]></category>
		<category><![CDATA[Unix-Based Server]]></category>
		<category><![CDATA[web host]]></category>
		<category><![CDATA[web hosting]]></category>
		<category><![CDATA[webhost]]></category>
		<category><![CDATA[Windows Server]]></category>

		<guid isPermaLink="false">http://www.djarot.com/?p=300</guid>
		<description><![CDATA[Yeah, you got it right, it's YET another tips to find web hosting. When you google this keyword, you 'd get upto 9 mils results on how to choose web hosting. So why bother to write something within the same topic? I do this as a personal note. A place where can I bookmark, where the most fun part is it's my own place. With the spirit of Adding some values out of what 's already there out there, I 'm continuing my typing. […] <a href="#" title="" rel="bookmark">[ &#8594; ]</a>]]></description>
			<content:encoded><![CDATA[<p>Yeah, you got it right, it&#8217;s YET another tips to find web hosting. When you google this keyword, you &#8216;d get upto 9 mils results on how to choose web hosting. So why bother to write something within the same topic? I do this as a personal note. A place where can I bookmark, where the most fun part is it&#8217;s my own place. With the spirit of Adding some values out of what &#8216;s already there out there, I &#8216;m continuing my typing.</p>
<p><strong>1. Speed and Reliability.</strong></p>
<p>Web host should be fast, yet reliable. You &#8216;d notice this word &#8220;UPTIME&#8221; mentioned all over webhost provider. It refers to the time when this offered service is functional. Did you even know that you should go for the one with minimum uptime 99%?  You heard me right, 99% is a minimum. Don&#8217;t go anything below it. In fact, 99% is too low. You should actually go with higher than 99.5% uptime. Guarantee always reflect to some amount of compensation. Be sure you got that in hand.</p>
<p><strong>2. To Go or Not To Go With Unlimited</strong></p>
<p>Point 2 here would be about traffic or sometimes called bandwidth which refer to the real state: Data Transfer. How much amount of bytes that your site transferred to your visitor  when they &#8216;re on your site and browse around. To go or Not to go with Unlimited bandwidth offers, that &#8216;s the question. Never believe any &#8220;unlimited&#8221; terms advertised on some web host, as unlimited is ain&#8217;t really unlimited at all in the end. You &#8216;d never be able to use that oh-so-called-unlimited-amount, &#8216;coz it will always hit other limits &#8211; which sometimes specified somewhere else where you could find it being redefined to be &#8220;yeah-it-actually-is-limited&#8221; in some way. Always go for offers that stated clearly how much traffic of some offered packages allows.</p>
<p>Oh, if you still need me to say it out loud, the answer would always be, Not to Go. And buddy, this point is also applied for this popular term called Unlimited Disk Space. End of point 2.</p>
<p><strong>3. A Real Functional Technical support</strong></p>
<p>When I say functional, I mean functional. You know, when you need &#8216;em they around. When You ask things they answered. Do they offered a functional 24/7 support? Refers to 24 hours a day &#8211; 7 days a week. Refers to all year around? You &#8216;ll gonna need a webhost that have staff working on weekends and some national holidays. Things often went wrong at some of the most inconvenient times, and you &#8216;d be surprised that a web hosting provider that advertise 24/7 support doesn&#8217;t really have this kinda support on their end. I &#8216;ve got some worse moments of my own with this kind of provider. I got my self in to a webhost  that run by bunch of salesmen, which have this smooth talky-talk, but not really how to fix problems. So tested it out first.</p>
<p><strong>4. Some Fancy Thingy Called Software</strong><br />
<span id="more-300"></span><br />
I &#8216;m referring to these things : PHP, .htaccess, FTP, MySQL, Perl, SSI, telnet, crontabs, SSH, Email, POP3, Auto Responders, Mail Forwarding. Make sure, you have all that, and you can use each and every one of &#8216;em without asking for approval first. Yeah, there &#8216;re some web hosts don &#8216;t allow you install Perl or PHP scripts, not without their approval. You can&#8217;t really have some SEF (search engine friendly) url or customized Error pages if you don &#8216;t have access to .htaccess. You &#8216;ll gonna need MySQL to create database based kinda of websites. You &#8216;ll gonna need all email functions such your own email address (on your own domain name), auto responder, pop3, forwarding.</p>
<p>I &#8216;m also referring to Shopping Cart and SSL / secure server, if you &#8216;re planning on creating an e-commerce site that need to collect credit card for your payment. Stay clear of web hosting provider that don &#8216;t offer these facilities provided. </p>
<p><strong>5. Your Own Administration Backend</strong></p>
<p>This point here I &#8216;m talking about would be the Control Panel. You may find it being called with some other various names, such Control Panel, Admin Panel, Cpanel and such. A place where you could administer all things about your own hosting account on your own. You don&#8217;t wanna spend your money to a web hosting that whenever you need to create your email address, you should ask their support to do so, right? It &#8216;s one of the most common thing we webmaster do all the time over and over again, and it would be great great hassle if it should be a &#8220;should-wait-on-technical-support&#8221; kinda task.</p>
<p><strong>6. Multiple Domain and Sub-Domains</strong></p>
<p>You should definitely aim for this if, you &#8216;re planning on having multiple domains or multiple sub domains. Check out also, the extra amount &#8211; if there &#8216;re any &#8211; they would charge for this extra feature.</p>
<p><strong>7. Operating System Types</strong></p>
<p>Yeah, the type of server and operating system of it, is matter. Well, you can&#8217;t really go for others if you &#8216;d use asp programs, you would need to go with Windows server. In other flip side of it, is the more stable, feature-laden and often cheaper Unix-based systems, which runs Apache server. Me, Unix-based is my preferable and favorite choice. The why is, with the same goal of creating dynamically generated pages which access the database, writing it down on PHP is alot more MORE then tying down to ASP. I meant it. You could configure a lot of facilities with no requirement to ask your technical support to implement &#8216;em. Isn&#8217; t it the coolest thing?</p>
<p><strong>8. Payment Plans and Pricey Thingy</strong></p>
<p>Price always is factor. And most go for the cheapest. But not in this post. It &#8216;s about things to help you to find the Best web hosting, and NOT the cheapest one. Based on my own personal experiences, go for the cheaper one is desirable, but the other flip side of it, is you would often get what you&#8217;ve paid for. Cheaper always means lack on something. In my experience, they always lack on support, uptime, and speed. It doesn&#8217;t necessarily always mean that the best is the most expensive one. Not always. So playing the period plans would help you a lot on testing out things. Buying a monthly package would allows you to switch quickly if your web host turned out to be dissatisfying.</p>
<p><strong>9. Reseller Web Hosting</strong></p>
<p>It &#8216;s a term of a web hosting who doesn&#8217;t really own their web servers. They &#8216;re a reseller of some other hosting company. It would be disadvantages, as you might be dealing with some people who don &#8216;t really know the what and the how the system they &#8216;re selling. But, not all resellers are disadvantages, as there &#8216;re some reliable and fast resellers which actually good and cheaper than their orig hosting company. Bottom line is, if you &#8216;re in this situation, your best shot is investigate both.</p>
<p><strong>User Reviews</strong></p>
<p>It always matters to hear things from users end. They &#8216;ve been there using the services, so hearing from them about their experiences on how certain web hosting services doing so far would always be great point of consideration for ya. For me it &#8216;s pretty much essential. Do some researches to some web hosting reviews, of some top 10 web hosting listing. Spend your time to read, you wont regret of the &#8220;found-out&#8221; you &#8216;d discover.</p>
<p>Okay so, I &#8216;m having this strange de-javu again by the time I read this writing. As all things above &#8211; you could find &#8216;em already out there. Well, atleast I write &#8216;em down on my own perspective. Somebody might thought my point of view is interesting, who knows? Hope it help you out in some sort of point.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/10-things-you-must-know-to-find-the-best-web-hosting/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Get Competitive Advantage of Exchange Hosting</title>
		<link>http://www.djarot.com/get-competitive-advantage-of-exchange-hosting/</link>
		<comments>http://www.djarot.com/get-competitive-advantage-of-exchange-hosting/#comments</comments>
		<pubDate>Thu, 29 Jan 2009 06:46:09 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Internet & Technology]]></category>
		<category><![CDATA[The Mind]]></category>
		<category><![CDATA[Exchange Hosting]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[Microsoft Exchange Server]]></category>

		<guid isPermaLink="false">http://www.djarot.com/?p=292</guid>
		<description><![CDATA[Have you guys heard about exchange hosting? You know, Microsoft Exchange Server that being purchased as a hosted service from a number of providers. Oh, maybe my first question should be.. Have you guys ever heard about Microsoft Exchange Server? Well, some of us knew it, some don ‘t. So it ’s always worth a defining moment, and when it comes to define stuff, where else better than wikipedia? Alrite, here ’s what it is […] <a href="#" rel="bookmark" title="">[ &#8594; ]</a>]]></description>
			<content:encoded><![CDATA[<p>Have you guys heard about exchange hosting? You know, Microsoft Exchange Server that being purchased as a hosted service from a number of providers. </p>
<p style="float:right;text-align:right;margin:0 0 0 10px;"><img src="http://www.djarot.com/images/exchange-hosting.jpg" alt="Exchange Hosting" title="" /></p>
<p><em>Oh, maybe my first question should be.. Have you guys ever heard about Microsoft Exchange Server?</em></p>
<p>Well, some of us knew it, some don &#8216;t. So it &#8216;s always worth a defining moment, and when it comes to define stuff, where else better than wikipedia? Alrite, here &#8216;s what it is,</p>
<blockquote><p>Microsoft Exchange Server is a messaging and collaborative software product developed by Microsoft. It is part of the Microsoft Servers line of server products and is widely used by enterprises using Microsoft infrastructure solutions. Exchange&#8217;s major features consist of electronic mail, calendaring, contacts and tasks; support for mobile and web-based access to information; and support for data storage.</p></blockquote>
<p><strong>What &#8216;s so Great About it?</strong></p>
<p>When I started this discussion with some of web developer colleagues of mine &#8211; at some evening, sitting together having a cup of coffee at a coffee cafe around the corner &#8211; one of &#8216;em said,<br />
<span style="color:#333;">&#8220;Well I &#8216;m just a web developer, we all are, how this Exchange Server would do me &#8211; or us &#8211; any good?&#8221;</span></p>
<p>To be truly honest, I &#8216;m having a blank moment of that very second. He got the point. Although, one part of his words still bothers me &#8211; as web developer is not just a &#8220;just&#8221; &#8211; but still, he got the point. Why would this Exchange Server do us any good, as the most busiest of us is having a dedicated server, and that&#8217;s more than enough. </p>
<p>Okay, blank moment is gone as in a sudden something shoot the silence &#8211; another dude sitting next to me,<br />
<span style="color:#333;">&#8220;Well it may not be this time, but someday we &#8216;ll find it useful. That would be &#8211; you know &#8211; the time when a client come to us in need of a website, and a demand of a server that enables his site to offer comprehensive messaging services for small to medium-sized businesses (SMBs), small office/home office (SOHO) businesses, and individual information workers.&#8221;</span></p>
<p><i>..And this dude, totally got the core point.</i></p>
<p><strong>Flexible Business Modeling</strong></p>
<p>Based on Microsoft Exchange Server 2007 Service Pack 1 (SP1) and Windows Server 2003 or Windows Server 2008, this messaging solution provides tools for flexible business modeling. You can offer a broad range of services that go from basic e-mail up to higher value services, such as providing additional storage, hosting personal domains, and calendars. Exchange Server 2007 SP1 brings a rich set of new technologies, features, and services to this release of the solution. Exchange Server 2007 SP1 is built on the foundation of RTM, and added additional usability, performance, and scalability enhancements. <i>That &#8216;s according Microsoft TechNet.</i><br />
<span id="more-292"></span><br />
Okay so, our next discussion is all about, where you &#8216;d get the best exchange hosting, as there many providers offer some unbeatable features on their own terms? We who sit together that evening are bunch of web developers, so reading hosting reviews would be one of our main schedule of each day. Maybe not really each day, you know.. you &#8216;ll get the point. I &#8216;m not gonna discuss about tips to get the best exchange hosting, or what review site that have great info about any of <a href="http://www.sherweb.com/sharepoint-hosting" title="Sharepoint Hosting" target="_blank">sharepoint</a> web hosting stuff. Herein, I &#8216;ll write you the real deal. Based on some researches on review sites and such. It&#8217;s SherWeb.</p>
<p><strong>Competitive Advantage</strong></p>
<p>The marketplace today is extremely competitive. New and innovative ways being seek and invented to stay ahead of the competition. A real constant battle for better tools, that help generate greater efficiency and productivity. If you or your company is a player in this jungle, you better boost up your employees performance with SherWeb&#8217;s hosted exchange and increase their productivity at work by improving their collaboration and communication skills. </p>
<p><strong>Lowest price, Best Features, Best Support</strong></p>
<p>They offers one full featured Hosted Exchange plan. Their price is pretty much competitive, $8.95/month per mailbox and there are no minimum number of users required. Each mailbox size is an incredible 3 GB and comes with the most advanced antispam solution eliminating at least 98% of junk messages. I must say it&#8217;s the most generous offer in the industry! It truly is. Seriously.</p>
<p><strong>Free <a href="http://www.sherweb.com/sharepoint-hosting">Sharepoint</a> 2007</strong></p>
<p>Using the combined collaboration features of Hosted Exchange and Hosted SharePoint, users in your organization can easily create, manage, and build their own collaborative Web sites and make them available throughout the organization. SherWeb &#8216;s Sharepoint hosting features:</p>
<ul>
<li>Free SharePoint for all Exchange users. All Exchange users will be able to log in using the same user name and password as their Outlook/Exchange account.</li>
<li>100 MB of disk space included. For larger SharePoint projects, you can purchase one of our Hosted SharePoint plans.</li>
<li>Project collaboration. Give your teams access to password protected Web sites where they can upload and share documents, edit documents collaboratively, discuss between members etc.</li>
<li>Meeting management. Manage meetings for a team all from one place.</li>
<li>Discussion and Team Surveys. Members can easily create discussion groups and surveys on any subject pertinent to their work.</li>
</ul>
<p>Peter Cassar, SherWeb CEO said,<br />
<em>SherWeb distinguishes itself apart by its commitment to excellence, its devotion to support and its competitive prices. We are proudly dedicated to providing a personalized service to all our customers and this is reflected in all our daily tasks. </em></p>
<p>They &#8216;re aiming to be a strategic business partner. Through ongoing relationship with customers, they &#8216;ve demonstrated their ability to build and protect their clients businesses. It &#8216;s personalized, reliable and responsive.</p>
<p>What more I can say? These dudes really are the real deal I &#8216;m speechless.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/get-competitive-advantage-of-exchange-hosting/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>WordPress 2.6.1 Dangerous Vulnerabilities, Upgrade to 2.6.2 NOW!</title>
		<link>http://www.djarot.com/wordpress-261-dangerous-vulnerabilities-upgrade-to-262-now/</link>
		<comments>http://www.djarot.com/wordpress-261-dangerous-vulnerabilities-upgrade-to-262-now/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 13:16:25 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Programming Stuff]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[SQL Column Truncation]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[weakness of mt_rand()]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[WP 2.6.1 bugs]]></category>

		<guid isPermaLink="false">http://www.djarot.com/?p=129</guid>
		<description><![CDATA[So you guys still on 2.6.1 version? Well, be aware. There 're 2 vulnerabilities marked as dangerous as it would allow attacker to reset the password of another user. Stefan Esser of suspekt.org recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). With his help ,Wordpress team worked around these problems and were releasing WordPress 2.6.2, last September 8, 2008. […] <a href="#" title="" rel="bookmark">[ &#8594; ]</a>]]></description>
			<content:encoded><![CDATA[<p>So you guys still on 2.6.1 version? Well, be aware. There &#8216;re 2 vulnerabilities marked as dangerous as it would allow attacker to reset the password of another user. </p>
<p style="float:right;text-align:right;margin:0 0 0 10px;"><a href="http://www.djarot.com/wordpress-261-dangerous-vulnerabilities-upgrade-to-262-now/" title="" style="border:none;"><img src="http://www.djarot.com/images/img-129a.jpg" alt="WP 2.6.1 Bugs" title=""/></a></p>
<p>Stefan Esser of suspekt.org recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). </p>
<p>With his help, WordPress team worked around these problems and were releasing WordPress 2.6.2, last September 8, 2008. Yeah, I know, i &#8216;m a bit late to write this, but it&#8217;s always better be late then not knowing at all, right?</p>
<p><b>Should I upgrade?</b></p>
<p>If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.  Stefan Esser has already release details of the complete attack, both for <a href="http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/" target="_blank" rel="external nofollow">SQL Column Truncation</a> and <a href="http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers/" target="_blank" rel="external nofollow">the weakness of mt_rand()</a>.  The attack is difficult to accomplish,  but its mere possibility means, upgrading to 2.6.2 is recommended.<br />
<span id="more-129"></span><br />
Some bloggers and sys admin with open registration feature for their site or blog, has closed their registration temporarily until they got chances to upgrade to 2.6.2. Wiser choice I must say, couldn&#8217;t agree more.</p>
<p><b>Version 2.6.2 Bugs, Fixes and Security Patches</b></p>
<p>There &#8216;re some bugs found for 2.6.1 or previously 2.6, and the 2.6.2 have all the fixes and security patches. If you &#8216;re interested to take a look at the 2.6.2 bugs and fixes list, headed to this page of that contains a <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.6.2&#038;resolution=fixed&#038;order=priority" target="_blank" rel="external nofollow" title="2.6.2 Bugs, Fixes and Security Patches">handful of bug fixes</a>.</p>
<p>So, wait no more, upgrade now! For all of you who upgrade it already, congrats!</p>
<p style="float:right;">[ <a href="http://www.djarot.com/wordpress-261-bugs-super-bahaya-upgrade-ke-262-sekarang/" rel="bookmark" title="Wordpress 2.6.1 Bugs Super Bahaya, Upgrade ke 2.6.2 Sekarang!">Indonesian version</a> &rarr; ]</p>
<p><br style="clear:both;"/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/wordpress-261-dangerous-vulnerabilities-upgrade-to-262-now/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Citibank &#8217;s Customers ATM PIN have been Compromised!</title>
		<link>http://www.djarot.com/citibank-s-customers-atm-pin-have-been-compromised/</link>
		<comments>http://www.djarot.com/citibank-s-customers-atm-pin-have-been-compromised/#comments</comments>
		<pubDate>Wed, 02 Jul 2008 19:49:13 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[The Mind]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.djarot.com/blog/2008,07,02,citibank-s-customers-atm-pin-have-been-compromised.php</guid>
		<description><![CDATA[Alrite, let’s take a break for a while.. Put the whole search engine optimization tipsy tricks a side for a minute or two.. and take a look at our daily life a bit. It’s been a while since my last post about vulnerability, and it’s kinda answering my oldest call about how much I care to this security world years ago.
The subject above should tell us the idea of the topic I 'm gonna write.  […] <a href="#" title="" rel="bookmark">[ &#8594; ]</a>]]></description>
			<content:encoded><![CDATA[<p style="float:right;text-align:right;margin:0 0 0 10px;"><a href="#" title="" style="border:none;"><img src="http://www.djarot.com/images/citibank-atm.jpg" alt="" /></a></p>
<p>Alrite, let&#8217;s take a break for a while.. Put the whole search engine optimization tipsy tricks a side for a minute or two.. and take a look at our daily life a bit. It&#8217;s been a while since my last post about vulnerability, and it&#8217;s kinda answering my oldest call about how much I care to this security world years ago.<br />
The subject above should tell us the idea of the topic I &#8216;m gonna write. Uh huh, you got it right buddy, <strong>Citibank &#8216;s Customers ATM PIN have been compromised!</strong> This subject is kinda spooky, but the real life situations are even more frightening!</p>
<p>I just finished this scary headline in yahoo, that hackers broke into Citibank&#8217;s network of ATMs inside 7-Eleven stores and stole customers&#8217; PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.</p>
<p>The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs — the numeric passwords that theoretically, I repeat, theoretically, are among the most closely guarded elements of banking transactions — by attacking the back-end computers responsible for approving the cash withdrawals.</p>
<p><b>Is it even possible to do?</b></p>
<p>Well, from my experiences in the past when I still work on this &#8220;un-paid job not even a dime called being a freelance security adviser which most people not even know we were existed since we&#8217;re all writing security advisories using a cyber-nickname&#8221; group, there &#8216;re no such thing as &#8220;impossible&#8221; in hacker &#8216;s dictionary.<br />
This group I used to work for ( for free ), our everyday activities is scanning for network vulnerabilities, and checking some software bugs, writing the advisories about it, and issued them in major security sites, contacting the vendors, and the best part of it, without getting paid. Whoa..<br />
Yup, you heard me right, there still such people doing it, for some noble purposes. Me? I &#8216;m just a former, not anymore one of them now. As I built this tiny wonderful world we used to call &#8220;a family&#8221;, I should work my a55 out to monetize my expertize — ( is it even called an expertize? lol ) — to survive this rude world!</p>
<p>Back to the main issue, Yup it&#8217;s possible, nothing is impossible, the word impossible is not even existed in hacker &#8216;s glossary, not even in their vocabulary. You know most known hacker &#8216;s quote? &#8220;We did it because we can&#8221;. Whatta spirit!<br />
From here, I &#8216;m gonna use the word &#8220;the bad guy&#8221; to replace the word hacker, coz I don&#8217;t agree to this public opinion that hackers always being referred to the bad guys.</p>
<p><b>How this Scary thing even possible from Happening?</b></p>
<p>Okay, we&#8217;re step into the mechanism, the how to, and the hole they&#8217;re into.<br />
<span id="more-55"></span><br />
The bad guys are targeting the ATM system&#8217;s infrastructure, which is increasingly built on Microsoft Corp.&#8217;s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption — which means encoding them to cloak them to outsiders — some ATM operators apparently aren&#8217;t properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.</p>
<p><u>In plain english: </u></p>
<p>There &#8216;s a hole, which, it&#8217;s possible for us who know how to manage to get there, could take the advantages of the PIN data leaking.</p>
<p>This hole is created, from un-clean practices of some ATM operators who don&#8217;t properly doing the most basic known security practice called encryption.</p>
<p>Where&#8217;s the hole exactly? It&#8217;s between the automated teller machines and the computers that process the transactions, while in transit.</p>
<p>Avivah Litan, a security analyst with the Gartner research firm said:</p>
<blockquote><p>&#8220;PINs were supposed be sacrosanct — what this (read: the hole and the PIN data leaking) shows is that PINs aren&#8217;t always encrypted like they&#8217;re supposed to be. The banks need much better fraud detection systems and much better authentication.&#8221;</p></blockquote>
<p><b>The How to.. </b></p>
<p>Woohoo.. The How to.. The best part of all advisories articles. Let&#8217;s conclude a bit. So.. There &#8216;s a hole, where the PIN data are leaking, and they&#8217;re leaking badly. How the bad guys (or should I say: we wannabe. lol) managed to get there?</p>
<p><em>Well.. It&#8217;s still a mystery. </em></p>
<p>Are you expecting some thing like: copy and paste the whole part of the script below, compile it to be a php executable file, execute it through a web interface using any favorite browser you used to use. Do you?</p>
<p><u>The most recent updates on this situation</u>:</p>
<p>A critical issue in the investigation is how the bad guys infiltrated the system, a question that still hasn&#8217;t been answered publicly.</p>
<p>All that&#8217;s known is they broke into the ATM network through a server at a third-party processor, which means they probably didn&#8217;t have to touch the ATMs at all to pull off the heist.</p>
<p>They could have gained administrative access to the machines — which means they had carte blanche to grab information — through a flaw in the network or by figuring out those computers&#8217; passwords. Or it&#8217;s possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.</p>
<p>All I can say is, in some hacker&#8217;s glossary meaning, it&#8217;s a direct attack.<br />
If the bad guy finally found the leak, means the hole of this system has been there since the day its build, right? Actually it help us finally figured, that there &#8216;re something not right ( please notice: i don &#8216;t use the word &#8220;wrong&#8221;) from the first place.</p>
<p><b>Vendor &#8216;s Respond</b></p>
<blockquote><p>Citibank, part of Citigroup Inc., has declined to comment on the technique or how many customers&#8217; accounts were compromised. It said it notified affected customers and issued them new debit cards.<br />
&#8220;We want our customers to know that, consistent with legal requirements, we do not hold them responsible for fraudulent activity in their accounts,&#8221; the bank said in a statement. </p></blockquote>
<p>Oh well, we &#8216;re all agreed, the most interesting part of any vulnerability articles is the vendor responses.<br />
The great part is It said it notified affected customers and issued them new debit cards&#8230; We do not hold them responsible for fraudulent activity in their accounts..<br />
Refunded all the loss? Have no idea, hoping so..</p>
<p><em>Alrite guys&#8230; Be aware. Be safe.</em></p>
<p style="text-align:right;"><a href="http://www.djarot.com/blog/2008,07,03,pin-atm-nasabah-citibank-bocor.php" title="PIN ATM Nasabah Citibank BOCOR!">[ Indonesian Version ]</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/citibank-s-customers-atm-pin-have-been-compromised/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>About this Vulnerabilities Category</title>
		<link>http://www.djarot.com/about-this-vulnerabilities-category/</link>
		<comments>http://www.djarot.com/about-this-vulnerabilities-category/#comments</comments>
		<pubDate>Sun, 30 Mar 2008 17:47:15 +0000</pubDate>
		<dc:creator>Jarot</dc:creator>
				<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.djarot.com/blog/2008,03,30,about-this-vulnerabilities-category.php</guid>
		<description><![CDATA[First of all, knowledge belong to the world. For every single people in this very earth. It&#8217;s a human rights. Curiosity to seek the truth, finding out what&#8217;s behind things, how things work. Yeah. A human nature. A human rights. This category was created based on that very idea, advisories, and mostly educational purposes. Some [...]]]></description>
			<content:encoded><![CDATA[<p>First of all, knowledge belong to the world. For every single people in this very earth. It&#8217;s a human rights. Curiosity to seek the truth, finding out what&#8217;s behind things, how things work.<br />
Yeah. A human nature. A human rights.</p>
<p>This category was created based on that very idea, advisories, and mostly educational purposes. Some of the articles are taken from the security sites with full sincere and respects of its writer. It&#8217;s an advisories anyway. It originally found, written, and publish for its vendor and origin&#8217;s consideration. It&#8217;s an educational material for all people who have the same concern for security, and how to make this world belong to the securest system as humanly as possible.</p>
<p>Taking my part carrying the responsibility of spreading the knowledge to the people in this mother earth, this category was born.</p>
<p>So, enjoy the reading, hope you found it useful.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.djarot.com/about-this-vulnerabilities-category/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

