Java and Python FTP Attacks Can Punch Holes Through Firewalls

itwbennett writes: Over the weekend, security researcher Alexander Klink disclosed an interesting attack where exploiting an XXE (XML External Entity) vulnerability in a Java application can be used to send emails. At the same time, he showed that this type of vulnerability can be used to trick the Java runtime to initiate FTP connections to remote servers. After seeing Klink's exploit, Timothy Morgan, a researcher with Blindspot Security, decided to disclose a similar attack that works against both Java's and Python's FTP implementations. 'But his attack is more serious because it can be used to punch holes through firewalls,' writes Lucian Constantin in CSO Online.

Congressional IT Staffers Took $100K from Iraqi Politician

RoccamOccam writes: Three brothers, working as IT staffers for several Democrat congressional representatives took $100,000 from an Iraqi politician while they had administrator-level access to the House of Representatives’ computer network, according to this report based on court documents.

The trio worked for dozens of representatives, including members of the intelligence, foreign affairs and homeland security committees. Those positions likely gave them access to congressional emails and other sensitive documents.

Natural Gas

Fossil fuels are dirty, old, inefficient, and obsolete. Besides, we'll be needing them for the raw materials for polymers and whatnot.

It's simple economics.

As is usually the case, conservatives are on the wrong side of progress into the future. They want to keep things the same but that is an impossibility. Life is change and therefore will always be at odds with conservative values.

That is precisely the side that conservatives are on: the change will happen when it makes since economically. Not because of burdensome government intervention, but because of innovation and simple economics.

The Clinton Foundation is downsizing

mi writes: You would think, the end of a political career would allow a genuinely charitable family to concentrate on their charity. Instead, the Clinton Foundation is closing shop (or, at least, downsizing) after their champion's electoral loss. According to the paperwork they filed with New York Department of labor, the reason is "Discontinutation [sic] of the Clinton Global Initative [sic]".

Only remove it for California

I certainly agree. However, if you are putting in the accent, then it goes over both the first and second "e", not just the last. I used to think that it only went over the last "e" (because of the American pronunciation).

I only point it out because it is the kind of thing that someone might notice on a job application.

Only remove it for California

2. If you can't get a job solely because your age is written on your resumé, then age discrimination is clearly still a problem.

Since you care enough to go to the trouble to write the word with an accent, I'd like to point out that correct spelling is résumé, which I was not aware of until recently. For years, I also thought that it was spelled resumé.

Well

Sorry, I was implying that the issue was a non-U.S. birth certificate. Someone who presented a non-U.S. birth certificate could have acquired U.S. citizenship and be eligible to vote - the official can't know just by looking at a birth certificate. So, when presented with a non-U.S. birth certificate, were the officials also demanding proof of citizenship before registration is allowed? The law doesn't demand that they do. The ridiculously easy loophole is still there.

