Bedak Sejuk Pun Bolehh!!

February 8th, 2010 by [re-arrange] 1 comment »

Oh my. Facebook changes its layout again. But that’s not what I wanted to ramble. I just wanted to laugh about this random Facebook group. Presenting.. the “Menentang Penggunaan Bedak Sejuk Oleh Orang Yang Tak Suka Black Metal”!!

laughing

Can we try to translate? Oh. “Against the Usage of Cold Powder by People who Dislike Black Metal!!”.

Whatever rocks your boat, guys. laughing

This Is a Pervert Post.. NOMNOM.. :P

January 31st, 2010 by [re-arrange] 15 comments »

Sincerely, I don’t have much to blog lately. Life’s been routine with nothing much interesting events that worth to be blogged, or might be too private to be blogged. But I just can’t let this piece of news went unnoticed..

Source: The Star.

No panties? I LOL. Will there be some naughty candid pictures being snapped by peoples showing how “curvy” things can be without panties? Ha ha ha. laughing This piece of news just attracted the perverts. I will not be judgemental about this; hey – you want to do it, its your choice, and it’s our amusement.

Ha ha. Ha ha. Ha ha. (laugh like Goofy – the trademark sinister laugh by Munir.)

ZOMG I was Hacked!

January 13th, 2010 by [re-arrange] 14 comments »

No. This is serious business. I am not kidding. I was hacked! laughing

Okay, the better term is defaced. Not hack. Alright, not even defaced too much anyway. What he did (assuming that Rapcik0 is a man; not sure if this Turkish guy is a woman – I doubt that but hey, Trinity was being thought as a man. Okay stop thinking!) was changed my title post to HTML code that redirect to his site.

And the way he got to edit my title post is caused by the reset password vulnerability. Looks like he injected some SQL into the password reset function, and it give access to him. Then he changed the password of my Wordpress account.

Damn.

I thought this hole was fixed prior to Wordpress 2.8.6!

Okay fine. I went to cPanel, checked if he got that access, and apparently not. Reset all my password, and then changed the database. Got my access back, so I upgrade again to the latest Wordpress. Then I undo his change. At first I thought he put the redirection on the index.php, but apparently not. That’s when I realized it was at the post title.

Done!

P/s: Lesson learn – a good precaution is always use strong password, upgrade the security and apply the fixes, yada yada yada. Thank you for this reminder, Rapcik0.