Calstuff
Don't mess this up!
-Kevin Deenihan,
Emeritus


Home
Archive
Extended

Help CalStuff!

Disclaimer: Calstuff and/or the opinions expressed are not affiliated with the University of California, Berkeley.
Recent Guest Posts
Tenants' Rights Week
by Jason Overman
Search

Powered by:
Contact

FaceBook CalStuff!
Allen L.
 About
 
 IM
Andy R.
 About
 
 IM
Ben N.
 About
 
 IM
Cooper N.

 About
 
 IM
Syndication
Site Feed (ATOM)
Comments Feed
Add to LJ Friends

Subscribe in NewsGator Online
Subscribe with Bloglines
Berkeley Blogs
CalJunket
With humor.
Cal Patriot Blog
Conservative Blog
UC Berkeley Livejournal
Discussion Forum
California Patriot Watch
Self Explanatory
Brad DeLong
Econ Prof
The Bird House
Cal Prof on everything
Cal Politik
Rants & Raves
Beetle Beat
Full Time Whiner
"Frat" Life
Cal "Frat" Boy
Cal Tzedek
Jewish Students Blog
Personal as Public
Soft Boiled Life
Hilariously Un-PC.
Cal Alumni/ Squelch Blogs
Kedstuff
Remember him?
I Fought the Law
Optimus Primed
Zembla
With Cuteness
Ne Quid Nimis
With Photography
Sunday, February 20, 2005
# posted by Andy @ 6:17 AM

Amazing Security Flaw on the ASUC Website
As if I haven't given my ASUC website friends a hard enough time already, here is something more to get them all upset with me. The ASUC website has a nifty little Calendar keeping track of events, where people can post what is going on. Any by people, I mean anyone! Go ahead, go add something yourself. It's super easy.

Already, someone has scheduled February 25th as Official ASUC "Get Absolutely Nothing Done Day" (not me, I promise). I assume sooner or later the adults will realize that we're monkeying around with their website and fix things, but for now it'a free for all.

Having a completely unprotected Calendar like this worked fine as long as nobody was actually using/looking at it, but I'm guessing the intention is for people to visit it sometime in the future, so some feature that requires a webmaster to approve things before they go up would probably be a good idea.

(And yes, I realize that I could have just just passed along an e-mail informing the people behind the website of the security flaw in the site, but this is substantially more fun. Also, before people accuse me of tarnishing the idea of a ASUC website that anyone could have been able to post events on, once people actually started visiting it, I'm sure a million people would have figured that out anyway and made all sorts of immature jokes. Finally, to those people who could do something about fixing this, you should totally pretend that you didn't see this post so us kids can have some fun before you shut things down.)

P.S. If you feel the need to update the calendar, be sure to grab a screen shot of your handiwork.
Email This Post!

Home
Advertisements
Advertising Policy

Place an Ad on Calstuff



Get Firefox!

Cal Magazines
Heuristic Squelch
Humor Mag
California Patriot
Conservative
Hardboiled
Lefty/Asian mag.
Bezerk
Comics Mag
In Passing
Bloggish
Cal Newsites
Daily Californian
Student Newspaper
Daily Planet
City Newspaper
Berkeleyan
Faculty/Staff news
Newscenter
Administrative Announcements
Indybay
Hard Left News
East Bay Express
Alt-weekly
Cal Other
UC Rally Committee
Stand nineteen feet tall! Be united! Be tough! Be proud!
CyberBears
GO BEARS!
ASUC
Cal's Student government
One
Cal's Student Portal
Berkeley Bookswap
Good Deals

Weblog Commenting and Trackback by HaloScan.com