Top Security News


Keeping An 'eEye' On Zero-Day Exploits
Marc Maiffret's eEye security firm has launched the Zero-Day Tracker, a website where the company will post and archive information on vulnerabilities hit by zero-day exploits. When a patch emerges...


BuddyProfile Sending AIM Users To Malware
A site that allows visitors to embed content in their AIM buddy profiles is being exploited by malware and adware distributors who create profiles laden with links to unwanted content. Adult and other undesired...


Holidays Are Good For Phishing
All the online holiday shopping is fertile ground for online scammers looking to fence a few ill-gotten dollars from unsuspecting consumers Sophos says a Web poll (already skewed toward Web users)....


CAN-SPAM Has Minimal Spam Impact
About three years after the debut of the CAN-SPAM act, very little impact has been made on the volume of spam deluging inboxes, a problem that has worsened each year Since CAN-SPAM was enacted on...


Code Injection Beyond SQL
Although SQL injection attacks have been a threat to websites, other types of code injection could be equally as toxic XML and LDAP could be as prone to a malicious injection of code as a SQL database on the...



David A. Utter
Tuesday:12.05.06

Microsoft RSS Blog Burned By Image Prank

When the RSS team posted an image taken by a former employee to their blog, they did so without asking the photographer for permission, and he responded by swapping the image with a pornographic one.

Hotlinking to an image in ex-Microsoft staffer Niall Kennedy's Flickr stream proved embarrassing to the people behind Microsoft's RSS Blog.

Kennedy was apparently angered enough to replace the hotlinked image with another one, using an adult photo partly blocked with the Creative Commons logo.

Seattle P-I reporter Todd Bishop wrote that the image had been posted under a Creative Commons license permitting non-commercial use of it with proper attribution.

Kennedy told Bishop why he made the change:

He wasn't pleased that Microsoft used his photo on a commercial site, without attribution. In addition, he said, the use of the photo violated the Flickr terms of service by not linking back to the site.
"Basically they stole one of my photos and put it on their blog," Kennedy said. "I decided to make them very aware of that fact."


Robert Scoble, ex-Microsoft blogger and currently with PodTech, criticized Kennedy's action and compared it to something "that gets everyone 16 and under to laugh.":

...is that really the best way that Niall could have gotten the image taken down?

I don't think so. Unprofessional, especially for someone who used to work at Microsoft.

Remember Niall, maybe someday this Web 2.0 bubble will end and you might need to go back to a company and look for a job. I know that doesn't seem probable right now, but I've been there.

Kennedy worked very briefly with Microsoft in 2005 on Windows Live Alerts, and abruptly left the company after a few months.

He cited lack of resources and other problems for his departure.

Scoble noted in a followup on his post that Kennedy never contacted the RSS team about the problem with using the image.

This serves as a good lesson for site publishers who choose to hotlink to another domain for an image.

Content that is not under one's control can be altered very easily, and leaving one's site open to a potentially embarrassing image swap does not build confidence with visitors.

About the Author:
David Utter is a business and technology writer for SecurityProNews, WebProNews, and InternetFinancialNews.


About SecurityProNews
SecurityProNews is updated in real time with vital internet security alerts, news and in-depth articles for IT Managers. SecurityProNews understands that IT Management Begins With Security.
 

SecurityProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
ITmanagementNews.com NetworkNewz.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
 
 

Advertising Newsletters Corporate Info Site Map Support
© 2006 SecurityProNews. An email newsletter.
, Inc. 2549 Richmond Rd. Lexington KY, 40509
All Rights Reserved. Terms under which this service is provided to you. Read our privacy policy. Contact us.
SecurityProNews is part of the iEntry Inc. Network of sites and newsletters.
SecurityProNews About Us News Archives Feedback