<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: TenthOfMarch Reviews Advertlets From The Inside (Part Two)</title>
	<atom:link href="http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/</link>
	<description>Technology, Reviews, Tutorials, Make Money Online</description>
	<lastBuildDate>Tue, 07 Feb 2012 03:56:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: TenthOfMarch</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-452</link>
		<dc:creator>TenthOfMarch</dc:creator>
		<pubDate>Sat, 05 May 2007 22:51:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-452</guid>
		<description>&lt;strong&gt;@Cikgu Azleen&lt;/strong&gt;
You are welcome. You are not the only one who uses the same password for *all* accounts. I am sure a large number of users does the same. It is advisable to change your passwords (especially those involving sensitive/important issues such as online banking) regularly.</description>
		<content:encoded><![CDATA[<p><strong>@Cikgu Azleen</strong><br />
You are welcome. You are not the only one who uses the same password for *all* accounts. I am sure a large number of users does the same. It is advisable to change your passwords (especially those involving sensitive/important issues such as online banking) regularly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cikgu Azleen</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-445</link>
		<dc:creator>Cikgu Azleen</dc:creator>
		<pubDate>Sat, 05 May 2007 11:48:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-445</guid>
		<description>I&#039;ve changed my password after reading your post.. Hehehe. I am that type of person who are very lazy to remember their passwordS so I used the same password for every account I have.. Unless if the system rejected that password.. TQ for bringing up this issue..</description>
		<content:encoded><![CDATA[<p>I&#8217;ve changed my password after reading your post.. Hehehe. I am that type of person who are very lazy to remember their passwordS so I used the same password for every account I have.. Unless if the system rejected that password.. TQ for bringing up this issue..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TenthOfMarch</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-269</link>
		<dc:creator>TenthOfMarch</dc:creator>
		<pubDate>Wed, 18 Apr 2007 20:04:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-269</guid>
		<description>&lt;strong&gt;@Shireen K&lt;/strong&gt;
LOL. No lah. It&#039;s just that as I dig, I found more. And the more I find, the more I want to dig.

&lt;strong&gt;@woofworks&lt;/strong&gt;
Hahaha. Sorry sifu. You are the second person complaining that.

&lt;strong&gt;@Firdauz&lt;/strong&gt;
Of course the people are concerned. It is their data that is in jeopardy.

&lt;strong&gt;@Josh Lim&lt;/strong&gt;
No hard feelings but to be honest, after reading all the explanations from your team, I am still not 100% convinced with the security of your system (before and after my review).

I&#039;m quoting Firdauz:
&lt;a href=&quot;http://www.tenthofmarch.com/2007/04/13/tenthofmarch-reviews-advertlets-from-the-inside-part-one/#comment-265&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&quot;What’s assumed as laziness and amateurish was in fact; &lt;strong&gt;our best decision at that particular time.&lt;/strong&gt;&quot;&lt;/a&gt;

That sounded &#039;wrong&#039; but well, it could be me.

I missed something that I didn&#039;t mention in my review. According to &lt;a href=&quot;http://www.microsoft.com/technet/security/smallbusiness/topics/networksecurity/enforce_strong_passwords.mspx&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;this&lt;/a&gt; and &lt;a href=&quot;http://technet2.microsoft.com/WindowsServer/en/library/041728b4-5ed9-44a8-99fe-c050333d42451033.mspx?mfr=true&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;this&lt;/a&gt;, the minimum length of a password must be at least 6 or 7 characters to be considered as standard. Shorter passwords are considered WEAK and are more vulnerable.

However, I have tested and your system allows password as short as &lt;strong&gt;ONE&lt;/strong&gt; character. I have one account&#039;s password which is &quot;&lt;strong&gt;a&lt;/strong&gt;&quot; and another account&#039;s password which is &quot;&lt;strong&gt;abc&lt;/strong&gt;&quot;.</description>
		<content:encoded><![CDATA[<p><strong>@Shireen K</strong><br />
LOL. No lah. It&#8217;s just that as I dig, I found more. And the more I find, the more I want to dig.</p>
<p><strong>@woofworks</strong><br />
Hahaha. Sorry sifu. You are the second person complaining that.</p>
<p><strong>@Firdauz</strong><br />
Of course the people are concerned. It is their data that is in jeopardy.</p>
<p><strong>@Josh Lim</strong><br />
No hard feelings but to be honest, after reading all the explanations from your team, I am still not 100% convinced with the security of your system (before and after my review).</p>
<p>I&#8217;m quoting Firdauz:<br />
<a href="http://www.tenthofmarch.com/2007/04/13/tenthofmarch-reviews-advertlets-from-the-inside-part-one/#comment-265" target="_blank" rel="nofollow">&#8220;What’s assumed as laziness and amateurish was in fact; <strong>our best decision at that particular time.</strong>&#8220;</a></p>
<p>That sounded &#8216;wrong&#8217; but well, it could be me.</p>
<p>I missed something that I didn&#8217;t mention in my review. According to <a href="http://www.microsoft.com/technet/security/smallbusiness/topics/networksecurity/enforce_strong_passwords.mspx" target="_blank" rel="nofollow">this</a> and <a href="http://technet2.microsoft.com/WindowsServer/en/library/041728b4-5ed9-44a8-99fe-c050333d42451033.mspx?mfr=true" target="_blank" rel="nofollow">this</a>, the minimum length of a password must be at least 6 or 7 characters to be considered as standard. Shorter passwords are considered WEAK and are more vulnerable.</p>
<p>However, I have tested and your system allows password as short as <strong>ONE</strong> character. I have one account&#8217;s password which is &#8220;<strong>a</strong>&#8221; and another account&#8217;s password which is &#8220;<strong>abc</strong>&#8220;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ABC</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-267</link>
		<dc:creator>ABC</dc:creator>
		<pubDate>Wed, 18 Apr 2007 17:05:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-267</guid>
		<description>Huh??? explanation can seems more questionable at times... I am not a techie.. but sometimes, i try to understand... 

1. security issues. How secure IS secure? (believe i asked that before)

2. Vulnerability of the system is not proven otherwise by just conducting a 24 hour manual monitoring and conclude a concrete guarantee.. 

I left myself anonymous this time around. I am sure the owner of this blog can find me. Thats because i do not wished to be contacted with regards to this except for the owner of this blog.</description>
		<content:encoded><![CDATA[<p>Huh??? explanation can seems more questionable at times&#8230; I am not a techie.. but sometimes, i try to understand&#8230; </p>
<p>1. security issues. How secure IS secure? (believe i asked that before)</p>
<p>2. Vulnerability of the system is not proven otherwise by just conducting a 24 hour manual monitoring and conclude a concrete guarantee.. </p>
<p>I left myself anonymous this time around. I am sure the owner of this blog can find me. Thats because i do not wished to be contacted with regards to this except for the owner of this blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh Lim</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-266</link>
		<dc:creator>Josh Lim</dc:creator>
		<pubDate>Wed, 18 Apr 2007 14:04:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-266</guid>
		<description>In creating Advertlets, a system to make money through your blog, we were aware that there are definite data privacy and security concerns, especially when it comes to trusting a third party to keep your personal details and password safe. Well, some bloggers did too - and one even went as far as to invite tech savvy members of the public to test the security of our system, and try to exploit any vulnerabilities they might find.

We did not expect this to happen - however, we and our system were not unprepared.

We first heard of the news through our RSS feeds, and 1 phone call from a friend. So, 2 members of the team stayed awake throughout the night to watch what people would do, and react as if needed. We kept track of what was happening - about 16 dummy accounts were created on the system from unique IPs, our hits rose drastically, and intrusions were detected from Malaysia, Indonesia &amp; Singapore.

From our logs, we could see as various methods were tried: SQL injection, brute force attacks, URL guessing, and social engineering. The last method was a rather interesting, if futile attempt - someone pretended to be one of our more popular bloggers and requested us to reset their password, apparently having forgotten it. The e-mail header was spoofed to make it seem like it was a actual e-mail of that particular blogger, but we noticed that the reply-to address was another address entirely. To be sure, we checked with the blogger in question, and found that it wasn’t an actual request.

In summary, throughout all the intrusion attempts, no intruder got to do anything further than creating a few fake accounts on our system, which were easily cleared. Our current security system has now been proven effective in a trial by fire - so yes, Advertlets.com is indeed secure, and we can vouch for the protection of your data and password. 

However, we will leave no stone unturned in our quest to take Advertlets further, and look forward to rolling out additional revenue and security features for our users, especially as our user base grows and we get more popular. Do let us know if you have any further questions, and thanks for your support!</description>
		<content:encoded><![CDATA[<p>In creating Advertlets, a system to make money through your blog, we were aware that there are definite data privacy and security concerns, especially when it comes to trusting a third party to keep your personal details and password safe. Well, some bloggers did too &#8211; and one even went as far as to invite tech savvy members of the public to test the security of our system, and try to exploit any vulnerabilities they might find.</p>
<p>We did not expect this to happen &#8211; however, we and our system were not unprepared.</p>
<p>We first heard of the news through our RSS feeds, and 1 phone call from a friend. So, 2 members of the team stayed awake throughout the night to watch what people would do, and react as if needed. We kept track of what was happening &#8211; about 16 dummy accounts were created on the system from unique IPs, our hits rose drastically, and intrusions were detected from Malaysia, Indonesia &amp; Singapore.</p>
<p>From our logs, we could see as various methods were tried: SQL injection, brute force attacks, URL guessing, and social engineering. The last method was a rather interesting, if futile attempt &#8211; someone pretended to be one of our more popular bloggers and requested us to reset their password, apparently having forgotten it. The e-mail header was spoofed to make it seem like it was a actual e-mail of that particular blogger, but we noticed that the reply-to address was another address entirely. To be sure, we checked with the blogger in question, and found that it wasn’t an actual request.</p>
<p>In summary, throughout all the intrusion attempts, no intruder got to do anything further than creating a few fake accounts on our system, which were easily cleared. Our current security system has now been proven effective in a trial by fire &#8211; so yes, Advertlets.com is indeed secure, and we can vouch for the protection of your data and password. </p>
<p>However, we will leave no stone unturned in our quest to take Advertlets further, and look forward to rolling out additional revenue and security features for our users, especially as our user base grows and we get more popular. Do let us know if you have any further questions, and thanks for your support!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firdauz</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-264</link>
		<dc:creator>Firdauz</dc:creator>
		<pubDate>Wed, 18 Apr 2007 09:25:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-264</guid>
		<description>We’re responding.

Live updating is in session.

Thanks for the concern.

Cheers people.</description>
		<content:encoded><![CDATA[<p>We’re responding.</p>
<p>Live updating is in session.</p>
<p>Thanks for the concern.</p>
<p>Cheers people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: woofworks</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-262</link>
		<dc:creator>woofworks</dc:creator>
		<pubDate>Mon, 16 Apr 2007 19:18:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-262</guid>
		<description>eh, y suddenly all so &#039;tech-ish&#039;....!</description>
		<content:encoded><![CDATA[<p>eh, y suddenly all so &#8216;tech-ish&#8217;&#8230;.!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shireen K</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-261</link>
		<dc:creator>Shireen K</dc:creator>
		<pubDate>Mon, 16 Apr 2007 14:20:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-261</guid>
		<description>fuh.... serious homework man..did u like get A  for research?</description>
		<content:encoded><![CDATA[<p>fuh&#8230;. serious homework man..did u like get A  for research?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TenthOfMarch</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-259</link>
		<dc:creator>TenthOfMarch</dc:creator>
		<pubDate>Mon, 16 Apr 2007 04:49:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-259</guid>
		<description>&lt;strong&gt;@Melvin,foong&lt;/strong&gt;
I&#039;ll let them continue doing their &#039;thing&#039;. They should bare in mind that, as &lt;a href=&quot;http://bosslepton.blogspot.com/2007/04/nuffnang-vs-advertlets.html&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;Boss Lepton puts it&lt;/a&gt;, &quot;your competitors should be the mainstream media&quot; and not between themselves. There must be hundreds, if not thousands of &#039;possible advertisers&#039; out there. Snatching from each other&#039;s &#039;plates&#039; won&#039;t do any good for either sides.

&lt;strong&gt;@Boss Lepton&lt;/strong&gt;
Thanks, boss.

&lt;strong&gt;@aw&lt;/strong&gt;
Final review sounds like &#039;the end&#039;, uh? Maybe I&#039;ll do a &#039;post-review&#039; review after 1 or 2 months. As for now, it&#039;s time to move on.

Hmmm...I wonder who should be my next &#039;victim&#039;. Or maybe I should blog about the birds and flowers for a little while.

&lt;strong&gt;@earl-ku&lt;/strong&gt;
Their &#039;cincai&#039; attitude was the one that raised my concerns. I hope they know which part &#039;can&#039; cincai, and which part cannot.

LOL. &quot;Free&quot; is quite subjective. I guess I&#039;m just utilizing my time.

If your predictions on the &#039;hitman&#039; is true, please make a police report if you notice me not blogging for more than 48 hours. Thank you.

&lt;strong&gt;@mooiness&lt;/strong&gt;
I have a feeling that at least 2 programmers are working on the pages I mentioned in this review. I notice some information on different pages are overlapping. Or maybe they just didn&#039;t planned &#039;what to have, and where to have it&#039; properly.

There is also a big contrast in design (look &amp; feel) between all the pages.</description>
		<content:encoded><![CDATA[<p><strong>@Melvin,foong</strong><br />
I&#8217;ll let them continue doing their &#8216;thing&#8217;. They should bare in mind that, as <a href="http://bosslepton.blogspot.com/2007/04/nuffnang-vs-advertlets.html" target="_blank" rel="nofollow">Boss Lepton puts it</a>, &#8220;your competitors should be the mainstream media&#8221; and not between themselves. There must be hundreds, if not thousands of &#8216;possible advertisers&#8217; out there. Snatching from each other&#8217;s &#8216;plates&#8217; won&#8217;t do any good for either sides.</p>
<p><strong>@Boss Lepton</strong><br />
Thanks, boss.</p>
<p><strong>@aw</strong><br />
Final review sounds like &#8216;the end&#8217;, uh? Maybe I&#8217;ll do a &#8216;post-review&#8217; review after 1 or 2 months. As for now, it&#8217;s time to move on.</p>
<p>Hmmm&#8230;I wonder who should be my next &#8216;victim&#8217;. Or maybe I should blog about the birds and flowers for a little while.</p>
<p><strong>@earl-ku</strong><br />
Their &#8216;cincai&#8217; attitude was the one that raised my concerns. I hope they know which part &#8216;can&#8217; cincai, and which part cannot.</p>
<p>LOL. &#8220;Free&#8221; is quite subjective. I guess I&#8217;m just utilizing my time.</p>
<p>If your predictions on the &#8216;hitman&#8217; is true, please make a police report if you notice me not blogging for more than 48 hours. Thank you.</p>
<p><strong>@mooiness</strong><br />
I have a feeling that at least 2 programmers are working on the pages I mentioned in this review. I notice some information on different pages are overlapping. Or maybe they just didn&#8217;t planned &#8216;what to have, and where to have it&#8217; properly.</p>
<p>There is also a big contrast in design (look &#038; feel) between all the pages.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boss Lepton</title>
		<link>http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/comment-page-1/#comment-258</link>
		<dc:creator>Boss Lepton</dc:creator>
		<pubDate>Mon, 16 Apr 2007 04:17:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.tenthofmarch.com/2007/04/16/tenthofmarch-reviews-advertlets-from-the-inside-part-two/#comment-258</guid>
		<description>Nah i think arsyan did a great job with the engine of advertlets. It&#039;s just shabby presentation, no offence. It&#039;s like using a windows vista to play a 80s dos game?</description>
		<content:encoded><![CDATA[<p>Nah i think arsyan did a great job with the engine of advertlets. It&#8217;s just shabby presentation, no offence. It&#8217;s like using a windows vista to play a 80s dos game?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

