Professor P.I. Flashbulb
Strange but true! Or shall I say FUNNY but true. A Philippine Internet Organization website is vulnerable to SQL Injection, a form of attack in which the attacker executes unauthorized SQL commands. SQL injection attacks are used to steal information from a database from which the data would normally not be available and to gain access to an organization’s host computers through the computer that is hosting the database.
According to their website, the organization is a non-profit organization that undertakes activities to enhance the growth of electronic commerce in the country; it also serves as the private sector advocate of Internet and electronic commerce; it contributes to the advancement of the state-of-the-art Internet and electronic commerce; and it provides a forum for dissemination, acquisition, exchange of information on matters of mutual interests to its members as well as for the discussion of their common problems relating to Internet and electronic commerce.
But how can an organization that can’t even secure its own website accomplish the above responsibility? How can it enhance the growth and the advancement of the state-of-the-art Internet and e-commerce in the country when it has not outgrown an old vulnerability that can be easily corrected?
Last week I was disgusted by the state of web presence of Philippine government agencies. Manila International Airport Authority (MIAA) in particular deserves a medal for being the most negligent government agency in the field of Information Technology because of its inability to simply renew its domain name. (update: As of July 21 that’s two days after Technews published their booboo, MIAA has changed provider from Meridian Telekoms to Globe Telecom, the site is now up but it is very evident that it was put up in a rush because of many dead links and the latest entry in the News link is a news story published in October 2003)
Yesterday, I was aghast when I went to the OFFICIAL website of the National Bureau of Investigation (www.doj.nbi.gov.ph). The “Current News” of the site is about NBI computerization dated January 11, 2002. The site of course is not complete without saying something about the DOJ Secretary Nani Perez (?). How can we expect these people to protect us from cyber crimes if they don’t even know how to update their site? There is another site of the NBI (www.nbi.gov.ph ) whose latest news is dated March 25, 2004, the site however does not say that it is the OFFICIAL website of the NBI.
I can’t help but laugh on the state of Internet and e-commerce presence in the country. I don’t know where we’re heading but with the rate of what is going on in government and non-government agencies, I know that we still have a very long way to be called world class.
-o0o-
Question:
Do you know where I can get an FM/AM application for my Nokia 6600? – Jerzon Manpower" <jerzon_jp@mydestiny.net>
Answer:
"Some Nokia devices come with a built-in FM radio, but the Nokia 6600 does not. We're often asked whether software is available to add a radio to their phone. Unfortunately, it's not that simple, as it's not just a software issue. Phones that have built-in radios contain dedicated hardware in the phone to do this (an FM RF tuner)... and the 6600 doesn't have that. If you're really desperate to listen to radio from your handset, note that it is possible to listen to streaming audio over the Internet via GPRS, although don't expect the results to be up to much! There are some Nokia headsets available with an FM radio in the lead, but we can't find one that works with the 6600. Best bet is to consider a small separate FM radio which is small enough to carry around, and capable of good FM reception on the move." (www.filesaves.com)
-o0o-
Question:
I just recently read your article about a cell phone virus being a hoax. You need to read some more man; don’t you know that cellphone virus was already found? Alfred Moralde (alf_moralde@hotmail.com)
Answer:
The Cabir was not discovered in the wild man, it was submitted to anti-virus developers as a proof of concept. Cabir does not exploit the weakness of the Symbian OS but the weakness of the users. To date only stupid users will be infected should Cabir be released in the wild.
-o0o-
Happy birthday to Albert Hamabad Libre a.k.a. Regie of Impact Unlimited Inc., Regie’s aunt Mariz and Cousin Angie are regular Technews readers according to my editor.

Join MB Technews newsgroup
Send your inquiries to pi_flashbulb@yahoo.com