Sunday, February 24, 2013

we moved to a new website

Dear Allabout readers we have just moved this site To Geektips Geektips | Latest Tech Updates

Thursday, January 12, 2012

textCAPTCHA API

The service implements captcha to prevent bots and automated scripts from submitting forms and using other website resources, typically for the purpose of posting spam messages. Unlike services using distorted images, textCAPTCHA posts random, text-based questions, such as easy arithmetic problems or logic puzzles, which users must correctly solve to proceed. Bots unable to interpret the meaning of the text are prevented from continuing.

API methods support requests for questions and MD5 hashes of any permitted answers.

Wednesday, January 11, 2012

Technorati API

From their site: Technorati is the recognized authority on what is happening on the World Live Web, right now. The Live Web is the dynamic and always-updating portion of the Web. We search, surface, and organize blogs and the other forms of independent, user-generated content (photos, videos, voting, etc.) increasingly referred to as citizen media.


Technorati :Highlights
Summary :Blog search services
Category :Blog Search
Tags :blog search deadpool
Protocols :REST
Data Formats :XML
API home :http://technorati.com/developers/

foursquare API

foursquare makes the real world easier to use. We build tools that help you keep up with friends, discover what’s nearby, save money and unlock deals. Whether you’re setting off on a trip around the world, coordinating a night out with friends, or trying to pick out the best dish at your local restaurant, foursquare is the perfect companion.


foursquare: Highlights
SummarySocial networking and city exploration
CategorySocial
Tagslocation search social mobile mapping photos
ProtocolsREST
Data FormatsXML, JSON, JSONP
API home https://developer.foursquare.com/

Saturday, December 31, 2011

Netvibes API

From their site: UWA (Universal Widget API) is the next generation of the Netvibes wigdet API, the successor of the Netvibes Mini Module API. With this new release, our API becomes a powerful framework for Web widgets development - not only for Netvibes widgets, but also for many other environments, among which are Apple�s Dashboard and the Google Homepage. With the UWA, you only need one API to build widgets for a host of environments.

Netvibes: Highlights

Summary
Personalized home page with widgets

Category
Widgets

Tags
widgets opensocial

Protocols
JavaScript

Data Formats
XML, JSON, JSONP

API home
http://dev.netvibes.com

I'm Human API

The I'm Human API is "where humanity wins the fight against machines," according to elxsy.com, the provider of the service. I'm Human is a visual CAPTCHA service which responds with a word, a grid of up to 25 images and the grid numbers which correspond to the correct answers. Humans must select the images that match the words and your application compares the results to the correct answer from the I'm Human API.

I'm Human: Highlights

Summary
Visual CAPTCHA service

Category
Security

Tags
captcha security

Protocols
REST

Data Formats
JSON

API home
http://www.elxsy.com/imhuman/api/

Google OpenID API

The Google OpenID API lets third-party web sites and applications let visitors sign in using their Google user accounts. The OpenID standard allows users to nor have to set up separate login accounts for different web sites, and conversely, frees web site developers from the task of managing login information and security measures. OpenID achieves this goal by providing a framework in which users can establish an account with an OpenID provider, such as Google, and use that account to sign into any web site that accepts OpenIDs. This page describes how to enable a web site or application to accept a Google user account for federated login.


Google OpenID: Highlights

Summary
OpenID login for Google account users

Category
Security

Tags
OpenID security identity

Protocols
REST

Data Formats
XML
API home
http://code.google.com/apis/accounts/docs/OpenID.html

OneLogin Api

The OneLogin API allows developers to interact with the OneLogin service. OneLogin provides an easy-to-use single sign-on solution for businesses that embrace cloud computing. OneLogin eliminates the need for employees to remember strong passwords and saves them time because they can log into applications with a single click. OneLogin's API supports five basic operations for each entity: read, list, create, update and delete. It uses RESTful protocol and responses are formatted in XML.

OneLogin: Highlights

Summary
Single sign-on solution

Category
Security

Tags
security enterprise cloud sbweb

Protocols
REST

Data Formats
XML

API home

http://support.onelogin.com/entries/113327-introduction

Waves

Ebys Multimedia had launched Waves!.This is a social network that connects people with friends and others.Why waiting for???
Keep on move!

MySpace Api

The MySpace Developer Platform (MDP) allows developers to create applications that interact with MySpace members and their social data. With MDP you will be able to create compelling new products that integrate directly into MySpace pages and get exposure to millions of people around the world


MySpace: Highlights

Summary
Social networking service

Category
Social

Tags
social opensocial

Protocols
REST, OAuth, JavaScript, PubSubHubbub

Data Formats
XML, JSON, ATOM

API home

http://wiki.developer.myspace.com/index.php?title=Category:RESTful_API

Google Plus Api

Google Plus is a service to share links, photos and other content. The Google Plus API allows developers to access publicly-available Google Plus content, including user information and publicly shared items.

Google Plus: Highlights

Summary
Content sharing service

Category
Social

Tags
microblogging social

Protocols
REST

Data Formats
JSON

API home
https://developers.google.com/+/api/

Facebook API

The Facebook API is a platform for building applications that are available to the members of the social network of Facebook. The API allows applications to use the social connections and profile information to make applications more involving, and to publish activities to the news feed and profile pages of Facebook, subject to individual users privacy settings. With the API, users can add social context to their applications by utilizing profile, friend, Page, group, photo, and event data. The API uses RESTful protocol and responses are localized and in XML format.


Facebook: Highlights

Summary
Social networking service

Category
Social

Tags
social webhooks

Protocols
REST

Data Formats
XML

API home
http://developers.facebook.com/

Facebook Social Plugins Api

Facebook Social Plugins Api
Facebook Social Plugins make a user's friend's social activity available via API. You can see what your friends have liked, commented on or shared on sites across the web. Social Plugins are a basic method of accessing data on Facebook and are specifically designed so none of your data is shared with the sites on which they appear.

All plugins use the Facebook JavaScript SDK.


Dashboard > Directory > Facebook Social Plugins API Profile
Facebook Social Plugins API

* Summary
* Mashups (13)
* How-To
* Developers (13)
* Comments

Facebook Social PluginsTrack this API

Facebook Social Plugins make a user's friend's social activity available via API. You can see what your friends have liked, commented on or shared on sites across the web. Social Plugins are a basic method of accessing data on Facebook and are specifically designed so none of your data is shared with the sites on which they appear.

All plugins use the Facebook JavaScript SDK.


*
* 1
* 2
* 3
* 4
* 5

facebook Social Plugins: Highlights

Summary
Facebook extensions

Category
Social

Tags
widgets social

Protocols
JavaScript

Data Formats

API home
http://developers.facebook.com/docs/plugins

Twitter API

The Twitter micro-blogging service includes two RESTful APIs. The Twitter REST API methods allow developers to access core Twitter data. This includes update timelines, status data, and user information. The Search API methods give developers methods to interact with Twitter Search and trends data. The API presently supports the following data formats: XML, JSON, and the RSS and Atom syndication formats, with some methods only accepting a subset of these formats.




Twitter: Highlights

Summary
Microblogging service

Category
Social

Tags
social microblogging

Protocols
REST

Data Formats
XML, JSON, RSS, Atom

API home
https://dev.twitter.com/docs

Flicker Api

Flickr is a photo-sharing community that enables users to upload, tag and comment on their photos and other users photos. The Flickr API provides the ability to view, manipulate, and search photo tags, display photos from a specific user or group, retrieve tags to construct URLs to particular photos or photo group. Flickr also provides an Authentication API for applications that need to perform restricted actions.

You can find more information about the Flickr developer community at code.flickr, including detailed API documentation.

Lizamoon SQL Injection Campaign Compared

Malware infections such as SQL injection are a well known security problem. Over the past two years we have seen several large-scale infections on the web, e.g. Gumblar.cn and Martuz.cn. Recently, a new SQL injection campaign called Lizamoon has gained a lot of attention. I had expected web sites would become more secure over time and less susceptible to simple security problems, so it is surprising that SQL injection is still a prevalent problem. That let me to wonder: Was Lizamoon as successful as previous infections? In a discussion about this problem, my colleague Panayiotis Mavrommatis suggested that comparing the size of campaigns via search engine result estimates might not be very accurate measurement.

That begs the question of how to assess the impact of infections. While the number of infected URLs is one possible measure, it is skewed by many different factors, e.g. a single vulnerable site contributes a large fraction of the infected URLs and overstates the impact. Instead, counting the number of infected sites might be a better metric. Even so, to judge the relative scale of an infection campaign, it might be helpful to compare it to previous incidents.

Below is a comparison of the Gumblar.cn/, Martuz.cn/ and Lizamoon infections based on Google's Safe Browsing data. The graph shows the number of unique infected sites over a 30 day sliding window.

Cybercrime 2.0

Cybercrime 2.0: When the Cloud Turns Dark

We recently published an article on web-based malware in ACM's Queue Magazine. It provides a short overview of some of the challenges with detecting malicious web sites such as social engineering and examples of techniques for compromising web sites, e.g. htaccess redirection on Apache, etc. This is the article on which my recent ISSNet talk was based.

Adobe PDF Vulnerability

Adobe PDF Vulnerability: Stack overflow in Font File parsing
Thursday, September 9. 2010
Metasploit has a great write up on new vulnerability in PDF. The basic problem is a stack overflow when parsing OpenType fonts. In particular, SING Glyphlet tables contain a 27 byte long unique name that is expected to be NUL-terminated and stored in a 28-byte buffer. The vulnerable code is using strcat and lacks bounds checking resulting in a stack overflow.

The PDF in the wild prepares the heap via Javascript and contains multiple different font files that are selected by navigating to a specific page in the PDF based on the viewer version. Each font files has slightly different shell code. It was amusing to see that the attackers after modifying the head and SING tables did not fix up their respective checksums. According to Metasploit, this exploit works under Windows 7 with both DEP and ASLR turned on. Fun Fun. As of now, no patched version is available. The SecBrowsing blog contains instructions with temporary remedies.