<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2" -->
<rss version="2.0">
    <channel>
        <title>Lowyat.NET: Latest topics by highwind</title>
        <description></description>
        <link>http://forum.lowyat.net/</link>
        <lastBuildDate>Mon, 08 Jun 2026 14:20:52 +0800</lastBuildDate>
        <generator>FeedCreator 1.7.2</generator>
        <item>
            <title>[WTS] Eastin Hotel Petaling Jaya Room - RM 190</title>
            <link>http://forum.lowyat.net/topic/3306823</link>
            <description>&lt;b&gt;Item(s):&lt;/b&gt;&lt;br /&gt;Eastin Hotel Petaling Jaya - Room Only&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Package includes:&lt;/b&gt;&lt;br /&gt;This package is for room only and does not include breakfast. Can top up additional RM 100 to go Executive Deluxe&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Price:&lt;/b&gt;&lt;br /&gt;RM 190&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Warranty:&lt;/b&gt;&lt;br /&gt;N/A&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Dealing method:&lt;/b&gt;&lt;br /&gt;Online Banking Transfer&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Location:&lt;/b&gt;&lt;br /&gt;N/A&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Contact method/details:&lt;/b&gt;&lt;br /&gt;PM&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Item(s) conditions:&lt;/b&gt;&lt;br /&gt;N/A&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Picture:&lt;/b&gt;&lt;br /&gt;N/A&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Reason for sale:&lt;/b&gt; &lt;br /&gt;Initially plan to use for my parents when they visit KL but they had cancelled their trip.</description>
            <author>highwind</author>
            <category>Garage Sales Archive</category>
            <pubDate>Fri, 01 Aug 2014 14:59:52 +0800</pubDate>
        </item>
        <item>
            <title>[WTS] Web Hosting + Website Creation</title>
            <link>http://forum.lowyat.net/topic/3216659</link>
            <description>&lt;b&gt;Web Hosting + Website Creation @ RM 300 per year&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Company Name:&lt;/b&gt; Latte Web Hosting (002247574-H)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Package includes:&lt;/b&gt;&lt;br /&gt;- Website creation on WordPress + Genesis Framework from Studiopress&lt;br /&gt;- Lifetime Domain Name&lt;br /&gt;- 4 pages of Web Page Design (Home, Services, About, Contact)&lt;br /&gt;- 2GB of Disk Space&lt;br /&gt;- 20 GB of Bandwidth&lt;br /&gt;- Up to maximum of 4 hosted domain names&lt;br /&gt;- Unlimited Subdomain&lt;br /&gt;- Unlimited Email Accounts&lt;br /&gt;- Unlimited MYSQL Database&lt;br /&gt;&lt;br /&gt;**Find out more info at &lt;a href='http://www.lattehosting.my/setting-up-your-home-business-now/' target='_blank'&gt;here&lt;/a&gt;</description>
            <author>highwind</author>
            <category>Garage Sales Archive</category>
            <pubDate>Wed, 07 May 2014 07:39:52 +0800</pubDate>
        </item>
        <item>
            <title>Buffet + Free flow drinks</title>
            <link>http://forum.lowyat.net/topic/3201827</link>
            <description>&lt;b&gt;Item(s):&lt;/b&gt;&lt;br /&gt;Korean BBQ &amp;amp; Steamboat Buffet + Free Flow of Drinks at Seoul Garden &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Package includes:&lt;/b&gt;&lt;br /&gt;Vouchers for 2 Pax&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Price:&lt;/b&gt;&lt;br /&gt;RM 79.80&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Warranty:&lt;/b&gt;&lt;br /&gt;None&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Dealing method:&lt;/b&gt;&lt;br /&gt;Online Payment + Email to transfer voucher&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Location of seller:&lt;/b&gt;&lt;br /&gt;Puchong&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Contact method/details:&lt;/b&gt;&lt;br /&gt;PM or SMS 016-4902831&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Age of item:&lt;/b&gt;&lt;br /&gt;New&lt;br /&gt;&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Item(s) conditions:&lt;/b&gt;&lt;br /&gt;New&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Picture:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Reason for sale:&lt;/b&gt;&lt;br /&gt;Extra vouchers being bought.</description>
            <author>highwind</author>
            <category>Garage Sales Archive</category>
            <pubDate>Tue, 22 Apr 2014 15:58:46 +0800</pubDate>
        </item>
        <item>
            <title>[WTS] PANASONIC CEILING FAN - FM15B0</title>
            <link>http://forum.lowyat.net/topic/3055843</link>
            <description>&lt;b&gt;Item(s):&lt;/b&gt;&lt;br /&gt;PANASONIC CEILING FAN - FM15B0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Package includes:&lt;/b&gt;&lt;br /&gt;- 60&amp;quot; Decorative Ceiling Fan&lt;br /&gt;- 5-speed Electronic Regulator&lt;br /&gt;- Enhanced Safety Features&lt;br /&gt;- Low Noise&lt;br /&gt;- Durable Advanced Motor&lt;br /&gt;- Thermal Safety Fuse&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Price:&lt;/b&gt;&lt;br /&gt;RM 145.00&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Warranty:&lt;/b&gt;&lt;br /&gt;New unit - warranty included&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Dealing method:&lt;/b&gt;&lt;br /&gt;COD&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Location of seller:&lt;/b&gt;&lt;br /&gt;Puchong, Bukit Jalil, Subang, PJ, KL&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Contact method/details:&lt;/b&gt;&lt;br /&gt;PM or SMS or Whatsapp @ 016-4902831&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Age of item:&lt;/b&gt;&lt;br /&gt;N/A&lt;br /&gt;&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Item(s) conditions:&lt;/b&gt;&lt;br /&gt;New&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Picture:&lt;/b&gt;&lt;br /&gt;[attachmentid=3755319]&lt;br /&gt;&lt;br /&gt;More info at:&lt;br /&gt;&lt;a href='http://homemartplus.com.my/index.php?page=shop.product_details&amp;flypage=flypage_lite_pdf.tpl&amp;product_id=599&amp;category_id=79&amp;option=com_virtuemart&amp;Itemid=230' target='_blank'&gt;Home Mart Plus&lt;/a&gt;&lt;br /&gt;&lt;a href='http://www.senheng.com.my/ceiling-fan/11640-panasonic-ceiling-fan-psn-fm15bo.html' target='_blank'&gt;Senheng&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Reason for sale:&lt;/b&gt;&lt;br /&gt;I had bought these fan initially to install into my new house but due to the reason that my relative had given me a better fan, I decided to use that and sell this out.</description>
            <author>highwind</author>
            <category>Garage Sales Archive</category>
            <pubDate>Thu, 05 Dec 2013 22:46:45 +0800</pubDate>
        </item>
        <item>
            <title>PC Fix 2011 Registry Cleaner Giveaway</title>
            <link>http://forum.lowyat.net/topic/2047373</link>
            <description>Hi&lt;br /&gt;&lt;img src='http://itscolumn.com/wordpress/wp-content/uploads/2011/09/pc_fix1.jpg' border='0' alt='user posted image' /&gt;&lt;br /&gt;I&amp;#39;m launching a lucky draw contest to give away 3 copies of licensed Registry Cleaner. The product name is called PC Fix 2011. It is a product that is going to give you a registry clean up and better performance. If you are interested, just head over to &lt;a href='http://www.itscolumn.com/2011/09/subscribe-share-and-win-registry-cleaner-worth-more-than-100/' target='_blank'&gt;this page&lt;/a&gt; for more details.&lt;br /&gt;&lt;br /&gt;P/S: Hope I did not violate any T&amp;amp;C of  this forum by posting this.</description>
            <author>highwind</author>
            <category>Software</category>
            <pubDate>Mon, 26 Sep 2011 13:05:23 +0800</pubDate>
        </item>
        <item>
            <title>Top 10 Web Application Vulnerabilites</title>
            <link>http://forum.lowyat.net/topic/1899360</link>
            <description>The top 10 list are:&lt;br /&gt;&lt;br /&gt;10.	Unvalidated Redirects and Forwards&lt;br /&gt;In common, web application usually redirects or forwards users to another page or website and then use the data within to determine where the user should go. If the data is not validated properly, it could redirect the user to some malicious website as the data mentioned is going to determine where the user will go. By accessing the malicious URL, it is highly potential that the user will get his computer infected with Malware. This could potentially lead to a phishing attack.&lt;br /&gt;Example of attack:&lt;br /&gt;· &lt;a href='http://www.your-site.com/redirect.jsp?url=phshing-site.com' target='_blank'&gt;http://www.your-site.com/redirect.jsp?url=phshing-site.com&lt;/a&gt;&lt;br /&gt;· &lt;a href='http://www.your-site.com/main.jsp?fwd=phishing-site.com' target='_blank'&gt;http://www.your-site.com/main.jsp?fwd=phishing-site.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;9.	Insufficient Transport Layer Protection&lt;br /&gt;Applications sometimes failed to protect the transport layer well. The transport layer that I mean here is using SSL/TLS as a methodology to protect the application data when transmitting between client and server or vice-versa. The purpose of this method is of course to encrypt the transmitting data. If the data are not encrypted, it can be easily stolen via man in the middle attack. In addition to this web application vulnerability, configuration of this method can be vital. Application should always use a strong encryption algorithm (at least FIPS 140-2) and it should also never use expired or invalid certificate. This is because it will cause the users to force themselves to accept the invalid certificate in order to browse the application. By doing this, it will eventually result in phishing attack easily as the user already have the habit to accept invalid certificates. As a conclusion to this, it is important to protect the transport layer in order to keep the data confidential and secured.&lt;br /&gt;&lt;br /&gt;8.	Failure to Restrict URL Access&lt;br /&gt;Failure to restrict URL access here means that the application failed to restrict certain users who are not supposed to view restricted page. In other words, this means the user might not have the privilege to access or it could also possible that the user did not perform any authentication also able to gain access to the restricted page. If the attacker found out the page is vulnerable to this attack, he can just forge the URL to access the page especially administrator’s page. Once the attacker is there, he can just do whatever settings or actions that supposedly only administrator can perform. Thus, developer should ensure the restricted page is only accessible by the right person.&lt;br /&gt;&lt;br /&gt;7.	Insecure Cryptographic Storage&lt;br /&gt;Passwords, credit card information and other sensitive data should be encrypted before storing into the database. If let say the attacker somehow manage to get the data in your database, it is still not completely compromised as it is already encrypted and the attacker will require a long long time to decrypt it. This of course only can happen if you encrypt the data properly with strong encryption algorithm and securely store the encryption key. In certain application, the developer did encrypt the data but left the key together with the data. Hence, the encrypted data can be easily decrypted by running some brute force to crack down the password the encryption key. The encryption key should always be separated from the application server. It is also recommended to use a hardware key container (HSM – Hardware Security Module) in your application to bring the security level of your application to another level.&lt;br /&gt;&lt;br /&gt;6.	Security Misconfiguration&lt;br /&gt;Having a good security also means having a good security configuration. The security configuration here means that everything under the sky that is deployed to your web application such as web server, application server, database, files and folders, and also framework are all properly configured. This includes as well ensuring all the items mentioned are fully updated as the older version tend to have vulnerabilities that attacker can take advantage of. The usage of default account and password are strictly not recommended. Not only that, the error stack trace should be managed properly in the way that it does not exposed to the user. Attacker will love to see all the stack trace message as it can give them more clue on how to attack your web application. Therefore, only display a very high level message or general error message to the user. Security configuration needed to be planned properly and check carefully before deploying the web application to the public.&lt;br /&gt;&lt;br /&gt;5.	Cross-Site Request Forgery (CSRF)&lt;br /&gt;The cross-site request forgery is quite a tricky vulnerability. What this vulnerability does is that it will forge the request through web URL when the victim clicked on any infected image link or even through cross-site scripting (XSS). This will change information that he did not actually requested to as an authenticated user. However, this require the user to be authenticated first by logging into the application and stored his authentication token into the session cookie.&lt;br /&gt;Example of attack:&lt;br /&gt;The user login into the application at www.myapp.com&lt;br /&gt;The user then does his normal web browsing probably googling some image and click on a panda image that he found interesting.&lt;br /&gt;Not realizing that the panda link is actually look like this in the html code:&lt;br /&gt;&amp;lt;img src=”http://www.myapp.com/main?transferfund=1500&amp;amp;destination=hackerAcc” /&amp;gt;&lt;br /&gt;Once the image is clicked, the user will immediately perform the transfer to hacker’s account.&lt;br /&gt;The drawback is that the attacker still need to guess the criteria to forge into the URL. Above is just an illustration as transferring funds should not be that simply implemented. However do bear in mind that if the attacker can do something that requires your authentication without him authenticating first, isn’t that sounds dangerous?&lt;br /&gt;&lt;br /&gt;...&lt;br /&gt;&lt;br /&gt;To continue reading this, you can refer to this &lt;a href='http://www.itscolumn.com/2011/05/top-10-web-application-vulnerabilities-and-security-risks-2010/' target='_blank'&gt;Top 10 Web Application Vulnerabilities&lt;/a&gt;.</description>
            <author>highwind</author>
            <category>Codemasters</category>
            <pubDate>Tue, 31 May 2011 09:18:03 +0800</pubDate>
        </item>
        <item>
            <title>Is My Google Adsense Illegal?</title>
            <link>http://forum.lowyat.net/topic/1895921</link>
            <description>Hi&lt;br /&gt;&lt;br /&gt;I run a blog which has adsense ads and recently I made an amendment due to not getting clicks from the ads i put above my header. I had shifted to slightly lower which is above my content. However, usually before I start my post, I will put a picture first and I am not too sure whether did I violate the Google Adsense T&amp;amp;C. I heard rumours said that one cannot put the adsense ads near to a picture. Glad to be helped.&lt;br /&gt;&lt;br /&gt;My site is:&lt;br /&gt;&lt;a href='http://www.itscolumn.com' target='_blank'&gt;IT Security Column&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;P/S: You can only see my problem in a single post page and not my home page.&lt;br /&gt;&lt;br /&gt;Thanks again  &lt;!--emo&amp;:respect:--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/notworthy.gif' border='0' style='vertical-align:middle' alt='notworthy.gif' /&gt;&lt;!--endemo--&gt;</description>
            <author>highwind</author>
            <category>Content Creators, Blogmasters &amp;amp; Webmasters</category>
            <pubDate>Sat, 28 May 2011 12:54:45 +0800</pubDate>
        </item>
        <item>
            <title>Sony Hacked Again</title>
            <link>http://forum.lowyat.net/topic/1891587</link>
            <description>Sony hacked again after the issue where 77 million Sony Playstation Network users were affected. It really seems like Japan is not having a good time. Apart from the old issue that just mentioned regarding the 77 million users, they were hit as well with the natural disasters, Tsunami and earthquake. Everyone would thought that Sony should be temporarily safe as they just got hacked, but no. Something Sony must had done to anger the hackers around to keep on penetrating their system.&lt;br /&gt;&lt;br /&gt;&lt;a href='http://www.itscolumn.com/2011/05/sony-hacked-again/' target='_blank'&gt;Full Story&lt;/a&gt;</description>
            <author>highwind</author>
            <category>Security &amp;amp; Privacy</category>
            <pubDate>Wed, 25 May 2011 09:41:09 +0800</pubDate>
        </item>
        <item>
            <title>Mac immunity might be over soon</title>
            <link>http://forum.lowyat.net/topic/1883922</link>
            <description>Check out the latest information on &lt;a href='http://www.itscolumn.com/2011/05/new-malware-targets-mac-system/' target='_blank'&gt;&lt;span style='color:blue'&gt;Mac Malware&lt;/span&gt;&lt;/a&gt;.</description>
            <author>highwind</author>
            <category>Security &amp;amp; Privacy</category>
            <pubDate>Thu, 19 May 2011 14:32:58 +0800</pubDate>
        </item>
        <item>
            <title>Securing online banking</title>
            <link>http://forum.lowyat.net/topic/1822741</link>
            <description>Few tips here that can help out in the online banking security&lt;br /&gt;&lt;br /&gt;&lt;a href='http://www.itscolumn.com/2011/03/how-to-ensure-online-banking-is-secured.html' target='_blank'&gt;http://www.itscolumn.com/2011/03/how-to-en...is-secured.html&lt;/a&gt;</description>
            <author>highwind</author>
            <category>Security &amp;amp; Privacy</category>
            <pubDate>Tue, 05 Apr 2011 16:36:55 +0800</pubDate>
        </item>
        <item>
            <title>Malaysia FIFA Clans</title>
            <link>http://forum.lowyat.net/topic/524732</link>
            <description>Hey guys,&lt;br /&gt;&lt;br /&gt;Let me introduce myself first. I&amp;#39;m LoOn4tiC from [W|nDs]. As we all know, recently the FIFA gaming scene had improved so much. 128 participants for WCG 07, and 90 over participants for WGT 07 and still counting. Besides number of players participating, number of clans also increasing. As far as i know, there are 5 clan existed in Malaysia&amp;#39;s FIFA scene, who are W|nDs, MyFES, FOX, METC and M|sT. The reason i started this topic is because i wanna gather all the clan members in a place where everyone can spread any incoming news on FIFA. Last year, W|nDs and MyFES have the first ever FIFA Clan War (as far as i know). So maybe next year we can have bigger clan war consist of 5 clans, or other clans can have their own respective clan war. If you don&amp;#39;t mind, I hope the representative of each clan can PM me your contact number so that i can contact you all in future for any upcoming events.&lt;br /&gt;&lt;br /&gt;The following representatives are:&lt;br /&gt;&lt;br /&gt;[W|nDs] : LoOn4tiC&lt;br /&gt;[MyFES] : Sildes, Arroyos&lt;br /&gt;[ToRn@d0] : ken0777&lt;br /&gt;[FOX] : BigBoss&lt;br /&gt;[DEGASA] : Effy14&lt;br /&gt;[METC] : -&lt;br /&gt;[M|sT] : -&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And if there are any new clan forming, you guys can post at this forum here to let the other FIFA players know about this  &lt;!--emo&amp;:)--&gt;&lt;img src='http://static.lowyat.net/style_emoticons/default/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /&gt;&lt;!--endemo--&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;[W|nDs] LoOn4tiC</description>
            <author>highwind</author>
            <category>Competitive Gaming</category>
            <pubDate>Sat, 22 Sep 2007 17:49:55 +0800</pubDate>
        </item>
        <item>
            <title>WCG.MY Closing Video</title>
            <link>http://forum.lowyat.net/topic/521338</link>
            <description>Anyone has the closing video for wcg.my 2007? Not the prize giving, it&amp;#39;s sort of like the overall review of what happened in WCG.MY 2007 throughout the whole WCG theme song (Beyong the Game).&lt;br /&gt;&lt;br /&gt;Thanks &amp;#33;</description>
            <author>highwind</author>
            <category>Gamers Hideout</category>
            <pubDate>Sun, 16 Sep 2007 14:08:47 +0800</pubDate>
        </item>
        <item>
            <title>PES5 Free Kick Help</title>
            <link>http://forum.lowyat.net/topic/244280</link>
            <description>Anyone can guide me through how to take a good free kick.... ?&lt;br /&gt;&lt;br /&gt;My free kick always hit the wall or keeper catches the ball.........any guide to score better ?</description>
            <author>highwind</author>
            <category>Gamers Hideout</category>
            <pubDate>Wed, 25 Jan 2006 18:58:54 +0800</pubDate>
        </item>
    </channel>
</rss>
