From maine-pm at mail.pm.org Thu Aug 7 10:30:17 2003 From: maine-pm at mail.pm.org (maine-pm@mail.pm.org) Date: Mon Aug 2 21:32:11 2004 Subject: [Maine-pm] 3-6 month Contract in Portland Message-ID: <001a01c35cf8$ce0a6b60$0a00a8c0@jminieri2> I'm not sure if anyone is interested in this, but it came across the Boston.pm group and I thought I'd forward it here: Cue Data Services is recruiting for the following position in Portland, ME: Client is an international company with huge online catalogue sales. Local candidates strongly preferred 3-6 month contract No third parties - no sponsorship Experience required with Perl/DB2 (must be Perl+DB2) on Unix. A plus would be experience with COBOL/DB2 on an OS390 Mainframe. Consultant will be doing production support (small pieces) of large projects. Start date is ASAP Regards, Dennis Cotrone Business Development / Technical Recruiter Cue Data Services, Inc. 45 Accord Park Drive Norwell, MA 02061 888-562-5945 ext. 310 Fax # 781-749-0515 dennisc@cuedata.com cuedata03@yahoo.com 2000 Inc. 500 Company 1999 Inc. 500 Company 1999 Unisys Outstanding Vendor 1998 Unisys Outstanding Vendor Computer Associates Channel Partner - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Visit our TALENT STORE at http://www.cuedata.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Visit our Software Site at http://www.cue-metamon.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ------------------------------------------------ Joe Minieri, CISSP Director of Application Engineering OpenService 110 Turnpike Road, Suite 308 Westborough, MA 01581 Phone: 508-380-6372 AIM: minieri -------------- next part -------------- An HTML attachment was scrubbed... URL: http://mail.pm.org/pipermail/maine-pm/attachments/20030807/83326993/attachment.htm From maine-pm at mail.pm.org Wed Aug 20 05:21:17 2003 From: maine-pm at mail.pm.org (maine-pm@mail.pm.org) Date: Mon Aug 2 21:32:11 2004 Subject: [Maine-pm] Administrative Update Message-ID: <002b01c36704$cb3e6560$0a00a8c0@jminieri2> Hi guys - We've got a few new members on the list - which is good news. I can't tell where everyone lives, but perhaps we're close to a quorum for a meeting. We've got 10 subscribers, including Andrew from Massachusetts. I've been trying to get the website thing straightened out, but I've received no responses to my emails - I've even been polite (no comments!). I'll keep pressing on. Joe ------------------------------------------------ Joe Minieri, CISSP Director of Application Engineering OpenService 110 Turnpike Road, Suite 308 Westborough, MA 01581 Phone: 508-380-6372 AIM: minieri -------------- next part -------------- An HTML attachment was scrubbed... URL: http://mail.pm.org/pipermail/maine-pm/attachments/20030820/5fd1d62b/attachment.htm From maine-pm at mail.pm.org Wed Aug 20 05:25:54 2003 From: maine-pm at mail.pm.org (maine-pm@mail.pm.org) Date: Mon Aug 2 21:32:11 2004 Subject: [Maine-pm] Perl/CGI exploits Message-ID: <003001c36705$700b1de0$0a00a8c0@jminieri2> I was reading Phrack the other day and came across this old, but interesting article that details some potential problems in scripts: http://www.phrack.org/show.php?p=55 &a=7 I was curious if anyone had any experiences with sloppy/vulnerable Perl scripts (written by others, of course) or tips on writing secure scripts. Thanks ------------------------------------------------ Joe Minieri, CISSP Director of Application Engineering OpenService 110 Turnpike Road, Suite 308 Westborough, MA 01581 Phone: 508-380-6372 AIM: minieri -------------- next part -------------- An HTML attachment was scrubbed... URL: http://mail.pm.org/pipermail/maine-pm/attachments/20030820/627930cb/attachment.htm From maine-pm at mail.pm.org Wed Aug 20 09:09:23 2003 From: maine-pm at mail.pm.org (maine-pm@mail.pm.org) Date: Mon Aug 2 21:32:11 2004 Subject: [Maine-pm] Perl/CGI exploits Message-ID: I prefer php for web scripting lately, though I'm sure it has it's own set of security vulnerabilities. I still use perl for it's rich set of modules and SNMP support, but limit my development to command line scripts that run as cron jobs. Those jobs update MySQL databases and my php scripts act as a front end for users who want to search the database. I couldn't get to Phrack.org, my company proxy classifies it as a "criminal skills" site! (Or should that be skillz?) Have to check it from home. Ron Lussier L.L. Bean, Inc. Network Management Analyst (207) 552-5152 >>> 08/20/03 06:25AM >>> I was reading Phrack the other day and came across this old, but interesting article that details some potential problems in scripts: http://www.phrack.org/show.php?p=55&a=7 I was curious if anyone had any experiences with sloppy/vulnerable Perl scripts (written by others, of course) or tips on writing secure scripts. Thanks ------------------------------------------------ Joe Minieri, CISSP Director of Application Engineering OpenService 110 Turnpike Road, Suite 308 Westborough, MA 01581 Phone: 508-380-6372 AIM: minieri -------------- next part -------------- An HTML attachment was scrubbed... URL: http://mail.pm.org/pipermail/maine-pm/attachments/20030820/0a978ab0/attachment.htm