WTF?!? Who is Gregory??

hmmm when i tried to reply to this dodgy dog, this is what happened to my machine....

A potentially dangerous Request.Form value was detected from the client (_ctl37:txtMessage="...r: irroot <[email protected]...").
Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.

Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.Form value was detected from the client (_ctl37:txtMessage="...r: irroot <[email protected]...").

Source Error:

An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.

Stack Trace:


[HttpRequestValidationException (0x80004005): A potentially dangerous Request.Form value was detected from the client (_ctl37:txtMessage="...r: irroot <[email protected]...").]
System.Web.HttpRequest.ValidateString(String s, String valueName, String collectionName) +230
System.Web.HttpRequest.ValidateNameValueCollection(NameValueCollection nvc, String collectionName) +99
System.Web.HttpRequest.get_Form() +113
System.Web.UI.Page.GetCollectionBasedOnMethod() +70
System.Web.UI.Page.DeterminePostBackMode() +47
System.Web.UI.Page.ProcessRequestMain() +2106
System.Web.UI.Page.ProcessRequest() +217
System.Web.UI.Page.ProcessRequest(HttpContext context) +18
System.Web.CallHandlerExecutionStep.System.Web.HttpApplication+IExecutionStep.Execute() +179
System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously) +87
 
this is a beauty ...

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">
Dear Mr Nietsky
This is just the cherry on top of several weeks of dissatisfaction with
Sentech. We've experienced problems ranging from extremely slow connection
speeds to "power outages", and "international server unavailability".
It's really getting way too much and if your service does not improve within
the week, ie - before Wednesday 4 August 2004 - I will be taking my business
elsewhere, notwithstanding the fact that I agreed to a 12 month contract.
As Sentech is failing to deliver on its side of the deal, I will be forced
to go elsewhere. My husband and I run two businesses from home, and Sentech
is forcing our clients to look elsewhere. Sentech's lack of service is
damaging our livelihood.
The mistake below is just unacceptable.
Our most recent ticket number regarding a complaint is XXXX (removed by regardtv).
Yours faithfully
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
 
hi there kbentz i promise thats not my fault :) if you need to MSN me do so via your messaanger not the website your browser seems to be blocking it ...

TTFN
 
loose cannon, dont quote peoples job ticket numbers, as this 'outs' them and clearly and easily identifies them to the sentech people watching this forum. If you're hiding names and email addy's, then the job ticket numbers also need to be hidden..
 
That's stupid. It wasn't a quote from a forum member. There's no way they can trace that job ticket to a forum username....
 
nonrooker he has a point they will be able to trace it to a person ie telephone/address/bank number ... who knows what ...

TTFN
 
And that's bad?

"Oh sorry sir...I believe your personal details got out, we're terribly sorry..blah blah blah"
 
http://www.itweb.co.za/sections/techforum/2004/0407280845.asp

is this to throw users off about the spreading of information ??

this is a clever PR stunt bypass the issue by confusing the masses ...
and no doubt themselves ...

TTFN
 
http://www.sentech.co.za/index.php?name=Forum&file=viewtopic&t=39&sid=245af7ff83d2f061552e37cfd3227a5c

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">
SENTECH: OFFICIAL APOLOGY TO MYWIRELESS CUSTOMERS

Dear Customer

Please be informed that we are aware that certain information contained in our MyWireless customer database was inadvertently e-mailed to a small number of MyWireless customers on Saturday, 24 July 2004. We confirm that the database only contained the customer's name, contact number, physical address and e-mail address.

Please understand that the database was sent out through human error as an attachment. Steps to withdraw and delete the e-mail were taken immediately via telephone.

Sentech regrets the incident, apologises for the error and would like to assure you, our valued customer, that we have taken the necessary corrective measures and actions to ensure that this type of error does not occur again in the future.

We trust that you will continue supporting Sentech and its products, in shaping the landscape of our telecommunications industry.

Yours sincerely,

Maureen Mphatsoe
Portfolio Manager: Public and Media Relations
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by loosecannon</i>
<br />http://www.itweb.co.za/sections/techforum/2004/0407280845.asp

is this to throw users off about the spreading of information ??
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

Winston should take a page out of his own book and secure the network at the Golf Park[:0] , yeah thats right, its wide open, or at least it was a few weeks ago.[}:)]

<center>Log your info at MyWireless Survey</center>
 
Pity we were doing a different type of war-driving. E-room wireless network was it?

<div align="left"><font size="2"><font face="Trebuchet MS"> |<font color="blue">256k</font id="blue">| |<font color="blue">26%</font id="blue">| |<font color="blue">66<font color="black">/</font id="black">HYDEPARK</font id="blue">| [:X][8D][:X]
</font id="Trebuchet MS"></font id="size2"></div id="left"><font size="2"> MyWireless: [:)] or [xx(] <font size="4">?</font id="size4"><b>Do the MyWireless User Poll @</b> <font color="blue">http://dorris.hopto.org/</font id="blue"></font id="size2">
 
nonroker - you'd be surpised what the people end up telling customers ...

I just phoned, ONLY gave my ticket reference and said I wanted to check my account details .... guess what .....

It's just too easy.

Remember the access a typical Call Centre staff member has ? ...
 
Comment at the bottom of the ITWeb story:

I think that Sentech should focus on their own security and confidentiality issues.

BY ANDREW FRASER

[28 Jul 2004] Given that Sentech has only recently closed gaping holes in their own network, which allowed all and sundry to rape their international bandwidth; and that they managed to email a confidential subscriber list (including all contact details) to a number of their users in the last week, I`m a little wary of taking advice from Mr Smith.

Well said, Andrew![:D]

Donn Edwards
http://privacy.4mg.com
 
re publicizing job numbers (whether of forumites or others) Its just a good security habit to get into - avoiding listing that little bit of info that can be used to 'social-engineer' the drones at the call centre, or to provide Sentech with a direct link between forumites and their actual usernames.

Anonymity is a good thing, so that Sentech cant easily make a 'baddies list' or in any way clearly identify each forumite over time.

I mean Winston Smith - Dog Trainer and Security Expert himself, tried to sniff out who certain forumites were in reality, from me, when I met him, in the guise of 'simple curiosity' - which I didnt buy for a second. So even a month or more back, they were probably making lists of forumites nicknames and trying to link them to the real individual users - for whatever reason.

And sometimes forumites do put their job numbers up, which means that they are no longer anonymous nicknames on a forum - but a clearly identified user, to Sentech..

Some may not mind that, but its something to consider, depending on what you're saying online about Sentech itself..
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by LoneGunman</i>
<br />
Some may not mind that, but its something to consider, depending on what you're saying online about Sentech itself..

<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

SENTECH - you know who I am, fix your crappy speed problem!

---

There, said it now.


_________________________________________________________________________
No more catenna, now its a custenna
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by noswal</i>
<br />

SENTECH - you know who I am, fix your crappy speed problem!

---

There, said it now.


<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
Ditto for me....I'm not hiding my identity, my name is available for all to see in my profile. Sentech, don't waste time trying to find out who I am....Just fix the problem.


MW128, Tower 50 (Northpark Plaza), Signal:12%,S-N-L: 5, BER: 40%
 
Top
Sign up to the MyBroadband newsletter
X