<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Virtual Employees | Virtual Assistant Services</title>
	<atom:link href="http://www.longerdays.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.longerdays.com</link>
	<description>An leading provider of American based Virtual Employee and Virtual Assistant services.</description>
	<lastBuildDate>Thu, 16 Feb 2012 01:16:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Going Green! by Chad Lawie</title>
		<link>http://www.longerdays.com/going-green/comment-page-1/#comment-1832</link>
		<dc:creator>Chad Lawie</dc:creator>
		<pubDate>Thu, 16 Feb 2012 01:16:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/virtual-assistance/?page_id=723#comment-1832</guid>
		<description>Hello Jen,

I&#039;m not sure if I completely understand the question. Do you mean, can we discuss our services with you before getting started? If so, most certainly! Please call us anytime, M-F, 9-5:30 EST.

Thank you,

Chad</description>
		<content:encoded><![CDATA[<p>Hello Jen,</p>
<p>I&#8217;m not sure if I completely understand the question. Do you mean, can we discuss our services with you before getting started? If so, most certainly! Please call us anytime, M-F, 9-5:30 EST.</p>
<p>Thank you,</p>
<p>Chad</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Going Green! by Jen Yost</title>
		<link>http://www.longerdays.com/going-green/comment-page-1/#comment-1831</link>
		<dc:creator>Jen Yost</dc:creator>
		<pubDate>Wed, 15 Feb 2012 23:50:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/virtual-assistance/?page_id=723#comment-1831</guid>
		<description>Hello - Do you offer a consultation to discuss your VA services? 

Thanks.</description>
		<content:encoded><![CDATA[<p>Hello &#8211; Do you offer a consultation to discuss your VA services? </p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Writing Services by Chad Lawie</title>
		<link>http://www.longerdays.com/writing-service/comment-page-1/#comment-1828</link>
		<dc:creator>Chad Lawie</dc:creator>
		<pubDate>Wed, 15 Feb 2012 20:35:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/virtual-assistance/?page_id=717#comment-1828</guid>
		<description>Hi Jay,

We would definitely be interested! I&#039;ll send you an email so we can discuss the details of the project.

Thank you,

Chad</description>
		<content:encoded><![CDATA[<p>Hi Jay,</p>
<p>We would definitely be interested! I&#8217;ll send you an email so we can discuss the details of the project.</p>
<p>Thank you,</p>
<p>Chad</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Writing Services by Jay</title>
		<link>http://www.longerdays.com/writing-service/comment-page-1/#comment-1827</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Wed, 15 Feb 2012 20:19:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/virtual-assistance/?page_id=717#comment-1827</guid>
		<description>I am interested in learning more about your writing services. We are in the process of establishing a physical newsletter to our members and are looking for writers as well as an editor to make sure it sounds good and to create the layout. 

I will be more than happy to go into more detail in further emails, however i am just looking to gauge your interest in a project such as this and to see if this would fit nicely into your expertise area. 

Thanks 
Jay</description>
		<content:encoded><![CDATA[<p>I am interested in learning more about your writing services. We are in the process of establishing a physical newsletter to our members and are looking for writers as well as an editor to make sure it sounds good and to create the layout. </p>
<p>I will be more than happy to go into more detail in further emails, however i am just looking to gauge your interest in a project such as this and to see if this would fit nicely into your expertise area. </p>
<p>Thanks<br />
Jay</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Receptionist Services by Chad Lawie</title>
		<link>http://www.longerdays.com/receptionist-services/comment-page-1/#comment-1789</link>
		<dc:creator>Chad Lawie</dc:creator>
		<pubDate>Wed, 08 Feb 2012 01:52:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/virtual-assistance/?page_id=707#comment-1789</guid>
		<description>Hello Dr. Boyle,

We have a talented team, and we can help with any task that you are willing to train us to do.

You will work with a single point of contact at LongerDays and you can call that person directly by extension. There is typically no waiting time to speak with your team lead.</description>
		<content:encoded><![CDATA[<p>Hello Dr. Boyle,</p>
<p>We have a talented team, and we can help with any task that you are willing to train us to do.</p>
<p>You will work with a single point of contact at LongerDays and you can call that person directly by extension. There is typically no waiting time to speak with your team lead.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Receptionist Services by Dr. Brian Boyle</title>
		<link>http://www.longerdays.com/receptionist-services/comment-page-1/#comment-1787</link>
		<dc:creator>Dr. Brian Boyle</dc:creator>
		<pubDate>Wed, 08 Feb 2012 00:40:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/virtual-assistance/?page_id=707#comment-1787</guid>
		<description>I am a physician who occasionally requires pre-authorization for certain procedures. If trained, could you do this?

I also need occasional appointment scheduling using an online service. Can you do this for me?

I suppose its possible to call directly to give tasks. Is this right? Sometimes calling is quicker than email.

Is there an average waiting time for calls?

Thanks. Just browsing but looking to hire within the month.</description>
		<content:encoded><![CDATA[<p>I am a physician who occasionally requires pre-authorization for certain procedures. If trained, could you do this?</p>
<p>I also need occasional appointment scheduling using an online service. Can you do this for me?</p>
<p>I suppose its possible to call directly to give tasks. Is this right? Sometimes calling is quicker than email.</p>
<p>Is there an average waiting time for calls?</p>
<p>Thanks. Just browsing but looking to hire within the month.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InfusionSoft 1-click upsell security risks by nonickch</title>
		<link>http://www.longerdays.com/blog/1-click-upsell-with-infusionsoft/comment-page-1/#comment-1731</link>
		<dc:creator>nonickch</dc:creator>
		<pubDate>Thu, 02 Feb 2012 01:03:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/?p=2718#comment-1731</guid>
		<description>just strip out all infusionsoft-special characters like you would do with SQL statements.
That takes care of the wildcard-based attacks, but does not 100% cover for all the attacks.

The problem is that marketing people are all for ease of use, and security is the inverse of ease squared. For example, wildly popular one-click upsell scripts will happily grab your infusionsoft contact ID for an upsell from a cookie. How do you feel about billing random people?</description>
		<content:encoded><![CDATA[<p>just strip out all infusionsoft-special characters like you would do with SQL statements.<br />
That takes care of the wildcard-based attacks, but does not 100% cover for all the attacks.</p>
<p>The problem is that marketing people are all for ease of use, and security is the inverse of ease squared. For example, wildly popular one-click upsell scripts will happily grab your infusionsoft contact ID for an upsell from a cookie. How do you feel about billing random people?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on LongerDays Free Trial by Sean Oberle</title>
		<link>http://www.longerdays.com/longerdays-free-trial/comment-page-1/#comment-1663</link>
		<dc:creator>Sean Oberle</dc:creator>
		<pubDate>Tue, 24 Jan 2012 13:45:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/?page_id=3442#comment-1663</guid>
		<description>I spoke with Chad yesterday.  I am looking for writers to convert government reports, press releases, etc. into short stories (4-8 para) for my newsletter. Ultimately, this would occur on a weekly basis, on Wednesdays or Thursdays.</description>
		<content:encoded><![CDATA[<p>I spoke with Chad yesterday.  I am looking for writers to convert government reports, press releases, etc. into short stories (4-8 para) for my newsletter. Ultimately, this would occur on a weekly basis, on Wednesdays or Thursdays.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InfusionSoft 1-click upsell security risks by Chad Lawie</title>
		<link>http://www.longerdays.com/blog/1-click-upsell-with-infusionsoft/comment-page-1/#comment-1598</link>
		<dc:creator>Chad Lawie</dc:creator>
		<pubDate>Wed, 11 Jan 2012 14:06:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/?p=2718#comment-1598</guid>
		<description>Thought provoking! Thanks for taking the time to share that.

So you are suggesting it is best to setup webforms to create new contacts, and then routinely check for duplicates, instead of having the webform automatically update the contact information if the contact exists.</description>
		<content:encoded><![CDATA[<p>Thought provoking! Thanks for taking the time to share that.</p>
<p>So you are suggesting it is best to setup webforms to create new contacts, and then routinely check for duplicates, instead of having the webform automatically update the contact information if the contact exists.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InfusionSoft 1-click upsell security risks by nonickch</title>
		<link>http://www.longerdays.com/blog/1-click-upsell-with-infusionsoft/comment-page-1/#comment-1597</link>
		<dc:creator>nonickch</dc:creator>
		<pubDate>Wed, 11 Jan 2012 11:53:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.longerdays.com/?p=2718#comment-1597</guid>
		<description>That doesn&#039;t make any sense.
The name would be andrew;cat%20/etc/passwd and if passed to infusionsoft it will happily store it.
This is not a shell script, it&#039;s PHP, so unless you eval (that function is evil) or somehow sneak it in an exec() call.
Also, /etc/shadow is no longer an easily-breakable encryption (well, at least as easy as it used to be in the 90&#039;s)

A real security issue, which is not widely discussed, is the IS API-special characters like % (the wildcard character for searches). Let&#039;s say for example that your upsell script tries to locate a pre-existing contact by his email, before proceeding to bill him with the current product.

is_find($_GET[&#039;Email&#039;]).
if found, get first valid card, bill the product to him and ship to some address.

So, if I type my email to be &quot;a*&quot;, this will match all emails starting with an a. Most scripts just grab the first result of the query and bill him something.

Of course, having such a script where the only verification is an email is so bad, it should be illegal (is it?). But I have seen quite a few floating around. A &quot;get hit first, fix later&quot; security mentality of low-cost development which unfortunately is very popular in contractor-based development.

A more commonplace variation of this exploit is when an API-based webform creates/updates contacts:
1. check if contact already exists (by email).
2. If he exists, update the information on the contact table
3. If he doesn&#039;t exist, create the contact.

In this case one can just wipe clean all your IS contacts by simply spamming the form with emails: a*, aa*. ab*... ba*,bb*...</description>
		<content:encoded><![CDATA[<p>That doesn&#8217;t make any sense.<br />
The name would be andrew;cat%20/etc/passwd and if passed to infusionsoft it will happily store it.<br />
This is not a shell script, it&#8217;s PHP, so unless you eval (that function is evil) or somehow sneak it in an exec() call.<br />
Also, /etc/shadow is no longer an easily-breakable encryption (well, at least as easy as it used to be in the 90&#8242;s)</p>
<p>A real security issue, which is not widely discussed, is the IS API-special characters like % (the wildcard character for searches). Let&#8217;s say for example that your upsell script tries to locate a pre-existing contact by his email, before proceeding to bill him with the current product.</p>
<p>is_find($_GET['Email']).<br />
if found, get first valid card, bill the product to him and ship to some address.</p>
<p>So, if I type my email to be &#8220;a*&#8221;, this will match all emails starting with an a. Most scripts just grab the first result of the query and bill him something.</p>
<p>Of course, having such a script where the only verification is an email is so bad, it should be illegal (is it?). But I have seen quite a few floating around. A &#8220;get hit first, fix later&#8221; security mentality of low-cost development which unfortunately is very popular in contractor-based development.</p>
<p>A more commonplace variation of this exploit is when an API-based webform creates/updates contacts:<br />
1. check if contact already exists (by email).<br />
2. If he exists, update the information on the contact table<br />
3. If he doesn&#8217;t exist, create the contact.</p>
<p>In this case one can just wipe clean all your IS contacts by simply spamming the form with emails: a*, aa*. ab*&#8230; ba*,bb*&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

