1. What did you do this past week?

    Last week, I watched 3 episodes of Narcos. Melanie wouldn’t let me touch the show without her consent, so I am stuck on an artificial cliffhanger. Anyways, I did a bit of work on side projects and class assignments (mostly right before the deadline like this one). I went to Houston at the start of the week and I went  to Dallas to finish the week.

  2. What’s in your way?

    Mostly shuffling through the two jobs. This will be resolved within the next 2 weeks.

  3. What will you do next week?

    Start working on the project Collatz. And try my best to do classwork on time.

  4. What’s my experience of the class?

    Last week, I got called on for the first time this semester by Downing. It was a close call since I wasn’t planning on showing up that day.

  5. What’s my pick-of-the-week or tip-of-the-week?

    I read an article last night on how dangerous XML can be. The summary of the article is as follows. If you are using an up-to-date XML parser, and your use-case only involves using xml as a way to transfer data, you should be fine. Otherwise, don’t allow custom entities in your parser settings. There are multiple exploits that target vulnerabilities in how XML is structured.

    An example the author gave involved the use of nested custom entities to generate a billion instances of the word “lol” dynamically on the target machine, wasting many cycles and consuming a lot of memory.

    An even scarier example involved the use of custom entities with values being pulled from the server’s file system.

Categories: CS373

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts


CS373 Fall 2017: Mustafa Taleb

Summary of my experience This semester has gone by pretty fast! I’ve learned a lot of Python, React, SQL, and got a refresher on some of the design patterns I learned from Software Design with Read more…


CS373 Fall 2017: Mustafa Taleb

What did you do this past week? Last week, I was able to turn a project (for work), from 3 months, to only 2 weeks behind schedule. It felt nice being able to deliver something Read more…


CS373 Fall 2017: Mustafa Taleb

What did you do this past week? Last week, I met with the team to discuss and distribute work on the project. We got most of the data in, as well as the player profile Read more…