Feb 2 2008

OpenID

freebird

Finally a decentralized way of signing into multiple services is here. Now with Yahoo and Google supporting OpenID looks like it is going to take over the world and replace other authentication systems. (good by .NET passport !)
I was using my OpenID URI http://freebird.myopenid.com for sometime now & wanted to use my domain as my OpenID.

how to use blog URL (blogspot) or a domain as OpenID URL

  1. Sign up for an OpenID with a ID provider. (http://myopenid.com is what I am using)
  2. open the index.html or template of your blog / website and add the following to head section.

<link rel=”openid.server” xhref=”http://www.myopenid.com/server”  />

<link rel=”openid.delegate” xhref=”http://freebird.myopenid.com/”  />

The advantage of this method is that our OpenID will remain the same and we can change the ID provider.

In the case of a wordpress blog, we can edit the header.php file of the active template and add the above in the head section.

Enabling OpenID for wordpress blog

  1. get OpenID plugin for wordpress from here
  2. follow the instructions to activate the plugin
  3. if needed, edit the comments.php file of your template as mentioned the README file

Aug 17 2006

Stealing Yahoo! login details

freebird

There is a URL http://www.geocities.com/hott_new_pics_for_you17/ floating around for some days which steals yahoo ids of users.

The login form in the page POSTS the form data to ” http://www2.fiberbit.net/form/mailto.cgi” This cgi script sends the Username and Password to the mail id : staff.yahoo.mail.team@gmail.com in the following format.

____________________________

送信元ホスト名: MY_ISP / IP
送信元ブラウザ: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv: Gecko/20060728 Firefox/1.5.0.6
送信元URL :login = fgfg
passwd = gfgg
.save = Sign In
____________________________

The following mail id occurs when there is an error in form sumbission: root@www2.kjps.net