Feb 15


At last, they have made decision on Malaysia election date. But I do notice until now they haven’t fix security flaw on “Semakan daftar pemilih”. I hope their programmer improve their website as I’m afraid someone outside will tweak database.

EC Chairman appeals to media to give equal coverage to all political parties

PUTRAJAYA: Malaysians will go to the polls on March 8.

The Election Commission announced that nomination day for the 222 parliamentary and 505 state seats would be Feb 24.

A total of 10,922,139 registered voters on the 2007 master electoral roll gazetted on Feb 5 would be eligible to vote. Of this, 221,085 are postal voters.

Official statement: Abdul Rashid showing the election writ at the press conference to announce the nomination and polling days at his office in Putrajaya yesterday.

Commission chairman Tan Sri Abdul Rashid Abdul Rahman said the number of days for campaigning would be 13 days, inclusive of nomination day.

The campaigning period is longer this time compared with the eight days in the 2004 election, he said, adding that it should be adequate for all parties to conduct their activities.

He added that the commission also took into account internal security and public order when making the decision.

“Thirteen days are more than sufficient. We have been fair; don’t ask for more,” he told a packed press conference after chairing an hour-long meeting with commission members here yesterday.

The dissolution of Parliament took place 15 months before the expiry of its five-year term to pave the way for the 12th general election.

He said the election writs to state election officers would be issued today to inform them to proceed with the conduct of the elections while notices to returning officers in each polling area would be issued tomorrow.

Abdul Rashid said 30 political parties registered with the commission would be contesting.

Stating that March 8 would be the start of a one-week school holiday, Abdul Rashid advised all registered voters to exercise their fundamental rights to cast their votes between 8am and 5pm.

“Don’t sleep on voting day. Come out and vote and be part of the political life of the country. All have full freedom to exercise their rights,” he said, admitting that people were more eager to vote this time.

He also hoped that the usual 75% voter turnout would be bettered or at least maintained this year.

He said the EC would be spending about RM200mil on the elections. There will 149,000 official appointees, mostly schoolteachers, and 50,000 casual workers.

Abdul Rashid said the commission had no power to endorse observers but that it was supportive of efforts by election watchdog group Malaysians for Free and Fair Elections (Mafrel) to continue monitoring the conduct of the general election.

He appealed to the media to give equal airtime and press coverage to all political parties.

On presentation of gifts and offers of treats during the campaign period, Abdul Rashid said based on case law such offers by candidates were an offence but only the police and Anti-Corruption Agency could act against this.

When asked about the party in power allocating funds for development projects during the campaign period, Abdul Rashid said that by convention this had been done over the years and advised those in doubt to “go to the courts”.

On whether candidates’ agents would be allowed to witness counting of postal votes, Abdul Rashid said EC officers would be monitoring and that no decision was made on the matter.

He also assured Malaysians that the polls would be conducted fairly and there should be no fear of vote-rigging and phantom voters.

Transparent plastic ballot boxes, indelible ink and ballot papers without serial numbers would be used in this election, he added.

This is first time I will elect my ghost ‘representative’. the last election I don’t manage to register my name so now i’ll be good Malaysia citizen.

written by ™ ķЯαž£ ™ \\ tags: , , , , , , , , , ,

Feb 06

As Election just around the corner, suddenly I feel need to check my status. So i jump into here and keyin my details. Luckily, system generating this:-

Malaysia Election 2008

MEDAN KETERANGAN
Kad Pengenalan : xxxxxxxxxxxx
Nama : KHAIRUL EFEEZA BIN ISMAIL
Tarikh Lahir : xx xxx xxxx
Jantina : LELAKI
Lokaliti : 131 / 25 / 03 / 002 – TTJ TMN TUANKU JAAFAR
Daerah Mengundi : 131 / 25 / 03 – TAMAN TUANKU JAAFAR
DUN : 131 / 25 – PAROI
Parlimen : 131 – REMBAU
Negeri : NEGERI SEMBILAN
Status Rekod : DATA INI UNTUK SEMAKAN DAFTAR PEMILIH

At last!! I could select who should I pick.. hmm suddenly I would like to see how lousy their programmer is. It doesn’t take me long as I’ve found HUGE FLAW on their website. As this being used as cross reference Malaysia wide, it’s good to have this application SECURE!!

As I’m getting money by telling people how bad is their website, so here some documentation (can’t reveal all due to security reason!)

1) Form validation – do not use JAVASCRIPT!!
This the main error many web developer neglect.

function submitted(){ stripSpaces(); function stripSpaces() { var x = document.def.txtIC.value; document.def.txtIC.value = (x.replace(/^\W+/,\’\')).replace(/\W+$/,\’\'); }

if (document.def.txtIC.value == “”) { alert(“Sila masukkan No. kad pengenalan anda”);} else {

document.def.txtSub.value=”Submitted”; document.def.submit(); document.def.CETAK.enabled();} }

function count(CntValue){ document.def.txtSerial.value=CntValue ; }

Obviously revealing parameter involve. Instead, they should create inner ASP form evaluate to avoid people seeing what paramater involve. From here one with minimum web skills know already where to tweak.

2) No input inner ASP validation
As they are putting obvious Javascript validation, we could test well known SQL penetration test. I won’t reveal process here unless they have fix this “unskilled”error. To conclude, here the output.

Microsoft OLE DB Provider for SQL Server error ’80040e14′
Incorrect syntax near the keyword ‘******’.
/daftar.asp, line 60

From here we could test SQL penetration.

TO CONCLUDE: THIS WEBSITE IS NOT SECURE AT ALL!! PLEASE REDO YOUR WORK LAZY WEBMASTER!!

written by ™ ķЯαž£ ™ \\ tags: , , , , , ,

Dec 05

Let say My IC number is 800613-xx-xxxx… i’m born in 1980

My baby IC number is 070830-xx-xxxx …she born in 2007

My grandchild IC number 340830-xx-xxxx … born in 2034

How about if  my super grand child born in 13 June 2080 and I have longer live?
My super grand child IC number would be 800613-xx-xxxx

1) So how old am I during 2080?  -ANSWER:- NEWBORN BABY WITH 0 years old
2) How old my newly born super grand child? -ANSWER:- 100 years old !

Then my next questions should be:-
1) How to determine you age from IC – NONE

WHAT A FLAW !

written by ™ ķЯαž£ ™ \\ tags: , , , , , , , , ,