Schedule

Schedule

Saturday, November 22

1416682800 The Tech Guy

Sunday, November 23

1416769200 The Tech Guy
1416783600 This Week in Tech

Monday, November 24

1416852000 Tech News Today
1416855600 Triangulation
1416861000 iPad Today
1416873600 Tech News 2Night

Tuesday, November 25

1416938400 Tech News Today
1416942000 MacBreak Weekly
1416949200 Security Now
1416956400 Before You Buy
1416960000 Tech News 2Night
1416963600 All About Android
1416972600 Padre's Corner

Wednesday, November 26

1417019400 FLOSS Weekly
1417024800 Tech News Today
1417028400 Windows Weekly
1417035600 This Week in Google
1417046400 Tech News 2Night
1417048200 Android App Arena
1417053600 Ham Nation

Thursday, November 27

1417111200 Tech News Today
1417114800 Know How...
1417118400 Marketing Mavericks
1417123800 Coding 101
1417127400 Home Theater Geeks
1417132800 Tech News 2Night
1417134600 The Giz Wiz

Friday, November 28

1417197600 Tech News Today
1417201200 This Week in Law
1417219200 Tech News 2Night

Saturday, November 29

1417287600 The Tech Guy

Sunday, November 30

1417374000 The Tech Guy
1417388400 This Week in Tech

Monday, December 1

1417456800 Tech News Today
1417460400 Triangulation
1417465800 iPad Today
1417478400 Tech News 2Night

Most Recent Episodes

This Week in Law

Does a broad privacy policy grant a company access to customer data?

Tech News 2Night

Uber's bad PR Prompts Changes at Lyft

Tech News Today

Google and Rockstar settle their patent case

The Giz Wiz

3D fruit printer, Mous Musicase, Nomiku sous vide, and more!

This Week in Computer Hardware

Dell's 60Hz IPS Monitors, Gorilla Glass 4, and Windows 10.

Coding 101

The holiday pricer.

Tech News 2Night

Google's Tool to Remove Ads

Home Theater Geeks

3D Audio, Acoustic Room Design, and Anythony Grimani.

Marketing Mavericks

LinkedIn, HR resumes, Social Footprint

Know How...

Network of pollution, viewer questions, and Quadcopters

Coding 101 13

Sanitize')DROP TABLE Python;

April 17 2014

Hosts: Fr. Robert Ballecer, SJ and Shannon Morse

Guest: Dale Chase

Welcome to Coding 101 - It's the TWiT show that gives YOU the knowledge to live in the wonderful world of the programmer. This week we are introducing our newest module, Python with Code Warrior Dale Chase!

To see all the code used in today's episode, go to Our Github Repository for Module 2

Loops (Recap)

* As we may recall, loops are an easy way to reuse code.
* It allows us to "loop" a section of code so that it doesn't have to be writen over and over.

While Loops
"While loops in Python work very much like they do in C#

They use some sort of counter and some sort of relational true/false statement. The while loop will continue to run as long as the statement is true. The true/false statement is pre-test, meaning that it will evaluate the statement BEFORE the loop code is executed."

Code Sample:

counter = 0

while counter < 5:

counter = counter +1
print counter

Output:
1
2
3
4
5"

Sanitizing your Input!

The Heartbleed Bug

What is the Hearbeat?
* The problem lies in the "Hearbeart"
- It's a way to keep a SECURE TLS session alive /// to keep it from "timing out"
- The Heartbeat is a payload of arbitrary data which is sent from one end of the connection to the other, and back again.
- If the heartbeat makes the round trip intact, then both sides of the connection know that the connection is still active and still secure.

Here is the OpenSSL Code

(The Bug starts on Line 3972)
/* Read type and payload length first */

hbtype = *p++;

n2s(p, payload);

pl = p;

hbtype is the TYPE of data

P++ increments the pointer

p is the pointer for the payload

payload is the length of the payload"

The problem is that the SENDER gets to set the "payload" length and the code never checks to see if the sent length matches the recieved length of the payload.

The Crux of the Matter:
* The Hearbleed bug stems from code that does not check to make sure it's recieving into memory what it expected.
* In other words... IT DIDN'T SANITIZE IT'S INPUT!

Get in Touch With Us!

* Subscribe and get Coding 101 automatically at TWiT.tv!
* Follow PadreSJ and Snubs on Twitter.
* Watch the show live and join the chatroom every Thursday at 1:30pm PST.
* Email us at Padre@twit.tv and Shannon@twit.tv.
* Join our Google+ Community!

Download or subscribe to this show at twit.tv/code. Also, check out our transcripts.

Bandwidth for Coding 101 is provided by Cachefly.

Running time: 41:46

Sponsors: