[CODE4LIB] yaml/xml/json, POST data, bloodcurdling terror

2015-12-17 Thread Brian Hoffman
Thanks, this was interesting. But the JSON segment is a little less than terrifying as it’s predicated on the misuse of eval(), which is commonly and easily avoided. > On Dec 17, 2015, at 11:00 PM, CODE4LIB automatic digest system > wrote: > > > Date:Thu, 17 Dec 2015 09:22:07 -0500 >

[CODE4LIB] RETRACTION: Code4Lib Keynote Speakers

2015-12-17 Thread Whitni Watkins
Whoops! Crossed wires sometimes causes problems. Please disregard previous email about Code4Lib 2016 keynote speakers and watch for a correction email. Thanks, Whitni Watkins on behalf of the keynote committee

Re: [CODE4LIB] yaml/xml/json, POST data, bloodcurdling terror

2015-12-17 Thread Eric Lease Morgan
On Dec 17, 2015, at 8:22 AM, Andromeda Yelton wrote: > I strongly recommend this hilarious, terrifying PyCon talk about > vulnerabilities in yaml, xml, and json processing: > > https://www.youtube.com/watch?v=kjZHjvrAS74 > > If you process user-submitted data in these formats and don't yet k

[CODE4LIB] Job: Assistant Director for Digital Collections at The National WWII Museum

2015-12-17 Thread jobs
Assistant Director for Digital Collections The National WWII Museum New Orleans This position reports to the Director of Curatorial Services and is responsible for directing the digitization of the Museum's collections and the subsequent management of these materials. Content to be digitized inclu

[CODE4LIB] Job: Digital Technician at George Eastman House

2015-12-17 Thread jobs
Digital Technician George Eastman House Rochester The George Eastman Museum is seeking candidates for a Digital Technician position in its Moving Image Department. This is a full time, grant funded position, with possibility of renewal. The Museum preserves over 28,000 film titles in all film gaug

[CODE4LIB] Code4Lib 2016 Keynote Speakers

2015-12-17 Thread Whitni Watkins
Hello list, I'm very happy to announce that the keynote speakers selected through our community voting process have agreed to keynote the 2016 Code4Lib conference in Philadelphia. *Kimberly Bryant* (http://www.blackgirlscode.com/about-bgc.html) will provide the opening keynote on March 8th and *

[CODE4LIB] Job: Data & Publications Librarian at Inter-American Development Bank

2015-12-17 Thread jobs
Data & Publications Librarian Inter-American Development Bank Washington, D.C. The Inter-American Development (IDB) Bank Main Library seeks a collaborative, energetic, innovative and service-oriented Data and Publications Librarian to join its established team of information professionals. Thi

[CODE4LIB] Job: Application Developer at University of Pennsylvania

2015-12-17 Thread jobs
Application Developer University of Pennsylvania Philadelphia _Duties_ The Penn Libraries Digital Library team is looking for a self-motivated, detail-oriented applications programmer who will be responsible for the development, monitoring, and on-going maintenance of web-based software used t

Re: [CODE4LIB] yaml/xml/json, POST data, bloodcurdling terror

2015-12-17 Thread David Mayo
Thanks! That's really solid. I just spent $EMBARRASSINGLY_LONG_TIME figuring out how to turn off half of Saxon's XML parsing functionality for some of these reasons. On Thu, Dec 17, 2015 at 9:22 AM, Andromeda Yelton < andromeda.yel...@gmail.com> wrote: > I strongly recommend this hilarious, terr

[CODE4LIB] yaml/xml/json, POST data, bloodcurdling terror

2015-12-17 Thread Andromeda Yelton
I strongly recommend this hilarious, terrifying PyCon talk about vulnerabilities in yaml, xml, and json processing: https://www.youtube.com/watch?v=kjZHjvrAS74 If you process user-submitted data in these formats and don't yet know why you should be flatly terrified, please watch this ASAP; it's il

[CODE4LIB] Job: Content System and Collections Strategist at University of Cincinnati

2015-12-17 Thread jobs
Content System and Collections Strategist University of Cincinnati Cincinnati, OH The University of Cincinnati Libraries seeks an innovative professional to support our high quality research collections in increasing digital formats as a Content System and Collections Strategist. In collaboration