Welcome to BARMAGY Sign in | Join | Help

The most common software security mistakes

Through my humble experience with software development I’ve seen developers making fetal security mistakes without even feeling that they are doing something wrong. So I’ve decided to gather these common mistakes in a list so it would be easier to avoid. Through this article I will give examples regardless to the used technology but the concepts applies to all technologies. So here we go

1.       Don’t hide confidential information within your code: whatever you do don’t rely on hiding information within your code because as long your code is distributed to the client then the client might do with it as s/he wishes, which includes disassembling or decompiling your code and obtaining your confidential information. The kind of confidential information that you shouldn’t hide within your code might include but is not limited to passwords, user names, connections strings, IP addresses, domain names, symmetric encryption algorithms and of course  symmetric encryption keys. And of course don’t rely on obfuscation.

2.       Don’t forget to validate user input: sounds obvious but most developers think that user input is only limited to the user controls like text boxes and submit buttons but that is not true. User input might include but not limited to server requests, browser cookies, query strings and post requests. If you are expecting a zip code entered by the user then the user won’t need special characters like (!@#$%^&*()”’;:<>) so your application must not accept them. If the user will send you a request with an integer id in the query string then you don’t need negative values so your application must not accept them. SQL injection attacks and privileges escalations might happen through cookies if you don’t validate its content properly before processing it.

3.       Don’t validate input at the client side: for example in web applications don’t validate user input using java script because the user might disable java script in his/her browser. In case of windows applications the user might be able to reverse engineer the application and reverse the validation algorithm to pass the unwanted input.

4.       Don’t send confidential information to the client side: if you send any confidential information like network credentials to the client side then the user might be able to intercept it using any means like packet sniffing and analyze it to use it to access your resources unauthorized.

5.       Don’t send user confidential data on a network without encryption: if you are sending your user credentials or any other critical data on any sort of network you better encrypt the whole connection so no one would be able to intercept the connection and extract the confidential information from it. For web applications SSL would be sufficient for non critical applications.

6.       Don’t send data to host without confirming it’s the legitimate host: for example don’t authenticate on a server without confirming it’s the legitimate one because it might be just a trap to gather your users’ credentials. Basically this is easily done with the use of Active Directory as a 3rd party to authenticate both parties and confirm for each one that the other party is the legitimate one.

7.       Don’t save any confidential information at the client side: if you saved user passwords on his/her machine and it got compromised then the attacker would obtain the user passwords with ease, so you should always encrypt any confidential data when saving it at the client side to avoid this from happening.

8.       Don’t be selfish and protect your user not only your system: most developers think always that the users are always the bad guys whom are trying to penetrate and bring down the system but it’s rarely when you find developers that think of users as victims whom might get attacked with the use of there system. XSS attacks proves this.

9.       Don’t be optimistic: don’t remove security validations because the current part is only accessed by admins, the admin account maybe highjacked and used to control the whole system that is running your application.

10.   Be paranoid: always think the worst. The more your system is critical and you want it to be secure the more you must be paranoid. Always plan for the worst, for example consider if your servers got compromised so how are you going to protect your users confidential data? What if your servers got flooded or your connections were down? What if your users got hacked and there credentials were stolen? What if your network was penetrated and what if your traffic was filtered? You must always ask your self the worst questions while designing the security schemes of your application.

Thanks for reading and I wish you have enjoyed this article. I would like to hear your opinions so your comments and feedbacks would be really appreciated.

kick it on DotNetKicks.com
Published Tuesday, September 04, 2007 1:04 AM by Fady

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

# The most common software security mistakes

You've been kicked (a good thing) - Trackback from DotNetKicks.com
Tuesday, September 04, 2007 1:12 AM by DotNetKicks.com

# re: The most common software security mistakes

A very nice list which should always kept in mind when designing applications.
Tuesday, September 04, 2007 9:20 PM by Wim Haanstra

# re: The most common software security mistakes

thanks and i hope you enjoyed it :)
Wednesday, September 05, 2007 4:38 PM by Fady

# re: The most common software security mistakes

For number 3, always validate user input on the server side, but I don't think it's a bad thing to validate user input on the client as well.  You should really validate both places.  A web application with no client side validation can get really ugly.
Wednesday, September 05, 2007 7:28 PM by Matt Casto

# re: The most common software security mistakes

@Matt
thanks for the feedback
i didn't mean that validating on the client side while validating on the server side is wrong
i meant counting only on the client side validation is wrong
for example you can't authenticate a user on the client side, or check for invalid characters, XSS and sql injections on the client side without doing so on the server side
i suggest that validation at the client side should be only for usability not for security so the user don't have to wait till a web page load or till a windows applications calls a XML web service or something similar
Wednesday, September 05, 2007 11:05 PM by Fady

# re: The most common software security mistakes

Great list Fady
For #3, You have to validate on both sides, but the primary validation is the server side one, and the extra is the client side
Saturday, September 08, 2007 11:21 PM by Mohammed Hossam

# re: The most common software security mistakes

@Mohammed
thanks Mohammed
"For #3, You have to validate on both sides, but the primary validation is the server side one, and the extra is the client side "
yes thats right, i was just emphasizing that client side validation can always be bypassed
for example you can't write something like this in javascript at the client side :)
if(password == "secret")
doStuff()
Saturday, September 08, 2007 11:51 PM by Fady

# re: The most common software security mistakes

well i think its not all the scurity mistakes that software have but i really loved the list u had did and thats why i love open scoures coz it can fix others mistakes nice work and i had learn somethins new and keep writing .
Thursday, January 10, 2008 4:04 AM by mostafa

# re: The most common software security mistakes

@mostafa
thanks man, yes this is not a full list of course, it's just the most common mistakes as the way i see it, others may not agree with me and see this list from a different aspect
thanks again and i hope u enjoyed the article
Friday, January 11, 2008 4:35 AM by Fady

# re: The most common software security mistakes

FPnxPA  <a href="http://qszqltynjkwu.com/">qszqltynjkwu</a>, [url=http://pdjvzvfxbren.com/]pdjvzvfxbren[/url], [link=http://fgtceqjlplkm.com/]fgtceqjlplkm[/link], http://fefjniwcwnza.com/
Friday, March 21, 2008 4:44 PM by mwpofrq

# re: The most common software security mistakes

M6E0Xd  <a href="http://vyjgoiorvlub.com/">vyjgoiorvlub</a>, [url=http://bomcktxrjknh.com/]bomcktxrjknh[/url], [link=http://vsdpdgyoludq.com/]vsdpdgyoludq[/link], http://fllmbyvcnynx.com/
Tuesday, May 20, 2008 9:56 AM by wgebsdeymdf

# re: The most common software security mistakes

fikuKv  <a href="http://pqxmypwuwern.com/">pqxmypwuwern</a>, [url=http://ztumkpmiekmn.com/]ztumkpmiekmn[/url], [link=http://gawchfeorniv.com/]gawchfeorniv[/link], http://tbbpkubcpety.com/
Tuesday, May 20, 2008 10:44 AM by thblttmnlm

# Cheap Avodart

Hi! rather righteous employ!
[url=http://bodk2544winw.byethost13.com]avodart side effects[/url]
Best regards! ;)
Wednesday, July 02, 2008 12:56 PM by FreeAvodart

# Cheap Doxazosin

Hi! deeply advantageous labour!
[url=http://hest6544floy.0catch.com/doxazosin-used-to-treat.html]doxazosin used to treat[/url]
Best regards! ;)
Wednesday, July 02, 2008 9:59 PM by FreeDoxazosin

# Cheap Hytrin

Hi! deeply usefulness come to c clear up!
[url=http://bodk2544winw.00freehost.com/hytrin-dyspepsia.html]hytrin dyspepsia[/url]
Best regards! ;)
Thursday, July 03, 2008 1:36 PM by FreeHytrin

# Cheap Proscar

Hi! utter advantageous come to c clear up!
[url=http://lucy5480regi.100freemb.com/painful-erection-proscar.html]painful erection proscar[/url]
Best regards! ;)
Thursday, July 03, 2008 6:10 PM by FreeProscar

# Cheap Kamagra

Hi! rather advantageous come to c clear up!
[url=http://hest6544floy.byethost31.com/kamagra-st-lemon-flavour.html]kamagra st lemon flavour[/url]
Best regards! ;)
Thursday, July 03, 2008 10:33 PM by FreeKamagra

# re: The most common software security mistakes

ferret2020|AWWWWп»ї bye robot :D
 
<a href="http://pillsinter.com/?p=56">boosterthon prizes 2010</a>

a1syaaqqa
Wednesday, March 23, 2011 9:36 PM by mumUnopeChume

# re: The most common software security mistakes

NY0KCk AFAICT you've covered all the bases with this answer!
Saturday, April 09, 2011 7:18 PM by Destiny

# re: The most common software security mistakes

Monday, April 11, 2011 7:04 PM by eibuyabo

# re: The most common software security mistakes

Thursday, April 21, 2011 9:15 PM by otjganj

# re: The most common software security mistakes

Friday, April 22, 2011 11:37 AM by iubbhwzfi

# re: The most common software security mistakes

I had got a dream to make my own firm, nevertheless I didn't earn enough of money to do this. Thank goodness my friend recommended to take the home loans. Thus I took the sba loan and made real my old dream.
Wednesday, May 04, 2011 10:31 AM by loans

# re: The most common software security mistakes

That is no matter how hard you want to complete high quality america essay, because the masters custom essays writing firm can do that much better. Hence, take a rest and purchase essays.
Monday, May 09, 2011 10:48 PM by art essay

# re: The most common software security mistakes

There's a terrific amount of knowledge in this atrilce!
Tuesday, August 09, 2011 6:08 AM by Retta

# re: The most common software security mistakes

Tuesday, August 09, 2011 1:41 PM by fabiktyb

# re: The most common software security mistakes

Thursday, August 11, 2011 6:59 PM by xbgeyznnre

# re: The most common software security mistakes

I always propose university students  to buy college essay just because it is a correct solution for people who are not experienced in writing.
Thursday, October 20, 2011 9:02 AM by essay samples

# rtrtew

buy cialis Online    
[u][/u]
Monday, December 26, 2011 6:29 PM by viagra

# rtrtew

buy cialis Online    
[u][/u]
Monday, December 26, 2011 6:29 PM by viagra

# rtrtew

buy cialis Online    
[u][/u]
Monday, December 26, 2011 6:30 PM by viagra

# rtrtew

buy cialis Online    
[u][/u]
Monday, December 26, 2011 6:30 PM by viagra

# rtrtew

buy cialis Online    
[u][/u]
Monday, December 26, 2011 6:30 PM by viagra

# gffPcUxGmtuTqp

Wednesday, January 25, 2012 7:27 AM by pHLMEZJ7

# hwgUyTULTKxtt

Could you ask him to call me? <a href=" http://BuyZopicloneat.blog.cz/ ">Buy Zopiclone </a>  051
Wednesday, January 25, 2012 2:21 PM by Rmktaryd

# CbJcwWYUeK

How much is a First Class stamp? <a href=" http://BuyZolpidem.blog.cz/ ">Buy Zolpidem </a>  077312
Wednesday, January 25, 2012 3:30 PM by Fszjzjqi

# DQdzmJOLgHpE

I'm a trainee  <a href=" http://ValiumOnlinee.blog.cz/ ">Valium Online </a>  :O
Wednesday, January 25, 2012 6:58 PM by Pjacuces

# fWZmxxBdrKQhKAQE

I'd like to apply for this job <a href=" http://BuyAtivan.blog.cz/ ">Buy Ativan </a>  znwzti
Wednesday, January 25, 2012 9:13 PM by Wqniymjt

# UvPqHxGJnLvNsWCE

Do you like it here?
Wednesday, January 25, 2012 10:46 PM by Eharviap

# HsfQKmgrdVwsmughWws

Are you a student? <a href=" http://BuyClonazepamyt.blog.cz/ ">Buy Clonazepam </a>  7669
Thursday, January 26, 2012 1:39 AM by Xcbelksx

# jvcsbUlvHBHxugIz

I'm training to be an engineer <a href=" http://BuyTopamax.blog.cz/ ">Buy Topamax </a>  tov
Thursday, January 26, 2012 2:46 AM by Mdkndcjy

# phFEWKVdYDsA

I support Manchester United <a href=" http://BuyModalert.blog.cz/ ">Buy Modalert </a>  >:-[
Thursday, January 26, 2012 3:53 AM by Iuxdqgrf

# vrfhbCLlgAFriLt

I'm on business <a href=" http://LorazepamNoPrescriptioniky.blog.cz/ ">Lorazepam No Prescription </a>  7754
Thursday, January 26, 2012 5:00 AM by Eermkwum

# DUmnlUKVMMYfQI

I'm doing an internship <a href=" http://BuyValiumne.blog.cz/ ">Buy Valium </a>  262723
Thursday, January 26, 2012 9:26 AM by Tyhmbmzv

# DryPQeaOcHNc

History <a href=" http://CheapValiumbo.blog.cz/ ">Cheap Valium </a>  %-[[[
Thursday, January 26, 2012 11:39 AM by Tubzkykl

# apUjKmSapWbOvb

I'm originally from Dublin but now live in Edinburgh <a href=" http://BuyRetinA.blog.cz/ ">Buy Retin A </a>  7694
Thursday, January 26, 2012 12:47 PM by Dftvrint

# hmaQluCNIKQVUOPt

very best job <a href=" http://CheapAtivan.blog.cz/ ">Cheap Ativan </a>  61741
Thursday, January 26, 2012 1:56 PM by Shizdzci

# BAwxFARSJpZTBvo

Could I have a statement, please? <a href=" http://Stilnoxy.blog.cz/ ">Stilnox </a>  qqvptz
Thursday, January 26, 2012 4:17 PM by Gtphcawf

# LxguGVJipfKH

I like it a lot <a href=" http://BuyRivotrilek.blog.cz/ ">Buy Rivotril </a>  723
Thursday, January 26, 2012 5:27 PM by Qyvvevxy

# kFWrvKFYRyeV

I want to make a withdrawal <a href=" http://BuyLunesta.blog.cz/ ">Buy Lunesta </a>  cnht
Thursday, January 26, 2012 6:37 PM by Ictwuobh

# OKfemPVcJhUMw

Can you hear me OK? <a href=" http://BuyAtivanNoPrescriptionqag.blog.cz/ ">Buy Ativan No Prescription </a>  82374
Friday, January 27, 2012 11:07 PM by Xlcrasbg

# lzqobtmtEAaMFQwOml

We're at university together <a href=" http://BuyModafinil.blog.cz/ ">Buy Modafinil </a>  qpuu
Saturday, January 28, 2012 3:14 AM by Qetzcuvq

# kRwZnYNUayOmq

Could you please repeat that? <a href=" http://BuyStilnox.blog.cz/ ">Buy Stilnox </a>  bmxczb
Saturday, January 28, 2012 4:24 AM by Dmqpozey

# FARTaRtAUuGsPUEmV

The United States <a href=" http://BuyTemazepam.blog.cz/ ">Buy Temazepam </a>  :-PPP
Saturday, January 28, 2012 5:36 AM by Irrkzzzw

# scNKVfKVps

Enter your PIN <a href=" http://BuyProvigil.blog.cz/ ">Buy Provigil </a>  :PP
Saturday, January 28, 2012 6:46 AM by Hzjadjxj

# RuBAjSftVDkmdAB

What's your number? <a href=" http://BuyLibrium.blog.cz/ ">Buy Librium </a>  wwvd
Saturday, January 28, 2012 9:10 AM by Lzfujnth

# QsbedLmvYyHeRhIMj

I'd like to apply for this job <a href=" http://SleepingPills.blog.cz/ ">Sleeping Pills </a>  06571
Saturday, January 28, 2012 11:36 AM by Yhwkbiss

# BBttBlMQVbXcmb

History <a href=" http://BuyDiflucan.blog.cz/ ">Buy Diflucan </a>  8-]
Saturday, January 28, 2012 12:52 PM by Hlenetnb

# AJgYauTFRBOYwqBhw

Good crew it's cool :) <a href=" http://BuyCymbalta.blog.cz/ ">Buy Cymbalta </a>  031
Saturday, January 28, 2012 2:04 PM by Pcnuojeu

# xorJrtwlBWnF

How do I get an outside line? <a href=" http://Lunesta.blog.cz/ ">Lunesta </a>  tpg
Saturday, January 28, 2012 3:19 PM by Myoojnik

# CVeIAHndUzaQSbP

Will I have to work on Saturdays? <a href=" http://ZolpidemWithoutPrescription.blog.cz/ ">Zolpidem Without Prescription </a>  %[[
Saturday, January 28, 2012 4:35 PM by Nvqdaoas

# gxCUhyNtRbIDglXZV

I'd like to cancel this standing order <a href=" http://ClonazepamOnlineyri.blog.cz/ ">Clonazepam Online </a>  qqb
Saturday, January 28, 2012 5:50 PM by Cqcanues

# prQilmUgwhLFcc

this is be cool 8) <a href=" http://BuyStrattera.blog.cz/ ">Buy Strattera </a>  24672
Saturday, January 28, 2012 9:28 PM by Ybtgewdv

# gDVqgCfvCVvEJXt

I'd like to cancel a cheque <a href=" http://BuyImitrex.blog.cz/ ">Buy Imitrex </a>  %-(
Saturday, January 28, 2012 11:46 PM by Wzzoaiwf

# gDVqgCfvCVvEJXt

I'd like to cancel a cheque <a href=" http://BuyImitrex.blog.cz/ ">Buy Imitrex </a>  %-(
Saturday, January 28, 2012 11:48 PM by Wzzoaiwf

# nXPvouTDbyaPHxmOWSV

I'd like to pay this cheque in, please <a href=" http://BuyValiumOnline.blog.cz/ ">Buy Valium Online </a>  :-))
Sunday, January 29, 2012 3:13 AM by Jnfzecbl

# bMDMAvEUciTViK

I live here <a href=" http://BuyNitrazepam.blog.cz/ ">Buy Nitrazepam </a>  wzo
Sunday, January 29, 2012 4:23 AM by Bbrwbgpx

# puqaahZSWDBFLmQMh

How much notice do you have to give? <a href=" http://BuySeroquelfaf.blog.cz/ ">Buy Seroquel </a>  =-O
Sunday, January 29, 2012 5:34 AM by Xsnlecqo

# zdKSaNClJtsnQNZIMA

It's a bad line <a href=" http://AdderallXr.blog.cz/ ">Adderall Xr </a>  8-DDD
Sunday, January 29, 2012 7:57 AM by Jnzousia

# arcfnENRmKBoOVT

I came here to work <a href=" http://CheapLorazepamiu.blog.cz/ ">Cheap Lorazepam </a>  813
Sunday, January 29, 2012 11:34 AM by Nvemovft

# QOqalRDAooEkr

On another call <a href=" http://PainPillsOnline.blog.cz/ ">Pain Pills Online </a>  rwnv
Sunday, January 29, 2012 5:39 PM by Botmlagq

# vSCZbZGZYYLSt

I came here to study <a href=" http://CheapZolpidem.blog.cz/ ">Cheap Zolpidem </a>  :DDD
Sunday, January 29, 2012 8:07 PM by Pleohduc

# BtCZMvgYenSHfOMt

I'm a housewife <a href=" http://BuyZopicloneqes.blogoak.com/?postarch=2 ">Buy Zopiclone </a>  741009
Monday, January 30, 2012 1:19 AM by Joavxssb

# OUNyxEzgHJEbWAwDZr

It's funny goodluck <a href=" http://BuyZolpidemmap.blogoak.com/?postarch=2 ">Buy Zolpidem </a>  uenot
Monday, January 30, 2012 2:29 AM by Mrmxaxlj

# QCHDAydvwpMebXrTsgS

I'd like to cancel this standing order <a href=" http://ValiumOnlineyja.blogoak.com/?postarch=2 ">Valium Online </a>  570
Monday, January 30, 2012 6:00 AM by Rhpdkusk

# omQxwZYSXmESPEZSq

Could you tell me the number for ? <a href=" http://BuyAtivanogy.blogoak.com/?postarch=2 ">Buy Ativan </a>  62820
Monday, January 30, 2012 8:23 AM by Yfacijhi

# opUvVeTeojtYPatE

Which university are you at? <a href=" http://CheapClonazepamata.blogoak.com/?postarch=2 ">Cheap Clonazepam </a>  :-OOO
Monday, January 30, 2012 11:59 AM by Wmepycjf

# oSZasofygC

Which university are you at? <a href=" http://BuyClonazepamre.blogoak.com/?postarch=2 ">Buy Clonazepam </a>  vhgag
Monday, January 30, 2012 1:13 PM by Kghlwkca

# TYPJAeheec

A book of First Class stamps <a href=" http://BuyTopamaxis.blogoak.com/?postarch=2 ">Buy Topamax </a>  :-]]
Monday, January 30, 2012 2:27 PM by Mpwiqilv

# uKrabgHMXjz

Is this a temporary or permanent position? <a href=" http://BuyModalertgoc.blogoak.com/?postarch=2 ">Buy Modalert </a>  :-PPP
Monday, January 30, 2012 3:09 PM by Dhwfwwuj

# gHyRGpfUwRsKvxp

A company car <a href=" http://LorazepamNoPrescriy.blogoak.com/?postarch=2 ">Lorazepam No Prescription </a>  8PP
Monday, January 30, 2012 4:26 PM by Hpzzgyus

# FDOtHdjPwlJAUATco

I'd like to send this parcel to  <a href=" http://BuyValiumyc.blogoak.com/?postarch=2 ">Buy Valium </a>  884
Tuesday, January 31, 2012 12:26 AM by Vefdvkvw

# ihuEXeIXskXhWgBt

We've got a joint account <a href=" http://CheapValiumfu.blogoak.com/?postarch=2 ">Cheap Valium </a>  484
Tuesday, January 31, 2012 9:21 AM by Zecrdcog

# CavMGbecqqSYkHdQd

One moment, please <a href=" http://BuyRetinAtod.blogoak.com/?postarch=2 ">Buy Retin A </a>  01180
Tuesday, January 31, 2012 10:35 AM by Lnriddta

# MXPsKbqZimQQ

Could you transfer $1000 from my current account to my deposit account? <a href=" http://CheapAtivane.blogoak.com/?postarch=2 ">Cheap Ativan </a>  082580
Tuesday, January 31, 2012 11:50 AM by Ringfafl

# zXowitCPoNRo

I have my own business <a href=" http://Stilnoxaq.blogoak.com/?postarch=2 ">Stilnox </a>  970
Tuesday, January 31, 2012 2:23 PM by Hdhjesbf

# bEENjrxgeZPueeCUw

Which year are you in? <a href=" http://BuyRivotrilip.blogoak.com/?postarch=2 ">Buy Rivotril </a>  915508
Tuesday, January 31, 2012 3:41 PM by Mvxrstij

# OijvHtrZTSRlBhDO

A jiffy bag <a href=" http://BuyLunestaop.blogoak.com/?postarch=2 ">Buy Lunesta </a>  %))
Tuesday, January 31, 2012 4:59 PM by Qxnufosg

# XTQkGuGrNqOthBdFBsK

Would you like a receipt? <a href=" http://BuyAtivanNoPrescried.blogoak.com/?postarch=2 ">Buy Ativan No Prescription </a>  cja
Tuesday, January 31, 2012 6:17 PM by Ydxcgybe

# JwLasTpSFeDlzyHVTCB

Have you got any experience? <a href=" http://AtivanOnlineab.blogoak.com/?postarch=2 ">Ativan Online </a>  abugmi
Tuesday, January 31, 2012 8:53 PM by Tppavmlj

# byOrgggLGpX

Will I get travelling expenses? <a href=" http://BuyModafiniluha.blogoak.com/?postarch=2 ">Buy Modafinil </a>  2240
Tuesday, January 31, 2012 10:08 PM by Obyytgig

# qCkARyehLjFyKqbZTQm

I'm unemployed <a href=" http://BuyStilnoxjo.blogoak.com/?postarch=2 ">Buy Stilnox </a>  8-[
Tuesday, January 31, 2012 11:27 PM by Szltbvgg

# zvpjEgIXBEnbhKtgn

very best job <a href=" http://BuyTemazepamqof.blogoak.com/?postarch=2 ">Buy Temazepam </a>  lmfvh
Wednesday, February 01, 2012 12:39 AM by Deghnoee

# eVEVsOwLbCsF

I'm retired <a href=" http://BuyLibriumabo.blogoak.com/?postarch=2 ">Buy Librium </a>  8-))
Wednesday, February 01, 2012 4:20 AM by Trwxnbej

# qMjegPRucRSyddRzD

I was born in Australia but grew up in England <a href=" http://SleepingPillsyjy.blogoak.com/?postarch=2 ">Sleeping Pills </a>  197289
Wednesday, February 01, 2012 6:50 AM by Xdrllrji

# HIQRhWhRLFIZouKuM

I'd like to apply for this job <a href=" http://BuyDiflucanyku.blogoak.com/?postarch=2 ">Buy Diflucan </a>  xavd
Wednesday, February 01, 2012 8:03 AM by Sdzjuphk

# UPzxwRdkpdVA

I'd like to open an account <a href=" http://BuyCymbaltayp.blogoak.com/?postarch=2 ">Buy Cymbalta </a>  8[
Wednesday, February 01, 2012 9:18 AM by Gmolkmnx

# UtPhxUAwxJRkFPWjD

I'd like to withdraw $100, please <a href=" http://Lunestary.blogoak.com/?postarch=2 ">Lunesta </a>  976493
Wednesday, February 01, 2012 10:33 AM by Ymcqlfst

# wxeyyrFTTLlESIy

Whereabouts are you from? <a href=" http://ZolpidemWithoutPresy.blogoak.com/?postarch=2 ">Zolpidem Without Prescription </a>  8-((
Wednesday, February 01, 2012 11:48 AM by Njsbfbom

# yMKHkdhOHvJFVI

How do I get an outside line? <a href=" http://ClonazepamOnliney.blogoak.com/?postarch=2 ">Clonazepam Online </a>  458
Wednesday, February 01, 2012 1:03 PM by Sptiamlh

# yMKHkdhOHvJFVI

How do I get an outside line? <a href=" http://ClonazepamOnliney.blogoak.com/?postarch=2 ">Clonazepam Online </a>  458
Wednesday, February 01, 2012 1:03 PM by Sptiamlh

# sYJnhiXwfWd

I was born in Australia but grew up in England <a href=" http://BuyStratteraym.blogoak.com/?postarch=2 ">Buy Strattera </a>  itd
Wednesday, February 01, 2012 4:52 PM by Drbybfqq

# PzcQLRItoRnWMPBD

Could I have an application form? <a href=" http://BuyImitrexo.blogoak.com/?postarch=2 ">Buy Imitrex </a>  =-D
Wednesday, February 01, 2012 7:24 PM by Igpkvfgn

# lutzWigxuBjFQ

US dollars <a href=" http://BuyValiumOnlineoo.blogoak.com/?postarch=2 ">Buy Valium Online </a>  17856
Wednesday, February 01, 2012 11:33 PM by Lclqlptv

# AgQoMPnomMLExZTOF

I didn't go to university <a href=" http://BuyNitrazepamjad.blogoak.com/?postarch=2 ">Buy Nitrazepam </a>  zip
Thursday, February 02, 2012 12:46 AM by Afwhlsey

# ogZjCBcgpBQM

Can I take your number? <a href=" http://BuySeroquelgo.blogoak.com/?postarch=2 ">Buy Seroquel </a>  :-P
Thursday, February 02, 2012 1:59 AM by Gupjahuv

# MbqgHBehLGOSo

Get a job <a href=" http://AdderallXrjog.blogoak.com/?postarch=2 ">Adderall Xr </a>  kiuavh
Thursday, February 02, 2012 4:26 AM by Yhmaghee

# apXZPdTyuKJVYdvXKJ

We've got a joint account <a href=" http://CheapLorazepamte.blogoak.com/?postarch=2 ">Cheap Lorazepam </a>  bdvvn
Thursday, February 02, 2012 8:09 AM by Clnwortk

# emqUiEGBkoOmPMbGqjt

What do you study? <a href=" http://WhatDoesPhentermino.blogoak.com/?postarch=2 ">What Does Phentermine Look Like </a>  vllcjf
Thursday, February 02, 2012 9:24 AM by Tcrwbcof

# mfpyulqerBv

How much notice do you have to give? <a href=" http://PainPillsOnlineel.blogoak.com/?postarch=2 ">Pain Pills Online </a>  %-DDD
Thursday, February 02, 2012 2:25 PM by Bzpujgjv

# iHdQkJCxZiMhbPO

We need someone with experience <a href=" http://CheapZolpidemgej.blogoak.com/?postarch=2 ">Cheap Zolpidem </a>  8-[[
Thursday, February 02, 2012 4:57 PM by Wiolfkww

What do you think?

(required) 
required 
(required)