Using Google Code search to find the programming language most likely to drive you mad

After seeing all the great uses people are finding for Google's new Code Search I thought, "yeah these are useful, but what would be really useful would be to use this to find out what language is most likely to drive programmers mad!"
So I developed a rigourous methodolgy which primarily consists of searching for code invoking the name of Great Cthulhu ! What surer sign of madness than using the name of a great old one!
so without further ado, here's the results of my painstaking search.

From this we can clearly see that C is leading the pack, with TCL obviously a pretty mind-bending second place.

Lightweight Windows... At last

Redmond | Feature Article: Server Core: Windows Without Windows
Interesting looks like Microsoft are working on a cut down version of vista for certain core services. This is one of the things that's bugged me about windows for ages (why does a server need a media player!!) and I think one of the main things that'd hampered their activitie s in creating a more secure operating system.
Looks a touch basic at the moment and I'm left wondering how easy it will be for 3rd party vendors to get their software running on it (it would make complete sense for things like database servers to use this rather than a default install of windows), but it's definately a step in the right direction.

Really interesting study on the prevalence of SQL injection

Michael Sutton's Blog : How Prevalent Are SQL Injection Vulnerabilities?
Really interesting study showing that of a sample population of web apps. live on the Internet 11.3% had SQL injection vulnerabilities.
I also thought it was very interesting to see how a combination of the googleAPI and some relatively simple coding can be turned into a very powerful vulnerability finding mechanism.
I've been doing some SQL injection work on recent tests and it's amazing how much information you can get from a database through one error message, it's pretty trivial (especially if automated) to enumerate all tables on a database and all databases on a server assuming (which tends to be the case) that the database server hasn't been hardened and the user being used by the web application hasn't been restricted (again tends to be the case)
Thinking about it, it's a little surprising that no-one's gone the extra step and done an automation that auto-roots servers with SQL injection vulns... It would be a fair bit harder than a buffer overflow (lots more variables to take account of like differing database servers and differing results from the initial injection allowing different queries to work) but given the reduced efficacy of worms attacking publicly available services (there's not really been a repeat of slammer in recent years) it would seem to be a viable attack path...