Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts
Monday, December 28, 2009
Monday, September 21, 2009
phpmyadmin attack
another reason why you should not extract files that retain the default structure. here's a list of addresses for phpmyadmin someone tried to access unsuccessfully
/mysqladmin//setup/config.php?type=post HTTP/1.1
/phpMyAdmin2//setup/config.php?type=post HTTP/1.1
/phpmyadmin2//setup/config.php?type=post HTTP/1.1
/myadmin//setup/config.php?type=post HTTP/1.1
/MyAdmin//setup/config.php?type=post HTTP/1.1
/myAdmin//setup/config.php?type=post HTTP/1.1
/phpAdmin//setup/config.php?type=post HTTP/1.1
/phpadmin//setup/config.php?type=post HTTP/1.1
/mysql//setup/config.php?type=post HTTP/1.1
/pma//setup/config.php?type=post HTTP/1.1
/phpmyadmin//setup/config.php?type=post HTTP/1.1
/phpMyAdmin//setup/config.php?type=post HTTP/1.1
I particularly like this agent used:
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01 [en]
Thanks for the visit. 217.145.96.131
/mysqladmin//setup/config.php?type=post HTTP/1.1
/phpMyAdmin2//setup/config.php?type=post HTTP/1.1
/phpmyadmin2//setup/config.php?type=post HTTP/1.1
/myadmin//setup/config.php?type=post HTTP/1.1
/MyAdmin//setup/config.php?type=post HTTP/1.1
/myAdmin//setup/config.php?type=post HTTP/1.1
/phpAdmin//setup/config.php?type=post HTTP/1.1
/phpadmin//setup/config.php?type=post HTTP/1.1
/mysql//setup/config.php?type=post HTTP/1.1
/pma//setup/config.php?type=post HTTP/1.1
/phpmyadmin//setup/config.php?type=post HTTP/1.1
/phpMyAdmin//setup/config.php?type=post HTTP/1.1
I particularly like this agent used:
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01 [en]
Thanks for the visit. 217.145.96.131
Friday, September 11, 2009
Officelive basic domain renewal no longer free
I hate that I seem to be in the dark about the change in officelive basic. I was able to snag a domain when officelive offered domain registrations free with their service. I guess with the economic climate as it is; they would cancel the domain renewals which they had already done for new officelive basic customers for over a year? (they have stated at that time they will honor free renewals for older customers). I am just disappointed. I was lucky enough to check on my office live account and saw the clear message about domain renewals no longer free but if I didn't...
Sad thing is I would have known if I use my microsoft email account registered for the domain but since that's not my primary account (I now see they sent the mail out 08/04/2009 but two months doesn't seem like enough time). Since checking today and it giving me a 2 week time period to transfer; I did it on my lunch break. It was quite confusing. The registry key they gave didn't actually do anything at the transfering registar. The registry key is specific to http://www.melbourneit.com.au/cc/godirect/. Then there is the odd process where they change the registry key after having to register with their site. You would think; that was the key to use to transfer the domain after unlocking it.
No it was actually the show password section of the domain which reviews an "authinfo" password to use. Alot of multiple steps and I still have to wait for the email to accept transfering the domain. oh well. You can't get much things free nowadays...
Been a very gloomy day especially since it's september 11... everyone seems very solemn.
Sad thing is I would have known if I use my microsoft email account registered for the domain but since that's not my primary account (I now see they sent the mail out 08/04/2009 but two months doesn't seem like enough time). Since checking today and it giving me a 2 week time period to transfer; I did it on my lunch break. It was quite confusing. The registry key they gave didn't actually do anything at the transfering registar. The registry key is specific to http://www.melbourneit.com.au/cc/godirect/. Then there is the odd process where they change the registry key after having to register with their site. You would think; that was the key to use to transfer the domain after unlocking it.
No it was actually the show password section of the domain which reviews an "authinfo" password to use. Alot of multiple steps and I still have to wait for the email to accept transfering the domain. oh well. You can't get much things free nowadays...
Been a very gloomy day especially since it's september 11... everyone seems very solemn.
Thursday, July 30, 2009
Drupal Cron run failed
Very interesting situation. I love drupal (not sure why) even though if you add even a few modules the load time becomes snail pace. Also any sort of shared hosting environment and it can break down with database connect issues so it's a pain. Forget about getting even a dozen logged on users on a shared environment because depending on the modules... you will get booted out of your hosting provider. Enough complaining; done. Reason for this post is for my recent problem. I tried to run cron and it says:
Cron failed.
I tried to run it again and log says:
Attempting to re-run cron while it is already running.
Oh really? I'll wait a while and a few hours later I try again and get this message:
Cron has been running for more than an hour and is most likely stuck.
Well the server seems fine... not high load so I internet searched and the solution appears to be to disable the update status module. I ran cron successfully. I re-enabled update status module and ran cron again. Successful. Great. Problem solved. At least for Drupal 5.19
For Drupal 6.13 you will have to modify /modules/common.inc.
Look for Line 2637 and change $semaphore = variable_get('cron_semaphore', FALSE); to $semaphore = FALSE;
Remember to run cron and with success; revert the change.
Cron failed.
I tried to run it again and log says:
Attempting to re-run cron while it is already running.
Oh really? I'll wait a while and a few hours later I try again and get this message:
Cron has been running for more than an hour and is most likely stuck.
Well the server seems fine... not high load so I internet searched and the solution appears to be to disable the update status module. I ran cron successfully. I re-enabled update status module and ran cron again. Successful. Great. Problem solved. At least for Drupal 5.19
For Drupal 6.13 you will have to modify /modules/common.inc.
Look for Line 2637 and change $semaphore = variable_get('cron_semaphore', FALSE); to $semaphore = FALSE;
Remember to run cron and with success; revert the change.
Blocking Domain tools / whois.sc / Aboutus.org
There is nothing more disgusting than a website that crawls your site and than create snapshots of it so they can sell it people. That's domaintools.com for you and I've been blocking them for over a year with these ip blocks which are not effective as from a recent search yielded results just 2 months back.
I'm using the entire arin blocks assigned to them in iptables which is far more effective:
Name Intelligence uses compass communication Direct Allocation. Blocking entire compass communication ip range because they seem to added 1-2 additional ips to them which is not listed in arin.net.
64.246.160.0/19
216.145.0.0/19
Name Intelligence using Spry Network 66.249.0.0/19. You can block entire spry network or just below which is assigned to name intelligence
66.249.16.0/23
Excessive indeed but since these ip seems to be a hosting provider no big deal but I will monitor the logs to tweak this but I doubt I will. I don't have a problem with archives.org anymore; only because I sent a certified letter for them to remove any existing data of my domains and stop archiving in the future because a robots.txt doesn't really remove your information. It just prevents them archiving from that moment on. In which case when the robots.txt is gone the archiving will continue and the old data will still be there. Very disappointed with that organization.
Anyway here's a work in progress of the ips that I am seeing them since July 2009. I'll update this if I can:
64.246.161.30
64.246.161.42
64.246.161.190
64.246.165.10
64.246.165.140
64.246.165.150
64.246.165.160
64.246.165.170
64.246.165.180
64.246.165.200
64.246.178.34
64.246.187.42
66.249.17.123
66.249.17.159
216.145.5.42
216.145.11.94
216.145.14.142
216.145.17.190
I'm using the entire arin blocks assigned to them in iptables which is far more effective:
Name Intelligence uses compass communication Direct Allocation. Blocking entire compass communication ip range because they seem to added 1-2 additional ips to them which is not listed in arin.net.
64.246.160.0/19
216.145.0.0/19
Name Intelligence using Spry Network 66.249.0.0/19. You can block entire spry network or just below which is assigned to name intelligence
66.249.16.0/23
Excessive indeed but since these ip seems to be a hosting provider no big deal but I will monitor the logs to tweak this but I doubt I will. I don't have a problem with archives.org anymore; only because I sent a certified letter for them to remove any existing data of my domains and stop archiving in the future because a robots.txt doesn't really remove your information. It just prevents them archiving from that moment on. In which case when the robots.txt is gone the archiving will continue and the old data will still be there. Very disappointed with that organization.
Anyway here's a work in progress of the ips that I am seeing them since July 2009. I'll update this if I can:
64.246.161.30
64.246.161.42
64.246.161.190
64.246.165.10
64.246.165.140
64.246.165.150
64.246.165.160
64.246.165.170
64.246.165.180
64.246.165.200
64.246.178.34
64.246.187.42
66.249.17.123
66.249.17.159
216.145.5.42
216.145.11.94
216.145.14.142
216.145.17.190
Friday, May 29, 2009
the case for fsock
I know security is high on web hosting but is it really necessary to only enable fsock to port 80 and not a few other ports. Bluehost only allows port 80 and claims on their help faq that it is required for bandwidth tracking but allows a 30 dollar additional yearly fee for a dedicated ip which will open up the rest of the ports. Arggh. Why do hosting companies do this. Netfirms is even more ridiculous. They use to allow fsock to other ports since at least december 2008(I am pretty sure) but now only port 80. Not that it really matters since their hosting is exceptionally unreliable due to their databases always overloaded spitting out errors from any content management system. Sigh. Now I can't even park a few dozen websites and use fsock to send out emails from google apps with my domain.
When did web hosts do this? Can't they understand their email features are practically useless and it helps everybody when people can fsock out to their own smtp servers. The horror.
When did web hosts do this? Can't they understand their email features are practically useless and it helps everybody when people can fsock out to their own smtp servers. The horror.
Sunday, May 17, 2009
The problem with opendns.com
I had to ditch opendns.com once again as my dns name server. It previously had to do with speed but I was willing to overlook it for some statistical information on dns queries and what domains was requested. Good way to snoop on what people in your private network is doing but since it is just me... the appeal is just not there. I was initially excited with blocking categories but it turned out to be a huge joke. Yes people voting on domains so you can block their category is useful but it's about as useful as their phishing protection. More times than I can remember; firefox blocked more domains on their voting list than opendns did. There's also the major problem of no one voting for domains which quite frankly there should be more than one person after a domain has been added for over a week which is often not the case. Then there are those that vote based on religious and political beliefs. Ruins the whole system and I blame the staff for not just deleting the users after finding a pattern but I guess it's becoming a lot like wikipedia.
Anyway the final straw came from the very annoying flash lag. It will frequently freeze my firefox and periodic nonloading of requests was a bit too much but I held in there for 2 weeks. I suppose I might go back to do some statistics when I open my wireless network more but I could not have my visitors annoyed by the slowness issue. That would reflect badly upon me.
So basically my name servers are back to 4.2.2.1-4.2.2.6. They always performed better than the default verizon dsl name servers which had started handing out name suggestions on bad domains. I still use dns-o-matic which is a opendns.com service. That now is one very useful service and I recommend that to everyone who wants to manage dyanmic ips with host names.
Anyway the final straw came from the very annoying flash lag. It will frequently freeze my firefox and periodic nonloading of requests was a bit too much but I held in there for 2 weeks. I suppose I might go back to do some statistics when I open my wireless network more but I could not have my visitors annoyed by the slowness issue. That would reflect badly upon me.
So basically my name servers are back to 4.2.2.1-4.2.2.6. They always performed better than the default verizon dsl name servers which had started handing out name suggestions on bad domains. I still use dns-o-matic which is a opendns.com service. That now is one very useful service and I recommend that to everyone who wants to manage dyanmic ips with host names.
Saturday, May 9, 2009
Verizon Automatically updating DSL modem Firmware
This is probably no special news to verizon users in the new york area. In fact I actually read this in the dslreports forums but I decided to replace my really old verizon westell modem (which is just a modem that predates the 2100). Why? The old modem model B90-36R516-01 is quite big compared to a 6100 (twice in size of the modem and power brick). Anyway after just one day of being connected online and set in bridge mode it had the annoying blink red internet light but functioning just fine. Imagine my surprise when I woke up today and saw the internet blinking green instead of the regular red and off.
Apparently in the middle of the night sometime when I wasn't using the internet the modem just upgraded the firmware to "Proline DSL Model" with the trademarked verizon logo with red theme. Firmware at 4.04.03.00 and Transceiver Revision at 7.2.3.0. Fortunately the new firmware automatically connects to the internet with the handle "newdsl" (what's the password?) so I was able to find the details of setting it to bridge mode in the new interface.
For future reference the information I would need is:
login: admin
password: password
ip: 192.168.1.1/255.255.255.0
walled garden: 192.168.1.1/verizon/redirect.hml
The walled garden is a forced registration screen that might come up. This is similar to why I dumped a netgear router wg614 because it wouldn't allow me to setup anything until it detected a WAN connection. Incredibly annoying. For the netgear situation it was 192.168.1.1/CA_HiddenPage.htm to disable the wizard.
Apparently in the middle of the night sometime when I wasn't using the internet the modem just upgraded the firmware to "Proline DSL Model" with the trademarked verizon logo with red theme. Firmware at 4.04.03.00 and Transceiver Revision at 7.2.3.0. Fortunately the new firmware automatically connects to the internet with the handle "newdsl" (what's the password?) so I was able to find the details of setting it to bridge mode in the new interface.
For future reference the information I would need is:
login: admin
password: password
ip: 192.168.1.1/255.255.255.0
walled garden: 192.168.1.1/verizon/redirect.hml
The walled garden is a forced registration screen that might come up. This is similar to why I dumped a netgear router wg614 because it wouldn't allow me to setup anything until it detected a WAN connection. Incredibly annoying. For the netgear situation it was 192.168.1.1/CA_HiddenPage.htm to disable the wizard.
Sunday, May 3, 2009
Myspace Cancellation Spam
Feeling more annoyed than usual probably from the rain today. Not too long after cancelling my myspace account; I have been getting numerous spam like daily from greatbirdsite.com, titaniumnetworksllc.com, visitsee.com, hesayyes.com, bestsitemap.com, isuperform.com, internetsalesdata.com, hotclickbank.com and visitsee.com, cckmm018.com, and internetaccessonline.com to my yahoo account. Why am I making this baseless accusation? Well this email was used exclusively for myspace believe it or not and I've not given this email for over 3 years under any circumstances as I've now used gmail since their spam filters are amazing.
If there was an easier way of marking them as spam when I get them over popmail it would be great but since they do not have that function unlike gmail imap which is configurable in thunderbird; I am stuck logging in daily to mark it as spam. This has been going on for a week. Myspace.com sucks.
I have tried contacting yahoo.com but they are particularly unhelpful since I only have the enable spam option which is already enabled. They actually have the nerve to ask me to contact the isp of the spam messages by the "Received" line of the full internet headers. I WOULD NOT HAVE THIS PROBLEM IF THEIR MARK SPAM WORKS! Is it so impossible to understand??? Basically i've been forwarding them daily(and marking them as spam) to mail abuse and asking them to enable some option to send all messages to spam if they are not from my contacts list... Here's hoping for some solution before I remove their smtp/pop account from my email client.
Update: The only solution seems to be go back to classic version of yahoo and block the domains so it doesn't reach your inbox. Mark spam doesn't work and yahoo does not care at all. Very disappointed.
This is block domain email spam list:
wonkwonkrs.com
wonkwonkfive.com
bestsitemap.com
visitsee.com
greatbirdsite.com
titaniumnetworksllc.com
hesayyes.com
isuperform.com
internetsalesdata.com
hotclickbank.com
cckmm018.com
internetaccessonline.com
lovejustright.com
bestfindfree.com
If there was an easier way of marking them as spam when I get them over popmail it would be great but since they do not have that function unlike gmail imap which is configurable in thunderbird; I am stuck logging in daily to mark it as spam. This has been going on for a week. Myspace.com sucks.
I have tried contacting yahoo.com but they are particularly unhelpful since I only have the enable spam option which is already enabled. They actually have the nerve to ask me to contact the isp of the spam messages by the "Received" line of the full internet headers. I WOULD NOT HAVE THIS PROBLEM IF THEIR MARK SPAM WORKS! Is it so impossible to understand??? Basically i've been forwarding them daily(and marking them as spam) to mail abuse and asking them to enable some option to send all messages to spam if they are not from my contacts list... Here's hoping for some solution before I remove their smtp/pop account from my email client.
Update: The only solution seems to be go back to classic version of yahoo and block the domains so it doesn't reach your inbox. Mark spam doesn't work and yahoo does not care at all. Very disappointed.
This is block domain email spam list:
wonkwonkrs.com
wonkwonkfive.com
bestsitemap.com
visitsee.com
greatbirdsite.com
titaniumnetworksllc.com
hesayyes.com
isuperform.com
internetsalesdata.com
hotclickbank.com
cckmm018.com
internetaccessonline.com
lovejustright.com
bestfindfree.com
Saturday, May 2, 2009
Verizon DSL unblocked port 80?
I had pretty given up on setting up a web server really on my verizon dsl in new york because they have been blocking it since code red virus which is like over 7 years? I did setup dynamic ip hosting with port forwarding for some demonstrations but imagine my surprise when I read a forum post in dslreports.com that someone mentioned that verizon was slowly removing the port 80 block.
It's UNBLOCKED!!! I can not seem to find any internet searches that verified my outcome but than it could also because of my recent phone problems where a telephone repair man said I had a short and would get the Central Office to change my circuit.
Great news right? Too bad they block the smtp port 25 but I thought this was a worthy of a blog post since I'm so excited.
It's UNBLOCKED!!! I can not seem to find any internet searches that verified my outcome but than it could also because of my recent phone problems where a telephone repair man said I had a short and would get the Central Office to change my circuit.
Great news right? Too bad they block the smtp port 25 but I thought this was a worthy of a blog post since I'm so excited.
Wednesday, April 8, 2009
what's the point of expotv.com?
I was thinking of a cheap pair of leather sandals and old navy seems like a good idea because with a discount it would only be 10 dollars. The problem is I bought the cheap 2 dollar or so plastic sandals that really sucked. Imagine my surprise when a search brought up a video from expotv.com. What a ridiculous piece of garbage coming out of these people. Last time I couldn't even walk a full block around the block without being in pain let alone 3 miles... Also plastic straps are not comfortable and these stupid slippers break. Mines did but than it could be because I am a man and these old navy sandals are very thin and no cushion. Kept slapping me on the back of the feet as I walk. However to my dismay some guy also gave it 5 stars.
So anyway. Just another rant for a stupid website that is absolutely no help at all.
So anyway. Just another rant for a stupid website that is absolutely no help at all.
Sunday, December 28, 2008
Winster.com - A review
One of my recent guilty pleasures has been playing winster.com. I have started only last week but it is quite enjoyable so I wanted to share a blog post on it. It started from a email from mypoints.com (another reward site I am very happy with) and with that I registered with a reward of 500 mypoints after 1 million points from winster.com. Winster gives you 200 spins a day and 700,000 points to start with.
I have to admit the first 2 days I was addicted to the slot machines and that is where people are more willing to exchange pieces to get a 5 way match. This will get a little confusing if you do not play the game or read the help on what pieces give what rewards. However the experience is not always pleasant. "Winnie" is where a select group likes to engage in the strategy of jackpot. With only 200 spins it will probably not appeal to most people because I was in a room that wanted to do it alphabetically (by name) who gets the jackpot. That takes a very long time and alot of wasted spins with most getting one winnie and a bunch of wilds. It is preferrable to keeping at least one winnie so the next person can go for the jackpot. This situation realy requires 5 people to be successful; perferably all 5 have the attention to exchanging pieces so their spins are not wasted and people cash in even the lowestest matches. This usually is not the case from my experience so finding good unselfish players is key and also adding them as friends.
Around the 3rd or 4th day I started to play some other games and used google to see what is the best reward was. I came about a strategy for the burger game however I found almost noone in the game will exchange or chat. But it was a little easier getting points because you have a better chance of matching a burger because it has alot more options than slots. However the lack of mutual exchanging was very disappointing.
My favorite after 7 days now is the "Spell Squad". It is slightly challenging and it goes with my not wanting to waste spins (it's probably a human defect which has the advantage of being resistant to gambling in real life and wasting money unnecessarily). I came about this wonderful strategy link at http://www.sushifury.com/winster.html and it is probably much better written than what I have now. I suggest you read it as well as it follows a similar conclusion in my next paragraph. People playing "spell squad" didn't appear to like exchanging or communication which was disappointing. My strategy still seems to find the right friends and have a private room of a 5 way so each can get a 9 word completion quicker.
In conclusion I am getting about 50 points per spin on 200 free spins as a free member from "spell squad". That would mean I would get my first 5 dollar gift certificate next month from amazon. I changed to amazon from mypoints because my poor math skills told me 500 points mypoints is slightly less than an amazon gift card. However sushifury stated you need to be a member to cash a reward and you get lesser free spins per day does not corrolate with what I read from winster. However his post is rather old. Winster is really not worth the effort but if you have 1/2 hour to an hour I am confident as a free member you can get a 5 dollar gift card every year without any strategy. However mypoints generally gives me enough points to redeem for a 25 dollar gift card in that same same with much less work and far greater gift card choices. If I were to pursue a paid membership at 10 dollar a month, I should be getting about 4 times (800 spins vs 200 free spins) 4 times(bonus for paid membership) times 300,000 points a month which gives me a redemption of a 15-20 dollar gift card (very limited choices) a month but it would take 4 times the amount of time I am currently taking per day. However if paying the minimum 5 dollar membership I should essentiall break even every month on around a minimum hour of playing. I encourage you to do the math yourself on whether you would have the time and whether it is worth it.
WARNING: The winster.com suffers from a great deal of lag and 30 second interspacial ads. At times my whole room was disconnected and playing was simply not possible for short periods (few minutes) at a time. I feel I should mention this because it was not a smooth playing experience.
I have to admit the first 2 days I was addicted to the slot machines and that is where people are more willing to exchange pieces to get a 5 way match. This will get a little confusing if you do not play the game or read the help on what pieces give what rewards. However the experience is not always pleasant. "Winnie" is where a select group likes to engage in the strategy of jackpot. With only 200 spins it will probably not appeal to most people because I was in a room that wanted to do it alphabetically (by name) who gets the jackpot. That takes a very long time and alot of wasted spins with most getting one winnie and a bunch of wilds. It is preferrable to keeping at least one winnie so the next person can go for the jackpot. This situation realy requires 5 people to be successful; perferably all 5 have the attention to exchanging pieces so their spins are not wasted and people cash in even the lowestest matches. This usually is not the case from my experience so finding good unselfish players is key and also adding them as friends.
Around the 3rd or 4th day I started to play some other games and used google to see what is the best reward was. I came about a strategy for the burger game however I found almost noone in the game will exchange or chat. But it was a little easier getting points because you have a better chance of matching a burger because it has alot more options than slots. However the lack of mutual exchanging was very disappointing.
My favorite after 7 days now is the "Spell Squad". It is slightly challenging and it goes with my not wanting to waste spins (it's probably a human defect which has the advantage of being resistant to gambling in real life and wasting money unnecessarily). I came about this wonderful strategy link at http://www.sushifury.com/winster.html and it is probably much better written than what I have now. I suggest you read it as well as it follows a similar conclusion in my next paragraph. People playing "spell squad" didn't appear to like exchanging or communication which was disappointing. My strategy still seems to find the right friends and have a private room of a 5 way so each can get a 9 word completion quicker.
In conclusion I am getting about 50 points per spin on 200 free spins as a free member from "spell squad". That would mean I would get my first 5 dollar gift certificate next month from amazon. I changed to amazon from mypoints because my poor math skills told me 500 points mypoints is slightly less than an amazon gift card. However sushifury stated you need to be a member to cash a reward and you get lesser free spins per day does not corrolate with what I read from winster. However his post is rather old. Winster is really not worth the effort but if you have 1/2 hour to an hour I am confident as a free member you can get a 5 dollar gift card every year without any strategy. However mypoints generally gives me enough points to redeem for a 25 dollar gift card in that same same with much less work and far greater gift card choices. If I were to pursue a paid membership at 10 dollar a month, I should be getting about 4 times (800 spins vs 200 free spins) 4 times(bonus for paid membership) times 300,000 points a month which gives me a redemption of a 15-20 dollar gift card (very limited choices) a month but it would take 4 times the amount of time I am currently taking per day. However if paying the minimum 5 dollar membership I should essentiall break even every month on around a minimum hour of playing. I encourage you to do the math yourself on whether you would have the time and whether it is worth it.
WARNING: The winster.com suffers from a great deal of lag and 30 second interspacial ads. At times my whole room was disconnected and playing was simply not possible for short periods (few minutes) at a time. I feel I should mention this because it was not a smooth playing experience.
Friday, November 14, 2008
Spyware Malware Infestation - Smitfraud TDSS
Wow. I've been pretty careful to prevent myself from being infected by viruses or spyware but this time it takes the cake. Seems one of my free webhosts had their server compromised. This caused a site that was hosted on them(my site in fact) to install malware on my computer. I was stupid not to heed the warning on firefox saying first my site was reported as attack site (what?! was my first reaction) so I went on internet explorer to check it out for some insane reason.
Near immediately my avast 4 antivirus spit out a warning which I closed(stupidly instead of trying to clean it) which I can only assume it installed on my computer. Another warning spit out to remove the malware file which I did; causing my computer to freeze up. A reboot later it has already installed c.exe (with a.exe b.exe d.exe in temp folder) for startup along with a ~temp process masquerading as a microsoft virus scanner not installed icon on systems tray near the time. It's amazing because when the popups asked if you want to install virus scanner and right clicking on the virus tray icon automatically opens a spam link.
Avast/Clamwin.exe couldn't detect it as a running process but fortunately I was able to remove it by killing 2 processes, removing the listing of the program c.exe on startup and finally deleted the file in my temp directory.
**Updated -
It was actually much worst than I thought. My dns was completely taken over and I could not figure out what process was causing it. Windows defender (Now I'm starting to think it's completely useless) at full scan detected nothing. I could not open spybot at all. Hijack installer could not install. Accessing windowsupdate was set to local (trendmicro website set to localhost) even majorgeeks resolve back to 127.0.0.1. What an incredibly awesome program despite it being malware obviously that would not access alot of sites which is not a simple edit of the hosts file because it was not touched and prevented opening programs that could fix it. It's focused on sending you to a virus scanner too which is hilariously evil.
Finally I went to safe mode and fortunately I got spybot to work only after editing the filename! (still working in safe mode!) to just spybot.exe and it was able to find Smitfraud-C.gp, Smitfraud-C, and Win32.TDSS.rtk along with an a.exe file in windows/system32/. Took a fix and a rescan which detected it again to solve the problem....
**Final Update
Absolutely premature again. Much more serious than I though. A trojan rootkit? was installed and symptoms include freezing the system (mouse will work) and reaquiring dns whenever internet connection was established. This was the work of TDSS. I tried running a smitfraud fix which did nothing to TDSS of course but a combofix.exe was able to remove the following:
c:\windows\system32\drivers\TDSSmxwe.sys
c:\windows\system32\Drivers\TDSSypaa.sys
c:\windows\system32\TDSSaoli.dat
c:\windows\system32\TDSSarxx.dll
c:\windows\system32\TDSSdxcp.dll
c:\windows\system32\TDSSgurc.log
c:\windows\system32\TDSSjont.dll
c:\windows\system32\TDSSkkao.log
c:\windows\system32\TDSSmcfp.dll
c:\windows\system32\TDSSmrxq.dll
c:\windows\system32\TDSSmtpe.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnpur.dll
c:\windows\system32\TDSSoitu.dll
c:\windows\system32\TDSSsahc.dll
c:\windows\system32\TDSSshyf.log
c:\windows\system32\TDSSuxrr.dll
c:\windows\system32\TDSSvcce.dll
c:\windows\system32\TDSSvoqm.dll
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Legacy_NPF
and gave me full access to the internet without taking control of the dns. If I did not have a computer it would be make one suicidal trying to download the tools or access the web to figure out how to remove this. Pretty much having to run spybot to reset the virus so you can access the internet for less than a minute before retaking over some entries. I acquired malwarebytes' anti-malware which detected 20 objects (mostly corrected files from combofix with the added extension of .vir and a few restore points) that took over 5 hours to run on my computer. The online trendmicro virus scan took even longer...
I guess this is karma for my recent posts. I am overly grumpy lately... Not that these events can make anyone better.
Near immediately my avast 4 antivirus spit out a warning which I closed(stupidly instead of trying to clean it) which I can only assume it installed on my computer. Another warning spit out to remove the malware file which I did; causing my computer to freeze up. A reboot later it has already installed c.exe (with a.exe b.exe d.exe in temp folder) for startup along with a ~temp process masquerading as a microsoft virus scanner not installed icon on systems tray near the time. It's amazing because when the popups asked if you want to install virus scanner and right clicking on the virus tray icon automatically opens a spam link.
Avast/Clamwin.exe couldn't detect it as a running process but fortunately I was able to remove it by killing 2 processes, removing the listing of the program c.exe on startup and finally deleted the file in my temp directory.
**Updated -
It was actually much worst than I thought. My dns was completely taken over and I could not figure out what process was causing it. Windows defender (Now I'm starting to think it's completely useless) at full scan detected nothing. I could not open spybot at all. Hijack installer could not install. Accessing windowsupdate was set to local (trendmicro website set to localhost) even majorgeeks resolve back to 127.0.0.1. What an incredibly awesome program despite it being malware obviously that would not access alot of sites which is not a simple edit of the hosts file because it was not touched and prevented opening programs that could fix it. It's focused on sending you to a virus scanner too which is hilariously evil.
Finally I went to safe mode and fortunately I got spybot to work only after editing the filename! (still working in safe mode!) to just spybot.exe and it was able to find Smitfraud-C.gp, Smitfraud-C, and Win32.TDSS.rtk along with an a.exe file in windows/system32/. Took a fix and a rescan which detected it again to solve the problem....
**Final Update
Absolutely premature again. Much more serious than I though. A trojan rootkit? was installed and symptoms include freezing the system (mouse will work) and reaquiring dns whenever internet connection was established. This was the work of TDSS. I tried running a smitfraud fix which did nothing to TDSS of course but a combofix.exe was able to remove the following:
c:\windows\system32\drivers\TDSSmxwe.sys
c:\windows\system32\Drivers\TDSSypaa.sys
c:\windows\system32\TDSSaoli.dat
c:\windows\system32\TDSSarxx.dll
c:\windows\system32\TDSSdxcp.dll
c:\windows\system32\TDSSgurc.log
c:\windows\system32\TDSSjont.dll
c:\windows\system32\TDSSkkao.log
c:\windows\system32\TDSSmcfp.dll
c:\windows\system32\TDSSmrxq.dll
c:\windows\system32\TDSSmtpe.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnpur.dll
c:\windows\system32\TDSSoitu.dll
c:\windows\system32\TDSSsahc.dll
c:\windows\system32\TDSSshyf.log
c:\windows\system32\TDSSuxrr.dll
c:\windows\system32\TDSSvcce.dll
c:\windows\system32\TDSSvoqm.dll
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Legacy_NPF
and gave me full access to the internet without taking control of the dns. If I did not have a computer it would be make one suicidal trying to download the tools or access the web to figure out how to remove this. Pretty much having to run spybot to reset the virus so you can access the internet for less than a minute before retaking over some entries. I acquired malwarebytes' anti-malware which detected 20 objects (mostly corrected files from combofix with the added extension of .vir and a few restore points) that took over 5 hours to run on my computer. The online trendmicro virus scan took even longer...
I guess this is karma for my recent posts. I am overly grumpy lately... Not that these events can make anyone better.
Monday, November 10, 2008
H.264 vs Xvid for the lamer
I unfortunately have this conversation that has periodically come up in the last two years. It always occur because of two things. One of them being complete ignorance and some sort of elitism perceived from knowing a few things about video quality. The second is the worst and usually involves selfishness or just plain stupidity.
For most people this conversation will never come up because you would only worry about video quality when you are actually using it to perhaps back up dvds or some sort of media for personal use. The conversation however will come up from those who are leechers. Now leechers have existed long before edonkey which made sharing easier for the less technical savvy usenet group. There are nothing but complainers on the internet but when there was private sharing of movies from the divx/xvid era in irc it has exploded with bittorrent.
That ease of use has come about with the lack of wisdom and common sense. In the persuit for video quality which was the initial goal of divx/xvid came H.264. At the gain for a few measily megabytes which has become increasely cheaper to the point I no longer buy dvds to store my media files (I just buy a large hard drive on sale now), processing power was needed to encode and decode video arguebly with fewer problems which is rare problem not noticable with a skilled xvid encoder. So what's the problem than? H.264 should be the goal for most encoders right? WRONG!
I will now use a few reasons to chastise anyone who waste anyone's time arguing for H.264 encoding while downloading movies which you did not pay for and which you did not encode just cause you think the video quality is better. First off, thank you for making global warming worst by using more processing power to encode media for marginal savings in media size. Thank you for considering the many fully working divx/xvid players that do not and will not play H.264 movies well or at all. It's very considerate of you to be environmentally friendly by causing tons of electronics obsolete and end up in landfills because you think H.264 is superior than xvid/divx. The economy is better off for everyone because you download H.264 movies from the internet at no cost while thousands are laid off production companies losing money making those movies and the minimum wage workers at blockbuster or any brick and mortar business selling them.
So in essence. If you are worried about the quality enough to advocate H.264 movies from the internet please consider buying them rather than show yourself as a complete loser and plain old A$$Hole on the internet.
For most people this conversation will never come up because you would only worry about video quality when you are actually using it to perhaps back up dvds or some sort of media for personal use. The conversation however will come up from those who are leechers. Now leechers have existed long before edonkey which made sharing easier for the less technical savvy usenet group. There are nothing but complainers on the internet but when there was private sharing of movies from the divx/xvid era in irc it has exploded with bittorrent.
That ease of use has come about with the lack of wisdom and common sense. In the persuit for video quality which was the initial goal of divx/xvid came H.264. At the gain for a few measily megabytes which has become increasely cheaper to the point I no longer buy dvds to store my media files (I just buy a large hard drive on sale now), processing power was needed to encode and decode video arguebly with fewer problems which is rare problem not noticable with a skilled xvid encoder. So what's the problem than? H.264 should be the goal for most encoders right? WRONG!
I will now use a few reasons to chastise anyone who waste anyone's time arguing for H.264 encoding while downloading movies which you did not pay for and which you did not encode just cause you think the video quality is better. First off, thank you for making global warming worst by using more processing power to encode media for marginal savings in media size. Thank you for considering the many fully working divx/xvid players that do not and will not play H.264 movies well or at all. It's very considerate of you to be environmentally friendly by causing tons of electronics obsolete and end up in landfills because you think H.264 is superior than xvid/divx. The economy is better off for everyone because you download H.264 movies from the internet at no cost while thousands are laid off production companies losing money making those movies and the minimum wage workers at blockbuster or any brick and mortar business selling them.
So in essence. If you are worried about the quality enough to advocate H.264 movies from the internet please consider buying them rather than show yourself as a complete loser and plain old A$$Hole on the internet.
Subscribe to:
Posts (Atom)