header image
 

Um, Spock?

I couldn’t help but post this little gem that I saw on the morning news LOL.

Leonard Nimoy doing some weird crap in the ’60s. I’m just waiting for him to say something about this not being logical LOL.

Larry Potash on WGN morning news finds the weirdest stuff on the internets :P

More keylogging attacks - Gamers be extra cautious!!!

It seems the attacks that are infecting websites are growing:

- Another attack is currently targeting servers running vulnerable ASP scriptsthat can be exploited through SQL injection to host malicious HTML code. The injected code references a malicious script… which in turn injects an IFRAME into the page to redirect users to a site that tries to exploit various known and patched vulnerabilities. This attack is believed to have affected over 15,000 pages, but the number of unique servers compromised may be far less.

- Yet another large-scale attack involving SQL injectionis targeting servers running PHPBB. This attack injects HTML code that loads a malicious JavaScript file from ‘free.hostpinoy.com’. Reports indicate that this attack is much more prevalent, perhaps because of the ubiquity of PHPBB. Over 150,000 pages may be affected. Note again, however, that the number of unique servers compromised may be far less. In previously observed cases, over 5000 pages have been affected on a single domain. At the time of writing, most of the sites hosting the exploits or malicious JavaScript are down, but they may come back online at any time. Administrators are advised to audit their web services to ensure that no exploitable flaws exist in the publicly exposed scripts and that the latest versions are installed. Network admins are advised to block access to ‘2117966.net’ and ‘free.hostpinoy.com’ at the gateway.
Source: safer-networking.org

Our friends over at Safer Networking (the makers of Spybot Search & Destroy) have been tracking this threat since it came out and providing good updates as they come available.

Shadow Server has a new update:

uc8010.com and 2117966.net Attacks Linked

We are posting this up a little late, but better late than never. In our last post we mentioned the several thousands of websites that were SQL injected to reference malicious JavaScriptcode on 2117966.net. At the time we were actually just taking an educated guess that this was the result of SQL injection. However, it has since been confirmed on Neil Carpenter’s Blog at http://blogs.technet.com/neilcar/archive/2008/03/15/anatomy-of-a-sql-injection-incident-part-2-meat.aspx

Source: Shadow Server

SANS has a new article on this as well:

Couple of days ago fellow handler Scott wrote a diaryabout sites hosting exploits for various Realplayer vulnerabilities. One of the malicious sites mentioned in the article, uc8010.com looked particulary interesting. When you search for this web site in Google you get thousands of other, compromised sites that are all pointing to the uc8010.com web site. This, obviously, sparked some interest in the security community so we decided to dig a bit further into this attack.

Source: isc.sans.org

If you have not,  check your systems with the latest versions of virus definitions from the maker of you anti-virus software and run Microsoft’s Baseline Security Analyzer to make sure you are patched properly. If you want a list of contiguous IP blocks for China and Korea to block for spam, hacking etc, this guy has researched and listed them:
http://www.okean.com/
His list complete list is available here:
http://www.okean.com/sinokorea.txt

Gamers beware-keyloggers inc!

From Yahoo! News:

San Francisco - Hackers looking to steal passwords used in popular online games have infected more than 10,000 Web pages in recent days.

The Web attack, which appears to be a coordinated effort run out of servers in China, was first noticed by McAfee researchers on Wednesday morning. Within hours, the security company had tracked more than 10,000 Web pages infected on hundreds of Web sites.

Source: Yahoo!

So watch your machines, your passwords etc. EQ2 has had a rash of stuff getting stolen, as can be seen in this thread up on the official forums:

http://forums.station.sony.com/eq2/posts/list.m?topic_id=411665

There are a number of players reporting that they have watched their friends and guildmates get cleared out, completely. Don’t let this happen to you.

Make sure you grab something like Spybot Search and Destroy, Adaware, or Hijack This! and scan your system for possible problems if you think you might have succumbed to this recent outbreak of infected web pages.

Here’s a bit of info from sans.org:

Situation:
Over 10,000 legitimate websites have been compromised and now have a javascript link that will direct visitors to a malicious website hosted on 2117966.net. The malicious website attempts to exploit the vulnerability described in MS06-014 MS07-004, MS06-067, MS06-057and a number of ActiveX vulnerabilities.

Successful exploitation result in the installation of a password-stealing malicious program that attempts to steal the logon credentials from websites and online games.

Recommended immediate action:
Block 2117966.net at your web proxy.

http://isc.sans.org/diary.html?storyid=4139

Free Tibet

I was sitting in my office today around noon and heard a loud mob coming up the street which happens from time to time on Michigan Ave. Sometimes it’s Palestinians, sometimes it’s Jews for Israel, sometimes it’s anti-Iraq war protesters, today it was the Tibetan supporters.

It seems that things have heated up in the protest over China’s human rights violations in regards to Tibetans. People  have been protesting all over the world over this issue since China won some Olympic host bid.

It seems the protesting has been claiming lives recently. The Chinese are trying to quell the protests and there are reports of fatalities inflicted by Chinese security forces for the past few weeks.

TCHRD[Tuesday, March 18, 2008 22:49]
The Tibetan Centre for Human Rights and Democracy (TCHRD) received confirmed information from multiple sources, that at least three Tibetan protesters were shot dead this afternoon during a peaceful demonstration in Kardze County, Sichuan Province in eastern Tibet after Chinese security forces started an indiscriminate firing on the peaceful Tibetan protesters. 
Source: Phayul.com

Continue reading ‘Free Tibet’

Bye-Bye to the Cans

Ok, this deserves a resounding cheer from the EVE community.

http://myeve.eve-online.com/devblog.asp?a=blog&bid=540

It seems all the trash floating around in space is finally going away. It’s amazing even in video games humans have a giant propensity for throwing junk all over the place. I guarentee if this happens in EVE, once humanity populates space, it’ll be the same, except there won’t be a program to remove all of the junk we’re leaving floating around in space IRL LOL.

Continue reading ‘Bye-Bye to the Cans’

Me and my Motorola-Q part 2…

So I just got a call from Verizon telling me that I can upgrade my phone early. Guess they realize the Q sucks :P I felt like the Verizon guy though when they called me, the delay between the call being switched from their automatic dialer to the telemarketer was a bit lengthy, so she didn’t realize I had answered. I guess I should have said “can you hear me now?” :P

They’re trying to get me to get a Blackberry Pearl. They look alright, and I guess it does what my phone does now, but, I’m wondering if I can transfer my applications over to it that I purchased (since the Q comes with absolutely nothing installed but Windows CE). I’m not sure if the phone is thin enough for me either. I also need to see if the charger I have for my Q will work for that thing, as well as my bluetooth headset. Headset probably will, not that I use it a whole lot. I hope the battery lasts longer too.

Continue reading ‘Me and my Motorola-Q part 2…’

Some further thoughts on crafting in EQ2

OK, so I guess I had some thoughts about crafting in EQ2, and I guess I’ll share some of them.

Once upon a time there was no real way for someone to make a finished product unless they had “help” or purchased the components that someone else made from the broker. I guess at some point the developers realized that it wasn’t very realistic or functional to keep things that way so they added the extra recipies that everyone could get for the build components. That was all fine and dandy, but it still took a REALLY long time to get anything accomplished this way. I spent so much time, like 70% of my time making subcombines, that I wasn’t going out and having any fun with the rest of the game. Then about a year later they decided to revamp all of that and make it strictly based on harvestable components. It was a really great change really. Unfortunately they also nerfed all of the items crafters could make to be rather useless.

Continue reading ‘Some further thoughts on crafting in EQ2′

Foreclosure of a Dream

Again with the Megadeth, jeez, anyways so they did another song long time ago called “Foreclosure of a Dream” and, yet another song dealing with a very recent issue. It’s kinda funny how this video/song was dealing with the mess during the first Bush’s term in office and is relavent in the current Bush’s term. Go figure.

 

At the moment, there are hundreds of thousands of people being screwed over by lenders and credit card companies all over the U.S. These companies have ridden roughshod over the population without any regulation or intervention from the Congress, and Congress still isn’t going to help any of you.

Continue reading ‘Foreclosure of a Dream’

Some pictures of Chicago

Here’s a couple shots of life in Chicago this winter.

Just in a mood to post something different ;)

This is the squirrel that wanted to come to Thanksgiving dinner.

img138.jpg img133.jpg img126.jpg img125.jpg

Continue reading ‘Some pictures of Chicago’

Rise of the E-Peen!

So, this is a continuation of my “The relationship between developer and player“, I’ve just noticed a lot more epeenery from the EQ2 community as of late and think I need to expand on what I started to talk about earlier.

It seems that there are two types of people that participate on the forums of most MMOs and other fan sites, the ones who are rational and behave in a civilized manner, and the ones who are total asses. The ones that are intelligent and not screaming children usually will get a response from a developer. The asses start off attacking developers than start crying when they don’t get a response even louder than when they were being asses. I’m going to mostly complain about the latter, and MAYBE make a few comparisons with the former. So in keeping with the E-Peen theme, I’m going to write this in a rather aggressive tone.

Continue reading ‘Rise of the E-Peen!’