March 13, 2005

SurfJunky Update

SurfJunky Update: As of today, I have attracted at least one down-link at SurfJunky, that pay for auto-surfing website that started up last month. While no one knows whether or not we'll get paid, I just leave it up and running on my extra computer screen. - Stats to date:
Activity Points: 72
Payment rate: $0.45 per hour
Hours spent surfing: 120.67

Your earnings: $54.32

Keep checking back - I will keep you abreast of whatever happens with this. I am making sure not to cheat, use refreshers or anything that might get me banned. I'm following all their rules as best I can.

Blogger Is Getting On My Nerves

Blogger is really pissing me off lately. All this weekend, posting on Blogger has been like a lottery. You put together your post and hit the publish button. If you win the lottery, your post gets published on your blog. If you lose the lottery, your post goes into the Ether, never to be seen again (unless you hit the back button and cut and paste it into a more stable program, e.g. Notepad). I've wanted to try to play with the image posts I've been making lately to try to wrap text around the pics, etc...but I can't even get Blogger to behave enough to simply make a post, much less know what it's published or not. I've even seen some blogs where Blogger is posting 3 times, probably because their redirection code is screwed up, but the script is going ahead anyway.

March 12, 2005

Losing a Hard Drive Sucks Major <bleep>

Dead Disk Drive
I lost a disk drive this week. It had gone south on me before, just after the warranty ran out of course; but it lasted 6 months after the last failure. I'm pretty sure it failed while waking up from sleep one morning when I came down to check my email. It started making nasty noises and putting it in the freezer didn't help. I didn't have anything VERY valuable on it, but I did lose some pictures from my trip to Vegas that I hadn't yet burned to CD. Losing a hard drive sucks, especially one that was only manufactured 2 years ago.

Mystery Pic Revealed

Pistachio Nut with +17 diopter macro lens
Mystery Pic revealed: Ok, I can't hold it in till Sunday - the picture is of a pistachio nut. No winners this time - but I'll post another one soon(er or later) - maybe make it a regular feature.

March 11, 2005

Are you a fan of Wikipedia? I know I am - it's a fantastic extension of the Internet, allowing people to share information in a manner that makes sense, editing each other's works and offering some very solid research on important subjects. Well, BoyHowdy introduced me to the Uncyclopedia today, and it went right into my bookmarks list. Everyone has something they want to rant about, or otherwise spread disinformation about - (my favorite rant is Ikea so far). And here you can do it all to your heart's content. But forget about well researched articles. This site is all about disinformation, rumour and humour. So put on your 6th sense before visiting.
I would like to thank Peter Mack for The Perspective of the Day: Go to The Global Rich List and see where you lie on the grand scale of the world's wealth. I think I'll permanently bookmark this site so that every time I think I'm a poor shmuck without enough money, I can click on the bookmark and lighten my perspective on things.

March 09, 2005

DANGEROUS NEW PHISHING ATTACKS: A new phishing email with the following URL is being sent around - it appears to use Ebay's own servers to redirect the user information to the hacker's PC.... Although the link in the email is expressed simply: https://signin.ebay.com/ws/eBayISAPI.dll?UpdateAgreement

Here's the code for the attacking link:

https://signin.ebay.com/ws/eBayISAPI.dll?
SignIn&UsingSSL=1&pUserId=&co_partnerId=2&siteid=0&ru=http%3A%2F%
2Fcgi4.ebay.com%2Fws%2FeBayISAPI.dll?MfcISAPICommand%3dRedirectToDomain%
26DomainUrl=http%3A%2F%2F127.0.0.1%2FeBayISAPI.php&pageType=1883
(hackerPC address changed to protect the stupid)

Note that the link sends you to Ebay's signin service! If you click on the link, you actually end up on Ebay's signin page! And clicking on the Certificate Info verifies that the actual SSL session is indeed being held with Ebay's normal signin service....so what's going on here?
The hacker is using Ebay's own scripts against them. Apparently the RedirectToDomain command is meant to pass the user credentials to the hacker's configured PC at 127.0.0.1 (real hacker address in the email!) where the script eBayISAPI.php is waiting for the user to arrive. Potentially, if eBay's login server is stupid enough, it will pass the user's credentials to the specified redirected URL.

This is a fairly sophisticated phishing attack. Potentially the hacker might not even end up getting your password. Maybe they get an internal authentication code for your eBay account that allows them to act as if they were logged in to your account, by passing those authenticated signals on to other eBay servers (in specially formatted HTTP requests).

While I've notifed eBay (at spoof@ebay.com), there's a lesson in secure web application design in how this email attack works, and web designers should pay heed to the weaknesses and vulnerabilities inherent in passing credentials from server to server in 'custom' login scripts/scenarios. At a very minimum, checks should be made to ensure the machine you're passing to is on a pre-approved list. A secure channel should be used if at all possible (client PKI certificates!)


March 07, 2005

In Other News: Got my butt handed to me during lunch today. A coworker and I play chess at lunch. He beat me hands down 2-0. Since I've been spending more time on HTML and div tags than studying/practicing chess, I'm beginning to lose the edge I had on him that was keeping us even. I'm going to have to buckle down and study if I want to win. Time to go check out the current version of Chess Position Trainer. That's a completely free practice tool for studying your repertoires and practicing against known positions. It's good software, and if you play chess, you should be using it.
If you haven't already - check out the 'What is this' contest two blog entries down - no one has gotten it yet ;)
Here we go again. For those of you who have been on the Internet long enough - Pay for Surfing is back. There is a service called Surf Junky making the rounds that will potentially pay you 45 cents an hour to leave a browser running on your computer. It's fairly obtrusive, but if you have two monitors (or two computers!) and frequently don't need the screen real estate, you can still work while ads scroll on your second screen. I've signed up and so far, my computer has supposedly earned $17+. Now to see if they end up actually paying me. Surf Junky may be old news already, but there's plenty of buzz about them already. They've already denied users of the Firefox browser access to their service because of the many plugin capabilities of the browser and the ability to use them to cheat the system into believing you are there when you're not. The way they did this was to turn off those accounts, with money in them, no less - raising the hackles of a large community of people yelling 'Scam!'. I'll report on what happens with my account right here on Randomblings, so keep your eyes peeled. I'll let you know when I bypass the $25 mark (sign up under my referral link if you want to help me get there quickly) and I'll let you know when or if I ever get paid via Paypal.

UPDATE: My Surf Junky total passed $25 today (3/8/2005). I have not used Firefox or cheated in any way. I'm going to leave it running until their 'payday'. Here are the current stats as of 12:55 EST:
Personal Earnings

Activity Points: 33
Payment rate: $0.45 per hour
Hours spent surfing: 55.64

Your earnings: $25.04

March 06, 2005

Guess the Closeup Contest: If you can guess what this is a picture of, you'll get a free outbound link on my blog page(s). It'll be over on the left side and show up on all of the pages in my site (pending no layout changes, of course):