" /> kasia in a nutshell: October 2002 Archives

« September 2002 | Main | November 2002 »

October 31, 2002

boo

It's Spiderella The Spider Queen and her evil minion, The Black Pussycat.

(Copy this image and die a gruesome and torturous death with no internet access and only the use of windows 95 for eternity plus I'll kick your butt)

Verizon and MSN

My cell phone service provider, Verizon is switching its web services to MSN. This means I *have to* setup a hotmail account.. I've been trying to delay this as long as possible, but it seems I cannot do that anylonger. Got my 'final notice' in e-mail today.

What does a hotmail account mean to my cell phone? Lots and lots of spam. Wondeful, can't bloody wait.

So anyone who has my cell phone email address.. it will no longer be valid soon.. e-mail me for the new one. Something @hotmail.com -- not sure what yet.

Another question.. what the heck is this butterfly doing to this man's crotch?

October 30, 2002

Verizon spammer settlement

Verizon made a settlement with the notorious spammer Alan Ralsky. According to this article he is "barred" from sending messages to Verizon customers.

The settlement, parts of which are secret, means that Verizon's 1.64 million Internet customers in 40 states will no longer receive spam from Alan Ralsky, whose Michigan- based company, Additional Benefits LLC, is considered one of the largest sources of bulk e-mail.

Outside of wishing that this settlement was not secret.. (why exactly is the spammer being treated so nicely?) I wish they had gone a step further and prohibited him from sending messages through the Verizon network altogether.. that way, unable to control Internet routing, he could be breaking the agreement anytime he sent spam.

Maybe next time.

What we need is legislation that prohibits marketing by using customer's own resources without explicit permission from said customers. Hence, you can't send me marketing email (using my bandwidth and storage space) unless I permit it (opt-in list), you can't market yourself in my referrer log (using my server and my bandwidth) without my permission, and you cannot post marketing comments in my weblog without my permission.

Why is the government protecting businesses, not constituents. We are living, breathing humans, corporations are made up entities.. why do they have more rights? I cannot legally protest McDonald on their property without their permission, but they can fill up my inbox with marketing messages against my wishes. Why are McDonald's rights (it's just an example) more important than mine?

CT NEMBA picnic thingy

CT NEMBA presents The Fifth Annual Fall Fiesta
Sunday, November 3, 830 am to ???

Sounds like fun.. I won't be there unfortunately, I have a pretty busy weekend planned.. but thought I'd post the info anyway in case someone reading this weblog wishes to check it out.. you can join at the door.

More Info -- New England Mountain Biking Association.

October 29, 2002

Spam in comments

Mark does a nice summary and critique of possible solutions to spam in weblog comments.

Thankfully I've yet to encounter this problem in my weblog. I'm sure it won't be long until I do so I've already been thinking about a solution to this. I don't like disabling comments as I enjoy input and the little discussions that sometimes sprout at the most unexpected moments.

I also don't like the idea of making users register just to post a comment. Sure -- it may detract from spam to a certain extent but it inconveniences those who just want to leave a comment and be on their merry way.. Spammers already make our lives difficult enough, I don't want to add to that just to protect myself from those slimey rodents.

Since I don't receive all that many comments my solution involves a combination of several approaches:

1. Comments from regular contributors (email address - user/name and/or ip address match) show up automagically.
2. Comments from everyone else go to a queue for human-approval (that would be me *wave*).

The second part can be nicely refined..
- the typical ways of bot detection (time, agent, etc.. )
- keyword trap (typical spam trap tool)
- manual (me again, hi) black list.

Sounds like a lot of work.. I should get scripting.. right after I finish the ten other projects I'm in the middle of.. sigh

October 28, 2002

What happens when you don't think through design

.. and rely on ping's output for your app to work.

Excerpt:
--- 192.168.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% loss, time 2023ms
rtt min/avg/max/mdev = 2.430/2.445/2.470/0.059 ms

Notice there is no "packet loss" but just loss? There is also no "packets received" just "received" and round-trip is now just rtt and now we have time and mdev now how nice.

Do they just do these things to break other peoples programs?

I don't know about other programmers.. but it never occured to me to standardize the output of my code that's destined to be human readable in order to keep some third party application supported. That's just too funny.. (okay, so I'm easily amused)

October 27, 2002

Pretty foliage

Nothing makes you feel better on a Sunday than taking a ten mile hike on a sunny day in beautifully colored woods. Except maybe bringing your camera with you and taking some colorful pictures.

Connecticut foliage is in full peak right now, here are some pictures I've taken today.. click on thumbnails to see larger versions.

----
Edit: Since someone mentioned wallpaper, I do have all these in 3.1mpx format if someone wants one, just email me.

    

        

        

        

        

        

Referrer spam take three

Seems this is now of more interest.. wired just did a story on this new spam form.

Referral logs, intended to collect information on who visited a website and how they happened to arrive there, are being stuffed with bogus links. Curious bloggers who click on a logged link to see who visited their site are instead led to pornography or advertising sites.


No kidding.. I wrote about it here, here and here.

Spammers, once again, take something useful and make it less so.. and where's our legislature in all this? Oh yes, too busy protecting rights of corporations instead of the people they're supposed to serve.

Repeat after me..
It is NOT okay to use someone's resources to spam them with marketing messages..
It is NOT okay to interfere with someone's usage of email to spam them with marketing messages.
It is NOT okay to interfere with someone's usage of system logs to spam them with marketing messages.
It is NOT okay to interfere with someone's usage of the internet to spam them with marketing messages.
It is NOT okay to fill peoples lives with marketing messages.

Fictional entities (corporations) should not have rights above those of living humans (dead ones can't be spammed).

How long before http://www.weblogs.com and http://blo.gs can no longer defend themselves from spammers and will discontinue their services? I'm guessing less than a year. Thanks a lot.

October 25, 2002

kasia is always standing there

Find out what google says about you!

This is fun... I'm learning all these new things about myself!

kasia is actually drinking beer
kasia is installed
kasia is makes top ten bitches again for 2001
kasia is a recognized expert in the complex field of non
kasia is a simple program that allows you to play with another person online
kasia is a valuable resource to executives and managers and she brings experience to each assignment to achieve results
kasia is another fan of long
kasia is willing to do light housework

[via: Reflective Surface]

Referrer ads take 2

The company I discussed in this entry just hit my server today. Now they join the lucky few in my list of banned IP addresses.

ip48.ip54.com Address: 207.253.71.48

October 24, 2002

Referrer spamming service

Not going to link to the page, I refuse to provide them more traffic.. I hate advertising enough as it is, but I hate it even more when they use *my* resources without my permission to spam me with a message I don't want to see. I've already been spammed with this method before and I hate being duped this way. Get out of my system logs.

From the spam service website:

We are doing referrer marketing: adding your URL as a referrer in the logs of thousands of weblogs. If you are seeing this page, referrer advertising worked with you.

Thankfully, no, read this on Inluminent. Here's hoping nobody is stupid enough to actually pay them money.

You might also see it as a PR tool for bloggers.

Q: How many weblogs can you reach?
A: We are currently reaching 55,250 weblogs, more being added every hour.

The best PR tool for a blogger is to create interesting content that others want to read, not make others visit through deception. This could only turn me off from reading a weblog. In fact, I should start checking my referrer logs closely and keep a list of weblogs that subscribe to this service, just to make sure I don't visit them. In fact everyone should do that.. just to make sure this company makes no money from spamming other peoples system logs.

Q: How mush does it cost?
A: The cost of a referrer broadcast is CAN$ 1500, which converts roughly to US$ 1000. We accept Visa and MasterCard.

Anyone who has to pay money to get others to read his writing probably isn't worth my time anyway.

How low will marketing companies get before something is done about this? Why are advertisers still legally allowed to use peoples own resources to spam them with unwanted marketing messages?

Mail down

Stupid SBC The connection where my main mail server lives is down.. So I've had no e-mail since sometime around 3am.. and I don't know when it will come back..

Hence, If you e-mailed me during this time, don't expect a reply soon.. (hopefully I will get it once the server is back up though).

If it's an emergency, use my work e-mail address [firstinitial][lastname]@tickets.com -- should be easy to figure out :)

-------
Update:
Turns out SNET (the local SBC spawn) had a scheduled maintenance last night and my friend who owns the said connection didn't reset his router until recently and my mail is working now. I apologize for calling SBC "stupid" undeservingly (this time, they have deserved it at other times.. ). I'll clean out my inbox later (there are about a hundred messages there.. ).

October 23, 2002

All gentoo'd

Now that I just installed tcsh on my gentoo box I feel that my setup has been completed -- everything else is decoration. I have pretty looking gnome, refresh is (finally) at a pleasant 85, my scroll mouse scrolls and my sound card is ready to play horrible sounds embedded in web pages.

I probably recompiled the kernel few times too many -- I concluded it's best to compile usb support in since I have a usb keyboard (I don't intent to attempt recovering my system w/o a keyboard if a module
doesn't load - Jeremy), other than that I think it went pretty smoothly.. except for the episode with my network..

It's funny, really.. see I crimped my cables maybe 4 or 5 years ago.. back when I was still relatively clueless about the finer things in networking. I used a cute, little colour scheme.. something like..

WO O WG G WB B WBR BR

This worked well for me over the years.. with my old 10BT hub.. I bought a switch/router (the wireless one I mentioned here). My network stopped working.. to my credit it didn't take me long to figure out it was the cables.. Because full duplex fast ethernet needs...

WO O WG B WB G WBR BR

Google Fight

Take that Microsoft.

Linux wins a google fight, my life is now complete :)

October 22, 2002

IE 6.0 stylesheet bug fix

There's a bug in how IE 6.0 renders stylesheet. If you're using Movable Type templates you probably noticed that the part of your blog entries below the end of your side section is not visible.. reloading or moving back and forward sometimes fixes that. Here's a screenshot of Jeremy's Blog to show you what I mean.

I found a workaround for it using a stylesheet element.. seems to work fine. Simply add:

float: right;

To the #links section of your styles.css file. If you're not an MT user, it's the section that's causing IE to cut off content.. that's where you want to add it... of course if the section is on the left, you want 'float: left;'.

Edit: That breaks how mozilla renders the page, but that can also be fixed by adding a width attribute to the same section:

width: 30%;

So far this seems to work for me..

Sixth row!

Geddy's side. Those are my seats for the upcoming Rush concert at the Mohegan Sun in Uncasville, CT. I had much better seats for the opening night show in Hartford, but heck, these are free.

Why is it that Rush fans are inevitably geeks or musicians.. (or combination of the two) it's odd.

Now with valid RSS feeds!

Thanks to the RSS Validator both my feeds (1.0, 2.0) are now valid. I never actually realized MT 2.2 didn't provide valid feeds.. I should read more.

Thanks to Mark Pilgrim, Sam Ruby and Bill Kearny for this great tool.

More info at Mark's site.

News aggregators and bandwidth.

Mark has a good point. I've had my news aggregator set to update once an hour.. that's really excessive and unnecessary.. I read it maybe once or twice a day, what's the point of constant updating? Changed it to once every 4 hours, and since it now runs on my laptop it'll actually be closer to once or twice a day.

A large percentage of my traffic is news aggregators.. a quick calculation puts it at 25%, I'm probably off on that though.. so far it's not a problem, yet, as I don't pay for my bandwidth and if it does become a problem I have other options I can utilize.. (I do a lot of little sys-admin work here and there for friends and aquaintances, that gets me freebies.. like bandwidth). This isn't a complaint.. just more or less an agreement with Mark -- no need to update hourly something that isn't read that often.

October 21, 2002

Suing google over page ranking

LawMeme:

SearchKing, Oklahoma's premiere parasitic link-farm, is suing Google for tweaking its PageRank algorithm to lower SearchKing's scores.

One might hope this one gets thrown out pretty quickly.. but then again our legal system isn't exactly known for its favouring of logical thinking.

[via: slashdot]

Doonesbury on blogging

No comment necessary.

[via: scriptingnews]

October 20, 2002

Earth Erotica

heatherfirth.com:

Earth Erotica celebrates the inherent beauty, creative power, and spiritual essence of sexuality as expressed in landscape.


My favourite.

You'll jeopardize your credit rating

Tonight seemed like a good night for a movie I've seen already and since Brazil was at hand.. that is what I watched.. Either my perception of movies has changed with age or this movie has changed or my reality has changed.. one of these, because it seemed very different from the last time I watched it.. years ago..

What once seemed ridiculously funny no longer was.. buried under paperwork now has meaning.. and a new threat has emerged...

Happiness.. we're all in it together

Great movie, well ahead of its time.

October 19, 2002

I don't like Barnes and Noble

To be honest, I never really did. Ever since the day I first discovered the university bookstore which happily overcharges for every teeny thing it sells (powerbar? That'll be $3, thank you) is actually a spawn of B&N.

Yesterday, as I was driving home with my newly purchased wireless network stuff I saw a B&N sign.. "cool a bookstore" I thought, as I was planning to get a mod perl book.

I should have known better. This wasn't a bookstore, this was B&N hell, books included.

Not only does their computer book selection suck (they didn't have the one I wanted..) but the whole store has the warm feel of a emergency ward waiting room. To make matters worse, as I fondly remembered my local Border's coffee shop (it's a great little hang out) I thought "at least I'll grab a coffee". Right. The B&N coffee shop turned out to be a Starbucks complete with snotty personnel who turn their noses on anyone ordering a plain, black coffee.

Latte my ass.

October 18, 2002

Gentoo update and wireless

Today was payday.. payday means I can go out and spend some money without feeling particularly guilty.. so I went to CompUSA (yes, I know, but this is CT nothing else here) and bought a WAP and a wireless pcmcia card.

They happened to have a sale on the Linksys wireless access point/router/switch for $99 so it seemed like the obvious choice (I was planning on buying a Linksys wap anyway).. and a Linksys pcmcia wireless card for $60. Not a bad deal at all.

Configuration under linux was a snap and within 5 minutes I was able to get online wireless.. sweet.

Now the bad news.. Apparently the network card I have in the desktop pc (orion) on which I'm installing gentoo doesn't like the new Linksys router. It semi-detects it (sets itself to full duplex) but that's about it.. DHCP doesn't work, static config doesn't work.. yet it works happily with the old 10BT Linksys hub I have. I do have a spare netgear card lying around somewhere, so I'll just replace it tomorrow.. don't really feel like doing that tonight, but this puts my gentoo install off by a day.. It is more than halfway there already, but don't really want to finish it without Internet access.

On the bright side, I'm typing this while lying in bed :) Wireless rules.

October 17, 2002

A news-source I used to like..

Seems to be going straight to the dogs..

The Register presented us today with this article which seems to be annoying at best. A long, pointless ramble making fun of some poor girl's weblog.. as far as I can tell simply because she happens to be a Microsoft employee.. Now whether this -- what can only be described as a rant, is deserved or not, I honestly don't know as I haven't read the blog in question.. My question is, how is this news? Even a tabloid would have better sense of newsworthy material... If this blog was required reading, I could see the point.. but as it is, I just don't.

It just stinks of spite and meanness.. not something I look for when I want to read news.

A blog is poorly written and has a parody.. whooptie freaking do.. there's a news story of the year for you..

I'm going in

Installing gentoo on my desktop today.. so until that's done and over with I'm left with only a laptop as a tool of communication with the outside world.. (well, that and telephones, cars, humans, but those don't count).

If I don't come out in the next several hours, someone come and save me from pulling all my hair out. I don't think I'll look all that great with a big, red, bald head (red from all the hair pulling, see).

-- Update time --

One hour later: Still doing a backup.. what you thought I did that before anouncing a new install? Nah.. that would make too much sense..

8:15PM Started the prep process for compiling.. I wonder if this will be done by tomorrow on my dual 600mhz system..

10:30PM: bootstrapping finished and compiling began.. so that took about 2 hours 15 minutes.. this will take a lot longer.. probably 6+ hours..

8:00AM: It appears to have finished compiling over night.. tonight, kernel!

October 16, 2002

You're not allowed to read this...

.. if you live in the US of A.

Thank you DMCA, for bringing absurdity into our daily Internet-based lives.

The Register:

Red Hat has struck a small blow against the DMCA, by publishing a security patch which can only be explained fully to people who are not within US jurisdiction. The company's position here seems to be not altogether voluntary - according to a spokesman "it is bizarre, and unfortunately something Red Hat cannot easily do much about," but like it or not Red Hat has been recruited to the campaign to make the DMCA look ridiculous.

Sorry..

The information I provided (which was just public ping plotter data, nothing internal) is getting misrepresented elsewhere.. I can't allow that, so I'm taking this down.

CNet news:

Tickets.com spokeswoman Melissa Zukerman acknowledged the problems, but said that some fans were able to get through and buy tickets. She likened the Web site problems to fans trying to buy tickets over the phone to a popular concert and getting a busy signal.

"(Giants) fans were very anxious to get tickets," Zukerman said. "The bottom line is that the tickets were sold out."

Ping Plotter graph from Steve.

cool

"Tickets.com sucks" -- Craigslist took the page down, but I was so amused by it I went through the trouble of grabbing a screenshot from my cache.


The Scobleizer:

I did get to the "buy tickets" page three times, but each time I clicked purchase tickets it put me back into an error page that kept refreshing. Not a good experience at all. Big events will continue to happen and it just isn't a good way to sell tickets this way. I wonder if anyone wrote a script to try to get through.

That wouldn't work.. the problem here was just too many people trying to access the pages..

When you download music you make Britney cry

P2P is the source of all evil. At least that's the impression one might get from reading this USA Today article.

Beginning a dialogue about online habits can be difficult, even when kids are receptive, says Anne Collier, creator of NetFamilyNews.org, a weekly online newsletter. "It's too hard to explain to Mom and Dad what they're doing online, and it's just daunting. ... Even though more parents are becoming aware of file sharing, it's still not top-of-mind for them."

Okie dokie, this is such an important issue that could not possibly be covered by like, giving the kid a set of values and morals while growing up.. nope, this is the modern birds and bees talk..

"Sit down junior, we need to talk. Have you heard of the bits and bytes?"

[via: dslr]

October 15, 2002

Thank you

For my my new book.. it's next on my reading list now.

October 14, 2002

Oh, Microsoft..

Cannot even use a real person to fake an ad.. don't they have enough money to pay someone off?

They took the page down.. but I grabbed a screenshot from google's cache to preserve it for posterity..

Stock photo they used is here.

The "editor's note" at the end is a nice touch..

Editor's Note: Now that we've successfully converted our writer to a Windows PC, we will be working on getting her to try a Pocket PC. Stay tuned for more developments!

[via: slashdot]

Update:
Yahoo news

An employee at a public relations company hired by Microsoft, Valerie G. Mallinson of Shoreline, Wash., later acknowledged she was Microsoft's mysterious convert. The Associated Press tracked Mallinson by examining personal data hidden within documents that Microsoft had published with its controversial ad.

How ironic that the horrible lack of privacy thanks to MS software is what made it easy to find her :)

I'm watching you!

I was playing around with my camera's light settings trying to learn more about using it..

Here's a medley of a result.. Interesting how different the results are. Wasn't going to post this publically but a friend thought it interesting.. bleah.. move along now.. nothing to see here..

October 13, 2002

Java persistence frameworks

Nice little walk through at the blogging roller.

I'm an old fashioned gal and tend towards using JDBC's ability to retrieve metadata and build persistence framework on the fly.. Performance degredation is negligent for my purposes.

This is of course for my own little projects.. at work, well, we use something other.

Spamming through referrer logs

I'm sure I'm not alone in the practice of checking my referrer logs to see where most of my visitors come from.

This morning, I found an odd one..


216.123.202.196 - - [13/Oct/2002:03:58:47 -0700] "GET http://www.unix-girl.com/blog/ HTTP/1.1" 200 114362
"http://avs.raverpussies.com/members/absolutesex/d114d45d/Jack-Lisa0083.html" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"

There were eight of these entries all referring back to what looks like randomly generated string within the 'raverpussies.com' site and all requesting just my /blog/ directory (the most popular page on my site).

Being the paranoid conspiracy theorist that I am, I thought this odd at the very least.. so armed with my trusted lynx (very carefully and wearing rubber gloves) I opened the said website.. As suspected, it's just another porno site with zero relevance to my page (other than I'm a female and am equipped with the same type of body parts that are apparently splayed all over the pages there). I would strongly suggest nobody visit them unless they want endless pop-ups and a high-jacked browser..

The obvious conclusion.. I've been spammed through my referrer log! A google search unearthed this kuro5hin article from May 2001 on this very topic.

It certainly looks like this slimy practice isn't new at all.. just new to me. With the relatively new custom of displaying the recent referrers on the front page of many blogs I can see this quickly growing in popularity.. After all.. it's an easy way to get yourself linked from pages that are guaranteed to have multiple daily visitors.

Excuse me, I now have to go sanitize my logs. Pass the lysol.

October 12, 2002

Pictures from under the umbrella

It's been raining, raining and raining some more.. but I finally couldn't stand it and went out for a small hike in the rain.. Took my camera along, of course.. and took a couple of fall pictures.. The foliage in CT isn't quite there yet... but I managed to find some other interesting objects to photograph.

Taking pictures in bad lighting, in rain with no tripod and an unsteady hand isn't easy.. so forgive me the crummy quality.

Click on the thumbnails to see the (much bigger) versions.











Cats and kitchen counters

It's a love story.

I do clean it before I cook on it!

Rain.. rain.. rain..

It's been raining for two days. It's raining today. Forecast for tomorrow? More rain.
I can't even go to the coffee shop and work outside on my laptop.. sigh


Bits and pieces..

Krzysztof says.. people are starving at the buffet of life.. well.. old and tired soliloquies aside I think this is the wrong audience for this.

Dave hates AIM for MAC.. It's not better for linux..

The senat once again is trying to screw small internet broadcasters, so what else is new?

David Johnson finds blogging difficult. When in doubt, just make an entry full of links to other blogs :)

Finally (if anyone is still reading this) Derek thinks asking friends to help with a move is lame.. but isn't it more fun (and free exercise!) to move heavy items with a bunch of good friends and then spend the evening in an empty new apartment drinking beer, eating pizza and laughing at each other? Some of the best times I've had where moves.

October 11, 2002

What is wrong with this picture

There is a new attraction in central Connecticut. It opened last Saturday, but the level of attention has yet to decline.

At any given hour of a day, if you drive by it, there is a crowd of cars attempting to enter the parking lot. A police officer is on hand directing the traffic flow (who is paying for that?). Line of cars blocking the right lane of the adjacent highway for a mile, sometimes longer.

Drivers sitting in their cars, some smoking cigarettes, some looking impatiently through the windshield.. most are lone drivers.

There are orange traffic cones blocking off the right turn lane prior to the entrance.. and the place is mobbed.. line of people out the door.

What is this phenomenal attraction?

A newly opened Krispy Kreme Donut Shop. I kid you not.

I want out of Connecticut. Now.

The homeless guy's blog

A homeless guy finds a refuge on the Internet.

"Online, the only thing that can be judged by others is your communication, your voice, your opinion. Before anyone says a thing, all people on the Internet are considered equal. It's a level of equality so pure it creates a tension that's hard to deal with."

http://www.thehomelessguy.blogspot.com/

October 10, 2002

Weird things kasia eats

I was just sharing what I had for supper with someone and it occurred to me I really should share it in my blog.

Lady-bug socks and teddy-bear sheets aside, I'm a pretty weird person.. Particularly when I'm preparing a meal out of whatever is leftover in the food storage appliance commonly referred to as a refrigerator after a week of no grocery shopping.

Tonight's menu..
- leftover tofu cut in irregular strips, tossed in picante sauce (I like it really hot)
- leftover, store-made cole slaw that still looks vaguely edible
- last survivor from a package of wheat pita bread bought sometime in the beginning of the week.

Put it all together and what do you get? A yummy pita sandwich that needs to be chased with lots of seltzer water..

MT upgrade

Being the hip chick that I am, I just upgraded to Movable Type 2.5 to run the newest and greatest...

All seems to work so far, except for the old search plugin, but that can be fixed..

Tip for those running MT with mod_perl: need to restart apache before running the upgrade script.. yes, I know it's common sense since mod_perl caches perl, but I managed to forget that..

At least this forced me to backup MySQL for once.. so if this server crashes (Steve, you are doing backups, right?) I'll be able to recover the invaluable information (yah, right) I have in this journal blog.

Steve, Lynne, Wendy, check your blogs, guys..

Aztec Autumn

Finished reading it last night. Not worth bothering with, really.. it's just a shadow of Aztec which is a terrific book and highly recommended. The ending made me want to throw "Aztec Autumn" out the window.. gratuitous sex scenes didn't help it at all..

Now reading "American Gods".. starts off pretty well..

October 09, 2002

Hacking blogs through comments?

Someone apparently is attempting to do some hacking using the comment posting ability in blogs.. (and apparently a really poor and misguided attempt)

In this entry.. this is the code he attempted to execute:

xxx<?php readfile("/etc/passwd") ?>xxx

Apparently he attempted the same thing on Ask's blog since he came to my site through a comment I posted there.

Since he's so nice as to try and get my /etc/passwd file I might as well be nice and post his IP address 63.89.29.6 which is in a block owned by Lally, Mcfarland & Pantello who have a really hideous website.. (they own the whole class C 63.89.29.0.. someone playing at work?)

Someone tell this guy MT is not php.. but even if it was php (of which I know next to nothing).. would it really be *this easy* to get the passwd file? I really don't think so.. but I could be wrong..

Okay, after further reading, apparently it is that easy to get the passwd file using php unless it's run in safe mode.

October 08, 2002

Escher in lego

These are really cool..

"Balcony"
"Belvedere"
"Ascending and Descending" (a personal favourite).

[via: jwz]

Credit card company stupidity

I use my credit card company's (who shall remain un-named to protect the stupid) online bill payment system. Went to make a payment today and they added additional security.. Now not only do I have to provide them the last four digits of my social security number when making a payment, but now they also request my mother's maiden last name as well.

How utterly ridiculous.. I know.. this is just in case someone hacked into my account and wants to pay it off for me.. right? Gee.. god forbid something like that should happen..

To access my statement online all I needed was my credit card number and last four digits of my social security number.. wouldn't you think this is the point at which they would like additional security? Furthermore.. if I need the number to access the statement.. what else are they protecting my account from? Obviously someone already has the most valuable commodity.. as in the number itself, if they got this far.

More google oddities

I swear this is an obsession with me now..

When I wrote this entry, I was the number one hit on google for search fix google. I was still the number one hit yesterday.. (I did say I'm obsessing about this.. ).. today.. I'm not even registering on that search.. I've looked lots of pages back.. nothing! Search for 'fix google kasia' (no quotes) registers an old entry of mine as a first hit (from back in August) but not the one that was number one hit just yesterday.

All my other rankings have not changed.. I'm still the number one hit for 'porn clerk stories' and 'python in the nutshell' and other searches I whined about here.

In fact, putting in a sentence from that entry registers nothing at google now.. this is something that was ranked as the first hit on google yesterday.. now it's not even indexed?

This is pretty weird.. I'm starting to think someone at google is playing with this manually.. how's this for conspiracy theory slash paranoia? Someone please tell me there's a rational explanation here.. I just haven't thought of it?

[ref: Irony defined]
[ref: Somebody fix google]

October 07, 2002

Dual laptops

The peak of technology at my house.. my laptop now has a laptop.. or should that be my desktop has a laptop?

I'm scared

I commute to work every day (except for sickdays, of course *cough* *cough*) and it's about 30 miles one way. That's a long drive. It seems even longer when it spent driving down (..a long desert highway.. (bleah, wrong song)) a boring, uneventful route in central Connecticut. Quite possibly world's most boring drive.

Normally, I pretty much just space out, turn on some awful music (one of my friends calls it "your rave music", it's really not.. but okay) and happilly drown out the existence of anybody else while I roll down the road to get to the traffic lights that will lead me to work. I usually run the red light for a left turn at this point, since it's a useless wait and cops (hi officer) aren't normally present.

Today, for some bizzarre reason I was awake enough to pay attention to my surroundings while driving. No, really, I was. I am now frightened. I noticed something that has escaped me before.. I mean I did realize people these days prefer to buy the bigger cars.. you know.. SUVs, minivans, trucks, tanks, missile silos on wheels that kind of thing.. but this is frightening. My little mazda is apparently the smallest car left on roads today. At least in Connecticut. At least on highway 91 South between routes 9 and 68. At least in my closest vicinity.

As I was looking around me in panic all I could see where these huge vehicles, all seemingly set on attacking and devouring my little car. I could just picture their grilles filled with bearings rumbling "gas.. give me gas". It reminded me of that horrible movie based on a Stephen King story (aren't they all horrible when they're made for tv?). The one where vehicles rebel and attack their owners at a gas station. I don't recall the title.. but that's what it felt like all of a sudden, except instead of just the vehicles rebelling, it was the owners that drove them into a frightening highway commute squalor.

I'm scared to drive back home.

I'm interesting

Well, at least someone thinks my blog is.

Chuq has started a new blog and begins by giving out compliments. That's always a good start and guaranteed to earn some links at least! (See? Worked on me!).

Anyone else notice that the blogging world seems to be dominated by mac users? Maybe it's just the ones I read..

October 06, 2002

Quick and dirty guide to having a 100k/s throttle policy

Was doing this on multiple servers today, might as well get a blog entry out of it.
Note: this requires mod_so to be installed.. w/o that you'll need to do a lot more work.
To find out if you have mod_so, use /usr/local/apache/bin/httpd -l


  1. Download mod_throttle
    http://www.snert.com/Software/mod_throttle/mod_throttle312.tgz

  2. upack & unzip the tgz file
    tar -xzvf mod_throttle312.tgz

  3. Edit mod_throttle.c Change: (this is for a freebsd system)

    #define USE_POSIX_SERIALIZATION
    #undef USE_SYSTEM_V_SERIALIZATION

  4. Edit Makefile

    Important stuff:
    1. APXS=/usr/local/apache/bin/apxs
    2. APACHECTL=/usr/local/apache/bin/apachectl

  5. make install (that's not a mistake, don't need to do make first).
    You'll need to do this as root or using sudo since it edits the httpd.conf file.

  6. Edit httpd.conf to set a throttle policy

    #
    # Throttle policy limits connections to 100k/s per IP address
    # Keeps a history of 1000 ip addresses
    #

    <IfModule mod_throttle.c>
       ThrottleClientIP 1000
       ThrottlePolicy Speed 100K 1s
       <Location /ts>
          SetHandler throttle-status
       </Location>
    </IfModule>

  7. Restart apache

    /usr/local/apache/bin/apachectl restart

  8. You're now throttling the entire server to 100k/s per IP.

You know you've read a good book..

.. when you feel empty after finishing it. It's almost as if a family member had died and you'll never see them again.


"Red Azalea" by Anchee Min is one of those books, highly recommended.

Google fix: ugly hack?

While everyone else with a weblog is complaining their google ranking has dropped mine seems to have soared ever higher. I've been trying to come up with a logical explanation for this and failed.. The only possible difference I can see between my site and others is that I do not actually call it a 'weblog' 'blog' or anything of the sorts.. well, other than in the url anyway.

Is it possible that google's fix to not rank weblogs as high is as ugly as that? I hope not.

[ref: Irony defined]
[ref: Somebody fix google]

October 05, 2002

Purty flowers

I've been busy. My laptop is now running RedHat 8, now before everyone goes off screaming "what? Redhat???".. I just didn't have the time or inclination to attempt installing gentoo on a laptop.. I needed something up and running so I wouldn't have to use win2K, so yes, RedHat. It's pretty.


Here's a picture of the laptop with RedHat, better than the previous one, no?

Speaking of newer linux, thanks to the magic of using a newer kernel I can now use my card reader (for my digital camera) under linux.. very cool.


I named it andromeda, my desktop is orion. Speaking of my desktop, it was just the power supply that blew (ref: this entry), I had a spare, replaced it and all is well *phew*.

October 04, 2002

Revenge of the blog at Yale

Something interesting in Connecticut for once.. I might just go out of curiosity.

[via Scripting News]

It's all about timing

Today I got my new laptop. It's not exactly new, since it's used.. but it's a nice little laptop and just perfect for my needs. Dell Latitude, 400mhz, 128MB RAM, 6GB hard drive.. what more do I need. Oh yes, 128MB more RAM that is on its way from Dell to me as I type this ($33, not bad at all).

So of course, here I am home.. downloading new RedHat so I can dual boot this little thing (I'll finally be able to upgrade my desktop and put gentoo on it) as right now it's running Windows 2K (yuck, but at least it *has* an operating system.. and sometimes even unix girls use windows) when I hear a *poof* sound... Never a good thing..

My PC's power supply blew.. just like that.. It's all about timing..

Newsreader annoyances

I use amphetadesk as my newsreader, now before I get a gaggle of good advice on why I should use something like, say, netnewswire, let me remind you, I do not have a mac. Thank you. Back on topic. I use amphetadesk, it's a decent newsreader.. it serves its purpose relatively well but has one major annoyance.

All newschannels display in one page. One big page. One giant, humongous, long, memory-hogging, netscape-crashing, long-time-loading page that is hard to navigate.

There are several gripes here, and really only one for the newsreader: I wish it would allow breaking into pages.. I quickly glanced through their README file and it doesn't appear to.

The other gripe is about some weblogs.

This is probably akin to starting a religious war (see vi vs emacs), but I'll do it anyway. I wish the weblogs that are seemingly completely published by their RSS feed (as in the feed contains the entire entries not just an excerpt) weren't or at least gave a secod feed that was just headlines (kind of like mine, default MT feed.).

I find myself scrolling through several hundred lines of text that I've already read or chose not to read each time I look through headlines in my newsreader. I don't want to do that!

I like reading weblogs from where they live (their original websites) not from my newsreader.. I only use that to see if a site has been updated and if the new headline grabs me. That's all. Nothing more.

I realize some like this behaviour.. so how about an alternative feed for minimalists like me?

Third gripe (like I mentioned above, there are several gripes) is weblogs that use images. (No John for once this isn't about yours =) ). Images also display in my newsreader. Now envision subscribing to 4 or 5 newsfeeds that are full of text (entire entries) and full of images... what do you get?

One long, giant, humongous, slow loading, memory-hogging, netscape crashing page that is hard to navigate.

October 03, 2002

Blast from the past

I think I need to clean up my bookmarks more often.. found this: "Csh Programming Considered Harmful" post from 1994!

excerpt:
The following periodic article answers in excruciating detail the frequently asked question "Why shouldn't I program in csh?".

woohoo..

cranky

I'm all for sharing information, but honestly, if you're going to copy one of my rants, at least give me a link... It's odd to read something someplace else and realize "wait a minute.. I wrote that..".

October 02, 2002

Java on the desktop

Jeremy has been blogging from the OSXCon. Today James Gosling talked about Java.

Gosling said.. Java has been successful everywhere but the desktop. Or at least that's what people hear. It's big on the server and that drowns out the desktop news.

This is something I just don't understand. Why push Java on the desktop? It has not done well in that market and I don't really think it will in the future no matter how many swing libraries materialize. Don't get me wrong, Java is a great language. It's versatile, powerful and manages to keep simplicity despite being a powerhouse of tools.

The main thing about Java is "write once, run anywhere".. which is fantastic, but it turned out to be better for servers than clients. There are a lot of problems with developing Java GUIs, swing not-withstanding. They're slow, quirky and look and feel isn't quite standardized (that's a bigger problem than people might think) . Unless ran in a browser... and who the heck really wants applets besides Yahoo games?

Webstart is a cool project, but since a user needs to have Java already installed on their computer to use it, it's relatively useless in saving Java on the desktop. I just don't think this will happen unless Microsoft starts to distirbute Java as part of the operating system and I don't see that happening anytime soon. Not yet anyway.

Irony defined

Someone pointed this out to me today.. Search google for fix google.

I actually wrote them an e-mail today.. I don't know why this bugs me so much, but it does..
I mean, come on.. number one hit for nanaimo bar?

[ref somebody fix google]

Be careful what you post!

From Kuro5hin..

Just another Mechanic takes a customer's car for a joyride - mechanic stupidly writes about it - customer reads it - mechanic gets fired story.

OH YEAH, SHE EVEN TOLD THE SERVICE WRITER TO MAKE SURE THAT NO "PUNK" DRIVES HER CAR, WELL SINCE I AM THE MUSTANG SPECIALIST HERE AT THE DEALER, I GUESS I AM "THE PUNK", ALL THE MORE TO DRIVE HER '03 COBRA VERT AND SEE WHAT ITS GOT..

The dealer, Northside Ford, fired the mechanic shortly after being informed of the problem.

Of course this brings up a question.. how soon before someone gets fired over a faked posting somewhere..

October 01, 2002

Just linking

Mark's boss wanted him to stop writing. He didn't, and now he has a resume and this post.

I don't know if I would have the guts.. I'd like to think I would.. but honestly, I don't know. Thankfully my boss is not a pompous ass.

Mark also has a cool cat.

Go Mark.