<?xml version="1.0" encoding="iso-8859-1"?> <rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/">

<channel>
<title>Confessions of a G33k</title>
<link>http://WWW.cleverhack.com/blog/</link>
<description>One tech obesessed geek girl opining about current events, technology, and herself. </description>
<dc:language>en-us</dc:language>
<dc:creator>joy@cleverhack.com</dc:creator>
<dc:rights>Copyright 2005</dc:rights>
<dc:date>2004-05-31T00:47:29-05:00</dc:date>
<admin:generatorAgent rdf:resource="http://www.movabletype.org/?v=2.661" />
<admin:errorReportsTo rdf:resource="mailto:joy@cleverhack.com"/>
<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2000-01-01T12:00+00:00</sy:updateBase>


<item>
<title>for my syndication readers</title>
<link>http://WWW.cleverhack.com/blog/archives/001279.html</link>
<description>The main blog url and syndication feeds have changed to cleverhack.com. Change your links accordingly....</description>
<guid isPermaLink="false">1279@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>The main blog url and syndication feeds have changed to <a href="http://www.cleverhack.com">cleverhack.com</a>.  Change your links accordingly.</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1279" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001279.html#comments" title="Comment on: for my syndication readers">Comments (0)</a></p> 
<p>Comments on this Entry:</p>


</description>
]]></content:encoded>
<dc:subject>site info</dc:subject>
<dc:date>2004-05-31T00:47:29-05:00</dc:date>
</item>
<item>
<title>Iraq war photos</title>
<link>http://WWW.cleverhack.com/blog/archives/001278.html</link>
<description>I found this site featuring photos apparently taken by a German photojournalist during the early part of the Iraq war...</description>
<guid isPermaLink="false">1278@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>I found this site featuring <a href="http://theprecipice.org/gallery/iraq/">photos apparently taken by a German photojournalist during the early part of the Iraq war</a> via <a href="http://blogsnob.simpleads.net/">blogsnob</a>.  Nevermind your politics, go look now.  </p>

<p><img alt="04_20_iraq_c.gif" src="http://WWW.cleverhack.com/blog/archives/04_20_iraq_c.gif" width="250" height="167" border="0" /></p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1278" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001278.html#comments" title="Comment on: Iraq war photos">Comments (1)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2524">Arthur</a> on 
May 30, 2004  9:26 PM)


(some of them not safe for work)</p>
</description>
]]></content:encoded>
<dc:subject>current events</dc:subject>
<dc:date>2004-05-30T19:25:13-05:00</dc:date>
</item>
<item>
<title>The Mac is a Harsh Mistress</title>
<link>http://WWW.cleverhack.com/blog/archives/001277.html</link>
<description>I was clickity, clicking along in my daily blog reading and found this gem...The Mac is a harsh mistress Microsoft,...</description>
<guid isPermaLink="false">1277@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>I was clickity, clicking along in my daily blog reading and found this gem...<a href="http://fishbowl.pastiche.org/2004/05/25/the_mac_is_a_harsh_mistress">The Mac is a harsh mistress</a></p>

<blockquote>Microsoft, ladies and gentlemen, is a cheap whore. She lives on the fringes of the law, but there’s no getting rid of her because she fulfils a certain need in our society. People want what she is selling.

<p>There’s a certain painted-on mystique to her, of course. We’ve all been indoctrinated with the propaganda, the hooker with the heart of gold, the disturbingly wide-mouthed Pretty Woman. When you find her, though, beneath the paint she’s really quite plain. You take what you need from her, but reluctantly and because you have no alternative. You get what you want, but she is almost peripheral to the act.</p>

<p>Apple is a lover.</p>

<p>From the moment you meet her, you know that she wants you to be happy. She wants to be a part of your life, and you can’t help but be drawn into wanting to be a part of hers. She is beautiful and elegant in ways that the layers of paint on the Microsoft street-walker can only desperately try to imitate.</blockquote></p>

<p></p>

<p><br />
</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1277" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001277.html#comments" title="Comment on: The Mac is a Harsh Mistress">Comments (3)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2521">Colin</a> on 
May 29, 2004 11:00 PM)


So true.

Exprimenting with color?</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2522">Dianna</a> on 
May 30, 2004  1:40 PM)


OMG so true.. I love it!  (I moved my blog btw to unsecuregirl.com) xoxox </p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2523">Colin</a> on 
May 30, 2004  2:35 PM)


Dianna the site you say you moved your blog to, doesn't work...</p>
</description>
]]></content:encoded>
<dc:subject>amusement</dc:subject>
<dc:date>2004-05-29T18:50:47-05:00</dc:date>
</item>
<item>
<title>RIAA sues single mom making $21K/yr</title>
<link>http://WWW.cleverhack.com/blog/archives/001276.html</link>
<description>Good going guys. Here&apos;s a question to be posed....Is it fair to sue a 41 year old single Mom who...</description>
<guid isPermaLink="false">1276@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p><a href="http://www.siliconvalley.com/mld/siliconvalley/8765723.htm">Good going guys</a>.</p>

<p>Here's a question to be posed....Is it fair to sue a 41 year old single Mom who ostensibly had a computer in her house to encourage her daughter's education, but who herself could not use that computer?</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1276" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001276.html#comments" title="Comment on: RIAA sues single mom making $21K/yr">Comments (4)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2515">Derek</a> on 
May 28, 2004  9:44 AM)


Frivolous lawsuits are bad in general...but the RIAA has taken it to an entirely new level of uselessness.  They are apologists for an industry that puts out subpar products and they reply to their customers' (I hate the term consumers) frustrations with high prices, low quality and limitations on fair use.  The fact that they are suing those least able to pay is just sick.  It's akin to picking on the smallest kid in the playground multiplied by 1000 (estimated figure).

It's a damn shame.
-D</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2516">Colin</a> on 
May 28, 2004 11:44 AM)


I really think everything they are doing is worthless.  First off making a women like that pay tons of money is just crazy and heartless.  Second, all of these lawsuits, don't scare me one bit, I still download as much music as I always have, by doing this they aren't making any "friends", I can see them soon going down the path as SCO.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2517">Harald</a> on 
May 28, 2004  1:27 PM)


Sadly, you're preaching to the choir. There are a whole bunch of people who _have_ been taken in by RIAA propoganda, but I don't think they're reading our weblogs... :)</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2519">ilan</a> on 
May 29, 2004  3:37 AM)


your post has inspired some comments over on blogcritics...</p>
</description>
]]></content:encoded>
<dc:subject>interesting...</dc:subject>
<dc:date>2004-05-27T15:31:42-05:00</dc:date>
</item>
<item>
<title>I agree</title>
<link>http://WWW.cleverhack.com/blog/archives/001275.html</link>
<description>Michelle Malkin, on the media embrace of a certain two female bloggers. But give The Washington Post two vain, young,...</description>
<guid isPermaLink="false">1275@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p><a href="http://www.townhall.com/columnists/michellemalkin/mm20040526.shtml">Michelle Malkin</a>, on the media embrace of a certain two female bloggers.</p>

<blockquote>But give The Washington Post two vain, young, trash-mouthed skanks who couldn't care less about what their parents think of their sex-drenched infamy, and the newspaper can't wait to help make them full-fledged members of the media elite.</a> </blockquote>

<p>As a wise person once told me, "Anyone can talk dirty, real women have class."</p>

<p><br />
Related Link:<a href="http://www.washingtonpost.com/wp-dyn/articles/A48909-2004May22.html">WaPo article</a></p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1275" onclick="OpenTrackback(this.href); return false">TrackBack (1)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001275.html#comments" title="Comment on: I agree">Comments (0)</a></p> 
<p>Comments on this Entry:</p>


</description>
]]></content:encoded>
<dc:subject>pop culture</dc:subject>
<dc:date>2004-05-27T01:21:35-05:00</dc:date>
</item>
<item>
<title>Live capture comment spammer logs</title>
<link>http://WWW.cleverhack.com/blog/archives/001274.html</link>
<description>Yesterday afternoon I went to take a quick look at my logs, only to notice that a comment spammer was...</description>
<guid isPermaLink="false">1274@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>Yesterday afternoon I went to take a quick look at my logs, only to notice that a comment spammer was hitting me in real time.  When I realized what was occurring, I immediately went to ban the offending IPs as they appeared.  Here's the logs, and I want to point out a few things to y'all.</p>

<p>First, take a look at the HTTP error codes.<br />
HTTP 403 - are IP's I've banned.  It appears that some of the IPs that hit me on Tuesday were ones that were used in previous comment spamming attacks.  This means that the comment spammers probably only have a set amount of cracked machines that they can use.  This also means that IP banning after being attacked will help alleviate the problem.<br />
HTTP 405 - method not allowed.  I've throttled MT to only accept comments after a certain amount of time.  And the idiot who created this script apparently was unaware of this limitation, thusly his comments are being rejected.</p>

<p><br />
Host: <a href="http://64.124.222.172">64.124.222.172</a>             [Attack script on webserver - IP <a href="http://www.dnsstuff.com/tools/whois.ch?ip=!NET-64-124-222-0-1&server=whois.arin.net">WHOIS resolves to above.net</a>]<br />
Url: /blog/archives/001202.html<br />
Http Code : 403<br />
Date: May 25 16:18:53<br />
Http Version: HTTP/1.1"<br />
Size in Bytes: 1010</p>

<p><br />
Host: 24.97.4.148<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 16:01:19<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 200.202.216.162<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 16:01:18<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 66.186.173.42<br />
Url: /blog/archives/001202.html<br />
Http Code : 403<br />
Date: May 25 16:01:16<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 998<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 69.10.70.130<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 16:01:16<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: <a href="http://64.124.222.172">64.124.222.172</a>   [Attack script]<br />
Url: /blog/archives/001202.html<br />
Http Code : 403<br />
Date: May 25 16:01:15<br />
Http Version: HTTP/1.1"<br />
Size in Bytes: 1010</p>

<p><br />
Host: 219.117.212.87<br />
Url: /blog/archives/001202.html<br />
Http Code : 200<br />
Date: May 25 16:01:15<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 8602<br />
Referer: -<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 213.171.57.162                [Surprise, this IP is from .ru]<br />
Url: /blog/styles-site.css<br />
Http Code : 200<br />
Date: May 25 16:00:45<br />
Http Version: HTTP/1.1"<br />
Size in Bytes: 6026<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)   [Looks like a legit browser.]</p>

<p><br />
Host: 200.180.247.230<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:57:19<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 198.26.130.36<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:57:17<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 61.120.94.198<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:57:16<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 80.82.139.21<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:57:14<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 203.22.206.51<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:57:02<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 212.25.77.189<br />
Url: /blog/archives/001202.html<br />
Http Code : 403<br />
Date: May 25 15:57:00<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 998<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 203.122.54.129<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:56:58<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 80.49.24.15<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:56:55<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 63.171.110.188<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:56:48<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p><br />
Host: 200.163.234.2<br />
Url: /blog/archives/001202.html<br />
Http Code : 405<br />
Date: May 25 15:56:36<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 318<br />
Referer: http://www.cleverhack.com/blog/archives/001202.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1274" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001274.html#comments" title="Comment on: Live capture comment spammer logs">Comments (0)</a></p> 
<p>Comments on this Entry:</p>


</description>
]]></content:encoded>
<dc:subject>blogosphere</dc:subject>
<dc:date>2004-05-26T13:14:27-05:00</dc:date>
</item>
<item>
<title>I&apos;m around</title>
<link>http://WWW.cleverhack.com/blog/archives/001273.html</link>
<description></description>
<guid isPermaLink="false">1273@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p><img alt="imblogging.jpg" src="http://WWW.cleverhack.com/blog/archives/imblogging.jpg" width="200" height="295" border="0" /></p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1273" onclick="OpenTrackback(this.href); return false">TrackBack (1)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001273.html#comments" title="Comment on: I'm around">Comments (7)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2456">ilan</a> on 
May 21, 2004  3:07 PM)


cool shirt.  have you seen mightygirl's? it's a trip.  check out mightygirl.net.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2457">Janine</a> on 
May 21, 2004  6:08 PM)


That is tres cool.

Judging from the diminished number of enormously stressed-out people in the B&N Starbucks this week, is it safe to wager that you survived exam-time and congrats are in order?</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2507">Colin</a> on 
May 21, 2004 11:30 PM)


Good to hear, I like the new green color.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2509">Nobody</a> on 
May 22, 2004  9:10 PM)


Is that photo, specifically the slogan, supposed to be some kind of pithy Margitte-esque commentary on the whole non-blogging mess i.e. his infamous painting titled "This is not a pipe" or am I just drinking too much beer tonight?</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2510">Charlie On the Pennsylvania Turnpike</a> on 
May 25, 2004  8:07 AM)


Great photo.

Cute shirt.

Cute subject, too.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2511">Harald</a> on 
May 25, 2004 12:42 PM)


 I was going to say something like that, but I thought I'd get in trouble...</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2513">Shawn</a> on 
May 25, 2004 10:59 PM)


The color change is not quite that easy on the eyes.</p>
</description>
]]></content:encoded>
<dc:subject>about me</dc:subject>
<dc:date>2004-05-21T14:08:39-05:00</dc:date>
</item>
<item>
<title>Nick Berg emails from Iraq</title>
<link>http://WWW.cleverhack.com/blog/archives/001272.html</link>
<description>The Philadelphia Inquirer (reg. required for site access) has published some of the emails sent from Nick Berg in Iraq....</description>
<guid isPermaLink="false">1272@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p><a href="http://www.philly.com">The Philadelphia Inquirer</a> (reg. required for site access) has published some of the <a href="http://www.philly.com/mld/inquirer/news/local/8651712.htm?template=contentModules/printstory.jsp">emails sent from Nick Berg in Iraq</a>.  </p>

<p>I am going to <a href="http://www.outsidethebeltway.com/archives/006135.html">trackback to OTB</a> since James has a latest news roundup there.  </p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1272" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001272.html#comments" title="Comment on: Nick Berg emails from Iraq">Comments (3)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2443">James Joyner</a> on 
May 13, 2004  9:38 PM)


Thanks for the tip.  otbblog/jamesotb will work on the registration.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2444">James Joyner</a> on 
May 13, 2004  9:47 PM)


Actually, they want e-mail so it's james@mydomain.com - jamesotb</p>
<p>(Carol on 
May 18, 2004  4:47 PM)


Forgive
Jesus said, Father forgive them for they know not what they do.
As we forgive even the most horrendous crimes, God forgives us of our great crime of rejecting him.

Romans 5:8:  But commendeth his love toward us, in that while we were yet sinners Christ died for us.</p>
</description>
]]></content:encoded>
<dc:subject>current events</dc:subject>
<dc:date>2004-05-13T21:34:45-05:00</dc:date>
</item>
<item>
<title>wifi, free as in beer?</title>
<link>http://WWW.cleverhack.com/blog/archives/001271.html</link>
<description>Outside the Beltway linked to this post by Phil Libin advocating folks to not secure their wifi access points because...</description>
<guid isPermaLink="false">1271@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>Outside the Beltway <a href="http://www.outsidethebeltway.com/archives/006125.html">linked</a> to this post by <a href="http://www.vastlyimportant.com/vastly/2004/05/wireless_access.html">Phil Libin</a> advocating folks to not secure their wifi access points because "it's too hard" for the average person to set up their WAP securely.  I wrote a quickie response at OTB about some concerns, and I also found <a href="http://www.securityfocus.com/columnists/237">this article at Security Focus covering the legal aspects of wifi use</a>.</p>

<p>As with any shared network, there are a host of issues to consider when providing access to others.  What if the person sharing your network downloads something illegal?  Are you keeping logs tracking who is who?  If you are unable to secure a WAP, who is to say that you've properly secured your own computers?  What about if your provider shuts you down for excess bandwith usage?</p>

<p>In other words, if you are thinking of setting up an open WAP, think long and hard about the implications, both technical and legal.  While it's great to talk about ubiquitious wifi connectivity, we're still in a tangled web of undefined legal risks.  If nothing else, you're putting yourself at the mercy of others who may be able to take advantage of you.</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1271" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001271.html#comments" title="Comment on: wifi, free as in beer?">Comments (2)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2445">Phil Libin</a> on 
May 14, 2004  1:23 AM)


Joy,

You make a good argument, but I’m going to stick by mine.

I never said that people shouldn’t secure their WAPs.  I think that people *don’t* secure their WAPs because the technology is poorly implemented and frustrating.  If WiFi security was more robust and easier to use, it would naturally be in everyone’s advantage to use it. 

However, if I’m going to ask average consumers to spend a few hours on computer “security”, I’d much rather they first install the latest OS patches, turn off file sharing, install a firewall at the network and on every computer, learn a bit about “phishing” and other scams (and maybe download SpoofStick), install an anti-virus program and get the latest signatures, check for spyware and rethink their passwords.  When they’ve done with all that, they can monkey around with their WiFi network.  All the other stuff is more important, more effective and easier to do.

Even if you manage to keep your WiFi access point encrypted, you’re not really adding a whole lot of security.  Everything just reverts right back to plaintext as soon as it goes from the WAP to the ISP, all your HTTP and FTP and email is bouncing around the guts of the web for anyone to see.  If you’ve got data worth protecting, use SSH or SSL or a VPN – then it doesn’t matter if you’ve secured your WAP.  If a non-SSL site asks you for a password, assume that everyone can see it.  If you send out unencrypted, unsigned email, assume that there’s going to be a searchable trail of everything you’ve ever written somewhere or another.

As for the legal aspects, I don’t buy it.  Internet access is not a firearm, and I don’t have any responsibility to make sure others can’t use the bits my access point decides to shoot out into the air.  If my ISP has a problem with this, they should figure out how to restrict access on their side.  I shouldn’t have to waste my time setting up “security” to solve their billing problem.  If a crime is committed in my neighborhood, it’s not up to me to prove that I didn’t do it.  It’s up to the authorities to find whoever did – and to prove it.  Of course, you’re right that this area is “undefined” and it may take an unpleasant case or two to iron things out.  If you’re concerned about being blamed for the actions of others on “your” wireless network, by all means take the appropriate precautions.  For what it’s worth, I’ve found that MAC filtering works better than WAP encryption.

So, bottom line: we need better security technology that takes the burden of securing all data away from the user.  In the mean time, locking down residential wireless access points is not my top security priority, and may not be a good way to spend finite security resources.


</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2447">Misanthropyst</a> on 
May 14, 2004  6:40 PM)


Resistance is Futile. You Will Be Assimilated.

Joy, you sound like a lawyer!

;^)</p>
</description>
]]></content:encoded>
<dc:subject>technology</dc:subject>
<dc:date>2004-05-13T19:30:03-05:00</dc:date>
</item>
<item>
<title>ATTN: Floridians</title>
<link>http://WWW.cleverhack.com/blog/archives/001270.html</link>
<description>Be on the lookout for Giant African Land Snails! From this hobbyist page about Giant African Land Snails....</description>
<guid isPermaLink="false">1270@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>Be on the lookout for <a href="http://www1.naplesnews.com/npdn/florida/article/0,2071,NPDN_14910_2881199,00.html">Giant African Land Snails</a>!</p>

<p><br />
<img alt="HandSnail.jpg" src="http://WWW.cleverhack.com/blog/archives/HandSnail.jpg" width="364" height="200" border="0" /><br />
From <a href="http://homepage.ntlworld.com/animal-zone/Snails.htm">this hobbyist page about Giant African Land Snails</a>.</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1270" onclick="OpenTrackback(this.href); return false">TrackBack (1)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001270.html#comments" title="Comment on: ATTN: Floridians">Comments (4)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2439">bert</a> on 
May 13, 2004  2:25 PM)


I'd be more worried, except for the fact that our Agriculture Commissioner is Charles Bronson... These snails don't stand a chance.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2440">Colin</a> on 
May 13, 2004  7:19 PM)


Those snails are insane.  I can't believe they can ge so big, and that someone would wnt them as pets.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2441">Phil Libin</a> on 
May 13, 2004  8:04 PM)


Holy crap!  I came to this blog to respond to your post about my WiFi security position (your next entry – it’s not “Larbin”), but I got distracted by the giant snails.  I don’t even remember all the great counter arguments I was going to use.  Must… Not... Stare... At... Giant... Snail.</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2442">Arthur</a> on 
May 13, 2004  8:27 PM)


Hmmm. I wonder what they taste like.</p>
</description>
]]></content:encoded>
<dc:subject>amusement</dc:subject>
<dc:date>2004-05-13T12:50:43-05:00</dc:date>
</item>
<item>
<title>scottrichter422@yahoo.com</title>
<link>http://WWW.cleverhack.com/blog/archives/001269.html</link>
<description>Slashdot had a thread this morning about infamous spammer Scott Richter and his OptInRealBig organization winning a temporary restraining order...</description>
<guid isPermaLink="false">1269@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>Slashdot <a href="http://yro.slashdot.org/article.pl?sid=04/05/12/1226222&mode=thread&tid=111&tid=123&tid=126&tid=95&tid=99">had a thread this morning</a> about <a href="http://www.google.com/search?hl=en&edition=us&q=infamous+spammer+scott+richter&btnG=Google+Search">infamous spammer Scott Richter</a> and his <a href="http://www.spamhaus.org/rokso/listing.lasso?-op=cn&spammer=Scott%20Richter%20-%20OptInRealBig">OptInRealBig organization</a> winning a temporary restraining order against <a href="http://www.spamcop.com">SpamCop</a>.  In fact, Scott Richter is such an infamous spammer that this blog has <a href="http://www.cleverhack.com/blog/archives/000724.html">mentioned him before</a>.  </p>

<p>What made my morning, however, was buried in the Slashdot thread.  Apparently, <a href="http://www.comedycentral.com/mp/play.php?reposid=/multimedia/tds/cord/cord_8121e.html">the Daily Show had interviewed Scott "High Volume Email Deployer" Richter</a> at some point and the resulting video is hilarious.  And his email address was included in the end.  </p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1269" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001269.html#comments" title="Comment on: scottrichter422@yahoo.com">Comments (0)</a></p> 
<p>Comments on this Entry:</p>


</description>
]]></content:encoded>
<dc:subject>spam</dc:subject>
<dc:date>2004-05-12T11:30:38-05:00</dc:date>
</item>
<item>
<title>I think they need some girlfriends</title>
<link>http://WWW.cleverhack.com/blog/archives/001268.html</link>
<description>Host: 12.159.150.10 Url: /ccbill/secure/ccbill.log Http Code : 404 Date: May 11 15:05:49 Http Version: HTTP/1.0&quot; Size in Bytes: 624 Referer:...</description>
<guid isPermaLink="false">1268@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>Host: 12.159.150.10<br />
Url: /ccbill/secure/ccbill.log<br />
Http Code : 404</p>

<p>Date: May 11 15:05:49<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 624</p>

<p>Referer: -<br />
Agent: -</p>

<p>This is an attempt at trying to download a ccbill.log file, which is apparently part of a streaming video management package (i.e. for those subscription only Adult sites) called <a href="http://www.ccbill.com/">ccbill</a>.  What's scary is that I merely typed in ccbill.log on google and the first result was a <a href="http://www.jaddo.net/forums/index.php?showtopic=4242">page which describes how to use the .log file to grab password information</a>.</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1268" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001268.html#comments" title="Comment on: I think they need some girlfriends">Comments (0)</a></p> 
<p>Comments on this Entry:</p>


</description>
]]></content:encoded>
<dc:subject>technology</dc:subject>
<dc:date>2004-05-11T15:30:57-05:00</dc:date>
</item>
<item>
<title>There really is a Googleblog</title>
<link>http://WWW.cleverhack.com/blog/archives/001267.html</link>
<description>Remember the hubbub that erupted when someone found a blank page at www.google.com/blog? Well, it seems as though Evan Williams...</description>
<guid isPermaLink="false">1267@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>Remember the hubbub that erupted when someone found a blank page at <a href="http://www.google.com/blog">www.google.com/blog</a>?  Well, it seems as though <a href="http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&edition=us&q=evan+williams+blogger&btnG=Google+Search">Evan Williams neé Blogger now Google</a> fame really did convince someone at Google to create a <a href="http://www.google.com/googleblog/">Googleblog</a>.<br />
</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1267" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001267.html#comments" title="Comment on: There really is a Googleblog">Comments (0)</a></p> 
<p>Comments on this Entry:</p>


</description>
]]></content:encoded>
<dc:subject>blogosphere</dc:subject>
<dc:date>2004-05-11T11:32:06-05:00</dc:date>
</item>
<item>
<title>Some security concerns about Bluetooth...</title>
<link>http://WWW.cleverhack.com/blog/archives/001266.html</link>
<description>Bluetooth, that wireless networking technology which allows computers, mobile phones and other devices to communicate apparently has some security concerns,...</description>
<guid isPermaLink="false">1266@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p><a href="http://www.bluetooth.com/">Bluetooth</a>, that wireless networking technology which allows computers, mobile phones and other devices to communicate <a href="http://www.infoworld.com/article/04/05/10/HNbluetooth_1.html">apparently has some security concerns</a>, namely <a href="http://www.bluejackq.com/bluesnarfing.asp">bluesnarfing</a> and <a href="http://www.bluejackq.com/howtobluejack.asp">bluejacking</a>.  And don't forget that British pastime of <a href="http://www.wired.com/news/culture/0,1284,62687,00.html">toothing</a>.</p>

<p>Not that I would know, even though I own a spiffy PowerBook running OS X Panther, my wireless provider <a href="http://www.verizonwireless.com:80/b2c/store/controller?item=phoneFirst&action=viewPhoneOverview&sortOption=priceSort">does not offer Bluetooth ready phones</a>.  <br />
</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1266" onclick="OpenTrackback(this.href); return false">TrackBack (0)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001266.html#comments" title="Comment on: Some security concerns about Bluetooth...">Comments (1)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2432">fluffy</a> on 
May 10, 2004 10:08 PM)


Bluejacking is not a security threat, it's just a clever way of pushing out a message to other phones, making it an annoyance at best.

IIRC, Bluesnarfing only affects a few Bluetooth chipsets on the market, such as Nokia's, and even then I believe it requires the device to be set discoverable, which most people don't do.

The 'network security' issues of Bluetooth are way overblown, since the vulnerable devices (i.e. phones) don't act as network devices, and its range is so short that anyone who's able to grab stuff from a device over Bluetooth would theoretically be able to physically access it anyway.  I mean, sure, don't put a Bluetooth dongle on a computer which is tucked away inside a locked cabinet, but I don't think it's really the big security fuss which various "experts" are making it out to be.</p>
</description>
]]></content:encoded>
<dc:subject>technology</dc:subject>
<dc:date>2004-05-10T21:55:50-05:00</dc:date>
</item>
<item>
<title>Spammers doing it by hand....</title>
<link>http://WWW.cleverhack.com/blog/archives/001265.html</link>
<description>Host: 203.115.12.41 Url: /blog/archives/001245.html Http Code : 200 Date: May 10 19:42:06 Http Version: HTTP/1.0&quot; Size in Bytes: 10375 Referer:...</description>
<guid isPermaLink="false">1265@http://WWW.cleverhack.com/blog/</guid>
<content:encoded><![CDATA[<p>Host: 203.115.12.41<br />
Url: /blog/archives/001245.html<br />
Http Code : 200</p>

<p>Date: May 10 19:42:06<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 10375</p>

<p>Referer: http://www.cleverhack.com/blog/archives/001245.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p>------------------------------------------------------------------------------</p>

<p>Host: 64.124.222.172<br />
Url: /blog/archives/001245.html<br />
Http Code : 200</p>

<p>Date: May 10 19:41:49<br />
Http Version: HTTP/1.1"<br />
Size in Bytes: 8505</p>

<p>-----------------------------------------------------------------------------</p>

<p>Host: 217.117.14.167<br />
Url: /blog/archives/001258.html<br />
Http Code : 200</p>

<p>Date: May 10 19:41:45<br />
Http Version: HTTP/1.0"<br />
Size in Bytes: 9985</p>

<p>Referer: http://www.cleverhack.com/blog/archives/001258.html<br />
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)</p>

<p>What you see above are three entries from my logs.  Two are comment spams and the middle entry, sans user agent info, is what I think is a probe.  (My "recent visitors listing" only shows the last page someone requested.)  You see, yesterday, I renamed my mt-comments.cgi file to something more prosaic in hopes of killing off the automated comment spam.  As you can see, that move lasted all of 24 hours, with the spammers apparently probing (the <a href="http://www.dnsstuff.com/tools/whois.ch?ip=64.124.222.172">WHOIS for the probe machine</a>) to find out the new filename.</p>

<p>Anyway, renaming mt-comments.cgi doesn't work.  And aside from IP banning the client machines posting the comment, I can't think of anything more creative to do at the moment.</p></p>
<p>
<a href="http://WWW.cleverhack.com/cgi-bin/mt/mt-tb.cgi?__mode=view&entry_id=1265" onclick="OpenTrackback(this.href); return false">TrackBack (1)</a> | <a href="http://WWW.cleverhack.com/blog/archives/001265.html#comments" title="Comment on: Spammers doing it by hand....">Comments (2)</a></p> 
<p>Comments on this Entry:</p>


<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2434">fluffy</a> on 
May 11, 2004 12:25 PM)


You can always do this, if you don't want to move to  a different comment engine entirely: http://trikuare.cx/mt/archives/000410.php

It doesn't even require moving to PHP, though it's helpful to (since then you're not stuck with a static, easily-discovered key per page).</p>
<p>(<a href="http://WWW.cleverhack.com/cgi-bin/mt/redbow.cgi?__mode=red&amp;id=2437">Paul Kuliniewicz</a> on 
May 12, 2004  4:43 PM)


Even just using the single-static-key version of fluffy's method cuts down on comment spam dramatically.  I've only had a couple of spams get through, and both of those were one-shot affairs and may have been by-hand.</p>
</description>
]]></content:encoded>
<dc:subject>spam</dc:subject>
<dc:date>2004-05-10T20:31:06-05:00</dc:date>
</item>



</channel>
</rss>