Stimulants For Your Meaty Carrot

This post is over 14 years old and may contain information that is incorrect, outdated, or no longer relevant.
My views and opinions can change, and those that are expressed in this post may not necessarily reflect the ones I hold today.
 

Have you ever wondered how your email provider determines what email is spam and what isn’t?

If you haven’t Googled it and figured out already, here’s the easy and basic answer: each email goes through a filter that applies a handful of checks on the email. If the email fails to pass a particular check, it earns points. If the email accrues a particular number of points or more, it gets sent to the Spam folder.

For example, if the email subject is in all capital letters, it will get some points. If the email subject has more than one exclamation point in it, it might get a few more points. If the email was delivered from a domain name that is historically known to send spam, it will get a lot of points. If it has particular keywords in it, it will get points depending on how common the particular keyword is in spam emails.

If you haven’t noticed already, a very frequent spam email that many people receive is third-party advertisements for Viagra. Unfortunately for the spammers, most email providers have identified this spam and have become very good at identifying Viagra advertisements. So, the spammers have to be­come creative.

For example, instead of calling the drug Viagra, they might call it V1agra or Vi@gr@. They might not even call it Viagra at all, and just call it "male enhancement supplements."

Yesterday, I got an email with a subject line that I think is so far the most creative subject for selling Viagra: "Buy stimulants for your meaty carrot."

I’m not sure if that is an epic win or an epic fail.

 

—§—

 

Tuna Water Bottle

This post is over 14 years old and may contain information that is incorrect, outdated, or no longer relevant.
My views and opinions can change, and those that are expressed in this post may not necessarily reflect the ones I hold today.
 

A few days ago while I was at the Badger Herald office working, I went next door to a sandwich shop to get some dinner. After ordering, I went over to the receiving counter and noticed a water bottle with a piece of tape on it with "TUNA" written on it.

It boggled me so much that I decided to take a picture of it.

Tuna Water Bottle

In other news, I took my last quiz in my sociological theory course today, and I’m almost done with the class. Normally, lecture would have met again this Wednesday, but because the instructor is traveling for a job interview, he canceled our last class and finished everything up today. Now, the only thing I have left to do for the class is to finish a paper by 4 PM on Friday.

 

—§—

 

Applying to Medical School Fail

This post is over 14 years old and may contain information that is incorrect, outdated, or no longer relevant.
My views and opinions can change, and those that are expressed in this post may not necessarily reflect the ones I hold today.
 

While I was going through my camera today, I came across this picture that I took this past Thursday of a worksheet I got during my statistics for psychologists course.

Regression

It was a worksheet containing data that our professor gave us so we can use it during lecture to go over regression. It was data from applications submitted to medical school, and each applicant’s corresponding MCAT score, GPA, score on letters of recommendation, and score on judgment.

"The point of doing this is to predict the chances of each applicant being accepted into medical school based on the predictors. So this first applicant had an MCAT score 582, a GPA of 1.9, a recommendation letter sco … wait, a GPA of 1.9? What is this person doing applying to medical school?"

 

—§—

 

I Got Hacked

This post is over 14 years old and may contain information that is incorrect, outdated, or no longer relevant.
My views and opinions can change, and those that are expressed in this post may not necessarily reflect the ones I hold today.
 

If you visited my website earlier today, you might have noticed that it was hacked for a short period of time. Fortunately, I received a few emails letting me know, and I was able to investigate the situation immediately and get everything repaired within a few hours of the attack.

For those of you who missed it, all the content on my website was removed and replaced by the fol­low­ing message:

I did some thorough detective work with my friend who owns my website’s hosting company to find out exactly how this happened. One thing I immediately noticed was that all the pages of my website were being forwarded to a suspension page. After seeing this, I had a good feeling that it wasn’t me or my website that got directly hacked, but this was a result of my website’s host getting hacked.

Basically, what the hacker did was hack That Hosting and suspended all the accounts on the server. Then, the hacker set the suspension page to the message above, so it would look as if the hacker was able to hack every single website on the server individually. Once I figured this out, I knew that it would be an easy solution – just log in to the administrative control panel and unsuspend my account. Un­for­tunately, the hacker changed my password and the email address associated with it, so I wasn’t able to log in as an administrator.

I texted my friend, and after a short while, we managed to get everything sorted out and working back to normal. While my friend tried to figure out who the hacker was, I was more concerned about how the hacker gained access to That Hosting, so I traced recent activity on the server to find out what the hacker did. After a little bit of sniffing around, I was able to figure out exactly what the hacker did.

First, the hacker used a security flaw in Web Host Manager Complete Solution (WHMCS) to inject PHP code into our server via the support ticket system. For whatever reason, WHMCS thought it would be a good idea to let people use {php} to start PHP parsing in their ticket. The hacker injected an extremely long chunk of PHP code; a sample of what it looks like is shown below.

Once the support ticket was submitted, the injected code ran on the server and started creating files. When it was done executing, it sent a confirmation to the hacker with the following message:

The hacker could then navigate to the file specified in the confirmation message to find a file that would allow shell access via CGI. The hacker would log in with the password provided in the confirmation message.

Once logged in, the hacker would have complete access to the web server and be able to run any commands as desired. For those of you more familiar with Windows operating systems, this is basically like opening a command prompt and being able to type in whatever you want.

To demonstrate that this works, I ran a command to delete the xa7m3d.evil file (which was the CGI-Telnet file). After I submitted the command, no error messages appeared, which most likely means that the file was successfully deleted.

To confirm that the file was deleted, I refreshed the page, and got a 404 (file not found) error.

Thus, I was able to verify that the commands entered into this program ran successfully and the hacker could do whatever (s)he wanted with the server as long as (s)he knew what the proper commands to use were.

So what was I able to conclude from this? It’s clear that the hacker group 10:01 aren’t really hackers, but a bunch of people who search the Internet for programs and instructions they can use to hack other people. The only real hacker here is xa7m3d, who coded the actual tool and identified the PHP injection method that 10:01 used to hack into That Hosting.

So before you go around being a script kiddie and hack people’s websites, make sure that you only hack unexperienced people, because if you hack someone like me, I’ll call you out on my blog, explain exactly how pathetic you are, and tarnish your reputation.

 

—§—

 

One Final Exam Down, Three to Go

This post is over 14 years old and may contain information that is incorrect, outdated, or no longer relevant.
My views and opinions can change, and those that are expressed in this post may not necessarily reflect the ones I hold today.
 

Today was my last day of Music in Performance, and I took my first of four final exams.

Music in Performance is basically a class where you go to a concert hall, listen to people perform a variety of different music, and answer five easy quiz questions to get credit for attending the performance. Then, at the end of the semester, you take a final exam that asks questions about the composers performed during the semester and their style of music and time period of activity.

A slightly annoying part about the exam was that we had to memorize the countries of origin of all the composers, which took a decent amount of effort, but fortunately, we were given the information to memorize rather than having to research it ourselves, so it wasn’t that huge of a deal.

In other news, next week is the last week of the semester and I have two exams on Tuesday and Thursday, so I’m going to go study now.

 

—§—

 

Facebook Comment turned Epic Novel

This post is over 14 years old and may contain information that is incorrect, outdated, or no longer relevant.
My views and opinions can change, and those that are expressed in this post may not necessarily reflect the ones I hold today.
 

During my sociological enterprise lecture today, I think I sat next to a girl who might have set the world record for spending the most time writing a single Facebook message.

She started writing it at 12:59 PM, one minute before lecture started. She continued on until 1:22 PM when she finally hit Enter and posted the novel-like comment.

It was very distracting.

 

The Daily Shoot Assignment of the Day

#DS573: Make a photograph emphasizing a square or a grid today. (Assigned June 11, 2011.)

Keyboard Numpad

It always amazes me to see how well my camera can pick up on the dust particles covering all of my be­longings.

 

—§—