Another user-agent to blacklist: “Proxy Gear Pro/2.1”

On 2015-06-01 I saw my first attack using the user agent “Proxy Gear Pro/2.1 (Windows; N; Windows NT 6.1; en)“. The request was “GET http://impuls.name/pgpro/getheaders3.php?test=bf2c347a6b<br /> 8ea868ec3dcbf221e75565&auth=1CBE595CB00AF HTTP/1.1“. A bit of Googling suggests this is software from Russian hackers that can be used to find exploitable HTTP proxies and/or act as a proxy. I’ve added it to my blacklisted user-agent rules: # Block ZmEu and other bots based on their user agent signature.
Read more...

White trash heterosexuals raising children with godly morals

This is what happens when you let heterosexuals raise children. Said by a commenter on the Joe My God blog article about a brawl between two women at a Walmart in Beech Grove, Indiana. The comment is in response to learning that one of the woman instructed her son to: Johnny, punch here in the face! Johnny, punch her in the fucking face! This is the perfect counter-example to all the bigoted xtians who wail about homosexuals being allowed to marry and adopt children.
Read more...

Russian hackers using HTTP proxy requests to attack other sites

You really should disable support for proxying in your web server unless you a) know why you need it enabled, and b) have carefully configured your proxy not to allow arbitrary requests. A new attack I started seeing two days ago illustrates why. Below are the URIs of the first and most recent attack of this sort I’ve seen. I’ve modified the Login values to obscure the accounts being attacked. The malware is attempting to use my server to mask the real source of the attack to verify account credentials.
Read more...

FRC says xtian persecution in Middle East same as in America

Another day, another begging for money email from the Family Research Council. This one asks us to Please Take a Stand for Persecuted Christians In American… and Everywhere! By providing “My Gift to Stand!” (which are links to pages where you can give the FRC money). They continue with Christians overseas are our example. They are being crucified. They are being beheaded. They are being tortured. And yet they refuse to renounce Jesus Christ.
Read more...

How Christians and Atheists respond to (perceived) persecution

Apparently the following image is making the rounds on Facebook: It’s sad that devout followers of a religion (not just Christians but also Jews, Muslims, Hindus, etc.) tend to be so deeply indoctrinated their minds are closed to new evidence. It’s hard to believe that someone cannot even imagine evidence that would change their mind. They have their fingers in their ears and their heads buried in the sand while saying “la-la-la I can’t hear you”.
Read more...

Doctor who filed a SLAPP lawsuit against Dr. Steven Novella and SBM charged with deceptive advertising

Consumer Health Digest #15-21 by Stephen Barrett, M.D. who runs the Quackwatch web site just arrived in my inbox and contained some welcome news: The Medical Board of California has charged Edward L. Tobinick, M.D. with advertising improperly that his clinic offers “revolutionary” and “breakthrough” treatment that can enable patients with strokes, Alzheimer’s disease, and other chronic neurological conditions to improve rapidly—often within a few minutes—after receiving his injections. Tobinick, who operates the Institute of Neurological Recovery (INR), with offices in Boca Raton, Florida and Los Angeles, California, has for many years offered to treat spine-related pain and various neurological conditions with Enbrel (etanercept), a drug that is FDA-approved for other purposes.
Read more...

Movie review: “San Andreas”

“San Andreas” is what I call a summer popcorn movie. Something very different from the art house fare I usually watch (e.g., “Far From the Madding Crowd“). That was reflected in the audience which included a man who fiddled with his phone, making no attempt to shield the screen, at least eight times throughout the film. He was close enough to be annoying but far enough away that I couldn’t discreetly tell him to stop being a self-centered asshole.
Read more...

Malware attacking the WordPress Download Manager plugin

I’ve seen three attempts to exploit the WordPress Download Manager plugin in the past couple of days and forty since I saw the first one on 2015-02-06. Not a huge number which is why it escaped my attention until now when I saw several attacks in a short interval. The signature is a “POST /” request with payloads like the following (these are from the most recent attacks): action=wpdm_ajax_call&user_login=admin-jonns&execute=wp_insert_user&role=administrator&user_pass=1213141516 action=wpdm_ajax_call&user_login=userdemo&execute=wp_insert_user&role=administrator&user_pass=demopassword action=wpdm_ajax_call&user_login=uLIr2a&execute=wp_insert_user&role=administrator&user_pass=c3oTzz This article at blog.
Read more...

New malware user-agent value: “Jorgee”

Update 2015-09-09: I’ve seen a huge increase in people reading this article in the past two days. Checking my logs I see that my server was attacked again by the “Jorgee” malware yesterday. The previous attack was almost exactly three months ago (specifically 2015-06-03). The latest attack was from a personal computer in Brasil with a gvt.net.br domain name. The attack signature appears to be identical to earlier attacks. As I say below the smart thing to do is explicitly disallow proxying and blacklist any source trying to use your server as a proxy.
Read more...

Hosting provider Aventice.com lets their clients attack other computers

Immediately after posting the article below I emailed this to the Aventice abuse team: You're clearly trying to balance the needs of the Internet as a whole while not pissing off your customers. But your VPN customer in this case is clueless. The right thing to do is to not blacklist my server so that you and your customer stop hearing unpleasant news. You and your VPN customer should continue to accept attack reports and deal with each one to minimize the harm to the Internet as a whole.
Read more...