I Love These Lights

Filed under:9/11 — posted by Anwyn on September 4, 2009 @ 11:09 pm

But that fact notwithstanding, it’s shameful that eight years after the fact, we still have only lights. It is dishonorable to those who were killed and to the governing bodies involved that they have not yet been able to agree on an appropriate plan and build it. On the other hand, I’d rather we have lights forever than have anything that smacks of either submission, guilt, or shame-facedness. I still have a soft spot for the new WTC 7:

Drat

Filed under:Television — posted by Anwyn on September 3, 2009 @ 5:05 pm

I hoped when I quit watching Smallville that I wouldn’t have to watch Kristin Kreuk make Concerned Frowny Faces any more.

Alas. Run, Chuck, save yourself!

Message Problem

Filed under:Mothering,Politics — posted by Anwyn on September 2, 2009 @ 10:02 pm

So the president will address schoolchildren at noon on Tuesday, Sept. 8.

Let me stipulate up front that my child doesn’t start school till Wednesday, Sept. 9, by the scheduling of the school and not by me keeping him home. Which raises the question of whether or not his kindergarten teacher will record the speech and show it once school starts.

I’ve read a lot of opinions, from (I think) childless AP and Ace to Mama Venom and Daddy Vodka–one “Keep your kids home,” one “Really?” one “Yeah, I can sorta see that,” one “Pick your battles,” and Keep-’em-home Vodka’s follow-up answer to AP.

As Vodkapundit agrees in that last link, the problem is probably not the probably-pap speech itself. The problem is twofold: 1) The arrogance inherent in the president declaring himself the teacher for the time being and 2) The smacking–even if it is just a smacking without substance–of the Little Octobrists. This is not the Presidential Physical Fitness Award, with an impersonal established award for any student meeting the stated criteria. Obama doesn’t establish much, as a matter of fact, that he doesn’t then have to backtrack on, as the administration has already done once on this here speech. But what he does establish, or attempt to establish, is statist all the way. If the president really just wants to send a personal message to students to work hard and stay in school, that’s one thing, but when heavy statism is all you’ve shown yourself willing to sell, why should you be surprised when parents don’t like even the bare possibility of it being sold to their kids behind their backs?

And why does the president believe anybody’s kids need his personal message, even if it is just about staying in school and working hard? I think there’s a lot of merit to Kate’s point that if you make a big deal, the kids will make a bigger deal of it in their minds than you otherwise would. Fortunately I do not have to choose whether the Bean will hear the president in school or not … this year. Like so many things about statism, though, this could be, or try to be, the thin end of a wedge. And, as always, I can’t help but picture the outrage had Bush put an address into schools, something he did not do even right after 9-11. He did not appoint himself our children’s personal grief counselor. The president is not our kids’ teacher or nanny, either.

And: Nice Deb goes fairly nuclear.

And also: What I’m trying to say is that in this case, the message might well be the messenger himself. The essential fact that the president puts an address into the schools sends a message of statism, whatever the speech itself does or doesn’t say–that children should work hard because the president says so. That’s not why they should, and they shouldn’t be taught otherwise.

Mildly Stated Uplifting Dose of Pure Awesome

Filed under:Uncategorized — posted by Anwyn on August 24, 2009 @ 9:28 pm

Or, stretching of fair use:

So our new president wanted a fundamental overhaul of the health-care system—17% of our GDP—without a serious debate, and without “loud voices.” It is akin to government by emergency decrees. How dare those townhallers (the voters) heckle Arlen Specter! Americans eager to rein in this runaway populism were now guilty of lèse-majesté by talking back to the political class. …

At no time had Ronald Reagan believed that the American covenant had failed, that America should apologize for itself in the world beyond its shores. There was no narcissism in Reagan. It was stirring that the man who headed into the sunset of his life would bid his country farewell by reminding it that its best days were yet to come.

In contrast, there is joylessness in Mr. Obama. He is a scold, the “Yes we can!” mantra is shallow, and at any rate, it is about the coming to power of a man, and a political class, invested in its own sense of smarts and wisdom, and its right to alter the social contract of the land.

My boy Allah knows how to pick ’em. Definitely read the whole thing.

Don’t Fall For It

Filed under:Not Cool,Politics,Priorities — posted by Anwyn on August 16, 2009 @ 10:14 pm

So now that it looks like the public “option” is dying, those of us who want the government to stay out of our purchasing and consumption of medical treatment can breathe a sigh of relief, right? Don’t believe it. They will next try to pass some watered-down piece of garbage that is still garbage, probably at the very least to include mandated health insurance. And doesn’t that look like fun? And if they pass that and it’s a boondoggle, they’ll point to it to say “See! That’s why we need the government to run it!” The camel’s nose under the tent.

I don’t understand why I’ve only seen one post anywhere that even mentions the real problem and points the way to a perfectly workable, even fairly cheap, solution: cut the tie between employment and health insurance. How many people even know what that tie is–the reason why most people get medical insurance from their employers? It’s because when you buy it that way, it’s bought with pretax dollars, whereas if you buy it yourself, it’s posttax. So your company is paying some money in on your behalf instead of paying it to you as wages, it doesn’t get taxed, and you kick in the rest off your paycheck, pretax as well. So who do the insurance companies market their plans to? Your employer, who wants to get a great plan that pays for everything that it can hold up as a swell “benefit” of coming to work for them. I’d rather have more money and buy cheap insurance myself–catastrophe-only insurance that would pay if I had to be hospitalized or needed ongoing treatment for a serious illness but that would let me pony up on my own when I go to see my doctor about that damned itchy eczema on my elbow or take my son to his doctor because he bonked his head even though there’s obviously absolutely nothing wrong with him.

Sever the link via changes in the tax law. Either lay the income tax on all money that pays for medical insurance, or take it off of all of it–one seemingly simple way to do that might be to have your insurance company send you a tax form in February, like a W-2, that lists the total of all money you’ve paid in insurance premiums that year, and you file that with your tax return and the amount is deducted from your taxable income. Then insurance companies would have to market their plans to individuals, not corporations, and suddenly paying $600 per month or whatever it is for a small family to go to the doctor a total of seven times in a year doesn’t look so damn good, does it? Buy yourself some cheap catastrophe-only insurance with a high deductible, and wham, you’ve just “lowered your costs.” And the real cost of an actual doctor’s visit would come down too, since the docs would be so happy to have patients who pay cash on delivery rather than cutting through eight layers, minimum, of red tape to get paid less than they charge. You think doctors and hospitals don’t inflate charges because they know the insurance companies won’t pay at that rate anyway? I don’t think that.

I’m no expert in any of these fields; I’ve just been watching what’s going on for a long time and watching Obama attempt to push us off the cliff of socialism. IF they can’t pass socialized medicine, they’ll pass something lesser and expect us to wipe our foreheads and give thanks that we dodged the bullet, Comrade. Don’t do it. Don’t blink. Stand firm and insist that instead of more regulation, they take regulation away. Strip out the tax irregularity that incentivizes employers to “pay” for our medical insurance instead of paying us and letting us get our own. Medical insurance never should have come to this pass; it should be like car insurance, which would never pay to take the car in for an oil change. Deregulate medical insurance and I got your costs savings right here.

“Have You Got Anything Without Spam?”

Filed under:Blogging — posted by Anwyn on July 14, 2009 @ 9:53 am

A Guest Post by Spam Killer Daddyman

Spam is usually very straightforward to manage in WordPress blogs. Almost all of it arrives in the form of comments and is quickly (we hope!) dispatched by the admin (either manually or by her spam filter). Some spammers are more devious, exploiting security holes in WordPress or mysql to embed their nastiness directly within the blog.

This blog recently began to show spam in its RSS feed. Interestingly enough, the spam didn’t show up when viewing the feed directly–only when viewing it through a reader like My Yahoo! or Google Reader. The blog had clearly been infected by some sort of malware.

RSS feeds typically deliver a short summary of WordPress posts, either inline (as in Google Reader) or when you hover the cursor over a link (as in My Yahoo!). The symptoms of this particular malware infection are that only the most recent post contains any summary text at all, and rather than displaying an article summary, it recommends the reader “Buy Aristocort…” or some other nonsense.

We searched through the WordPress files and mysql database but found no trace of the spam. We updated WordPress to the latest version, but still the spam persisted. (Anwyn aside: Therefore, the problem had to be in files that were not updated–either in the WP theme files or in the mysql database itself. Gulp.)

After quite some time of sifting through a mysqldump, I finally stumbled across something suspicious in the wp_options table: a string, hundreds of characters long, that looked like a data dump of some kind. The epiphany came when I saw the following characters toward the end of the string:

[…]cfJ3byJXZ”(edoced_46esab(lave[…]

Alter your perception a bit and read that string backwards:

[…]eval(base64_decode(“ZXJyb3Jfc[…]

This is php code. Base64 is a conversion format commonly used to send binary attachments via email. It’s also a great way to hide malicious code. I’ve seen trojans use it before, but I’ve never seen it coded backwards.

Decoding this, we discovered the php code that has been affecting the RSS feed. We also found other bits that were monitoring cookies, collecting system information and other dangerous things like login information.

So how does this backwards code get executed? Well, the answer to that lies in the Akismet plugin directory. In a file named .akismet.cache_< date >.php, there was code with a strrev() function. This instructs the code in the database to reverse itself and become readable. It appears, although I can’t tell definitively without fully deconstructing the code, that this malware leverages the Akismet spam-filter plugin to do its dirty work. I’m sure the author took great pleasure in that.

Why is this only seen in things like Google Reader and My Yahoo? It turns out there’s a regular expression match done for key sites:

if(preg_match(“/bot|google|slurp|bing|msn|charlotte|crawl|yahoo|search|spider|inktomi|ask|alexa|seek/”,$_SERVER[“HTTP_USER_AGENT”])&&sizeof($_COOKIE)==0){

(Anwyn aside: In addition to the RSS readers, the Googlebot also sees the damaged code. Thus when I advance-googled for “aristocort” only on my site, Google turned up page after page that it said had that word–but if you clicked on a link, you got an entire category page where, of course, there was no mention of the spam words. Clever.)

Cleanup Procedure

If you’re seeing spam in your WordPress blog’s RSS feed and you have any dotfiles in your Akismet plugins directory (.akismet.cache.php, .akismet.cache_< date >.php, etc), then you’re probably suffering the same affliction as this blog. The fix:

1. Back up your WordPress files. This is just to be on the safe side.

2. Back up your WordPress Database. Again, just to be on the safe side.

3. [Disclaimer by Anwyn: We didn’t actually install Akismet on any other blog to double-check that the following affected files were not normally present in a healthy Akismet install. We just nuked them from orbit, and my blog and spam filter do not seem to be suffering. However, if you have more than one of these suspect files, you might want to search each of them for this string: strrev. This is the dangerous command and thus the dirty file. Daddyman googled for these kinds of files related to Akismet and found nothing normal–only warnings of spam exploitation–so you’re probably safe to delete them all, but we don’t know with 100 percent certainty.) Clean up WordPress by deleting any akismet dotfiles (.akismet.*) in the wp-content/plugins/akismet folder.

4. Clean up the database by removing all affected wp_options lines. The easiest way to do this is with phpmyadmin. Select your database, browse the wp_options table, and look for rows that have an option name of rss_< something >. Do not delete any of the following rows: rss_excerpt_length, rss_use_excerpt, rss_language. Delete any rows which have an option_name of rss_< long string of numbers and letters (hexadecimal) >. For example, in our installation an entry beginning with “rss_f541…” contained the base64_decode() string. You can delete any rows that have a name with a similar format, whether or not you see obviously malicious code; it will not harm your RSS.

5. Create a new post and verify that your RSS feed is now displaying correctly. Google Reader does a good job of refreshing on demand. The My Yahoo homepage doesn’t refresh promptly even if you select the refresh option, so you may need to wait a while before getting confirmation there.

6. Delete cookies in the browser(s) which you use to administer your site. This is just to be safe.

7. Change your WordPress password! You may also want to change your main database password. If you do that, be sure to also update it in wp-config.php.

8. Enjoy a spam-free, fully functional RSS service!

Staying Spam-Free

Here are two maintenance steps to help keep your blog clean and performing well:

1. Harden your WordPress installation! An ounce of prevention is worth a pound of cure.

2. Periodically purge spam comments from your database. When you classify a comment as spam, it disappears from sight, but the actual data remains in your database. In the case of this blog, which has been up for several years, 75 percent of the database (or about 9MB) was old spam comments. (Anwyn aside: Good Lord.) A simple sql command, run periodically, will remove all of that cruft and help optimize your database. The sql magic can be run either from phpMyAdmin or directly via the mysql CLI. Just connect to your database and execute the following statement:

delete from wp_comments where comment_approved=”spam”;

There are also some WordPress plugins, such as “Delete Spam Daily,” which profess to make this an even simpler process. I haven’t tried them, so be careful.

–Daddyman

(Anwyn aside: I hadn’t updated WordPress since it was first installed on this host, years ago. If I had, no doubt whatever back door the spammers came in through would have been eliminated.)

The Next Top Post

Filed under:Blogging — posted by Anwyn on July 12, 2009 @ 8:42 am

Another test. We’ve deleted what we think is reams of nasty code directly out of my database. If Daddyman really has cracked this problem, he might be able to document it for people like him who googled and found only that “yes, this problem exists, what’s happening here?” but no answers.

NASTY code, people. Reams of it. You better not be seeing any more of it on the feed to this post. Let me know …

Test Post

Filed under:Blogging — posted by Anwyn on July 11, 2009 @ 10:55 pm

Be vewy, vewy quiet. I’m hunting spammers.

How’s the Feed?

Filed under:Blogging — posted by Anwyn @ 10:21 pm

Still bad? Still spammy? I upgraded to WP 2.8.1 tonight (chorus of angels sings HA-LE-LU-JAH) and we seem to have at least a remnant of the old RSS problem. Sing out if you typically view my RSS feed and are seeing spam in it. Kthxbai.

Maybe the Hot, Dry Summers Here Are Just Training for Texas

Filed under:Politics,Priorities — posted by Anwyn on July 1, 2009 @ 7:56 pm

It sure sounds like a nice place to live.

Happy Birthday to Xrlq

Filed under:Cool — posted by Anwyn on June 29, 2009 @ 8:14 pm

A bit late in the day, but with warmest birthday good wishes.

Allah Getting Huge Kick Out of Baiting at Least Two-Thirds of His Readers

Filed under:Ew,Jerks,Not Cool,Politics,Uncategorized — posted by Anwyn on June 24, 2009 @ 5:24 pm

The third that hates Huckabee with a fiery passion and the third that loves him with a … fiery white passion. Don’t mess with me, punk.

Get Divorced First, Idiots

Filed under:Good Grief,Not Cool,Politics,Priorities — posted by Anwyn @ 3:11 pm

How hard is this crap? Get divorced before you send love emails to the new chick. Get divorced before you fly off for four days and turn off your state cell phone. This man had a few thoughts of running for president? We can take a divorced president, champ. We can’t take a stupid one–even though for a lot of voters, it takes a lot to prove stupidity. You chose the fastest route. Congratulations, Mark Sanford, you get–new love. Hope it was worth it.


previous page · next page


image: detail of installation by Bronwyn Lace