Diary of a Network Geek

The trials and tribulations of a Certified Novell Engineer who's been stranded in Houston, Texas.

9/23/2011

Gadget Trak Really Works!

Filed under: Art,Fun,News and Current Events — Posted by the Network Geek during the Hour of the Sheep which is mid-afternoon or 3:45 pm for you boring, normal people.
The moon is a Full Moon

Ever lost a camera?

And, by “lost”, I mean, has your camera ever been stolen?  Well, Gadget Trak can help.  And, now we know that it’s not an empty claim!
I’ve mentioned other camera tackers before, but Gadget Trak’s stolen camera finder has been verified by a photographer who used it to recover his camera.

The photographer is a pro by the name of John Heller who “lost” $9,000 worth of equipment he needs to pursue his livelihood while on assignment in California.  He used the tool to find other photos on the internet that had been taken with his stolen camera.  That led him to another pro who had unwittingly bought the stolen camera.  The L.A. Police are still investigating the people from whom the stolen camera was bought, but what really matters is that Mr. Heller has gotten his gear back!

And, yes, that is a free service they offer.  Because, hey, on a Friday am I going to try to sell you something?  Of course not!
Y’all have a great weekend!

9/14/2011

Finally, A Cure For This Disease

Filed under: Deep Thoughts,Life, the Universe, and Everything,News and Current Events,Personal — Posted by the Network Geek during the Hour of the Rooster which is in the early evening or 6:43 pm for you boring, normal people.
The moon is a Full Moon

No, seriously!

It seems that there’s an new, experimental, gene therapy that may cure cancer.  At least, for two of three test subjects, it cured advanced chronic lymphocytic leukemia.  That’s a type of cancer, incidentally, very similar to the diffuse large B-cell lymphoma that I was diagnosed as having back in 2007.  You can read the full story over at the New York Times, but, here’s the rundown in brief.
The researchers took regular, virus-and-tumor-fighting T-cells from the patients and added specially tailored genes to them which let the T-cells target the cancer cells.  Then, they “dripped” the altered T-cells back into the patients, who had already exhausted all other treatment options, including chemotherapy and bone-marrow transplants.  Ten days later, the first patient got the chills.  And his temperature spiked while his blood pressure dropped.  The doctors moved him to an intensive care unit, not quite sure what was happening to him.  A few weeks later, all his symptoms were gone.  And so was the leukemia.  He was normal.

Granted, there have only been three test cases, including the one I just described, with varying results, but two out of the three had an apparently complete cure of their cancer.  For most of us who have had cancer of any kind, those are pretty damn good odds.  They’re odds that I’d take, should I have cancer again, that’s for sure.
And, frankly, it all sounds like a miracle, like science-fiction come true.

When I was getting chemotherapy, I ordered a t-shirt, really without thinking too much about it.  It was a joke, about the future and how we were promised jetpacks and how the futurists lied to us.  But, when it arrived, I read it more closely.  Here’s what it said:
“they lied to us
this was supposed to be the future
where is my jetpack,
where is my robotic companion,
where is my dinner in pill form,
where is my hydrogen fueled automobile,
where is my nuclear-powered levitating home,
where is my cure for this disease
Well, it looks like the future is now.
Thank God.

 

9/12/2011

Another Year’s Reprieve

Filed under: Advice from your Uncle Jim,Bavarian Death Cake of Love,Deep Thoughts,Life, the Universe, and Everything,News and Current Events,Personal — Posted by the Network Geek during the Hour of the Monkey which is in the late afternoon or 5:20 pm for you boring, normal people.
The moon is a Full Moon

I’m not going to die.

Well, at least, I’m not going to die of cancer.  Not this year, anyway.
Today, the oncologist told me my lymphoma is in full remission still.  In fact, the scar tissue has shrunk even more, from 14cm to 11cm, which I think is kind of amazing, but didn’t seem to illicit any special notice from the doctor.  Some people are just impossible to please, I guess!
He was a little worried because my blood pressure was high, but, then again, I’d just driven though rush-hour traffic to wait around for more than an hour for results on whether or not I was going to have to let them poison me for another six months.  All things considered, I think it’s pretty normal that I might have a slightly elevated BP!  But, I will keep an eye on it and make sure it normalizes again.
He did say, also, that I’ve made it to the point where less than 10% of the people have a likely recurrence of lymphoma.  And, according to his Physician’s Assistant, the five-year mark is where I can be officially considered “cured”, which is the first time anyone has actually told me that.  Everyone else keeps telling me that I’ll never really be “cured”, per se, but always in remission with a smaller, and smaller, and smaller chance of reoccurence every year.  So, today, I got a little more hope than I had before, which is actually pretty nice.

All in all, a pretty good result.  I’ll go back in another 10 months for another scan, which is not quite as long as I’d like, but, better than going again sooner because they found something to be concerned about.  At that time, they will start me on a course of annual visits for this scan, which I’m not incredibly happy about, but will do until a better option comes along.  And, based on what his PA told me, I think it will be something negotiable.  The doctor may not realize that, but, well, I suspect he’s not quite used to dealing with a patient like me.  My last doctor and I joked about the fact that I wouldn’t pay my bills until I knew she was going to do her job and save my life.  We agreed that it seemed only fair!  Of course, she did, in fact, save my life, so I did pay those bills.  That is, however, one concern I have for the long-term; paying those bills.  This gets to be a pretty expensive process and if I don’t really need to keep doing it every year, I may chose to opt for a slightly modified plan.
The doctor may not be excited by that, but I have ten months to sharpen my bargaining skills, while he’s completely in the dark about my plans.  It’ll be interesting to see how that turns out!

Until then, though, I continue to work on my general health and wellness.  I was pleasantly surprised to weigh in at a mere 216, fully clothed and laden down with my ridiculous “daily carry” of keys and flash drives and over-stuffed wallet and all the other pocket litter, as the spies call it, that I usually have on me.  As I mentioned, my blood pressure was a bit high, but I’ll work on that.  A little Zen meditation, and maybe some yoga, ought to bring that under control again.
Oh, don’t be so shocked by the yoga!  No, I haven’t started doing it yet, but several people have suggested it and I decided to start looking into it.  I’m getting older and starting to tighten up some.  My knees in particular seem to get stiffer faster than they did.  Besides, I hear yoga class is a great place to meet women who are physically fit!

I do still struggle a bit with depression.  Nothing too bad, but, well, it is something that cycles around on a semi-regular basis.  I figure the yoga and meditation would help with that, too.  Speaking about my psychological well-being…
My oncologist tells me I should get married.  I thought it might be better to start with dating, but I’m pretty sure I can work the “doctor’s orders” into a decent and semi-original opening line.  I think a bit of laughing in the face of death might help some, too.  I hear chicks dig that.  Of course, I also hear that magnets can cure joint pain and people pay huge money for the kind of rough treatment my poor colon got last week for “health reasons”.  Frankly, I find it hard to believe that a regular course of high colonics could possible be good for me, so I’ll take the things Men’s Health tells me about women with a grain of salt.  (Though, I have started to edit my Match.com profile again in preparation for stepping out in the wild world of dating again.  Seriously.  Lock up your daughters!  Seriously!)

So, yeah, after all my angst last week about the physical side-effects of chemotherapy, I’ve been spared that.  I even got better than expected news, frankly!  So, I admit, I do feel a bit foolish for getting so worked up about it.  I mean, I should have more faith than that, shouldn’t I?  Well, that’s something else I’m still working on.
Thankfully, it seems I have the time.

 


Advice from your Uncle Jim:
"Nobody has ever expected me to be President."
   --Abraham Lincoln

9/5/2011

In Search of Schrödinger’s Tumor

Filed under: Advice from your Uncle Jim,Deep Thoughts,Life, the Universe, and Everything,News and Current Events,Personal — Posted by the Network Geek during the Hour of the Hare which is in the early morning or 7:52 am for you boring, normal people.
The moon is a Full Moon

I may, or may not, have cancer.

Now, before all my regular readers and, due to my automated update configurations, my Twitter and Facebook friends who might read this, get too excited, nothing has changed in my recent medical status.  However, Wednesday, I go in for a scan.  A regular scan, nothing special, nothing new.  My scheduled, nine-month scan, per the standard protocol.  Or so I have been lead to believe.

The scan, however routine it may be, will not decide if I have cancer, however.
That, I’m afraid, already is.  Or is not.  Either my body has betrayed me again and a cancerous growth has lodged itself in my chest or it hasn’t and I’m as healthy as I feel.  Personally, I’m inclined to think that I’m cancer free, still, and this whole exercise will be a test of the quality of my health insurance.  But, also, as it turns out, it’s a test of my patience and courage.

You have to understand, I’m not afraid of cancer.  Or of death, either, really.  It’s chemotherapy that terrifies me.
Cancer, as such, is just a way of describing cells that have gotten a bit carried away with themselves and aren’t too particular about playing by the standard set of rules.  And death…  Well, death is the one thing we all have in common.  None of us make it out of this place alive.  Not a one.  Death, in its way, is the final answer.  The ultimate solution to every problem I’ve ever had or can ever conceive of having.  So, no, though I don’t know what waits on the other side of that particular experience, death doesn’t frighten me so much.
Chemotherapy, on the other hand, I do know.  It is, I think, the embodiment of suffering.  At least, for me.

I know everyone’s experience with chemotherapy is different, so, let me take a moment and tell you why it is that I fear it.  For me, chemo was about losing all my hair, all my color, close to sixty pounds, and virtually all my energy.  And, frankly, in a very, very short amount of time.
My hair went first.  I remember it coming out in clumps in the shower.  Just like in the movies.  I started to cry when it happened.  Great racking sobs, with tears running down my face, mixing with the soapy water.  No one can see you crying in the shower.  I recommend it, if you have any crying to do in the future and you’d rather people not know.  It’s one of the many useful things I’ve learned from one of my ex’s.  I took my beard trimmer and cranked it down to the shortest setting, then sheared the rest away myself.  My own way of taking a bit of control back, I suppose.  But, I remember that day, more than four years ago, as if it were yesterday.  A few days later, I shaved for the last time in what would turn out to be more than six months.
My eyebrows and ear hair and nose hair weren’t far behind.  You have no idea how important nose hair is until you don’t have any.  Trust me.  My nose ran for weeks and weeks and weeks.  Nonstop.  All those annoying, little hairs filter the nasty gunk out of the air and grip it with that snotty mucous up in there and keep it from getting into your lungs, as it turns out.  Without it, well, your nose just runs and runs and runs like a little kid with a cold on a Winter playground.

The weight and the color took longer.  By the time I was an unhealthy, pallid gray, my goatee had become so thin that I shaved it off.  And, I was a larval, grub-like thing, pale and weak, before the weight started to melt off me.
Frankly, I wouldn’t have minded the weight loss, but it took muscle as much as it took the fat.  And, of course, it involved severe nausea and, yes, actual vomiting.  Not to mention all the other symptoms, like how everything smelled different; how all my favorite food smelled, well, wrong somehow.  And the weird bloating I would get in my hands and arms that led the doctors to proscribe diuretics and force the poor nurses to record how much I peed, by volume.  I was measured and weighed regularly.  Multiple times per day, actually.  Oh, and the drugs!  Pills by the score, a fist-full at a time.  Self-administered injections three times a day, at one point.  All while fighting nausea and trying to find a square inch of flesh that I could still pinch up enough to get a needle into without going all the way through.

Death would have been easier.

But, as a wise, Zen-Catholic almost-monk reminded me recently, without fear, there can be no bravery.
He also reminded me that the test will only show what is, or is not, already there.  It will only tell me if I have just another problem to deal with, or another opportunity to exercise my courage, or, simply, a bill to pay and just another doctor’s appointment to go to and questions to ask and answer.
And, either way, all I can do is live in the present moment.  What’s happened is done already.  What happens in the future is yet to be determined and may not have anything to do with what has come before.  And, regardless of the results of this scan on Wednesday, which I’ll get on the following Monday, I can only live as best I can, as best I know how.  There will, ultimately, be other scans, other tests, potentially one every year until the day I do, finally, make the last great leap into the dark.  In between those scans, however many there may be, I slowly, gradually, have chosen to live healthier.  The past couple years, I’ve been juicing.  Fresh, home-made, organic vegetable juice.  And, this year, fruit smoothies.  Both, or either, instead of sandwiches for lunch, along with yogurt, which has lately been organic as well, and, newest of all, Greek for the higher protein.
I exercise more regularly than ever.  I’d like to be less heavy than I am, or at least less fat.  Pound for pound, more muscular would be just fine at my weight.  Less stiff and less creaky in the joints would be okay, too.  Some mornings when I get up, I sound very much like a bowl of Rice Krispies my joints snap, crackle and pop so much.  Several people have suggested that I add yoga to my exercise regimen, that it would help with flexibility and ease my stiff joints.  And, when I hear a thing three times, from three very different people, I have to at least investigate that or risk the Universe taking offense at my willfully ignoring the suggestion.  So, this conservative, meat-and-potatoes, tough-minded, mostly pragmatic Mid-Westerner has found himself a bit adrift in Texas, more liberal and open-minded toward alternative health practices, eating mostly fruits and vegetables and “crunchy granola”, and, yes, finally, investigating yoga, of all things.  At least I hear the classes are mostly women, so, who knows, maybe I’ll meet a nice, healthy girl who won’t laugh too loudly at my foolishness.

So, regardless of how terrified I may be of having to endure chemotherapy again, or how distasteful I find the radioactive enema I will pay an enormous deductible on, I will face the day, the scan, with as much courage and dignity as I can still manage.  I will do my best to be thankful for the friends and family who support me in my weakness and discomfort, and, yes, for the medical staff who will run me through their gauntlet.  I will try to be patient while waiting for the results of what is already there, or not, like Schrödinger’s cat, who’s state cannot be known until it is observed.
And, when all is said and done, I will try not to let the fear cripple me, but, rather, I will do my best to live more fully.  Certainly, more fully than I have been, more courageously, I hope.  I will still know fear, I am sure, but, as I was reminded, there can be no courage without the fear first.

Of course, until that all happens, I will be more than happy to accept your prayers, good thoughts, and any introductions to nice, pretty, healthy ladies who aren’t more than ten years younger than I.
But, let’s start with those prayers, okay?
Thanks.


Advice from your Uncle Jim:
"Before you give someone a piece of your mind, make sure you can spare it."

8/9/2011

Cyber Pearl Harbor?

Filed under: Geek Work,News and Current Events,The Dark Side,Things to Read — Posted by the Network Geek during the Hour of the Pig which is in the late evening or 10:41 pm for you boring, normal people.
The moon is a Full Moon

Really?  Are they bringing this one out again?

I’ve heard about the dangers of “cyber war” almost since I got started in this business twenty years ago.  Essentially, since the internet existed, people have been claiming that dangerous hackers are going to take over our infrastructure from within.  Sound familiar?  Like, oh, say, the Red Threat of the Cold War?
It’s pretty easy to get IT guys like me whipped into a frenzy about this.  Back in the day, Winn Schwartau wrote THE go-to book on the subject, [amazon_link id=”B00127UJMO” target=”_blank” container=”” container_class=”” ]Information Warfare[/amazon_link], and in that book he talked about a so-called “Cyber Pearl Harbor” that ushered in a new era of digital warfare.  Well, now, it seems, ZDNet is reporting that we may have already had our so-called Cyber Pearl Harbor.  According to security researchers at McAfee, and elsewhere, several targets, including the United States, have been under a five year sustained cyber attack and they went on to speculate that a “state actor” was likely behind the attacks.  A security consultant at Sophos pointed out that fingers are usually pointed in China’s direction when government-funded and supported cyber attacks are discussed.  And, I have to admit, based on the other forms of espionage, especially industrial espionage, that we’ve seen from them over the years, it wouldn’t surprise me if they were using the Internet to attack various sites remotely in an attempt to get restricted information of various kinds.

But, is this a “Pearl Harbor”-like event?  I mean, really?
Do you see people rallying around this issue?  Are hackers joining the U.S. Military to defend our cyber borders?  If they are, it’s one of the best kept secrets in the world right now.  Seriously.
Pearl Harbor was a galvanizing event in our history.  That one event is what got us off the fence and into World War II, as a nation.  Honestly, I don’t see that happening here, or anywhere that high-level computer tech is the focal point of the debate.  We may rely on that tech to get our jobs done or to entertain us, but, really, most people don’t have any idea of the security work that goes on behind the scenes.  This is an invisible war, if it even can be called that.
Again, I think it’s a new form of Cold War.  It’s a battle waged in the shadows against an all but invisible enemy.  It won’t be fought like a conventional war of any kind, much less like World War II.  And, if the cyber war is an apt metaphor at all, then it’s a war we’re already fighting.

Oh, and as for the Chinese, well, they’ve already used their influence as a global market to get a partial retraction from those fine folks at McAfee, who are now claiming that there is no definitive link to any “state actor” of any kind, much less China.  Of course, I’ve only seen the back-peddling on a single, English-language, but Chinese supported, news site.  Still, that, my friends, is the view of the new global economy and the real war.  Big governments will start to throw their weight around and corporations will “adjust” their position on the truth to tap the market and access their bottom line.  Of course, that’s nothing new, either.  China’s been doing that for years.  Only now, they may be the biggest market still available in the entire world.
Looks like we all better start learning Mandarin!

8/2/2011

Android Virus

Filed under: Geek Work,MicroSoft,News and Current Events,The Dark Side — Posted by the Network Geek during the Hour of the Rooster which is in the early evening or 6:51 pm for you boring, normal people.
The moon is a Full Moon

No, not a flu that your synthetic humanoid might catch.

Virus writers target operating systems with a large installed user base.  There’s nothing controversial or even particularly interesting about that statement.  It’s a generally accepted concept based on observation, if not actual hard facts.  For a long time, that’s why there were so many viral attacks on Windows.  Windows enjoyed the greatest market penetration, so Windows users had to put up with the most frequent attempts to penetrate their machines.
But, that’s changing as the distribution of operating systems changes.  Android, in various forms and flavors, is now the most installed operating system.  Yeah, that’s right, someone has been writing viruses (virii ?) that attack your Android phone.

I’ve seen two new stories about this today.  One from a Houston local tech celebrity, Dwight Silverman over at the Houston Chronicle, and elsewhere, both talking about a new Android Trojan that can actually record your voice conversations.
One of the things that people like about Android is that it can load software from places other than a restricted, safe, controlled marketplace, but, that’s also one of the liabilities.  Apparently, the malware takes advantage of that ability to load itself onto your phone’s SIM chip and force the phone to record conversations to the chip then, optionally, upload those recordings to a server, presumably controlled by an attacker.  It’s somewhat unclear how that process would be initiated, but the simple fact that it can do it at all is chilling to me.  Also unclear from the articles was whether or not this has been spotted in the wild.
Hopefully, not yet.

So, here’s another warning for you.  Your devices, of any kind, are not safe.  Not ever.  If you have them powered on and they can connect to a network, even if you think they aren’t, you may still be vulnerable.  The Internet, in all its forms, is a wild and wooly and dangerous place.
Be careful out there, people.

8/1/2011

No More Mac Malware?

Filed under: Apple,Geek Work,MicroSoft,News and Current Events,Rotten Apples,The Dark Side — Posted by the Network Geek during the Hour of the Rooster which is in the early evening or 7:01 pm for you boring, normal people.
The moon is a Full Moon

I hope so!

And, by that I mean, I hope all that Mac Malware we heard about a couple weeks ago is gone.
Now, I know several Mac fanboy blogs linked to the note I put up about the Mac malware some time back thought I was going out of my way to bash Apple, but, honestly, nothing could be further from the truth.  In fact, I hadn’t given it another thought until Ed Bott wrote “Where did all the Mac malware go?”  I threw the original story out there as a warning to all the Apple users who think the Mac and OS X is entirely free from any malware and utterly safe.  That’s just not true.  It is, I have to admit, much safer, in general, than Windows.  There are a couple reasons for that, but, mostly, it’s because of market share and how Apple does, well, everything.

So, that last explosion of malware may be the only shot you hear fired.  At least, for a while.
Frankly, I hope so.  And, I hope that it put enough scare into people that they take security seriously anyway.  As Apple’s market share grows, their products will all become a more appealing target for hackers and crackers.  Though I hope to be proven wrong, I suspect that there is malware being written to attack Macs and, possibly, iPhones and iPads.   In fact, that malware may be already written and just waiting for the right infection vector.  Maybe.

Maybe I’m just a bit cynical and I’m waiting for the proverbial other shoe to drop.
For years, Apple fanboys have told people that Macs were completely virus free and were more secure by their very nature.  Sadly, that’s not true.  We’ve heard the first shots fired in a new skirmish in the secret war for desktops of all kinds.  It’s big business.  I don’ t think this is the last we’ve heard about Mac malware.
But, maybe I’m wrong.  Maybe Apple has closed that hole and all the other holes, too.  Maybe the Macs are all safe and that’s why we haven’t heard about that malware recently.
Maybe.

But, can you afford to take the chance?

7/12/2011

RIght Sourcing

Filed under: Criticism, Marginalia, and Notes,Deep Thoughts,Geek Work,News and Current Events — Posted by the Network Geek during the Hour of the Tiger which is terribly early in the morning or 5:05 am for you boring, normal people.
The moon is a Full Moon

Regular readers know I’m not a big fan of outsourcing.

I am, however, even less of a fan of off-shoring.
Now, before someone calls me racist again, let me say that I have no problem at all with non-US citizens making money, no matter what country they’re from.  Honest!  I’m friends with more than one proud Green Card holder!  But, I’m not a big fan of shipping jobs to a foreign country when someone right here in the United States is out of work and can do the job.  In fact, for years I’ve advocated what one company I worked for did; Rural Sourcing.

Of course, at the time, we didn’t call it that, but, as it turns out, that’s what it is.
We had a call center in a very rural town, connected to our data via a satellite.  In fact, they were connected to the same service bureau that we were.  It was a pretty good deal, all the way around.  We got decent, cheap labor, that spoke English without an accent to our American customers.  They got better jobs than the local sugar beet canning factory.  Yeah.  That was our employment competition.  Can you guess where the majority of the people in town wanted to work?  I’ll give you a hint, it wasn’t standing on a production line with high-speed machinery.

So, while this isn’t new, it is, apparently, a newish idea for corporate America at large.
In any case, take a look at the article on Tech Republic; First Rural Sourcing Effort Proves Successful.
As I mentioned, it’s not new at all, but it must be a new concept for the author of the article.  I think it’s a great idea.  It CAN be cost effective to use local developers and local call centers in rural areas.  I don’t think it’s wrong to try and pull some of this business back from overseas.  I think it’s good, smart business.

5/29/2011

DNS Redirect Attack

Filed under: Geek Work,News and Current Events,Rotten Apples,The Dark Side — Posted by the Network Geek during the Hour of the Horse which is around lunchtime or 12:34 pm for you boring, normal people.
The moon is a Full Moon

I’m seeing traffic about this, so I thought I’d write up what I found.

I tweeted about a strange DNS-based network/malware attack that I saw on Friday, but, at the time, I didn’t see any interest, so I didn’t go into any real details.  Besides, I may be a hardcore geek, but I do have a life and was going out.  But, now, I’m seeing search engine traffic hitting my blog apparently looking for details, so I thought I’d describe the attack, as I saw it.

First of all, let me mention that I’ve seen a higher-than-usual occurrence of malware infections the past couple of weeks.  I mean, it’s a hazard of my business that, sooner or later, people are going to get infected, either through bad behavior or by accident, but the past three weeks or so I’ve seen way more problems like that than is even remotely normal.  So, bearing that in mind, I’ve been on a kind of high-alert status looking for any malware problems, but this was something new.

It started with someone from another location, who’s on a totally, physically separate network which uses a different internet service provider to connect to the Internet, calling me with a problem.  It was, apparently, a recurrence of a virus he had previously that we cleaned.  He described being taken to a webpage that featured a maroon graphic background with a white icon of a policeman holding up his hand to indicate “stop”.  The text on the page gave a message that said the user’s browser was not the correct version to access the page and that an upgrade was required.  Helpfully, it provided a button to press to receive the “upgrade”.  Obviously, the “upgrade” was an infection.  (You can see an example of the graphic here.)  Thankfully, I trained my users well enough to be suspicious of these kinds of things and no one who reported this actually clicked on it.

About the same time this happened, I noticed that my iPhone wasn’t connecting to the wifi hotspot I have setup in my office.  I checked the configuration and noticed that the DNS servers listed were wrong.  In fact, they’d all been replaced with a single DNS server; 188.229.88.7  Obviously, that seemed suspicious to me, so I opened a command prompt on my PC and did a tracert to see if I could figure out where this server was and, from that, why it had become the default DNS server on part of my network, despite my having very carefully configured totally different DNS servers that I knew were safe.  It looked like the tracert results showed me a network path that led out of the country somewhere, which was, to me, very suspicious.

Before I could really pursue that, though, I got another call from a user at my location reporting the exact same error message and graphic, but going to a totally different website! I went to his computer and checked the IP configuration and found that his DNS servers had been replaced by the rogue server as well.  I refreshed his network config, several times actually, and the DNS servers reset, but, when I thought to check some other people in the same area of the building, his configuration set itself back to the rogue DNS server!  So, I reset the local network equipment to clear the DNS cache, and whatever other caches may have gotten poisoned by this attack, and the problem seemed to go away.  Unfortunately, whatever had caused the compromise was still active and seemed to poison the DNS cache and the DNS configuration again.  It did seem sporadic, though, as if the ISP was trying to correct the issue at their end.

As far as I can tell, the attack actually seemed to be network-based in some way.
At least, I couldn’t find any computer on my network that was infected with anything that AVG, Norton Anti-virus, or Malware Bytes could find.  It is, I suppose, possible, that this attack was so new that no of those programs had an updated detection pattern for it, but, based on the lack of detection, and the fact that it happened on two physically separate networks almost simultaneously, leads me to believe that this was a network-based attack.  I suspect that an ARP cache or DNS cache or something similar was attacked and compromised on a major network router somewhere.  Possibly one of the edge routers at a trans-continental connection somewhere.  From the tracert results I had, it looked like it was the East Coast somewhere, leading to Europe via London to France, though I could be wrong.  It’s possible that was a blind alley meant to throw researchers off the trail in some way.
Also, as of this writing the rogue DNS server seems to be out of commission, though that might change, too.

The Internet is a wild and wooly place, ladies and gents, and you can’t always count on your friendly, neighborhood Network Geek to watch over you and keep you safe!  So, be careful out there!
(And, if you’re a fellow professional who’s seen this, too, leave me comments and tell me what you found!)
UPDATE: Looks like the server is still active, but my ISP has blocked DNS traffic to it, to fix the problem.
Also?  I hate the bastards that do these things.  I hate every last one of the little rat bastards!

UPDATE/FOLLOW-UP: So, it seems like a lot of people have been effected by this problem!
Check the comments for what other folks did and tools they might suggest to help with the problem.  Frankly, I wish I’d had known about those tools when I started my day!  Yes, I was *totally* wrong when I said it looked like it was coming in from outside the routers.  It was, in fact, *several* PCs that were infected with whatever it was.  I found it, much like at least one commenter, by checking the results of “ipconfig /all” in a command prompt.  I noticed that the DHCP server listed in the config was NOT my actual DHCP server!  So, as I went from machine to machine, I saw several PCs that kept coming up as DHCP servers.  I used Malware Bytes to scan the infected PCs and it seemed to clean them off.  At least, for now.  I’m not sure what I’ll find in the morning.
Apparently, Friday, when it looked like the problem was getting cleaned up, it was really just people shutting their workstations down early for the long weekend.
In any case, as at least one commenter has mentioned, it looks like updates for the various scanners should be coming out this week, so keep updating your antivirus and antispyware programs and scan your networks!  Well, scan them more completely and carefully than you already have.
And, as always, if you have any new information or suggestions for tools to clear up the issue, please, leave them in the comments!

5/26/2011

Mac Malware News Update

Filed under: Apple,Geek Work,MicroSoft,News and Current Events,Rotten Apples,The Dark Side — Posted by the Network Geek during the Hour of the Rooster which is in the early evening or 6:26 pm for you boring, normal people.
The moon is a Full Moon

Good news!

First, there are things you can do to protect yourself from this new Mac malware:
Start by disabling the automatic opening of downloaded files.  The world has changed for you Mac users and you simply can’t trust just any download any more.  Welcome to the world that Windows users have lived in for years and years.
Also, don’t let things install on your machine unless you’ve gone out looking for them!  Again, don’t trust anything that looks like an automatic update or a “free” program that wants to install automatically, especially if you haven’t been searching for any thing!
Seriously, you can’t trust people on the Internet.  I know this may come as a shock to the Hippie, “free-love” sort of people Mac users think themselves to generally be, but, yeah, not everyone on the Internet has your best interests at heart.  Well, except me.  You can trust me.  Honest.

Secondly, in a “few days” Apple will allegedly put out an update to make you safe again.
At least, that’s what they’re saying.  No definite deadline on that, though, so be careful and make sure to check your updates regularly!  Staying up to date on patches is one of the better ways to help prevent an infection.  Also, if you haven’t already, please, consider getting an anti-virus program for your Mac.  OS X is a growing target for hackers as the installed user-base grows, so, sooner or later, you’ll see more of these little nasties coming your way.  Your platform’s growing popularity will make it a growing target!  So, before it’s too late and you’re asking your friendly, neighborhood network geek for help in cleaning up the mess, install an anti-virus to prevent the mess in the first place.  The computer you save may be your own!

« Previous PageNext Page »

Powered by WordPress
Any links to sites selling any reviewed item, including but not limited to Amazon, may be affiliate links which will pay me some tiny bit of money if used to purchase the item, but this site does no paid reviews and all opinions are my own.