<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-7782260</atom:id><lastBuildDate>Wed, 07 May 2008 20:10:41 +0000</lastBuildDate><title>Vitalsecurity.org - A Revolution is the Solution</title><description/><link>http://www.vitalsecurity.org/</link><managingEditor>paperghost</managingEditor><generator>Blogger</generator><openSearch:totalResults>905</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-487727865705781137</guid><pubDate>Wed, 07 May 2008 20:08:00 +0000</pubDate><atom:updated>2008-05-07T21:10:41.214+01:00</atom:updated><title>Mid-Week Spywareguide Roundup</title><description>&lt;span style="font-family:verdana;"&gt;Here we go again!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* I just called, to say.....nothing, actually&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/05/i_just_called_to_saynothing_ac.html"&gt;Strange and annoying phonecalls&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;. We all hate them, don't we? Especially when you can't decide if they're trying to sell you things (bad) or just steal all your personal data to sell on (worse).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* It's a trap&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: Hot chick adding herself to my Myspace friends list = &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/05/its_a_trap.html"&gt;Disaster&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;. Mind you, I have plenty of &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;real&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; hot chicks on my list so that's okay.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* Hackmemes&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: Did you ever want to see a DDoS tool whose sole purpose for creation was as part of a meme war? Even better, a DDoS tool that's actually stuffed full of memes purely so it'll gain acceptance with the groups involved in the battle in the first place? Then &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/05/memehacks_1.html"&gt;here comes Christmas&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/mhack2-794739.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/mhack2-794737.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;&lt;br /&gt;....you do like Mudkips, right?&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/05/mid-week-spywareguide-roundup.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-2784786987029995669</guid><pubDate>Tue, 06 May 2008 18:55:00 +0000</pubDate><atom:updated>2008-05-06T20:02:27.448+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Hooray for everything</category><title>Fixed!</title><description>&lt;span style="font-family:verdana;"&gt;Things I am happy about this week:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;1) The comments on &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/"&gt;Spywareguide&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; are working again, and you can now post as you see fit. Swear to God.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;2) The day I posted &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/2008/04/feedburner-stat-trouble.html"&gt;this ramble&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; complaining about Feedburner woes, Netvibes (who, judging from endless posts in their support group via &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.google.co.uk/search?q=netvibe+feedburner+issues&amp;amp;ie=utf-8&amp;amp;oe=utf-8&amp;amp;aq=t&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a"&gt;Google&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;, seem to have been the cause of endlessly fluctuating Feedburner stats) went and migrated all of their users to the new interface. Since that day, my stats have been back to normal and have actually gone up a little bit. Anyone else out there using Feedburner noticed a more regular pattern in their stats since a week ago?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;3) Insert your own happy thing here, I'm all out.&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/05/fixed.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-1439197871751240333</guid><pubDate>Tue, 06 May 2008 06:48:00 +0000</pubDate><atom:updated>2008-05-06T09:35:48.311+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Conferences</category><title>Worst. Idea. Ever.</title><description>&lt;span style="font-family:verdana;"&gt;All I want to know is, &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;who comes up with this stuff&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;See, I've been waiting.....and waiting......and waiting......for the sessions from RSA2008 to hit the web, so we can watch and listen and absorb or whatever. There's a lot of people who couldn't make it who have also asked me if / when my own presentation would be available to listen to. Last year, RSA seemed to be pretty open about who could get their hands on the talks (Hell, we still have one complete with funky Flash thing &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.facetime.com/newsevents/botnet_live_rsa2007/botnet_live_rsa2007.html"&gt;here&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Now? I get an Email from the RSA organisers last night pointing me to &lt;a href="https://ec.rsaconference.com/attendee/event/rsa365.ww"&gt;this page&lt;/a&gt;, with the following genius idea:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;The information and ideas discussed at RSA Conference 2008 will have an impact on the information security industry for years to come. Be sure to capture all of the discussions by replaying the session recordings from this year's Conference. (Free for 2008 Full Conference attendees, $395 for non-attendees)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Wow, yes! What a brilliant idea! We'll have "an impact on the security industry for years to come" by.....letting all the same people who saw the talks originally &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;watch them again&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Wooo!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Also, WTF and doh. Let's be honest and put the hyperbole aside for a second - nothing talked about at RSA will "have an impact on security for years to come", because nobody cares. It was a bunch of talks about stuff, and now it's over. Some were good, some were bad, same as it ever was. But hamming it up with over-the-topness just so we can justify charging lots of money to let people hear it who couldn't make it / afford it? Man, that sucks. That sucks ass, and is a &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;terrible&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;, exclusionary idea.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;If there was anything of worth, of interest spoken about at RSA, how are we helping to spread those ideas by chaining them to full conference passes or extortionate amounts of cash after the event is long gone?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;And why is it always just about the "security industry" anyway? There's a whole variety of people and initiatives that likely fall outside that narrow definition (purely because they're not running around yelling BUY THE BOX!) and yet they're just as active, just as important to the security scene as anyone else.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;But of course, they didn't pay stupid amounts of money to attend and so don't count. Excuse me while I roll my eyes. How many people attending these conferences are only there because their company paid for them to go in the first place? And how many of those people wouldn't come within a hundred feet of security conferences if they actually had to pay up themselves?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Nobody can claim access to 365 session recordings for $395 is good value for money, because nobody in their right mind is going to &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;listen&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; to three hundred and sixty five sessions unless they are clinically insane.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Anyone with any interest in RSA2008 that didn't go is more likely to want to hear the odd handful of sessions - and here's a breaking newsflash, they are NOT going to pay out four hundred bucks just to hear them. I don't believe RSA have a "reduced fee" anywhere to listen to (say) five talks, but meh, even that would suck.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I really doubt half the people at RSA on free Full Conference Passes (courtesy of their company) would complain if people who didn't attend got to hear the talks for free after the event. Again, by this point nobody cares, right? It's now just a bunch of talks at some conference somewhere, and everyone is now too busy gearing up for the next conference in a few weeks or months time.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt; And if someone argues that it's not good form to have the great unwashed masses listening in for free when all those companies had to stump up tons of cash for full conference passes? Well, too bad for all those companies. Surely half the fun of the full pass is the chance to hear people speak in person that you always wanted to see present twenty feet away from you - not simply possession and apparent ownership of the words that came out of their mouth.&lt;br /&gt;&lt;br /&gt;To me, security is all &lt;span style="font-style: italic;"&gt;about&lt;/span&gt; protecting those same "great unwashed masses" with as much vigor and force as the companies at RSA devote to protecting enterprise and business customers - great unwashed masses that (currently) don't have a hope in Hell of hearing talks that might actually contribute to making them consider security a little more in their day to day lives.&lt;br /&gt;&lt;br /&gt;It all seems a bit greedy and possessive to me, but then I only spoke at RSA.&lt;br /&gt;&lt;br /&gt;What do I know?&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/05/worst-idea-ever.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-2554930179114192529</guid><pubDate>Sun, 04 May 2008 18:57:00 +0000</pubDate><atom:updated>2008-05-04T22:01:48.987+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Won't somebody please think of the children</category><title>Offtopic: Arbitrary Attacks on Videogames Annoy Me</title><description>&lt;a style="font-family: verdana;" href="http://en.wikipedia.org/wiki/Peter_Hitchens"&gt;Peter Hitchens&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; wheeled out a predictable attack on videogames - namely Grand Theft Auto 4 - in the print edition of the Daily Mail today. His tortured logic spilled onto his &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hitchensblog.mailonsunday.co.uk/2008/05/why-the-left-ar.html"&gt;weblog&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;, so I left him the following reply:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;"Could it possibly be bad for a child or a teenager to spend long hours impersonating a violent car thief?" (Hitchens)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;Could it possibly be bad for you to write a "won't somebody think of the children" missive to whip up the usual sensationalist panic about videogames while (predictably) failing to mention the product in question is clearly labeled 18 for adults?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;Rather than decry the game, perhaps it might make more sense to attack gamestores that happily sell products aimed at an older market to kids. Perhaps it might be better to attack the parents that thoughtlessly hurl products aimed at an older market at their children.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;Unless, of course, you're *also* going to blame the collapse of Western civilization on every single activity aimed at someone over 18 along with the horrors of GTA4?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;The gaming market has grown and aged with the products. I've played games for 25 years, and I don't particularly fancy playing "super happy hooray for everything" anymore.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;Thanks for trying to limit my choice of personal pursuits via the agenda you're pushing without even bothering to try the product in question.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;If you *had* actually tried the game, you wouldn't be writing it off as a senseless, lawless gunfest with no consequences, morals or anything approaching depth beyond "kill everything in sight".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;It's mature, its intelligent, its - shock horror - actually very grown up, and at least one major videogame site said of this game in its review that the more realistic and serious nature of the lead character meant that they were actually *less* inclined to go on a gun rampage, because it "didn't feel like something the character would do".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;To impress upon a player that sense of depth with regards a fictional character jumping around on a screen is pretty impressive. To do such a thing when it could be argued the basic mechanic of the title is to shoot people, even &lt;span style="font-weight: bold;"&gt;more&lt;/span&gt; so.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;But of course, you're too busy wheeling out assumptions and blanket statements.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;He never published the comment. Funny, that...&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/05/offtopic-arbitrary-attacks-on.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-7630166740534528761</guid><pubDate>Fri, 02 May 2008 16:33:00 +0000</pubDate><atom:updated>2008-05-02T17:35:07.998+01:00</atom:updated><title>Spywareguide Roundup</title><description>&lt;span style="font-family:verdana;"&gt;Shall we get down to business?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* Credit Card up for Renewal? Then Beware This Phish&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: A &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/05/credit_card_up_for_renewal_the.html"&gt;funky little diversion&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; through a Phish scam that caught my eye simply because my credit card was due to expire.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* The Spectre of Rogue Facebook Applications, Back Once More&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: Ooh, it's &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/05/the_spectre_of_rogue_facebook.html"&gt;all kicking off&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; with Facebook applications again!&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* Pinont.com - No Need to Panic&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: Aargh, it's an apocalyptic wave of.....&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/05/pinontcom_no_need_to_panic.html"&gt;viagra spam&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* Beware - New MSN Messenger Password Stealing Program in the Wild&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: This is a &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/05/beware_new_msn_password_steali.html"&gt;pretty slick application&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; for scumbags everywhere - click a few buttons, and hey presto, a ready-rolled executable that can be used to steal your MSN Messenger login credentials. here's the Client:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/msnhxr4-750602.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/msnhxr4-750600.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;And here's what the attacker will see with the click of a button, assuming the victim let the infection file execute on their PC beforehand:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://www.vitalsecurity.org/uploaded_images/msnhxr11-750617.jpg" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;.....ouch.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/05/spywareguide-roundup.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-3304274745655722175</guid><pubDate>Thu, 01 May 2008 16:06:00 +0000</pubDate><atom:updated>2008-05-01T17:59:35.045+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>WTF</category><title>Would you like a side order of WTF with those fries?</title><description>&lt;span style="font-family:verdana;"&gt;Sometimes I see things that break my brain.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;This is one of those things. Sighted on Facebook, the content falls somewhere between comical and extremely creepy, so of course I'm publishing the whole glorious train wreck below:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://www.vitalsecurity.org/uploaded_images/needs_more_drugs-781499.jpg" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;.....what??&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I love how "I am dead" is thrown in as an afterthought, like having pencil shavings up your butt and not having any nose or ears wasn't quite bad enough.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Bonus points if you can work out why it has a random picture of two teens hugging attached, too. As for "don't send it to me", I can't say I have any dead seven year olds missing half their face waving kitchen knives on my friends list to send this to, but oh well.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/05/would-you-like-side-order-of-wtf-with.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-7636887613732183696</guid><pubDate>Thu, 01 May 2008 14:35:00 +0000</pubDate><atom:updated>2008-05-01T15:36:58.731+01:00</atom:updated><title>I can haz typoz?</title><description>&lt;span style="font-family: verdana;"&gt;Comedy spelling galore &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blogs.paretologic.com/malwarediaries/index.php/2008/04/28/malware-authors-have-trouble-with-spelling-and-grammar/"&gt;here&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;. You'd think with all the money they have, these malware writers could afford dictionaries...&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/05/i-can-haz-typoz.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-5791711453660465623</guid><pubDate>Wed, 30 Apr 2008 18:23:00 +0000</pubDate><atom:updated>2008-05-06T07:49:50.173+01:00</atom:updated><title>Mid-Week Spywareguide Roundup</title><description>&lt;span style="font-family:verdana;"&gt;Haven't had one of these for a while, so here goes.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* &lt;/span&gt;&lt;a style="font-weight: bold; font-family: verdana;" href="http://blog.spywareguide.com/2008/04/here_phishy_phishy.html"&gt;Here Phishy, Phishy&lt;/a&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt; and &lt;/span&gt;&lt;a style="font-weight: bold; font-family: verdana;" href="http://blog.spywareguide.com/2008/04/booze_and_binders.html"&gt;Booze &amp;amp; Binders&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;: Some leet hax script kiddy applications currently in circulation. I'd throw in a picture here, but amazingly the Blogger image upload tool is broken. Again. Blogger is full of so much win and awesome, and by win and awesome, I mean crap and fail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* Locking down Facebook Chat&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: Nothing particularly revelatory, but a &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/04/locking_down_facebook_chat.html"&gt;little delve&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; into the wonderful world of Facebook Chat, or (to be more accurate) how to get rid of the damn thing if (like me) you had no clue what you were supposed to click on when confronted by hundreds of people saying HELLO LOL. Once more, no pictures. Blogger. Fail. Epic fail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* Myspace - Who is Watching the Detectives Part 3:&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; Did Myspace ever fix their "system error" that allowed people to view exactly who had been snooping round their profile pages? Click &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/04/myspace_who_is_watching_the_de_2.html"&gt;this&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; and find out. Ooh, the suspense.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;* Off-Topic Fun: Videogames are Awesome&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;: Spurred on by my post about the &lt;a href="http://blog.spywareguide.com/2008/03/dreamphish_how_to_ruin_a_10_ye_1.html"&gt;Dreamcast phishing incident&lt;/a&gt; a few weeks ago, I decided to go deep into off-topic country and &lt;a href="http://blog.spywareguide.com/2008/04/offtopic_fun_videogames_are_aw.html"&gt;post up a bunch of my old videogame systems&lt;/a&gt;. I used Flickr for these images, so nothing stops me from posting these up:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;style type="text/css"&gt;.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }&lt;/style&gt;&lt;div class="flickr-frame"&gt;    &lt;a href="http://www.flickr.com/photos/paperghost/2434714460/" title="photo sharing"&gt;&lt;img src="http://farm4.static.flickr.com/3121/2434714460_7a1b9cbb1c.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;    &lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/2434714460/"&gt;My Shenmue Collection&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;                &lt;p class="flickr-yourcomment"&gt;    &lt;/p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;style type="text/css"&gt;.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }&lt;/style&gt;&lt;div class="flickr-frame"&gt;    &lt;a href="http://www.flickr.com/photos/paperghost/2452105889/" title="photo sharing"&gt;&lt;img src="http://farm4.static.flickr.com/3267/2452105889_d003379f9e.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;    &lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/2452105889/"&gt;ChuChu Rocket Box Set (Front)&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;                &lt;p class="flickr-yourcomment"&gt;    &lt;/p&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I encourage anyone remotely interested in old game systems to post up some screenies of their collections. I had planned for people to post their links directly on Spywareguide, but it appears the hope invested in the &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/2008/04/spywareguide-comments-now-working-again.html"&gt;comment fixing&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; was a little premature. With that in mind, post your links here and when (if) the comments start working again on SPG, I'll port everything over there.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/mid-week-spywareguide-roundup.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-2920025628745833402</guid><pubDate>Tue, 29 Apr 2008 08:25:00 +0000</pubDate><atom:updated>2008-04-29T09:32:57.067+01:00</atom:updated><title>Feedburner Stat Trouble?</title><description>&lt;span style="font-family: verdana;"&gt;For the last month or so, my Feed subscriber count has been fluctuating wildly - it currently says 1,319 which is correct but (more often than not) keeps showing at around the 900 mark, which is way off the real total. I eventually worked out that this is because Feeburner is having issues with anyone subscribed to the site via &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.netvibes.com"&gt;Netvibes&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; as they upgrade to their new release.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Whoops.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Apparently they claim subscribers aren't affected, it just makes your stats look more rubbish than they actually are. I've noticed this sudden drop-off affecting quite a few security blogs out there so if you're wondering where all your subscribers are going, it's down to Netvibes. No ETA on when this will be fixed, which sucks.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/feedburner-stat-trouble.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-3357347899213629234</guid><pubDate>Mon, 28 Apr 2008 20:23:00 +0000</pubDate><atom:updated>2008-04-28T22:01:01.246+01:00</atom:updated><title>Wait, what?</title><description>&lt;span style="font-family: verdana;font-family:verdana;" &gt;I got this in my mailbox today:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="" id="VOCUSHTML"&gt;&lt;span style="font-weight: bold; font-family: verdana;"&gt;April 28th, 2008&lt;br /&gt;For Immediate Release:&lt;br /&gt;Contact: Colonel Custard (aka the corporate criminal creamer)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;Footage available: www.GreenwashGuerrillas.org&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Greenwash Guerrillas Pie Thomas Friedman at Brown University&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;YouTube Censors Video; Pie Thrower Faces University Disciplinary Procedures&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Providence, RI - New York Times columnist and author Thomas Friedman was pied by the Greenwash Guerillas while giving an Earth Day Lecture at Brown University. The Greenwash Guerillas targeted Thomas Friedman because of his support for U.S. military intervention in the Middle East, neo-liberal economic policies that harm the world’s poor, and especially for promoting bogus solutions to the global climate crisis.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;"We sought to expose the hypocrisy of allowing Friedman, who is known for his influential support of U.S. wars for oil in the Middle East, to call himself an environmentalist,” explained Greenwash Guerrilla Margaree Little. "He has blood on his hands that no amount of 'green' can wash away."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Little, a Brown University student identified as one of the pie throwers, faces University disciplinary hearings, potentially including expulsion. Colonel Custard, the second pie thrower, remains at large.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Little and Custard jumped on stage as Friedman began his talk, entitled “Green is the new Red, White &amp;amp; Blue.” The talk focused on how green technology and corporate environmentalism can restore the United States to its "natural place in the global order."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;They tossed two green-colored cream pies at Friedman and dashed off as leaflets denouncing Friedman were thrown to the crowd. According to the pamphlets, “On behalf of the earth and all true environmentalists – we, the Greenwash Guerillas, declare Thomas Friedman’s ‘Green’ as fake . . . as the cool-whip covering his face.”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The Greenwash Guerillas object to Friedman’s support for nuclear power, coal power, industrial biofuels, and carbon trading markets. "These false solutions are smokescreens, intended to generate massive corporate profits while creating global humanitarian and environmental disasters,” said Colonel Custard.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Video of the pie throwing incident was posted on YouTube, and received close to 70,000 views in 36 hours, making it one of the most popular videos on the site. Without notice, YouTube abruptly censored the video, removing it from the website. Hundreds of news outlets, blogs, and websites had linked to the video. The Greenwash Guerillas have reposted the clip at: www.GreenwashGuerrillas.org&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;"Given the many other pieings on YouTube(1), the removal of the video can only be understood as an act of political censorship," said Little. "One has to wonder whether Friedman, a billionaire with a lot of connections, has more influence than “you” on YouTube."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;“The Greenwash Guerillas chose the harmless and humorous tactic of pie-throwing because our goal was to take this perpetual charlatan off his new green pedestal,” said Colonel Custard. “Friedman’s support for coal and nuclear power is as misguided as his counsel on Iraq.”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;This is the second time Friedman has been hit by a pie. In October 2002, he received a banana pie to his face while promoting his writings on free-market globalization in Boston."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;p style="" class="MsoNormal"&gt;&lt;span style=""&gt;&lt;span style="font-family:verdana;"&gt;Now, that's a pretty awesome thing to appear in your mailbox by any standards.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;However.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Someone getting a pie in their face gets removed from Youtube, but insanely stupid crap like &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.youtube.com/watch?v=yje9yGEvrjU"&gt;idiots juggling cats&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; (warning: an idiot juggling a cat) and an &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.youtube.com/results?search_query=msn+hacking&amp;amp;search_type="&gt;endless stream&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; of leet hax videos never seem to get canned?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Meh, whatever. I &lt;span style="font-style: italic;"&gt;will&lt;/span&gt; say that the options for reporting hacking videos on Youtube are limited at best - if you're not reporting a copyright violation, physical attacks or animal abuse (though I guess the animal abuse option is broken, seeing as a moron is still juggling his cat) then you're pretty much up a creek without a paddle.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Pie throwing is pretty cool, though.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/priority-list-that-makes-no-sense.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-3179094625283299395</guid><pubDate>Thu, 24 Apr 2008 10:10:00 +0000</pubDate><atom:updated>2008-04-24T11:10:22.322+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>A winner is you</category><title>A Day in the Life.....of an idiot</title><description>&lt;span style="font-family: verdana;"&gt;22/04/08, 12:38AM:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://img222.imageshack.us/img222/6066/daylife1.jpg" alt="Image Hosted by ImageShack.us" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;br /&gt;22/04/08, 10:01PM:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://img222.imageshack.us/img222/3250/daylife2.jpg" alt="Image Hosted by ImageShack.us" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;br /&gt;22/04/08, 10:05PM:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://img222.imageshack.us/img222/3287/daylife3.jpg" alt="Image Hosted by ImageShack.us" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;br /&gt;22/04/08, 11:09PM:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://img222.imageshack.us/img222/6726/daylife4.jpg" alt="Image Hosted by ImageShack.us" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;br /&gt;They still drop the soap in jail, right?&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/day-in-lifeof-idiot.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-5379762579556902403</guid><pubDate>Wed, 23 Apr 2008 15:34:00 +0000</pubDate><atom:updated>2008-04-23T16:37:34.129+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>You stole my Cloudsong</category><title>If you're going to rip someone off, make it look pretty</title><description>&lt;a style="font-family: verdana;" href="http://www.luclatulippe.com/2008/04/18/book-publisher-in-china-plagiarizes-and-steals-illustrations/"&gt;Part 1&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" href="http://apefluff.com/colorful-illustrations-93c-update-1/"&gt;Part 2&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Ouch.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/if-youre-going-to-rip-someone-off-make.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-3694340116827247801</guid><pubDate>Wed, 23 Apr 2008 14:51:00 +0000</pubDate><atom:updated>2008-04-23T15:56:35.722+01:00</atom:updated><title>From English to Russian in one Leet swoop</title><description>&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/04/an_interesting_development.html"&gt;This&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; grabbed my attention today. Not too often I see leet hax wannabes hauling up the "Nothing to see here, Russian money guys at work" facade...&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/from-english-to-russian-in-one-leet.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-6879047765659716873</guid><pubDate>Mon, 21 Apr 2008 20:22:00 +0000</pubDate><atom:updated>2008-04-21T21:49:24.431+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>A winner is you</category><title>He's back, now with twice the fail</title><description>&lt;span style="font-family:verdana;"&gt;Remember &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/2008/04/chris-boyd-is-disgrace-to-infosec.html"&gt;this guy&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;? Sure you do. Well, he's back again with another breathtaking display of getting-it-all-wrong.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" href="http://www.computerworld.com/comments/node/9078498?page=1"&gt;Fish, meet barrel&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;. It's clear our anonymous superhero isn't going to reveal their identity OR say anything even remotely approaching common sense, so this one goes out to you, whoever you are:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.vitalsecurity.org/uploaded_images/failwand1-749420.gif" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Man, that's gotta hurt.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/hes-back-now-with-twice-fail.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-8705853655544522111</guid><pubDate>Mon, 21 Apr 2008 11:06:00 +0000</pubDate><atom:updated>2008-04-21T12:10:27.824+01:00</atom:updated><title>Found while browsing Google News</title><description>&lt;span style="font-family: verdana;"&gt;"&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.buffalonews.com/home/story/328122.html"&gt;Catching the Script Kiddies&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;" - now that's interesting. The words "script kiddy" sometimes get the odd mention in news articles, but only usually as a passing reference. This is the first one I've seen in a loooooong time where they were the &lt;/span&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;primary focus&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; of the piece.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Hacking school computers, no less. Well, I hope they were better at it than &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/2008/03/epic-failure.html"&gt;this guy&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;. No wait, I don't. Meh, as long as they got busted it's all good.&lt;br /&gt;&lt;br /&gt;I doubt this is the start of a massive trend of "let's write about kids hacking stuff", but good to see it pop up as a fully fledged article somewhere. More, please.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/found-while-browsing-google-news.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-6344430403661626014</guid><pubDate>Mon, 21 Apr 2008 07:46:00 +0000</pubDate><atom:updated>2008-04-21T08:49:02.411+01:00</atom:updated><title>Sometimes, you just can't blame it on technology</title><description>&lt;span style="font-family: verdana;"&gt;Take &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://forum.skype.com/index.php?showtopic=121391"&gt;this guy&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;, for example. Maybe there's a Skype dating group he can join or something...&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/sometimes-you-just-cant-blame-it-on.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-7689423220531606265</guid><pubDate>Fri, 18 Apr 2008 08:48:00 +0000</pubDate><atom:updated>2008-04-18T09:59:53.374+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Melons</category><title>The Melon Pirates get their own conference</title><description>&lt;span style="font-family:verdana;"&gt;Not to be outdone by RSA, our friends responsible for the wonderful &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/2008/02/if-youre-going-to-spam-make-it.html"&gt;Melon Pirate spam&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; not so long ago are back, with all new levels of stupid. Just click the image and let your brain soak it all up:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/melonswtf-714455.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/melonswtf-714407.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="postbody"  style="font-family:verdana;"&gt;I swear, I don't go looking for this stuff. It just finds me.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/melon-pirates-get-their-own-conference.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-5987046991275240239</guid><pubDate>Fri, 18 Apr 2008 06:50:00 +0000</pubDate><atom:updated>2008-04-18T07:54:49.306+01:00</atom:updated><title>"Chris Boyd is a disgrace to infosec"</title><description>&lt;span style="font-family: verdana;"&gt;Wow, &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.computerworld.com/comments/node/9078498"&gt;someone doesn't like me&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; this week. I will now stand in the corner and hang my head in shame.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/chris-boyd-is-disgrace-to-infosec.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-8108105747998208856</guid><pubDate>Thu, 17 Apr 2008 16:55:00 +0000</pubDate><atom:updated>2008-04-17T20:57:43.598+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>WTF</category><category domain='http://www.blogger.com/atom/ns#'>LOL</category><title>Double Trouble</title><description>&lt;span style="font-style: italic;font-family:verdana;" &gt;"Dude why am I getting a different friend request from you?"&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; - some guy I know on Facebook&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Why indeed. A quick search for myself on Facebook later, and....&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/fakeboyd1-736049.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/fakeboyd1-736046.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;......hello, future blog entry!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;A quick rummage around the fake profile on the bottom reveals some curious things. For example,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/fakeboyd2-736058.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/fakeboyd2-736054.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Most of the information above is wrong. Even better than that:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/fakeboyd3-752947.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/fakeboyd3-752944.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;.....I'm doing what with who now? Seems I can't keep my hands off the ladies, because...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/fakeboyd4-752951.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/fakeboyd4-752949.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I'm just THAT memorable! Well, that or she was sent a completely fake "We knew each other because.." mailblast. Finally, it appears I have a penchant for turning up on photograph pages and making random comments. Namely:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/fakeboyd5-733350.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/fakeboyd5-733348.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Go web go! So yeah, if you happen to get any odd things sent to you on Facebook from "Chris Boyd" (like, I rub myself in lard and think of you at night or I am your baby-daddy) then it's probably best to ignore it.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Awesome-tastic.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/double-trouble.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-7935972593179279113</guid><pubDate>Wed, 16 Apr 2008 18:00:00 +0000</pubDate><atom:updated>2008-04-16T19:05:01.980+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Myspace</category><title>Creepy Myspace Interweb Stalkers</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/msvids5-764788.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/msvids5-764768.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Remember the &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/04/myspace_who_is_watching_the_de.html"&gt;Myspace thing&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; from a few weeks back where some nifty code could auto- subscribe you to someones video channel (and thus give them a method of knowing exactly who had visited their page)?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Well, some further digging has revealed that this particular scam has been in use by scumbags everywhere since at &lt;/span&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;least&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; October 2007.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;That's pretty bad news, right there. So is the fact that this is &lt;/span&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;still going on&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; - visit &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/04/myspace_who_is_watching_the_de_1.html"&gt;Spywareguide&lt;/a&gt; for details.</description><link>http://www.vitalsecurity.org/2008/04/creepy-myspace-interweb-stalkers.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-5399694511245700725</guid><pubDate>Wed, 16 Apr 2008 17:53:00 +0000</pubDate><atom:updated>2008-04-16T18:58:42.749+01:00</atom:updated><title>Paperghost: Naked and caught on video, supposedly</title><description>&lt;span style="font-family: verdana;"&gt;Oh, what a wonderful title. Anyway, I got this in my mailbox today:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/nakedandonvideo-700311.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/nakedandonvideo-700309.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;Of course, clicking the link takes you to one of those fake codec installer jobbies. I know, I know - you all really wanted to see that mythical Myspace clip of me parading around in my birthday suit at 3AM.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Sorry kids, maybe next time.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/paperghost-naked-and-caught-on-video.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-8833244751674276822</guid><pubDate>Wed, 16 Apr 2008 17:44:00 +0000</pubDate><atom:updated>2008-04-17T10:45:52.029+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Conferences</category><title>The two most annoying things I always get asked at security conferences</title><description>&lt;span style="font-family:verdana;"&gt;RSA 2008 was always going to be a tough one to pull off - while most people were probably going there to dazzle everyone with the latest cutting edge exploits, cryptography-tech and innovations in the technology field, I was going to show up and talk about kids hacking things.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Already off to a tricky start, things were made more complicated by the structure dictated by such an enterprise - throw in all the juicy stuff right at the start to keep peoples attention, and you risk having nothing interesting to whip out at the end. Keep it too general at the start, and you risk incurring the wrath of the OMG KIDS HACKING ON THE INTERNET? OH, WOW REALLY? THAT'S SUPPOSED TO BE NEWS NOW? brigade.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Of course, the news isn't that kids are "hacking on the Internet" - the news is that nobody is still paying it much (if any) attention. Why is that? It's a tricky question to answer.&lt;br /&gt;&lt;br /&gt;I did have a few people come up to me while I was at the FaceTime booth who fired the following at me, and I usually always get something along these lines (indeed, one guy got particularly stroppy with me for no good reason at InfoSec Europe after asking me the first one). It used to irritate me, but now it just makes my eyes roll and probably glaze over a bit. I might start to think about shopping I need to purchase. A funky song from yesteryear might autoplay in my mind while I jig from side to side in a sexy yet creepy fashion. Who knows.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;1. Sounds interesting, but what is the value to your company?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Well, in terms of specific value to "my company" (and indeed, all companies), anything interesting and productive is good publicity, and good publicity = good news for any company, right? If nobody knows who you are, they're less likely to buy your stuff. If everyone knows who you are, you've achieved some form of visibility and so might sell slightly &lt;span style="font-style: italic;"&gt;more&lt;/span&gt; stuff. If what you do is worthwhile and productive, there's an increased chance people might take your equipment for a test drive. Anyone that can't see the obvious benefits of that, just doesn't get it.&lt;br /&gt;&lt;br /&gt;The other side-effect of lots of publicity is that scumbags the world over - and those scumbags can be anyone from the 17 year old kid in his bedroom to the nastiest of kiddy pr0n creators - don't like a light shone in their face.  It all helps, and it all goes a little way towards people actively working in security one less headache to deal with.&lt;br /&gt;&lt;br /&gt;These &lt;/span&gt;&lt;span style="font-family:verdana;"&gt;people also tend to forget that it's not just a case of shutting down some websites and that's it. If you start with a person, you inevitably end up with their interesting and unique infection files which can then be protected against. If you start with the file, you can usually trace it back to a fame-hungry mofo.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;There's no reason why we can't have our cake and eat it, and no reason why we can't simultaneously look to grab the files for detections AND attempt to shut down the people making those files permanently. In that sense, we're doing what anyone else in security is doing - providing detections - and also trying to ensure they don't keep pumping out infection files all day long. Anything done after grabbing the files and providing detections is a bonus. &lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;That's a benefit to everybody, and I'm &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;interested&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; in providing a benefit to everybody - not &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;just&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;the parent company.&lt;br /&gt;&lt;br /&gt;Why does "value" always have to equate to tangible amounts of cash on the table? If it's done purely to help people, does that suddenly lose all worth? Is it only relevant if I'm rolling around in a swimming pool stuffed with hundred dollar bills or something?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I'm sure the future victims of some credit card scammer who won't now be stung because we already shut him down three weeks ago will see the value in it, or the people using some social networking site that won't be hit because we already shut down the clowns producing the latest scam, and so on and so on. To me, people complaining about the dollah dollah bill, y'all worth of things not being entirely evident by "simply" shutting down wannabes, hackers, crackers and God knows who else have it all back to front.&lt;br /&gt;&lt;br /&gt;In case they forgot, I apply the same "burn it all down to the ground" method for everyone from &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.informationweek.com/news/showArticle.jhtml?articleID=191600169&amp;amp;subSection=Breaking+News"&gt;Adware vendors&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; to &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.eweek.com/c/a/Security/AIM-Rootkit-Attack-Traced-to-Middle-East/"&gt;hackers in the Middle-East&lt;/a&gt; and &lt;a style="font-family: verdana;" href="http://www.infoworld.com/article/07/08/07/Web-scam-wanna-buy-a-house_1.html"&gt;everyone inbetween&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;. Was it an issue then? Or does it only become an issue because people can't immediately see the worth in slicing up wave after wave of script kiddies?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I mean, it's not like many of these kids will be doing bigger, better and nastier things in five years time or less if left unchecked, right? It's not like they're gearing up to be the next wave of assclowns who people like me will eventually have to chase down anyway, right?&lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;What? What's that? They WILL?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Oh.&lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;br /&gt;The next question I had thrown at me from one or two guys was something similar to this:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;2. I used to hack back in the day, and I'm still on the scene though I don't do anything anymore. You shouldn't call these kids hackers, because it's an insult to all of us real hackers who were all about exploration and fighting the system etc etc (insertpartabouthowtheyactuallyusedtohackthingsanywayhere).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;My response to that was, you're unhappy about them being lumped in under the semantically awesome term "hacker", you claim to still be "on the scene", you probably read articles in 2600 magazine about the "true worth and nobility of hackers" and yet &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;don't actually do anything&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; to steer them towards your ideal goal of "hackers not being into illegal things as such and actually being all about exploration and freedom of expression"?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Wow, then EPIC FAIL FOR YOU.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Anyway, ramble over. I just want you to know what not to ask me at conferences (along with, "Did you enjoy the flight". That one sucks too).&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/two-most-annoying-things-i-always-get.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-7297013482036040405</guid><pubDate>Wed, 16 Apr 2008 17:32:00 +0000</pubDate><atom:updated>2008-04-16T18:39:01.821+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Takedown</category><title>Fail</title><description>&lt;span style="font-family:verdana;"&gt;If you meet me, have some courtesy&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://www.vitalsecurity.org/uploaded_images/htcl1-710325-710167.gif" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Have some sympathy, and some taste&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://www.vitalsecurity.org/uploaded_images/htcl2-710357-710199.gif" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Use all your well-learned politesse&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="font-family: verdana;" src="http://www.vitalsecurity.org/uploaded_images/htcl3-718665-731397.gif" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Or Ill lay your.....soul to waste.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/deadlol-712234.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/deadlol-712228.jpg" alt="" border="0" /&gt;&lt;/a&gt;</description><link>http://www.vitalsecurity.org/2008/04/fail.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-791586776616815249</guid><pubDate>Tue, 15 Apr 2008 07:17:00 +0000</pubDate><atom:updated>2008-04-15T08:40:47.607+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Conferences</category><title>RSA 2008: Pictures Galore</title><description>&lt;span style="font-family:verdana;"&gt;You can jump over to &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://blog.spywareguide.com/2008/04/rsa_2008_opening_salvo.html"&gt;Spywareguide&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; and see an overview of the session we did at RSA last week (with links to a bunch of articles), and also click &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.flickr.com/photos/paperghost/sets/72157604526785192/"&gt;here&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; for as many pictures as you can shake a stick at.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Incidentally, many of you have asked me about &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.flickr.com/photos/paperghost/2413150060/in/set-72157604526785192/"&gt;this TShirt&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Sorry, I had it custom made. That's right, I go into TShirt shops and ask for junk like this. To the guy that came up and asked me where I got it? I admit it, I felt like I was kicking a puppy when you asked me what booth you could get it from. To the randomly selected booth that suddenly had some dude come up and bug you for a "Tonight we dine" shirt, I apologise.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Well not really, it was pretty funny.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Eventually, RSA will (hopefully) provide a link to the full talk - when they do, I'll link to it and all that jazz. Wish they'd get a move on, they were a lot quicker linking to this stuff last year...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/rsa-2008-pictures-galore.html</link><author>paperghost</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7782260.post-6643851063829810529</guid><pubDate>Sun, 13 Apr 2008 15:21:00 +0000</pubDate><atom:updated>2008-04-13T19:30:00.644+01:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Conferences</category><title>British Airways: Redefining "Sucktastic" for the 21st Century</title><description>&lt;span style="font-family:verdana;"&gt;I've arrived home, no thanks to BA. Already having endured the &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/2008/04/flight-ba-287-i-knew-this-was-wrong-day.html"&gt;wonders of BA287&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;, you can imagine my reaction at seeing this upon arrival at SFO:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/delayed-713280.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/delayed-713277.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;.....oh BA, not again. Even before checking in, some dude was handing out "We're sorry, but.." letters so I knew it was gonna be bad. As it turned out, the plane was indeed delayed for a stupidly long time but we didn't plunge out of the sky - hey, bonus.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Of course, this meant I had to be ultra-snappy when getting to Terminal 5 to ensure I didn't miss my connecting flight. Imagine my dismay, then, when it turned out that the following snazzy electronic poster:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/lies-720371.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/lies-720368.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;.....would turn out to be spectacularly incorrect.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;As soon as you get to the departures lounge, there's no indication of where you're supposed to go. Do I stay in the same terminal? Do I have to catch one of those bus things to the other buildings down the road somewhere?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;No idea. Sadly, I made the fatal mistake of asking British Airways staff. Before you knew it, they'd sent me downstairs to the bit where you catch the bus where I was told "Terminal 1" by some guy who could barely speak English. Not entirely convinced, I asked the woman at the Terminal 1 bus departure gate only to be told "Terminal 4".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Well holy crap, SOMEONE tell me where to catch the damn plane. Can't be that hard, can it?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;As it turns out, yes. Yes, it can. Not long after the guy who told me Terminal 1 mocked me with a "Why could you &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;possibly&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; want to go upstairs?" type comment, someone else came down and apologised profusely because......the plane was leaving upstairs from Terminal 5, and there was no way back up the escalator.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;A few minutes of shouting later, and they let me go back up in a freight elevator of some description, but of course it was too late and my plane was already flying off into the distance. I did feel better giving the Terminal 1 guy the two finger salute, but not by much - especially when it turned out that the next plane would be something like FIVE HOURS LATER (of course, it was delayed severely which meant a grand total of seven hours of swearing and ranting but it's entirely academic by this point).&lt;br /&gt;&lt;br /&gt;Even trying to use a phone to let people know you weren't dead was an exercise in futility. Approaching the helpdesk (no more than ten feet away from a non-working payphone), this is how it all went down:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Me&lt;/span&gt;: Hi, are there any phones working yet?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Some stupid woman&lt;/span&gt;: Sorry?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Me&lt;/span&gt;: When I flew out last week, none of your payphones were working and I'm guessing it's still the same?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Some stupid woman&lt;/span&gt;: We're having problems at Terminal 5?&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;&lt;/span&gt;&lt;img style="font-family: verdana;" src="http://www.vitalsecurity.org/uploaded_images/omd12-741033.jpg" /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Well, BA ain't getting one over on &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;me&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; again. Spying the &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/uploaded_images/doorway-741131.jpg"&gt;first class lounge&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; off in the distance (and watching my fellow cheap-seat passengers being turned away with hopeful cries of "but I have extra legroom seats!"), a quick burst of the old "walk backwards while saying goodbye" trick later and I was confronted with free food, booze and all the comfy seating I could handle. I know it looks like I'm hiding under a table in the first picture, but I swear I'm not:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/stealth-763756.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/stealth-763752.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/lounge-763727.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/lounge-763723.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;After stuffing my face with all the pasta, noodles and muffins I could cram into my gob I started looking round for something a little more fun:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/i_demand_more_booze-720341.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/i_demand_more_booze-720338.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Oh, free booze? Don't mind if I do. I pretty much nuked the free drinks bar. Well actually, &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;all&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; the free drinks bars. Then I made all their free Internet access Terminals look like this:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/desktop_hijack-741104.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/desktop_hijack-741100.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Aside from tales of lost luggage, some of them linked to the BA287 flight &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.vitalsecurity.org/2008/04/flight-ba-287-i-knew-this-was-wrong-day.html"&gt;writeup&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; from the week before, so I'm sure they appreciated that too. In fact, I made sure lots of articles like &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://robnewby.blogspot.com/2008/04/just-when-you-thought-it-was-safe-to-go.html"&gt;this&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;, &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.prevx.com/blog/86/Prevx-off-to-RSA--Well-kind-of.html"&gt;this&lt;/a&gt; and &lt;a style="font-family: verdana;" href="http://community.zdnet.co.uk/blog/0,1000000567,2000331828b,00.htm"&gt;this&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; were popping up all over their desktops. Enjoy, BA, enjoy. It's all for you, baby.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I finally arrived home God knows how many hours after the whole shambles started, and can't say I was surprised to see a pile of people stuck at my final destination asking where their luggage had gone:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.vitalsecurity.org/uploaded_images/bags_gone_again-713252.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.vitalsecurity.org/uploaded_images/bags_gone_again-713249.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Someone at British Airways needs a good kick to the face. A sustained and brutal beating, actually. Cries of "Don't Taze me, bro" will only have the exact opposite effect. Not only will I never fly with them again, I'm happily going to &lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt;encourage&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; people not to fly with them either.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;You should too.&lt;/span&gt;</description><link>http://www.vitalsecurity.org/2008/04/british-airways-redefining-sucktastic.html</link><author>paperghost</author></item></channel></rss>