Ear! Ear! Or Not

I’ve picked up yet another ear infection. 🙁
This time the pain isn’t so bad, but yesterday morning it swelled so much it completely closed up. I went to the doctor who gave me some ear drops. But my ear is closed up — they can’t get in! I’ll have to wait to see if they have any affect.
In the meantime the pressure is so much that not only is my hearing reduced, which is frustrating, but I have a constant white noise too.
Now that is very unsettling. Whenever the world around me goes quiet this white noise comes to the fore, its really annoying! And when the rest of the world is making a noise, whilst I can’t hear it directly it’s there in the background contributing to my hearing loss. 🙁

I’m back

I’m back! A simple search for mike on Google has me back at number 7. This just 7 days after I failed to appear in the top 900! I’m back at number 1 for ‘mike little’ too.
Both of these results are with the new URI.
All this thanks to good old Google honouring the 301 return code and some very sophisticated redirection code turning, for example, a request for http://zed1.com/b2/archives/p/986/more/1/c/1/Happy-Birthday-Chloe (my customised b2 SE frendly URIs) into a permanent redirect to WordPress‘ cruft-free URI https://journalized.zed1.com/archives/2003/12/26/happy-birthday-chloe/

PS: I’m still number 1 on MSN at the old URI

Referer Spamming is Back!

It looks like referrer spamming is back and it’s more sophisticated than before.

I normally get a notification email from my stats package whenever I have had 100 visitors to the website. Note that’s 100 real visitors using browsers it doesn’t count crawlers or bots. I normally get two or three a day, I’m running at about 270 unique visitors per day.
I noticed yesterday that I was getting them about every three hours. That’s more than twice the normal rate and I don’t recall anything happening on the site to justify it. I was immediately suspicious and investigated.
On looking at my stats package (I use Power Phlogger) I noticed lots and lots of hits on my home page all with the same referer (an unsavoury site to which I shall not link!).
“Oh!” says I (to myself), they are at it again. “…Wait a minute! They never showed up here before!” And indeed they didn’t. You see I have my stats set up so that you need a browser with JavaScript enabled to log an entry in my stats. That way I get a count of real people and not bots, crawlers, and other automated visitors.
My next thought then, was that someone had come up with a referer spamming script that actually went so far as to decode the page and execute the JavaScript (loading another JavaScript file in the process). Hmmm… not likely really.
A closer look showed me that each visit was from a different IP address too. Again, I know that you can spoof IP addresses and even do it with automation, but then I noticed that some ‘visitors’ had visited the page more than once. In order for Power Phlogger to record that, you have to have accepted the cookie it sent and returned it with subsequent requests. I also saw that the user agent strings were spread across several different versions of Internet Explorer and on several different version of Windows. With different screen resolutions! Finally I saw that several visits seem to have come via legitimate ISP proxy servers.
No-one would write a referer spamming script that sophisticated would they?
The only conclusion I can draw is that this referral spamming is being done via trojan applications (or automated remote control), and is actually controlling Internet Explorer on the victims’ machines.
The implications for this are huge! Referral spamming is minor in comparison to what could be done.
Massive denial of service attacks that are indistinguishable from legitimate visitors? How about all those saved passwords on all those machines. If you have that much control of the victims machine then why not try to visit every single banking site you can think of and try to login. You may as well start with the favourites folder, the victims bank is probably already in there. Imagine someone with Passport configured! I could think of lots and lots more.

The mind boggles at the insecurity of Windows!