<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Piet Bos dot ME &#187; incidents</title>
	<atom:link href="http://pietbos.me/category/incidents/feed/" rel="self" type="application/rss+xml" />
	<link>http://pietbos.me</link>
	<description>recently returned to Beijing, China from a 2yr break in Valencia, Spain</description>
	<lastBuildDate>Mon, 30 Jan 2012 19:53:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>petty crime in Valencia during Fallas</title>
		<link>http://pietbos.me/incidents/petty-crime-valencia-fallas-239/</link>
		<comments>http://pietbos.me/incidents/petty-crime-valencia-fallas-239/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 13:05:38 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[incidents]]></category>
		<category><![CDATA[Las Fallas]]></category>
		<category><![CDATA[life in Valencia]]></category>
		<category><![CDATA[bullfight]]></category>
		<category><![CDATA[camera]]></category>
		<category><![CDATA[Chinese]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[fallas]]></category>
		<category><![CDATA[pictures]]></category>
		<category><![CDATA[thief]]></category>
		<category><![CDATA[Valencia]]></category>

		<guid isPermaLink="false">http://pietbos.me/?p=239</guid>
		<description><![CDATA[petty crime sees a sharp rise in Valencia during the Fallas]]></description>
			<content:encoded><![CDATA[<p>This post was meant to have some pictures of the fallas that are erected throughout the city.</p>
<p>However my brand-new camera got stolen yesterday while I was having drinks with Ivan and his father-in-law.</p>
<p>It was &#8220;fished&#8221; right out of the pocket of my coat that was hanging over my chair. The thief actually &#8220;did&#8221; both my pockets as the map in my other pocket also was gone. Pure opportunism.</p>
<p>One of the staff of Lisboa, the bar where it happened, told us that petty crime like this sees a sharp rise in Valencia during the Fallas. </p>
<p>As Mia put it: &#8220;po cai mian zai&#8221;, an old Chinese saying that means something like when you lose fortune, you avoid disaster.</p>
<p>Because I bought tickets for our first bullfight for tomorrow, I will have to buy a new camera today <img src='http://pietbos.me/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://pietbos.me/incidents/petty-crime-valencia-fallas-239/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>malware notification Beijing Day Trips</title>
		<link>http://pietbos.me/web-stuff/malware-notification-beijing-day-trips-229/</link>
		<comments>http://pietbos.me/web-stuff/malware-notification-beijing-day-trips-229/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 03:21:05 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[gadgets]]></category>
		<category><![CDATA[incidents]]></category>
		<category><![CDATA[web stuff]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[work]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Beijing Day Trips]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[CCleaner]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[Filezilla]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[footer.php]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Search Quality Team]]></category>
		<category><![CDATA[hard copy]]></category>
		<category><![CDATA[help desk]]></category>
		<category><![CDATA[IP]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malwarebytes' Anti-Malware]]></category>
		<category><![CDATA[MySQL]]></category>
		<category><![CDATA[Namecheap]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[plugins]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[shell access]]></category>
		<category><![CDATA[source code]]></category>
		<category><![CDATA[Spybot Search & Destroy]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[WinSCP]]></category>
		<category><![CDATA[Yahoo! Counter starts]]></category>

		<guid isPermaLink="false">http://pietbos.me/?p=229</guid>
		<description><![CDATA[Yesterday I was unpleasantly surprised to receive an email from the Google Search Quality Team sent to all possible email addresses for the domain; the subject line read Malware notification...]]></description>
			<content:encoded><![CDATA[<p>Although I do not really do an awful lot with <a href="http://www.beijingdaytrips.com">Beijing Day Trips</a> anymore, the site is still online and receives plenty of hits as such. Sometimes people even send me an inquiry and I can help them out.</p>
<p>Yesterday I was unpleasantly surprised to receive an email from the Google Search Quality Team sent to all possible email addresses for the domain beijingdaytrips.com; the subject line read &#8220;Malware notification regarding beijingdaytrips.com&#8221;.<br />
[singlepic=276,320,240,,center]</p>
<p>After reading the vague email, I of course went to check immediately and what I saw was not pleasant: a dark red Google screen that said that the site I was planning to visit was malicious.</p>
<p>In Firefox I disabled the warning message (seems not possible in Chrome, my default browser), so I could have a look at my source code. All the way at the bottom I noticed some sort of code that I certainly hadn&#8217;t put there. It was some Javascript calling &#8220;Yahoo! Counter starts&#8221; and pointing to 2 IP addresses 218.93.202.61/cp/ and 78.110.175.21/cp/. With a quick search I discovered that these IP&#8217;s point to some Russia mafia sites for all kinds of shit you certainly don&#8217;t want on your computer.<br />
[singlepic=277,320,240,,center]</p>
<p>Since the bad code seemed to be in the footer I uploaded the footer again to check if that helped. It didn&#8217;t. I then had a look at the footer.php stored on my computer and saw to my dismay that it actually had changed! That piece of shitty code had been added to my footer.php on my own very computer without my knowledge!!!</p>
<p>Mind you I have a paid security package from AVG that scans my computer each and every day.</p>
<p>So I deleted the malicious code, uploaded the clean file and had another look in the source code. Huh? Shitty code was still there! Time to contact the help desk of <a href="http://www.namecheap.com">Namecheap</a>. Their first response was that they could not help with Google warnings, but after explaining again they started to think with me.</p>
<p>Now, 36 hours later, the site is up and running again, <del datetime="2009-03-05T11:05:07+00:00">although the Google warning still has to be removed. My best guess is that disabling the warning will take longer than them enabling it in the first place, but so be it</del> <strong>UPDATE March 5 noon-time:</strong> site is back into safety zone, wonderful to see that they white-list as fast as blacklist!. A safer internet is what we all want, right?</p>
<p>If you would like to know how I eventually got rid of the malicious code, please read along.<br />
<span id="more-229"></span></p>
<p>Since uploading a clean footer.php didn&#8217;t help, I deleted all theme-files and re-uploaded clean ones: no positive results.</p>
<p>Then I deleted the entire <a href="http://wordpress.org">WordPress</a> installation and uploaded it again, while I was at it, also upgraded to the latest version. Again, no positive results. </p>
<p>I had <a href="http://www.ccleaner.com/">CCleaner</a>, <a href="http://www.safer-networking.org/en/spybotsd/index.html">Spybot Search &#038; Destroy</a> and AVG run full system checks. This afternoon I added another paid program: <a href="http://www.malwarebytes.org/">Malwarebytes&#8217; Anti-Malware</a>. Spybot and CCleaner came up with the usual entries, nothing to worry about and certainly nothing that pointed even remotely in the direction of this &#8220;Yahoo! Counter starts&#8221;. The full computer scan of AVG also didn&#8217;t turn up anything, so now it was down to Malwarebytes&#8217; Anti-Malware to come up with something, otherwise it would have been EUR 25 down the drain&#8230;</p>
<p>It did actually find 11 malicious entries that I quarantined and deleted! Makes you wonder why the other 3 cannot pick up on that&#8230;</p>
<p>Since the malicious piece of code had been able to add stuff to my files, search through my entire computer to extract FTP login details, use Filezilla without causing any alarmbells to go off and upload the edited files to my server, I was not taking any risks anymore.</p>
<p>I changed all passwords and deleted all my existing FTP-accounts. I printed out a list of all my existing passwords (email, MySQL, WordPress login, etc.) and deleted them permanently from my computer. The only safe place is a hard copy (i.e. a paper with all this info) and you just gotta hope that you won&#8217;t lose it!</p>
<p>In the meantime the help desk had been checking the entire site on their end too and eventually told me that it had to be the databases. They had checked them but couldn&#8217;t find anything. Of course I could delete them and use an old backup to restore them in another clean WordPress install, but I first wanted to try out something else.</p>
<p>I made a list of all installed plugins and then deleted them all from the server. I checked the site and&#8230;. the malicious code was gone! <img src='http://pietbos.me/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> , yup my first happy face.</p>
<p>I then downloaded all fresh (and therefore clean) versions of the plugins. Now I needed a secure FTP, so I did a search and came up with <a href="http://winscp.net/eng/index.php">WinSCP</a>. To enable it I needed to set up shell access on my cPanel and generate a public and a private key. Also Namecheap needed to enable shell access for me on their side and when that was done (and I had to write down another long password on my hard copy) I could start uploading all fresh plugins again.</p>
<p>It is now 2 hours ago that my site is clean again and I immediately requested Google and <a href="http://www.stopbadware.org">StopBadware</a> to review my site.</p>
<p>The good thing about this experience is that I never even knew that FTP was so unsafe and that I now have Secure FTP access to my sites. With the private encrypted key, it will take a very long time for any type of software to do a &#8220;guess attack&#8221; on what it possibly could be.</p>
<p>I also learned that although Namecheap has not offered hosting for a very long time, they certainly make their customers feel safe in their hands. They literally have been doing anything in their power to solve this serious problem. The people that man their help desk are very valuable to the success of the organisation, something my old host could learn quite a bit from&#8230;</p>
<p>Namecheap Help Desk and in particular Evgeniy Z, thanks for all your support!</p>
<p><!--BEGIN NAMECHEAP LINK --></p>
<div align="center">
<a href="http://www.namecheap.com/?aid=88&#038;rid="><br />
<img src="//files.namecheap.com/graphics/linkus/468x60-1.gif" height="60" width="468" border="0" alt="Domain name registration at namecheap.com for $9.69"></a></div>
<p><!--END NAMECHEAP LINK --></p>
]]></content:encoded>
			<wfw:commentRss>http://pietbos.me/web-stuff/malware-notification-beijing-day-trips-229/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>rolling truck</title>
		<link>http://pietbos.me/incidents/rolling-truck-88/</link>
		<comments>http://pietbos.me/incidents/rolling-truck-88/#comments</comments>
		<pubDate>Sun, 26 Aug 2007 09:38:44 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[incidents]]></category>

		<guid isPermaLink="false">http://www.senlinonline.com/snippets/2007/08/rolling-truck/</guid>
		<description><![CDATA[Today I went with a friend to see some houses for my homestay project in the area of the airport and while we were waiting for the bus back to downtown an accident happened 100 meters from where we were standing. A truck with a concrete mill was driving way too fast over a crossing [...]]]></description>
			<content:encoded><![CDATA[<p>Today I went with a friend to see some houses for my <a href="http://www.homestaybeijing2008.com">homestay project</a> in the area of the airport and while we were waiting for the bus back to downtown an accident happened 100 meters from where we were standing.</p>
<p>A truck with a concrete mill was driving way too fast over a crossing and it seemed that the driver tried to evade a car. We were standing on a side road, so couldn&#8217;t really see what happened, but we did see the truck rolling over the crossing. Since our bus was arriving we didn&#8217;t have the time for a closer look, so I could only take a picture of the result from the bus. I did do some color adjustments as the photo was a bit too dark to actually see the truck lying on it&#8217;s side.</p>
<p align="center"> <img src="http://www.senlinonline.com/snippets/wp-content/uploads/070826.jpg" title="rolling truck" alt="rolling truck" height="300" width="400" /></p>
]]></content:encoded>
			<wfw:commentRss>http://pietbos.me/incidents/rolling-truck-88/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Served from: pietbos.me @ 2012-02-07 10:18:54 -->
