<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Saiweb &#187; Uncategorized</title>
	<atom:link href="http://www.saiweb.co.uk/category/uncategorized/feed" rel="self" type="application/rss+xml" />
	<link>http://www.saiweb.co.uk</link>
	<description>Ramblings of a Sys admin</description>
	<lastBuildDate>Mon, 06 Feb 2012 14:57:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Name and shame volume 1 82.98.131.66</title>
		<link>http://www.saiweb.co.uk/uncategorized/name-and-shame-volume-1-82-98-131-66</link>
		<comments>http://www.saiweb.co.uk/uncategorized/name-and-shame-volume-1-82-98-131-66#comments</comments>
		<pubDate>Tue, 12 Jul 2011 09:00:49 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/?p=1023</guid>
		<description><![CDATA[So I&#8217;ve decided to start some name and shame posts for &#8220;naughty&#8221; ip&#8217;s that trip an ids, turn up in my log audits etc &#8230; and who are woefully ill prepared &#8230; Dear 82.98.131.66, This post is for you, I&#8217;m not sure what you hope to gain by failing repeatedly to gain access to this [...]]]></description>
			<content:encoded><![CDATA[<p>So I&#8217;ve decided to start some name and shame posts for &#8220;naughty&#8221; ip&#8217;s that trip an ids, turn up in my log audits etc &#8230; and who are woefully ill prepared &#8230;</p>
<p>Dear 82.98.131.66,</p>
<p>This post is for you, I&#8217;m not sure what you hope to gain by failing repeatedly to gain access to this blog (god knows I hardly have time to update it &#8230;) but doing it from a host with all your ports open probably not the best idea in the world, so here&#8217;s some information on you.</p>
<p>And for anyone else reading this, I usually end up ignoring the standard user enumeration and brute force attacks (As the offender get blacklisted very quickly), in this case however it was a targeted attempt &#8230;</p>
<p><strong>Your ISP&#8217;s whois</strong></p>
<div class="codecolorer-container text default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;height:300px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br />17<br />18<br />19<br />20<br />21<br />22<br />23<br />24<br />25<br />26<br />27<br />28<br />29<br />30<br />31<br />32<br />33<br />34<br />35<br />36<br />37<br />38<br />39<br />40<br />41<br />42<br />43<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">inetnum: &nbsp; &nbsp; &nbsp; &nbsp;82.98.128.0 - 82.98.143.255<br />
netname: &nbsp; &nbsp; &nbsp; &nbsp;DINA-HOSTING1<br />
descr: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;PROVIDER Local Registry<br />
descr: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Dinahosting S.L.<br />
country: &nbsp; &nbsp; &nbsp; &nbsp;ES<br />
admin-c: &nbsp; &nbsp; &nbsp; &nbsp;RB1624-RIPE<br />
tech-c: &nbsp; &nbsp; &nbsp; &nbsp; EP2912-RIPE<br />
status: &nbsp; &nbsp; &nbsp; &nbsp; ASSIGNED PA<br />
mnt-by: &nbsp; &nbsp; &nbsp; &nbsp; DINAHOSTING-MNT<br />
mnt-lower: &nbsp; &nbsp; &nbsp;DINAHOSTING-MNT<br />
mnt-routes: &nbsp; &nbsp; DINAHOSTING-MNT<br />
source: &nbsp; &nbsp; &nbsp; &nbsp; RIPE # Filtered<br />
<br />
person: &nbsp; &nbsp; &nbsp; &nbsp; Ruben Bouso<br />
address: &nbsp; &nbsp; &nbsp; &nbsp;Rua das Salvadas, 41<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 15705 - Santiago de Compostela<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Spain<br />
phone: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;+34900854000<br />
fax-no: &nbsp; &nbsp; &nbsp; &nbsp; +34981577449<br />
e-mail: &nbsp; &nbsp; &nbsp; &nbsp; <span class="mh-email"><a href='http://www.google.com/recaptcha/mailhide/d?k=01zJpju87KejH2_v9OHtypaA==&amp;c=HB--0ELSvSHklS6olocUz6KQYH32Nn2J6xyVLGkRFIE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01zJpju87KejH2_v9OHtypaA==&amp;c=HB--0ELSvSHklS6olocUz6KQYH32Nn2J6xyVLGkRFIE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="This email is protected with reCaptcha, please click the link to retrieve the email">HIDDEN EMAIL</a></span><br />
nic-hdl: &nbsp; &nbsp; &nbsp; &nbsp;RB1624-RIPE<br />
mnt-by: &nbsp; &nbsp; &nbsp; &nbsp; DINAHOSTING-MNT<br />
source: &nbsp; &nbsp; &nbsp; &nbsp; RIPE # Filtered<br />
<br />
person: &nbsp; &nbsp; &nbsp; &nbsp; Eladio Perez<br />
address: &nbsp; &nbsp; &nbsp; &nbsp;Rua das Salvadas, 41<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 15705 - Santiago de Compostela<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Spain<br />
phone: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;+34 900854000<br />
e-mail: &nbsp; &nbsp; &nbsp; &nbsp; <span class="mh-email"><a href='http://www.google.com/recaptcha/mailhide/d?k=01zJpju87KejH2_v9OHtypaA==&amp;c=fsozJ61fFJyzTOBR8MlRE5YlsG_ApnCLA3yiIW92UZE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01zJpju87KejH2_v9OHtypaA==&amp;c=fsozJ61fFJyzTOBR8MlRE5YlsG_ApnCLA3yiIW92UZE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="This email is protected with reCaptcha, please click the link to retrieve the email">HIDDEN EMAIL</a></span><br />
nic-hdl: &nbsp; &nbsp; &nbsp; &nbsp;EP2912-RIPE<br />
mnt-by: &nbsp; &nbsp; &nbsp; &nbsp; DINAHOSTING-MNT<br />
source: &nbsp; &nbsp; &nbsp; &nbsp; RIPE # Filtered<br />
<br />
% Information related to '82.98.128.0/18AS42612'<br />
<br />
route: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 82.98.128.0/18<br />
descr: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; First Dinahosting S.L. prefix<br />
origin: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;AS42612<br />
mnt-by: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;DINAHOSTING-MNT<br />
mnt-lower: &nbsp; &nbsp; &nbsp; DINAHOSTING-MNT<br />
mnt-routes: &nbsp; &nbsp; &nbsp;DINAHOSTING-MNT<br />
source: &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;RIPE # Filtered</div></td></tr></tbody></table></div>
<p><strong>Log of you attempting to get access to ftp</strong></p>
<div class="codecolorer-container text default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;height:300px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br />17<br />18<br />19<br />20<br />21<br />22<br />23<br />24<br />25<br />26<br />27<br />28<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">Jun 12 20:02:45 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=15007 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=5840 RES=0x00 SYN URGP=0 <br />
Jun 12 20:02:45 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=15008 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:45 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=15009 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:45 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=65 TOS=0x00 PREC=0x00 TTL=56 ID=15010 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:45 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=65 TOS=0x00 PREC=0x00 TTL=56 ID=15011 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=58 TOS=0x00 PREC=0x00 TTL=56 ID=15012 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=15013 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=92 RES=0x00 ACK FIN URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=48056 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=5840 RES=0x00 SYN URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=15014 DF PROTO=TCP SPT=58291 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=48057 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=48058 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=65 TOS=0x00 PREC=0x00 TTL=56 ID=48059 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:48 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=69 TOS=0x00 PREC=0x00 TTL=56 ID=48060 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=58 TOS=0x00 PREC=0x00 TTL=56 ID=48061 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=48062 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=92 RES=0x00 ACK FIN URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=18719 DF PROTO=TCP SPT=58295 DPT=21 WINDOW=5840 RES=0x00 SYN URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=48063 DF PROTO=TCP SPT=58293 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=18720 DF PROTO=TCP SPT=58295 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=52 TOS=0x00 PREC=0x00 TTL=56 ID=18721 DF PROTO=TCP SPT=58295 DPT=21 WINDOW=92 RES=0x00 ACK URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=69 TOS=0x00 PREC=0x00 TTL=56 ID=18722 DF PROTO=TCP SPT=58295 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:51 132 kernel: IN=eth0 OUT= MAC=**:**:**:**:**:**:00:13:5f:94:18:00:08:00 SRC=82.98.131.66 DST=81.201.132.43 LEN=65 TOS=0x00 PREC=0x00 TTL=56 ID=18723 DF PROTO=TCP SPT=58295 DPT=21 WINDOW=92 RES=0x00 ACK PSH URGP=0 <br />
Jun 12 20:02:52 132 fail2ban.actions: WARNING [vsftpd-iptables] Ban 82.98.131.66<br />
Jun 12 20:32:53 132 fail2ban.actions: WARNING [vsftpd-iptables] Unban 82.98.131.66<br />
...<br />
Jun 12 20:02:46 132 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=saiweb rhost=hl45.dinaserver.com &nbsp;user=saiweb<br />
Jun 12 20:02:48 132 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=saiweb rhost=hl45.dinaserver.com &nbsp;user=saiweb<br />
Jun 12 20:02:51 132 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=saiwebcouk rhost=hl45.dinaserver.com <br />
...</div></td></tr></tbody></table></div>
<p><strong>Can anyone say firewall?</strong></p>
<div class="codecolorer-container text default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">21/tcp &nbsp; open &nbsp;ftp<br />
22/tcp &nbsp; open &nbsp;ssh<br />
25/tcp &nbsp; open &nbsp;smtp<br />
53/tcp &nbsp; open &nbsp;domain<br />
80/tcp &nbsp; open &nbsp;http<br />
110/tcp &nbsp;open &nbsp;pop3<br />
143/tcp &nbsp;open &nbsp;imap<br />
443/tcp &nbsp;open &nbsp;https<br />
587/tcp &nbsp;open &nbsp;submission<br />
3306/tcp open &nbsp;mysql</div></td></tr></tbody></table></div>
<p><strong>You need to read <a href="http://www.saiweb.co.uk/security/cloaking-your-web-apps-the-hooded-apache">this</a> NOW!</strong></p>
<div class="codecolorer-container text default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">Server: Apache/2.2.0 (Fedora) PHP/5.2.9 with Suhosin-Patch<br />
Content-Length: 226<br />
Connection: close<br />
Content-Type: text/html; charset=iso-8859-1</div></td></tr></tbody></table></div>
<p><strong>Debian? seriously?</strong></p>
<div class="codecolorer-container text default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">SSH-2.0-OpenSSH_5.1p1 Debian-5</div></td></tr></tbody></table></div>
<p><strong>mySQL seems recent at least</strong></p>
<div class="codecolorer-container text default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">5.1.32-log?yV!&gt;VvoI?^~&quot;(D\$::QjC^C</div></td></tr></tbody></table></div>
<p>For the moment I am assuming a compromised box quiet why you wanted to come after this blog is beyond me.</p>
<ol>
<li>12/06/2011 &#8211; This blog written and evidence sent to ISP</li>
<li>12/07/2011 &#8211; The Scheduled publication for this post</li>
</ol>
<p><span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/name-and-shame-volume-1-82-98-131-66" data-text="Name and shame volume 1 82.98.131.66" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fname-and-shame-volume-1-82-98-131-66&#038;text=Name%20and%20shame%20volume%201%2082.98.131.66" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/name-and-shame-volume-1-82-98-131-66/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress Flowplayer subject of a study</title>
		<link>http://www.saiweb.co.uk/uncategorized/wordpress-flowplayer-subject-of-a-study</link>
		<comments>http://www.saiweb.co.uk/uncategorized/wordpress-flowplayer-subject-of-a-study#comments</comments>
		<pubDate>Thu, 04 Feb 2010 11:40:02 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[study]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/?p=824</guid>
		<description><![CDATA[I was a bit taken back today after stumbling across this pdf by Dr. Wolf-Fritz Riekert http://share.ieservices.de/downloads/documents/Wordpress_Flowplayer_Plugin_pash-m_recent_version.pdf Google translated version Seems my plugin and the code therein has been the subject of a study, after perusing the google translation of the document I can see some very interesting concepts on how to improve the plugins [...]]]></description>
			<content:encoded><![CDATA[<p>I was a bit taken back today after stumbling across this pdf by Dr. Wolf-Fritz Riekert <a href="http://share.ieservices.de/downloads/documents/Wordpress_Flowplayer_Plugin_pash-m_recent_version.pdf">http://share.ieservices.de/downloads/documents/Wordpress_Flowplayer_Plugin_pash-m_recent_version.pdf</a></p>
<p><a href="http://translate.google.co.uk/translate?hl=en&#038;sl=de&#038;u=http://share.ieservices.de/downloads/documents/Wordpress_Flowplayer_Plugin_pash-m_recent_version.pdf&#038;ei=EqtqS5qpI8mPjAeyq-3MBw&#038;sa=X&#038;oi=translate&#038;ct=result&#038;resnum=5&#038;ved=0CBwQ7gEwBDgK&#038;prev=/search%3Fq%3Dd.busby%2540saiweb.co.uk%26hl%3Den%26client%3Dfirefox-a%26rls%3Dorg.mozilla:en-US:official%26hs%3DeTf%26sa%3DN%26start%3D10"><br />
Google translated version</a></p>
<p>Seems my plugin and the code therein has been the subject of a study, after perusing the google translation of the document I can see some very interesting concepts on how to improve the plugins integration with wordpress itself, I have sent an email Dr. Wolf-Fritz Riekert, asking if I can take his concepts and apply them to my code, so have a read and check back for version 2.1.0.0 soon, </p>
<p>Also of note the authors at <a href="http://Flowplayer.org">Flowplayer.org</a> have also granted me permission to use the latest verison of flowplayer, this will be rolled into 2.1.0.0</p>
<p>Remember to request features please use my <a href="http://trac.saiweb.co.uk/saiweb/">Trac system</a>.</p>
<p><strong>Update:</strong>Dr. Wolf-Fritz Riekert has gotten back to me, this study is in fact the work of a group of students, the project leader of which was Martin Wörz, of <a href="http://ieservices.de">ieservices.de</a>, I&#8217;ll be liaising with him over the concepts in the study.</p>
<p><span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/wordpress-flowplayer-subject-of-a-study" data-text="WordPress Flowplayer subject of a study" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fwordpress-flowplayer-subject-of-a-study&#038;text=WordPress%20Flowplayer%20subject%20of%20a%20study" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/wordpress-flowplayer-subject-of-a-study/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>/bin/sh: bad interpreter</title>
		<link>http://www.saiweb.co.uk/uncategorized/bin-sh-bad-interpreter</link>
		<comments>http://www.saiweb.co.uk/uncategorized/bin-sh-bad-interpreter#comments</comments>
		<pubDate>Mon, 01 Feb 2010 11:41:58 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[bad]]></category>
		<category><![CDATA[interpreter]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[php]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/?p=816</guid>
		<description><![CDATA[For security newer distros of RHEL and their derivatives an mounting /tmp with the noexec option. Now if you have ever had to clean up a compromised web app you can see why this makes a lot of sense, and if not here&#8217;s a quick example. Yours/Clients web app becomes compromised, running kernel has a [...]]]></description>
			<content:encoded><![CDATA[<p>For security newer distros of RHEL and their derivatives an mounting /tmp with the noexec option.</p>
<p>Now if you have ever had to clean up a compromised web app you can see why this makes a lot of sense, and if not here&#8217;s a quick example.</p>
<p>Yours/Clients web app becomes compromised, running kernel has a buffer overflow that can lead to privilege escalation, attack writes out their code and compiles in /tmp, then runs said app from /tmp creating a pseudo root level shell, aka you&#8217;ve just been root kitted.</p>
<p>However there are legitimate reasons for using /tmp to compile, well I say legitimate, what I in fact mean is things like pecl, which you use to install extensions like APC require this &#8230;</p>
<p>workaround:</p>
<div class="codecolorer-container bash default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br /></div></td><td><div class="bash codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #7a0874; font-weight: bold;">export</span> <span style="color: #007800;">TMPDIR</span>=<span style="color: #ff0000;">'/a/paTh/your/user/can/write/to'</span></div></td></tr></tbody></table></div>
<p>Failing that:</p>
<p><strong>service httpd stop</strong></p>
<p><strong>DO NOT ALLOW ANY WEBAPP ACCESS WHILE NOEXEC IS IN USE!</strong></p>
<div class="codecolorer-container bash default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br /></div></td><td><div class="bash codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #c20cb9; font-weight: bold;">mount</span> -o,remount,rw,<span style="color: #7a0874; font-weight: bold;">exec</span> <span style="color: #000000; font-weight: bold;">/</span>tmp<br />
pecl <span style="color: #c20cb9; font-weight: bold;">install</span> apc<br />
<span style="color: #c20cb9; font-weight: bold;">mount</span> -o,remount,rw,noexec <span style="color: #000000; font-weight: bold;">/</span>tmp</div></td></tr></tbody></table></div>
<p><strong>DO NOT REMOVE THE NOEXEC OPTION IN /ETC/FSTAB PERMANENTLY YOU WILL REGRET DOING SO</strong><span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/bin-sh-bad-interpreter" data-text="/bin/sh: bad interpreter" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fbin-sh-bad-interpreter&#038;text=%2Fbin%2Fsh%3A%20bad%20interpreter" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/bin-sh-bad-interpreter/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache 2.2.3 dual extention vulnerability</title>
		<link>http://www.saiweb.co.uk/uncategorized/apache-2-2-3-dual-extention-vulnerability</link>
		<comments>http://www.saiweb.co.uk/uncategorized/apache-2-2-3-dual-extention-vulnerability#comments</comments>
		<pubDate>Tue, 05 Jan 2010 11:33:17 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[537535]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[dual extension]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/?p=802</guid>
		<description><![CDATA[Redhat bug 537535 Take for instance this code saved as test.php.png 123&#60;?PHP print_r&#40;$_POST&#41;; ?&#62; Low and behold this will render out the entire post array! and will interpret the php itself, now lets be clear here the proper use of selinux and directory structures to prevent UGC from being allowed to be access directly and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="https://bugzilla.redhat.com/show_bug.cgi?id=537535">Redhat bug 537535</a></p>
<p>Take for instance this code saved as test.php.png</p>
<div class="codecolorer-container php default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br /></div></td><td><div class="php codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #000000; font-weight: bold;">&lt;?PHP</span><br />
<a href="http://www.php.net/print_r"><span style="color: #990000;">print_r</span></a><span style="color: #009900;">&#40;</span><span style="color: #000088;">$_POST</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span><br />
<span style="color: #000000; font-weight: bold;">?&gt;</span></div></td></tr></tbody></table></div>
<p>Low and behold this will render out the entire post array! and will interpret the php itself, now lets be clear here the proper use of selinux and directory structures to prevent UGC from being allowed to be access directly and / or run arbitrary code would of prevented this, however as is often the case the setup is such that the preventative conditions could not / are not deployed.</p>
<p>At any rate this bug comes courtesy of the apache AddHandler directive,</p>
<div class="codecolorer-container bash default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br /></div></td><td><div class="bash codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">AddHandler x-httpd-php .php</div></td></tr></tbody></table></div>
<p>The statement above seems to &#8216;loose&#8217; match the .php extension meaning a file simply only contain .php anywhere in it&#8217;s filename to be interpreted as PHP.</p>
<p>The suggested work around for this is as follows:</p>
<div class="codecolorer-container bash default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br /></div></td><td><div class="bash codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #666666; font-style: italic;">#Workaround for bug here: https://bugzilla.redhat.com/show_bug.cgi?id=537535</span><br />
<span style="color: #000000; font-weight: bold;">&lt;</span>FilesMatch \.php$<span style="color: #000000; font-weight: bold;">&gt;</span><br />
SetHandler x-httpd-php<br />
ForceType text<span style="color: #000000; font-weight: bold;">/</span>html<br />
<span style="color: #000000; font-weight: bold;">&lt;/</span>FilesMatch<span style="color: #000000; font-weight: bold;">&gt;</span></div></td></tr></tbody></table></div>
<p>Note this does not effect the AddType directive, after testing on the same version using:</p>
<div class="codecolorer-container bash default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br /></div></td><td><div class="bash codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">AddType application<span style="color: #000000; font-weight: bold;">/</span>x-httpd-php .php</div></td></tr></tbody></table></div>
<p>Is not effected by this &#8216;bug&#8217;.</p>
<p><span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/apache-2-2-3-dual-extention-vulnerability" data-text="Apache 2.2.3 dual extention vulnerability" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fapache-2-2-3-dual-extention-vulnerability&#038;text=Apache%202.2.3%20dual%20extention%20vulnerability" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/apache-2-2-3-dual-extention-vulnerability/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>blocked by spambag.org</title>
		<link>http://www.saiweb.co.uk/uncategorized/blocked-by-spambag-org</link>
		<comments>http://www.saiweb.co.uk/uncategorized/blocked-by-spambag-org#comments</comments>
		<pubDate>Fri, 10 Jul 2009 15:45:40 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/?p=694</guid>
		<description><![CDATA[spambag.org domain appears to have not been renewed as such it is sat at a generic &#8216;adverts&#8217; placeholder. This does mean that RBL lookups against blacklist.spambag.org are returning as a &#8216;false positive&#8217;, (similar to the ORDB issue) If you are concerned about being listed on some RBL&#8217;s then get a copy of my sysadmin script [...]]]></description>
			<content:encoded><![CDATA[<p>spambag.org domain appears to have not been renewed as such it is sat at a generic &#8216;adverts&#8217; placeholder.</p>
<p>This does mean that RBL lookups against blacklist.spambag.org are returning as a &#8216;false positive&#8217;, (similar to the <a href="http://www.saiweb.co.uk/windows/blocked-by-ordb">ORDB</a> issue)</p>
<p>If you are concerned about being listed on some RBL&#8217;s then get a copy of my sysadmin script <a href="http://www.saiweb.co.uk/sysadmin">here</a> at the time of writing the &#8216;rblcheck&#8217; function checks 27 RBL&#8217;s.</p>
<p><span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/blocked-by-spambag-org" data-text="blocked by spambag.org" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fblocked-by-spambag-org&#038;text=blocked%20by%20spambag.org" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/blocked-by-spambag-org/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jing PRO MP4 quality issue</title>
		<link>http://www.saiweb.co.uk/uncategorized/jing-pro-mp4-quality-issue</link>
		<comments>http://www.saiweb.co.uk/uncategorized/jing-pro-mp4-quality-issue#comments</comments>
		<pubDate>Thu, 08 Jan 2009 13:55:52 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ffmpeg]]></category>
		<category><![CDATA[jing]]></category>
		<category><![CDATA[mp4]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/uncategorized/jing-pro-mp4-quality-issue</guid>
		<description><![CDATA[Ok I purchased Jing PRO to do some more video posts to saiweb &#8230; unfortunately the MP4 quality is lack luster. WPFP(document).ready(function() { //load player $f("saiweb_39f7d657ee80346bafb318ddd5766c00", "/wp-content/plugins/wordpress-flowplayer/flowplayer/gpl/flowplayer-3.1.5.swf", { plugins: { controls: { sliderGradient: 'none', progressGradient: 'medium', backgroundColor: '#141648', backgroundGradient: 'none', bufferGradient: 'none', opacity:1.0 } }, clip: { url:'http://cdn.saiweb.co.uk/wp-content/uploads/2009/01/jing_mp4_bad.mp4', autoPlay: false, autoBuffering: false }, canvas: { [...]]]></description>
			<content:encoded><![CDATA[<p>Ok I purchased Jing PRO to do some more video posts to saiweb &#8230; unfortunately the MP4 quality is lack luster. </p>
<p><div id="saiweb_e4524c41e1680b716a8227e9f148adcb" style="width:300px; height:179px;"></div><script language="Javascript" type="text/javascript">
	WPFP(document).ready(function() {
		//load player
		$f("saiweb_e4524c41e1680b716a8227e9f148adcb", "/wp-content/plugins/wordpress-flowplayer/flowplayer/gpl/flowplayer-3.1.5.swf", {
				plugins: {
  					 controls: {    					
      					
      					
      					
      					sliderGradient: 'none',
      					progressGradient: 'medium',
      					
      					
      					backgroundColor: '#141648',
      					
      					
      					backgroundGradient: 'none',
      					bufferGradient: 'none',
   						opacity:1.0
   						}
				},
			clip: {
					url:'http://cdn.saiweb.co.uk/wp-content/uploads/2009/01/jing_mp4_bad.mp4',
					autoPlay: false,
       				autoBuffering: false
				},
				canvas: {
					backgroundColor:''
				}})
			});</script>
				</p>
<p>To be honest I&#8217;d rather have a large size MP4 I can run through my own encode (i.e. FFMPEG) and get the quality I want &#8230;</p>
<p>Off goes the email to support &#8230; wooo &#8230;.</p>
<p>NOTE: You may have to watch the vid in fullscreen to view it properly, I have scaled the player down to fit the blog page width.<span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/jing-pro-mp4-quality-issue" data-text="Jing PRO MP4 quality issue" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fjing-pro-mp4-quality-issue&#038;text=Jing%20PRO%20MP4%20quality%20issue" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/jing-pro-mp4-quality-issue/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flowplayer WordPress 2.0.1.0</title>
		<link>http://www.saiweb.co.uk/uncategorized/flowplayer-wordpress-2010</link>
		<comments>http://www.saiweb.co.uk/uncategorized/flowplayer-wordpress-2010#comments</comments>
		<pubDate>Wed, 07 Jan 2009 10:36:35 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[flowplayer]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/uncategorized/flowplayer-wordpress-2010</guid>
		<description><![CDATA[Completion of the milestone listed here: http://trac.saiweb.co.uk/saiweb/milestone/wordpress-flowplayer%202.0.1.0 Means 2.0.1.0 has now been released, so go update and give it a run I have noticed that wordpress has a habit of setting incorrect file permissions on the config file after updating, if you also run into this issue let me know.Tweet]]></description>
			<content:encoded><![CDATA[<p><img src="http://cdn.saiweb.co.uk/wp-content/uploads/2009/01/2009-01-07_1029.png" alt="2009-01-07_1029" title="2009-01-07_1029" width="225" height="81" class="alignleft size-full wp-image-394" /></p>
<p>Completion of the milestone listed here: <a href="http://trac.saiweb.co.uk/saiweb/milestone/wordpress-flowplayer%202.0.1.0">http://trac.saiweb.co.uk/saiweb/milestone/wordpress-flowplayer%202.0.1.0</a></p>
<p>Means 2.0.1.0 has now been released, so go update and give it a run <img src='http://cdn.saiweb.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>I have noticed that wordpress has a habit of setting incorrect file permissions on the config file after updating, if you also run into this issue let me know.<span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/flowplayer-wordpress-2010" data-text="Flowplayer WordPress 2.0.1.0" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fflowplayer-wordpress-2010&#038;text=Flowplayer%20WordPress%202.0.1.0" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/flowplayer-wordpress-2010/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Last Day of Voting!</title>
		<link>http://www.saiweb.co.uk/uncategorized/last-day-of-voting</link>
		<comments>http://www.saiweb.co.uk/uncategorized/last-day-of-voting#comments</comments>
		<pubDate>Tue, 25 Nov 2008 11:07:25 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/uncategorized/last-day-of-voting</guid>
		<description><![CDATA[Today is the last day for votes, so please see the blog entry here: http://www.saiweb.co.uk/general/vote-buzz-for-it-superhero-2008 and vote! Cheers buzzTweet]]></description>
			<content:encoded><![CDATA[<p>Today is the last day for votes, so please see the blog entry here: <a href="http://www.saiweb.co.uk/general/vote-buzz-for-it-superhero-2008">http://www.saiweb.co.uk/general/vote-buzz-for-it-superhero-2008</a> and vote!</p>
<p>Cheers</p>
<p>buzz<span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/last-day-of-voting" data-text="Last Day of Voting!" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Flast-day-of-voting&#038;text=Last%20Day%20of%20Voting%21" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/last-day-of-voting/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>One eclipse to rule them all, One eclipse to find them, One eclipse to bring them all, and in dev joy bind them &#8230;</title>
		<link>http://www.saiweb.co.uk/uncategorized/one-eclipse-to-rule-them-all-one-eclipse-to-find-them-one-eclipse-to-bring-them-all-and-in-dev-joy-bind-them</link>
		<comments>http://www.saiweb.co.uk/uncategorized/one-eclipse-to-rule-them-all-one-eclipse-to-find-them-one-eclipse-to-bring-them-all-and-in-dev-joy-bind-them#comments</comments>
		<pubDate>Fri, 31 Oct 2008 10:04:30 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/uncategorized/one-eclipse-to-rule-them-all-one-eclipse-to-find-them-one-eclipse-to-bring-them-all-and-in-dev-joy-bind-them</guid>
		<description><![CDATA[So &#8230; LoTR was obviously on TV a few days ago &#8230; Onto the point, at the moment I am maintaining 2 different installations of eclipse &#8230; one for PHP, C++. Wouldn&#8217;t it be great if I could have both of these in one happy installation? &#8230; Yeh it would however getting all the dependencies [...]]]></description>
			<content:encoded><![CDATA[<p>So &#8230; LoTR was obviously on TV a few days ago &#8230;</p>
<p>Onto the point, at the moment I am maintaining 2 different installations of eclipse &#8230; one for PHP, C++.</p>
<p>Wouldn&#8217;t it be great if I could have both of these in one happy installation? &#8230; Yeh it would however getting all the dependencies is an utter nightmare &#8230; unless you have a program do it for you.</p>
<p>Long story short: http://ondemand.yoxos.com/geteclipse/start</p>
<p>Customize your eclipse before you download it.</p>
<p>(Thanks Austin!)<br /><span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/one-eclipse-to-rule-them-all-one-eclipse-to-find-them-one-eclipse-to-bring-them-all-and-in-dev-joy-bind-them" data-text="One eclipse to rule them all, One eclipse to find them, One eclipse to bring them all, and in dev joy bind them &#8230;" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Fone-eclipse-to-rule-them-all-one-eclipse-to-find-them-one-eclipse-to-bring-them-all-and-in-dev-joy-bind-them&#038;text=One%20eclipse%20to%20rule%20them%20all%2C%20One%20eclipse%20to%20find%20them%2C%20One%20eclipse%20to%20bring%20them%20all%2C%20and%20in%20dev%20joy%20bind%20them%20%26%238230%3B" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/one-eclipse-to-rule-them-all-one-eclipse-to-find-them-one-eclipse-to-bring-them-all-and-in-dev-joy-bind-them/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lowell Portfolio 1 Ltd</title>
		<link>http://www.saiweb.co.uk/uncategorized/lowell-portfolio-1-ltd</link>
		<comments>http://www.saiweb.co.uk/uncategorized/lowell-portfolio-1-ltd#comments</comments>
		<pubDate>Tue, 09 Sep 2008 10:48:20 +0000</pubDate>
		<dc:creator>Buzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Lowell]]></category>
		<category><![CDATA[Lowell Portfolio]]></category>
		<category><![CDATA[Lowell Portfolio 1]]></category>
		<category><![CDATA[Lowell Portfolio 1 Ltd]]></category>
		<category><![CDATA[Red Debt Collection]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[ScotCall]]></category>

		<guid isPermaLink="false">http://www.saiweb.co.uk/uncategorized/lowell-portfolio-1-ltd</guid>
		<description><![CDATA[UPDATE 26/07/09 &#8212;&#8211; READ THIS BEFORE POSTING A COMMENT OR SENDING AN EMAIL THIS PAGE IS PROVIDED FREELY WITH INFORMATION ON HOW TO DISPUTE THE CLAIM AGAINST YOU THIS PAGE IS NOT A REPLACEMENT FOR PROPER LEGAL ADVISE THIS SITE IS IN NO WAY PRESENTLY, NOR EVER HAS BEEN AFFILIATED IN ANY WAY WITH LOWELL [...]]]></description>
			<content:encoded><![CDATA[<p>UPDATE 26/07/09 &#8212;&#8211;</p>
<p><span style="text-decoration: underline;"><span style="color: #ff0000;"><strong>READ THIS BEFORE POSTING A COMMENT OR SENDING AN EMAIL</strong></span></span></p>
<p><span style="text-decoration: underline;"><span style="color: #ff0000;"><strong>THIS PAGE IS PROVIDED FREELY WITH INFORMATION ON HOW TO DISPUTE THE CLAIM AGAINST YOU</strong></span></span></p>
<p><span style="text-decoration: underline;"><span style="color: #ff0000;"><strong>THIS PAGE IS NOT A REPLACEMENT FOR PROPER LEGAL ADVISE</strong></span></span></p>
<p><span style="text-decoration: underline;"><span style="color: #ff0000;"><strong> </strong></span></span></p>
<ul><span style="text-decoration: underline;"><span style="color: #ff0000;"><strong>THIS SITE IS IN NO WAY PRESENTLY, NOR EVER HAS BEEN AFFILIATED IN ANY WAY WITH LOWELL PORTFOLIO</strong> </span></span></ul>
<p><strong> </strong></p>
<p><span style="color: #ff0000;">Sorry for the excessive use of bold and caps, however some people just are not getting the message, and I am getting emails / comments (<strong>some with very colourful language I might add</strong>) from people thinking this is Lowells website &#8230; it is not now was it ever nor will it ever be, this POST was made because I am in the same &#8220;boat&#8221; as you disputing my claim</span></p>
<p><span style="color: #ff0000;"><span style="text-decoration: underline;"><strong>&#8212; Update 05/01/2009, seems people are not getting the message so I have made this text bright red </strong></span></span></p>
<p>END UPDATE 26/07/09 &#8212;&#8211;</p>
<h1><span style="color: #0000ff;"><strong>UPDATE 18/02/2011</strong>: I am now getting several emails a week from people who are not reading the header of this post, </span></h1>
<h1><span style="color: #0000ff;">I will start a &#8220;wall of shame&#8221; for those people very shortly, DO NOT be among them &#8230; </span></h1>
<p>I hate scam artists &#8230; the latest today comes as &#8220;Lowell Portfolio&#8221;, apparently these guys bulk buy &#8220;bad debts&#8221; in the hope of scaring the unlucky sod that is their target into paying them without question, 99% of the time these debts don&#8217;t actualy exist &#8230;</p>
<p>Well I&#8217;m having none of it &#8230;</p>
<ol>
<li>First things first DO NOT TELEPHONE THEM, they will try to extract personal information from you, and attempt you get you to admit to the debt.</li>
<li> Keep and file any letter from them as evidence.</li>
<li> If they do telephone you demand everything in writing and hang up, at no point admit to the debt, it is down to them to provide evidence of the debt, an admission on your part absolves them of any &#8220;burden of proof&#8221;</li>
<li> As posted here: <a href="http://www.moneysupermarket.com/COMMUNITY/forums/t/lowell-portfolio-1-16516.aspx">http://www.moneysupermarket.com/COMMUNITY/forums/t/lowell-portfolio-1-16516.aspx</a> by <a href="http://www.moneysupermarket.com/community/members/boyboynova.aspx">boyboynova</a> respons with the following template letter RECORDED DELIVERY.</li>
</ol>
<p>Response template:</p>
<p>To Whom It May Concern:</p>
<p>Your Reference: xxxx</p>
<p><strong>I DO NOT ACKNOWLEDGE ANY DEBT TO YOUR COMPANY</strong></p>
<p>With reference to the above account, I request that you send me a true copy of this credit agreement before I will correspond further on this matter.</p>
<p>This is my right under the legislation contained within section 77 (1) and section 78 (1) of the Consumer Credit Act 1974, and I am entitled to receive a copy of my credit agreement on request.</p>
<p>Your obligation also extends to providing me with a statement of account. I enclose a £1<br />
postal order, which represents payment of the statutory fee payable under the Consumer Credit Act.</p>
<p>I understand that a copy of my credit agreement should be supplied within 12 working days from the date of this letter.</p>
<p>I understand that under the Consumer Credit Act, creditors are unable to enforce an agreement if they fail to comply with a request for a copy of the agreement under these sections of the Act.</p>
<p>Also, since you are a Debt Collection Agency, I would also ask that you supply a signed true copy of the executed deed of assignment for the above referenced agreement.</p>
<p>This is an obligation, whether you are the original creditor or not, under section 189 of the Consumer Credit Act 1974.</p>
<p><strong>Non-compliance with my request is a criminal offence under the above Act and will result in a report being submitted to the relevant statutory authorities.<br />
In summary, </strong></p>
<p><strong>I DO NOT ACKNOWLEDGE THIS DEBT AND THEREFORE REQUIRE YOU TO SUBSTANTIATE THIS BY PROVIDING THE FOLLOWING DOCUMENTATION BEFORE I CORRESPOND FURTHER:</strong></p>
<p>1.True copy of original credit agreement<br />
2.Statement of account<br />
3.Copy of the executed deed of assignment from (INSERT COMPANY NAME HERE )<br />
4.Fair Processing Notice.</p>
<p>As you are aware, a credit agreement that is not properly documented and signed by the customer is totally unenforceable under the CCA and therefore is a complete defence to any court claim that is issued.</p>
<p>Take note at this stage, that any legal action you may contemplate will be both vigorously defended and contested.</p>
<p>Further to the above, please ensure that any contact by yourselves is made in writing only to the above address. Telephone calls and personal visits will not be accepted and viewed as harassment.</p>
<p>As this account is now in dispute, I would also draw your attention to The Banking Code section 13.6:-</p>
<p>We may give information to the Credit Reference Agencies about personal debts you owe us if:</p>
<p>·The Amount Owed is Not in Dispute.<br />
·The Office of Fair Trading provided a Code of Guidance that is in relation to Debt Collection: OFT 664 Response to consultation paper and final guidance on unfair business practices dated July 2003<br />
Deceptive and/or Unfair Methods-<br />
2.8 Examples of unfair practices are as follows:-<br />
k. Not ceasing collection activity whilst investigating a reasonably queried or disputed debt.</p>
<p>If you continue in your pursuance of this account I will have no other alternative than to report you to both, The Information Commissioner and The Office of Fair Trading.</p>
<p>Furthermore, I shall submit a Consumer Credit Act 1974 complaint to the OFT upon the basis that you have failed to comply with the OFT&#8217;s direction of 5 April 2006 and are therefore not a &#8216;fit and proper person&#8217; to hold a consumer credit license under the 1974 Act.</p>
<p>If you do not understand what this means then seek advice from your legal department.</p>
<p>I look forward to hearing from you within the statutory time limit.</p>
<p>Yours faithfully</p>
<p>&lt;&lt; YOUR NAME HERE &gt;&gt;</p>
<p><strong>UPDATE 14/01/2009:</strong> I have received a letter in the post today from ScotCall Debt Collecting Services, it appears their client Lowell Portfolio 1 LTD has passed the debt onto them for recovery, no doubt in an effort to disgusie the collection as not being for Lowell no doubt due to people fighting and winning cases against them.</p>
<p>After a friendly telephone conversation with one of ScotCall&#8217;s agents I stated  &#8220;my right under the legislation contained within section 77 (1) and section 78 (1) of the Consumer Credit Act 1974, and I am entitled to receive a copy of my credit agreement on request.&#8221; and queries whether this should be in writing to themselves or lowell, the reply came &#8220;No problem Sir, as we only receive your contact details and the debt amount, we will simply pass this account back to our client&#8221;, at which point I thanked the agent and requested confirmation in writing, &#8220;All telephone call are recorded, and you will receive a standard letter detailing this conversation in a couple of days&#8221;.</p>
<p>More updates to come.</p>
<p><strong>UPDATE 26/01/2009: Lowell On Watchdog</strong> http://www.bbc.co.uk/blogs/watchdog/2009/01/the_chase_for_debts_not_always.html</p>
<p><strong>UPDATE 23/07/2009: Claim dropped!</strong> Well I can say after sending this letter via email and a very long discussion on the phone with one of their supervisors, Lowell have said &#8220;They are unable to provide a signed credit agreement&#8221; and that &#8220;Their client in the interest of taking a commercial view, without admitting liability have agreed to clear their claim&#8221;, I have a letter confirming the amount owed is now £0.00<span style="float: left;" ><a class="twitter-share-button"  data-via="Saiweb" data-count="horizontal" data-related="Saiweb:David Busby" data-lang="en" data-url="http://www.saiweb.co.uk/uncategorized/lowell-portfolio-1-ltd" data-text="Lowell Portfolio 1 Ltd" href="http://twitter.com/share?via=Saiweb&#038;count=horizontal&#038;related=Saiweb%3ADavid%20Busby&#038;lang=en&#038;url=http%3A%2F%2Fwww.saiweb.co.uk%2Funcategorized%2Flowell-portfolio-1-ltd&#038;text=Lowell%20Portfolio%201%20Ltd" >Tweet</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saiweb.co.uk/uncategorized/lowell-portfolio-1-ltd/feed</wfw:commentRss>
		<slash:comments>222</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using apc
Database Caching 22/71 queries in 0.208 seconds using apc
Object Caching 1709/1835 objects using apc
Content Delivery Network via Rackspace Cloud Files: cdn.saiweb.co.uk

Served from: www.saiweb.co.uk @ 2012-02-08 18:09:38 -->
