2008年11月24日 星期一

網絡的索馬里海盜

索馬里附近海域有海盜專門搶劫油輪,商船,再勒索巨額贖金。
在網絡世界也有這類的海盜,我在前文講過的 makeuseof.com 就是這個例子。網主在他這篇文中進一步講他不是唯一的受害者,最少有另外兩個網站也受到同樣的勒索,而且相信是同一人所為。
事情的發生經過:
1. 幾位受害者都是用 gmail 作為登記 Registrant 的電郵。
2. 那位入侵者似乎用了一個 Gmail 的漏洞 (但大家到現在都未知道是甚麼),進入了受害人的 gmail 戶口,建立了一些非常「毒」的 Filters Rules。例如從 registrar 的電郵會自動轉寄至入侵者的電郵地址。以下的 screen cap 是其中一位受害者的:

3. 入侵者再到 registrar 用 Forget password 的方式改變原有的戶口的資料。跟手將 domain 轉到另一 registrar 的戶口。
4. 勒索金錢。


在提到的上文內有一個 Comment 很有用的 tips ,有用 gmail 登記為網站 registrar 可以參考:

Comment by Brandon Blaylock Subscribed to comments via email
2008-11-22 05:42:05

Here are some very easy ways to ensure the security of your domain.

1. Set your whois email contacts to an administrative email account. Set a very long and complex password on the account and have all email forwarded to your daily use account. Since you do not log into the account and it has a very long and obfuscated password it makes it much more difficult to break into. Also set very random security questions, as sometimes your security questions can be very simple to break. Since the email address listed in the whois database is publicly available it is the prime target for anyone attempting to steal a domain, this practice adds a layer of security, much like root priveledges in a linux environment.

2. Get privacy on your domain. Privacy masks your whois contact information. The less information someone has on your domain, the more difficult it becomes for them to gain control of it. Also be aware that there are services that keep a history of whois information, so this is not a fullproof method of privacy since the information is probably still out there.

3. Keep your registrar(GoDaddy, Moniker, Etc.) email address different than your whois email address. This makes it more difficult for someone to gain direct access to your domains since your account email will not be publicly available.

4. If you are really concerned, pay for a service like Protected Registration at GoDaddy. This service locks down a domain irrevocably. In fact, it makes it almost impossible to transfer even if it’s you that wants do the transferring.

5. Keep alerting on. Most registrars have account options that will send you an email if any registrant information is changed or a domain is unlocked. Make sure it’s turned ON!

6. Call the experts! I have all my domains at GoDaddy and I use Google Apps on over 40 domains. If I need to know something about my account I call the free support and ask them.

2008年11月4日 星期二

MakeUseOf.com 被偷了的 domain

這是一篇值得一看的文章(包括留言),尤其是你從 godaddy.com 買 domain 和用 gmail.com 作為聯絡地址。

http://makeuseof-temporary.blogspot.com/2008/11/real-truth-behind-makeuseofcom-domain.html


後記: 用 blogger.com 寫文的確會增加在 google search 的排名和上榜時間,這文我是 20 分鐘前寫的,用 google search "makeuseof.com" 的中文網頁,已經是排在第一版了。

2008年8月1日 星期五

奧運

「平安奧運」不僅在現實的內地各大城市出現,到處都是搜查,安檢。原來在網絡世界也加強了。

由前天開始,有兩個客報告我說寄往大陸的電郵打回頭。內容類似:


This is the Postfix program at host mail.example.com.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The Postfix program

(expanded from ): host
mail.example.com.cn[123.321.11.70] said: 551 User not local; please try
(in reply to MAIL FROM command)



再登他們的內地電郵伺服器一看,完全沒有有關的 maillog,即以上 error message 是由「中間人」發出的。信件被 intercept 了。最大可能就是 GFW 了。

我跟客人說,看來要過奧運,情況才會改善。

AdWords

今天開始了在 Google AdWords 落廣告。其實應該說是昨天開始的。最初試了鍵入了幾個 keywords。今朝再看報告,完全沒有「展示」過我的廣告。原來我的最高點擊成本太低了。大部份我選的 keywords 都幾貴,最平的都要 HK$1.20/click ,有些要去到 HK$3.00。今天提高了我的成本和加上更多 keywords,過幾小時後再看,開始廣告有 broadcast 出去了。

我使用 Google AdWords 當然希望可以靠廣告增加 Sales ,但也想在這過程中學習 Google AdWords 的使用辦法。坦白講,今天是第二日用,很多功能仍未熟習。我希望用熟之後可以開拓另一門生意 --- Google Adwords 的中介人。我想有得做的。

2008年4月7日 星期一

使用 Google Apps 的問題

今天在某個客戶的 mail queue 發現有幾個以下內容:


BFDDC3060041 3599 Sun Apr 6 22:51:16 MAILER-DAEMON
(host aspmx.l.google.com[209.85.147.27] said: 450-4.2.1 The Gmail user you are trying to contact is receiving mail 450-4.2.1 at a rate that prevents additional messages from being delivered. 450-4.2.1 Please resend your message at a later time. If the user is 450-4.2.1 able to receive mail at that time, your message will be delivered. 450-4.2.1 For more information, please visit 450 4.2.1 http://mail.google.com/support/bin/answer.py?answer=6592 n37si17898359wag.24 (in reply to RCPT TO command))
someuser@somedomain.com


someuser@somedomain.com 當然是我改了的地址。;-)
再看看內容,是一個 Rebound message 的垃圾郵件,someuser@somedomain.com 是一個被利用作為 sender 的受害者。這也是我前文: 巴黎鐵塔 反轉再反轉 所講的情形。
再仔細調查,somedomain.com 是使用 google apps 寄存電郵的。我不知道 Gmail 說: receiving too many messages in a short period of time 是指多少數量,但我的試驗是他整個 domain 暫不能接收了 (因為我在他的網頁找到其他電郵地址) 。
似乎 Google 除了封鎖了人家整個 domain 電郵接收外,沒有一些更積極的處理方式。還是要用 paid service 的 google apps 才有???

PS: 這個受害者的網站是一個政治評論網站。

2008年3月25日 星期二

大不是好

今天下午發生的:


(host imsmx.netvigator.com[218.102.53.61] said: 452 4.4.5 Insufficient disk space; try again later (in reply to MAIL FROM command))

2008年3月13日 星期四

USB 手指大揭示 (2)

長話短說: 各位找尋 USB 手指資訊的可以看看右面的 Google 廣告有沒有,以下內容基本跟 USB 手指無關。如浪費你 Click 入來的時間,請見諒!!


正題

如果閣下是這個網誌的忠實讀者 (希望還有 XD),當然會知道我幾個月也無有貼新文了。原因只有一個字: 懶。無寫當然也沒有留意這個網誌的瀏覽量。上星期心血來潮,登入的 Google Analytics 看看。咦,奇怪了,無寫幾個月,瀏覽量沒有顯著的減少,有些日子甚至是新高。深入些看看,原來有接近 1/3 訪客是看這篇文的: 32GB USB手指大揭示。再看看來源分析,原來是由「USB 手指」這個關鍵字進入的。

自己試試 google search 一下這個「USB 手指」關鍵字。我的天啊,原來在五十多萬個查詢結果中,上述的那篇文是排第一的!!! (無論是 google.com.hk, google.com.tw 和 google.com.cn 搜尋都是)。

奇怪和有點興奮是我第一個感覺,但跟著下來我就想到那些賣 USB 手指的商家應該跟我聯絡,在我這篇文的「某個位置」賣個廣告,成效應該不錯的。當然,Google Adwords 在某方面其實就是做緊我這描述的賣廣告方式。

其實如何落 Google Ad 我覺得絕對是一項專門和要有想像力的工作。舉個例子: 用「陳冠希」做關鍵字搜尋,大家認為可以賣甚麼廣告。不正經的當然是性用品 (不知 Google adwords 是否接受),正經的是賣「USB 加密手指」。我留意了整整兩個星期了,就是沒有這類的 Google adwords。

後記: 如果這篇文用「USB 手指」關鍵字也被推到 Google search 的頭十位之內,我以後會勤力些寫網誌的。XDD