Tuesday, October 31, 2006

Solving CAPTCHAs

A Slashdost post indicated that humans are ready to solve CAPTCHAs for a very low price.

Somebody asked for a quote to solve CAPTCHAs in a 50 hour week on a freelancer recruitment website.
The average asking price to solve CAPTCHAs in 50 hours was 57$, which makes it almost a dollar for an hour. The least asking quote was 30$ (0.6$ for an hour).

The description for this job type is really vague. The number of CAPTCHAs to be solved is not specified. What is specified is the number of hours for which the human will have to work on solving the CAPTCHAs. I would expect a spammer to rather tell the number of CAPTCHAs that need to be solved.

Also there is somehow an implicit assumption that the CAPTCHAs are from a database or are generated by the software. It could very well be that they are relayed to the software application, in which case, the concept of 'finished the job' would not exist. The person who won the bid would have to be available for 50 hours, during which there could be high activity to no activity.

, ,

Sunday, October 29, 2006

Guns - primitive solutions?

Tuesday, August 17, 2004
Guns - primitive solutions?

An interesting conversation with my Prof. led to the realization that guns are such primitive solutions to defense!

Many many generations back taking a life out, eliminating a life form was the solution to any defense or self preservation related problem. And unfortunately this primitive solution is used even today!

Most of the people with firearms reason out that self defense is the reason why they are in possession of one. But if this is true, then it is also worthwhile considering that the elimination of another life form for the self preservation of one is a solution which dates back to time immemorial and is thus an extremely antediluvian form of a solution!

Isn't it strange that better tools are not there? And if you reason out that there is research going on for such weapons, even then I am surprised that it has taken this long to even realize the need for such non-killing weapons.

I guess it can be accepted that taking the life of any life form should be the last resort in any case, in any developed society. For it guarantees everyone that basic right and fundamental right of life. Take this right away from some life form/s and it might be taken away from you too. The best way to guarantee that you always have this right is to ensure that every other living form has the same right without any kind of exception. (For it could be that as you treat some life form/s as an exception to this rule, you might be considered to be an exception by some other life form/s.)

So if we have agreed upon that, then the next step is to realize the primitiveness in the idea of taking away a life in order to defend oneself. Surely there are better ways to guarantee self preservation than this extreme step.

To attack is not the best defense in this case, surely not for an advanced society.

UPDATE:
The recent episode of the UCLA police using Taser, has brought a lot of focus on the usage of 'non-lethal' weapons. Wikipedia article on Shock Guns highlights the advantages and disadvantages of such weapons.

UPDATE:
The movie 'Lord of War' is about an arms dealer, Yuri Orlov, who is cold and cynical to the point that he says:
"They say, "Evil prevails when good men fail to act." What they ought to say is, "Evil prevails." ".

The movie ends with Yuri saying:
"You know who's going to inherit the Earth? Arms dealers. Because everyone else is too busy killing each other. That's the secret to survival. Never go to war. Especially with yourself."

Guns, do we need them?

The lobbyists for guns say "Guns do not kill people. People kill people". Which has been countered by a similarly illogical statement: "Fingers do not kill people. Bullets do".

, ,

From the archives

Tuesday, August 31, 2004
The Thousand whispers of the Banyan leaves

they whisper softly to me...what I don't know.
and now, I don't go to the tree anymore.........


Tuesday, September 21, 2004
Brrrr....its cold again !!!!

Well the cold season has arrived !! Some were waiting for it some don't like it.
Last night I recorded 15C on my little thermometer key chain. I was wearing the jacket to school for the first time too. Late in the night it was really cold. The unprepared were shaking and shivering while the ones with the jackets were doing better.

That means from today onwards there will be more winter wear out in the school. That also means that soon I wont be able to cycle to school anymore and will loose my much much valued independence!!!!

, ,

Friday, October 27, 2006

nsl-school IM Worm

I recently received some messages with malicious links through Yahoo messenger from a friend.

These were the messages:
(I have replaced nsl-school.org with NSL-LINK and myglobal-news.com with MYGLOBAL-LINK.)
DO NOT RECONSTRUCT NOR CLICK ON THE LINKS

(10/27/2006 4:10:33 AM): never click into the links like something in this image http:// /dontclick.jpg !!!
(10/27/2006 4:11:12 AM): Screenshot of new windows version _ Windows Vista http:// /vista.jpg so cool
(10/27/2006 4:11:55 AM): Screenshot of new windows version _ Windows Vista http:// /vista.jpg so cool
(10/27/2006 4:12:42 AM): 1 of my vacation pictures http:// /vacation1.jpg
(10/27/2006 4:13:55 AM): Miss World 2006: http:// /MissWorld.jpg !!
(10/27/2006 4:15:09 AM): My pics http:// /mypics.jpg << (10/27/2006 8:50:59 AM): wtf is this ? wanna give me a shit ? http://NSL-LINK/?id=news Breaking news : school girls are kidnapped by the terrorists !! http://MYGLOBAL-LINK/?news_id=18388 (10/27/2006 9:04:21 AM): damn, she is so cute http://NSL-LINK/?id=miss_world After googling this for sometime I found out that this seems to be the activity of a worm which is affecting Asian users of Yahoo Messenger. Trend Micro calls this worm as WORM_SOHANAD.C.

Among the messages I received, you would notice that some were incomplete. Perhaps Yahoo is blocking these links, but I am not too sure if that is true.

=====================================
Trend Micro in their report on this worm mention:
In addition, when an Internet Explorer window having the title bar Mesothelioma, Asbestosis & Lung Cancer Information - Microsoft Internet Explorer is opened, this worm changes the said name with null.

(Rare Cancer + Google AdSense + Litigations + advertisements) Fraud:
Following the lead of 'Mesothelioma' I got to know of the findings of FaceTime Security Labs on their blog 'blog.spywareguide'. Their article on the very sophisticated KMeth worm can be read here.

This analysis caught the attention of a large number of news portals on the web and the story was splashed almost everywhere. The article shows how sophisticated the malcode writers' business model is. A real complicated fraud. If you read and understood the complicated fraud model, you would recall that depending on the country the affected user is, the page will display differently.

I guess that is what Trend Micro was describing when they said that Mesothelioma related page titles are changed to null. This of course is my attempt to link WORM_SOHANAD.C and Worm KMeth together. A google for 'nsl-school' revealed that most of the people who complained about this worm were Asians. If KMeth was designed primarily for the US then, why aren't there complaints/rants from US users?

=====================================
Anti-Virus Vendors and blocked URLs:
The only way an user affected by a virus/worm can know more about the virus/worm is by using a search engine. In this case, of all the words in the messages that I received, "nsl-school" is a characteristic word. So searching for this word on the web seems the best option. But alas, anti-virus vendors do not specify the link completely in their pages! As in this instance the anti-virus vendor has deleted the complete links. How then will an affected user know more?

Trend Micro's English language page on this worm does not mention "nsl-school" at all. While in their Chinese Version (Google translated Chinese version) for the same worm they forgot to block the URL in one instance which luckily allowed me to confirm that the messages were indeed sent by the SOHANAD.C worm.

, ,

Wednesday, October 25, 2006

The far away moon

In a far off world a moon shines.

I believe that it has the softest lustrous white glow. But it is very far away, so far that I will never be able to reach it. I have never seen it nor heard stories about it. But I believe that it exists and I sit and imagine about it when I am sad and disappointed.

The more I imagine about its beauty the more beautiful it becomes. The only problem with that is, that the more beautiful it becomes, the farther it drifts away from me. But I don't mind that because I like to imagine its beauty, its soft shine and the solace its beams provide.

, ,

Monday, October 23, 2006

what?

The boat gently rocked.

He drew out his lighter and lit his cigarette. I noticed for the first time that he was wearing gloves. Perhaps he was hiding some old scars from his violent Hungarian past. He had lost his family there I knew. So I preferred to stay mum and let him do all the talking. He was a good story teller I must admit. He went on and on and on with the story. My legs were beginning to go numb. I was sure I would walk with a limp for ever, after this long ordeal and my thoughts drifted to how my life would be if I was to become a cripple. Meanwhile he spoke of Guatemala.

I thought it would be good as the police surely would not line me up and I wounld not be their usual suspect for every felony that happened in my area. Yes, that would be great. I was getting tired of being taken to the police station every time some crime happened to be interrogated. No don't get me wrong, I like cops. I would've liked to have been a fed myself but.... Anyways then I was thinking about the next logical step when he interrupted my thoughts.

"Have you ever seen him?" he stared into my eyes intently and asked me, as if I was the key to the mystery. I shook my head and replied "No".

He repeated his question "Have you ever seen him?" and this time stared into the space. Nevertheless I again answered that I had never seen him but had heard a lot of stories about him from people. He simply smiled at me. I did not think too much about his smile but now realize that I made a mistake. I should have understood its implications, but you see I was almost blinded by my own reasoning, which I had no reasons to doubt. And don't tell me that you have never committed the same mistake, come on, we all have. The only difference is in the number of times we commit the same mistake.

He continued, "I hate tension. Tension is a killer."
"It killed my wife and my kids once. I was really tensed.", I wondered what he meant by that. I thought maybe he was getting delirious, it was easy to become so you see.

We were there in that small room and the violent shaking of the choppy waters shook everything inside the stomach so wildly that all one would want to do is to throw it all out. The blazing hot sun and the hunger added to the whole mess.

He mumbled something next. I strained my ears to hear that and I soon realised that he was singing a Turkish song. He wasn't speaking to me though he was looking at me. I didn't know what to do. I for sure thought he had flipped it, flipped it for real.

Luckily for me, he regained his senses. He asked for another cigarette. I gave him one. I was dying to ask him some questions. I thought this was the best opportunity to do so. And before he could go ahead with his story I asked him "Have you ever avenged a death?".

He laughed, he laughed for a good few minutes and then calmly answered "No".

I asked him if he was in prison before.

"You do some time, they never let you go. You know. They treat you like a criminal. I'm not a criminal."

I murmured that I agreed to that.

(c) Deapesh.

, ,

Sunday, October 22, 2006

The Lake near my house

Sometime in the middle of cold cold February, when the moon is half full, a white horse takes off from the middle of the lake. People who were at the lake at such times have seen the horse and swear that it was not their imagination.

The faint moonlight adds to its splendour and to its whiteness. With a head that is bent it appears from the lake and without turning around or even moving its head, it slowly takes off into the sky. It is said that if one mounts the horse, then the horse takes the rider to the land of the rider's dreams. In such a land, the rider will find all his/her dreams come true.

Far far away beyond the clouds, it is said that such lands exist. Riding the white magical horse of the enchanted lake is one way to get there.

, ,

Credit Card Number Input - Web Design

We shop on the internet very often (though there are some who fear online shopping yet). Atleast I do shop often.

And everytime I shop (or even pay bills online) I get irritated with the web design for accepting the credit card expiration date details. All of my credit cards state the expiration year using numbers only. E.g.: 05/02 standing for the fifth month in 2002. But almost everywhere (online shops, online bill payment web sites) I am asked to enter the name of the month when my card is due to expire.

This is reason for irritation to me, since I now have to covert the number to the month name and I am not too fast at that!! I wonder if this irritates other net users too or is it that I am growing old and lazy ?

WHY, WHY do online web forms need to know the name of the month when credit cards display the month's number?

I can't understand the rational for this design!

I was happy to note that meritime.com, an online shop, provided the shopper with a drop down list which stated the name of the month and also the number, e.g.: Feb (2), Mar(3).

Simple and nice design !

, ,

Thursday, October 19, 2006

Orkut and CAPTCHAs

Aha, Orkut is now using CAPTCHAs.

Their scheme:
If you scrap someone with a URL such as www.google.com, you might be an automated malicious entity and thus should prove that you are a human. The way to do that is by passing a very simple CAPTCHA.

If you get the CAPTCHA wrong, you are given another CAPTCHA to break.


They have been having problems with malicious links. I guess this is their way to solve that problem.

Great to see one more example of CAPTCHA !

, ,

UPnP, Firewall Alerts and Wireless Router

After recently having configured the new netgear wireless router for our home, there was a huge increase in the firewall alerts that I started getting. Every 2 seconds there would be a new alert. I withstood the annoyance for some time and then after fantasizing that this might be some malcode related activity, I fired up Wireshark and logged all packets from my computer.

I must add that the firewall alerts had a pattern. All alerts blocked were from a specific port on my computer to the router. The port which was associated with the alerts on my end was running svchost.exe. My firewall would block a Syn packet from my computer to the router's port x and then after a second or two would block a similar packet to port x+1 and so on.

Looking at the packet capture files, I noticed that these connections had something to do with UPnP. Once I determined that, the rest was easy. I realised that I had to turn off the UPnP feature on the router to stop all the unecessary alerts. After doing that my poor stressed out firewall had some relief at last !!

, ,

Tuesday, October 17, 2006

August Phishing Trends Report - US and number of phishing sites

"August Phishing Trends Report" (http://www.antiphishing.org/reports/apwg_report_August_2006.pdf) released by APWG recently, states:

In August, Websense® Security Labs saw a continuation of the top three countries hosing phishing websites. The United States remains the on the top of the list with 27.88%. The rest of the top 10 breakdown is as follows - China 14%, Republic of Korea 9.59%, France 4.07%, Japan 3.66%, Germany 3.23%, Australia 3.06%, Russia 2.46%, Canada 2.22%, Sweden 2.04%.



I find this surprising because I expected that it would be the easiest to shut down phishing sites in the US when compared to any other country and thus US would host the least phishing sites.

Any insights?

, ,

Sunday, October 15, 2006

Lakes Around Fairfax - Lake Thoreau

Lake Thoreau:


This pretty lake is surrounded on almost all sides by communities. Houses on its shores thus have their own private entrances to this lake. This lake in Reston is well maintained. Because of all the houses that are on its shores the trail that surrounds this lake is not exactly on its banks. Now and then the trail touches its banks and then looses itself amidst very pretty houses with landscaped mini gardens. The whole place is very well maintained.

, ,

Lakes Around Fairfax - Burke Lake

Burke Lake:


A unusually warm weekend afternoon in late winter saw us (roomates) on the green lawns of this lake. That was my first encounter with this lake. It is a pretty lake with a trail that runs around its shores. Some day I will go boating here, some day.

, ,

Lakes Around Fairfax - Lake Fairfax

Lake Fairfax:

A pretty small lake in Reston city. The lake provides grounds for camping. I saw many RVs parked in the camp grounds. It made me wonder if there was any fun at all to camp in a RV and have many other RVs as neighbours !

, ,

Tuesday, October 10, 2006

YouTube, Google and "the beta mystery"

Google has acquired YouTube. I am interested in knowing as to how long it would take for the successful YouTube to be labelled as another Google "beta" product !

As of 23:25 EST, 10/10/2006, YouTube is yet not beta. Would be interesting to notice it changing to YAGBP.
(YAGB -> Yet Another Google Beta Product)

I really don't understand this "beta mystery". Should use google itself to search for answers. Do you know something?

, ,

Sunday, October 08, 2006

Lazy Dreamer

This was so stupid, that I had to delete it !

Gosh, when will I learn to write a few lines.....

, ,

Saturday, October 07, 2006

Social Networking Sites and e-mail harvesting

It must surely be every spammer's dream come true.

On Orkut, a social networking site, I noticed in some of the special interest forums, a person would post a message which would be similar to:
"I have this . If you want it, reply with your e-mail id to this post."
(On one forum I saw such postings, wherein the person promised to send a mp3 file of an advertisement which ran on TV years back.)

And all the people interested in receiving a copy of this file would post their e-mail ids ! What a way to harvest some email ids, if a spammer uses this idea.

People posting their email ids openly, beats the system of being able to control who can view the email ids which has been incorporated in Orkut.

People......!!

, ,

Tuesday, October 03, 2006

LisaNova - Competition

It was once said (and perhaps believed in) - "The means are more important than the ends". That meant that the action was more important than the fruit. But something killed that....and that was this world's definition of "competition" !!

Watch this hilarious youtube video on competition:



Personally, I feel the "Harvard guy vs. the Yale girl" is exceptional !

What about you, do you believe that the end is more important than the means?
Have you won even though you played by the rules? Or in today's competitive world, players who play by the rules never win?

, ,