<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Elliott C. Back &#187; My Blog</title>
	<atom:link href="http://elliottback.com/wp/category/blogging/my-blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://elliottback.com/wp</link>
	<description>Internet &#38; Technology</description>
	<lastBuildDate>Tue, 03 Nov 2009 23:59:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Domain Name Registration Scam</title>
		<link>http://elliottback.com/wp/domain-name-registration-scam/</link>
		<comments>http://elliottback.com/wp/domain-name-registration-scam/#comments</comments>
		<pubDate>Tue, 07 Oct 2008 10:34:08 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[My Blog]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2008/10/07/domain-name-registration-scam/</guid>
		<description><![CDATA[I just received an interesting email, which &#8220;offers&#8221; to help me secure my .com domain name in the Chinese varieties .cn and .hk.  It&#8217;s more of a threatening piece of spam, because it carries the fear that if I do not avail myself of their services, them or another company will steal my brand!
Subject: [...]]]></description>
			<content:encoded><![CDATA[<p>I just received an interesting email, which &#8220;offers&#8221; to help me secure my .com domain name in the Chinese varieties .cn and .hk.  It&#8217;s more of a threatening piece of spam, because it carries the fear that if I do not avail myself of their services, them or another company will steal my brand!</p>
<blockquote><p><strong>Subject:</strong>  YOUR DOMAIN NAME (elliottback)&#8217;S CURRENT SITUATION</p>
<p>Dear  ELLIOTT C.Back</p>
<p>We are the domain name registration organization in Hong Kong, ,which mainly deal with the domain names&#8217; conflicts of the company in China and Asia regions.We have received an formal application online from one company named &#8220;TianHaiYuanTong (China) Investment Co.Ltd&#8221; who is trying to  apply for the domain names(www. elliottback.cn www. elliottback.hk etc.) and the Internet keyword(elliottback) as their domain name and internet brand on Oct 6,2008.After our initial examination, we found that the keywords and domain names being  applied  are the same as your company’s name and trademark. These days we are dealing with it. If you don’t know this company, we doubt that they buy these domain names with other aims.  We have not started the registration for TianHaiYuanTong company until now. In order to deal with this issue better, please contact us by telephone or email as soon as possible.</p>
<p>Best Regards,<br />
Boyce Meng   </p>
<p>Tel: +852-31757931 (ext8048)<br />
Fax: +852- 31757932<br />
Email: <a href="mailto:boyce.meng@hk-nsc.org.cn" title="mailto:boyce.meng@hk-nsc.org.cn">boyce.meng@hk-nsc.org.cn</a></p>
<p>Hong Kong Network Service Company Limited<br />
website: www.hknsc.hk</p></blockquote>
<p>However, as far as I can tell, there is no such &#8220;Tian Hai Yuan Tong&#8221; company, and I am not replying.  I advise you to do the same, and post any more samples of this spam in the comments!</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/domain-name-registration-scam/feed/</wfw:commentRss>
		<slash:comments>75</slash:comments>
		</item>
		<item>
		<title>New Website Features</title>
		<link>http://elliottback.com/wp/new-website-features/</link>
		<comments>http://elliottback.com/wp/new-website-features/#comments</comments>
		<pubDate>Sun, 13 Jan 2008 08:55:31 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Interface]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2008/01/13/new-website-features/</guid>
		<description><![CDATA[I&#8217;ve just added two little cute features to the main page of my website.  They don&#8217;t do much more than improve the usability and aesthetic of the front page by a tiny margin.  The first is quite practical&#8211;it alerts you and sets the 404 status code if you loaded my site through a [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve just added two little cute features to the <a href="http://elliottback.com">main page of my website</a>.  They don&#8217;t do much more than improve the usability and aesthetic of the front page by a tiny margin.  The first is quite practical&#8211;it alerts you and sets the 404 status code if you loaded my site through a domain or subdomain:</p>
<p><img id="image2521" src="http://elliottback.com/wp/wp-content/uploads/2008/01/noway.png" alt="noway.png" /></p>
<p>The second is a Flickr badge across the top of my page, with a custom-made Flickr logo to take you to my Flick page:</p>
<p><img id="image2522" src="http://elliottback.com/wp/wp-content/uploads/2008/01/flickr.png" alt="flickr.png" /></p>
<p>But this is Web 2.0, and I use the Thickbox script in other places on my site, so why not here too?</p>
<p><img id="image2523" src="http://elliottback.com/wp/wp-content/uploads/2008/01/flickrbox.png" alt="flickrbox.png" /></p>
<p>It&#8217;s fun tinkering around with your main page.  I need to add a cookie-rotator to the image on the front page, rather than make it time based.  Then people can see different versions of me everytime they come back, rather than the current &#8220;new elliott at 1 AM&#8221; business.</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/new-website-features/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sigh.  Not a spammer.</title>
		<link>http://elliottback.com/wp/sigh-not-a-spammer/</link>
		<comments>http://elliottback.com/wp/sigh-not-a-spammer/#comments</comments>
		<pubDate>Tue, 20 Nov 2007 05:07:46 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[My Blog]]></category>
		<category><![CDATA[Plugins]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2007/11/20/sigh-not-a-spammer/</guid>
		<description><![CDATA[I got a lovely email just now threatening me for being a notorious spammer:
Your doing it to drive up your Google Rank is pitiful, though I&#8217;ve informed Google of your attempts to game their system.  Further evidence of scraping will be dealt with through the legal system. Perhaps a note to [your employer] will [...]]]></description>
			<content:encoded><![CDATA[<p>I got a lovely email just now threatening me for being a notorious spammer:</p>
<blockquote><p>Your doing it to drive up your Google Rank is pitiful, though I&#8217;ve informed Google of your attempts to game their system.  Further evidence of scraping will be dealt with through the legal system. Perhaps a note to [your employer] will be of use as well.</p></blockquote>
<p>I sent back my reply, which indicates that no I am not a spammer, thank you very much:</p>
<blockquote><p>I&#8217;m terribly sorry you are experiencing web scrapers, but honest-to-god it&#8217;s not me.  I wrote a plugin a long time ago for Wordpress called &#8220;WP Autoblog&#8221; that can take an RSS feed and import them as a series of posts.  The posts get branded with attribution like &#8220;Post by XYZ and software by me&#8221; which you&#8217;re probably mistaking for something I&#8217;m actively a part of.  I wrote the plugin to aggregate some of my family blogs (<a href="http://ericback.com" title="http://ericback.com" target="_blank">ericback.com</a>, <a href="http://elliottback.com" title="http://elliottback.com" target="_blank">elliottback.com</a>) together into a single feed, but it quickly became abused by spammers so I pulled it.  You can read <a href="http://elliottback.com/wp/archives/2006/06/06/wp-autoblog-a-syndication-plugin/">more here</a>.</p></blockquote>
<p><img id="image2488" src="http://elliottback.com/wp/wp-content/uploads/2007/11/sad.png" alt="sad.png" /></p>
<p>All this in spite of people making <a href="http://www.blog.thesietch.org/2006/12/04/wp-autoblog/">photo-aggregators</a>, <a href="http://mu.wordpress.org/forums/topic.php?id=3247&#038;page">sitewide tagging</a>, and <a href="http://comox.textdrive.com/pipermail/wp-hackers/2007-October/015873.html">making Planet sites</a>.  I can&#8217;t believe how much grief a hacky Wordpress plugin has given me over the years.  Hopefully as it gets more and more out of date, <a href="http://www.google.com/search?hl=en&#038;safe=off&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;hs=Vvf&#038;q=%22software+by+Elliott%22&#038;btnG=Search">this query count</a> will start to drop from 400k (not that much) to a few hundred.  Then I will smile.</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/sigh-not-a-spammer/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Denial of Service Attack (DOS), Grrr&#8230;.</title>
		<link>http://elliottback.com/wp/denial-of-service-attack-dos-grrr/</link>
		<comments>http://elliottback.com/wp/denial-of-service-attack-dos-grrr/#comments</comments>
		<pubDate>Mon, 05 Nov 2007 02:43:17 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[WTF]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2007/11/04/denial-of-service-attack-dos-grrr/</guid>
		<description><![CDATA[Today I had the pleasure of a random guy in Mexico recursively downloading as much of my site as he could, which sent my CPU load to 2.0, a level that Dreamhost would find acceptable but which I personally freak out about.  The r-dns and IP of this guy are:
dsl-189-171-15-59.prod-infinitum.com.mx
189.171.15.59
He started at 04/Nov/2007:12:04:36 and [...]]]></description>
			<content:encoded><![CDATA[<p>Today I had the pleasure of a random guy in Mexico recursively downloading as much of my site as he could, which sent my CPU load to 2.0, a level that Dreamhost would find acceptable but which I personally freak out about.  The r-dns and IP of this guy are:</p>
<blockquote><p>dsl-189-171-15-59.prod-infinitum.com.mx<br />
189.171.15.59</p></blockquote>
<p>He started at 04/Nov/2007:12:04:36 and ended (by iptables ban) at 04/Nov/2007:20:17:03.  In those 8 hours and thirteen minutes, he made over 250,000 requests.  That&#8217;s an extra 8.5 requests per second from a single IP, which is clearly unacceptable behavior:</p>
<blockquote><p>[root@fc624389 ~]# cat access_log | grep 189.171.15.59 | wc -l<br />
251923</p></blockquote>
<p>If you don&#8217;t believe me, the next biggest offender over the last 24 hours made only 4,400 requests:</p>
<blockquote><p>[root@fc624389 ~]# cat access_log | cut -d&#8217; &#8216; -f1 | sort -n | uniq -c | sort -nr | more<br />
 251923 189.171.15.59<br />
   4403 66.249.73.116<br />
   2012 76.88.78.239<br />
   1646 70.141.105.233</p></blockquote>
<p>The user agent of this guy doesn&#8217;t tell *me* anything about him, but maybe one of you readers has an idea?</p>
<blockquote><p>189.171.15.59 &#8211; - [04/Nov/2007:12:04:38 -0500] &#8220;GET /wp-content/themes/greenmarinee/images/links_bullet.gif HTTP/1.1&#8243; 200 467 &#8220;http://celebrity-photos.elliottback.com/&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Media Center PC 3.0; .NET CLR 1.0.3705; .NET CLR 1.1.4322)&#8221;</p></blockquote>
<p>Another thing that bugs me is he requested each URL about 7 times.  WTF?  Do you really need to spider my site as fast as you can <em>seven times</em>?</p>
<blockquote><p>[root@fc624389 ~]# cat access_log | grep 189.171.15.59 | cut -d&#8217; &#8216; -f11 | sort | uniq | wc -l<br />
35414</p></blockquote>
<p>I am either thinking of writing a very evil script to confuse non-google/msn/live/ask/yahoo bots by writing in an infinite number of invisible links into my websites, or installing some kind of mod_throttle into my apache.  It looks like mod_limitipconn might help here, too.</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/denial-of-service-attack-dos-grrr/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Server :D</title>
		<link>http://elliottback.com/wp/new-server-d/</link>
		<comments>http://elliottback.com/wp/new-server-d/#comments</comments>
		<pubDate>Wed, 25 Jul 2007 12:30:30 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[My Blog]]></category>

		<guid isPermaLink="false">http://elliottback.com/wp/archives/2007/07/25/new-server-d/</guid>
		<description><![CDATA[If you are reading this, we just moved everything to a new server.  The box is a Core 2 Duo 64bit machine w/ 2 GB of RAM, and a 160GB ATA hard disk, hosted by our buddies at Cari.net, the best web hosts ever!!  If you&#8217;re wondering how we plan to transition, we [...]]]></description>
			<content:encoded><![CDATA[<p>If you are reading this, we just moved everything to a new server.  The box is a Core 2 Duo 64bit machine w/ 2 GB of RAM, and a 160GB ATA hard disk, hosted by our buddies at <a href="http://cari.net">Cari.net</a>, the best web hosts ever!!  If you&#8217;re wondering how we plan to transition, we moved all the files and DNS to this machine, and the DB is hosted still remotely on the old box.  When the DNS has solidified, we&#8217;ll just scp over the database and everything will be 100% good to go.</p>
]]></content:encoded>
			<wfw:commentRss>http://elliottback.com/wp/new-server-d/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
