It's Monday morning and all my bills are paid with nothing left over, if only I had a few extra dollars. I could make a botnet, but there are two big problems with that…
1. I can’t code
2. It’s illegal
Darn. I guess I will just have to resort to reading about them.
Mac botnet generated $10,000 a day for Flashback gang
Summary: Flashback was robbing Google of advertising dollars by redirecting clicks from infected Mac OS X machines and stealing the ad revenue.
Security researchers at Symantec are estimating that the cyber-crimibals behind the Flashback Mac OS X botnet may have raked in about $10,000 a day.
In a new blog post that discusses the business model of the botnet, Symantec found that Flashback was robbing Google of advertising dollars by redirecting clicks from infected Mac OS X machines and stealing the ad revenue.
At its height, Flashback contained more than 700,000 Mac machines and Symantec calculates that a botnet of that size could easily generate about $10,000 a day in click-fraud.
Some details from Symantec’s blog:
The Flashback ad-clicking component is loaded into Chrome, Firefox, and Safari where it can intercept all GET and POST requests from the browser. Flashback specifically targets search queries made on Google and, depending on the search query, may redirect users to another page of the attacker’s choosing, where they receive revenue from the click . (Google never receives the intended ad click.)
The ad click component parses out requests resulting from an ad click on Google Search and determines if it is on a whitelist. If not, it forwards the request to [a] malicious server.
Symantec reports that the hijacked ad click is based on a user searching for “toys”.
We can clearly see a value of 0.8 cents for the click and the redirection… This redirected URL is subsequently written into the browser so that the user is now directed to the new site, in effect hijacking the ad click Google should have received.
“This ultimately results in lost revenue for Google and untold sums of money for the Flashback gang,” Symantec said.
www.zdnet.com/blog/security/mac-botnet-generated-10000-a-day-for-flashback-gang/11727?tag=mantle_skin;content
Monday, June 4, 2012
Friday, June 1, 2012
Google is Going to Takeover the World
Google wants to run .lol Web domain
NEW YORK (CNNMoney) -- Internet addresses are about to expand way past .com and .org, and Google wants in. It applied to grab not only .google, but also fun suffixes like .lol.
The company said it would like to operate "domains we think have interesting and creative potential," citing .lol as an example.
Google (GOOG, Fortune 500) is just one of the hundreds of companies that have applied for new generic top-level domains (gTLDs) -- the ".com" part of website addresses -- in an upcoming massive expansion of the Internet's infrastructure. The full list of applicants, and their proposed new domains, will be announced on June 13.
Google revealed some of the gTLDs it's applied for -- .google, .youtube., .docs and .lol -- in a blog post published on Thursday. The company said last month that it had applied for some new domains, but it didn't go into specifics at that time.
In an interview earlier this month with CNNMoney, a Google representative said that the company expected to be one of the biggest applicants in the domain expansion process.
Other organizations that have gone public with their interest include groups proposing .nyc, .paris, Unicef, Hitachi and Canon.
Google's top brass has a close relationship with the Internet Corporation for Assigned Names and Numbers (ICANN), the non-profit, global coordinator of the Internet's naming system. Vint Cerf, Google's "chief internet evangelist" and the author of Google's Thursday blog post, is the former chairman of ICANN's board of directors.
Expanding domains is no simple task: ICANN had for years been kicking around the idea of suffixes for brand names, cities and general keywords. Last June, the organization approved a plan to open for submissions and review thousands of applications for new gTLDs.
Supporters of the move say dot-brand sites will help companies market themselves and ensure security. HSBC, for example, could tell customers that a purported HSBC site isn't legitimate unless it ends in .hsbc. And a company like Verizon (VZ, Fortune 500) could market products at cellphones.verizon and store locations at losangeles.verizon.
Critics counter that expanding domain suffixes will be confusing for consumers -- cnn.cnn, anyone? -- and not worth the effort.
But ICANN's plan is surging forward -- even though the application process has been fraught with technical issues and delays.
ICANN began accepting applications for new domains on January 12 through a web-based system, and planned to unveil the applicant list on April 30. But on April 12 -- the original deadline for submitting an application -- ICANN took the system offline after a "glitch" allowed some users to see others' data.
The organization planned to have the system back within a few days, but the issues persisted for weeks. ICANN finally re-opened the application system on May 21 and accepted entries until May 30. The application list will be announced next month.
As of May 30, ICANN said it had received about 1,900 applications.
ICANN has gradually rolled out a handful of new domains over the past decade, including the controversial .xxx domain that got the green light in March 2011. The new proposed expansion will be far bigger than anything done previously.
But for interested companies, the new domains don't come cheap.
ICANN charges $185,000 per domain application, a extensive paperwork bundle that requires scores of policy documents. The technical setup and upkeep on a single domain will cost additional thousands -- or even millions -- per year.
It's a slow and painstaking process. With domains like .law and .sport, many suitors are expected to battle for the same coveted keyword. So if multiple applicants want a single domain, and ICANN deems them equally worthy, the name goes to auction -- which could end up costing millions for the winning bidder.
Even if two keywords aren't exactly the same, "confusingly similar" domain suffixes are forbidden. For example, if an apple farmers' union grabs .apples, then iGizmo maker Apple (AAPL, Fortune 500) would be blocked permanently from registering .apple.
http://money.cnn.com/2012/05/31/technology/google-domains-lol/index.htm?iid=Popular
NEW YORK (CNNMoney) -- Internet addresses are about to expand way past .com and .org, and Google wants in. It applied to grab not only .google, but also fun suffixes like .lol.
The company said it would like to operate "domains we think have interesting and creative potential," citing .lol as an example.
Google (GOOG, Fortune 500) is just one of the hundreds of companies that have applied for new generic top-level domains (gTLDs) -- the ".com" part of website addresses -- in an upcoming massive expansion of the Internet's infrastructure. The full list of applicants, and their proposed new domains, will be announced on June 13.
Google revealed some of the gTLDs it's applied for -- .google, .youtube., .docs and .lol -- in a blog post published on Thursday. The company said last month that it had applied for some new domains, but it didn't go into specifics at that time.
In an interview earlier this month with CNNMoney, a Google representative said that the company expected to be one of the biggest applicants in the domain expansion process.
Other organizations that have gone public with their interest include groups proposing .nyc, .paris, Unicef, Hitachi and Canon.
Google's top brass has a close relationship with the Internet Corporation for Assigned Names and Numbers (ICANN), the non-profit, global coordinator of the Internet's naming system. Vint Cerf, Google's "chief internet evangelist" and the author of Google's Thursday blog post, is the former chairman of ICANN's board of directors.
Expanding domains is no simple task: ICANN had for years been kicking around the idea of suffixes for brand names, cities and general keywords. Last June, the organization approved a plan to open for submissions and review thousands of applications for new gTLDs.
Supporters of the move say dot-brand sites will help companies market themselves and ensure security. HSBC, for example, could tell customers that a purported HSBC site isn't legitimate unless it ends in .hsbc. And a company like Verizon (VZ, Fortune 500) could market products at cellphones.verizon and store locations at losangeles.verizon.
Critics counter that expanding domain suffixes will be confusing for consumers -- cnn.cnn, anyone? -- and not worth the effort.
But ICANN's plan is surging forward -- even though the application process has been fraught with technical issues and delays.
ICANN began accepting applications for new domains on January 12 through a web-based system, and planned to unveil the applicant list on April 30. But on April 12 -- the original deadline for submitting an application -- ICANN took the system offline after a "glitch" allowed some users to see others' data.
The organization planned to have the system back within a few days, but the issues persisted for weeks. ICANN finally re-opened the application system on May 21 and accepted entries until May 30. The application list will be announced next month.
As of May 30, ICANN said it had received about 1,900 applications.
ICANN has gradually rolled out a handful of new domains over the past decade, including the controversial .xxx domain that got the green light in March 2011. The new proposed expansion will be far bigger than anything done previously.
But for interested companies, the new domains don't come cheap.
ICANN charges $185,000 per domain application, a extensive paperwork bundle that requires scores of policy documents. The technical setup and upkeep on a single domain will cost additional thousands -- or even millions -- per year.
It's a slow and painstaking process. With domains like .law and .sport, many suitors are expected to battle for the same coveted keyword. So if multiple applicants want a single domain, and ICANN deems them equally worthy, the name goes to auction -- which could end up costing millions for the winning bidder.
Even if two keywords aren't exactly the same, "confusingly similar" domain suffixes are forbidden. For example, if an apple farmers' union grabs .apples, then iGizmo maker Apple (AAPL, Fortune 500) would be blocked permanently from registering .apple.
http://money.cnn.com/2012/05/31/technology/google-domains-lol/index.htm?iid=Popular
Thursday, May 31, 2012
How to Insult a G33k
Today just seems like an insult kind of so here are some Geeky ones.
Also I wanted to let anyone reading this know that I would love to hear your comments. If you like it, if you don’t, what you would like see more of, or less of. Or just let me know that you are out there. Have wonderfully G33ky day.
33 Geeky Insults You Can Use Almost Anywhere
In general, geeks prefer to use brains rather than brawn to get themselves out of a situation. As a result, their insults are often witty, literary and highly intelligent. But not always.
Here are a few of our favorites. (Note to parents: you may want to preview these first before your kids pick them up.)
You know, you are a classic example of the inverse ratio between the size of the mouth and the size of the brain. — The Doctor, Doctor Who
Why, you stuck up, half-witted, scruffy-looking… Nerf herder! — Princess Leia, Star Wars Episode V: The Empire Strikes Back
If you spend word for word with me, I shall make your wit bankrupt. — Thurio, The Two Gentlemen of Verona by William Shakespeare
[You're] a girl with as much talent for disguise as a giraffe in dark glasses trying to get into a polar-bears-only club. — Blackadder, Blackadder Goes Forth
You clinking, clanking, clattering collection of caliginous junk! — The Wizard, The Wizard of Oz
You’re about as much use as a condom machine in the Vatican. — Rimmer, Red Dwarf
[He] may look like an idiot and talk like an idiot but don’t let that fool you. He really is an idiot. — Groucho Marx as Rufus T. Firefly, Duck Soup
I’ll explain and I’ll use small words so that you’ll be sure to understand, you warthog-faced buffoon. — Westley (The Dread Pirate Roberts), The Princess Bride
Don’t look now, but there’s one man too many in this room and I think it’s you. — Groucho Marx as Rufus T. Firefly, Duck Soup
I fart in your general direction. Your mother was a hamster and your father smelt of elderberries. — French Guard, Monty Python and the Holy Grail
Well if it isn’t fat stinking billygoat billyboy. How art thou, thou globby bottle of cheap, stinking chip-oil? Come get some in the yarbles, if you have any yarbles, you eunuch jelly thou! — Alex DeLarge, A Clockwork Orange
You are a sad strange little man, and you have my pity. — Buzz Lightyear, Toy Story
To call you stupid would be an insult to stupid people! I’ve known sheep that could outwit you. I’ve worn dresses with higher IQs. — Wanda, A Fish Called Wanda
Your heart is full of unwashed socks. Your soul is full of gunk …The three words that best describe you are as follows, and I quote, “Stink, stank, stunk!” — How the Grinch Stole Christmas! (TV version)
He has no enemies, but is intensely disliked by his friends. — Oscar Wilde
Freaking idiot. — Napoleon, Napoleon Dynamite
You bowl like your momma. Unless of course she bowls well, in which case you bowl nothing like her. — Sheldon Cooper, The Big Bang Theory
Shut up, Big-booty, you coward. You are the weakest individual I ever know. — Doctor Emilio Lizardo/Lord John Whorfin, Buckaroo Banzai, Across the 8th Dimension
Well, I’ll tell you something that should be of vital interest to you. That you, sir, are a NITWIT! — The Doctor, Doctor Who
I didn’t mean to say that the Enterprise [or your car/van/truck/RV] should be hauling garbage. I meant to say that it should be hauled away as garbage! — Korax, Star Trek – “The Trouble With Tribbles”
Don’t get uncool and heavy on me now. — Neil, The Young Ones
Your brain’s so minute that if a hungry cannibal cracked your head open, there wouldn’t be enough to cover a small water biscuit. — Blackadder, Blackadder Goes Forth
I’m trying to thank you, you pointed-eared hobgoblin! — Dr. Leonard McCoy, Star Trek
I think… no, I am positive… that you are the most unattractive man I have ever met in my entire life. In the short time we’ve been together, you have demonstrated every loathsome characteristic of the male personality and even discovered a few new ones. You are physically repulsive, intellectually retarded, you’re morally reprehensible, vulgar, insensitive, selfish, stupid, you have no taste, a lousy sense of humor and you smell. You’re not even interesting enough to make me sick. — Alexandra Medford, The Witches of Eastwick
Some cause happiness wherever they go; others, whenever they go. — Oscar Wilde
You would bore the leggings off a village idiot. — Blackadder, The Black Adder
Shut your festering gob, you tit! Your type really makes me puke, you vacuous, toffee-nosed, malodorous pervert! — Monty Python’s Flying Circus
Smeg head. — Lister, Red Dwarf
Well, of course, this is just the sort of blinkered philistine ignorance I’ve come to expect from you non-creative garbage. You sit there on your loathsome spotty behinds squeezing blackheads, not caring a tinker’s cuss for the struggling artist. You excrement, you whining hypocritical toadies with your colour TV sets and your Tony Jacklin golf clubs and your bleeding masonic secret handshakes. You wouldn’t let me join, would you, you blackballing bastards. Well I wouldn’t become a Freemason if you went down on your stinking knees and begged me. — Monty Python’s Flying Circus
You are a fart factory, slug-slimed sack of rat guts in cat vomit. A cheesy scab picked pimple squeezing finger bandage. A week old maggot burger with everything on it and flies on the side. — Rufio, Hook
What are you, a captain in the innuendo squad? — Micky, Doctor Who
Out. For. A. Walk… Bitch. — Spike, Buffy the Vampire Slayer
You are about one bit short of a byte. —Anonymous
I do desire we may be better strangers. — Orlando, As You Like It by William Shakespeare
http://www.wired.com/geekdad/2012/05/33-geeky-insults/?utm_source=Contextly&utm_medium=RelatedLinks&utm_campaign=Interesting
Also I wanted to let anyone reading this know that I would love to hear your comments. If you like it, if you don’t, what you would like see more of, or less of. Or just let me know that you are out there. Have wonderfully G33ky day.
33 Geeky Insults You Can Use Almost Anywhere
In general, geeks prefer to use brains rather than brawn to get themselves out of a situation. As a result, their insults are often witty, literary and highly intelligent. But not always.
Here are a few of our favorites. (Note to parents: you may want to preview these first before your kids pick them up.)
You know, you are a classic example of the inverse ratio between the size of the mouth and the size of the brain. — The Doctor, Doctor Who
Why, you stuck up, half-witted, scruffy-looking… Nerf herder! — Princess Leia, Star Wars Episode V: The Empire Strikes Back
If you spend word for word with me, I shall make your wit bankrupt. — Thurio, The Two Gentlemen of Verona by William Shakespeare
[You're] a girl with as much talent for disguise as a giraffe in dark glasses trying to get into a polar-bears-only club. — Blackadder, Blackadder Goes Forth
You clinking, clanking, clattering collection of caliginous junk! — The Wizard, The Wizard of Oz
You’re about as much use as a condom machine in the Vatican. — Rimmer, Red Dwarf
[He] may look like an idiot and talk like an idiot but don’t let that fool you. He really is an idiot. — Groucho Marx as Rufus T. Firefly, Duck Soup
I’ll explain and I’ll use small words so that you’ll be sure to understand, you warthog-faced buffoon. — Westley (The Dread Pirate Roberts), The Princess Bride
Don’t look now, but there’s one man too many in this room and I think it’s you. — Groucho Marx as Rufus T. Firefly, Duck Soup
I fart in your general direction. Your mother was a hamster and your father smelt of elderberries. — French Guard, Monty Python and the Holy Grail
Well if it isn’t fat stinking billygoat billyboy. How art thou, thou globby bottle of cheap, stinking chip-oil? Come get some in the yarbles, if you have any yarbles, you eunuch jelly thou! — Alex DeLarge, A Clockwork Orange
You are a sad strange little man, and you have my pity. — Buzz Lightyear, Toy Story
To call you stupid would be an insult to stupid people! I’ve known sheep that could outwit you. I’ve worn dresses with higher IQs. — Wanda, A Fish Called Wanda
Your heart is full of unwashed socks. Your soul is full of gunk …The three words that best describe you are as follows, and I quote, “Stink, stank, stunk!” — How the Grinch Stole Christmas! (TV version)
He has no enemies, but is intensely disliked by his friends. — Oscar Wilde
Freaking idiot. — Napoleon, Napoleon Dynamite
You bowl like your momma. Unless of course she bowls well, in which case you bowl nothing like her. — Sheldon Cooper, The Big Bang Theory
Shut up, Big-booty, you coward. You are the weakest individual I ever know. — Doctor Emilio Lizardo/Lord John Whorfin, Buckaroo Banzai, Across the 8th Dimension
Well, I’ll tell you something that should be of vital interest to you. That you, sir, are a NITWIT! — The Doctor, Doctor Who
I didn’t mean to say that the Enterprise [or your car/van/truck/RV] should be hauling garbage. I meant to say that it should be hauled away as garbage! — Korax, Star Trek – “The Trouble With Tribbles”
Don’t get uncool and heavy on me now. — Neil, The Young Ones
Your brain’s so minute that if a hungry cannibal cracked your head open, there wouldn’t be enough to cover a small water biscuit. — Blackadder, Blackadder Goes Forth
I’m trying to thank you, you pointed-eared hobgoblin! — Dr. Leonard McCoy, Star Trek
I think… no, I am positive… that you are the most unattractive man I have ever met in my entire life. In the short time we’ve been together, you have demonstrated every loathsome characteristic of the male personality and even discovered a few new ones. You are physically repulsive, intellectually retarded, you’re morally reprehensible, vulgar, insensitive, selfish, stupid, you have no taste, a lousy sense of humor and you smell. You’re not even interesting enough to make me sick. — Alexandra Medford, The Witches of Eastwick
Some cause happiness wherever they go; others, whenever they go. — Oscar Wilde
You would bore the leggings off a village idiot. — Blackadder, The Black Adder
Shut your festering gob, you tit! Your type really makes me puke, you vacuous, toffee-nosed, malodorous pervert! — Monty Python’s Flying Circus
Smeg head. — Lister, Red Dwarf
Well, of course, this is just the sort of blinkered philistine ignorance I’ve come to expect from you non-creative garbage. You sit there on your loathsome spotty behinds squeezing blackheads, not caring a tinker’s cuss for the struggling artist. You excrement, you whining hypocritical toadies with your colour TV sets and your Tony Jacklin golf clubs and your bleeding masonic secret handshakes. You wouldn’t let me join, would you, you blackballing bastards. Well I wouldn’t become a Freemason if you went down on your stinking knees and begged me. — Monty Python’s Flying Circus
You are a fart factory, slug-slimed sack of rat guts in cat vomit. A cheesy scab picked pimple squeezing finger bandage. A week old maggot burger with everything on it and flies on the side. — Rufio, Hook
What are you, a captain in the innuendo squad? — Micky, Doctor Who
Out. For. A. Walk… Bitch. — Spike, Buffy the Vampire Slayer
You are about one bit short of a byte. —Anonymous
I do desire we may be better strangers. — Orlando, As You Like It by William Shakespeare
http://www.wired.com/geekdad/2012/05/33-geeky-insults/?utm_source=Contextly&utm_medium=RelatedLinks&utm_campaign=Interesting
Wednesday, May 30, 2012
The Internet is on FIRE... Or Not
Good Morning,
I'm sorry that I have not posted in the last couple days. I have been out of town and the hotel internet was not the greatest.
So the interest Geek News for today is an Article from Wired.com talking about a very interesting piece of Malware. I have added the URL at the bottom of the article, I would recommend taking a look at the site because there are some cool graphics.
Meet ‘Flame,’ The Massive Spy Malware Infiltrating Iranian Computers
A massive, highly sophisticated piece of malware has been newly found infecting systems in Iran and elsewhere and is believed to be part of a well-coordinated, ongoing, state-run cyberespionage operation.
The malware, discovered by Russia-based antivirus firm Kaspersky Lab, is an espionage toolkit that has been infecting targeted systems in Iran, Lebanon, Syria, Sudan, the Israeli Occupied Territories and other countries in the Middle East and North Africa for at least two years.
Dubbed “Flame” by Kaspersky, the malicious code dwarfs Stuxnet in size — the groundbreaking infrastructure-sabotaging malware that is believed to have wreaked havoc on Iran’s nuclear program in 2009 and 2010. Although Flame has both a different purpose and composition than Stuxnet, and appears to have been written by different programmers, its complexity, the geographic scope of its infections and its behavior indicate strongly that a nation-state is behind Flame, rather than common cyber-criminals — marking it as yet another tool in the growing arsenal of cyberweaponry.
The researchers say that Flame may be part of a parallel project created by contractors who were hired by the same nation-state team that was behind Stuxnet and its sister malware, DuQu.
“Stuxnet and Duqu belonged to a single chain of attacks, which raised cyberwar-related concerns worldwide,” said Eugene Kaspersky, CEO and co-founder of Kaspersky Lab, in a statement. “The Flame malware looks to be another phase in this war, and it’s important to understand that such cyber weapons can easily be used against any country.”
Early analysis of Flame by the Lab indicates that it’s designed primarily to spy on the users of infected computers and steal data from them, including documents, recorded conversations and keystrokes. It also opens a backdoor to infected systems to allow the attackers to tweak the toolkit and add new functionality.
The malware, which is 20 megabytes when all of its modules are installed, contains multiple libraries, SQLite3 databases, various levels of encryption — some strong, some weak — and 20 plug-ins that can be swapped in and out to provide various functionality for the attackers. It even contains some code that is written in the LUA programming language — an uncommon choice for malware.
Kaspersky Lab is calling it “one of the most complex threats ever discovered.”
“It’s pretty fantastic and incredible in complexity,” said Alexander Gostev, chief security expert at Kaspersky Lab.
Flame appears to have been operating in the wild as early as March 2010, though it remained undetected by antivirus companies.
“It’s a very big chunk of code. Because of that, it’s quite interesting that it stayed undetected for at least two years,” Gostev said. He noted that there are clues that the malware may actually date back to as early as 2007, around the same time period when Stuxnet and DuQu are believed to have been created.
Gostev says that because of its size and complexity, complete analysis of the code may take years.
“It took us half a year to analyze Stuxnet,” he said. “This is 20 times more complicated. It will take us 10 years to fully understand everything.”
Kaspersky discovered the malware about two weeks ago after the United Nations’ International Telecommunications Union asked the Lab to look into reports in April that computers belonging to the Iranian Oil Ministry and the Iranian National Oil Company had been hit with malware that was stealing and deleting information from the systems. The malware was named alternatively in news articles as “Wiper” and “Viper,” a discrepancy that may be due to a translation mixup.
Kaspersky researchers searched through their reporting archive, which contains suspicious filenames sent automatically from customer machines so the names can be checked against whitelists of known malware, and found an MD5 hash and filename that appeared to have been deployed only on machines in Iran and other Middle East countries. As the researchers dug further, they found other components infecting machines in the region, which they pieced together as parts of Flame.
Kaspersky, however, is currently treating Flame as if it is not connected to Wiper/Viper, and believes it is a separate infection entirely. The researchers dubbed the toolkit “Flame” after the name of a module inside it.
Among Flame’s many modules is one that turns on the internal microphone of an infected machine to secretly record conversations that occur either over Skype or in the computer’s near vicinity; a module that turns Bluetooth-enabled computers into a Bluetooth beacon, which scans for other Bluetooth-enabled devices in the vicinity to siphon names and phone numbers from their contacts folder; and a module that grabs and stores frequent screenshots of activity on the machine, such as instant-messaging and e-mail communications, and sends them via a covert SSL channel to the attackers’ command-and-control servers.
The malware also has a sniffer component that can scan all of the traffic on an infected machine’s local network and collect usernames and password hashes that are transmitted across the network. The attackers appear to use this component to hijack administrative accounts and gain high-level privileges to other machines and parts of the network.
Flame does contain a module named Viper, adding more confusion to the Wiper/Viper issue, but this component is used to transfer stolen data from infected machines to command-and-control servers. News reports out of Iran indicated the Wiper/Viper program that infected the oil ministry was designed to delete large swaths of data from infected systems.
Kaspersky’s researchers examined a system that was destroyed by Wiper/Viper and found no traces of that malware on it, preventing them from comparing it to the Flame files. The disk destroyed by Wiper/Viper was filled primarily with random trash, and almost nothing could be recovered from it, Gostev said. “We did not see any sign of Flame on that disk.”
Because Flame is so big, it gets loaded to a system in pieces. The machine first gets hit with a 6-megabyte component, which contains about half a dozen other compressed modules inside. The main component extracts, decompresses and decrypts these modules and writes them to various locations on disk. The number of modules in an infection depends on what the attackers want to do on a particular machine.
Once the modules are unpacked and loaded, the malware connects to one of about 80 command-and-control domains to deliver information about the infected machine to the attackers and await further instruction from them. The malware contains a hardcoded list of about five domains, but also has an updatable list, to which the attackers can add new domains if these others have been taken down or abandoned.
While the malware awaits further instruction, the various modules in it might take screenshots and sniff the network. The screenshot module grabs desktop images every 15 seconds when a high-value communication application is being used, such as instant messaging or Outlook, and once every 60 seconds when other applications are being used.
Although the Flame toolkit does not appear to have been written by the same programmers who wrote Stuxnet and DuQu, it does share a few interesting things with Stuxnet.
Stuxnet is believed to have been written through a partnership between Israel and the United States, and was first launched in June 2009. It is widely believed to have been designed to sabotage centrifuges used in Iran’s uranium enrichment program. DuQu was an espionage tool discovered on machines in Iran, Sudan, and elsewhere in 2011 that was designed to steal documents and other data from machines. Stuxnet and DuQu appeared to have been built on the same framework, using identical parts and using similar techniques.
But Flame doesn’t resemble either of these in framework, design or functionality.
Stuxnet and DuQu were made of compact and efficient code that was pared down to its essentials. Flame is 20 megabytes in size, compared to Stuxnet’s 500 kilobytes, and contains a lot of components that are not used by the code by default, but appear to be there to provide the attackers with options to turn on post-installation.
“It was obvious DuQu was from the same source as Stuxnet. But no matter how much we looked for similarities [in Flame], there are zero similarities,” Gostev said. “Everything is completely different, with the exception of two specific things.”
One of these is an interesting export function in both Stuxnet and Flame, which may turn out to link the two pieces of malware upon further analysis, Gostev said. The export function allows the malware to be executed on the system.
Also, like Stuxnet, Flame has the ability to spread by infecting USB sticks using the autorun and .lnk vulnerabilities that Stuxnet used. It also uses the same print spooler vulnerability that Stuxnet used to spread to computers on a local network. This suggests that the authors of Flame may have had access to the same menu of exploits that the creators of Stuxnet used.
Unlike Stuxnet, however, Flame does not replicate automatically. The spreading mechanisms are turned off by default and must be switched on by the attackers before the malware will spread. Once it infects a USB stick inserted into an infected machine, the USB exploit is disabled immediately.
This is likely intended to control the spread of the malware and lessen the likelihood that it will be detected. This may be the attackers’ response to the out-of-control spreading that occurred with Stuxnet and accelerated the discovery of that malware.
It’s possible the exploits were enabled in early versions of the malware to allow the malware to spread automatically, but were then disabled after Stuxnet went public in July 2010 and after the .lnk and print spooler vulnerabilities were patched. Flame was launched prior to Stuxnet’s discovery, and Microsoft patched the .lnk and print spooler vulnerabilities in August and September 2010. Any malware attempting to use the vulnerabilities now would be detected if the infected machines were running updated versions of antivirus programs. Flame, in fact, checks for the presence of updated versions of these programs on a machine and, based on what it finds, determines if the environment is conducive for using the exploits to spread.
The researchers say they don’t know yet how an initial infection of Flame occurs on a machine before it starts spreading. The malware has the ability to infect a fully patched Windows 7 computer, which suggests that there may be a zero-day exploit in the code that the researchers have not yet found.
The earliest sign of Flame that Kaspersky found on customer systems is a filename belonging to Flame that popped up on a customer’s machine in Lebanon on Aug. 23, 2010. An internet search on the file’s name showed that security firm Webroot had reported the same filename appearing on a computer in Iran on Mar. 1, 2010. But online searches for the names of other unique files found in Flame show that it may have been in the wild even earlier than this. At least one component of Flame appears to have popped up on machines in Europe on Dec. 5, 2007 and in Dubai on Apr. 28, 2008.
Kaspersky estimates that Flame has infected about 1,000 machines. The researchers arrived at this figure by calculating the number of its own customers who have been infected and extrapolating that to estimate the number of infected machines belonging to customers of other antivirus firms.
All of the infections of Kaspersky customers appear to have been targeted and show no indication that a specific industry, such as the energy industry, or specific systems, such as industrial control systems, were singled out. Instead, the researchers believe Flame was designed to be an all-purpose tool that so far has infected a wide variety of victims. Among those hit have been individuals, private companies, educational institutions and government-run organizations.
Symantec, which has also begun analyzing Flame (which it calls “Flamer”), says the majority of its customers who have been hit by the malware reside in the Palestinian West Bank, Hungary, Iran and Lebanon. They have received additional reports from customer machines in Austria, Russia, Hong Kong, and the United Arab Emirates.
Researchers say the compilation date of modules in Flame appear to have been manipulated by the attackers, perhaps in an attempt to thwart researchers from determining when they were created.
“Whoever created it was careful to mess up the compilation dates in every single module,” Gostev said. “The modules appear to have been compiled in 1994 and 1995, but they’re using code that was only released in 2010.”
The malware has no kill date, though the operators have the ability to send a kill module to it if needed. The kill module, named browse32, searches for every trace of the malware on the system, including stored files full of screenshots and data stolen by the malware, and eliminates them, picking up any breadcrumbs that might be left behind.
“When the kill module is activated, there’s nothing left whatsoever,” Gostev said.
UPDATE 9 a.m. PDT: Iran’s Computer Emergency Response Team announced on Monday that it had developed a detector to uncover what it calls the “Flamer” malware on infected machines and delivered it to select organizations at the beginning of May. It has also developed a removal tool for the malware. Kaspersky believes the “Flamer” malware is the same as the Flame malware its researchers analyzed.
http://www.wired.com/threatlevel/2012/05/flame/
I'm sorry that I have not posted in the last couple days. I have been out of town and the hotel internet was not the greatest.
So the interest Geek News for today is an Article from Wired.com talking about a very interesting piece of Malware. I have added the URL at the bottom of the article, I would recommend taking a look at the site because there are some cool graphics.
Meet ‘Flame,’ The Massive Spy Malware Infiltrating Iranian Computers
A massive, highly sophisticated piece of malware has been newly found infecting systems in Iran and elsewhere and is believed to be part of a well-coordinated, ongoing, state-run cyberespionage operation.
The malware, discovered by Russia-based antivirus firm Kaspersky Lab, is an espionage toolkit that has been infecting targeted systems in Iran, Lebanon, Syria, Sudan, the Israeli Occupied Territories and other countries in the Middle East and North Africa for at least two years.
Dubbed “Flame” by Kaspersky, the malicious code dwarfs Stuxnet in size — the groundbreaking infrastructure-sabotaging malware that is believed to have wreaked havoc on Iran’s nuclear program in 2009 and 2010. Although Flame has both a different purpose and composition than Stuxnet, and appears to have been written by different programmers, its complexity, the geographic scope of its infections and its behavior indicate strongly that a nation-state is behind Flame, rather than common cyber-criminals — marking it as yet another tool in the growing arsenal of cyberweaponry.
The researchers say that Flame may be part of a parallel project created by contractors who were hired by the same nation-state team that was behind Stuxnet and its sister malware, DuQu.
“Stuxnet and Duqu belonged to a single chain of attacks, which raised cyberwar-related concerns worldwide,” said Eugene Kaspersky, CEO and co-founder of Kaspersky Lab, in a statement. “The Flame malware looks to be another phase in this war, and it’s important to understand that such cyber weapons can easily be used against any country.”
Early analysis of Flame by the Lab indicates that it’s designed primarily to spy on the users of infected computers and steal data from them, including documents, recorded conversations and keystrokes. It also opens a backdoor to infected systems to allow the attackers to tweak the toolkit and add new functionality.
The malware, which is 20 megabytes when all of its modules are installed, contains multiple libraries, SQLite3 databases, various levels of encryption — some strong, some weak — and 20 plug-ins that can be swapped in and out to provide various functionality for the attackers. It even contains some code that is written in the LUA programming language — an uncommon choice for malware.
Kaspersky Lab is calling it “one of the most complex threats ever discovered.”
“It’s pretty fantastic and incredible in complexity,” said Alexander Gostev, chief security expert at Kaspersky Lab.
Flame appears to have been operating in the wild as early as March 2010, though it remained undetected by antivirus companies.
“It’s a very big chunk of code. Because of that, it’s quite interesting that it stayed undetected for at least two years,” Gostev said. He noted that there are clues that the malware may actually date back to as early as 2007, around the same time period when Stuxnet and DuQu are believed to have been created.
Gostev says that because of its size and complexity, complete analysis of the code may take years.
“It took us half a year to analyze Stuxnet,” he said. “This is 20 times more complicated. It will take us 10 years to fully understand everything.”
Kaspersky discovered the malware about two weeks ago after the United Nations’ International Telecommunications Union asked the Lab to look into reports in April that computers belonging to the Iranian Oil Ministry and the Iranian National Oil Company had been hit with malware that was stealing and deleting information from the systems. The malware was named alternatively in news articles as “Wiper” and “Viper,” a discrepancy that may be due to a translation mixup.
Kaspersky researchers searched through their reporting archive, which contains suspicious filenames sent automatically from customer machines so the names can be checked against whitelists of known malware, and found an MD5 hash and filename that appeared to have been deployed only on machines in Iran and other Middle East countries. As the researchers dug further, they found other components infecting machines in the region, which they pieced together as parts of Flame.
Kaspersky, however, is currently treating Flame as if it is not connected to Wiper/Viper, and believes it is a separate infection entirely. The researchers dubbed the toolkit “Flame” after the name of a module inside it.
Among Flame’s many modules is one that turns on the internal microphone of an infected machine to secretly record conversations that occur either over Skype or in the computer’s near vicinity; a module that turns Bluetooth-enabled computers into a Bluetooth beacon, which scans for other Bluetooth-enabled devices in the vicinity to siphon names and phone numbers from their contacts folder; and a module that grabs and stores frequent screenshots of activity on the machine, such as instant-messaging and e-mail communications, and sends them via a covert SSL channel to the attackers’ command-and-control servers.
The malware also has a sniffer component that can scan all of the traffic on an infected machine’s local network and collect usernames and password hashes that are transmitted across the network. The attackers appear to use this component to hijack administrative accounts and gain high-level privileges to other machines and parts of the network.
Flame does contain a module named Viper, adding more confusion to the Wiper/Viper issue, but this component is used to transfer stolen data from infected machines to command-and-control servers. News reports out of Iran indicated the Wiper/Viper program that infected the oil ministry was designed to delete large swaths of data from infected systems.
Kaspersky’s researchers examined a system that was destroyed by Wiper/Viper and found no traces of that malware on it, preventing them from comparing it to the Flame files. The disk destroyed by Wiper/Viper was filled primarily with random trash, and almost nothing could be recovered from it, Gostev said. “We did not see any sign of Flame on that disk.”
Because Flame is so big, it gets loaded to a system in pieces. The machine first gets hit with a 6-megabyte component, which contains about half a dozen other compressed modules inside. The main component extracts, decompresses and decrypts these modules and writes them to various locations on disk. The number of modules in an infection depends on what the attackers want to do on a particular machine.
Once the modules are unpacked and loaded, the malware connects to one of about 80 command-and-control domains to deliver information about the infected machine to the attackers and await further instruction from them. The malware contains a hardcoded list of about five domains, but also has an updatable list, to which the attackers can add new domains if these others have been taken down or abandoned.
While the malware awaits further instruction, the various modules in it might take screenshots and sniff the network. The screenshot module grabs desktop images every 15 seconds when a high-value communication application is being used, such as instant messaging or Outlook, and once every 60 seconds when other applications are being used.
Although the Flame toolkit does not appear to have been written by the same programmers who wrote Stuxnet and DuQu, it does share a few interesting things with Stuxnet.
Stuxnet is believed to have been written through a partnership between Israel and the United States, and was first launched in June 2009. It is widely believed to have been designed to sabotage centrifuges used in Iran’s uranium enrichment program. DuQu was an espionage tool discovered on machines in Iran, Sudan, and elsewhere in 2011 that was designed to steal documents and other data from machines. Stuxnet and DuQu appeared to have been built on the same framework, using identical parts and using similar techniques.
But Flame doesn’t resemble either of these in framework, design or functionality.
Stuxnet and DuQu were made of compact and efficient code that was pared down to its essentials. Flame is 20 megabytes in size, compared to Stuxnet’s 500 kilobytes, and contains a lot of components that are not used by the code by default, but appear to be there to provide the attackers with options to turn on post-installation.
“It was obvious DuQu was from the same source as Stuxnet. But no matter how much we looked for similarities [in Flame], there are zero similarities,” Gostev said. “Everything is completely different, with the exception of two specific things.”
One of these is an interesting export function in both Stuxnet and Flame, which may turn out to link the two pieces of malware upon further analysis, Gostev said. The export function allows the malware to be executed on the system.
Also, like Stuxnet, Flame has the ability to spread by infecting USB sticks using the autorun and .lnk vulnerabilities that Stuxnet used. It also uses the same print spooler vulnerability that Stuxnet used to spread to computers on a local network. This suggests that the authors of Flame may have had access to the same menu of exploits that the creators of Stuxnet used.
Unlike Stuxnet, however, Flame does not replicate automatically. The spreading mechanisms are turned off by default and must be switched on by the attackers before the malware will spread. Once it infects a USB stick inserted into an infected machine, the USB exploit is disabled immediately.
This is likely intended to control the spread of the malware and lessen the likelihood that it will be detected. This may be the attackers’ response to the out-of-control spreading that occurred with Stuxnet and accelerated the discovery of that malware.
It’s possible the exploits were enabled in early versions of the malware to allow the malware to spread automatically, but were then disabled after Stuxnet went public in July 2010 and after the .lnk and print spooler vulnerabilities were patched. Flame was launched prior to Stuxnet’s discovery, and Microsoft patched the .lnk and print spooler vulnerabilities in August and September 2010. Any malware attempting to use the vulnerabilities now would be detected if the infected machines were running updated versions of antivirus programs. Flame, in fact, checks for the presence of updated versions of these programs on a machine and, based on what it finds, determines if the environment is conducive for using the exploits to spread.
The researchers say they don’t know yet how an initial infection of Flame occurs on a machine before it starts spreading. The malware has the ability to infect a fully patched Windows 7 computer, which suggests that there may be a zero-day exploit in the code that the researchers have not yet found.
The earliest sign of Flame that Kaspersky found on customer systems is a filename belonging to Flame that popped up on a customer’s machine in Lebanon on Aug. 23, 2010. An internet search on the file’s name showed that security firm Webroot had reported the same filename appearing on a computer in Iran on Mar. 1, 2010. But online searches for the names of other unique files found in Flame show that it may have been in the wild even earlier than this. At least one component of Flame appears to have popped up on machines in Europe on Dec. 5, 2007 and in Dubai on Apr. 28, 2008.
Kaspersky estimates that Flame has infected about 1,000 machines. The researchers arrived at this figure by calculating the number of its own customers who have been infected and extrapolating that to estimate the number of infected machines belonging to customers of other antivirus firms.
All of the infections of Kaspersky customers appear to have been targeted and show no indication that a specific industry, such as the energy industry, or specific systems, such as industrial control systems, were singled out. Instead, the researchers believe Flame was designed to be an all-purpose tool that so far has infected a wide variety of victims. Among those hit have been individuals, private companies, educational institutions and government-run organizations.
Symantec, which has also begun analyzing Flame (which it calls “Flamer”), says the majority of its customers who have been hit by the malware reside in the Palestinian West Bank, Hungary, Iran and Lebanon. They have received additional reports from customer machines in Austria, Russia, Hong Kong, and the United Arab Emirates.
Researchers say the compilation date of modules in Flame appear to have been manipulated by the attackers, perhaps in an attempt to thwart researchers from determining when they were created.
“Whoever created it was careful to mess up the compilation dates in every single module,” Gostev said. “The modules appear to have been compiled in 1994 and 1995, but they’re using code that was only released in 2010.”
The malware has no kill date, though the operators have the ability to send a kill module to it if needed. The kill module, named browse32, searches for every trace of the malware on the system, including stored files full of screenshots and data stolen by the malware, and eliminates them, picking up any breadcrumbs that might be left behind.
“When the kill module is activated, there’s nothing left whatsoever,” Gostev said.
UPDATE 9 a.m. PDT: Iran’s Computer Emergency Response Team announced on Monday that it had developed a detector to uncover what it calls the “Flamer” malware on infected machines and delivered it to select organizations at the beginning of May. It has also developed a removal tool for the malware. Kaspersky believes the “Flamer” malware is the same as the Flame malware its researchers analyzed.
http://www.wired.com/threatlevel/2012/05/flame/
Saturday, May 26, 2012
Picture Is Worth A Thousand Words
It's Saturday and a three day weekend. What more could a person ask for? Since it's a fun filled weekend I figured we could use a couple fun geek images. The first one is one of my favorite geek images and the second is just funny.
Friday, May 25, 2012
Links, Links, and More Links
Hello All,
Today’s Geekness is a list of links that provide a lot of useful information. The below list is where I get some of my information. I wanted to share because there are some really interesting articles that can be found. My favorite by far is Wired.com. I also get the magazine and it is worthy of a few hours of perusing. I hope you enjoy and have a wonderfully Geek filled weekend.
https://www.zdnet.com/blog/security http://cyb3rsleuth.blogspot.com/
http://www.threatexpert.com/ http://www.shadowserver.org/wiki/
http://www.thedarkvisitor.com/ http://packetstormsecurity.org/
https://isc.sans.edu/ http://www.emergingthreats.net/
http://blogs.securiteam.com/ http://www.wired.com
http://garwarner.blogspot.com/ http://blog.fireeye.com/
http://www.malwaredomainlist.com/mdl.php http://slashdot.org/
http://www.darkreading.com/ http://www.theregister.co.uk/security/
http://www.dailychanges.com/ http://contagiodump.blogspot.com/
https://threatpost.com/en_us/blogs http://nakedsecurity.sophos.com/
http://www.cyberesi.com/blog/ http://targetedemailattacks.tumblr.com/
http://arstechnica.com/ http://www.reddit.com
Today’s Geekness is a list of links that provide a lot of useful information. The below list is where I get some of my information. I wanted to share because there are some really interesting articles that can be found. My favorite by far is Wired.com. I also get the magazine and it is worthy of a few hours of perusing. I hope you enjoy and have a wonderfully Geek filled weekend.
https://www.zdnet.com/blog/security http://cyb3rsleuth.blogspot.com/
http://www.threatexpert.com/ http://www.shadowserver.org/wiki/
http://www.thedarkvisitor.com/ http://packetstormsecurity.org/
https://isc.sans.edu/ http://www.emergingthreats.net/
http://blogs.securiteam.com/ http://www.wired.com
http://garwarner.blogspot.com/ http://blog.fireeye.com/
http://www.malwaredomainlist.com/mdl.php http://slashdot.org/
http://www.darkreading.com/ http://www.theregister.co.uk/security/
http://www.dailychanges.com/ http://contagiodump.blogspot.com/
https://threatpost.com/en_us/blogs http://nakedsecurity.sophos.com/
http://www.cyberesi.com/blog/ http://targetedemailattacks.tumblr.com/
http://arstechnica.com/ http://www.reddit.com
Thursday, May 24, 2012
Yahoo FAIL
Here is one of the fun parts about my job. I get to research things like this. Yahoo has accidentally released their Private Key. I am guessing that someone has been fired over this. This is a good article to read and is a great example of how important it is to check over your work.
Yahoo Includes Private Key in Source File For Axis Chrome Extension
Yahoo on Wednesday launched a new browser called Axis and researchers immediately discovered that the company had mistakenly included its private signing key in the source file, a serious error that would allow an attacker to create a malicious, signed extension for a browser that the browser will then treat as authentic.
The mistake was discovered on Wednesday, soon after Yahoo had launched Axis, which is both a standalone browser for mobile devices as well as an extension for Firefox, Chrome, Safari and Internet Explorer. Yahoo is touting the browser's predictive search capability, which will guess what the user is trying to search for as she is typing and bring up thumbnail images of potential matches.
But that's not the thing that got the most attention. Within hours of the Axis launch, a writer and hacker named Nik Cubrilovic had noticed that the source file for the Axis Chrome extension included the private PGP key that Yahoo used to sign the file. That key is what the Chrome browser would look for in order to ensure that the extension is legitimate and authentic, and so it should never be disclosed publicly.
"The certificate file is used by Yahoo! to sign the extension package, which is used by Chrome and the webstore to authenticate that the package comes from Yahoo!. With access to the private certificate file a malicious attacker is able to create a forged extension that Chrome will authenticate as being from Yahoo!" Cubrilovic wrote in an analysis of the problem.
After realizing the mistake Yahoo had made, Cubrilovic created a cloned, forged extension for Chrome, signed it with the Yahoo key and then installed it on Chrome with no problems. He uploaded the code for the original Axis Chrome extension and his own spoofed one to GitHub.
Yahoo officials said that they are in the process of publishing a new, repaired extension.
"The clearest implication is that with the private certificate file and a fake extension you can create a spoofed package that captures all web traffic, including passwords, session cookies, etc. The easiest way to get this installed onto a victims machine would be to DNS spoof the update URL. The next time the extension attempts to update it will silently install and run the spoofed extension," Cubrilovic said in his analysis
http://threatpost.com/en_us/blogs/yahoo-includes-private-key-source-file-axis-chrome-extension-052412?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular
Yahoo Includes Private Key in Source File For Axis Chrome Extension
Yahoo on Wednesday launched a new browser called Axis and researchers immediately discovered that the company had mistakenly included its private signing key in the source file, a serious error that would allow an attacker to create a malicious, signed extension for a browser that the browser will then treat as authentic.
The mistake was discovered on Wednesday, soon after Yahoo had launched Axis, which is both a standalone browser for mobile devices as well as an extension for Firefox, Chrome, Safari and Internet Explorer. Yahoo is touting the browser's predictive search capability, which will guess what the user is trying to search for as she is typing and bring up thumbnail images of potential matches.
But that's not the thing that got the most attention. Within hours of the Axis launch, a writer and hacker named Nik Cubrilovic had noticed that the source file for the Axis Chrome extension included the private PGP key that Yahoo used to sign the file. That key is what the Chrome browser would look for in order to ensure that the extension is legitimate and authentic, and so it should never be disclosed publicly.
"The certificate file is used by Yahoo! to sign the extension package, which is used by Chrome and the webstore to authenticate that the package comes from Yahoo!. With access to the private certificate file a malicious attacker is able to create a forged extension that Chrome will authenticate as being from Yahoo!" Cubrilovic wrote in an analysis of the problem.
After realizing the mistake Yahoo had made, Cubrilovic created a cloned, forged extension for Chrome, signed it with the Yahoo key and then installed it on Chrome with no problems. He uploaded the code for the original Axis Chrome extension and his own spoofed one to GitHub.
Yahoo officials said that they are in the process of publishing a new, repaired extension.
"The clearest implication is that with the private certificate file and a fake extension you can create a spoofed package that captures all web traffic, including passwords, session cookies, etc. The easiest way to get this installed onto a victims machine would be to DNS spoof the update URL. The next time the extension attempts to update it will silently install and run the spoofed extension," Cubrilovic said in his analysis
http://threatpost.com/en_us/blogs/yahoo-includes-private-key-source-file-axis-chrome-extension-052412?utm_source=Threatpost&utm_medium=Tabs&utm_campaign=Today%27s+Most+Popular
Wednesday, May 23, 2012
A Joking Geek Is A Happy Geek
This is my first real post on my journey to becoming a full fledged geek, and I think that it would only be appropriate to start it off with a few geek jokes. Adding humor to life makes everything better.
1. There are 10 types of people in the world: those who understand binary, and those who don’t. 2. If at first you don't succeed; call it version 1.0 3. I'm not anti-social; I'm just not user friendly 4. My software never has bugs. It just develops random features 5. 1f u c4n r34d th1s u r34lly n33d t0 g37 4 l1f3 6. Bad or missing mouse driver. Spank the cat? (Y/N)
I know that they’re bad jokes but they make me laugh. If anyone is reading this please feel free to post your own geek jokes. I would love to hear them.
A Little More About Me:
I work in a very technical job and have for about a year and a half now. I have learned so much in that time that it blows my mind, but I still feel that I am not where I should be. I love my job and could not imagine a better group of people to work with. They have no problems explaining things to me that I don’t understand and we are constantly joking (this was my inspiration for making my first post jokes). But I feel that need to step up my game.
I hope everyone has a wonderfully geek filled day.
1. There are 10 types of people in the world: those who understand binary, and those who don’t. 2. If at first you don't succeed; call it version 1.0 3. I'm not anti-social; I'm just not user friendly 4. My software never has bugs. It just develops random features 5. 1f u c4n r34d th1s u r34lly n33d t0 g37 4 l1f3 6. Bad or missing mouse driver. Spank the cat? (Y/N)
I know that they’re bad jokes but they make me laugh. If anyone is reading this please feel free to post your own geek jokes. I would love to hear them.
A Little More About Me:
I work in a very technical job and have for about a year and a half now. I have learned so much in that time that it blows my mind, but I still feel that I am not where I should be. I love my job and could not imagine a better group of people to work with. They have no problems explaining things to me that I don’t understand and we are constantly joking (this was my inspiration for making my first post jokes). But I feel that need to step up my game.
I hope everyone has a wonderfully geek filled day.
Tuesday, May 22, 2012
Who Am I
My name is Rebecca and I am a borderline geek. “What is a borderline geek?” you ask. Well, it’s what it sounds like, I am too geeky to not be a geek and not geeky enough to live in a geek world. I speak geek, but not fluently. I understand some of the jokes, but still get lost in the humor.
My father is a chief geek, with a PHD in Computer Forensics and almost 40 years in the IT world you kind of have to be. I always joked that I was born and breed geek. The truth is that when I was younger I fought tooth and nail to not follow in my father footsteps (don’t get me wrong, I love my father I just wanted to be my own person), but I didn’t stand a chance, I love Technology. Hell I learned my alphabet when I was three playing Wheel of Fortune on the computer in my father’s lap. For awhile I was convinced that the alphabet went qwerty….
Now that I am older I understand that it’s ok to follow in my father’s footstep, that it doesn’t mean I’m not my own person. The problem is I spent so much time fighting who I was that I lost out on the chance to learn a lot of things and now I’m play catch up. My father still teaches me new thing every day. I know enough that I can have a conversation with him without having to stop every two minutes and have something explained. But I am not at a point where I want to be, I have so much more to learn. That is where this blog comes in to play, I will post (try to post) one geeky thing a day. Whether it is a story, something I learned, or a joke.
My father is a chief geek, with a PHD in Computer Forensics and almost 40 years in the IT world you kind of have to be. I always joked that I was born and breed geek. The truth is that when I was younger I fought tooth and nail to not follow in my father footsteps (don’t get me wrong, I love my father I just wanted to be my own person), but I didn’t stand a chance, I love Technology. Hell I learned my alphabet when I was three playing Wheel of Fortune on the computer in my father’s lap. For awhile I was convinced that the alphabet went qwerty….
Now that I am older I understand that it’s ok to follow in my father’s footstep, that it doesn’t mean I’m not my own person. The problem is I spent so much time fighting who I was that I lost out on the chance to learn a lot of things and now I’m play catch up. My father still teaches me new thing every day. I know enough that I can have a conversation with him without having to stop every two minutes and have something explained. But I am not at a point where I want to be, I have so much more to learn. That is where this blog comes in to play, I will post (try to post) one geeky thing a day. Whether it is a story, something I learned, or a joke.
Subscribe to:
Posts (Atom)

