Sunday, June 29, 2008

Power Outage 6/28/2008

It rained yesterday. Thunder, lightning, then gentle summer showers on and off until the sun came out.

And then some nutjob took out a telephone pole (what an archaic sounding phrase - I suppose they're "power poles" these days). It was brutal. The power bounced hard about four times and then everything that wasn't on a UPS went dark.

The juice was out for two hours. It drained all three UPS's. When it started flowing again my DHCP lease had expired and BOT House & company got a new IP address:

75.179.182.137

Write that down (and remember, port 32777 for BH and port 38777 for EX///).

An IP change is ALWAYS a major pain in the ass. I don't use Dynamic DNS so I have to log on to GoDaddy's DNS servers and change... everything. And for as much as I've been ragging on them for the past few weeks, I have to say their DNS runs better than it ever used to be. The changes were damn near instantaneous and all my... ahem... covert connections at work found their way back home within a few minutes.

Stunning work, GD.

Saturday, June 28, 2008

Back to Business

I have decided to stop boring you all with proxy business so I have split off all the project notes here. There are links to the pertinent blog postings on the project so that if you're really interested you can go back and review.

It's time to get back to other stuff. First off, check out this shit (click the pic for a larger view):

The joint has been jumpin' lately. I have never seen so many folks banging away at the UT servers. There are probably two reasons for this:

GoDaddy finally fixed the ftp issue (for now at least), but they gave no explanation. I would have bothered them for one but I was getting very tired of dealing with them. The best tech support, in my opinion, is no tech support at all. Just make it run right and leave me alone, fellas.

I leave the Map on the screen when I kick back in the evening and watch TV or read a book (I'm currently reading a biography of W.C. Fields if you give a shit). Every now and then I look up and it seems like the entire world is killing each other in my fambly room. It's quite extraordinary.

I'd like to do a time lapse video of the Map but I haven't figured out how to do that yet, short of a real time capture and iteratively doubling the speed in Windows MovieMaker. I think it would look pretty cool.

Be that as it may, I have a lot of bloggable things going on. Our security group recently got re-orged at work and that has been loads of fun. Our new Chief Security Officer is very Web 2.0 and he commands us to blog on our intranet SharePoint server (big woof) at work. I'm already slacking off on that piece. My "editorial style" is definitely NSFW ("not safe for work") so I think I'll do it my way here and then tone it down for the retards at work.

Like anybody actually reads that shit.

Or this shit, for that matter.

WTF is going on in Bahrain?


View Larger Map

If you've been following the Proxy List since it went online (and I know you haven't since all the hits I've been getting are from Google - but what the heck, I'm usually just talking to myself here anyway) you may have noticed that Bahraini proxies take up about 30% of the list.

All of the lists I poach show the same thing. Somebody is scanning the fuck out of Bahrain.

I've done a small random sampling/reality check and found that the proxies are, indeed, answering. None of them are ping-able, but that's not surprising since a lot of Web sites started following Microsoft's lead when they shut off ICMP to their servers in the late 90s (can you say "Ping of Death", boys and girls?).

All the addresses I've checked belong to Bahrain Telecomm. None of them have DNS names.

And the few I've scanned have only port 80 open. Because there is no server banner, my initial, expert evaluation is:
  • Bahrain Telecomm is new at the ISP business
  • They have no clue what they're doing

The alternate view, which I consider less likely, is that their customers have been hacked. No, these are probably access points or cable modems or, simply, some sort of distributed cache setup for their client base.

In the process of reality-checking my reality check, I have started to get some "403 Access Denied" responses from addresses that were working yesterday. The Bahraini proxy surge may be over soon.

[ OK, quick Smurf joke:
Q. What do you call a Smurf from Manama?
A. Bahraini Smurf ]

I have seen these proxy surges dozens of times. I used to use Proxy4Free back in the heyday of proxy lists (roughly 2001-2005, since then it's been relatively useless). They would have pages and pages and pages of Chinese and/or Brazilian proxies (port 6588 was big in Brazil for some reason) that, by the time I got to them, were all offline.

Those ISPs obviously discovered the error of their ways and fixed everything. You can't blame that kind of massive idiocy on the end user (well, you can and they probably did).

You may have also noted a slew of Japanese "proxies" at the end of the list. These have been reality-checked as well, and they're all junk. They will disappear sometime on June 30th, when the Master Reality Check process kicks off next (it runs on Monday, Wednesday, and Friday). After a typical Master Reality Check the list will go from ~450-500 proxies down to ~350.

For some unknown reason those Japanese sites are proxy judge pages (here is a random sample - it won't bite), so they look like proxies to my algorithm. I have found a way to distinguish them from the genuine article and will be implementing that this weekend.