BBB - Baby Behind Bars

No comment required:

BBQ @ Lavi’s

Last night we went for a BBQ at Lavi’s house, who happens to live just a few mins (walking distance) from our house. Candice and Pia enjoyed real grass in Lavi’s backyard:

And the kids inside practiced their babysitting skills:

Thanks Lavi!

Happy Birthday Pam!

Happy Birthday to the geek in Philadelphia who can be seen figthing the other two Boggle-Titans of the family in this picture from Christmas 2001.

And if you ever end up at a hospital in Philly and happen to be under her knife, I suggest some serious bribery with an XBox-Game or a voucher for a dinner at Morimoto before she starts using the knife.

Baby induced exercise

I mentioned before that we have a little wireless camera in the baby’s room pointing at Pia’s bed. Every 20 secs it will take a snapshot and store it on my web server. From there we can distribute the images to a number of locations in the house (the TiVo in the bedroom and the Media Center PC in the Living Room). While Pia is sleeping we often have the Media Center PC play an endless loop of latest pictures, which means we see Pia on the TV set and the scenery changes every 20 secs.
Last night around 6pm we also had the TV showing us the sleeping baby. At one point when I glanced at the screen, I saw this:

What you see is little pea just after she woke up. She pulled herself up on the side of the crib and is standing on her mattrass holding on to the rail. At this point, more than half of her body are above the rail, which means that if she leans forward she’ll get over the rail and fall about 4-5 feet onto the carpet.

Well, when I saw this on the screen I dashed from the living room to the nursery in no time and found out that little baby had fallen backwards into the crib. Candice was laughing, because she had never seen me running so fast.

Ten minutes later I was working on lowering the mattrass in the crib …

The irony …

It would be funny if it wasn’t so sad:

(my.yahoo.com headlines from 5/19/2004)

The laughing sequence

I was forced to post this entry - Candice was standing right behind me with a big long knife and asked me to finally post the pictures where the little Pea is smiling. Most often she looks so serious and we had to show the world that she can smile as well:

Ebay Scam: What do yernadop, Randy and supfly2k@hotmail.com have in common?

Friday I received another “phishing” email (see also: ebay “Account Verification” scam / yernadop and Ebay Account Verification - yernadop again - Wake Up! on this site). This time I was directed to another hijacked server at https://203.229.212.233/ebay1/ebay1/index.html (not linked for obvious reasons).

The page at this URL showed the well-known “Verify your EBay account” page which again included entry fields for all sorts of personal stuff (like SSN, Bank account numbers, PIN numbers for your ATM card, etc.).

I went to the site, looked around and managed to get a nice directory index by going to https://203.229.212.233/ebay1/ebay1/. Here’s a snapshot of this directory:

Index of https://203.229.212.233/ebay1/ebay1/

Again I see “yernadop” appearing in some of the files/directory-names on this site. However this time there’s more stuff.

In one of the source files (verified.html) I find this fragment of HTML code:

<TD><IMG height=1 src="https://203.229.212.233/ebay1/ebay1/My%20eBay_com%20Items %20I'm%20Bidding%20On%20for%20supafly2k@hotmail_com_files/spacer.gif"
width=180></TD>
<TD><IMG height=1 src="https://203.229.212.233/ebay1/ebay1/My%20eBay_com%20Items %20I'm%20Bidding%20On%20for%20supafly2k@hotmail_com_files/spacer.gif"
width=1></TD>

Those are the definitions of two fields in a table which use the same content, an image called “spacer.gif”. The interesting part here: It seems that the creator of this file was not very careful. Notice that “supafly2k@hotmail.com” appears in the “filename” for the images. This happens when somebody uses a browsers feature to save an existing web page (the original at ebay.com) and then reuses the save d files on another web site. I now know that the person who saved the files has an ebay account and uses supafly2k@ebay.com as the username/handle.

The second thing I noticed was the following. In some of the directories on the hijacked site I find WS_FTP.LOG files. Those files are created by a popular windows FTP application (see http://www.ipswitch.com/Products/WS_FTP/) and provide a log of all transfers that happened from a source location to a destination location.

Here are three sample lines from one of those WS_FTP.LOG files:


2003.12.21 17:48 B C:\Documents and Settings\Randy\My Documents\ebay1\ebay1\eBay Verification_files\1_active_35x35.gif --> 080803.netfirms.com /www/eBay Verification_files 1_active_35x35.gif
2003.12.21 17:48 B C:\Documents and Settings\Randy\My Documents\ebay1\ebay1\eBay Verification_files\2_disabled_35x35.gif --> 080803.netfirms.com /www/eBay Verification_files 2_disabled_35x35.gif
2003.12.21 17:48 B C:\Documents and Settings\Randy\My Documents\ebay1\ebay1\eBay Verification_files\3_disabled_35x35.gif --> 080803.netfirms.com /www/eBay Verification_files 3_disabled_35x35.gif

The first sample line says that on December 21, 2003 somebody transferred an image called “1_active_35×35.gif” from the source computer to the ftp-server at 080803.netfirms.com in the directory “/www/eBay Verification_files”. This “somebody” again was not careful and revealed part of his/her identity because we can see “Randy” appearing in the path to the source document.

This links yernadop, supafly2k@hotmail.com and “Randy” together. Let’s wait for the next phishing email to collect more information …

PS: The https://203.229.212.233/ phishing site seems to be down this morning.

Grab bag of recent baby pictures

Sometimes I feel like I’m taking too many baby photos, but then family/friends seem to demand it. So here’s a grab bag of recent photos of the little pea. No comment, because those really don’t need a comment:

 

 

 

 

Cactus’ getting ready to bloom

About two more weeks (if the weather stays nice and warm) and we should see an explosion of blooming cactus around us. Every day when we walk the dogs we can see more and more cactus getting ready to show us some amazingly colorful flowers.

You’ll see it as well when it happens …

 

 

|