Monday, February 21, 2005

I woke up at 7.40am, and found that I hadn't turned the alarm clock back on (I would have turned the alarm off when I went to bed after I came home on Friday night having an asthma attack).

I got up, setup the machine to rescue more data from the disk with the corrupt partition table, onto the disk that was in the tivo.

I got ready, had a shower, dressed, breakfast etc. When I was getting dressed, I realised that my belt wasn't here. I must have left it at my mate's place, after I had a shower after the storm we got stuck in.

I dug out a crappy old belt, just need something to hold my pants up, and I left for work, I think it must have been about 8.30am I left.

It was a bit bright this morning, and I didn't have any glasses either, because I haven't had a chance to get a new pair, after I lost the lens out of the other pair at the beach on Saturday afternoon.

I got on the freeway, just a few kilometres on, there was 2 cop cars in one of the u turn bays, and 2 cops, one was holding a radar gun against the traffic, and the other guy was just standing there.

I wasn't speeding (for once) as I went past, and the guy standing there stared at me the whole time he could see me.

I watched him out of the corner of my eye, and when I'd gone past, I looked in my mirror, and saw him still looking at me.

I kept going, got fuel, kept going, got to work at 9.45am.

I sat down at my desk (I can't get in through the firestairs anymore, they've fixed the door so it shuts properly), and found that my machine had rebooted for some reason. Hmm, annoying.

I sat and did some coding for a while, no idea what I was working on.

I got an email about emails being forwarded around with virii attached to them, and ignored it, and went back to work.

A few minutes later, I got an email, with a virus attached. I forwarded it to the guy who looks after the email stuff, and then I realised that it hadn't been sent to me specifically, but that it had actually been sent to the allusers email address, so it had gone to everyone in the department, how terrific.

I wonder how many dumb users are going to click on the attachment, and infect their machines (even though they have norton antivirus on all the machines, it's as useful as tits on a bull at the best of times, letalone when the clients aren't configured properly, so they don't get updates from the management server, and you can't update them manually).

I went up to see what was going on, and the shit had hit the fan. There were virus infected emails going all over the place.

I went back to my desk, and looked at the one I had received, because I use Thunderbird, not lookOut, so I was able to easily look at the headers of the email, whereas when people using lookOut tried to look at anything to do with the emails, they were automatically deleted.

I found the IP of the machine sending them, it was at one of our remote sites.

I went back up, and told them what I'd found.

I still have the diskless machine up there, running knoppix, so I tried to kick off a port scan across the machine sending the virii out, but found that it was down (it wouldn't respond to pings either, and -P0 or whatever it is didn't help, someone must have turned the machine off).

A few minutes later another one came around the network, I looked at it, and found a very similar IP address, same site.

I port scanned that IP, and found that it had an smtp service running on it. Hmm.

It also had VNC running on it, so I remoted in, to find out what was going on, why the virus scanner hadn't found/cleaned it etc.

I'd just started poking around on the machine, found the virus definitions file months out of date, and was trying to find where I could force an update (it's not obvious when the client is configured to use a central server, "LiveUpdate" or whatever it's called is greyed out etc), when the session became unresponsive, and then VNC terminated.

I tried to ping the machine, and found that it had gone down, someone's turned it off.

The guy from upstairs wasn't in today yet, he was still sorting his car out. I called him, to find out, because someone told me that he'd be there around lunchtime (and I wanted to go for lunch), he told me that he'd been out to somewhere near Penrith to buy his car, and was just back at home now, and would be leaving in a bit, so he'd be up there tonight, but after work (to stay in the pub, and go back to work the next day).

I told him what was going on with the virii, that it was a good day to be out of the office, and that I might see him a bit later.

A few minutes after I got off the phone, another virus email came around. This time it came out of a machine in our building. Right, I want to go and find this machine, and give someone a kick up the ass for clicking on shit.

I went with the sysadmin, and we wandered around looking for the machine. We eventually found it, someone's desktop machine, they'd left it unlocked, so I was able to just sit down and start working out what the hell was going on.

I grabbed a virus cleaner application someone had downloaded, and I run that across the machine. While I waited for that, I went about working out why the machine didn't have up to date virus signatures.

I discovered that just like the other machine I'd been on briefly, they were both pointing at a management server in one of the remote sites which had been shutdown a few weeks ago. That would explain why they don't have up to date signatures, since the signatures distribution server they are using is gone.

I don't know why a machine in our building would be pointing at a server 200km away at a remote site, instead of the one in the server room upstairs though.

I grabbed the file containing the configuration, plonked it in where it goes (some obscure directory) restarted the Norton Virus services (no point calling it an antivirus service, since it's not), it picked up the file, reconfigured itself, and then I was able to force an update of the signatures.

By this time the woman whose machine it was had come back, I told her I was cleaning off a virus infection that was attempting to infect other machines on the network.

There was no point having a go at her, she wouldn't have known what she was doing anyway, and probably just dumbly clicked on an email attachment.

The clean tool finished, it had removed a few infected files, binaries etc, and the smtp service was stopped now.

The sysadmin and I finally got out to lunch, it was now 2.20pm. I don't remember where we went for lunch, but I think it was the cafe up the road we've been going to.

After that, I went to look for a new belt, I need a new one anyway, I'm almost have to put new holes in the old one, because it's too small, which is really not a good look.

I went into Kmart, and looked at the belts, they didn't have any in the right size, all far too big, or far too small.

I looked around for sunglasses too, but couldn't find any in Kmart, so I left again.

I went into Lowes to look for a belt, they had a few, and a couple that didn't look too bad, but I wasn't sure of the sizes properly, and I couldn't look at them, because there was a woman in between the belt rack and the wall, sitting on the floor, sorting out shirts or something.

I stood there for a couple of minutes, waiting for her to finish and move, but she didn't, so I gave up, and left.

I went into Best and Less, they didn't even have a rack of belts, so I left there.

I'd pretty much given up, and started heading back to work. I went past a Reject shop, and figured they might have belts, or at least glasses.

I went in, looked around, found a belt. I looked at the sunglasses, but they were all really crap.

I figured I'd keep looking for glasses. I paid for the belt, and then I left.

I didn't get a bag for the belt, because I'd heard something on the radio that morning, about the amount of rubbish we generate, and the guy was going on in particular about when you go to the shop, and get a plastic bag to carry one single thing, which is a good point.

I continued heading back to work, and a couple of doors up, there was a Go Lo shop, so I decided to look at the glasses in there.

I went, immediately thought they all looked crap, but after looking closely, I found one paiur that were alright. I grabbed them, and went over to the til to pay.

Some chick came over to serve me, asked how I was, the usual bullshit chit chat that for some reason we all feel is necessary when talking to someone, ie "how are you?" "fine, and how are you?" "I'm fine".

Anyway, she asked me how I was, "fine" was my reply, I then asked how she was, and she replied, telling me that she'd rather not be in there right ow. Wow, I think that's the first time I've actually had someone give me an honest answer to that question (I've given people honest answers a few times, but never received one before).

I told her I felt the same, and that was why I was down wandering around the shops, and not at work.

I paid for the glasses, and she asked if the belt was from there too, and I told her that I'd got it next door.

I left, and I contined back to work.

When I got back there'd been a few more virus infected emails, more remote sites doing it now.

I found that the machine I'd been in earlier was back up, so I used VNC to connect to it again. I put the updated config file, and restarted the service to fix it, and then I was just about to kickoff the cleaner tool, when whoever was using the machine came along and closed all the windows I'd opened.

I logged out of the machine, and went upstairs to find out what else was going on.

I was hanging around up there for a bit, a guy in IT had written an email explaining how the users could check their machines, to see if they had a stupid virus update server, and to let us know, so we could fix it.

I read it, fixed it up a bit, and then he sent it out to everyone.

A bit after that, someone said something about Melbourne Airport, and I wondered what was going on. We checked Sydney Morning Herald website, and found an article about a gas leak or something, and people had gone to hospital, and then airport was shut down.

I checked the Bureau of Meteorology website while I was there, found they'd issued a massive storm warning, just up north, and it was heading south.

It was supposed to have high winds, and hail, and torrential rain.

I decided I wasn't hanging around at work for it to get here, that I'd race it.

I grabbed my stuff, raced down to my bike, and took off going south. It was only 5pm. I was quite overcast, but a little way down the freeway, it was fine.

I didn't see anything of the storm or rain or anything on the way home.

I went to the supermarket and got stuff for dinner, it was still sunny when I got home, so I ran a load of washing, and hung it out.

I went back to the machine I was recovering data off, and it had all finished, and I had everything.

I had dinner, and made and drank a couple of long islands, and then I went to bed.

0 Comments:

Post a Comment

<< Home