I used to live a block away from a historical marker in the Dundee neighborhood of Omaha, Nebraska. It marked the site where one of these balloon bombs exploded (in the sky, harmlessly). It's crazy how far they could go.
Point taken; it "works" for certain values of "work."
> They could hire an army of reviewers. They just don’t.
They may actually do that too, but perhaps there are thresholds that must be met for something to reach a reviewer. I have some sympathy for Google here as I work on email security in a high-volume environment. ML is one tool in the box, and human reviewers are another. Everything is a tradeoff between resources, false positives, and false negatives.
At least my organization's customers can contact support if something is going wrong, but for people trying to legitimately use Google Ads, it can be an extremely frustrating situation of shouting into the void. (And getting boilerplate support answers back from the void.)
I'd bet just about anything that Google uses machine learning to decide whether or not to trust a site for ads. It seems like the only solution that would work at a large enough scale to handle that kind of demand (versus more defined but more labor- and resource-intensive malware/fraud detections). I think that also explains why the review process seems so arbitrary and ineffective - in essence, not even Google knows why Google decided your site was bad. I used to help people with hacked websites, but eventually I had to refuse to work on projects where the only symptom was a Google Ads denial because it was such nonsense. In one case a guy completely removed his site and replaced it with a 0-byte page, and even after we saw Google-owned IP addresses doing a crawl in the site access logs, they still told him there was malware (including a list of infected URLs that no longer existed).
If I'm correct, changing your domain might help in that machine learning algorithms consume tons of signals and maybe altering that particular one would push your site under the "bad" threshold. But it might not do anything. It's a super frustrating problem. I hope you can stumble onto a solution or find someone at Google willing to help.
Does }__ appear in your logs? All versions of all branches of Joomla prior to I think 3.4.6 had a problem with serialization that allowed arbitrary PHP execution.
The Dating Ring (YC in 2014) tried to do that. It didn't quite work out, at least not how they hoped. The second season of Startup Podcast was all about them.
I heartily recommend that podcast. Even if you're not all about startups, I think it's fascinating that they give you a first-hand look into the subjects' attempts to start their company, with recordings and interviews about things as they happen, rather than in retrospect.
Oh! I was thinking of a much more detailed writeup. I actually didn't reverse any hardware or software; I guess this was a SIGINT-only effort. Parts of my approach were inefficient or redundant, but that's because I knew next to nothing about radio, SDR, etc. when I started. I basically found out that SDRs exist and thought they sounded cool, and decided to try to use one to see what I could see around my house. In brief:
Like Andrew, I looked up the FCC ID to find the right frequency for Simplisafe. I used a RTL2832 USB device ($25, from Amazon) and SDRSharp on Windows to record the signals. I used Audacity to look at the raw recordings and figure out that it was on-off keying, with a pulse length of about 5 microseconds.
I fed those raw recordings into a Gnuradio program I built (on Kali - I had trouble setting it up on Ubuntu so I gave up and just used a Kali image). I realize now that Gnuradio can interface directly with an SDR, but at the time, I already had all the recordings saved, so I just worked with those. I wanted to use Gnuradio's fancy clock sync module to convert the pulses directly to symbols, but I couldn't get it to work. So I used a threshold detector instead, with a rate limiter, so the output consisted of strings about 120 1s or 0s per pulse. I wrote a Python script to convert those into a text representation with just a single 1 or 0 for each pulse.
It was easy enough to identify a preamble that comes with each transmission, and then most of my effort went into comparing like transmissions from different devices (e.g. "door open" from my three door sensors), or different messages from the same device (e.g. "door open" vs. "door closed" from the same sensor). If their encoding scheme is a standard or well-known one, I certainly wasn't able to find it. It took a lot of frustrating dead-ends to finally figure it out.
With that done, I wrote more Python code to decode a recorded transmission, or put together a transmission representing any device ID I want, any message I want, etc. I used an Arduino and a cheap 433MHz transmitter/receiver device ($5 from Amazon) to send my transmission, and my base station heard and acknowledged it. I haven't done much more with it since then.
I'd like to, but I'm not sure how to proceed. I don't know if I should try notifying Simplisafe, and/or give people more time to get rid of the system. I also don't have a good way to publish - I don't have a personal website or anything. Any suggestions?
I did a similar project with Simplisafe, but I went the SDR route and figured out their protocol, so I can forge sensor/keypad messages or decode PIN entries from keypads. (I'm in contact with the IOActive researcher, Andrew, to share this information.) It was a fun learning experience. My original goal was to just get the damn system to reach my detached garage (which is about 25 feet from my house).
In his blog post, Andrew said he didn't bother to reverse-engineer the protocol because if you can replay a "disarm" command with the correct PIN, that's everything you need. That's probably true, but it could also profit an attacker to record someone's PIN in case they use it for other things. And depending on the limits of the Simplisafe base station, you could potentially brute-force a "disarm" from every possible device ID - most likely, you'll eventually use the ID of a keyfob associated with the system, so it will disarm. Then you'd have control without the user ever entering their PIN.
These things are largely academic, I think. It's been known for a while that you can just jam the system by transmitting at 433MHz while you kick down the doors or whatever. Very cool anyway.
On the other hand, now I can build my own sensors and add them to my system, if I want. Or build a repeater so I can finally have a keypad in my garage. :)
"I just can't imagine living in fear of some concealed-carry-permit holding goon deciding to shoot the place up."
You don't need a concealed-carry permit to carry a concealed gun; you just need one to do it LEGALLY. I would venture to guess that a person who carries concealed with the intent of committing murder will not have bothered to get a permit.
My reasoning for keeping a killing machine (it lies around either in a safe or on my person at all times) is because crime happens, and criminals are willing to do things like use force and/or weapons. Police can't be everywhere, and while their response time here is pretty good, it's generally more than enough time for the criminals to do what they want and escape. I'd be happy to go back in time and un-invent guns, but as it stands, I don't see any way to remove all of them from all criminals' hands. So it seems to me the only viable preventive measure is for citizens to defend themselves with the same tools the criminals illegally use to commit their crimes.
- Dogs. Obviously this won't work for everyone, as you may not like dogs or be allowed to have them or able to afford them. Also not all dogs will be effective alarms; one of mine starts growling if she hears a butterfly down the street, while the other one would unlock the door for a burglar if she could, just hoping he'd pet her.
- Lighting on all points of entry. I have time-controlled lights on the doors and motion-sensing floodlights on the detached garage. All are LED so they're fairly efficient and long-lasting.
- Simplisafe security system. It's self-installed, wireless, and no contract. Depending on your subscription you can get monitoring only, or monitoring plus a mobile and web app. I really got this more for the 24/7 smoke and carbon monoxide alarm monitoring, but the entry and motion sensors are a nice addition. (If you do have dogs, you might consider declining police dispatch though.) And there are little stickers / signs to try to scare off burglars.
- A large can of pepper spray (stream, not spray). I don't own a firearm (and I'd really rather not use it in the house even if I did). I think someone breaking into the house would most likely be a burglar and would rather flee than get in a fight, so I think a non-lethal solution is good to have.
- Cameras. I have a mix of brands of wireless cameras and iSpyConnect, watching the entrances. This is more for me to check in on things remotely, but the recording could be handy too.
- Neighbors. I'm not super-close friends with mine, but I'm neighborly, and we look out for each other.
- Insurance. If you're renting, make sure you have renter's insurance. A security system may get you a discount on your home or renter's insurance also. And an automatic offsite backup system is a good idea, of course (I use CrashPlan).
Leaving out all the other "mysteries" of the story, I still don't understand how the entire wormhole/tesseract/etc. occurred if Murph had to use Cooper's data to save humanity. Isn't that a paradox? If humanity perished, how did it ever reach the point of manipulating space/time to construct the wormhole, summon Cooper, etc.?
I freelance dealing with these kinds of problems, and I wanted to correct one thing.
The article states that the message "The site may be compromised" appears in Google result pages when "the site has been hacked and complete control is taken by some third party without any owner’s permission. Anyone can contact the webmaster and help them to resolve this issue."
That's not true. It means that Google has seen content on the site that doesn't meet Google's standards - in other words, there's spam on the site. Usually this means the site is hacked and spam content has been added through various means:
- obfuscated code added in legitimated script files, which only displays when the visitor's user-agent string is a search engine bot
- a script that generates tons of static files with keywords it receives from a distributed spam network
- links and text in invisible page elements added directly to a database (like Joomla or Wordpress)
I've also seen the occasional instance of this warning when there was simply a lot of spam on a site (e.g. in forum posts). Once you clean it up, you do have to use Webmaster Tools to get Google to reconsider and revoke the warning. It usually takes one to two weeks.
By contrast the "This site may harm your computer" warning refers to pages with content that attempts the installation of malware. You can also use GWT to clear this warning and it's much faster - within a day, generally.