Thursday, August 30, 2007

Dog Boots don't exist for a 80lb. steel spring

Review of Bark'n Boots Grip Trex

These boots display great quality materials (Vibram sole, neoprene/cordura uppers), smooth stitching and great craftsmanship. They are far better than anything else available such as Walkaboot, Ultra-Paws, Neopaws, etc). This whole shoe looks as good as any made for human children. HOWEVER, they did not fit or stay on, at least for my dog, who is like a tightly wound spring and creates a lot of traction forces when he runs and darts about.

The general design of these boots is still the same as the old version (which you may see on the clearance rack at some shops) in that the shoes only come up to the wrist, and unlike a human wrist or ankle, the width of the dog's wrist is about the same as the paw's width. That means this boot's single wrist strap holds about as well as a handcuff would on a cigar. My dog lost the first boot in less than 5 minutes after we started walking a wooded trail and continued to lose more at regular intervals.

Another problem with the fit was that the boots would flip upside down on the dog's feet so that he was standing on the uppers instead of the sole. For the boots that were not totally lost, I had to keep resetting them on his feet every 5-10 minutes. What allows the boot to twist around like this is that the inside of the boot is shaped like a cone, which allows the boot to rotate around on the foot. If the upper material was cut flatter and had more of a wetsuit stretch, it might resist that spinning better.

Relating to the boots' ability to stay on is its "side-loading" design like a slipper, as opposed to "top loading" like a human boot. Because of this and the poor holding power of just the single Velcro strap, the boot just comes off the way a tube sock would if it were pulled down to just the ball of your foot and given a few shakes. If the boot were top loading, though, the L-shape angle of ankle to foot seam would help hold the boot on, plus there could be additional lacing up the ankle as there is on a human hi-top shoe.

Another problem with the low cut is that at the back of the boot, where ankle becomes paw, the shoe suffers from "plumber butt." That is, at the L bend between ankle and foot, the shoe material hangs open in the same way that the back of your own pants opens along your rear belt loop when you bend over. This gap at the back of the shoe allows debris such as weed seeds, foxtails, pebbles, sand and other itchy poky things to fall inside the shoe where they will irritate the dogs feet worse than having no shoes at all. This could be alleviated if the upper were cut to angle up the leg a bit more before being wrapped with a second strap. A second strap could prevent things from falling inside the shoe and assist in securing the boot on the foot.

I contacted Ruff Wear about the problems of this low-top design and they said they would be coming out with another model boot that will secure higher on the ankle in Spring or Summer 2008.

After observing the performance of the Velcro in the field, I found that with a dog that runs through all kinds of grass and brush, the "sticky" side of the Velcro quickly becomes clogged with debris, reducing its effectiveness at staying fastened. I think that the straps on these boots got clogged enough to weaken the connection enough that just brushing against things on the trail and the dog's flexing caused them to release, and make the boot just suddenly open and fall off. Perhaps old-fashioned laces would be better, or else quick-adjust buckles like are used on backpack straps. Velcro in this application seems to only be good for securing dangling slack strap.

I feel part of the reason the boots stayed on so poorly was because they were not fitting properly. If you intend to buy these boots, you need to have a look at the "alternate size chart" that is buried in the FAQ on Ruff Wear's website. It is slightly different than the more common size chart that you typically see displayed near these products and it may help you pick the right size.

Also buried in their FAQ is notice that most dogs' rear feet are smaller than their front feet. Because of this, their rear feet may take a smaller size than their front feet. So, if you want to get the right fit, try on some boots at an REI store first, or order boots 2 at a time from ruffwear.com (they sell individual boots now for $15 each). Otherwise, if you just buy a set of 4 boots all the same size, as they are sold at retail, you may end up with half being too big.

Because of all these problems, I had to be dealing with boots every 5-10 minutes on the hike, instead of enjoying ourselves on it. These boots are so expensive to replace, the fact that they do not stay on as designed currently is a big problem. That said, I still would much rather have a set of boots that worked than $60 or even $100.

These did not work for me. If your dog just prances gently along, or is old and moves slowly, they might work for you.


Monday, July 30, 2007

Toyota Tacoma Seats

I came across this scanned document (click for full size view) describing the available seat types for 2005-present Toyota Tacoma while ordering waterproof neoprene seat covers from Wetokole.com.

In case Tacoma owners didn't know, the passenger seat folds flat into a table with a plastic tray for tabletop, and in between the seat back and seat bottom of the passenger seat, some models have 2 metal brackets intended for holding a baby seat.

This diagram is probably hard to find and may be useful for other modifications or accessories.

Now does anyone know whether the stock stereo has an aux audio input behind the dash somewhere for my mp3 player so I don't have to take the whole dash apart to find out?

UPDATE on aux input: No, your non-premium stock stereo does not have an aux input. But it does have a plug on the back for connecting a CD changer. The USA Spec PA12TOY adapter can plug in there, and then provide you with analog RCA stereo inputs and a native iPod dock connector so you can play your music through your car stereo.

Thursday, February 22, 2007

Recovering (or stealing) a domain registration

Most organizations don't think much about their domain registration until it either expires -- disabling their website and email -- or until the day before they intend to launch a new website at a new webhosting provider.

Often the internal employee who originally purchased a domain registration for a company no longer works there, or the web host that handled the registration as a middleman becomes defunct, and the owner is left with no record of how to access the registration. The result is that the registration is frozen, nameservers and WHOIS contacts cannot be changed and the poor mope who's been assigned the wild goose chase of regaining control of the domain name has no idea where to begin.

Where to begin is first identifying the registrar for a particular domain name. This information is in the publicly available WHOIS database. If you've never queried WHOIS, take a look at http://geektools.com/whois.php and enter any domain name. In the output, the identity of the registrar is contained in the bits of data labeled "Referral URL," "Sponsoring Registrar," or "Registrar."

Because everything these days is web-based self-service, most registrars have a self-help way to recover a password. This generally consists of going to a public page on the registrar's website (that you identified through WHOIS), entering the domain name in a form, and the registrar sending an automated message to the email address in the registrar's records that offers a way to recover or reset the password used to access the registration. Whoever can read that email will be the de facto new owner of the registration.

As a practical matter, whoever controls a domain registration controls all email and the website for that domain. Gone are the days when you needed to pay a special "registrant transfer" fee and sign papers in order to sell your registration to another party. Today, any legitimate registrar has a web interface that lets the domain owner login and change whatever data they please, including "registrant." If you want to sell your domain name, all you do now is give the username and password to the new owner, and they can login to change WHOIS info, nameservers, or even approve a registration transfer to a new registrar.

Network Solutions, the oldest registrar with the worst service and highest prices, has automated tools on their website that allow anyone on the internet to take control of a domain registration registered there, so long as that person has access to read the email of the Administrative Contact listed in the publicly visible WHOIS database. You can find Network Solutions automated login recovery page here: https://www.networksolutions.com/manage-it/forget-login.jsp

[Unlike most other registrars, at Network Solutions, total login recovery is a 2 phase project. First you have to recover the "Account ID" that NetSol arbitrarily assigns to owners, and that no one can remember. This is done by putting either the domain name or the Admin Contact's email address in NetSol's web form. Then they automatically email the Admin Contact the Account ID associated with the registration. Once you have that Account ID, you paste it into the "lost password" form, and they email the same Admin Contact a link to click that will reset the password. Whoever receives those emails can reset the password to the account, login, and do whatever they please with the registration.]

If the Administrative Contact's email address is "@" the same domain as the registration, then the organization should have an easy time reading those machine-generated emails (ask your system administrator or web host for help). However, using the same domain name as an email contact point on the registration is usually a bad idea, since if anything goes wrong with the registration (like expiration), then email at that domain name is likely to be broken and you will not be able to receive email sent to that address at the same domain name. For that reason, it's a good idea to use a permanent email address at a different domain name as a contact point on your registration, such as one from Yahoo, Gmail, or your local ISP.

In some cases, the email address for the Admin Contact that the registrar has on record may also be defunct, and if it's your job to recover that registration, you might be ready to give up at that point and start faxing blurry paperwork to Network Solutions (which, by the way, anyone, even Nigerians, can also do) to prove you're entitled to access, then waiting helplessly four days for them to get around to considering it.

An alternative is to look closely at the Admin Contact email address listed in WHOIS. If you can take over the email address marked as Administrative Contact, you can take over the entire registration of any Network Solutions registration. Seizing a registration that way means you will have control over email to the entire organization, can redirect their website traffic and more.

Because many organizations never think about their domain registration until it's expired and their entire domain is down, the contact information in WHOIS associated with those registrations is consequently not maintained accurately by registrants, either. This provides any registration recovery agent, or thief, a foothold. If the email address of the Admin Contact is one "@" a public internet service provider, you can check to see if that email address is valid anymore. If it's not, it's yours.

One can check by sending an email to that address and waiting for a bounce message or reply. Or, you can lookup the MX record of the domain name, then connect to the SMTP port on that server, and initiate a manual SMTP conversation with that server to test whether the listed Admin Contact email address is still "occupied."

For example, the Admin Contact for a particular domain name registered at Network Solutions is "swall@bigsky.net." Bigsky.net was a company bought out by bigger ISP, Amerion. Amerion continues to let subscribers (like S. Wall) have email at the original local ISP's "bigsky.net" namespace.

The organization for which S. Wall was an Admin Contact has lost its registration login info, has kept no records, and now wants to change web hosts, which requires gaining access to and modifying their domain registration.

The easiest thing we might do to resolve this is email that Admin Contact's address and see if we can get the user to cooperate and either forward or read to us whatever emails from the registrar they receive. But what if that user canceled her email service a long time ago and there's no one to answer? What if, when we email that address, we just get a bounce message with an error like "Code 550, no such user?"

If were interested in learning on a more massive scale how prevalent this condition is (Admin Contact email addresses that are abandoned), we might write a script to harvest all the Admin Contact email addresses from a list of domain names, programatically testing each Admin Contact's email address, searching for "no such user" type errors, and saving all the ones that we find in a pile labeled "vulnerable."

In our example, we're looking at the Admin Contact address "swall@bigsky.net," and after extracting the MX record of the bigsky.net domain using nslookup, host, or dig (http://geektools.com/digtool.php), we find the following MX records:
bigsky.net mail exchanger = 20 bigsky.net.amerion.mail6.psmtp.com.
bigsky.net mail exchanger = 30 bigsky.net.amerion.mail7.psmtp.com.
bigsky.net mail exchanger = 10 bigsky.net.amerion.mail5.psmtp.com.
We can test any of those mailservers (they all should behave the same) in the following way:
telnet bigsky.net.amerion.mail5.psmtp.com 25
Trying 64.18.5.10...
Connected to bigsky.net.amerion.mail5.psmtp.com.
Escape character is '^]'.
220 Postini ESMTP 157 y6_8_11c0 ready. CA Business and Professions
Code Section 17538.45 forbids use of this system for unsolicited
electronic mail advertisements.
helo whatever.com
250 Postini says hello back
mail from: someone@whatever.com
250 Ok
rcpt to: swall@bigsky.net
550 unknown user
The last response tells us that the Admin Contact's email address is up for grabs.

All of the above could be encapsulated into a fairly simple script capable of being fed a long list of domain names (or dictionary words ending in ".com") that an attacker would like to steal, extracting the email address of the Admin Contact using a little WHOIS and regular expression action, then another regex to parse out the domain name of that email address, then a lookup to pull the MX for that email address' domain, and then a little socket programming to test that MX to see if that email address is still valid. An attacker who has written the above program could have a list of 1000 popular domain names that are ripe for hijacking, overnight.

For any email addresses at public internet service providers that are invalid, all one need do to own that address is go to that ISP's website and sign up for an account. In our example, I signed up with Amerion over the phone for a $9.95/month account. Five minutes later I was receiving mail addressed to "swall@bigsky.net" through Amerion's handy webmail system. Two minutes after that (and after changing the email address listed as Admin Contact on the registration), I was canceling the account over the phone with a nice Amerion rep who did not inquire further into why I needed the service for less than 10 minutes.

Anyone could do the same with any unoccupied email address at any public internet service provider.

Being able to receive that email meant that I could receive Network Solutions' automated password recovery messages, and as soon as that happened, I had control over this domain. Lucky for this organization, they asked me to provide them with this service.

However, for all the thousands of other organizations out there with stale contact information on their domain registrations, and the chunk of those unlucky enough to have the Admin address be unoccupied space at a public provider, anyone with a stolen credit card number can deface your website, intercept your company's email, or even sell your domain name for a tidy sum to an innocent third party.

For those readers feeling uneasy about my publishing such exploits, I recommend reading the rationale of "full disclosure" and how publication actually improves security: http://www.schneier.com/crypto-gram-0702.html#4

Admittedly, though, this really is not a case of Network Solutions or any other registrar leaving a security hole in the domain registration system. Rather, this vulnerability of some registrations is really a product of the convenience demanded by consumers who are just not very well-versed in maintaining integrity or security of sensitive data.

Sunday, December 24, 2006

Could Santa Exist?

Spending Christmas with girlfriend's kids ages 4 and 6 who ask questions about how Santa delivers all these presents to good boys and girls while they sleep on Christmas eve. I say I don't know the answer, but let's figure it out together using some basic math and a few conservative assumptions.

We assume that Santa only delivers presents during the night while you're sleeping. That's why children never see him. So, in order to accomplish that before you (or another child in the same time zone) wake up, Santa must finish all his work in that time zone within about 10 hours.

Tonight, for this Christmas Eve, we're in north Idaho, and luckily for the kids, I happen to have a McNally Road Atlas showing the other places in the same time zone, along with their populations. Other places like Washington (5.8 million), Oregon (3.4 million), Idaho (half of 1.2 million), California (33.8 million), and Nevada (1.9 million). British Columbia, half of Alberta, Canada and a bit of Mexico are also in the same time zone, but we don't need to consider them for this exercise.

If we add them all up, the total number of people living in our time zone is about 46 million. Since it takes 2 adults to create one child, but one adult can create more than one child, and also that some adults have no children, let's make a conservative estimate that only 1/4th of the total population are children. That comes to about 11.5 million children (46,000,000 / 4).

Let's assume that half those children are rotten little goblins and that Santa doesn't stop at their houses. That reduces it down to 5.75 million children (11,500,000 / 2). Lets also assume that on average, there are 2 children to a household, so Santa would only need to make 2.875 million stops (5,750,000 / 2) during that 10 hour overnight span.

All this means that Santa would need to make 287,500 stops every hour (2.875 million / 10 hours). That's equivalent to 71,875 stops every 15 minutes (287,500 / 4). Or 4,791 stops every minute (71,875 /15). If Santa worked at this pace, he would have to slide down the chimney, drop off presents, eat the cookies that you leave out for him, and fly off away again at a rate of (4,791/60) 79 houses per second!

If all these reasonable assumptions are true, and with the distances of thousands of miles, then that would mean Santa moves faster than the speed of light, which Einstein said was impossible. Theory of Relativity aside, how could a man so fat move that fast?

And if he could, on a sleigh built by elves, wouldn't the U.S. military shoot him down and haul all the wreckage back to Area 51? Why wouldn't they? After all, Santa delivers presents to children around the world, including to terrorist states like Iran, North Korea, and Syria. And anyone who provides aid or comfort to our enemies is also our enemy. Even if it's Santa Claus.

So if you still think there's a Santa Claus, then go to sleep!

Wednesday, November 22, 2006

Itiva, quanta, venture capital, snakeoil

Recently came across a startup called Itiva, claiming to have technology to bring high quality media to PC's without bandwidth worries. It involves a lot of long noun chains, new paradigms, and revolutionary but proprietary Quanta™. Sounds like snake oil to me.
"Itiva provides the first scalable, reliable and economic Internet video delivery platform"
False. There are plenty of scalable, reliable video platforms, the latest of which is bittorrent. Apple.com/trailer serves video content all day long and has for years. Google just bought YouTube that serves tons of video.
"patent-pending technology delivers fast, full screen, high quality (DVD or HD quality) video over the Internet without performance compromise"
This is not a compression technology, merely a transport technology. Therefore, I can't see how full-screen DVD quality data can ever be "fast." A movie that fits on a regular DVD is about 4 gigabytes worth of data. That will never be fast no matter how many "quanta" you break it up into.
"highest quality home theatre video experience for millions of simultaneous viewers"
Think about Apple's iTunes and how long it took to struggle for a deal with record companies in order to provide the music content. And all that music content is encoded in a "lossy" format not because Apple doesn't have the bandwidth to serve larger, better quality music files, it's really because the record companies will not allow high quality digital content to be sold like that on the internet. They are too worried about flagging CD sales and digital piracy. That's why every single bit of music for sale in iTunes is of worse quality than the CD you can buy at the store. The videos for sale there are also only about VHS quality and smaller than the resolution of a regular TV, and not because Apple can't handle the traffic. Also, look at the fact that Netflix, the internet movie pioneer, still does not offer movie downloads. It's not because of a technical problem, it's because of a legal problem. The MPAA does not want high quality video floating around the internet. So why will these media companies that own the rights to this content suddenly begin releasing it just because a technology appears that makes mass consumption more feasible? If anything, easy mass consumption will make media companies less likely to release high quality digital material.
"while popular in the illegal file sharing community, [P2P] is not suited for large-scale commercial deployment"
False. torrents are not just a way to steal copyrighted material. Torrents are used to easily distrubute large (800+meg) files such as Linux CD images by big-name vendors like Debian. Many other open source projects that take up a lot of space are being distributed by torrents/P2P. P2P has lots of purposes. And, if one of your peers happens to be on your same network, their traffic does not have to be routed over the internet to you, permitting the ISP to reap the same benefits that Itva says its own product provides (and that I'm guessing an ISP would have to pay for).
"P2P is also very costly to ISPs because it uses tunneling protocols that have a direct impact on bandwidth cost to the ISPs"
Anything that actually uses any bandwidth is going to be costly to ISPs who pay for bandwidth. Unless the data is sourced from within the ISP's network, in which case they are not generating internet traffic in order to serve it. This Itva product seems to involve a little of that but I can't see why I'd be interested in it as an ISP unless I was AOL or MSN. An ISP generally is just a conduit, not a content provider. If they are selecting and providing content, they become legally responsible for it, and why would I be interested in that mess (and losing my DMCA safe harbor) if I make a living selling connections?
"In order to keep these costs under control, ISPs have throttled the P2P protocol by using packet shapers"
And in response, people defeat that by training their P2P programs to travel over port 80 to look like other web traffic. Also, if I pay my local ISP for a 1mb/s connection, I am going to complain if they are shaping my torrent traffic down to 256k just because of the type of traffic it is. They sold me a pipe that was advertised to do a certain speed, and it's wrong for them to discriminate against certain kinds of traffic. This concerns the whole "net neutrality" debate that is going on right now. See Freedom to Tinker articles on the subject.

My point is that ISPs cant sell broadband internet connections and then expect to prevent people from using those connections in order to reduce the ISP's own bandwidth costs. Itva is not really solving a problem, the content I want is most likely not on my ISP's network, and therefore I have to get it from the internet. Breaking bits into "Quanta™" and reassembling them on my computer does not use less bandwidth. If I need a 4gig file, 4 gigs worth of bandwidth ultimately needs to be used, if there is no compression (and Itva is not a compression tool).
"designed to support the volume of rich media and streaming video available. Consequently, the video viewing experience is poor and has not yet reached a point that is comparable with traditional TV,"
and then claims 4 reasons for why that is.

Those stated reasons are part of the story, but can be overcome with current technology platforms if one is intent on overcoming them. The primary reason digital content doesn't compare with traditional content is because the RIAA and MPAA will not allow high quality digital copies to be put in the stream of commerce because they are afraid of copying.

Itva seems to be mostly some kind of proxy caching thing that ISPs are supposed to employ on their own network so that they can serve their users without having to use internet bandwidth. This means also that ISPs are supposed to pay Itva for this product, but I don't see why they would. It's going to be a long time before a good number of internet users reach even T-1 speeds (relatively low speed broadband), and that's only 1.54megabits per second.

1,540,000 bits = 192,500 bytes
1 megabyte ~= 1,000,000 bytes
at T-1 speed:
5 seconds to get 1 megabyte
500 secs (8m) to get 100 megabytes
5000 secs (1.2h) to get 1 gig.

A full screen DVD quality movie will be at least 3 gigs, and therefore take about 3.5 hours to download, even over a relatively fast T-1 or DSL rated at 1.54mbp/s. Even if my ISP has the movie proxy-cached or running special Itva software so they don't have to deliver over the internet, it still takes this long just to get it the last mile from my ISP to me. And most people have connections slower than that and that condition will be a fact of life for most ISP customers for a long time. People don't want huge files, they want small ones. And with the increasing popularity of networked mobile phones with small memory capacity, I think there will be more demad for smaller, not bigger files. See also the Freedom to Tinker article on Last Mile.

I can't see any advantage that Itva would bring. It seems like a middle man adding very little value, and worse, contributing to the proposition that ISPs need not act with "net neutrality," which is a bad thing for all consumers/internet users. Breaking large files into small peices and reassembling? So what?

One of the principals of Itiva has recently started a blog (how can you convince venture capitalists without one?) at http://www.robertarn.com/ that doesnt illuminate much about the product, but a lot about his anti-consumer position regarding "net neutrality."

The blog offers a couple of "widespread beliefs" that I don't agree in the first place are widespread, and then spends several paragraphs debunking those beliefs. Then it talks about broadcast video usage on dumb devices like TVs (and even DVRs, where your recorded content is trapped and you cannot access it except to play it back just on that DVR) and implies that the amount of usage on user-controlled computing devices will soon approach it.

Of course, it wont, because copyright holders won't put the content out there, for fear of copying, piracy, and the total inadequacy of any DRM scheme (if your machine can read the data, and you control the machine, then you can always make the machine record the data). He also spends a lot of time bashing P2P, probably because it accomplishes for free what his product will charge for. He also wrongly characterizes as "theft of services" when a paying ISP customer uses P2P. I don't like his attitude, needlessly referring to the Bittorrent creator as autistic, and for being on the wrong side of the net neutrality debate. Maybe because his product is of no use in a net-neutral environment. There's way too much hype, FUD and self-promotion. Compare it to blogs of legitimate companies, where there is no preaching, fact twisting, or arguing. This guy is after the venture capital and that's all.

Granted, I may just be demonstrating my own ignorance. When the first web browser "Mosaic" came out in 1994, I installed it on my 486, looked at it for a few minutes and said "this is stupid," and deleted it.

Wednesday, September 20, 2006

Paypal module passes STORE_NAME instead of item

The PayPal payment module (paypal.php,v 1.39 2003/01/29) for OSCommerce does not pass a meaningful item description to Paypal as a transaction is processed. Instead, the developer of this module programmed it to send the name of your store instead:
tep_draw_hidden_field('item_name', STORE_NAME) .
The result is that when the transaction completes, Paypal sends the store owner an email notification, unhelpfully describing the item purchased as "[name of your store]".

We will fix this by changing the code in the payment module to send a better description for that field. While we're at it, we'll change the code to better support stores selling multiple items in one transaction because this Paypal module comes "out of the box" designed more for single item purchase. When multiple items are purchased, this module just gives an aggregate description of the whole transaction, without any detail of what exatly was purchased.

To fix both of these problems, use the patch file below, or edit (path to your store)/includes/modules/payment/paypal.php and jump down to this function:
function process_button() {
find the line that looks like:
$process_button_string = tep_draw_hidden_field
and insert a comment marker right before it:
/*
$process_button_string = tep_draw_hidden_field
and then go down a few more lines from there until you get to the one that has a semicolon at the end, instead of a period. After that line, insert an ending comment marker:
*/
Now, after your ending comment marker (commenting out the original code makes it not operate anymore, while preserving it for reference), insert the following:
 # Multiple item payment, P. 86 of 
# https://www.paypal.com/en_US/pdf/PP_WebsitePaymentsStandard_IntegrationGuide.pdf

$process_button_string = tep_draw_hidden_field('cmd', '_cart') .
tep_draw_hidden_field('upload', '1') .
tep_draw_hidden_field('business', MODULE_PAYMENT_PAYPAL_ID) .
tep_draw_hidden_field('handling_cart', number_format($order->info['shipping_cost'] * $currencies->get_value($my_currency), $currencies->get_decimal_places($my_currency))) .
tep_draw_hidden_field('currency_code', $my_currency) .
tep_draw_hidden_field('custom', $order->info['comments']) .
tep_draw_hidden_field('return', tep_href_link(FILENAME_CHECKOUT_PROCESS, '', 'SSL')) .
tep_draw_hidden_field('cancel_return', tep_href_link(FILENAME_CHECKOUT_PAYMENT, '', 'SSL'));

# add individual items and amounts to keep in PP transaction history and notices

$i=0;
foreach($order->products as $key => $arr)
{
$i++;
$process_button_string .= tep_draw_hidden_field("item_name_$i", $arr["qty"] ." ". $arr["name"]) .
tep_draw_hidden_field("amount_$i", $arr["qty"] * $arr["final_price"]);

}
Save the file, and now every payment transaction from your OS-Commerce store that is processed with this payment module will send Paypal the item name and price of each item your customer is purchasing. The "handling_cart" field adds a single shipping fee to the entire order. If you want to charge shipping amount per item, see the manual mentioned in the code comment above and use multiple "shipping_X" fields inside the foreach loop instead.

Once you make this change, the email notices that Paypal sends to the shop owner after each purchase will contain a detailed list of what was bought. Both the customer and the merchant will also have detailed records of the itemized list stored in the Paypal transaction history. This is much better than just one aggregate item with a total price and no Paypal record of what the order consisted of.

Using my patch file to make the above change.
You can skip a whole lot of manual editting if you download the patchfile included below, save it as paypal.patch in the same directory as the original paypal.php file, and then run the following shell command:
patch -b paypal.php < paypal.patch
The -b option will make a backup copy of the original file, just in case.

Tuesday, September 12, 2006

Getting your rental deposit back

My friend gets jammed up a lot. In July it was over his deposit on a residential rental that he shared with some roommates. The landlord stopped by two days before their lease expired to express some very demanding expectations about how her crummy little shack should be returned, otherwise it was coming out of their deposit.

Landlord's list of intended charges included:
  • the brown, unwatered sections of lawn
  • replacing dead landscaping bushes
  • edging and weeding
  • professional carpet cleaning in a damp sub-basement!
  • scrubbing stains out of 60 year old grout with particular cleaning products
  • replacing a stolen freezer

My friend knew this list was going to mean a large chunk of their $1,000 security deposit would be missing when they got it back. The landlord even hired a lawn psychiatrist to come over and pad the bill with exotic plant examinations. So I was asked to be there as a mouthpiece when the landlord returned to check on cleaning progress.

I did, and let her know (in the most helpful and innocent manner) that she really couldn't deduct a thing from the deposit because 1) the property is in the same condition now as it was when she rented it to them, and 2) she never did a written "check-in" sheet documenting the original condition, and without it, the law is not on her side for making deductions from the deposit.

We went back and forth, her pointing out some alleged damage, my saying it was like that when they moved in, her saying it wasn't, and my asking then for the move-in condition of that item on the non-existent "check-in" sheet.

After some tense moments, she left. Then I went to the library to write a pre-emptive letter for my friend to get the landlord to see why I was right and she would have to give back the whole deposit. It's included below, and you may copy it freely for personal use in saving your own security deposit from greedy slumlords.


A couple of weeks later, my friend received a refund from the landlord minus just one deduction, $149 for the landlord's freezer that was stolen from the garage earlier in the year. I'm certain that without my first letter laying out the legal analysis, there would have been many more deductions.

That last $149 still bothered him because he believes the thief was the landlord's son, or someone to whom the landlord gave keys, and because they also stole gear from his truck the same night. So it was up to me to secure return of that last amount, and I had reserved some of my ammo for just such an occasion.

Here is my second letter to the landlord, wherein I prove that white is black, and black is white, according as I am paid. You may freely copy it for personal use in recovering your own security deposit.




(I should also metion that between these two letters, I laid a small trap for the landlord should she have made any deductions for cleaning. Montana law states that before any cleaning charges can be deducted from a deposit, the landlord must give the tenant 24 hours to perform that cleaning himself, in order to avoid charges. I knew that she had already promised the house to another tenant on the same day my friend's lease was to expire, and that even if she knew about that statute, she would not have wanted to go through the inconvenience of following it. If she didn't follow it, then any charges for cleaning would have been easy to recover in court, plus additional damages for intentionaly disobeying the law. In any case, this landlord never made a deduction for cleaning charges.)

The day before my deadline given in the second letter, my friend received this from the landlord, along with a check for $149.00.

I am in receipt of your letter dated August 23, 2006 stating that the freezer was taken from a locked garage, yet you stated to me last fall that the garage door was not locked and that you did not report the freezer theft to the police. Therefore, the freezer theft was due to your failure to lock the garage, and amounts to damage. The refrigerator you offered to leave behind did not include a freezer with similar capacity to the lost freezer. A judge with common sense would agree that you are responsible for the replacement freezer cost. Be that as it may, it is not worth my time to further address this matter, and am enclosing a check for $149.00, the cost of the freezer which was withheld from the deposit.


It's clear from her letter that the landlord still thinks she's right about the freezer, but probably sees that she is wrong about everything else and therefore won't take her chances in court.

Granted, my friend should not have told the landlord that he left the garage wide open, and I wish my friends would consult me by cellphone before making damaging public statements. However, even allowing that he might have left the door open, we would need to debate whether that consituted any comparative negligence in a quiet Missoula neighborhood, and even if it did, my friend's omission was not the proximate cause of the freezer being stolen. The superceding and intervening cause of it's loss was solely the intentional act of an uninvited trespasser. Such a criminal act would break any chain of causation caused by acts or omissions of my client, and render my client not legally responsible for the loss.

An uninvited trespasser could have just as easily set the whole garage on fire, and by the same reasoning, the landlord would not be able to charge the smoking pile of debris against my friend's deposit.

Though there's a small chance she's right about the freezer (very small, don't bet on it), she's almost certainly wrong on the other items mentioned in my second letter which could cause her losses upwards of $3,000.00. That's why it's good to have many arguments, as long as each is strong.

Since this landlord also happened to be a (non-practicing) lawyer, she could recognize her risk, and also her disadvantage in being held to a higher standard regarding knowledge of landlord-tenant law.

If your landlord is just some old codger who doesn't consult lawyers and goes on just as he did in feudal times before tenant protection laws existed, then you might really have to sue him. And you should. It will help improve the quality of landlords and their business practices in your area.

Actually, I am sad that Landlord did not take us on. I was looking forward to splitting the take with my friend, 90% for me and 10% for him.

Friday, September 08, 2006

Windows Key to access Ubuntu Start Menu

I was so used to using the Windows Key on the keyboard to open the Windows Start menu, I just expect it to work on Gnome panels too.

If you don't already have an Ubuntu "Main Menu" item on your panel, you can add one by right clicking on the panel, choose "Add to Panel," then scroll down to "Utilities" and click the "Menu Bar" item and then the "Add" button. If you want to move that item around on your panel, you can figure out how to do that by right clicking it.

Now to bind the Windows Key to that item. Click your panel's "Main Menu" item, then "System," "Preferences," and "Keyboard Shortcuts." Under the "Desktop" group, click "Show the Panel Menu," then press your Windows Key and you will see the associated binding change to "Super_L". Click the "Close" button on this dialogue and you are done.

Now when you hit your Windows Key, it opens the Main Menu, equivalent to the Windows Start button.

Thursday, September 07, 2006

Stop gnome-terminal screen clear

Gnome-terminal (and Mac OSX Terminal.app) clears your screen when you quit a pager or editor and I don't like it. You won't like it either if you need to refer to the thing you were just looking at after you exit back to shell. This happens with man, less, more, pico, vi and others.

Here's an example of gnome-terminal automatically clearing the screen when exiting a pager. This is what needs fixing:



Here's what it does after we fix it. No more automatic clearing:



I used to fix this problem easily in the MUD by setting an environment variable: setenv NO_CLEAR 1

But Ubuntu Dapper is no LPMUD. I searched Google for the fix. Other people had the same complaint. The best source of synthesized info I found was here.

That writer, Akkana, understood the problem and offers some solutions for everything except gnome-terminal:
"...there's no way to tell gnome-terminal to disable the alt screen behavior."
I eventually found my own solution to fix gnome-terminal that I'll share at the end of this post, but first I want to review Akkana's, since her site doesn't accept comments.

First, she correctly identifies that gnome-terminal is the source of my problem. I confirmed that by dropping out of X to a real console (CNTRL+ALT+F2), logging into my shell, and checking my TERM environmental variable:
echo $TERM
On a console, that returns "linux," and quitting any pager on a console leaves the paged info on my screen the way I want it. While in X (CNTRL+ALT+F7 to get back to X), using gnome-terminal, the $TERM variable is "xterm."

This means that I can't solve this problem under X in a way that will break my console. How limiting.

Akkana offered 3 ideas and I tried them all. The first was to create a file in my home directory called .Xdefaults (symlinked to .Xresources, just in case) that contains these lines:
XTerm*titeInhibit: true
xterm*titeInhibit: true
gnometerminal*titeInhibit: true
gnome-terminal*titeInhibit: true
and then launch new terminals both in the real xterm program and in gnome-terminal. Through trial and error, I determined that only the 2nd line above had any effect, and it only stopped screen clearing in the xterm program. That problem persisted in gnome-terminal.

If I would just use xterm, my work would be done. But I do not like xterm.

Akkana's next suggestion is to create a ~/terminfo/xtermnoalt.terminfo file and export a TERM for it into the bash environment. She provides the file, doctored xterm-color terminfo data, but with the ti/te and rmcup screen clearing bits removed. Without those, gnome-terminal is supposed to be tricked into never trying to use those features.

It sort of works, but causes an extra prompt warning that my terminal is broken:
~$ man man
Reformatting man(1), please wait...
WARNING: terminal is not fully functional
- (press RETURN)
I can hit RETURN and get the pager normally after that, and when I quit, my screen does not get cleared, but that broken warning is more irritating than the original problem.

The 'man' utility ultimately uses 'less' to do its paging, and 'less' is actually the program emitting that warning. Even though I always use 'more' instead of 'less,' and 'more' still works fine, I look at man files a lot, and I am not satisfied with these results.

Technically, I could go a bit further and just hack a fix for man. The man file on man (in the --pager option) says that man uses /usr/bin/pager for paging, and that's just a symlink to /etc/alternatives/pager, which is itself another symlink to /usr/bin/less. So I could change that last symlink to /bin/more and then 'man' and 'more' would work fine. But that is a crummy hack that still leaves pico (actually /bin/nano) totally broken:
~$ pico -w sdsd
Error opening terminal: xterm-noalt.
And I use pico a lot, so I'm still unsatisfied.

Akkana's last idea is to use a command option to 'less' to ignore terminal initializations, and yes, I could make an alias for that in ~/.bashrc so that I don't have to remember to type it (alias less='less -X') but pico would still be broken, and you know I need pico.

So I searched around the web trying to learn about termcap and terminfo. And that was hard. So instead, I downloaded all the other terminal emulators I could find, hoping to just dump gnome-terminal (apt-get install pterm aterm eterm multi-gnome-terminal konsole). I tried and hated them all.

In the end, I just got out my sledge hammer and did this:
mv /lib/terminfo/x/xterm /lib/terminfo/x/xterm.orig
ln -s /lib/terminfo/v/vt220 /lib/terminfo/x/xterm
That moves the original xterm definition out of the way, and symlinks the vt220 definition in its place. Vt220's do not do the "alternate screen" feature that makes your page disappear.

This fixes Gnome-terminal which is now being fed a vt220 definition that it thinks is xterm. Really, gnome-terminal should give users a way to turn off the annoying screen clearing feature. You and I are not the only ones that find it a nuisance.

[A reader later posted a much better solution in the Comments that uses infocmp and tic to "fix" the terminfo definition file used by the terminal program. URLs at the end of the Conclusion section.]

If you want to know how I came up with this elegant solution, I just did a 'man terminfo' (lots of websites said this was caused by "terminfo") and at the top of the page it said, "Synopsis: /etc/terminfo/*/*," so I looked in there (ls -l /etc/terminfo) and found a single README file which said that if this directory is empty, ncurses (the library in charge of cursors and terminal-like things) would look in /lib/terminfo/*/*. Looking there, I found all the term definitions and figured one of them would be without silly rmcup. Symlinking by trial and error, I found one that worked.

Conclusion

You can fix your broken gnome-terminal emulator by tampering with the terminfo definition files, and get gnome-terminal to swallow vt220 terminfo that is intentionally mislabelled xterm.

Nay-sayers may point out that vt220 is not the same as xterm and that this could cause other problems, but I haven't noticed any. If there are, they should be less annoying than xterm's rmcups screen clearing. I'm not worried. Vt220's don't have any "dangerous modes" such as those from a vt100 that can lock up a vt220's output to "line printer."

The worst result I've seen from this switch, after using it for 10 minutes, is that the X-mouse won't work in console programs like sysv-rc-conf anymore, because it's designed for an xterm, not a vt220. No big deal.

If you really hate my idea, there may be, after all, some X resources in gnome-terminal for which ti/te can be inhibited that would fix the original problem, but I don't know what else they might be called. I suppose one could read the gnome-terminal source, or email the developer, if one were (subjunctive, condition contrary to fact) very determined.

I do wish gnome-terminal had a few more user-configurable items in its menus. But at least it has a menu. Really, I'm sad that since I said goodbye to Windows, I don't have VanDyke's SecureCRT anymore.

My psychiatrist says that I should just run it under wine.

Benjamin's Reader Comments provided a real solution that fixes the whole problem correctly, rebuilding a custom terminfo definition file:

toward the end or reprinted on his own site.

This solution also works great on Apple OSX in Terminal.app. In my case, on the Mac, I am using the "Homebrew" Terminal profile, which uses xterm-color, so that is the terminal definition that I customized:

infocmp > ~/xterm-color-noclear.src
pico xterm-color-noclear.src
mkdir .terminfo
tic xterm-color-noclear.src
export TERM=xterm-color-noclear
pico .bashrc

Monday, July 03, 2006

eBay Scams Use Good English, Too

One of the comments to my original article said messages from people speaking poor English should be assumed to be a fraud, and that spotting fraud is basically as simple as that.



While that strategy will help one avoid some fraud, it does not permit one to enter a legitimate transaction with non-native English speakers. It also does not protect against attacks that come using good English, like this one:
X-Gmail-Received: 8bc0668f763bd8b5b375a143b754ccbca132c47e
Delivered-To: [my_email_address]
Received: by 10.54.158.8 with SMTP id g8cs39451wre;
Mon, 19 Jun 2006 16:32:19 -0700 (PDT)
Received: by 10.35.50.9 with SMTP id c9mr8941412pyk;
Mon, 19 Jun 2006 16:32:19 -0700 (PDT)
Return-Path: <mileaqw3@yahoo.com>
Received: from mx36.sjc.ebay.com (mxpool19.ebay.com [66.135.197.25])
by mx.gmail.com with ESMTP id w63si924779pyw.2006.06.19.16.32.19;
Mon, 19 Jun 2006 16:32:19 -0700 (PDT)
Received-SPF: neutral (gmail.com: 66.135.197.25 is neither permitted nor denied by domain of mileaqw3@yahoo.com)
Received: from sjcrow08.sjc.ebay.com (sjcrow08.sjc.ebay.com [10.6.67.61])
by mx36.sjc.ebay.com (8.13.5/8.13.5) with ESMTP id k5JNWI9B022604
for <[my_email_address]>; Mon, 19 Jun 2006 16:32:18 -0700
Received: from localhost.localdomain (localhost.localdomain [127.0.0.1])
by sjcrow08.sjc.ebay.com (8.11.6/8.11.6) with ESMTP id k5JNWIB11820
for <[my_email_address]>; Mon, 19 Jun 2006 16:32:18 -0700
Message-Id: <200606192332.k5JNWIB11820@sjcrow08.sjc.ebay.com>
Content-Disposition: inline
Content-Transfer-Encoding: base64
Content-Type: text/plain; charset="ISO-8859-1"
MIME-Version: 1.0
X-Mailer: MIME::Lite 3.01 (F2.72; A1.60; B2.20; Q2.20)
Date: Mon, 19 Jun 2006 23:32:18 UT
From: mileaqw3@yahoo.com
To: [my_email_address]
Subject: =?ISO-8859-1?B?ZUJheSBTZWNvbmQgQ2hh?=
=?ISO-8859-1?B?bmNlIE9mZmVyIGZvciBJ?=
=?ISO-8859-1?B?dGVtIDQ2NTAzMzI4MDAg?=
=?ISO-8859-1?B?LSAyMDA2ICBLYXdhc2Fr?=
=?ISO-8859-1?B?aSA6IEtMWCAgS0xYIDI1?=
=?ISO-8859-1?B?MFM=?=
=?ISO-8859-1?B??=
X-Mailer: Rest Of World Mailer=ROW::EMail

Ck1lc3NhZ2UgZnJvbSBlQmF5IE1lbWJlciBtaWxlYXF3MwoKCkRlYXIgZmxpZ2h0NTUzLCBZb3Ug
ZXhwcmVzc2VkIGludGVyZXN0IGluIGFuIGl0ZW0gdGl0bGVkIDIwMDYgIEthd2FzYWtpIDogS0xY
ICBLTFggMjUwUyAtIEl0ZW0gTnVtYmVyIDQ2NTAzMzI4MDAgYnkgYmlkZGluZywgaG93ZXZlciB0
aGUgYXVjdGlvbiBoYXMgZW5kZWQgd2l0aCBhbm90aGVyIG1lbWJlciBhcyB0aGUgaGlnaCBiaWRk
ZXIuIEluIGNvbXBsaWFuY2Ugd2l0aCBlQmF5IHBvbGljeSwgdGhlIHNlbGxlciBpcyBtYWtpbmcg
dGhpcyBTZWNvbmQgQ2hhbmNlIE9mZmVyIHRvIHlvdSBhdCB5b3VyIGJpZCBwcmljZSBvZiBVUyAk
MSw4MDAuMDAgLiBUaGUgc2VsbGVyIGhhcyBpc3N1ZWQgdGhpcyBTZWNvbmQgQ2hhbmNlIE9mZmVy
IGJlY2F1c2UgaGUgaGFzIGR1cGxpY2F0ZSBpdGVtcyBmb3Igc2FsZSBvciB0aGUgd2lubmluZyBi
aWRkZXIgd2FzIHVuYWJsZSB0byBjb21wbGV0ZSB0aGUgdHJhbnNhY3Rpb24uIElmIHlvdSBhY2Nl
cHQgdGhpcyBvZmZlciwgeW91IHdpbGwgYmUgYWJsZSB0byBleGNoYW5nZSBGZWVkYmFjayB3aXRo
IHRoZSBzZWxsZXIgYW5kIHdpbGwgYmUgZWxpZ2libGUgZm9yIGVCYXkgc2VydmljZXMgYXNzb2Np
YXRlZCB3aXRoIGEgdHJhbnNhY3Rpb24sIHN1Y2ggYXMgZnJhdWQgcHJvdGVjdGlvbi4KCgo9PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KClRoaXMgcmVx
dWVzdCBpcyByZWxhdGVkIHRvIGl0ZW0gIyA0NjUwMzMyODAwLgoKaHR0cDovL3d3dy5lYmF5LnBo
L3ZpSXRlbT9JdGVtSWQ9NDY1MDMzMjgwMAoKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09CgoKTWFya2V0cGxhY2UgU2FmZXR5IFRpcHMgCgpOZXZlciBy
ZXNwb25kIHRvIGFuIHVuc29saWNpdGVkIGVtYWlsIHRoYXQgaW5jbHVkZXMgaW5jZW50aXZlcyB0
byBidXkgb3Igc2VsbCBhbiBpdGVtIG9mZiB0aGUgZUJheSBNYXJrZXRwbGFjZS4gSWYgeW91IGdl
dCBzdWNoIGFuIGVtYWlsLCBwbGVhc2UgcmVwb3J0IGl0IHRvIGVCYXkgYXQgaHR0cDovL3d3dy5l
YmF5LnBoL2hlbHBUU0Zvcm0uCgpOZXZlciBwYXkgZm9yIHlvdXIgZUJheSBpdGVtIHRocm91Z2gg
aW5zdGFudCBjYXNoIHRyYW5zZmVyIHNlcnZpY2VzIHN1Y2ggYXMgV2VzdGVybiBVbmlvbiBvciBN
b25leUdyYW0gLSBzdWNoIHNlcnZpY2VzIG9mZmVyIEludGVybmV0IHNob3BwZXJzIG5vIHByb3Rl
Y3Rpb24gYWdhaW5zdCBmcmF1ZC4KCgo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT0KCgpOb3RlOiBJbW1lZGlhdGVseSBjb250YWN0IFJ1bGVzICZhbXA7
IFNhZmV0eSBodHRwOi8vd3d3LmViYXkucGgvaGVscD9wYWdlPWhlbHBQb2xpY2llcyBpZiBvbmUg
b2YgZUJheSdzIHJ1bGVzIHdlcmUgdmlvbGF0ZWQsIHN1Y2ggYXM6IAoKLSBZb3VyIGNvbnRhY3Qg
aW5mb3JtYXRpb24gd2FzIHVzZWQgZm9yIHB1cnBvc2VzIHVucmVsYXRlZCB0byBlQmF5IGJ1c2lu
ZXNzLCBwdWJsaXNoZWQgb25saW5lIG9yIG9mZmxpbmUsIG9yIHdhcyB1c2VkIGZvciB0aGUgcHVy
cG9zZXMgb2YgaGFyYXNzbWVudC4KCi0gWW91IHJlY2VpdmVkIGNvbnRhY3QgaW5mb3JtYXRpb24g
dGhhdCB5b3UgYmVsaWV2ZSB0byBiZSBlcnJvbmVvdXMuCgpUaGFuayB5b3UgZm9yIHVzaW5nIGVC
YXkhCgpodHRwOi8vd3d3LmViYXkucGgvCg==


As the first article discussed, the Return-Path is wrong for a legitimate Second Chance offer.



The square block of gibberish text is the message payload, base64 encoded. The encoding is probably intended to foil email providers' spam and malicious mail filtering. If so, it's a weak attack since any good mail filter will be capable of base64 decoding and examining the content. In any case, the real eBay does not base64 encode messages, so this is clearly a fake.



The above decodes to the following text in the email client:



Dear [ebay_username],

You expressed interest in an item titled 2006 Kawasaki : KLX KLX 250S - Item Number 4650332800 by bidding, however the auction has ended with another member as the high bidder. In compliance with eBay policy, the seller is making this Second Chance Offer to you at your bid price of US $1,800.00 . The seller has issued this Second Chance Offer because he has duplicate items for sale or the winning bidder was unable to complete the transaction. If you accept this offer, you will be able to exchange Feedback with the seller and will be eligible for eBay services associated with a transaction, such as fraud protection.

===================================================

This request is related to item # 4650332800.

http://www.ebay.ph/viItem?ItemId=4650332800

===================================================

Marketplace Safety Tips

Never respond to an unsolicited email that includes incentives to buy or sell an item off the eBay Marketplace. If you get such an email, please report it to eBay at http://www.ebay.ph/helpTSForm.

Never pay for your eBay item through instant cash transfer services such as Western Union or MoneyGram - such services offer Internet shoppers no protection against fraud.

===================================================

Note: Immediately contact Rules & Safety http://www.ebay.ph/help?page=helpPolicies if one of eBay's rules were violated, such as:

- Your contact information was used for purposes unrelated to eBay business, published online or offline, or was used for the purposes of harassment.

- You received contact information that you believe to be erroneous.

Thank you for using eBay!

http://www.ebay.ph/


Aside from the bad mail headers, additional problems with the content of the offer give it away as a fake. In order of highlighted material above:

  1. The thief did not know my real name, as eBay would if this were a real offer.
  2. A mistaken space between the price and period at the end of a sentence, and the pound sign and item number.
  3. Reference to ebay.ph which is the eBay domain for the Phillipines. I don't shop there.


I write back, agreeing to pay. The thief replies using a Yahoo mail account from an AOL IP address that, combined with the timestamps in the mail headers and a subpoena for billing records, law enforcement could use to track down an actual person.



There is no foreign accent in this message, so you cannot rely on broken English alone to alert you to bad deals.



Hello,



This is John Mitchell, owner of the bike, writing you my terms of sale in order to complete our deal.

The winner of the auction was unable to follow through with the purchase so I decided to use eBay's Second Chance Offer service to contact the other bidders. You are the first one to answer and the selling price will be your highest bid placed on my listing. This will also include the shipping charges to your address. Yes, I will take care of delivery as I have a cousin which owns a shipping company and he will gladly do me this favor.

The bike is in excellent working condition and with clear title. You will receive all the necessary papers to get the bike registered into your name. You have my word that you won't be dissapointed [sic] in this unit.

As for payment, I would like to let eBay handle the transaction, as I am currently out of the country on the Carribean Islands. I am a scenic photographer and I am working for a new project here. So eBay will be the best solution for the both of us. I need your full name and address and also your eBay user id to start the process with them. They will then email you an electronic invoice for your purchase along with the payment instructions.

I will be waiting for your reply in order to conclude this deal as smooth as possible.
Thank you very much for your time.



Best regards,

John Mitchell

Scenic Photographer


  1. Offering you free shipping preys upon the victim's desire to get something for nothing. It also keeps the price set at the amount the victim was last willing to pay. The thief does not want the victim to back out over shipping charges! Of course, if you go back and look at the auction this fraud is referring to, the real seller explicitly states:
    winning bidder pays all shipping charges!


  2. The thief's general promise that all "necessary papers" will be included tends to show that the thief does not know what the necessary papers are, and is therefore, not the real seller. Different states have different titling requirements. A real seller would say, "this comes with a bill of sale because my state doesn't require titles," or, "the title has already been notarized," something more specific, demonstrating knowledge that a legitimate seller would know.

  3. The claim of being a "scenic photographer" is just misdirection and an attempt to lull the victim into a false sense of security. The fact that the thief's signature at the end of the email includes a job title, but no phone contact information shows again that this is a fraud. Anyone with a "signature" that lists a job title will also list a phone number. Besides, if you're about to spend a few thousand dollars, a real seller would give you his phone number to make sure the sale is completed. Thieves won't because they need to hide in the shadows of the internet.

  4. The reason the thief wants your full name and address is because he wants to dummy up a fake shipping Bill of Lading to make you feel like you are actually going to get the merchandise. The reason he wants your eBay user ID is because he needs to generate a fake invoice from eBay that wouldn't look authentic without referring to your eBay user ID, and at this point, the thief doesn't have that because he doesn't know which victim you are.



    He sent many fake offers to multiple victims through eBay's "Contact Member" feature, which only reveals your user ID to him, and not your email address. When you reply to the first fake offer, the thief has your email email address, but no clue which eBay user ID it is associated with. Of course, if he only sent one fake offer and received an answer, he'd know the eBay user ID, but these thieves don't work that slowly. This fraud is taking place on a massive scale.


I reply to this message, providing a fictitious name, address and eBay ID. I confirm my last bid amount, intentionally supplying the wrong amount. His reply, by Yahoo Mail from another AOL IP address:


Ok,
you will receive the payment instructions from eBay first thing tomorrow morning.
please get back to me as soon as you hear from them.
Thank you.


As promised, the next morning, I receive this forgery:

X-Gmail-Received: 61bfa50c689e879991fa8974e1c9b24bd9771fcc
Delivered-To: [my_email_address]
Received: by 10.54.158.8 with SMTP id g8cs1138wre;
Thu, 22 Jun 2006 06:53:33 -0700 (PDT)
Received: by 10.37.18.36 with SMTP id v36mr2024819nzi;
Thu, 22 Jun 2006 06:53:33 -0700 (PDT)
Return-Path: <escrow@ebay.com>
Received: from mbe0.msomt.modwest.com (mbe0.msomt.modwest.com [216.220.25.82])
by mx.gmail.com with ESMTP id 40si955960nzf.2006.06.22.06.53.32;
Thu, 22 Jun 2006 06:53:33 -0700 (PDT)
Received-SPF: softfail (gmail.com: domain of transitioning escrow@ebay.com does not designate 216.220.25.82 as permitted sender)
Received: from findnot.com (mail.findnot.com [202.157.176.101])
(using TLSv1 with cipher EDH-RSA-DES-CBC3-SHA (168/168 bits))
(No client certificate requested)
by mbe0.msomt.modwest.com (Postfix) with ESMTP id 12B26D9057C
for <[my_email_address]>; Thu, 22 Jun 2006 07:53:13 -0600 (MDT)
Received: from findnot.com (findnot.com [127.0.0.1])
by findnot.com (8.12.11/8.12.11) with ESMTP id k5MDu3FS010458;
Thu, 22 Jun 2006 09:56:05 -0400
From: "eBay Escrow Service"
To: [my_email_address]
Cc: mileaqw3@yahoo.com
Subject: Invoice for your eBay item #4650332800
Date: Thu, 22 Jun 2006 09:55:54 -0400
Message-Id: <20060622134740.M92493@findnot.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=OPENWEBMAIL_ATT_0.141870155780449"


Looking only at the mail headers, the email is clearly a fraud. Although the Return-Path and From fields are nicely forged, the Received headers show that the mail originated from an anonymizing service called findnot.com.



The message portion of this forged email was very sloppy, saying only:


Dear [wrong_ebay_user_id],

Your payment instructions are attached to this message.

Thank you for using our services.

eBay Escrow Team.


The email contained an HTML attachment, which eBay would never send. I viewed it because Gmail will disable any embedded web-bugs and scripting, but normally, you should never open any file attachments unless you asked for them or know what you are doing.



The attached document was an amateurish forgery of an eBay invoice listing the fake Buyer Information that I provided, the wrong price, the thief's false Seller Information, and these instructions:


Please visit your bank and make the payment by wire transfer using the below details of our eBay agent #27:

Account Holder : Joel Rojo
Bank Name : La Salle Bank
Bank address: 68 Stratford Drive, Bloomingdale, IL, 60108
Checking Account #: 5308953453
Bank Routing #: 071000505

Confirm the payment by sending us the bank payment receipt to:
Fax Number (312) 276-8546.


This is a real bank and a real account number (the thief needs to be able to retrieve his money!). In order to open a bank account in the U.S., you need to provide quite a bit of identification. Therefore, it would be relatively easy for law enforcement to capture this criminal by serving a subpoena on the bank for his account records.



Sadly, no law enforcement agencies are interested in pursuing this. I contacted the Illinois Attorney General's Office and got no response. I also talked to an FBI agent on the phone who let me know that his agency could not help unless damages exceeded $100,000.



So again, in a case that was even easier to investigate than the original (the trail in that one led to Germany), no law enforcement agency would take any steps to stop and punish this crime. Meanwhile, the thief continues to try to steal from people (perhaps 10, 50, 500 per day) every day.



Considering that it is well within the thief's ability to contact 100 marks per day using robot harvesters, mass mailing, and other computing power, he could have easily approached over 800 people in the week between the time he contacted me and the writing of this article. If just 2% of victims fall for the scheme (I would bet money the rate is much higher), and the average damage is $2,000 then this thief and others like him can collect (800 * 2% * $2,000) over $30,000 per week -- with no resistance from any law enforcement agency!



In just 4 weeks, this thief can crack the FBI's $100,000 minimum, but because he's stealing smaller amounts from many victims, no single victim will get any help from the FBI, which is probably the only agency technically capable of investigating and prosecuting this kind of crime.



EBay does not pursue reports of this kind of abuse, either. More than a week after I sent them a detailed report about how the person who's eBay user with email address "mileaqw3@yahoo.com" was using eBay's "Contact Member" system to perpetrate fraud, that user still has an open eBay account with which to commit these crimes.