Sunday, June 10, 2012

MTGO Library Bot 4.98 is out!

The new version of ML Bot, 4.98, is now available for download. The new version contains a number of bug fixes, so an upgrade is recommended.

Friday, June 8, 2012

DNS Security (Part 4 of 4)

As we conclude this series on DNS Security, what can we botters do to improve our security?

The first step is to analyse what DNS servers you are actually using and how you can improve it.  Gibson Research Corporation has a wonderful utility for this located at http://www.grc.com/dns/benchmark.htm.  It goes into far more detail than I can here.

With the Linkedin Password leaking story of this week, it is important to remember how passwords are utilized.  Many sites will use a well known algorithm like MD5 to change the password into a blobby string.  This blobby string is then compared to a database which is stored on the server which you desire access to.

When you hear about a site losing control of their passwords, it is this database which has been compromised.  With possession of this database, the bad guys can compare these password hashes to their database of common passwords being hashed with MD5 and other hashes.  These are known as Rainbow Tables.

By the way, the fix for this is very simple, it is called Salting the Hash.  In addition to using this well known algorithm, a smart person will add their own secret salt recipe to the mix so that even knowing the hashed password, it will do the bad guy no good, and they will not know how to generate it.

So use this news story as an excuse to not only change your Linkedin password, but all your passwords.  Remember to use a long password as well, the longer the better.  If you desire a 2013 view on how passwords should be constructed, visit https://www.grc.com/haystack.htm.

Thursday, June 7, 2012

LinkedIn passwords leaked

LinkedIn confessed it had a data breach that compromised the passwords of some of its members, the social networking site said on Wednesday.
LinkedIn engineer Vicente Silveira confirmed on the site's blog that some passwords were "comprised." (http://tinyurl.com/cxje9xo)
"We are continuing to investigate this situation," he said.
LinkedIn said it sent emails to members whose passwords were affected explaining how to reset them, since they are no longer valid on the site.

If you use the same password on LinkedIn as in another website or email address, I strongly recommend you changing all your passwords.

Wikiprice now features more reliable prices

Last week we released a major improvement on wikiprice. Among the others, the prices are now updated more frequently, and the prices older than a week are automatically removed from the database.

If you are a bot owner, you will be able to see your bot listed on wikiprice in 4-5 hours after you launched it.

If you are a Magic Online user, you will find more bots and more reliable prices.

Tuesday, June 5, 2012

DNS Security (Part 3 of 4)

Last time we had a brief discussion on DNS (Dynamic Name Servers) and I identified what the problem facing many Internet users are.  Today, I’m going to list what we botters can do to see if we have been infected by this piece of malware.

First off, a website has been created to describe the problem in more detail than I did last time.

http://www.dcwg.org/

To see if you have been infected by this DNS changer malware, you visit this site:

http://www.dns-ok.us/

Since our bots are run on dedicated machines or virtual machines, these machines do not normally surf the Internet and certainly do not visit any high value sites except for MTGO Library.

So we would expect that our bot machines will pass the test.  If for some reason, your bot machines, or your primary machine does not pass the test, the website lists various fixes which are available.

Everything is pretty standard and nothing seems overly dramatic or difficult.

So why am I did I choose this series?  Because this one piece of malware, which has infected hundreds of thousands of users, had garnished such a large response from the various alphabet soup agencies and the computer security companies at large.  I was listening to David Perry, Director of Public Education for Trend Micro who said that each and every day, 50,000 pieces of malware are created.  He made a point to mention that these are unique pieces of malware, not changing a character to up the count and call it a new one.  He said that no one uses a count which include “variants” anymore.

So next time I am going to conclude this series on some advice on computer security and how we can run our bots and not worry about malware.

Sunday, June 3, 2012

Snapcaster Mage

WotC admitted that they messed up with Snapcaster Mage. I'm not going to sit here and look you in the eye and tell you that Snapcaster Mage is a fair Magic card.  Let me quote Zac Hill: "I worked with Tiago Chan to design it, and by the time they realized exactly how powerful it was in concert with the abundance of one-mana cantrips in Standard, the card was already out the door. We knew it was something we were going to have to attack in order to keep Standard in check. The challenge was deciding how best to do that. Now, before I dive into that process a little further, I want to spend a little bit of time talking about how we engineer cards that try to help put some reins on the environment. There are a couple of different kinds of hate cards. Some—like Grafdigger's Cage". With Snapcaster, you're just getting value along an axis. You might be Unsummoning twice, or cantripping, or countering a spell, or flashing back Dismember, or whatever. Snapcaster Mage, though, ensures that once your opponent has cast a single Mana Leak, it's actually more likely for your next spell to get countered than your first one, because in addition to the three remaining Mana Leaks, there are four more Snapcaster Mages capable of "turning on" that Mana Leak. This card is generating great card aventage, it has flash so that it can enter the battlefield whenever a player wants to. Therefore, you can even be killed by this creature if you are really low on life. I really don't see any drawback in this card. Snapcaster Mage is run in every possible format.

Why did I write about this right now? Well, soon WotC is going to announce the new ban list, many people are speculating that Snapcaster Mage is going to be on the list. Maybe now it is a good time to get rid off your Snapcasters.

Friday, June 1, 2012

DNS Security (Part 2 of 4)

Last time I referenced an article which states that hundreds of thousands of users may lose Internet connectivity on July 9th. 

http://www.foxnews.com/scitech/2012/05/25/google-warns-hundreds-thousands-may-lose-internet-in-july/

So what is this DNS anyway?  The best way to look at DNS, (Dynamic Name Server), is what many of us use our smartphones for.  When you decide to call John Smith, you tell your phone to not dial “John Smith” but a phone number associated with John Smith.  So you select John Smith and your phone redirects that request and dials 212-555-6789. 

DNS works the same way.  You put in www.mtgolibrary.com and your browser translates that into an aaa.bbb.ccc.ddd Internet address.

So what does this piece of malware do?  It just sits there, monitoring which DNS requests are made and if a high-value site is requested, this malware will intercept the valid request and substitute a fake answer in its place.  So instead of legitimately going to aaa.bbb.ccc.ddd for your bank, you’ll go to vvv.xxx.yyy.zzz instead.

Now what the bad guys will do is set up a site which looks and feels like your bank at vvv.xxx.yyy.zzz so that to the casual user, they’ve reached their bank.  The bad guys will even pull images from your bank’s real webpage to make the façade appear more authentic.  You then log into your bank and now the bad guys have your credentials and can now make a sizable withdrawal from your account.

So what can we botters do to deal with this silent but nasty threat?  We’ll touch on that next time.