Tuesday, July 24, 2007

Less lies, more interface.

It's been going on for too long now - video game marketing has been on a steady march down the tubes since 1996. I've gotta say, I'm awful disappointed by an industry created by the more recent generation, but not surprised.

The particular offense in question today is the common practice of posting "screenshots" of games with no interface or actual gameplay, usually featuring in-game cut scenes and cinemas instead. Similarly, posting trailers or whatever the hell marketing wants to call them with no actual footage of gameplay.

Take for example, the World of Warcraft site. Besides other offenses (giant JPEG backgrounds), it's a well known example of this crime against good taste. During normal gameplay, you can press ALT-Z to hide the interface, but you can't actually play the game like this, and I would estimate that 97% of the time, most players don't use the feature during a session.

Their website has approximately 170 screenshots, only 4 (2.35%) of which actually feature images containing the interface that you'll be staring at 97% of the time. That makes that portion of the site about 97.65% filthy fucking lies. Furthermore, it features 29 movie trailers/demos with a total of 16 (55.17%) scenes of actual gameplay. Not as much of a lie, but not too far from one either.

To put that in perspective, it's like those children's toys ads where 80% of the commercial is the 'theme' of the toy and 20% is actual play with music to make it sound like more fun. I can tolerate that, because kids are stupid. However, the majority of MMORPG players are not between the ages of 8-12, now are they (or are they)?

Final Fantasy XI is possibly an even worse offender. In order to take a screen shot you HAVE to turn off the interface. No exceptions unless you use an external utility to do it for you. There's no explanation for it, so it's probably safe to presume they don't want the game's extremely obtuse interface (amusingly absent from the Wikipedia page) to show up in screen shots.

Even more disappointing is when a game's "Screenshot" section cops out entirely. Take this example from the Age of Conan's (upcoming MMORPG) website.


See that? See the angle? Do you think the camera tilts at that angle during normal gameplay? I hope to hell it doesnt. That means it's a cutscene. But more importantly, the game has titties yet they're censored in the screenshot. Well, which is it; am I gonna see me some titties, or not?

Sadly, it takes a
childrens game to get it right. For shame, marketing departments, for shame.

Saturday, July 21, 2007

Failure of the week - Nipplemania


This is a new 'section' which will be updated every Saturday.

See, I hate blogs, really. More accurately, I hate people blogs (blogs about people, livejournal, for example). If I wanted to read some random assholes diary, I'd phone a number in the book and ask them to reveal their personal lives to me. Of course, on the phone no one in their right mind would do such a thing, but on the internet, well, that's different.

It will feature one lucky blogger and a special examination of their postings and the following:
  • Narcissism
  • Camwhoreism
  • Ugly colors/layout
  • Number of 'friends'
  • Moronic hardcore political/religious association and rants
  • Bad poetry/Emoness/Teenage Angst
  • ...And more!
I was originally planning to call this 'fag of the week' but remembered that I have nothing against homosexuality, and to put the bottom feeders on par with with them would be insulting.

This week we'll be taking a look at 'Nipplemainia'.

It goes without saying; If you want to find bad blogs, look no further than Xanga. I didn't even have to go further than the second page of google searches to come across this little gem.

Before I get into the details of the posts, let's start with the profile:
Name: Serena
Country: United States
State: New York
Metro: South Glens Falls and Glens Falls
Birthday: 9/9/1983
Gender: Female
Okay, a 24 year old from upstate New York. Your classic yuppie, nothing strange there.
Interests: cars (muscle cars, 60's vintage, some 70's), music (hard rock, heavy metal, grind, gore, what-thefuck-ever as long as IT HAS SOME BALLS) men... real men that talk like men, and don't want to organize my fucking closet. cats, horseback riding.. naturally world domination and the end to all existence.. did I forget I like roses too? :D
Expertise: sarcasm, dry humor, the obvious, artistry, and poetry.
Occupation: Computer related
Industry: Business
Vintage cars, okay. Her taste in music is questionable at best..but, what do we have here? I see, she wants a man to treat her like dirt and slap her around a bit. I can do that, I think. But hello, what's this?! World domination AND destruction? One or the other you dumb bitch. Can't have your cake and eat it too. Note the expertise and occupations; "Artistry/Computer related". That's going to be important later..

We're going to skip over the contact information and subscriptions, and skip straight to the "Blogrings", whatever the hell those are.

 ~*~ My Creative Imagination ~*
~`ART is muh Evrthing`~
 Painting Pictures with Words
 Poets Corner
!!!~DEAD POETS SOCIETY~!!!
my sarcasm is better than yours...so i win
Oh yeah, we got some real gems here. Teenagers of all sorts posting quality art and poetry. Clearly she's a patron of the fine arts. But enough boring profile details, let's move on to the good stuff, the posts!

You don't have to go more than two posts down to get to the bottom of this 'mysterious artistic blog'. Before you can even finish saying 'camwhore' you're confronted with a cold hard dose of her reality:


"Artistic Nudes" Yep. Sure. Right. Let's be honest here. Before us is a sad, neglected 24 year old who does anything for the short lived attention of a horny 16 year old looking to blow a load looking at some titties or some asshole macho boyfriend. Oh, and don't forget, pictures of cats.

But, let's not be too judgmental here. Perhaps her poetry can tell us something about her 'depth'.

Written: June 2, 2007
Title: W o r s h i p
I feel alone; perhaps not alone
so much as empty and helpless
with a fear inside of me so strong
I can't stop it from coming out.

I loved you and have for so long
it gets harder each moment to
tell truth from inner sanctions;
I've built a temple for you.

I envy your resonance and pray
for my rebirth in your mercy;
Surrendering my soul to your all
while I worship you.
© ~Serena~


Nothing there either. Hang on, I think I just threw up a little...

Had enough yet? No? Well, here's her info so you can get even more of her!
Message: message me: email me
Website: visit my website
AIM: nipplemaniea
Yahoo: neoandromedaxo
I personally recommend her website. She has no less than 3 blogs and two art-website accounts linked from there.

In conclusion, a classic narcissistic camwhore, no ifs/ands/buts about it. If you read this; please - get a life, make someone in your family at least a little proud of you. Go to school, get a real job, do something other than post your naked ass on the internet. We have enough of that already.


Friday, July 20, 2007

TTNET, Routers, Default Passwords and YOU!

I maintain a mail server, and occasionally check my logs. Occasionally, I investigate hosts that attempt spam, see why they were reject and what lists they were in, etc. Well, yesterday, I found something amusing.

A number of spam have in the past, come from a turkish ISP called TTNET.

Curious to see if a web server was operating on one of the hosts (many spammers have simple "user name/password" logins to a web interface for the various machines or bullshit "unsubscribe" forms), I popped a few IP's in my browser.

What I discovered...

See that? That's a login screen for a router.

I know what some of you are thinking, there's lots of those out there, right? Not with the default password set.

That's right, you can just log on in! In fact, the router even WARNS you to change the password, how thoughtful!

..Well, actually, it just asks you politely. Of course, if you're lazy, stupid, or just a DSL installer for a turkish ISP, you can just mash ignore and pretend you never saw it.

From there, you can do pretty much anything you want including (but not limited too):
  • Set up port forwarding to any host in the network.
  • Tun on traffic filters (some models)
  • Turn on/off view logging (some models)
  • Configure VPN settings (some models)
  • Change connection settings (notably fun: DNS for all your phishing phantasies)
  • VIEW/SET THE DSL USERNAME AND PASSWORD.


What? But they're all ***'d out?

Silly EndUser™. ***'s on webpages that aren't plopped in by auto complete are filled in by the webserver itself! I'll save that for another post, but essentially, the password is in the source, see?

See those massive black squares? That's not porn, that's user information and the associated password! Not exactly a shocker, but it further illustrates the moral of my story here. There were a number of hosts in the IP range of TTNET configured just like this, default passwords with the web interfaces turned on.

I realize turkey is probably not a upper-class high-tech heaven with super-awesome DSL installers, but there are still lessons to be learned here.
  1. Don't trust the guy getting paid minimum wage to install your service correctly.
  2. Secure your router, at least change the default password.
  3. Don't leave the "WAN Configuration Enabled" option on, ever.
  4. Don't ignore important warnings about password security.
  5. Device manufacturers do not care about security, be careful with your wallet.
If you work for a device manufacturer (HA HA HA), there's even more to learn here:
  1. Require a password change before allowing the WAN Configuration option to be turned on.
  2. Caution users about the horrific gravity of default passwords.
  3. Don't turn the WAN Configuration option on by default.
  4. Put the WAN Configuration option on a timer by default (with a stern warning before turning it on permanently).
  5. Instead of plopping the current password in a field, have a "change password" button with a separate page for setting the WAN password without the current password in it. This relieves the requirement of having to send the password in the form. (Of course, it makes recovery more difficult for us white hats.)
Well, I hope my readers (HA HA HA) learned something useful from this.