MyBB – Forum security and what to do when hacked

June 24th, 2009 No comments

If you run a MyBB forum, you’ll want to make sure you’re secure, and also know what to do should your forum get compromised. There are many things you should know on this subject, here’s a few of them.

How to secure your forum

Strong passwords

Your password should contain lowercase and uppercase letters, numbers, and symbols. This means it’ll be much harder to guess or crack. You shouldn’t use actual words in a password, but a random mixture of letters, numbers and symbols. For example, p455w0rd123 is not secure, whereas G6ga5^&ha@6D3 is secure and will be a lot harder to guess or crack. If a dictionary list is sued to bruteforce a login, having full words in your password could mean there’s a match; if the password is random characters, this won’t be possible. A 10 character password has 3,700,000,000,000,000 possible combinations, would take a human 580,000,000 years, or a computer 59 years, to crack. You can read more about that here.

Check your CHMOD permissions

As a general rule, all files should be CHMOD to 644, and all folders should be CHMOD to 755. If files or folders are given extra permissions, it may be a security risk. There are, however, some files and folders that need different CHMOD permissions to enable them to work.

  • Required – ./inc/settings.php – 666
  • Required – ./inc/config.php – 666 (install) 444 (after installation)
  • Required – ./cache/ – 777
  • Required – ./cache/themes/ – 777
  • Required – ./uploads/ – 777
  • Required – ./uploads/avatars/ – 777
  • Optional – ./admin/backups/ – 777
  • Optional – ./inc/languages/*language*/*all files*/ – 666
  • Optional – ./inc/languages/*language*/admin/*all files*/ – 666

Protect your config.php file

When you install your forum, ./inc/config.php needs to be CHMOD to 666 so that the database details can be written to it. However, once you’ve installed, this isn’t necessary, and having this file CHMOD to 666 can be a security risk. Once you’ve installed, you can CHMOD config.php to 444. Note that sometimes it will need to be CHMOD to 666 for an upgrade script to be run, however, if this CHMOD is necessary and your file is not set as such, the upgrader will tell you.

You can also use a .htaccess rewrite rule to block direct access to the config.php file. To do this, create a file called .htaccess in your ./inc/ folder, and put this code in it:

<files config.php>
Order deny,allow
deny from all
</files>

Now, whenever someone goes to yoursite.com/inc/config.php, instead of a blank page, they’ll get a 403 Forbidden error.

Make regular backups

Database backups are essential. Files, plugins and themes can be replaced if they get lost, but a database cannot. Make sure you make regular backups, and save them on your own computer or USB stick. Don’t rely solely on the MyBB backup directory for your backups, found at ./admin/backups/; if all of your files get deleted, these backups will get deleted too. Aim to download a backup to your computer every week, or when you make some major changes or additions to your forum, and check that it is complete by uploading it to a localhost installation.

Use another account as your admin account

If someone is trying to hack your forum, they’ll automatically target the admin account, to try and get ACP access. A hacker will know that the admin user will have a coloured username and show on the forum team page, and it’s easy to stop this. First, register a new account. Then, create a new usergroup, and give it ACP access, give the username the same style as normal registered members, and put the new user into that group; this will be the account you use to administrate your forum. Now, remove the ACP access from the standard administrator usergroup. You can now still use your usual account to post, and it will look like you are an admin, but you won’t have any ACP access, so any hacker that hacks your account will see that it was a waste of time. Plus, they could never find the user that does have ACP access, as that member would have a username in the style of a normal user.

Rename your admin directory and hide ACP link

MyBB gives you the ability to rename the ‘admin’ folder to something else. Although this is a weak form of security, it can still at least slow down a hacker; if they don’t know what your admin directory is called, they can’t try to login to it. To change this, look at line 26 of ./inc/config.php:

$config['admin_dir'] = 'admin';

Change the value of this variable, from admin, to whatever you want your admin directory to be called, and then rename the actual ./admin/ folder to the same value. The, instead of going to yoursite.com/admin/index.php, you would go to yoursite.com/newname/index.php

Along with this, MyBB gives you the ability to remove the link to the ACP from the welcomeblock. After all, what’s the point in renaming the admin directory for security purposes if someone can login as your account as normal and just click the link in the welcomeblock?? To do this, look at line 36 of ./inc/config.php:

$config['hide_admin_links'] = 0;

Then, change this to:

$config['hide_admin_links'] = 1;

Now, the link to the ACP will be removed from your welcomeblock, so you will have to manually type your admin directory when you want to open it, but this means that a hacker won’t know where it is if you rename the directory.

Disallow HTML in posts

In the settings for each forum, there is the ability to allow HTML to be posted. It is advised that you disallow this unless it is absolutely necessary. Although MyBB attempts to block any malicious scripts being parsed, there is still a chance that someone could post malicious HTML. If you have HTML allowed in all forums and would like to turn it off, run this query in phpMyAdmin:

UPDATE `mybb_forums` SET `allowhtml` = '0';

Then, you need to go to ACP > Tools & Maintenance > Cache Manager > forums > Rebuild Cache. Now, HTML will be disallowed in all forums.

Hide your version number

If you show your version numbers in your forum’s footer, you are advertising to hackers what version you’re using, and if your MyBB version is out-of-date, showing that you are on an older version is almost asking them to hack you. To turn off the version number, go to ACP > Configuration > General Configuration > Show Version Numbers > Off. Now, the version number won’t show.

Keep up-to-date with upgrades

Whenever an upgrade is released, you should upgrade to it as soon as you can. Upgrades are usually maintenance (bugs), security, or feature releases. If there is a security release, you should upgrade to make sure you won’t get hacked via the exploit that’s being patched. You should use the Version Check feature in your ACP regularly, and you should also subscribe to the MyBB Mailing List to be emailed on new updates.

Once you’ve done this, your forum should be as secure as possible. However, a hacker may still somehow find a way in, and if that happens, you need to know what to look for, and what steps to take.

What to do if you get hacked

Reset passwords

Once you are able to, you should immediately change your forum password, and also the password to your database. This is to make sure that the hacker can’t just login to anything again; new passwords mean they’re back to where they were before.

Check for new users

Check all new users registered after the time the hacker gained access to the forum; there may be a chance one of them has been added to a group with ModCP or ACP access, or they may have even created a new usergroup for a user. If you see anything like this, delete it.

Reupload all files

Download the MyBB package, and upload all of the MyBB files, except ./inc/settings.php. This will make sure that all of your files are clean, and there isn’t any malicious code in any of them. Make a note of any file changes you have made before doing this, though, so you can make them again after. This process will also make sure you have all the most recent files; you may have missed an important file in a security upgrade which contained the exploit that was used to hack you.

Check your CHMOD permissions

As above, check your CHMOD permissions after you have reuploaded the files. Make sure you’re not giving files or folders extra permissions that they don’t need.

Delete settings.php

Head to your ./inc/ folder and download your copy of settings.php… and then delete it from your server. It will be generated again, with the correct values from the database, and then we’ll know it’s a clean copy of the file, with no malicious code. You may need to click around on the forum a bit to get it to regenerate; the downloaded file is there so you can upload it again should it fail to regenerate automatically.

Rebuild config.php

You can manually remake your config.php to make sure it’s clean. Use this code to rebuild the file, and enter in your database details. Also make sure you change any other settings you need to, for example, the admin directory, hiding ACP links, or super admins.

Check your templates for malicious code

A common result of being hacked is having malicious code added to your templates, meaning it’s executed whenever a page is loaded. A common place for code to be added is the header, headerinclude, index, and footer template, as these templates are loaded the most. Check all templates, however, that aren’t default (have their name in green) and remove any code that isn’t supposed to be there. It’s usually in <script> tags and is usually a load of random numbers and letters. This should be removed as soon as possible.

[Post to Twitter] Tweet This Post 

Categories: MyBB Tags: , , ,

Cars – 19/06/09

June 19th, 2009 No comments

Went out for a meal today, saw some pretty nice cars in the carpark.

BMW E39 M5

BMW E93 M3 Convertible

Lotus Elise

Some of my favourite cars there, shame I didn’t have a bloody camera on me.

[Post to Twitter] Tweet This Post 

Categories: Cars, Matt Tags:

Coca Cola Advert Summer 2009

June 19th, 2009 1 comment

I love this advert, think it’s great.

Aww the little gremlins are sweet.

[Post to Twitter] Tweet This Post 

Categories: Matt Tags: , ,

MyBB Board Status Setting

June 19th, 2009 No comments

This is something that really annoys me and I need to vent.

This is what the setting looks like when you start with, when the board is open. It’s set to ‘no’.

MyBB Board Status 1

MyBB Board Status 1

Then, when you close it, it looks like this. It’s set to ‘yes’.

MyBB Board Status 2

MyBB Board Status 2

Simple, yes?? Just a yes/no setting?? Somehow, no.

A lot of people get confused by this setting.

“Where can I turn my board online again??”

Seriously??

When it’s open to begin with, it’s set to no. When you close it, you set it to yes. Is it not common sense that to open it, you set it to no again??

People seem to think that the actual yes/no setting is for the ‘Administratirs will still be able to view the forums’ message, but that makes no sense. It’s just extra information about turning the forums offline, admins will still be able to see it. The name of the setting is at the top of the box, ‘Board Closed’, then it’s either yes/no. Yes is closed, no is open. Why would the setting name be half way down the box?? Not only that, why would there be a setting to say whether or not admins could see the board at all?? What could that possibly be used for?? “Oh yes, I know, I’m the admin but I’ll make it so I can’t see my own forum”. Ugh.

Please, people, try and think about what this setting does, use some common sense.

[Post to Twitter] Tweet This Post 

Categories: Matt Tags: , ,

Why I left the LC

June 14th, 2009 No comments

For those of you that are interested, this is why I left the LC.

The LC is a ’spoiler-free’ forum to discuss Lost, amongst other things, run by D-Coc. After C4 sold the rights to Lost to Sky after Season 2, I thought I’d have to wait until the DVDs came out before I would be able to see all the other seasons, and this was the case with season 3. I read the discussions of season 3 as it was being aired in the UK, so I had a good idea of what happened, before I got season 3 on DVD. Watched it, and it was great, but then I thought it would be the same for season 4, having to wait for the DVDs. So, I decided to try and find a site that streamed the episodes, so I could watch them closer to the time everbody else would be, it would actually be a few days before they aired in the UK. So, that was my plan. I decided at this point to rewatch the first 3 seasons, starting right from the very beginning, so it would be fresh in my mind for when season 4 started. Over the next few weeks and months I did this, and got through all three seasons.

Season 4 came. I found the site to watch it, and watched the first episode, I think it was the day before it was on in the UK. As I was watching it, I was typing up my thoughts and observations, to post in the discussion thread; I was finally able to discuss the show at the same time as everybody else. I had about a page and a half’s worth of text typed up in Word, I’d done some research on stuff from the show, looked on WikiPedia, Lostpedia etc, found some stuff out, and I was pleased with it, it was the best Lost post I’d done. When the episode was being aired in the UK, the discussion thread was opened, and I posted my reply. I had to log out then because it was getting late, but I was expecting to be able to discuss the episode with everybody else the next day.

Logged in the next day… and I was banned. The reason was that it was thought my post wasn’t written by me. Apparently, I wasn’t capable of writing stuff that was that detailed. D-Coc knew that I hadn’t seen season 3 when it was being aired, and he thought that I hadn’t watched Lost in a long time, so to have written stuff of the detail I did, I must have stolen it from somewhere else and passed it off as my own. What the fuck is that about?? All of the observations were my own, and if I got something from WikiPedia or LostPedia, I clearly stated that that’s where I got it from. He didn’t know I’d just rewatched the first three seasons, and even if I hadn’t, why does the fact that someone hasn’t seen the show in a while mean they can’t make detailed observations of a new episode?? You could say that it’s a good thing that I posted something that was better than what would have been expected of me, but I didn’t look at it like that. All I wanted to do is finally discuss Lost but I wasn’t allowed to do that. That was my last proper Lost post and I never really properly posted on that forum much again since.

I then found out that this post wasn’t the only that led to my ban. Apparently, I had also posted spoilers, i.e. posting something about an episode that hasn’t been aired yet, spoiling the episode for other people. Now I’m not going to deny that this didn’t happen to some extent but it was nowhere near the level that would warrant a ban. In the build up to the fourth season there was some speculative discussion on what people thought would happen, and I let some things slip. They were very small things, so small that I didn’t notice I said them, nobody else even picked up on them, and even if they did, the sort of stuff that I said would hardly have spoiled anything for anyone. Furthermore, there were a few people, some who registered specifically to do this, and some who were regular members, who were posting blatent spoilers, clear as day, disclosing major plot details, and posting links to spoilers. Needless to say these stayed in public view for much longer than my slips-of-the-tounge, some of these members didn’t even get banned. I received an infraction as well as a ban whilst people who disclosed much more only got an infraction, if that. This was also partly bought on by the fact that I said I don’t reading mind spoilers and sometimes look for them, but me perhaps wanting to know something about a future episode does not mean I’m then going to tell everybody else about it. A few other people looked for spoilers far more than me, and advertised the fact that they did that far more than me, yet they didn’t get banned. Included in my infraction PM was something about me saying that I had watched the episode before it had been aired, but this was posted in a thread specifically made for people to say if they had watched the episode already, so I thought it was rather odd to receive an infraction for that.

So, you get banned from a Lost forum for posting about Lost, and, despite it being a spoiler-free forum, it seems major spoilers are allowed, whislt smaller ones result in a ban.

Makes sense.

[Post to Twitter] Tweet This Post 

Categories: Matt Tags: ,

What happened to the C4 forums??

June 13th, 2009 No comments

Channel 4 (C4) is one of the four free, terrestrial channels available in the UK. It mainly broadcasts American shows, and other crap like Big Brother. They also used to show Lost, one of my favourite programs ever. They had a community forum, and, about 4 years ago, after being badgered about it for a while, I signed up.

I didn’t realise it then but the forums themselves were terrible. You weren’t allowed to upload avatars, you had to choose from their selection, which weren’t even proper avatars, they were just weird, pixelated graphics, of strange things like a cactus, sandwich, chicken leg, exclamation mark, glass of beer… it was pretty poor. The smileys weren’t much better; well, the smileys themselves weren’t terrible, but the range of them was, we used to be quite excited when a new one was added.You couldn’t post images at all, there was no [img] tag, so it was impossible to post them, and, even worse, you weren’t allowed to post links. Eventually that was changed and you could post links to things that ‘were related to the discussion’ (what else would they be related to though??) but for a while, posting a link to anywhere other than the C4 site would probably have led to a ban. Private messages weren’t available either. There was a post edit time of about 60 seconds, hardly very useful if you make a long post and see a mistake after you’ve read it through 2 minutes later. You could have a signature though, and there was the ability to use some limited MyCode. The forums were very basic, but easy to use, just a simple message board, nothing more, nothing less. You had to be 16 to register though, but everybody just used a fake birthday so it was pretty pointless. The worst point though was the moderators, but I’ll go back to that later.

I only really went into the Lost forums when I started there. There were three to choose from, the normal forum, where spoilers etc were allowed, the Spoiler Free forum, and Off-Topic; a forum where people who posted in the lost forums could talk about any other crap they wanted to. I joined when the forums were quite busy already, when they first started there used to be less forums than that, just the main Lost one, but as the show was so popular, the Spoiler-Free and Off-Topic forums were added, so when I got round to joining, there were these three. I spent most of my time in the Off-Topic forum, and went to the Spoiler Free forum to discuss Lost. This was really good, we all had a lot of fun there.

Eventually I decided to venture outside of the Lost forums and see what else was available. It was only then that I really saw the amount of forums there were. The community was massive, there must have been over 100 forums, on pretty much every C4 show, past, present, and future planned ones, as well as magazines and radio shows etc, with hundreds of thousands of users and millions of posts. Everybody would generally stay in their own forums though. People watching Lost would stay in the Lost forum, people watching Big brother would stay in the Big Brother forums, it’d be like they were all completely separate forums, not one big one with sub-forums. There would be a select bunch of regular posters in each forum who would all know each other. Occasionally, if we were a bit bored, a group of us would go and invade another forum, and post there for a bit. Then the people from that forum would come to our forum, and we’d get to know those people a bit, before they went back where they usually posted and we’d forget about them. A forum holiday, if you will, going to somewhere new for a bit.

However, at the end of Season 2 of Lost, C4 sold the rights to it to Sky, a paid service, which I didn’t have. I never really knew for sure why they sold it but the most common rumour I heard was that the ratings for the second series were much lower than they were for the first, so they thought it wasn’t popular anymore, and got rid of it. Little did they know that the lower ratings were their own fault; they took so long to show the second series, and because the show was in fact so damn popular, and it had been shown in America long before it was shown on C4, people had got bored of waiting, and had found other ways to watch it, so when it was on C4, not as many people needed to see it, as they already had, hence the drop in ratings. Since it’s shown on Sky around a week after it’s shown on ABC in America, that long wait isn’t an issue anymore. The fact that I don’t have Sky isn’t an issue though, I get the episodes off of iTunes the day after they show on Sky, so I still see them, but this was the start of the downfall of the Lost forum.

Because C4 was no longer showing Lost, people realised that the forums may soon be closed so started making their own forums for it; there were two main ones created, one was more serious, and one was more for fun, with a Lost section to discuss the show, and I was one of the few people to be active on both of these new forums. This made the number of active members and daily posts start to fall on the C4 forums. Currently, however, both of these new forums are dying out, too, becoming less and less active.

Not only were people leaving to go to the newer forums, but people were getting sick of the moderators. They would ban people for the slightest rule infringement, and there was hardly ever any chance of being unbanned. There wouldn’t be a warning, you wouldn’t be given a second chance, you’d break a rule, and your account would usually be banned forever. Some people got banned for posting a link, which was ridiculous. I got banned for posting my email address, they said they banned me to protect me, said it was a safety policy… I eventually managed to get myself unbanned. If you got unbanned once, your next ban would be final, they’d never even consider undoing it. Even the most active members, with high 4 figure or even 5 figure post counts would get banned for insignificant things. This poor moderation was going on all the time I was on these forums, members would suddenly vanish, with the tell-tale signs of a ban, having their avatar and signature removed. However, once the new forums were starting up, people couldn’t see the point in posting on a forum with such poor features and crappy rules, with the risk of getting banned for nothing, so they moved to the new forums. Sure, some of us still posted there a bit, but not much. Within a few months of Lost being sold on, the C4 Lost forum was pretty much dead.

A few people stayed there, either people who didn’t want to join a new forum, and a few of us that did stayed around to try and keep it going. More and more people dropped dead, though, until pretty much everybody who was there were newbies, hardly anyone from the original group that was there when the forum was as it’s peak.

Then, eventually, I got banned again, my second ban, meaning that was it for me. I can’t remember what I got banned for, but I know it was something that would have been totally OK on any other forum. I had 6957 posts. After that I made loads of other accounts, but they all got banned eventually, whether it was because they figured out I was using a duplicate account, or for another pathetically small rule break. I kept making them to stay in touch with the few that were left.

The next stage was time restrictions. For reasons I never quite understood, they limited the posting times from 8AM – Midnight; from Midnight to 8AM, the forums would be read-only. I couldn’t see the point in this, most of the people on the forum were from the UK, so during the times the forums were read-only, most of us would be asleep anyway, but what about the people who would be awake at that time?? Seemed silly to me.

Then, suddenly, they announced they were going to be closing the Lost forums, all three of them. They said that as so few people were using it, and as they didn’t even show Lost anymore, there wasn’t much point in keeping it going. Instantly, people started complaining, saying that as they were so small, closing the Lost forums down wouldn’t save any disk space or bandwidth, or anything like that, and pleaded to have the forums saved. Amazingly, the forum staff actually listened… kind of. They said they would close down two of the three Lost forums, but that meant totally scrapping the other two. They wouldn’t merge them into one, or archive the others, they’d totally delete them. We were each allowed to choose 10 threads to save. 10 threads?? Of all the months, years, we spent there, and all the thousands of threads we made, how could we choose 10?? Plus, as hardly anyone was even there anymore, 10 threads from each person would have been less than 100 in total. Soon after, most of our discussions were completely wiped clean. We knew that it would only be a matter of time before the last Lost forum was gone though, we didn’t think the mods would keep it forever.

Shortly after, I saw the forums were closed. Not just the Lost ones. The entire bloody lot. The entire C4 community forum was closed. Not even a read-only archive. Completely gone. All of those posts, millions of them, going back many, many years with some excellent discussions, gone. They said that there wasn’t enough money to keep them going anymore.

Although we all saw it coming, for the Lost forums at least, we couldn’t believe it when it happened. Despite the fact that the forums were poor, the mods were crap, and we all left to join other forums, these forums were where it all began, where we all met each other, and none of the other forums would have happened without this one.

So, that’s that. Rest in Peace, C4 forums. We had some great times.

[Post to Twitter] Tweet This Post 

Categories: Matt Tags: ,

Google Logo – 6th June 2009 – Tetris

June 6th, 2009 No comments

Celebrating 25 Years of The Tetris Effect – courtesy of Tetris Holding, LLC

Google Logo - 6th June 2009 - Tetris

Google Logo - 6th June 2009 - Tetris

[Post to Twitter] Tweet This Post 

Categories: Matt Tags:

Complete stupidity – Part 3

June 4th, 2009 No comments

You know those signs that you put in the back of cars, ‘Baby on Board’, that sort of thing… well, they have those suckers that you use to stick them to the window. Once I was in the car and found two window blinds on the rear parcel shelf, they attach to the window with these suckers and block out the sun. Well, I took off the sucker, and stuck it on my forehead. Just for fun. Left it there for about a minute, and peeled it off. I then got the other blind, took the sucker off that one, and stuck them both to me head, still on my forehead, above my eyes. Then I took them off after about a minute and put them on my forehead again, more to the side of my head, and took them off after about a minute. I couldn’t see anything wrong with this, I just found it weirdly amusing to stick suckers to my head.

Within half an hour, I had 5, perfectly circular bruises starting to form. This started to worry me but I thought they’d stop. No, they got worse, and in a few hours they were quite clear. Five, very round, purple bruises, in a line across my forehead. It seems the suction had pulled the blood towards the skin, and as a bruise is just bleeding under the skin, that was the result, bruises. The next day at college was interesting. I got funny looks, laughs, and a few people asked what the hell happened. I just sighed, shrugged, and explained that I put suckers on my head.

They were there for at least a week. Some were there for two.

I’ve put suckers on my arm before to see how long they stay there for, and it’s fine if I get a bruise there, nobody’s going to see that, and if they do, who cares. A line of bruises on your head is another matter, though. There was a reason I knew I shouldn’t put suckers on my head, I just didn’t figure out what that reason was until now.

[Post to Twitter] Tweet This Post 

Categories: Matt Tags:

Complete stupidity – Part 2

June 3rd, 2009 No comments

When I wasn’t rising my bike the whole way to school, I’d ride about half way, leave it at a friend’s house, and walk with him the rest of the way, then after school we’d go back to his and I’d ride the rest of the way home. One day when we were walking back, we stopped, can’t remember why, and I saw this little shiny piece of metal on the floor. I picked it up, and examined it. For some strange reason, I decided to see how smooth the top and bottom edges of it were, so I slid my index finger and thumb along the edge of it.

Turned out it was a razor blade.

Yep, I picked up a razor blade off the floor and ran my finger and thumb along the blade on either side.

Seriously.

As I did this, I watched, as it sank itself inside my thumb and finger. I quickly realised what was happening and threw it to the floor. By this point, there was already rather a lot of blood on the floor, my shoes, and my clothes. It was trickling out of my finger at quite a steady pace, and was being spurted out of my thumb a bit harder and faster, seeing as your thumb has it’s own pulse. My friend didn’t really know what to do, and neither did I, so I just squeezed the base of my finger and thumb with my other hand. Bad idea, just made it squirt out even more. Hmm. We were about a 5 minute’s walk away from my friend’s house, so he decided we should knock on someone’s door to get a bandage or something. He then saw a cyclist go past, and for reasons I couldn’t quite understand, asked him if he could help. I didn’t see how a random cyclist would be able to do anything but it turned out he lived in the house right next to where we stopped him, which was rather lucky. By this time I had blood all over me, and the cuts were stinging like hell. The cyclist guy got a bucket of cold water and I sunk my hand into that; it quickly turned a very deep shade of red. After the bleeding had slowed to a controllable level I dried my hand, wrapped it in a bandage and walked the rest of the way to my friend’s house, and his mum drove me home.

After the bleeding had stopped, we could examine the extent of the damage. I could open the cut and see quite far inside my finger and thumb, the cuts must have been a good 5 or 6 millimeters deep, which may not sound like much on it’s own but that’s a fair way to go inside a finger or thumb. I could see where the flesh had been ripped apart, was quite interesting actually. They took ages to heal, and I can still faintly see where the blade went in, 5 or so years later.

I was pretty bloody lucky I didn’t get some hideous disease from this. For all I know, the razor could have been used, been used by someone who’d taken drugs, someone who was HIV positive, someone with some other blood disorder. I also have no idea how long it had been there, could have been rusty, a dog could have pissed on it… who knows what could have happened. I had all by jabs and vaccinations up to date so I wasn’t too worried, and nothing did seem to happen, but, who knows, some things can take a while to show up…

If you ever see a small piece of metal on the floor… don’t pick it up ;)

[Post to Twitter] Tweet This Post 

Categories: Matt Tags:

Complete stupidity – Part 1

June 3rd, 2009 No comments

When I was at secondary school I used to ride my bike to and from school everyday, it was about 2 miles each way. I’d have my normal backpack with my school books, lunch etc, and, at the start and end of each term, I’d have another backpack for my PE kit. I’d take my actual kit home every week (top, shorts etc) but at the end of each term I’d also bring back this other backpack which had my trainers, football boots etc in, just to clean them, and then I’d take it all back to school again on the first day back. Thing is, I was on my bike; I had to put the PE backpack over the normal one, so I’d have two on at once, the PE one kinda sat on top of the normal one. Very impractical, kept falling off, and it looked ridiculous, but there was no other way I could do it.

Anyways, one time, at the end of a term, I was riding home, with both bags, and had a thought; would it be possible to ride with my hands crossed?? I wanted to see if I could put my left hand on the right handlebar and my right hand on the left handlebar, and kinda just ride along like that for a bit. Very odd, and rather stupid too. Anyway, I took both hands off, and that was fine, I can go with no hands for ages, but then I put my right hand onto the left handlebar.

Next thing I knew, I was lying in the road. It seems that as I put my right hand on the left handlebar, I just pulled it towards me, sharply turning the front wheel, sending me flying. My left leg was being crushed by the bike, my right leg was somehow also trapped in something, my left arm was being crushed by my body, and my head was buried in the grass verge; lucky I went off where I did as the grass ended about a foot further along, would have been even worse if I’d smashed my head into the pavement. It was quite some fall. Even worse, my right arm had been scraped along the kerb, and I had the most hideous graze I’ve ever had, from just above my elbow, to my wrist, right along my forearm, about an inch wide, bleeding quite a lot, skin hanging off, nasty, I still have a scar there now. My normal backpack was pushed right up against the back of my head, and the force of the fall pushed all the books to the top, right against my head, and the PE one was kinda on top of my head, above the other backpack, so if you were standing behind me, you’d see one above the other. Also had the studs from the football boots hit me in the back of the head which was nice. So there’s me, lying in the road, with my legs tangled up in a bike, head in the grass, a bleeding arm and with my head being covered with bags. Not the most comfortable I’ve ever been. I was slightly dazed and was lying there for about 30 seconds, wondering what the hell had happened, then it dawned on me. Heard two cars drive past during this time, neither of them stopped. What lovely people. Finally got up, picked some grass and small stones out of my bleeding arm, and picked my bike up. The handlebars were parallel to the front wheel, the force of me going over bent the handlebars round 90 degrees, turned them back round and walked home. My left ankle was killing me from having the bike and my weight forced on it, so I couldn’t ride home, had to walk, wasn’t very far though. Lucky I didn’t break my arm or something, could quite easily have happened.

So, yeah, don’t try and ride your bike with your hands crossed. It will probably end up going very badly for you.

[Post to Twitter] Tweet This Post 

Categories: Matt Tags: