Monday, April 9, 2012

Anatomy of a Phishing Scam

As my Information Technology major in school has a concentration in network security, I have been learning a lot--especially lately--about the variety of tactics that hackers will use to compromise our networks, gain our usernames and passwords, and even steal our digital identities.

Also, as I work at a web design company and am now fluent and certified in HTML and CSS, two basic web programming languages, and have a general understanding of other languages as well, it has inspired me to take a closer look at the scams and "hacks" that we see--and often disregard--on a daily basis.

In this article, I will take a closer look and analyze three types of attacks:  A Facebook "hack," a mobile SMS (text message) scam, and the classic email scam.

The Facebook "Hack"

Everyone has seen what is commonly referred to as a "Facebook hack" or scam, and most people have grown wise enough to disregard them without a second thought.  These "hacks" can often be easy to recognize, as they are usually mass-distributed messages from your Facebook friends whose accounts have already been compromised, requesting that you visit some obscure URL (web address) to see an "outrageous video" or obtain some sort of special offer.

If these messages are uncharacteristic of the friend, such as a message to check out a viral video of a schoolgirl pole dancing in her dorm room when you know that the friend is devoutly religious and would never post such a thing, it should immediately raise a red flag in your head that the post is not legitimate.

However, sometimes mere curiosity or a cleverly worded scam might fool someone into clicking the link.  The screenshot below is of a scam post that was posted one of my friend's wall.  The post was published by one of his trusted friends, most definitely without their knowledge.


So, if someone posts something like this on your wall, or you notice it in Facebook's News Feed, how do you know whether or not it is legitimate or if it is indeed a scam?  Well, there are a few warning signs to look out for.

First of all, read the message in the screenshot above, and then ask yourself, "Is this how my friend actually talks?"  In this case, I don't actually know the person who left the message on my friend's wall, but I can clearly tell by reading it that it sounds more suitable to being spoken by a used car salesman and not somebody whose profile picture is of him on a walk with his daughter.

Second, I see the link to a URL that I don't recognize.  If it was a link to YouTube or CNN or another website that I had heard of, I would probably click on it without any question.  But if it is a site like the one above, I myself would be a bit skeptical about where it might take me.  Now, maybe this is just me being paranoid, but when it comes to Internet security, I live by the motto "better safe than sorry."

If I encounter a website that I wish to visit that could quite possibly be legitimate, I will oftentimes highlight and copy the URL, open an Incognito window if I am in Chrome (which is done by holding down Ctrl+Shift+N) so that it is not in in a browser window that is already logged into my Facebook account, paste the link in the address bar, and then go to the website.  Also, since I understand HTML and how to read it, if a site looks suspicious to me, I will first view it in its pure source mode by typing "view-source:" (without the quotes) into Chrome's address bar, followed by the URL.  However, this is more of an advanced technique.

The third sign that the post in the above screenshot is suspicious, which is most often a tell-tale sign of a Facebook "hack" is the information next to the timestamp on the post.  In the example above, it says "March 23rd at 1:24am via Check It Out!"  The mere fact that the post was done via some kind of Facebook app tells me that this individual must have clicked on a link that asked them to install an app on their Facebook account.  Before installing an app, you will always receive a notice of what permissions you are giving the app over your account, but most people disregard these warnings and proceed with the installation.  But without reading it, you may be opening the door wide open to your Facebook account to a malicious app and saying "Come on in!"  The app can then post on others' walls in your behalf, as seen above.

Now let's take a deeper look into what this particular post does.  I followed the steps I mentioned in a paragraph above to view the source code of the link, and discovered the following:


The link in the Facebook post actually had a trail of website redirects, meaning that going to that website would simply forward you on to another website, and then another, and then another.  Scammers will use this tactic to have several routes to their malicious trap, in case one or more of the web addresses get flagged as spam links and are blocked or present warnings.

Finally, I was able to trace the redirects to an actual website.  This website had code written to track a visit to the web page and reported the visit back to the Facebook app, in an attempt to "prove" to Facebook that it was a well-traveled page, attempting to fool its anti-spam filters.  After tracking the visit, the website would then promptly redirect the user to the final destination where, in this case, it would offer its free Six Flags passes.

If one were to actually view the website, it would look professional and raise no suspicions in regards to what it offers.  Essentially, it would look like any other website.  But a closer look at the code behind the page would tell a different story.


The first thing I noticed in the code is that it mentioned a number of tickets left, trying to get the visitor to hastily enter their information so that they could claim their ticket before they ran out.  However, the code says differently; the remaining number of tickets is static, meaning that it never changes.

The website would ask the visitor for their information as a way for the ticket to be delivered.  In this way the visitor promptly hands over their name, address, phone number(s), email address(es), and other information, which can be then be used to sell to third-party marketers, meaning that you'll be getting a lot more phone calls during dinner.  If the scammers are smart, they may also ask you to create a username and password, or what you think is a username and password.  Why would they do this?  Well, because many people use the same username and password for several accounts online.

Yesterday I had a friend approach me and have me look at an email that she had received, claiming that her Gmail account was going to be deactivated if she didn't click on a link and enter he login credentials. She did so and nothing happened.  I looked at the email, and noticed some tell-tale signs that it was a scam email that had somehow made it through the filter (but we'll get to email scams later).  After finding out that she had already provided her information to the false website, I asked her if she had another other accounts that used the same login credentials, and she said that her Facebook and even her PayPal account used the same information.  I told her to promptly go through the real channels to change those passwords, but what if she hadn't been warned?  How long would it have taken before her savings account had been emptied via PayPal?

In the Facebook example that I have been citing, I was actually impressed (for lack of a better word) that the scammers even took legality of their actions into consideration with their scam website, providing official Privacy Policy and Terms and Conditions pages...essentially "covering their bases."  This is what I found--in the code--when I viewed the Privacy Policy:


Notice how they blatantly say that they will be selling your information to third-party marketers and that you will be receiving special offers via phone calls, emails, etc.  The Terms and Conditions page showed a similar message:


The visitors may say to themselves, however, that "at least there is an unsubscribe button at the button of the page, so I won't receive marketing ploys if I don't want them, right?"  Wrong.  I viewed the source of the Unsubscribe page, and this is what I found:


Essentially, the unsubscribe page shows a form where they can enter their email address to unsubscribe from the offers, but in this case they are literally just going through the motions, because this form is simply an empty shell.  Although it looks like it submits the information, it never actually gets sent anywhere.  In other words, there is no unsubscribe option.

So, as you can see, Facebook "hacks" can have dire consequences, but only if you ignore your common sense and click on things that you probably shouldn't.

Text Message Scams

A few weeks ago, I got a text from an unrecognized number that my Google Voice account (which I love, as it's directly integrated with my Sprint phone) told me was from Washington DC.  The message told me that I had won a $1000 gift card from Walmart and could obtain it by entering a promo code at a certain website.


As crazy as it sounds, I didn't drop everything I was doing and click on the link while popping open a bottle of champagne when I got the message.  In fact, I even showed  it to my family, who said that they'd all received the same text message at different times over the past few days.  In fact, my mom said that she had heard a story on the news, mentioning a disgruntled ex-employee of Walmart that was sending out a phishing scam.  Whether this text is from the same source, I do not know.

I was curious to know what the link actually did so, like with the Facebook hack mentioned above, I used Google Chrome's "view-source" feature to check out the HTML code behind the "offer."  What I found was this:


Instead of routing the user through several domains like with the Facebook hack, this pulled up a page at the direct URL.  From looking at the HTML, it appears that the page displays a form which asks the visitor to input a variety of information to "claim their prize."  This input includes a first name, last name, email address, up to three phone numbers, and even a username and password.  The data is then submitted to a PHP file that is a server-side script that I did not have access to view.  But let's just assume that it doesn't use the data collected to generate a legitimate Walmart gift card and email it to the customer.

So what would happen if someone were to fall into this trap and fill out their information?  Well, first of all, that person would soon become fast friends with Mr. and Mrs. Spam.  Not just email spam, but text message spam as well, and possibly even telemarketing calls and/or scams.  (Is there a difference?)

If the visitor enters a username and password, they are compromising themselves in many ways, mainly because the majority of computer users tend to use the same username and password for several different accounts, as was the case with my friend mentioned in the previous case.

I would sincerely hope that people wouldn't fall into a trap as obvious as this, but if nobody fell for them, then scammers wouldn't take the time to generate false websites, so it definitely makes me wonder how many people were caught in the Walmart Scammer's net.

Spam Emails

Everyone hates spam email, but thanks to sophisticated filters within web-based email services like Gmail and Hotmail, many of us never have to deal with them unless we decide for some reason to go exploring in the Spam or Junk folder.

Another nice feature that has been incorporated into such web-based mail systems is the validation of emails from particular companies to prove their legitimacy, especially financially-related emails such as from banks and PayPal.  Hotmail, for example, will show a green shield next to emails like these.


But phishing scammers still try to catch those that are less vigilant with similar emails.  I have always been a fan of web-based email systems--Gmail in particular--and often wonder how well applications such as Microsoft Outlook, Mozilla Thunderbird, and others detect spam messages.

There are many tell-tale signs that can be used to detect whether or not an email is from a legitimate source.  Let's take the following email that I found in my own spam folder as an example:


The first warning sign, obviously, is the warning message displayed in red by the email system itself, warning the user that the email appears to be malicious in nature.  However, the other signs may be obvious to some yet more subtle to less-experienced users.

The wording of the email itself is at least attempting to sound professional, but for a company as renowned as Chase bank, I would expect something a bit more formal.  Also, if the user wasn't already mentally blinded by panic at having his or her account deactivated, it would be hard not to raise an eyebrow when seeing that the email from Chase Bank was supposedly sent from an email address from a very strange domain, being email.discover.com.  If it was a legitimate email from Chase, wouldn't it come from an email such as abuse@chase.com or something similar?

On a similar note, it is curious that the web link itself is from a strange domain, being fbren.com, as opposed to Chase's actual website.  These are things that I notice in a heartbeat and even laugh about, when others may not even notice in their panicked hurry to reactivate their supposedly canceled account.

Wanting to see where exactly this link would take me, I once again used the "view-source" feature in Chrome to view the HTML behind the so-called "re-activation website."


I noticed that, like the first example in this blog, this website also had an immediate redirect to another website.  However, this website was quite clever in its redirect, if it's not too ironic to say so.  They used an IP address as the domain, as opposed to an actual registered domain name, and then named the subdirectory of the site in such a way that the visitors would perhaps not notice the actual address and believe in its legitimacy.

Curious to know where the attackers originated, I used a simple WHOIS command in my Linux terminal, which gave me all the information I needed to know about the hackers:


It was interesting to note from the information above that the attack was actually originating from a university in China, meaning that some bored students were performing a scam right under their instructors' noses...and doing so from the school computers.

Knowing that this website was obviously a known phishing/scam website, and being very confident in the security of my computer and firewalls, I decided to take the plunge and click on the link--using the "view-source" feature, of course--to see what would happen.  Sure enough, I was immediately presented by a warning sign from Google Chrome, warning me about visiting the website in question.


Viewing the HTML code, it was very clear to me that this was web page that was designed to look identical to a legitimate page provided by Chase, complete with logo and color scheme.  However, when the visitor entered their information, it would be submitted to a PHP file called login, which would most likely execute code to capture the visitor's login information and redirect them to the actual home page of Chase Bank, so as to remove any suspicion.


And thus we see exactly how an email phishing scam works.

Conclusion

Having a strong background in Information Technology, especially in Internet security and web development, I look at all of these attacks and laugh to myself, thinking that there is no way that anyone could ever fall for such a thing.  Yet, as mentioned previously, hackers wouldn't spend so much time meticulously designing these traps unless they had at least enough people fall into them to make it worth the effort, which is highly alarming.

Kevin Mitnick, one of the world's most renowned hackers and--believe it or not--a personal hero of mine because of his vast well of knowledge of the Internet security world, recently said a quote on his Twitter feed that really makes sense with everything that I have mentioned in this post:  "Send a man a phish and he will click on it.  Teach a man to phish and 10,000 people will click on it."

It is shocking that, in such a day and age where computers and technology are so prevalent in our lives that so many people are still ignorant to the risks they take each time they click on their web browser.  But as long as they are vigilant, they need not fall into the traps that lay waiting.

Tuesday, April 3, 2012

A Silver Medal and a Thumb Drive

Oh the joys of running into your professors while making a pit stop in the restroom at school.

About a month ago, I decided to take advantage of a few minutes between classes to hit the head.  Upon walking inside, I found a friend of mine and one of my old professors, Professor Ormond, having a conversation.  I said a quick hello, and then went about my business.

Listening in, I noticed that Ormond was telling my friend Nathan about the SkillsUSA contest, which is a nationwide contest that recognizes a variety of different technical skills at both high school and post-secondary levels.  Ormond was trying to convince Nathan to sign up for the Web Design portion of the contest, as nobody had entered the competition at the university level, and whoever signed up would automatically be competing in the statewide competition.

After washing my hands (of course) and sliding past them toward the door, Nathan promptly said, "I don't know anything about web design...but Jeff does!"  Ormond's face lit up, and before I knew what was going on, I was being dragged into his office, and was presented with numerous packets of information regarding the competition.  Needless to say, I was about forty-five minutes late for my next class.

The contest involved designing a website from scratch for a client, who would be presenting the company's web design-related dilemma, and we would need to prepare and present a solution.  This content was unique to many of the other IT-related competitions, as it required the participant to work with a partner.

Luckily for me, I work at a web hosting and design company called Marketecture now, at which I design and support websites on a daily basis.  I entered this job, already possessing a pretty solid knowledge of web programming languages such as HTML and CSS, but my company actually paid for all of us to become certified with W3Schools in both languages.

Not only that, but I work with a fellow Utah Valley University student, Travis Harley, who is very skilled when it comes to the design aspect of websites, such as using tools like Photoshop and others to create magnificent-looking designs for clients.  I asked him to be my partner in the competition, and he readily accepted.

Over the subsequent weeks, we prepared vigorously for the competition, studying up on our coding skills and gathering the equipment necessary to participate.  For example, the rules instructed us that we would need to supply a hub or switch with two patch cables, in order to provide communication between our two laptops, which we also had to provide.  I purchased a pretty nice switch on Amazon, but it ended up not making a difference, because the rules changed soon after, allowing us to have a WiFi connection during the competition.

This was a great relief to us, as it meant that we could draw upon the previous sites that we had created in designing the website for the competition itself.

The design portion of the contest took place at 8am on Thursday, March 29th at Salt Lake Community College.  Travis lives in Saratoga Springs, which is on the way to the campus, so we carpooled up there together.  Upon arriving, we were introduced to the client, who explained that he needed a blog site created.  We were told that we just needed to design the home page of the website, depicting how it would be laid out, and not requiring us to create a functioning blog.

We were provided with some images from the company to use on the website, and commenced our work about an hour later.  We immediately put our heads together to decide on a layout and wireframe of the website itself, which I drew out on a notebook that I had brought with me.  I then began the coding of the actual site from scratch, using Microsoft's Web Expression 4 software, while Travis worked with Photoshop to design the background and banner images.

We worked extremely hard, continually modifying our designs to accommodate new ideas and concepts, and by the end of our time limit had a very professional website designed, complete with a JavaScript-powered animated main navigation menu, and an image rotator as the banner, which is Travis' specialty.

In essence, I was very proud of our work.  When our time drew to a close, we placed the website on a thumb drive and copied it to the presentation laptop.  We were then told to report the next day at the same time to present to the client, along with some other professionals in the web design field.

The presentation actually went quite well.  Travis explained his reasoning behind the color scheme and designs that he chose, taking the role of web designer, while I assumed the role of web developer and described the coding behind the project.  I also displayed the code itself, which I was very proud of, having placed many comments and indentations to make it very readable and understandable to any outsider.

Later that night was the award ceremony.  We sat in an auditorium filled with people from high schools, colleges, and universities all over the state of Utah.  At long last, our division was called, and we waited with bated breath to hear what our ranking would be.

To our surprise, we took second place in the competition, which to me was a tremendous accomplishment.  We stood on a podium not unlike those used during the Olympics, and were presented with silver medals.  We were then directed backstage, where we were presented with......a thumb drive.



Apparently each division had its own sponsor, and ours was Adobe.  They had a prize, which was any Adobe software package of the winner's choice, but only for those that placed first.  But, although I didn't receive any free software, I was still extremely grateful for the work that I had done, and felt very proud of our accomplishment.  If nothing else, it proved that I was able to take a task that, at first, sounded impossible, or at least extremely daunting, and follow through with it until the end.

Overall, it was a great experience, and I'm glad that I was able to be a part of it.

Sunday, April 1, 2012

New Beginnings [...And Haters]

Well, life has pretty must been speeding past, and I've barely had enough time to breathe, let alone continue to add blog posts...especially since there probably aren't many who even read them, if anyone at all.  But, basically I began this blog to essentially give me another output medium for my thoughts, if nothing else as a way to keep my sanity and put my thoughts and feelings into words.

I have been thinking about the point of keeping a blog, and remembered the original reason for starting this blog, which can be found by clicking here.  So, since I'm getting very tempted to read the book Feed by Mira Grant again, and I know that it will give me the kick in the pants I need to start writing here again, I might as well start now.  That....and I can't sleep.

So, I'm hoping that I can start writing again, giving brief updates of my life, some music-related, and others that are not.  I want this blog to be another way for me to express myself, as doing so through music has been put on hiatus since the break-up of my band Formerly So (which I will talk more about later).  So tonight's post will be about an incident that I would like to mention involving the band, mainly because it is already past 2am and I don't want to be up much longer.

As I mentioned in the previous paragraph, my band Formerly So officially disbanded in May of 2011, which is foreshadowed by some of my blog posts around that time.  However, I don't think that I ever mentioned the disbandment on this blog, although I did on Facebook, Myspace, the band's official blog, and all of the other media used with the band to notify our fans, in the form of an official Press Release.

Here is an actual copy of the press release, as it was posted on Facebook:


Although the band may not have split up under the best of terms (the full explanation would require much more time to describe than I want to spend tonight), I still consider myself to be friends with every member of the band, albeit I haven't communicated with two of the members in quite some time, outside of the occasional Facebook "like" or comment.

In fact, not too long after the band broke up, I actually got together with Brayden (the vocalist) and his cousin Andrew (who was Formerly So's rhythm guitarist for a short time before we found Tim) and attempted to begin a new project.  We wrote a couple of songs, and even laid down a the guitar and bass tracks in ProTools on Andrew's MacBook.  Jason Stapleton, Formerly So's keyboardist--who had since returned from his mission to Romania and which whom I currently work--also stepped in for a time to make some music with us.

Unfortunately, the new project never really got off the ground, mainly because of schedule conflicts and the lack of a drummer, which slowed the motivation.  So, once again, I was without a means to play my bass, except by myself to my dog or along with iTunes.

I have thought often about doing some kind of solo project, especially now that I have a Mac Mini with 8GB of RAM and GarageBand, but that hasn't happened yet.  But, musically related, there is a light at the end of the tunnel.  I have recently jammed with Jason, in an attempt  to work on some more piano-and-bass driven songs that we could hopefully perform.  It is extremely fun to jam with Jason, as he is one of my closest friends, and we have written some pretty sweet stuff together.

I also will be trying out with a really good band called Goodnight Annabelle in about two weeks, for which I am super excited.  They are a great band, their members seem extremely friendly and chill, and I am very impressed with the music they have already written.  There is also another musician with whom I've been in contact, who wants to get together and see if I want to jam with them and possibly start a project.  So there is still potential for me to reintroduce myself to the music scene.

But now for the whole reason that I decided to write a post tonight.  As I mentioned, I am still in contact with both Brayden and Jason, but have also been in contact with Adam and Tim, if only via texts, Facebook, and other technological means.  Today, for example, Tim texted me and asked if I still had administrator rights to the Formerly So YouTube channel, which of course I do.  He informed me that some Internet troll had posted some pretty nasty comments on a couple of our YouTube videos, and to see if I could remove them.

Today was the Priesthood session of General Conference, so once I was home and able to sit down at my computer, I checked out these comments:


As you can see, this person decided to attack the band because of the number of views that the videos had received.  One post was on our official music video, and the other was on the video posted by Utah Music Scene, where we were interviewed at the Salt Lake City venue Club Vegas.

Due to YouTube's new layout, it is much more difficult to remove posts, even if they are on your own videos.  I immediately changed the music video's settings to allow comments only by the owner's approval, and marked the comment to be removed and to block the user.

I even sent a private message to the poster, as I was so confused by why he would randomly attack my band, saying the following:

Hey man,
I just noticed your comments on a couple of our videos, and I'm wondering what would cause you to say all of that. Looking at your previous comments on your channel, it looks like you singled out this band for all of your hate comments and trolling, when I really don't see a reason.
Yeah, we didn't a ton of views on our video, but who cares? We were a local band, and were doing what we could to make it in an industry overflowing with local music. On top of that, we were a bunch of friends, getting together to do what we loved: making music and performing. If that's a sin, then put me down as a sinner.
So, clearly you have some kind of beef with the band, but either didn't do 30 seconds of research enough to find out that it had disbanded about a year ago, or hold a grudge on behalf of a member of the band due to reasons that you completely do not understand.
Regardless, your comments were childish and there was no reason for them. If you don't like the music, move on to another song from another band, it's as easy as that.
But the fact of the matter is that, despite the band not growing in its fanbase and disbanding due to reasons that you are not privvy to knowing, we produced some music that every member of the band is incredibly proud of, and we see it as a great accomplishment.
So, I would appreciate it if you would keep those ill-informed comments to yourself, and focus your efforts on something more worthy than attempting to demean a band that has parted ways such a long time ago.
If you really want to continue acting this way, then be a man and talk about it to us personally. I welcome your response: send it to formerlysoband@gmail.com and, assuming it's more than belligerent hate and prejudice, I promise to take the time to thoughtfully write out a response to any question you may have.
Thanks.- Jeff

I posted the same message as a comment on his actual channel as well, as I noticed that somebody else had commented on it after being bashed by him for some stupid reason.  Also, because the second comment (which appears in the screenshot above) was on a video not uploaded by me, I wasn't able to remove the comment, but instead posted the same message above in the form of a reply to his comment.  I believe that the reply was frank, yet professional in the sense that I didn't result to vulgarity or name-calling, so if anyone is to read it, they will see that he truly is a troll, and hopefully believe that it was handled well on our part.

I sent Tim the message via Facebook, but he replied back several hours after I had removed the comment, and told me that it was still visible, so he didn't know if it just took time to remove, or if there was more I needed to do.  I tried several things, including marking the comment as spam with several accounts and replying with a shorter version of the above message (just in case). I'm not sure what exactly I did to solve the issue, but the comment is now gone from our music video's page.  It shows my reply and has a link to show the original comment, but when clicked on, an error message displays, saying that the original message has been removed.

In closing, I don't understand why people decide to bash others for really no reason.  The comment on the music video page said something along the lines of "since this band only has X amount of views in a year's time and other mediocre bands have tons more, they should think they're a great band," whereas the comment in the screenshot above goes on to claim the reason why our band didn't succeed, which--for the record--is definitely incorrect, as we were successful and could have continued on to have a bigger fan base and more success, had other obstacles not hindered us.

Anyway, I don't know if one of the band members was disgruntled and was complaining about the band to someone, who went on to "help" by placing those comments, but I don't believe that could be the case, because it made all members of the band equally look bad.  I'm guessing it was just some Internet troll, who was just hate-filled and wanting to cause a stir.  Basically, being the quintessential Internet troll that everyone knows and hates, that CollegeHumor depicted so well in this video:

Monday, September 19, 2011

Becoming Everest BTS

As a follow-up to my previous post, I decided to post the Behind the Scenes video of the Becoming Everest music video:

Sunday, September 11, 2011

Quiet on the Set!

Almost a year ago, my band Formerly So worked together with my cousin Ty Jensen to film a music video to our song "Cut Down," the single of our debut album entitled "Disappointment is Control."  We had a three-member crew team working with us--excluding actors--which included Ty as the writer, director, and editor, Ken Wilcox as the chief cameraman, and James Vreeken as their assistant.


Despite the lack of manpower, the video was done very professionally and was very elaborate in every aspect.  We filmed in three main locations, being Ty's parents' garage in Farmington (which was designed to appear as a mechanics garage), Convicted Ink tattoo parlor in Orem, and Wendover, Nevada.

We made a two-day trip out of the Wendover shoot.  The first day, from early morning until late at night, was spent out on the Bonneville salt flats, where we shot some amazing performance shots.  It was very time consuming to load all of our equipment out there, and to carefully place our gear without corroding it with salt, but it was definitely worth it.  As cool as the daytime shots were, they couldn't compare to the shots taken after dark, with Ty's special blend of pyrotechnics.  Plus, with the help of Adam Boyd, our band's sound technician, we were able to construct an actual wall of fire behind us during a finale shot, which was as awesome as it was dangerous.

The second day we captured some footage inside the casino (which we ended up scrapping) and in the hotel room, followed by some scenes at the same airport where they filmed the movie Con Air with Nicholas Cage.  It was a lot of work, but even more work for Ty and his companions, who turned the footage into a very professional music video.

Yesterday, I had the chance to return the favor to Ty as I worked on his crew for the making of the Becoming Everest--a hardcore band based in Salt Lake City--music video to their song entitled "The Red in Redemption."  This video shoot was nothing like what was done for my band.  Ty is now a graduate of Utah Valley University in filmmaking, and owns his own music video production company called the Tyjens Media Music Video Production Bureau.  He has several more music videos under his belt and has transformed his sets into a completely professional outfit.


This video set had a 30-man crew, including Ty as the director, Ken as the chief cameraman, two assistants to the director, a lighting specialist, and several grips who set up equipment between shots.  I felt like a fish out of water because I was one of a couple people who wasn't in the digital media major and working towards a career in film.  Yet, I was lucky enough to have my cousin Jake--Ty's little brother--helping out as well.  Not only did it make the process much more comfortable having somebody I knew working alongside me, but it was great to hang out with Jake and remember all the fun we used to have together as kids.


The first half of the day, or rather until about 5pm, we worked on the shots involving an actress from BYU.  For quite a few of the scenes, I was put in charge of the air compressor, with which I would continually shoot her in the face, and she would fall backwards onto a large mat.  I felt bad, but she didn't seem to mind.


For one of the last scenes with her, Jake and I actually had to work together, standing on stools and raining flower pedals down on her.  I think they'll look pretty cool once the video is complete.

After the scenes with the actress were finished and she was free to go, we moved on to the shots with band.  Most of the band members were pretty cool and fun to hang around with, especially the guitarist/screamer.  He was a really nice guy and I enjoyed chatting with him between sets.  He and the bassist were also the most grateful for all the work the cast and crew were putting in to making them a video with no cost to them.


The day of filming started at 7am, and I had to leave at 10pm to submit some homework that was due by midnight, but apparently the shooting didn't stop until close to 1am.  Ty had actually arrived to set up much earlier than I did, arriving on set at 3:30am, and worked continuously the entire time.  He's obviously a very hard worker and I can't wait to see where these videos being added to his portfolio will get him once he introduces himself to Hollywood and the major music labels.

Monday, August 8, 2011

Steel Horse Summer

Three years ago, when I stepped foot in Utah after serving a two year mission in Brazil, I had a huge surprise when I walked into my backyard after so much time.  I greeted my dog, who surprisingly still recognized me, and played with him for a moment or two.  Then I turned around.  Behind me on the grass was a gleaming motorcycle, a black 2005 Honda VTX 1300R, parked behind a big yellow poster that said, "Welcome Home!  Let's Ride!"

Ever since that day, my dad and I have taken our bikes all across the western states on some very exciting rides, visiting motorcycle rallies, visiting national and state parks, or just going on rides to spend time together.  Together we have visited Yellowstone, Lake Tahoe, Zions National Park, Bryce Canyon, Reno, Jackson Hole, and a ton of other places.  This summer was no exception.

This year we were able to hit two rides together.  The first was a couple of weeks ago.  My dad and I, accompanied by my uncle David, took our bikes on a journey to Red Lodge, Montana, for a motorcycle rally.  We started our ride by driving all the way to Bozeman, Montana, where we faced some minor technical difficulties.  We entered the city of Bozeman during a rainstorm, and before long realized we weren't sure how to find our hotel and accidentally ended up back on the freeway heading toward Billings.  We pulled off on an off-ramp and called the hotel for directions.  When my dad went to start his bike again, he found that somehow his ignition starter was not working and his bike would not turn over.  Luckily my phone had the number of the Honda dealer in Orem and we reached them with three minutes before closing time.  The mechanic was very helpful and explained to my dad that he could simply hotwire his bike to start it until he could get it fixed, so the trip could continue.  I handed my Leatherman to my dad and he was able to use it to spark the engine and get it running.

The next day we hit the Red Lodge rally, which was awesome!  There were tons of vendors, and we spent a good amount of time just walking up and down the streets shopping.  After the rally, we heading onward to a small tourist town called Cody, Wyoming, home of Buffalo Bill.  It was a pretty fun town, with cowboy gunfights going on in the street and a cool pioneer village we were able to visit.


The next day we left Cody and made our way to Yellowstone, passing through the East entrance and making our way South to Jackson Hole, Wyoming, where we would spend the night.  The ride was very scenic, and we shot a bunch of cool pictures.  It was crazy how deep the water in the rivers were, and how islands near the Fishing Bridge were underwater.

Yet, we faced another difficulty when we stopped near West Thumb to take a few pictures.  David had been struggling with a semi-dead battery on his bike, and we had to jump start him when we left Cody.  But as he went to start the bike at West Thumb, it simply would not start, despite everyone's best efforts.  We finally had to make a plan for me and my dad to ride down to Jackson and buy a battery and bring it back to him.  He gave us his credit card and said he would wait for us there.  We traveled for almost two hours until we reached Jackson, and found a K-Mart that was open that sold batteries.  By then we had received a few voicemails from David saying he had called a tow truck and would meet us at the Southern entrance to the park.  My dad decided to leave me in the hotel room and return by himself to meet David.  I walked down to the Subway nearby for dinner, and spent a few hours reading and watching Netflix on my EVO phone.  They returned later that night and we went for a midnight snack at MacDonalds.

The next day we wrapped up our trip by returning home via the Mirror Lake Highway.  As we were in the thick of the forest, we felt a few raindrops and my dad decided it was prudent to pull over and put on our rain gear.  It was a wise decision, because not five minutes later we were hit with pounding rain that we could barely see through, and were it not for our waterproof clothing, we would have been soaked to the bone.  But the rain didn't stop us from visiting a scenic waterfall along the highway and taking pictures.


Despite the technical difficulties and the weather, we had a great time and the ride was one of the funnest that I've been on.  It was well worth the planning and preparation that my dad put into the trip.

Last week I had my second motorcycle trip of the summer, together with my dad and his old high school friend Robert Gornichec.  We went on a two-day trip to Moab, hitting three scenic parks:  Canyonlands, Dead Horse Point, and Arches National Park.


After arriving in Moab and having lunch, we visited Canyonlands State Park.  It was fun, as always, and had a lot of great photo ops.  We started by walking down to the ledge overlooking the White Rim Trail, just beyond the Visitor Center.  It is ironic that such an awesome viewpoint is not even marked on the maps within the building.  I especially love visiting that spot to watch my dad squirm, who is deadly afraid of heights ever since he drove his snowmobile off a cliff a few years back.


We then trekked up to Mesa Arch, which is a neat arch that is about two miles into Canyonlands.  By that time we saw some heavy rain clouds billowing our way, so we high-tailed it to our bikes and tried to beat it to Dead Horse Point so we could see the famous landmark at sunset.  Just outside of Canyonlands, on our way to the other park, the rain unleashed itself upon us with everything it had, and we were instantly soaked to the bone.  The rain/hail stung as it struck us, but we kept moving until we reached the ranger station.  The ranger was a nice guy that let us take refuge in his booth until the rain let up a bit, then gave us a free pass into the park.  We made our way to the lookout points and snapped a few pictures, but upon seeing the ominous rainclouds of a followup storm coming our way, we decided to not press our luck and head back, instead spending our time after dinner sitting in the hot tub at the hotel.


The next day we got up early and visited the Arches National Park, and made the traditional hike up to the famous Delicate Arch, which is the very same that is featured on most Utah license plates.  It was fun, however tiring, and after the hike we slowly made our way back to Moab.  We then traveled up the Colorado River a ways until we reached the Red Cliffs lodge, where we visited the film museum, that features exhibits for each movie that has starred some part of Moab, including Austin Powers: Goldmember, Mission: Impossible II, and Thelma & Louise.

After the museum, we made our way back home, thus ending another fun motorcycle ride.  I really look forward to these rides, and to the time I get to spend with my dad one-on-one.  I can't wait to see what adventures we will have next year, and until then plan to continue riding my bike as much as I can.

Tuesday, July 5, 2011

Fire and Rain

Tonight was the annual "Blow Stuff Up" party with all of my fellow employees from ShopKo.  Last year, Macedone (the "ringleader" of the show) bought a remote-controlled Hummer, which cost him about $50, and filled it with at least its worth in fireworks, and set it off while the rest of us ducked for cover.  When it was all over, we were left with a smoldering pile of plastic and streaks of white and red burned into our retinas for about ten minutes.


Would it be possible to top last year's Independence Day escapades?  I think we did.

We met tonight in the ShopKo parking lot, waiting for those who were working the closing shift to join us if they wanted to.  A few ominous sprinkles of rain splashed down on us, and black clouds surrounded us, and we started to wonder if our party was actually going to happen.  Within minutes, the rain started to pelt down, harder and harder.  A few people disappeared, choosing not to wait out the storm, while the rest of us retreated to the greenhouse in the Lawn & Garden center to remain as dry as possible.


We watched as the water began to rise, the drainage ducts in the parking lot being completely outmatched by the torrential downpour.  The rain came down in sheets as we watched our manager sprint from door to door, including the Lawn & Garden shed, making sure all of the locks were secure.  Eventually we decided that we would postpone the celebration until the following night, and everyone began to trickle out of the greenhouse and dart to their vehicles.



I realized that my dad had driven his motorcycle to work, and so I jumped in my car and drove over to RC Willey to give him a ride home.  However, when I was about a block away, I got a call from home saying that he had arrived home safely on the bike, despite the fact that he was completely drenched.

As I turned back, I called one of the party guests to see if they were still in the greenhouse waiting out the storm, only to find out that the rain was subsiding and the original plan was back on.  I returned to ShopKo and met up with the stragglers, and we soon left the premises to find the others, who had apparently left to procure a location to begin lighting off the fireworks.

They had found a secluded parking lot in which we could launch the pyrotechnics, and we stayed there until the firework curfew at eleven o'clock at night.  Despite the rain alternating between a drizzle and downpours, we had a great time, watching people light off a multitude of fireworks that cost a total of at least three hundred dollars.  It was super fun, and definitely outdid last year's adventure.  I wonder what next year will hold.