Finding distributors of specialized equipment is never an easy task, knowing where to start your search is usually the toughest part. That’s where Asher Equipment comes in. Al Asher & Sons has all of your specialized equipment needs, including:

  • Trucks
    Boom trucks, Bucket trucks, Winch trucks, Cable Take-up trucks, Digger Derrick, and Underbridge Inspection trucks
  • Underground Cable Pullers
    Sewer Rodders, Cable Choppers, Cable Scrappers, Reel Loaders, Winch Trucks, Cable Trailers, Reel Trailers, Pole Trailers, Tensioners, and Hogg Pullers
  • Cranes
    Pitman and Stinger cranes

Not only does Asher carry all of these specialized equipment items, but they also provide sales, rentals and parts and service. Asher isn’t narrow-minded when it comes to selection either, they carry specialized equipment from a large number of manufacturers, such as: Altec, Hi-Ranger, Hogg-Davis, National Crane, OK Champion, Pitman Crane, RO Stinger Crane, Sherman-Reilly, Standard Trailer, Teco, Telsta, Terex, TSE, Vactor, Versalift.

Though Asher is based out of the Los Angeles area, that shouldn’t deter you from considering them as a viable option because Asher can deliver specialized equipment sales nationwide. Additionaly, specialized equipment purchased from Asher qualifies for warranty protection, even reconditioned equipment comes with a conditional warranty – that should help in buyer confidence.

When it comes to purchasing utility trucks and other specialized equipment, the cost can often make or break the deal because specialized equipment almost always tends to be a high dollar item. The great thing about Asher is that they offer financing on their sales. Not only do they provide financing, but they also assist with loan applications, finance strategies and locating competitive rates – because lets face it, the best interest rate on financed items might not always be the first option. Asher uses established contacts at banks and finance companies to help land competitive rates for their customers.


In an effort to get all of my clients websites to be PCI compliant, I have come to find out that GoDaddy DNS servers are far from PCI compliant. Check out some of the related articles that I’ve posted on PCI compliance, and also review the following failure message about having DNS Recursion Enabled. Unfortunately, the areas where the GoDaddy DNS server fail the PCI compliance test must be updated by GoDaddy, and from what I gather, there doesn’t seem to be any urgency to resolve these issues on GoDaddy’s side. I’ve already begun migrating domain names from GoDaddy.

DNS Recursion Enabled

This DNS server has query recursion enabled, allowing it to answer requests for DNS zones outside of your authority. This configuration may allow attackers to perform a cache poisoning attack on your server, corrupting then name-to-IP translation tables, potentially enabling man-in-the-middle attacks.

Service:
CVE: CVE-1999-0024
NVD: CVE-1999-0024
Bugtraq: 136, 678


In working with many online merchants that accept credit card payments online, it has come to my attention that GoDaddy DNS servers are not PCI compliant, and they also fail PCI compliance tests on several different levels. The GoDaddy DNS servers failed the DNS Amplification Denial of Service test as conducted by TrustKeeper. I’ve included the specifics of the test results and failure message below.

DNS Amplification Denial of Service

The DNS server answers all queries, providing additional delegation information to arbitrary IP addresses. It is possible to send a query for the root zone (.) to the DNS server, and get an answer that is much larger than the query (often more than 20 times in size). An attacker could spoof the source IP address of the query, causing the DNS server to respond to the source IP with the larger answer. An attacker could focus these answers on a single target, resulting in a Denial of Service for that IP. Additionally, the amplification attack represents a risk to the DNS server in the form of Denial of Service. The server would have reduced ability to respond to legitimate DNS queries due to consumed system resources and and higher network traffic levels. Verification of this must be done from an host that is not on the network/intranet of the DNS server. Command to verify from a UNIX based system: ‘dig -t NS . @IP.OF.DNS.SERVER’ or ‘host -v -t NS . IP.OF.DNS.SERVER’. On Windows, run ‘nslookup -type=NS . IP.OF.DNS.SERVER’. If the response received includes answer and additional sections that lists a number of hosts (often on ‘root-servers.net’), then the system is vulnerable. The SANS Internet Storm Center has also provided an online tool to verify this issue (see the link to sans.org in the references).
Note: Vulnerabilities which result only in denial of service do not affect PCI compliance; however, they may still be critical to your systems.

Service: -
CVE: CVE-2006-0988, CVE-2006-0987
NVD: CVE-2006-0988, CVE-2006-0987
Reference: http://www.isotf.org/news/DNS-Amplification-Attacks.pdf
Reference: http://isc.sans.org/dnstest.html
Reference: http://isc.sans.org/diary.html?storyid=5713
Reference: http://www.nabble.com/ISC-BIND-Amplification-Attacktd21670165.html
Reference: http://zytrax.com/books/dns/ch7/


It has recently come to my attention that GoDaddy DNS servers are not PCI compliant, and they actually fail PCI compliance tests on several different levels. The first test that the GoDaddy DNS servers failed was DNS Cache Probing. I’ve included the specifics of the test results and failure message below.

DNS Cache Probing

It was possible to receive answers from this DNS server for nonrecursive queries for third-party domains. For an attacker, if a DNS answer to the non-recursive query is received, this indicates that a domain has recently been resolved by the DNS server (and, theoretically, other hosts that use the server). No response indicates that the queried domain was not recently resolved. This can allow an attacker to discover domains a queried by other hosts using this server, which might give an indication of web-browsing habits or domains accessed for business purposes.

Service: -
Reference: http://www.bind9.net/manual/bind/9.3.1/
Bv9ARM.ch04.html#AEN7 67
CVSSv2: AV:N/AC:L/Au:N/C:P/I:N/A:N (Base Score:5.00)


Being a fan of lowered cars and lifted trucks, I know a lot of people who work in the automotive industry either for large manufacturers, small tuner shops, automotive photographers, automotive writers, etc. One thing I’ve come to notice is that most of these groups have absolutely terrible websites – especially those who need to manage and maintain large amounts of data. That’s where idcubed.com‘s automotive.NET system comes in. automotive.NET is an aftermarket parts management system that allows users to maintain a listing of vehicles, brands, categories, parts as well as maintain mappings between each of those.

The automotive.NET system literally takes all of the work out of creating a website and lets you focus on parts, vehicles, categories and brands. You simply have to manage YOUR information, and not worry about creating/designing a website. If you are looking to sell car and truck parts online I’d highly suggest that you check out idcubed.com, inc. automotive.NET system.

I’ve got a friend who lives in New York City and always absolutely raves about Sabon products. To be completely honest, being a man, I have never really put too much importance on taking care of myself through “pampering”, but after one visit to the store with my good friend, she has changed my mind about “beauty products”, if you’d call it that when a man is using them.

Anyways, after the first visit, I found myself leaving the shop with a bag full of products from the Sabon gentlemen’s section, including shaving cream, aftershave, and cleanser (which I use on my face). The thing I like most about these 3 products that I use is the ingredients. They all contain white tea oil, shea butter and coconut oil which serve to clean, detoxify, purify and really just help refresh you.

Now, I haven’t yet become daring enough to go into the store and purchase a huge jar of a pink Lavendar Apple Body Scrub, but my friend keeps trying to convince me to try the Body Scrubs. Thus far, I’ve been able to keep her happy with the fact that I use all of the Sabon gentelmens products (shaving cream, after shave and cleanser), but recently, I come across the Sabon website – http://SabonNYC.com/, which made it difficult for me to tell my friend that I don’t want to buy body scrubs because it’s embarassing for me (a male) to walk into the store and ask for a big pink bottle.

Well, you can probably guess where this story is going, I ended up ordering one online and it has been the best thing on earth! My skin is so soft!!! I never thought I’d hear myself say those words (or type those words) but I am sold on Sabon, and now on their body scrubs.


After literally YEARS of waiting, the folks at Apple have finally decided to begin offering support for cut and paste in the new version of the Apple iPhone 3.0 software update. In addition to the support for copy and paste, there are a whole slew of other new features being offered, many of which include support for 3rd party devices.

So now that it’s almost here, what will be the first thing that you copy and paste once you install the new version of the iPhone 3.0 firmware?


It appears that Google is working on releasing a new version of the Google AdSense Homepage, and possibly even a new version of the Google AdSense reporting and user information page. However, as of right now, I am unable to log into my Google AdSense account, as everytime I try to sign in, I’m redirected back to the new default Welcome to AdSense page.

The sign in page is no longer part of the AdSense homepage, you click a link that reads: Already using AdSense? Sign in » but upon clicking and signing in, users are currently being redirected back to the main AdSense homepage.

I hope that Google has something good in-store for us! I’ll keep my fingers crossed.