Pages

Thursday, December 13

The Secret of the Time Machine-Assisted Hard Drive Swap

Gizmodo published this article this morning.  I thought it was brilliant.


Restore_System_Time_Machine.jpgThere's never been a better time to void the warranty on your MacBook and upgrade to one of those sweet 2.5" WD Scorpio 320GB drives. That was what made me throw caution to the wind and attempt a Time Machine-assisted swap. The good news is, it works as billed. You get a bit-for-bit transfer to the virgin drive with minimal fuss. The bad news is, if you don't use a little trick we discovered today, you probably won't get it to work at all.

I said "void the warranty" and I meant it. The process I went through today means it'll be harder for me to complain to Apple if things get weird, so be cautious! Given the experience I've had, I think HDDs will soon be given easy-access panels, like RAM has, because swapping a 2.5" SATA turns out to be straightforward, and the software, at least as far as Apple goes, is ready for novices.

The key here is that there's no preparation needed for the new drive. As long as you've backed up your old drive to an external disk using Time Machine, you can prepare for the grand opening. I won't bore you with gory details, except to say that I found a good bit of guidance from this dude's blog. MacBook_Pro_Guts.jpg
The Process
Once you open up the system and swap out the drives, you can set the old drive aside, hopefully never to use it again. Assuming all went well, you restart the system and insert an OS X Leopard installation DVD. You won't need the OS installer on it, but you will need it to act as mediator between the Time Machine backup drive and the newly installed blank drive. Once it boots up (you may need to manually restart to get it to work right) follow these instructions CAREFULLY:

1. Choose your language.

2. At the main screen, choose Disk Utility from the Utilities pull-down menu.

3. Select the drive itself and click on Partition.

4. In the Partition menu, select 1 Partition and Options... where you choose GUID Partition Table. Click OK then Apply, then say "yes" to whatever warning comes up.

5. Once you have reformatted the drive, close the Disk Utility window.

6. Do Not Go Forward. Instead, when you see the main Welcome screen, click the Back button, which takes you to the language select page. It sounds silly but DO IT. This shakes the system into action.

7. Once you have reselected your language and are back on the Welcome screen, click Utilities and select Restore System From Backup...

8. The process should go smoothly from that point on. You simply select appropriate disks to copy your chosen backup data from your Time Machine drive to the new internal drive, as shown in the following sequence:
Restore_1.jpg
Restore_2.jpg
Restore_3.jpg
Restore_4.jpg
Restore_5.jpg

The Back Story
Originally I tried my swap without first clicking back to the language page, and the installer could not find my new hard drive. Disk Utility saw it and happily formatted it with the GUID partition, but even on the second pass, the installer wouldn't show it as a target option. All I got was this hollow emptiness:
Searching_for_Disks.jpgI spoke with Jeerun Chan at Western Digital and asked him to try the same process, which yielded the same results. Then I tried it with another virginal hard drive, this time a 160GB SATA from Seagate. Between the two of us, we ran this test on three different configurations, with the same negative results.

The obvious but depressing solution was to just run the Leopard system installer, then use the migration tool to back up from my Time Machine drive. It's fairly smooth, and smart if you want a clean install on your new drive, but it's boring: it takes a few steps, and they're all obvious. I wanted a bit-for-bit dump from backup to new drive, fully automatic.

As I was installing Leopard on my second drive, the phone rang: it was Jeerun with the crazy back-button technique. I don't know how he thought to do it—I don't even think he knows, but the fact remains: when you have formatted your destination drive and are on the Welcome screen, click the back button and the process will work. If you don't click it, well, in our experience, it seems you will fail in your objective.

Obviously, this won't work if you don't regularly do a full system backup in Time Machine. If the omitted folders in your Time Machine options include system files, you won't be able to do this.

In truth, it might make sense to backup only personal files, especially since this process requires a Leopard install disk even to write the whole image back onto the new drive. Chen swears by SuperDuper, which is perhaps a better pro technique, one that doesn't require a system-install DVD. Still, I wanted to see if this major boast of Time Machine was all that it was cracked up to be. It is, and the end result will be tasty, as long as you don't forget that one little catch.

As with my last Time Machine HDD discovery, this one involves a little hocus pocus. While this method works, you may have your own trick, or a more scientific approach. If so, please share it in the comments below, and spare any fellow Mac users a frustrating afternoon.

Thanks to Jeerun and Heather at WD!

Wednesday, December 12

Security 2.0 feedback

Warning, this is a long one. I was asked by a reader to consolidate all of the feedback I got from the Security 2.0 posts and put them into one post. Sure! No problem. However, I got alot. No names though. If you want your name mentioned email me, and I'll edit the post to include your name (if you have a blog or something, and you want me to link to you, provide that info too). Let me just say exactly what I said on PaulDotCom, just because you don't understand the technology, isn't a reason to restrict it. You need to understand the technology, then make a risk assessment of what kind of impact it can have on your network.

To the commentary --

"iTunes is P2P by default on the local subnet, and possibly further with Wide Area Bonjour. ie. out of the box it will search for shared music, and it is one click for a user to share, no selection, their entire iTunes Library. In our University environment we have no shortage of bandwidth, and all protocols are permitted. iTunes is a useful teaching/learning tool. But the Authorities lean heavily on departmental IT admins to lean heavily on users to keep those Sharing buttons clicked OFF. The bogeyman is Copyright."

I disagree. iTunes, IMO, is not P2P. You can't trade music with it, you can, however, stream music from another person's iTunes list on the local network. But there isn't a way that you can trade music via this medium.

"I think one reason we have a restrictive policy set at work is because the default is 'fail'. That is, just because bittorrent is blocked here doesn't mean they've decided to block bittorrent; rather, it means that they haven't decided to open up bittorrent. Another similar reason is the security appliance -- rather than think about some security issues, we appear to simply go with whatever the Cisco box thinks is a reasonable thing to filter, including web pages. Many are blocked, many aren't, but no local thought has been put into most of it. It's a convenient excuse for management -- "justify why we as a business should allow IM" is easier for them than deciding whether or not IM is useful. This way, it actually costs someone's time to open up the hole, and therefore you need a business purpose to justify it. Does it "work"? To answer that I'd have to know what they're really trying to accomplish, and upper management is really trying to accomplish making the business make money -- more specifically? I don't know what they have in mind. Apparently, they don't think I need to know what they have in mind...or I could make a business case for them taking the time to tell me. :)"

Okay, so your organization isn't really against the use of these tools, but you have to have a legit reason to open it. Okay, I can understand that one. No problems there.

"The equipment I monitor is paid for with tax dollars. The public expects County employees to be processing their paperwork, not using tax money to download iTunes or play Internet Poker. By policy, County-related business purposes only."

This one obviously came from a county employee. I can also understand this one. This is more of a business restriction, not so much a "we are disallowing it because we don't understand the security of the technology".

"Web filtering: used to stop malware, legal liability from sexual harrasment (a porn site on a monitor makes an employer liable for creating a "hostile working environment"). Also, filtering logs are used when an employee's productivity is lacking, and they seem to be on web sites instead of working. iTunes, et. al.: Actually, all personal electronic devices were just banned at my company, because one person became annoyed when she tried to get the attention of an employee who was listening to their iPod. This is NOT a small company - it's a $2B multi-national manufacturing firm. This was NOT a security decision. IM: IM is banned because of SOX and IP concerns, along with past incidents of employees using IM and clearly losing productivity. Management does not consider spending any money (or time) for IM monitoring to be a priorpty."

Web filtering -- No porn because of harassment. Okay, I can understand that one. However, let's take a look at another side of that. One of the places where I have worked didn't allow us to go to porn sites. However, where I worked, we had to get exploits, and other random nastyness, to be able to write IDS signatures against them. Most of those sites have some explicit pictures on them. Because of the bureaucracy where I worked, getting a person "unblocked" was an act of God. Even though we had a legit reason. iTunes -- Now that's just stupid. IM -- Okay, that's a legit reason. Insider information. However, I'd rather allow people to do it, and monitor it, then to disallow it totally.

"I can tell you what my Draconian company does from a security standpoint. In terms of actual security, sure we have firewalls, A/V, spyware tools and the like, but that isn't what upper managment cares about. Hell, they're the last people to run they're spyware removal tools or not install unapproved software. No, they like using technology to either monitor us, or limit us in any way possible. According to the president of the company you need to be working every minute of the day and if you can't do something as if he were looking over your shoulder then you shouldn't do it at all (he has said this many times), namely it needs to be work related. All external email is blocked. Corporate email is not allowed for personal use. IM is not allowed, not for any of the reasons you mention, but rather to prevent us from chatting all day. Many websites are blocked. He randomly monitors throughout the day what we are doing via Network Lookout Pro, which shows all of our monitors tiles across his computer screen. If he sees something he doesn't like he zooms in to verify and then will take disciplinary action. He is old fashioned military and thinks you need to constantly keep "the troops" in check. As if allowing them to surf the web a bit or use personal email or IM will hamper their work. Granted excessive use could, but as long as they get their work done who cares!"

I discussed this on PaulDotCom as well. This is just insane! Apparently there is absolutely no reasonable expectation of privacy

"A few examples why we filter web access: Webmail - we block webmail because we can't monitor it properly for exfiltration of PII. In the past we used to block it because we AV scanned email, but not web traffic. Besides running your business out of your yahoo.com email address isn't fitting for an organization our size. Calendar sites - yes, we block google calendar. Why? Because some jackass was syncing his PDA to it and set it as public access. So a journalist was able to see that we had conference calls on the security issues in our SANs and what the conference participation code was. File storage sites - you don't want to know the number of spreadsheets holding customer data we found on these sites. Pr0n - people sue us if they work in a hostile work environment. Gambling - we do business in countries where they're behead you for doing stuff like that, but more importantly, they'll take away our license to operate. I don't mind losing a few employees in a Turkish prison, but I can't give up all of that oil money. Why we filter IM: In a word, regulators. SEC really frowns on traders having unmonitored communications. That, and a week doesn't go by that there isn't an IM worm. Also, I have enough cases open with email harassment, I don't need IM cases as well. iTunes: We don't block this one yet, but I'm working on it. Mainly because I don't have an iPod and I'm jealous. Actually it's because we've been working really hard on information control, encrypting our laptops, adding USB controls. So I really don't want to encourage them to plug a hard drive into my laptops."

Okay. I received another email that said that they don't allow iTunes because the company is not going to pay to have your songs backedup to the local backup server. I had another one write in saying that the company was concerned about Copyright issues. Maybe someone from Apple can talk about this. I know there are Apple employees that read this blog.

"
Let security people implement policy instead of people whose eyes roll when you talk about mitigating a risk and think that they should implement every security control possible "because it's there"."

Good thought.

"I would say that, having worked in DoD for the last 10+ years, many times sites/services are blocked for bandwidth conservation or to prevent timewasting by unit members. These include sites such as Pandora, MySpace, Blogspot.com and Itunes. I'm not sure how effective some of these blocks are. For instance, Pandora is blocked but there are dozens of other sites that are easy to find and access. MySpace and Blogspot.com and their ilk were blocked I believe because people spent WAY too much time updating their blogs rather than working. (I overheard conversations regarding how people would spend 6+ hours a day updating their MySpace) Also, I believe information was put on these sites that shouldn't be on the web. But again, is that the best way to moderate this? Blocking the sites addresses the first concern, but not the second as again their are dozens of other social networking/blogging sites to use. Your question about how effective all the regulations and policies are is another matter entirely. Like I said, I've worked in DoD for 10+ years, doing IA for most of that time. Have things gotten better over that time period? Yes and no. DoD is a LOT smarter about IA, but as we all know, it only takes one hole for the bad guys to get in while we have to defend every wall, door, window, nook and cranny. And DoD is not immune to similar demands that occur in the commercial world; namely that the General and/or his staff (CEO equivalents) want to do X and that want to do it now and this app is mission critical and IA doesn't have the power, and isn't included in the planning... you know the story and how hard it is to secure all that. Add to that how fast technology is moving and how hard it is to be REALLY sure that the neat new app you just installed doesn't have a security hole that allows remote access to your domain. And then there are home grown apps and did your developers (contractors or government) really follow best practices (or did they even know about them)? And finally, how can you stop users? Even smart users (see the recent break-ins at the labs in Tennessee and Los Alamos which I believe were attained through spear phishing)? Like I said, it only takes one hole. DoD is a lot smarter, but then so are the bad guys and at the moment, they outnumber us. I don't believe they are smarter than us, but we have limitations they don't. So, the final question is: Is it harder for the bad guys to get into DoD networks with all the current regulations as compared to 5 or 10 years ago? I think so, but without an objective external verification, it's hard to say for sure."

Excellent post. I used to work for DoD too. I think the "fear" of something happening is greater then the emphasis on the actual something happening.

Thank you all for posting your thoughts. If this prompted some more ideas, please feel free to leave it in comments. If you don't know want to post as your name, please feel free to post anonymously.

Subscribe here:

Add to Google Reader or Homepage

Fake Steve Jobs

If you came to my website yesterday and it was a bit slow, I apologize. It was kinda busy.

I wrote a little funny about Steve Jobs being at Al Gore's Nobel Peace Prize award ceremony yesterday. It was only significant because he wasn't wearing his trademark black turtleneck, jeans, and sneakers. He was wearing, what appears to be, a suit and tie. (Click on the link to see the picture).

Well, fake steve jobs picked this up and blogged it at fakesteve.blogspot.com.

Fake Steve Jobs, for those of you that don't know, is a blog ran by, what turns out to be an editor (or writer) for Forbes.com. He presents a very funny and satirical view of the world, skewed by what he thinks Steve Jobs (the real one) would say about topics. It's a good blog, I encourage you to add it to your daily rss feed.

Anyway, FSJ picked up my blog post, and blogged about it himself. Simply saying "So big deal, I wore a tie, who cares? Apparently this guy does. He even ran a photo." Pointing people to my website.

Heh. As you can imagine, FSJ gets a LITTLE BIT more traffic then joelesler.net, and here came the traffic.

I noticed it at about 7 am. Lights on my switch were ON. Not blinking. They were just on. I maxed out my bandwidth in about a half hour, and it remained that way for about 4 hours. Nice.

At about 10:20 am, I had over 6000 people (open sessions) at the same time. The network held this rate for about an hour and a half (started slowing down at around noon). When I went to bed last night at around 10:00 pm, I was tracking about 5000 people (open sessions) at the same time.

Snort didn't drop a packet. Not one. It analyzed every single bit of it. (Go Snort!)

So, go FreeBSD (my webserver), Go Snort (2.8.0.1), 37,935 hits yesterday isn't bad.

Tuesday, December 11

Safari wins for the first time today.



I took a look at my Google.com/analytics stats for joelesler.net today. Looks like Safari won for the first time today. So that either means that I am either getting more popular with OSX crowd, or it means that Apple is getting more prominent.

I am guessing the first.

Safari wins for the first time today.



I took a look at my Google.com/analytics stats for joelesler.net today. Looks like Safari won for the first time today. So that either means that I am either getting more popular with OSX crowd, or it means that Apple is getting more prominent.

I am guessing the first.

Pastor: Cop told fourth wife he killed third wife

So, the pastor of the 4th wife of Drew Peterson told the news that Drew had confessed to her (then then her to the pastor) that Mr. Peterson had killed his 3rd wife.
Well, it really _is_ he said, she said in this example.  But, I think the moral of this story for women is:  Be cautious when marrying anyone with the last name of Peterson.  Seems you wind up "not-healthy"..
Need I remind you, said 4th Wife is now missing?

Pastor: Cop told fourth wife he killed third wife

So, the pastor of the 4th wife of Drew Peterson told the news that Drew had confessed to her (then then her to the pastor) that Mr. Peterson had killed his 3rd wife.
Well, it really _is_ he said, she said in this example.  But, I think the moral of this story for women is:  Be cautious when marrying anyone with the last name of Peterson.  Seems you wind up "not-healthy"..
Need I remind you, said 4th Wife is now missing?

Steve Jobs wore a tie.

Those of us that remember back in the pre-Steve-return-to-apple days have seen him in a Suit and Tie. But in recent years, I haven't seen him wear anything but a black mock turtleneck, jeans, and sneakers.  Original Article here.

So it's quite interesting to see him in a suit and tie.




If it were anyone else, it wouldn't be news.  This was to see Al Gore receive his Nobel Peace Prize.

Steve, you're the man.  Wear what you want big guy.
UPDATE:  Found this picture of him in full dress.




Subscribe here:

Add to Google Reader or Homepage

Steve Jobs wore a tie.

Those of us that remember back in the pre-Steve-return-to-apple days have seen him in a Suit and Tie. But in recent years, I haven't seen him wear anything but a black mock turtleneck, jeans, and sneakers.  Original Article here.

So it's quite interesting to see him in a suit and tie.




If it were anyone else, it wouldn't be news.  This was to see Al Gore receive his Nobel Peace Prize.

Steve, you're the man.  Wear what you want big guy.
UPDATE:  Found this picture of him in full dress.




Subscribe here:

Add to Google Reader or Homepage

Monday, December 10

PaulDotCom Security Weekly

Episode 91 is live!  Go have a listen.  I sound a bit clogged up (nasal), and nervous at the beginning, but after I get into it, it went well!

CompUSA is done.

Compusa is done.  
This brings up several points.   I remember the fond days of CompUSA where you used to be able to go into the store and get random computer parts.  The problem is, there are SO many places to do this now, CompUSA never did anything to differentiate itself from the competition.  The only thing that CompUSA ever had that was different was the Mini-Apple Stores inside them.  Well, then Apple started their own stores, effectively killing the function of the Mini-Stores, so I am sure that didn't help.

Second, CompUSA's in general do not have the expertise that other stores do.  Now, in CompUSA's defense, they always tended to have more of a variety of products then the other guys, take keyboards for example.  CompUSA always had like 30 keyboards to pick from, while the other guys would not even have a third of that.  Especially not in a display where you could physically touch them and see how they felt underneath your fingers.

Apple must have saw this coming and that's why Apple started reselling their stuff through Best Buy as well.  I mean, everyone sells iPods, but not everyone sells the desktops and notebooks.  Best Buy does.  CompUSA does (or did).

The only thing that CompUSA really did that was over the competition is that they sold individual parts.  All kinds of Graphic Cards, power supplies, computer shells, and the like.  Best Buy doesn't break it down to this degree, however, most people that buy these individual parts can get them for a better deal online.

That's where CompUSA is getting their butt kicked.  People can order stuff online and have it shipped next day for free from some sites.

So, hasta la vista CompUSA.  You will be missed.  However, now that I am a mac guy, and I have an Apple Store that is closer to my house then your nearest store, I really don't care.

However, where am I going to take my certification tests?

Classic Vista Error

Saw this on Gizmodo.





Classic.

MSFT convinces you to buy crap

MSFT apparently isn't getting the sales of Vista that it wishes it had. So it's written an article on how to convince your managers that you need to upgrade.

By and large I have to deal with tons of Windows users on a daily basis. I've met two, seriously, two that are on Vista. The rest are on XP.

Hate to say it MSFT, but XPSP2 is the new 98SE. It is stable. Leave it alone. Why dump more shit on top of a already big pile of shit? Oh, to try and compete, that's right. Anyway. (*rolls eyes*)

So let's hit the bold points on the list (click on blog post heading for link).

"Security is the message"

"...management may not be aware that the most compelling reason to migrate to a newer operating system, such as Windows Vista, is to take advantage of the latest security features..."

MSFT, absolutely nothing about Vista that I have seen so far makes it less of a target. I have seen a bunch of upgrades for Vista, even updates that came out for Vista before it was even released!

"The challenges"
"Johnson said upgrades can be challenging for IT as well. It requires the team to be a lot more involved in the installation and testing of the individual machines, because users are typically not going to be the administrators. Users may also be resistant to this idea at first, because they can no longer download all those fun, quirky applications that may, inadvertently, make their machines vulnerable."

So, make like every other operating system, only execute things in the user space, get rid of the registry, and stop requiring "Administrator" access for every little thing!

"The hidden cost of vulnerability"

"What management may not realize, however, is that they are already paying a hefty hidden cost by having outdated systems in place, “because you are paying for an administrator’s time to deal with these issues,” Johnson said. The trick is to show management this in a way that translates into dollars saved."

Is that the trick? Nice word. "The trick." So we are now using the sys admin's of the networks to try and sell management on a piece of crap? Oh wait, did I say sell? I meant trick.

"Make a list"

"...itemize the work that they do in several categories: improved productivity, security breaches, recovering from problems..."

How do fancy graphics, Aqua Aero, and widgets gadgets make productivity higher? There are these fancy things in OSX, but they are just a nicety on top of an OS that makes things easier to operate, and you can get your work done. Vista has centered its whole idea around this graphical interface. Stop copying MSFT!

"Save me the money"

"So how do you convince management to buy new machines, or upgrade the RAM and get the latest OS, if what they are doing right now seems to work OK?"

Yes, MSFT, how do you do that?

"Proactive versus reactive"

"The best thing about the upgrades, once they are done, is that administrators will have more time to devote to preventing problems before they happen, Johnson said."

The only proactive thing I see about Vista is "Hey Boss, we need to upgrade to Vista, not for any other reason than, eventually... MSFT will stop supporting XP!!"

Not because it works better.

CompUSA is done.

Compusa is done.  
This brings up several points.   I remember the fond days of CompUSA where you used to be able to go into the store and get random computer parts.  The problem is, there are SO many places to do this now, CompUSA never did anything to differentiate itself from the competition.  The only thing that CompUSA ever had that was different was the Mini-Apple Stores inside them.  Well, then Apple started their own stores, effectively killing the function of the Mini-Stores, so I am sure that didn't help.

Second, CompUSA's in general do not have the expertise that other stores do.  Now, in CompUSA's defense, they always tended to have more of a variety of products then the other guys, take keyboards for example.  CompUSA always had like 30 keyboards to pick from, while the other guys would not even have a third of that.  Especially not in a display where you could physically touch them and see how they felt underneath your fingers.

Apple must have saw this coming and that's why Apple started reselling their stuff through Best Buy as well.  I mean, everyone sells iPods, but not everyone sells the desktops and notebooks.  Best Buy does.  CompUSA does (or did).

The only thing that CompUSA really did that was over the competition is that they sold individual parts.  All kinds of Graphic Cards, power supplies, computer shells, and the like.  Best Buy doesn't break it down to this degree, however, most people that buy these individual parts can get them for a better deal online.

That's where CompUSA is getting their butt kicked.  People can order stuff online and have it shipped next day for free from some sites.

So, hasta la vista CompUSA.  You will be missed.  However, now that I am a mac guy, and I have an Apple Store that is closer to my house then your nearest store, I really don't care.

However, where am I going to take my certification tests?

Classic Vista Error

Saw this on Gizmodo.





Classic.

Friday, December 7

Certification Litmus Test



Click on image to make it bigger. Go ahead. Then hit the back button.

Back now? Okay. There's the thread for the discussion on the DShield list about the SANS change for certifications. Notice the ads on the right of the screen? THAT'S MY PROBLEM.  See how commercialized the CISSP is now?  Ads for bootcamps.  Even though the thread thoroughly discusses GIAC certs, you see no ads for GIAC testing centers or bootcamps in there.

What is to say that it won't become that?

My whole point in this discussion is to not let the GIAC certifications (no matter how much you don't or do respect certifications, I don't really care for them one way or the other, I have a couple) go to the dirt.  So many "CERTS" have went downhill it's horrible.

I understand why this is taking place.  I just don't agree with it.  I understand that standards and that kind of thing are good.   The exams and the practical are hard. (I don't really care for the Silver GIAC cert.  I am a Gold kinda guy, I really like the practical.  That's why I like grading them.  If it were up to me, I'd reinstate the practical for everyone.)

Daughter is fine

I have had a couple people ask me about the condition of my daughter, who had some minor surgery this week.

She is totally fine.  Little blood and pus still coming out of the ears, but it is MUCH less, and we are applying drops.

Thank you all for your concern!  I appreciate it.

Snort question from the Mailbag

I got this email today in the mailbag:

"i have configure and running snort for NIDS (network intrusion detecting system), when i make DDOS attack simulations the snort can be detect the attack and rise alert. in another side there is gateway who contain general firewall. my purpose is when snort rise alert this is can make gateway computer applied the firewall, would you like to give me solutions for that.
thanks you very much."


What I think this person is asking is, "How can I get Snort to automatically update my firewall based on it's alerts."

Well, there are several answers to the question, the most reliable answer being: "Buy a Sourcefire 3D system"  Not only do you get the ability to do that, but you get SO much more.
The second answer to the question is, "Use SnortSAM".  SnortSAM is a project started (I believe) by Frank Knobbe.  

I've never used SnortSAM, so I can't say good or bad about it, but YMMV.

PaulDotCom Security Weekly

Referring back to my Podcast 101 story.

I was on PaulDotCom Security Weekly, the podcast last night as a Guest Host.   We had a good time talking about all the weekly security stories.

It was a good time, I communicated the whole time from my office in my house via Skype.  Can't complain about that.  It took about an hour and a half to do the whole thing, from setup to end of podcast.  All in all, a great time.  

Thanks go to Larry and Paul for having me on.

Certification Litmus Test



Click on image to make it bigger. Go ahead. Then hit the back button.

Back now? Okay. There's the thread for the discussion on the DShield list about the SANS change for certifications. Notice the ads on the right of the screen? THAT'S MY PROBLEM.  See how commercialized the CISSP is now?  Ads for bootcamps.  Even though the thread thoroughly discusses GIAC certs, you see no ads for GIAC testing centers or bootcamps in there.

What is to say that it won't become that?

My whole point in this discussion is to not let the GIAC certifications (no matter how much you don't or do respect certifications, I don't really care for them one way or the other, I have a couple) go to the dirt.  So many "CERTS" have went downhill it's horrible.

I understand why this is taking place.  I just don't agree with it.  I understand that standards and that kind of thing are good.   The exams and the practical are hard. (I don't really care for the Silver GIAC cert.  I am a Gold kinda guy, I really like the practical.  That's why I like grading them.  If it were up to me, I'd reinstate the practical for everyone.)

Daughter is fine

I have had a couple people ask me about the condition of my daughter, who had some minor surgery this week.

She is totally fine.  Little blood and pus still coming out of the ears, but it is MUCH less, and we are applying drops.

Thank you all for your concern!  I appreciate it.

PaulDotCom Security Weekly

Referring back to my Podcast 101 story.

I was on PaulDotCom Security Weekly, the podcast last night as a Guest Host.   We had a good time talking about all the weekly security stories.

It was a good time, I communicated the whole time from my office in my house via Skype.  Can't complain about that.  It took about an hour and a half to do the whole thing, from setup to end of podcast.  All in all, a great time.  

Thanks go to Larry and Paul for having me on.

Thursday, December 6

SANS proctorization part two

I just talked to someone from SANS.  Appparently the reason for the change is because GIAC has be ANSI certified.

Why you ask?

DOD Directive 8570.

DoD Directive 8570.1 was approved in December 2005 and requires DoD IA workers to obtain a commercial certification accredited under ISO/IEC standard 17024. ISACA's Certified Information Systems Auditor (CISA) and Certified Information Security Manager (CISM) certifications, accredited by the American National Standards Institute (ANSI), are among only 13 certifications approved by the DoD.

Apparently SANS has to meet this mark by the end of 2007.

I still don't agree with it.  It sounds like SANS is really making it difficult for the non-.gov/.mil folks.  

In the interest of full disclosure though, I did get my cert while I was .mil.  However, now I am not.  It still sucks.

RSS Feed, now at full throttle

I moved the RSS feed back to full.  Now that I have a descent count.  

I appreciate all the people that clicked through, either on the short rss article, or on others, it gives me a better count.  I think the bandwidth that I have is sufficient since I removed the bigger video files and what not from the site.  We should be good now.

All SANS exams to be proctored?

What kind of crap is this?

"Effective December 1st, 2007, all new GIAC certification attempts and
re-certification attempts are required to be proctored. The price of a
GIAC certification attempt in conjunction with SANS training is $499,
the challenge price remains $899. The price of a recertification
attempt is $325."

This is why people like the SANS certification.  Not only is it hard, (the test and the courses speak for themselves), but you get to take them in the comfort of your own home, on your own computer, in your own web browser.  This is one of the huge selling points of the GIAC certifications, and one that I have personally pushed.  No one wants to go take time out of their week to go to a testing center!  People want to be at home, late at night with the lights turned off, (insert whatever analogy you want here), and take the exams where they have no distractions.  I really don't agree with this.

"If you started your GIAC Silver Certification attempt and received
access to your exams before December 1st, 2007 your certification
requirements will remain unchanged."

Good.  I took mine several years ago.  Does this mean that re-certs will have to go to a testing center?  Will we have access to Google and other materials in order to take our tests?

"GIAC has selected Kryterion as our partner to deliver proctored exams
through their network of host locations. Kryterion has nearly complete
coverage in the USA and many testing centers throughout the world. In
addition, Kryterion has been very responsive to adding GIAC proctored
testing centers in locations where we need them. The list of Kryterion
test center locations posted on the GIAC website,
http://www.giac.org/proctor/kryterion.php. If you will be taking a GIAC
proctored exam in the future and do not see a site near you, please fill
out the form provided with your location specifics, so that we can work
to get a site added near you:
http://www.giac.org/proctor/kryterion.php#form"

Okay, so looking at this site, the nearest one to me is in Wilmington, at a CompUSA.  What is that?  50 miles from my house?  One direction?  So not only do we have to pay for the course, and the exam, but now, i have to get off my ass, and pay for the gas on my car to drive 100 miles to take a damn exam, which I used to take in my house!  Also, Kryterion has alot of CompUSA locations.  Okay, that's interesting, however, if BGR's rumor is true, that might be shortlived.  Then I have to drive God knows how far?

"All GIAC certification attempts purchased after December 1st, 2007 will
be comprised of one single exam that covers all the certification
objectives. This new exam format is four or five hours in length,
depending on the specific certification."

Okay, so not only get to sit in CompUSA for 4 to 5 hours, but then I have to take the exams all at once!  Not allowing for a nice break in between the TCP test and the class test like it used to be?  Bullshit.

"All GIAC certification attempts purchased after December 1st, 2007 are
open book format, but not open internet or open computer."

That sucks.  Really Really sucks.

"Candidates will be allowed to bring one back pack or briefcase of course books,
reference material, printed notes, printed spreadsheets, etc., but no
electronic devices such as extra computers, CD-ROM or USB flash drives."

Again, stupid, and it sucks.  But they didn't state the size of backpack or briefcase.  So if I can get my duffle back on my back?  Is that okay?

Dear SANS,

This is the stupidest thing you have ever done.  Far stupider then your practical drop that you did. (Which you fixed with the Silver/Gold program.)  I do not agree with it, and I think you will lose a very large majority of your certification base with this.  Why are you doing it?

"GIAC will soon be ANSI/ISO certified as a certification..."

What does that mean for me?  An extra cookie?  Does that get me hired, uh, less?  Does that give me more money in my bottom line if you get ISO certified?  No.  

Some of you are sitting there and saying "holy crap Joel, all you have to do is drive to a testing facility".  Yes.  That is the point.  You just lost the most motivating factor of your certification.  Me.  Being at home.  The world is moving to telecommuting and the ability to do anything from anywhere.  Hell, before now, I could have taken the SANS test on my iPhone!

Seems like SANS is going backwards.

RSS Feed, now at full throttle

I moved the RSS feed back to full.  Now that I have a descent count.  

I appreciate all the people that clicked through, either on the short rss article, or on others, it gives me a better count.  I think the bandwidth that I have is sufficient since I removed the bigger video files and what not from the site.  We should be good now.

Tuesday, December 4

Still a Quicktime ZeroDay out there!

WabiSabiLabi is reporting that the Quicktime vulnerability that I wrote about last week is NOT the one in their "for sale" repository.  
Now, the way I look at this is that WabiSabiLabi is not doing the responsible thing and disclosing it to the vendor.  They are selling it.  Basically trying to blackmail or hold the vulnerability for ransom.  

I'm not of the opinion that everything needs to be disclosed to the public, but it should at least be disclosed to the vendor.  If there is an exploit, and it's not being reported to the vendor, then it's irresponsible in my opinion.  

WabiSabiLabi says this is their philosophy: "Wabi-sabi nurtures all that is authentic by acknowledging three simple realities: nothing lasts, nothing is finished, and nothing is perfect."  

I can understand people trying to get paid for their research, but there is a certain line.  They should apply for a job at the vendor or something.  I don't know what the proper procedure is, but holding the vulnerability for ransom isn't fair.

If you are going to have a vulnerability, try to get the vendor to pay you for it.  Or keep it to your damn self.

If you are interesting in paying into WabiSabi's coffers: 442.62 will get you a Quicktime exploit for Windows XP.

A small price to pay for Apple to ensure the security of it's customers.

Two new Mac Exploits

I just saw that two new Mac Exploits have hit the streets.  Both are Denial of Service exploits.
The first one is an exploit against vpnd, version Leopard 10.5.0.  
The second is against xnu, 10.4, 10.5.1 (i386), and 10.5.1 (ppc).

Both are from digit-labs.org.

And we all know that a DoS is one step away from a remote exploit.

Podcast 101?

I've been invited to participate in a Podcast this week.  This will be my first "official" podcast.  I've been in other podcasts before, but just because I was present.  But this will be the first time I've been a panel member.  

Should be cool.

I don't actually know if I will be on the podcast yet, as my daughter is having some extremely minor surgery tomorrow.  If I am going to be on the podcast, I will let you know via a post here, with a link to the site.

Microsoft reopens WPAD Vulnerability from 1999.

Apparently MSFT hasn't had enough vulns lately.  They decided to reintroduce one (or never fix it in the first place).

From 1999.

Reported last week at a "ethical hacker conference" in New Zealand by Beau Butler, the WPAD vulnerability allows you to perform a man-in-the-middle attack for hostnames that do not have a FQDN.    Essentially, what happened is Microsoft fixed it back in 1999, and it's taken this long to figure out that they only fixed it for ".com".  Other extensions weren't fixed at all ".au", ".nz" for example.

Some blogs have picked this up and said "Zero Day!!!"  But it's not.  It's the same one from 1999.

Here is a link to the Microsoft Security Advisory posted yesterday.

It lists several mitigating factors.
• Customers who do not have a primary DNS suffix configured on their system are not affected by this vulnerability. In most cases, home users that are not members of a domain have no primary DNS suffix configured. Connection-specific DNS suffixes may be provided by some Internet Service Providers (ISPs), and these configurations are not affected by this vulnerability.
• Customers whose DNS domain name is registered as a second-level domain (SLD) below a top-level domain (TLD) are not affected by this vulnerability. Customers whose DNS suffixes reflect this registration would not be affected by this vulnerability. An example of a customer who is not affected is contoso.com or fabrikam.gov, where “contoso” and “fabrikam” are customer registered SLDs under their respective “.com” and “.gov” TLDs.
• Customers who have specified a proxy server via DHCP server settings or DNS are not affected by this vulnerability.
• Customers who have a trusted WPAD server in their organization are not affected by this vulnerability. (See the Workaround section for specific steps in creating a WPAD.DAT file on a WPAD server.)
• Customers who have manually specified a proxy server in Internet Explorer are not at risk from this vulnerability when using Internet Explorer.
• Customers who have disabled 'Automatically Detect Settings' in Internet Explorer are not at risk from this vulnerability when using Internet Explorer.

In my opinion, this is weak.  That's apparently Secunia's opinion as well.  As they rated it "less critical".

My question is, did MSFT re-introduce this vulnerability?  Or did they just half ass fix it in `99?

The following OS'es are affected:
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Vista
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional

Two new Mac Exploits

I just saw that two new Mac Exploits have hit the streets.  Both are Denial of Service exploits.
The first one is an exploit against vpnd, version Leopard 10.5.0.  
The second is against xnu, 10.4, 10.5.1 (i386), and 10.5.1 (ppc).

Both are from digit-labs.org.

And we all know that a DoS is one step away from a remote exploit.

Podcast 101?

I've been invited to participate in a Podcast this week.  This will be my first "official" podcast.  I've been in other podcasts before, but just because I was present.  But this will be the first time I've been a panel member.  

Should be cool.

I don't actually know if I will be on the podcast yet, as my daughter is having some extremely minor surgery tomorrow.  If I am going to be on the podcast, I will let you know via a post here, with a link to the site.

Microsoft reopens WPAD Vulnerability from 1999.

Apparently MSFT hasn't had enough vulns lately.  They decided to reintroduce one (or never fix it in the first place).

From 1999.

Reported last week at a "ethical hacker conference" in New Zealand by Beau Butler, the WPAD vulnerability allows you to perform a man-in-the-middle attack for hostnames that do not have a FQDN.    Essentially, what happened is Microsoft fixed it back in 1999, and it's taken this long to figure out that they only fixed it for ".com".  Other extensions weren't fixed at all ".au", ".nz" for example.

Some blogs have picked this up and said "Zero Day!!!"  But it's not.  It's the same one from 1999.

Here is a link to the Microsoft Security Advisory posted yesterday.

It lists several mitigating factors.
• Customers who do not have a primary DNS suffix configured on their system are not affected by this vulnerability. In most cases, home users that are not members of a domain have no primary DNS suffix configured. Connection-specific DNS suffixes may be provided by some Internet Service Providers (ISPs), and these configurations are not affected by this vulnerability.
• Customers whose DNS domain name is registered as a second-level domain (SLD) below a top-level domain (TLD) are not affected by this vulnerability. Customers whose DNS suffixes reflect this registration would not be affected by this vulnerability. An example of a customer who is not affected is contoso.com or fabrikam.gov, where “contoso” and “fabrikam” are customer registered SLDs under their respective “.com” and “.gov” TLDs.
• Customers who have specified a proxy server via DHCP server settings or DNS are not affected by this vulnerability.
• Customers who have a trusted WPAD server in their organization are not affected by this vulnerability. (See the Workaround section for specific steps in creating a WPAD.DAT file on a WPAD server.)
• Customers who have manually specified a proxy server in Internet Explorer are not at risk from this vulnerability when using Internet Explorer.
• Customers who have disabled 'Automatically Detect Settings' in Internet Explorer are not at risk from this vulnerability when using Internet Explorer.

In my opinion, this is weak.  That's apparently Secunia's opinion as well.  As they rated it "less critical".

My question is, did MSFT re-introduce this vulnerability?  Or did they just half ass fix it in `99?

The following OS'es are affected:
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Vista
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional

Short rss feeds

I've shortened my RSS feeds, please click on the link to get the full article, you'll see why below... with that said...

Ever since I moved the blog back from web.mac.com to my own servers, as I have said before, I am receiving alot more traffic than before.  At present I am getting about 4000-4500 hits a day, which isn't much in the grand scheme of things, but when you go from getting 1000 hits a day, to 4x that a day, it really makes a difference in servers, server load, and ability to serve content to readers to keep it interesting.

So, I'm trying to get an accurate metric of how many people read the blog.  Problem is, I have tons of people that read me through rss and atom feeds (btw -- the atom feed is being kept alive manually, I'll stop doing this shortly.  Please subscribe to the rss feed. http://www.joelesler.net/rss.xml).  

Most blog aggregation services will tell you in the "GET" request how many people they are aggregating for.  Google does this, Newslines does this, and Bloglines does this.  So thanks to them for that.  But these obscure blog readers; and individual blog readers that read in Safari, or Mail.app, or NetNewsWire, there is no good way to get a count from them.  You've got people coming from different IP's.  You have people coming from multiple IP's (do i count them as two?)  So it's tricky.

So what I did was, shortened the rss.xml feed.  That way, in hopes that you guys click into the site and read the full post, so I can get an accurate count.

I have every intention of making the rss feed full length again, let's say I'll do it next week.  So don't worry, you'll get your full feeds.   But for now, I am just trying to get an accurate count.

I've also posted some convenient "subscribe here" buttons on the right --------->
so if you read from one of those readers, feel free to add me there.  Notice that I've added the ones that give me counts :)

Thanks for your patience while I get this stuff done.  

Sunday, December 2

/usr/ports update

I updated my port tree (and all the ports underneath it) using portupgrade tonight.  Then bash stopped working.
Crap.

Found this article, (click on title of blog entry to go to the website).   Good thing I did too.

"...After this I was able to start X and continue on with my work. Though this worked, the above is not the correct way to fix the “shared object ‘libintl.so.6′ not found” error. Reading /usr/ports/UPDATING revealed I needed to do:

portupgrade -rf gettext

The above is required if you upgraded to: gettext-0.16.1. /usr/ports/UPDATING shows:

20070318:
AFFECTS: users of devel/gettext (ie: YOU)
AUTHOR: ade@FreeBSD.org

As a result of the upgrade to gettext-0.16.1, the shared library version
of libintl has changed, so you will need to rebuild all ports that
depend on gettext (ie: most of them, sorry):

portupgrade -rf gettext"

/usr/ports update

I updated my port tree (and all the ports underneath it) using portupgrade tonight.  Then bash stopped working.
Crap.

Found this article, (click on title of blog entry to go to the website).   Good thing I did too.

"...After this I was able to start X and continue on with my work. Though this worked, the above is not the correct way to fix the “shared object ‘libintl.so.6′ not found” error. Reading /usr/ports/UPDATING revealed I needed to do:

portupgrade -rf gettext

The above is required if you upgraded to: gettext-0.16.1. /usr/ports/UPDATING shows:

20070318:
AFFECTS: users of devel/gettext (ie: YOU)
AUTHOR: ade@FreeBSD.org

As a result of the upgrade to gettext-0.16.1, the shared library version
of libintl has changed, so you will need to rebuild all ports that
depend on gettext (ie: most of them, sorry):

portupgrade -rf gettext"

Thursday, November 29

Now, that's a nice User-Agent

I was looking through my httpd-access.log today for something, and ran across this, (Yes, I have removed the IP):

"[29/Nov/2007:17:18:18 -0500] "GET /uploaded_images/questionmark-785318.jpg HTTP/1.1" 200 6203 "http://www.bloglines.com/myblogs_display?sub=44519724&site=8488306" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.9) Gecko/20071025 Internet Explorer'); DROP TABLE browsers;--"
 
Little injection attempt there?  Trying to drop the ol' browser table in some kind of stats db.  

So who cares.  Well it made me think of something.  If this person can obviously alter his/her User-Agent to do that, what is to make you think that the rest of the Agent string is valid?  How do we know that his person is really using "Internet Explorer"?

At what point does the trust break.  I've often gone with the adage of "don't trust anything", not a single packet.   What if you use p0f to passively fingerprint the OS'es of the machines attempting to access your network, okay, and I go in, compile my own kernel on my Linux box, and set my IP and TCP attributes such that it will appear to be Windows when I communicate with your network?

What can you trust on your own network?  If someone hacks into your web server, is there any merit in seeing what they did once they got on the machine?  You no longer can trust a single thing on the box, and definitely anything coming out of the box!   It has to be rebuilt.

Mod_security did not catch the above attempt btw.  (It will now)

Facebook

I've been hearing alot recently about the new way to communicate with the world, via social networks.  MySpace, FaceBook, Pownce and the like.  I've had a couple people encourage me to do it.  So I decided I'd at least join one.

So I grabbed a FaceBook account and requested a Pownce account.  I have my principles against joining MySpace.  (Which in my opinion is truly the biggest waste of bandwidth on the internet.)

So, if you want, hit me up on FaceBook.  See you there.

Update:  I now have a Pownce account.  Hit me up there too.  Username = joelesler

Wednesday, November 28

Facebook

I've been hearing alot recently about the new way to communicate with the world, via social networks.  MySpace, FaceBook, Pownce and the like.  I've had a couple people encourage me to do it.  So I decided I'd at least join one.

So I grabbed a FaceBook account and requested a Pownce account.  I have my principles against joining MySpace.  (Which in my opinion is truly the biggest waste of bandwidth on the internet.)

So, if you want, hit me up on FaceBook.  See you there.

Update:  I now have a Pownce account.  Hit me up there too.  Username = joelesler

Rebuilt Website

The machine I was running this website on wasn't handling the load too well.  Had to rebuild.  I had a server sitting around here, so I loaded it with freebsd, and put www.joelesler.net on it.  

Now it works much better.  Had to place it in the basement of the house though, it was kinda loud with all those fans running.  Had to drill a hole in the floor of my office to get the Cat 6 cable through the floor, but all is well now.

Tuesday, November 27

Okay Apple. Are you awake?

Friend of mine pointed this out to me. http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0252
This vulnerability from 2002 appears to be the same vulnerability that was just found in 7.2 and 7.3 in Quicktime!

Except that the 2002 vulnerability was found in a piece of software called... Quicktime. Uh? And I thought Microsoft was the only company that re-introduced old vulnerabilities.

Come on Apple, I hold you to a higher standard than that! Let's go.

You get the moron label on this post.

UPDATE: The original vulnerability was for the Japanese version of Quicktime. You would think that Apple would update all their code.

Okay Apple. Are you awake?

Friend of mine pointed this out to me. http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0252
This vulnerability from 2002 appears to be the same vulnerability that was just found in 7.2 and 7.3 in Quicktime!

Except that the 2002 vulnerability was found in a piece of software called... Quicktime. Uh? And I thought Microsoft was the only company that re-introduced old vulnerabilities.

Come on Apple, I hold you to a higher standard than that! Let's go.

You get the moron label on this post.

UPDATE: The original vulnerability was for the Japanese version of Quicktime. You would think that Apple would update all their code.

Monday, November 26

Apple QuickTime 7.3 RTSP Response 0day Remote SEH Overwrite PoC Exploit

For those of you that have not seen it this morning, (actually, it was last week, but who cares), there is a PoC (and actual exploit code out for XP and Vista -- I have not seen any for OSX, just the PoC), for Apple Quicktime 7.3.  

While we are waiting for Apple to post a patch, please, please go here: http://zapatopi.net/afdb/build.html. And affix to head.

Uhhh thanks?  

Stupid advertising mistakes

W00t! I am Paypal, and I am going to give you 20% cashback, on all your purchases from all these fine retailers!!


Except we didn't have enough retailers to fill our graphic, so we took the same ones on the top, moved them around, and put them on the bottom too!  Look!  We have twice as many now!

Why do retailers feel the need to over inflate?  Sorry, I just needed to vent this morning.  Thanks.

Apple QuickTime 7.3 RTSP Response 0day Remote SEH Overwrite PoC Exploit

For those of you that have not seen it this morning, (actually, it was last week, but who cares), there is a PoC (and actual exploit code out for XP and Vista -- I have not seen any for OSX, just the PoC), for Apple Quicktime 7.3.  

While we are waiting for Apple to post a patch, please, please go here: http://zapatopi.net/afdb/build.html. And affix to head.

Uhhh thanks?  

Stupid advertising mistakes

W00t! I am Paypal, and I am going to give you 20% cashback, on all your purchases from all these fine retailers!!


Except we didn't have enough retailers to fill our graphic, so we took the same ones on the top, moved them around, and put them on the bottom too!  Look!  We have twice as many now!

Why do retailers feel the need to over inflate?  Sorry, I just needed to vent this morning.  Thanks.

Sunday, November 25

joelesler.net

I decided I should go ahead and actually get a primary domain, instead of surfing off of esler.is-a-geek.net (which is a dynamic dns freebie domain (is-a-geek.net), and bought joelesler.net. I couldn't get joelesler.com, my long lost twin in Australia owns that one, and I am not a .org, so I didn't get that one. esler.org and esler.net were also taken, or I would have grabbed those as well. That way I could set up fun email address for the whole family.

The only one that was available is esler.com, but they want 2500 bucks for that one. I'm not going to pay 2500 bucks for my own damn last name. But esler.com used to be a website for an airport in Alexandria, Louisiana, (seriously! Esler airpark!), so someone has it parked, and has the stranglehold on that one currently. I actually landed at the airpark once when I was in the military. We were going to Fort Polk, and that's the airport we landed in. Of course I didn't know it until later.

I have email here, all the DNS zones I can handle, and loads of other goodies that you can do with your own domain. So I have changed my email on the right of page to reflect my new domain.

Esler.is-a-geek.net will still work for now, it's free! But eventually, when I get tired of renewing it every 90 days, I'll ditch it.


Saturday, November 24

M/S Explorer is sinking

No really.  The M/S Explorer has crashed, and is sinking.

"More than 150 passengers and crew have been rescued from a stricken tourist ship after it hit ice off Antarctica.  The M/S Explorer is now lying on its side close to the South Shetland Islands, in the Antarctic Ocean."

Okay, so it was a cheap poke designed to get you laughing.  As long as it worked then I am fine.


(That was a Microsoft Explorer joke..)

joelesler.net

I decided I should go ahead and actually get a primary domain, instead of surfing off of esler.is-a-geek.net (which is a dynamic dns freebie domain (is-a-geek.net), and bought joelesler.net. I couldn't get joelesler.com, my long lost twin in Australia owns that one, and I am not a .org, so I didn't get that one. esler.org and esler.net were also taken, or I would have grabbed those as well. That way I could set up fun email address for the whole family.

The only one that was available is esler.com, but they want 2500 bucks for that one. I'm not going to pay 2500 bucks for my own damn last name. But esler.com used to be a website for an airport in Alexandria, Louisiana, (seriously! Esler airpark!), so someone has it parked, and has the stranglehold on that one currently. I actually landed at the airpark once when I was in the military. We were going to Fort Polk, and that's the airport we landed in. Of course I didn't know it until later.

I have email here, all the DNS zones I can handle, and loads of other goodies that you can do with your own domain. So I have changed my email on the right of page to reflect my new domain.

Esler.is-a-geek.net will still work for now, it's free! But eventually, when I get tired of renewing it every 90 days, I'll ditch it.


M/S Explorer is sinking

No really.  The M/S Explorer has crashed, and is sinking.

"More than 150 passengers and crew have been rescued from a stricken tourist ship after it hit ice off Antarctica.  The M/S Explorer is now lying on its side close to the South Shetland Islands, in the Antarctic Ocean."

Okay, so it was a cheap poke designed to get you laughing.  As long as it worked then I am fine.


(That was a Microsoft Explorer joke..)

Friday, November 23

Thank you for watching


For those of you who read my next post and then took the URL in the log that I posted, and copies and pasted that into the address bar of your browser, and read the Microsoft label page, you are missing the point. 
-- Thank you for reading, but that's not what I am asking. --
Look at the log entry.  If you have access to apache logs yourself, go look at yours, or find some on the internet, then come back and tell me what is wrong with that log entry.
(BTW -- Those of you that cut and pasted, about 20 of you did it, so don't feel bad, you are not alone.)

Wednesday, November 21

Why would a browser do this?

First of all, tell me what's wrong with this picture, then explain to my why a browser would do this?

[21/Nov/2007:16:36:05 --0500] "GET http://esler.is-a-geek.net/labels/Microsoft.html HTTP/1.1" 406 340 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Maxthon)" - "-"

Maxthon is the name of the browser.

iChat Screen Names For Over 30 Apple Stores

Digg - iChat Screen Names For Over 30 Apple Stores:

I never even thought of doing this with all the Apple Stores that I have been to. Get the screen names for all the iChat's for the machines in the store? Someone add these all to your iChat buddy list and send me a screen shot. That would be hilarious.

iChat Screen Names For Over 30 Apple Stores

Digg - iChat Screen Names For Over 30 Apple Stores:

I never even thought of doing this with all the Apple Stores that I have been to. Get the screen names for all the iChat's for the machines in the store? Someone add these all to your iChat buddy list and send me a screen shot. That would be hilarious.

Sunday, November 18

Gas is stupid expensive, and Security 2.0

Yeah, I get it. If oil prices go up for this reason or that reason, gas prices are soon to follow. But costing me 60.00 to fill up the tank?

Come on. Is that truly necessary? There is nothing that can be done
about that at all?


On another note--

I've thinking about writing a blog entry about the state of modern security in computer networks. Does it work? Where are we at?  Are all the extremely restrictive policies in your corporate work environment working?  What can be relaxed?  Why?

Like to hear your thoughts. What does "security 2.0" mean to you?  

Gas is stupid expensive, and Security 2.0

Yeah, I get it. If oil prices go up for this reason or that reason, gas prices are soon to follow. But costing me 60.00 to fill up the tank?

Come on. Is that truly necessary? There is nothing that can be done
about that at all?


On another note--

I've thinking about writing a blog entry about the state of modern security in computer networks. Does it work? Where are we at?  Are all the extremely restrictive policies in your corporate work environment working?  What can be relaxed?  Why?

Like to hear your thoughts. What does "security 2.0" mean to you?  

Wednesday, November 14

Cabling

I have no idea where this picture came from, (well, the site I got it from is here, but I don't know what the picture is of) but I thought it was great.

Think you have issues with cabling in your network?
Think again.

Cabling

I have no idea where this picture came from, (well, the site I got it from is here, but I don't know what the picture is of) but I thought it was great.

Think you have issues with cabling in your network?
Think again.

Monday, November 12

Love it when I am right

I love it when I am right.

Remember this post?  I said that Apple and Starbucks should partner.  Imagine the possibilities.


800 posts, and mod_security blocking

Took a look at my mod_security logs tonight.  Apparently, if you use Google's Reader to my rss feed, then actually try to go to my website via the link in the RSS..  trying to do all this when you are behind a Bluecoat Proxy server on your internal network...

You get blocked.  The bluecoat proxy forwards your "X-forwarded for" header to the Google Reader, then, finally when you click on the link to come to my website, Google forwards your internal IP.

Which mod_security didn't like:

"!^(((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-
9][0-9]?)|)|unknown)$" at HEADER("X-FORWARDED-FOR")

It doesn't like you.   I commented out the rule, so everything should be fine now.

Love it when I am right

I love it when I am right.

Remember this post?  I said that Apple and Starbucks should partner.  Imagine the possibilities.


800 posts, and mod_security blocking

Took a look at my mod_security logs tonight.  Apparently, if you use Google's Reader to my rss feed, then actually try to go to my website via the link in the RSS..  trying to do all this when you are behind a Bluecoat Proxy server on your internal network...

You get blocked.  The bluecoat proxy forwards your "X-forwarded for" header to the Google Reader, then, finally when you click on the link to come to my website, Google forwards your internal IP.

Which mod_security didn't like:

"!^(((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.(25[0-5]|2[0-4][0-9]|[01]?[0-
9][0-9]?)|)|unknown)$" at HEADER("X-FORWARDED-FOR")

It doesn't like you.   I commented out the rule, so everything should be fine now.

MacBook Pro Goodness

I bit the bullet.

I went out this weekend and purchased my first Intel based Mac. I didn't buy the first gen (or the second gen for that matter) MacBook Pro (MBP), simply because, usually, it's a bad thing to buy Apple hardware in it's first gen. (Except for the iPhone currently)

But the MBP is excellent. It's not hot, it runs fast (even with it's stock 2 Gigs of RAM), and works flawlessly. The MBP had Tiger on it when I bought it, but came with a Leopard install disk, which is nice.

The only thing that I had problems with was, my old wireless card from AT*T was PCMCIA. The new MBP's have Express card slots. So, I had to get a new card. Which the guy at the store, let me tell you, was a prick. Dude, obviously, if I come in, ask for an exact model number for a laptop card, tell you I already have an account (which he had to verify, because he didn't believe I already had a SIM card), I have obviously already looked to see if my computer supports it.

He insisted that OSX was not supported and the card wouldn't work. Well uh, no, it's not supported by AT*T that doesn't mean that it's not supported by the card manufacturer. (Option) What a tool, anyway...

I get the card home, plug it in, and wtf. The lights are flashing.. huh? What did I do wrong? Oh, I had the SIM card inserted backwards. My bad.

Flipped it around, and it worked fine. In fact, not only did it work fine, but Leopard has NATIVE DRIVER SUPPORT for it. No loading 3rd party software, no wierd communications spyware... err.. manager i mean... It just works. Nice little toolbar access to the card. Very nice.

Anyway, I gotta go order my other two Gigs of RAM for this thing, so I can love on it some more.

MacBook Pro Goodness

I bit the bullet.

I went out this weekend and purchased my first Intel based Mac. I didn't buy the first gen (or the second gen for that matter) MacBook Pro (MBP), simply because, usually, it's a bad thing to buy Apple hardware in it's first gen. (Except for the iPhone currently)

But the MBP is excellent. It's not hot, it runs fast (even with it's stock 2 Gigs of RAM), and works flawlessly. The MBP had Tiger on it when I bought it, but came with a Leopard install disk, which is nice.

The only thing that I had problems with was, my old wireless card from AT*T was PCMCIA. The new MBP's have Express card slots. So, I had to get a new card. Which the guy at the store, let me tell you, was a prick. Dude, obviously, if I come in, ask for an exact model number for a laptop card, tell you I already have an account (which he had to verify, because he didn't believe I already had a SIM card), I have obviously already looked to see if my computer supports it.

He insisted that OSX was not supported and the card wouldn't work. Well uh, no, it's not supported by AT*T that doesn't mean that it's not supported by the card manufacturer. (Option) What a tool, anyway...

I get the card home, plug it in, and wtf. The lights are flashing.. huh? What did I do wrong? Oh, I had the SIM card inserted backwards. My bad.

Flipped it around, and it worked fine. In fact, not only did it work fine, but Leopard has NATIVE DRIVER SUPPORT for it. No loading 3rd party software, no wierd communications spyware... err.. manager i mean... It just works. Nice little toolbar access to the card. Very nice.

Anyway, I gotta go order my other two Gigs of RAM for this thing, so I can love on it some more.

Friday, November 9

Welcome back

iWeb is a great program, makes nice webpages, the problem is, it stores the entire website in one huge file called "Domain". So, I have taken the time to transition everything back to here.

Essentially, because iWeb keeps everything in that one file, I couldn't edit the webpage on multiple computers, nor could I edit it from the road. I used to keep the Domain file on my iDisk, so I could sync it between machines... Which was fine... except when it got to be like 250 Mb's. It was alot to sync. So, I decided to move everything back to my Linux server.

I'll probably lose some people in the transition between the iWeb domain, and bringing it back to my server, but hopefully they find me again.

Welcome back

iWeb is a great program, makes nice webpages, the problem is, it stores the entire website in one huge file called "Domain". So, I have taken the time to transition everything back to here.

Essentially, because iWeb keeps everything in that one file, I couldn't edit the webpage on multiple computers, nor could I edit it from the road. I used to keep the Domain file on my iDisk, so I could sync it between machines... Which was fine... except when it got to be like 250 Mb's. It was alot to sync. So, I decided to move everything back to my Linux server.

I'll probably lose some people in the transition between the iWeb domain, and bringing it back to my server, but hopefully they find me again.

Tuesday, November 6

TWiT -- This Week in Tech

This week I started listening to TWiT, otherwise known as This Week in Tech. With Leo Laporte and John Dvorak.

First of all, little bit of background, I listen to two (now three) podcasts. I listen to Diggnation (which is what got me started listening to Podcasts), and the Totally Rad Show. Both have Alex Albrecht in them, (he’s pretty funny), and the former has Kevin Rose, founder of Digg.com and both are from the TechTV show The Screen Savers. Which was a show ‘back in the day’ before G4 bought the channel and ruined it. Anyway...

I started listening to TWiT (Leo Laporte was also a host of The Screen Savers) today and kinda like it. There are just a couple things about it that I am not in total agreement with. First of all, it’s press and media ish people. There are no real real real geeks on the show. (Alex and Kevin have even lost a bit of touch.) Hello? There are geeks out there people that have the ability to talk to the public as well! (Uh, me?) People can joke and be knowledgeable at the same time.

Second, one of things I found interesting in the TWiT podcast was John Dvorak. Now we all know Dvorak as the guy who is really big into bashing all things everything. Apple, Microsoft, etc. He’s got something to say. Most of which I agree with (when it comes to Microsoft being an evil corporation), but some of it I do not. (Like his famed Apple punditry). But it was interesting to hear him (in TWiT episode 119) say basically, look people Microsoft is done. Buy a Mac. It’s over for MSFT. Something I have been saying for awhile, because I pretty much dislike anything MSFT. But it was interesting to hear Dvorak say that.

Third, Leo doesn’t read his email. (He said this on Episode 119) I don’t know how you can survive without reading or writing email, since that is the mainstream form of communication now adays. But anyway, to each his own.

On the email note, I recently received an email chastising me about not writing on the blog anymore. Truth is, I’ve been very busy and haven’t had time to do a proper review of any tech stuff, and I’ve been up to my eyeballs in packets. (which I suppose I could write about).

Thanks to the couple hundred readers that I do have, I’ll have to get back on the blogging wagon. I always think that no one reads this thing until I start getting emails asking me to “write something new!” “Haven’t heard from you in awhile!”

Back to podcasts --

I was actually asked to start a podcast on general tech/security stuff, but I declined. First of all, who has the time? I wouldn’t do it alone, and the people I would want to do a podcast with would probably make fun of me for asking them to do it. (Although, if they did, it would be the funniest podcast out there, bar none.)

If you have any podcasts out there that you think I should be listening to, please let me know!

Monday, November 5

Google Phone, Apple Stock, and other Random Blatherings

Today’s news has just been a buzz with Google’s announcement of their “gphone”. Wait...

Google’s phone is NOT a PHONE! It’s Open Software, FOR phones. Google isn’t making a phone (yet), and no products have been announced. So at this point, this is ‘releaseware’. Other phone companies (Motorola, Sony, Nokia, and the like) have to want to put Google’s software on their phones. Will they do that? When they have a significant investment in their own OS’es on their phones now? Time will tell.

Apple’s Stock Price --

I can’t complain. Everytime Apple’s stock price levels out and doesn’t go anywhere for awhile, they introduce something new. iPhone, iPod Nano, iPod Touch, 3rd Quarter earnings, new laptops... just keep on going Apple, keep on going.

Trolls--
I’ve noticed as of late alot of trolls in some IRC channels that I am in. Why would you come into a product channel and say “your product sucks because ”? Do I jump into the #windows channel and say “Control Panel sucks, therefore the whole OS sucks!” No!, because that’s called “Trolling”! Why would you pop in one of my channels, where clearly, there are alot of people that know more about the product then you and say something insane like.. “You can’t achieve >1 Gig speeds with your product!”.

Sorry, just needed to vent.

For those reading this blog looking for leopard feedback, here you go. I like it. There are only a couple things I can’t get to work. Back to my Mac for one (probably because of some firewall setting I have), local lan browsing always doesn’t work, and my laptop battery power really really sucks now. I can drain my whole laptop battery in about 10 minutes. Something isn’t right.

I really like Time machine, it’s great. I like alot of their new features, even though, I admit, leopard could have used a bit more testing before release.

Hopefully they release a fix-it pack soon. But I still like it!