Pages

Sunday, April 4

iPad review

My mother in law, whose extent of using the Internet is asking where the big blue "E" is, sat done with my iPad and in five minutes of using it, knew how, and was determined that she wanted one. (That is to say that technology is not really her thing, she's a very smart woman)

My three year old daughter, who has prior computing experience on my iPhone, used my iPad for sly of about 3 seconds and was watching videos and playing games on it.

My wife, who also has an iPhone, works on Windows and Macs everyday started using it right away.

Reminded me of that Staples commercial. "That was easy".

I swore to myself that I would approach this device (writing this blog post on it, on the virtual keyboard too) with an open and objective mind, not to be an Apple fanboy, and really use nothing but this device for, say a week, and really give it a good review. I figure the only way to give a good review about this device is to do just that, and see, once and for all, if you really could replace a laptop with it.

Of course there are going to be the people marching with their picket signs proclaiming that the iPad is the end of the net book, "the end is nigh!!!". I am not saying they are wrong, but I am also not proclaiming that they are right either. This device clearly fills a void, that before it came out, we never knew existed.

We never knew what a nice interface for the mobile phone looked like until the iPhone came out either. Remember the interfaces of the Palm Treo and Blackberries before the iPhone came out? We never knew what a touch interface would yield us. Now look at the world, 3 years later, and you'd be hard pressed to go anywhere and not see at least a dozen iPhones on the way to your destination. Even in New York City, where AT&T's coverage is, frankly, horrible, you still see iPhones on almost everyone.

The iPad is similar. You never knew you had a need or a want for a device like this one until you pick one up and use it. For me, when sitting on the couch during the first 10 minutes of having it, browsing the Internet, setting up my email accounts and answering a few emails on it, i said to myself "I get it".

Apple describes the experience in using the device "far more intimate" than using a smartphone or a laptop. Now I understand why they used that particular piece of terminology. It doesn't seem as if there is a barrier to using the device. Not in terms of learning to use this device, but in terms of interacting with the content. You don't have the perception that you are moving the mouse or typing on a keyboard to manipulate the information. You feel like, you are creating or moving the information.

It feels like Star Trek. Ever watch the next generation, when Data or someone was configuring something on the screen? That, was the iPad. That's what it feels and looks like. Minority report (not the big screen, the little one) style.

You want to click on something, you tap it. You want to move or scroll, you move the stuff on the screen with your finger. Want to type something, you just, go and type it.

I'll rate everything on a scale of one to ten.

Typing (6)
It takes a minute to get used to typing on it, especially when you are trying to hit the "a" key with your pinky (i keep hitting s). But after about 20 minutes or 10 emails worth of typing, you are whizzing through typing on this thing fast as heck. No problem. I can type almost as fast on the iPad as I do on the regular keyboard, the main advantage I have is the error correction. It takes a second, just like you had to get used to on the iPhone, to remember that you shouldn't back space, just keep typing and more than likely the error correction on the OS will fix itself. Same issue with the apostrophe on certain words. For instance, "hell" you have to type manually, otherwise it'll come out "he'll". But I can imagine, after typing on this thing awhile, I'll go back to a regular keyboard and try and type the double space shortcut (period then space), and I won't be able to.

Also how you hold it is important, personally I prefer to type in landscape mode, as in portrait mode, the keyboard is a bit too wide to use with just my thumbs. In landscape mode, I can type on it comfortably.

Videos (9)
Watching videos on this thing is phenomenal. I have watched several episodes of tv shows, both House and Top Gear. All in "high definition" and all looked great. Now, the HD purists will complain that the resolution isn't high enough to be called high def, and the true 16x9 ratio isn't there, but it's a great device for watching content on.

Browsing (7)
Yeah, it doesn't have flash. No I don't care. I block flash in my desktop browser anyway, I prefer html5 for many reasons, the main being that html5 has never caused my fan on my laptop to kick on and run in overdrive. Flash always does. Try it. See how fast your computer heats up when you are using flash as opposed to html5. See how fast your battery dies in a comparison between the two. Otherwise browsing on this thing kicks butt. I have only encountered one problem on one website, where I couldn't scroll down, but the scrolling action was controlled by flash. So obviously.

Email (8)
Perfect client for writing a small email on. If you are one of those types who likes to write "War and Peace" length emails, then this might not be the device for you, even though you shouldn't have a problem, heck I wrote this whole long blog post on the virtual keyboard. But if you are like the 99.9% of email writers out there that answer there email in about 5 sentences or a couple paragraphs, then this device is just fine for you. The only two drawbacks so far that i see are, a) lack of universal inbox, which Steve Jobs himself said is coming and b) you cant move an email from one account to another.

Apps (6 for the iPhone apps that are pixel doubled, 8-9 for the iPad native apps)
While the pixel doubling for the iPad is good for iPhone shaped apps, some of the text can look a bit blocky, but they work just fine. My daughter had no problem playing her games, and you shouldn't either. I was testing out Real Racing over the weekend and it worked just fine. It was actually much better playing the game on a big screen instead of the iPhone. Some of the apps for the iPad that have been redesigned are great. I love them. Especially the Accuweather app. Beautiful. You can really tell the difference between the apps that were, from the ground up designed to work for the iPad, and the apps where they took the iPhone app, and just, made it bigger. I am sure, in time those apps will be redesigned now that the hardware is actually out.

Calendar (9)
It actually works, looks, and functions like a calendar. I use the iCal all the time constantly, and it's synced automatically with google calendar. On the iPhone, it worked great, it does work great, but the iPad is just, better some how. It looks better, it looks like a real calendar, or as well as real as a digital calendar can look. They real did a nice job with the presentation of the app, the top of it looks like you just tore off the day prior.

Contacts (9)
Same as above, it looks like a book, an actual contact book that might sit in that drawer under the phone in your kitchen. You use it like a book, it looks like a series of tabs on the left, and you can use it just like that.

Pages, Keynote, and Numbers (7)
These apps are great. I haven't gotten the chance to use Numbers and Keynote yet, but i sent the better part of today editing a document in Pages. (hey like i said, i really wanted to test the thing!). It's not as full featured as the desktop version, but it's a damn good word processor for the majority of documents that are going to be created. If my wife or my mother-in-law wanted to write a document, make a sign, or work on their resume, they could do so very easily.

iTunes, Videos, and Youtube (8)
They clearly designed this device to take advantage of the media in your iTunes library, or some deals that Apple is trying to make. This is a great device to watch videos on, as i already said, but the interfaces wrapped up in each of the above built in apps clearly make this a device perfect for consuming media on.

Speaker (8)
It's good. You can watch a movie, tv show, or whatever, and it functions great and has plenty of sound. It's not a 5.1 surround system, but it works great and it was actually a bit surprising.

Buttons (uh 10?)
Home button, volume buttons, and lock buttons just like the iPhone. However, the silent/ringer button has been replaced with a "screen lock" button. When switched, locks your screen in whatever position you currently have it in. Landscape or portrait, it just stays there. Useful if you are sitting at s strange angle on the couch or something and the iPad's accelerometer doesn't know if it's up or down or sideways.

Battery (10)

The battery is unbelievably long lasting.  I've been using it since Saturday, basically as my primary computer, and I've plugged it in once.  I've watched videos on it, I've browsed on it, I've played games on it, I've read books on it.  Just great battery life.

iBooks (8)

The books are great.  I've a couple free ones on my device here, and I've read about 100 or so pages.  The books work great in landscape or portrait, in sunlight, and in shade, inside and out.  The only thing about the iPad is that it weighs a pound and a half, which isn't a big deal, you just shift the weight from hand to hand every couple pages, unless you are a total sissy, or if you are 2 years old.  (My three year old little girl can hold it for a long period of time and not complain, so if that's any indication)

Screen (10)

The screen is beautiful.  Yes it gets fingerprints on it, but I have a little cloth from KlearScreen.com that I have had for years (since I first started using Macs), a newer one can be found in these kits.  I wipe the screen, it comes right off.  Something a little micro-fiberish takes everything right off, yeah, you could use a Tshirt too.  Glare on the screen?  People seem to think that sunlight would create a gigantic glare on the device, I disagree.  I think apps that have dark backgrounds are the worst culprit.  You read a book in iBooks, in full sunlight, no problem.  But if you are using the (AWESOME) Accuweather iPad app, which has a black background, it can be difficult.

Wifi (8)

I have read some forums online where people are complaining about the Wifi connectivity with the device.  It will start off at five bars, and then shrink down to 1 bar, then go back up again.  I have to admit, I was experiencing this at my mother-in-laws house, and her router is using WEP, Verizon FiOS Actiontec regular old wireless router with both B and G bands.  At home, I have two Apple WAPs running 802.11G and 802.11N.  The iPad communicates flawlessly all over the house, yard, and porches with a full five bars on either connection point.  Maybe this is a firmware issue (because apparently lots of people are experiencing problems), however, I..  am not, at home.

Now, as you'd expect let's address some of the downfalls of the device:

The Downfalls
No flash -- well, be that as it may. It is what it is, and I am sure, the longer the iPhone stays out, and the bigger the iPad gets, the end of flash may draw near.
No removable battery -- this was the big bitch about the iPhone when it first came out and it seems that people have largely gotten over this. You know, by plugging the darn thing in.  This isn't a phone, you don't need to trade out the batteries like you should need to with a phone.
No remove-able storage -- I don't know how this is that big of a deal. The iPad comes in 16 gig, 32 gig, and 64 gig of storage. If that's not enough space for you, then you might want to evaluate a cloud based storage solution of some type.
No Usb ports -- well clearly this is not a full featured computer. For the most of the audience and consumers out there, this could be a everyday useful computer. I think it's perfect for kids at school, for doctors, for lawyers, for my parents, for my brothers. Those of you that need to plug in your wacom tablet, or your thirty USB based devices, this isn't it. Apple clearly wanted the device to be stable and not susceptible tom third party drivers for USB devices and such.
Printing -- you can't print from it. Not natively, not yet. While it is certainly possible to set up a printer on the network and print wirelessly, heck I do it at my house, the iPad does notmhave the built in ability to print. Which kinda stinks. But, just like the iPhone, where someone wrote an app to be able to do just that, I imagine, given time, the iPad will be able to do the same thing.
No Camera -- The iPad has no camera, forward or back.  I don't think a back mounted iPad (like the iPhone) would be of much use, I mean, it would just be weird trying to take a picture with a device that big.  A forward facing one, so you could use it for video conferencing with iChat?  That would be AWESOME, and I wished they would have built it in, but alas, they didn't, so hopefully they do in a future version.
No Microphone -- It has a built in mic, I think the headphones are better.  I took my iPhone headphones (the ones with the mic built in to the lanyard) fired up the Skype app and made a call.  It worked perfectly.

I am sure there are more, if you feel so inclined to tell me what you think the downfalls of the device are in the comments, I'll be glad to update the post, and/or give my opinion.

In closing

I clearly believe that there is no way that you'll fully understand this device unless you use it.  There is clearly a market, and tons of potential for this device, and we'll see where it goes.

What do I recommend?

I recommend you get the biggest one.  64G.  You'll understand why once you have it, because you'll want to be consuming media on it, you'll want to be watching movies, have your apps, have your documents, have your stuff.  Especially those of you that are like me and travel a lot and want a device to use on the plane.  Get the biggest one.  The 3G vs. Wifi is a debate only you can answer.  Personally, I have a Mifi, so I have no need to have the 3G version, I use the Mifi as a Wireless access point, connect my iPad to it, and away I go.  Simple.

Overall Grade: 8

It's an excellent device, try before you buy, but you won't think you need one, until you use one.  Then, you won't know how you did without it.  It's the perfect couch device, bedside table device, and going to the bathroom device.

Friday, April 2

Note To Thieves: People You Rob Use Craigslist Too

A Story about a man who, much to his dismay, had his home broken into and several items stolen.  However, he was smart enough to think to look for his items on Craiglist, and found his computer.

Still looking for other items, but since he reported the man who he got his computer back from, I have a feeling that the rest will turn up soon as well.

At least the thieves didn't delete his harddrive.

Note To Thieves: People You Rob Use Craigslist Too - Houston Music - Rocks Off.

Google services on the iPad and tablet computers

Google today rolled out their new version of the Gmail web interface specifically for the iPad.  Looks pretty nice.


Nice side by side pane view, similar to the native iPad Mail app.


Read the post below:




Official Google Mobile Blog: Google services on the iPad and tablet computers.

AT&T has some shady billingness going on.

At my company we use a service named "Webex" to do remote presentations and conferencing.  So here you are, you join a Webex session on your iPhone.   See Cisco (the makers of Webex) made an iPhone app where you can view presentations and participate in an online presentation right on the Phone!  It's great!    You sign into a webex, and the webex app says "Hey, you want me to dial the conf number for you", Why sure!  You can dial the number, and then I can pop back over to the webex app!? Phenomenal.  Great technology, great to see it.
So it kicks you over to the Call screen where it proceeds to dial 8664693239 ,,<confcode>,,<attendee id>#  (commas are pauses in the Phone world)

The way that Cisco sends the number to the call app, inserts that space after the actual phone number, which makes the phone app format the aforementioned number as an international number.
So, the iPhone appears to dial the number as +8664693239.  You know what +86 is as a country code?  China.
So, that's not the problem, not the problem at all.  The iPhone dials the number correctly (even though it shows up incorrectly), you connect to the 866 toll free call and everything!
The problem is on AT&T's billing side, somewhere, where it receives the number under a different format, and the number on your bill shows up as 866-469-3239.
Know what it's billed as?  A call to +86.  Yup. China.

So, my most recent bill from AT&T showed a 200+ dollar call to China.
My question is, how common is this?  Is AT&T charging people like this for calls that aren't processed in the billing system correctly?  AT&T is just expecting people to pay the bill?  My bill was almost 500 dollars this month because of 4 or 5 calls like this.  (I do a lot of presentations.)
AT&T, fix your billing system.  Something is screwed up.

Thursday, April 1

Found footage: the first guy in the iPad line at 5th Avenue Apple Store


Someone should tell this guy that he could have ordered it and had it delivered straight to his house.  Just a thought.


httpv://www.youtube.com/watch?v=B4B3IjHP05o




Found footage: the first guy in the iPad line at 5th Avenue Apple Store.

OAuth access to IMAP/SMTP in Gmail

...another entry from Google on the "Openness" aspect of their solution.  They have implemented OAuth IMAP/SMTP for Gmail.  So instead of you having to pass a 3rd party website your username and password credentials, you can use OAuth to be able to authorize that 3rd party website to access the information in Gmail.  Nice Approach there I think.

Google Code Blog: OAuth access to IMAP/SMTP in Gmail.

Yale Daily News - ITS delays switch to Gmail

Many universities and businesses have switched to Gmail as an email processing, cloud based platform.  I like a lot of the features of Gmail, ease of access, simple interface.  But I'm not a fan of several things as well.

Yale was thinking about moving to Google Apps as a platform, and said that "everyone was so caught up in wondering how we can do it, and forgot to ask should we do it."

Interesting article.

Yale Daily News - ITS delays switch to Gmail.

Apples iPad: The Mothership Prepares for Launch

Stephen Fry comes to us from time.com regaling us of his tale of his recent visit to 1 Infinite Loop.  Stephen Fry is a great writer and tells a story about how he met and interviewed Phil Schiller, Eddy Cue, and Steve Jobs.  Then he tells us about his instant love with the iPad.

Many articles have been published about the iPad this morning that came up in my RSS reader.  I read Walt Mossberg's, I read Andy Ihnatko's.  Stephen Fry's didn't just tell a tale about the iPad, it told a tale about the design of it, the use of it, and the love affair he now has with it.

I have pre-ordered one, as I unabashedly like Apple products and clearly see a potential for this device (and as of this morning it has left China).  I'll be posting my own review of the device here for family, friends, and blog readers alike.

I have several family members waiting patiently to see what I think of it before they buy.

Check it out at the link below:

Apples iPad: The Mothership Prepares for Launch - TIME.

Wednesday, March 31

Fiber Economics — Dave Troy

Fiber Economics — Dave Troy: Fueled By Randomness.

Darn good article by Dave Troy, a business man out of Baltimore, MD.  He explains Verizon and Comcast, the two biggest players in Internet access (in terms of "innovation"), and how Google's Fiber ambitions play into that.

Thanks @awilliams for the pointer to that one.

The Geek/Nerd/Dork/Dweeb Venn Diagram




The Geek/Nerd/Dork/Dweeb Venn Diagram - Geekologie.

Tuesday, March 30

Seton Hill University to give all students an iPad

And so it begins... Seton Hill University to give all students an iPad.

This article from The Unofficial Apple Weblog, buried in my News Reader today, points out that the Seton Hill University up in Pennsylvania, starting Fall 2010 is going to be issuing an iPad to every man, woman, and child who enrolls into school.

So for those of you that read my blog and want to enroll in college at a "Catholic Liberal Arts University", here's your chance to get a free iPad.

How to specify a Snort Variable from the command line

So, my last post talked about how the -h command line tag in Snort doesn't actually specify HOME_NET like many people have thought.  I have received about 30 emails asking "well then how do I do this! OMG!"

Fear not, there is a way to do this.  So let's use the same testing criteria I did in my last post, same rule, same set up.

  • var HOME_NET any

  • var EXTERNAL_NET any


Are specified in my snort.conf file

Run Snort against the pcap and I get:

[**] [1:10000001:0] Alert! [**]

[Priority: 0]

03/29-16:57:47.361016 192.168.1.120:51968 -> 72.14.204.147:80

TCP TTL:64 TOS:0x0 ID:13360 IpLen:20 DgmLen:993 DF

***AP*** Seq: 0xC03BC58E  Ack: 0x8B9BF8F5  Win: 0x822B  TcpLen: 32

TCP Options (3) => NOP NOP TS: 63957188 2272801581

With the following rule:


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"Alert!"; content:"/content"; sid:10000001;)

Same as before, so now let's use the -S command line tag.  The -S tag, as stated in snort --help is:


-S <n=v>   Set rules file variable n equal to value v

So let's do that.


Command line is now:


snort -c snort.conf -l . -r snort.log.1269894717 -k none -S HOME_NET=192.168.0.0/16

Run Snort against the pcap again:




[**] [1:10000001:0] Alert! [**]

[Priority: 0]

03/29-16:57:47.361016 192.168.1.120:51968 -> 72.14.204.147:80

TCP TTL:64 TOS:0x0 ID:13360 IpLen:20 DgmLen:993 DF

***AP*** Seq: 0xC03BC58E  Ack: 0x8B9BF8F5  Win: 0x822B  TcpLen: 32

TCP Options (3) => NOP NOP TS: 63957188 2272801581

Alert.  Same as before, okay, so now for the real test..



Reverse the direction of the HOME_NET:


snort -c snort.conf -l . -r snort.log.1269894717 -k none -S HOME_NET=72.14.0.0/16

No alert.


So, for those of you (100's of you?) that have been using -h to specify your HOME_NET on your command line, read my post yesterday and found out that it doesn't work that way...


Try -S, it'll do what you want.

Monday, March 29

Snort -h doesn't do what you think it does.

I've seen a lot of traffic recently of people trying to use "-h" on the Snort command line to specify the variable $HOME_NET, and it's generated a lot of confusion as of late, so I thought I better write about it.

If you look in the manual, every time -h is used, it's used with a network range, or an individual IP, and it's also used with -l, also only used with -vde (otherwise sniffer mode). It's not ever made clear exactly what -h actually does. Similarly if you type:

snort --help

on the command line the -h tag says:
-h Home network =

So, one might think that by doing a -h on the command line, it specifies the HOME_NET variable found in the snort.conf on the command line. Well, as you probably have guessed by now, this is not the case.

So here's the truth: -h actually has nothing to do with the HOME_NET as specified in the snort.conf file.

As we know,
var HOME_NET any

Will specify which direction traffic should be examined in terms of the rules within the detection engine.
var HOME_NET 192.168.0.0/16

In the snort.conf file is then filled in in all the rules that call $HOME_NET. This is not -h.

So, for example, the following rule:

alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"Alert!"; content:"/content"; sid:10000001;)

In my Snort.conf

  • var HOME_NET any

  • var EXTERNAL_NET any



    I get the following alert:

    [**] [1:10000001:0] Alert! [**]

    [Priority: 0]

    03/29-16:57:47.361016 192.168.1.120:51968 -> 72.14.204.147:80

    TCP TTL:64 TOS:0x0 ID:13360 IpLen:20 DgmLen:993 DF

    ***AP*** Seq: 0xC03BC58E Ack: 0x8B9BF8F5 Win: 0x822B TcpLen: 32

    TCP Options (3) => NOP NOP TS: 63957188 2272801581

    If I define HOME_NET in the snort.conf



    • var HOME_NET 192.168.0.0/16

    • var EXTERNAL_NET any



    I still get the alert, okay.



    [**] [1:10000001:0] Alert! [**]

    [Priority: 0]

    03/29-16:57:47.361016 192.168.1.120:51968 -> 72.14.204.147:80

    TCP TTL:64 TOS:0x0 ID:13360 IpLen:20 DgmLen:993 DF

    ***AP*** Seq: 0xC03BC58E Ack: 0x8B9BF8F5 Win: 0x822B TcpLen: 32

    TCP Options (3) => NOP NOP TS: 63957188 2272801581

    If I define HOME_NET in the snort.conf as such:




    • var HOME_NET 72.14.0.0/16

    • var EXTERNAL_NET any



    I don't get an alert, exactly as planned, now... I conduct the same test. Same rule.



    • var HOME_NET any

    • var EXTERNAL_NET any



    In my snort.conf, but this time I am going to specify 192.168.0.0/16 in the -h command line tag.



    [**] [1:10000001:0] Alert! [**]

    [Priority: 0]

    03/29-16:57:47.361016 192.168.1.120:51968 -> 72.14.204.147:80

    TCP TTL:64 TOS:0x0 ID:13360 IpLen:20 DgmLen:993 DF

    ***AP*** Seq: 0xC03BC58E Ack: 0x8B9BF8F5 Win: 0x822B TcpLen: 32

    TCP Options (3) => NOP NOP TS: 63957188 2272801581

    Exactly as before.


    Now if I run -h with 72.14.0.0/16 at the command line I get the following alert



    [**] [1:10000001:0] Alert! [**]

    [Priority: 0]

    03/29-16:57:47.361016 192.168.1.120:51968 -> 72.14.204.147:80

    TCP TTL:64 TOS:0x0 ID:13360 IpLen:20 DgmLen:993 DF

    ***AP*** Seq: 0xC03BC58E Ack: 0x8B9BF8F5 Win: 0x822B TcpLen: 32

    TCP Options (3) => NOP NOP TS: 63957188 2272801581

    Where I should not have. So, no, it doesn't actually specify HOME_NET.


    So if you are trying to specify HOME_NET, you need to do it in the snort.conf file.


    -h, in fact, and after checking with development team and reading the code myself, -h corresponds to how packets are logged. (When using the old "log per directory" mode) However, this isn't very clear in the documentation, or in the --help file. So I've asked the developers to make this a bit more clear what -h does in the documentation as well as the code. It's pretty much only useful for Sniffer mode, not much for IDS mode.

    Security Update 2010-002 / Mac OS X v10.6.3

    About the security content of Security Update 2010-002 / Mac OS X v10.6.3.

    Apple just posted 10.6.3 which included a ton of security updates in the following pieces of software, so go update:

    • AppKit

    • Application Firewall

    • AFP Server

    • Apache

    • ClamAV

    • CoreAudio

    • CoreMedia

    • CoreTypes

    • CUPS

    • curl

    • Cyrus IMAP

    • Cyrus SASL

    • DesktopServices

    • Disk Images

    • Directory Services

    • Dovecot

    • Event Monitor

    • FreeRADIUS

    • FTP Server

    • iChat Server

    • ImageIO

    • Image RAW

    • Libsystem

    • Mail

    • Mailman

    • MySQL

    • OS Services

    • Password Services

    • perl

    • PHP

    • Podcast Producer

    • Preferences

    • PS Normalizer

    • QuickTime

    • Ruby

    • Server Admin

    • SMB

    • Tomcat

    • unzip

    • vim

    • Wiki Server

    • X11

    • xar



    Saturday, March 27

    Day Two: No One Even Attempts Hacking Chrome at Pwn2Own Competition

    Day Two: No One Even Attempts Hacking Chrome at Pwn2Own Competition - Google Chrome - Lifehacker.

    Found this interesting.  I didn't make it to CanSecWest this year, but several of my friends did go to this event/competition.  While I did see that every other major browser was cracked on day one, (IE8, Firefox, and Safari) Chrome didn't even get  tried, apparently.

    While Chrome does use the Webkit (safari) engine, Chrome starts each browser tab in a separate process which is in a 'sandbox'.

    On the usability side, I've been using Chrome on the Mac since they opened up the dev channel for it, and I really like it.

    Friday, March 26

    and then, there was rust

    Got a call today from the shop that is tearing down the Mustang for the rebuild, asking me to stop by if I could and take a look, it seems that the rust on the front end was a little worst than they expected.  I knew there was rust in there, but didn't know just how much...

    So basically, we are going to replace from the driver's seat on forward.  Frame, sidewalls, everything.  Of course, I am getting stuck with the bill of people not doing it correctly to begin with, but, I suppose, that's the downfall of having a 42 year old car.

    To look at the whole gallery of pictures I took today... Click here.

    Stay tuned.

    Thursday, March 25

    Detecting suspicious account activity on your Gmail

    Official Gmail Blog: Detecting suspicious account activity.

    I found this article interesting.  Google has implemented a kind of security feature in Gmail.  What it looks like, is now Google keeps track of the IPs that you log into your Gmail account from (which they  have for awhile now, check this out from back in 2008) and let's you know of any very strange deviations in pattern.

    The example they provide is this:




    Google knows, in this example, that this person normally signs in from California in the USA, then suddenly in the middle of all the normal accesses, there is a login in Poland.  Which is strange for the user, and you get this popup when you log into your gmail:




    I think this is head and shoulders above what any of the other competitors are doing with their free online email solutions, and hopefully this will make strides to curbing some spam and illegal access of accounts.

    No doubt that this had something to do with the illegal access of accounts from China during the whole "Google/Intel/insertothercompanieshere debacle".  Glad to see Google doing things like this.

    Wednesday, March 24

    Mustang Status...

    Had the car taken to the shop today.  I've removed most of the engine, and am to the point where I can't do anything else with the tools that I have available to me.  I don't know how to weld yet (I am learning, on the "job" training as it were), excuses, excuses, so anyway, to the shop the car went.



    I guess I didn't get all the coolant out of the system when I was taking that portion apart.



    This picture shows how much (well it kinda shows) I've stripped out of the car already.



    I didn't take a picture with the hood up.  Should have...


    Of course I'll post pictures along it's progress.


    What I'm putting into the car:




    • 351W motor, custom built crate engine (400-450 hp) (on order)

    • New front suspension

    • New radiator and coolant system

    • New 8in rear

    • New spindles (4 lug to 5 lug)

    • New Rims + Tires (obviously)

    • New T-5 Transmission

    Tuesday, March 23

    Some notes on “making Snort go fast under Linux”

    Work Together For The Benefit Of All ManKind… » Some notes on “making Snort go fast under Linux”.

    Read the above link if you are interested in Snort.  Author Edward FjellskÃ¥l does a nice job of explaining some really tricky details of Optimizing Snort.  Including little tweaks about how to optimize the kernel.

    Take a look, nice post Edward.

    iPhone universal inbox?

    Julio Rodriguez, a fellow Apple user wrote Steve Jobs an email thanking Apple for their great customer service, and proclaiming his "life-long" customer status.

    However, the interesting part for me came in the second paragraph where Julio ask Mr. Jobs:
    I just have one question for you; will iPhone ever have a universal mailbox just like Mail has on my Mac?  It would be so much easier and efficient

    Steve Jobs answered back in his typically terse answer form:
    Yep.

    Sent from my iPad

    For a screenshot of the email (including headers), check it out here.

    Reader Question: Why is your Blog named Finshake?

    Why is your Blog named Finshake? | Finshake.

    I received a request about why my Blog is named Finshake.  Read the above link for the reason.

    Note:  There is a search field on the right hand side of the blog.  Check it out.

    Indian military to weaponize world's hottest chili

    My Way News - Indian military to weaponize world's hottest chili.

    Read the above article.  This is a great use for food as a weapon.  Hurt?  Yes.  Lethal?  Probably not.  Immobilizing?  Heck yes.

    Sunday, March 21

    Inbox Zero is fail? Wrong.

    Alyssa Gregory, blogger at sitepoint, clearly doesn't get it.

    It = Inbox Zero, she says it can't be done.:

    Merlin Mann, the de-facto creator of Inbox Zero offered a nice rebuttal, basically saying, "you clearly don't get it."

    Then, Alyssa writes another post, basically saying "Uh, yeah, it still won't work."

    Of course, this isn't my fight, it's Merlin's, however, as a devout follower of Inbox Zero, relying on it constantly as my day in and day out way of staying sane, I offered this rebuttal, which are basically my feelings about email.  (Which I doubt she'll post, but whatever.)  Here it is.

    Merlin, you are still the man.
    I believe you are still missing the point. The point in Inbox Zero is to become a “decider” and a “do-er” instead of an email processor. You receive email, you make a decision about it’s purpose, either A) Respond right now if it takes less than 2 minutes, B) If it takes longer than two minutes, Put it into a folder to reply later, C) Make a TODO to DO the thing that is in the email, and save the email, or D) Delete it.

    Is the email that is sitting in my inbox right now, that I am staring at, actionable? Do I need to physically do something with the information that is front of me? Yes? Make to-do todo it, then DO it. No? Either file it, or delete it.
    Follow this process until you hit ZERO emails in your inbox.
    Then CLOSE your email. CLOSE it. And go DO the things that you made todo’s to, do.
    Even if those todo’s involve answering the email that you put into a folder under “B", you need to DO them. Only check email about twice or three times a day, and you will be much more productive.
    The point in Inbox zero is to process to ZERO, then CLOSE the inbox for the time being and GO CREATE. GO CREATE YOUR WORK BEING DONE.

    Then, later, open it back up.

    Thursday, March 18

    Cybersecurity Bill Trims Presidents Power

    Cybersecurity Bill Trims Presidents Power -- Cybersecurity -- InformationWeek.

    "The Senate Wednesday re-introduced a cybersecurity bill it considered last year, minus a provision that would have allowed the president to shut down the Internet in the event of a major cyber attack.

    The Cybersecurity Act, S. 773, co-sponsored by Senators Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine), is aimed at protecting critical U.S. network infrastructure against cybersecurity threats by fostering collaboration between the federal government and the private sectors that maintain that infrastructure."


    Check this out, interesting.



    Wednesday, March 17

    Hey Microsoft, Don't F*ck Up Windows Phone 7

    Hey Microsoft, Don't F*ck Up Windows Phone 7 - Windows phone 7 - Gizmodo.

    A funny post over on Gizmodo detailing how, apparently, Microsoft has put out a couple changes to Windows Phone Mobile 7. (What is it with Microsoft and the number 7 all of the sudden?  Unified messaging?)

    Apparently Microsoft is going to do two things wrong..

    1. No multitasking

    2. No Copy and Paste


    As for Multitasking, the iPhone doesn't have it "ish".  (Mail and various other "Apple only" apps can run in the background).   However, the rumor is that iPhone 4.0 will have multitasking.  So Microsoft, instead of trying to get ahead of the curve, you are going to be at least 3 years behind in copying Apple?  Seriously?  Way to step up the innovation there guys.

    Copy and Paste..  Well, the iPhone didn't have it until iPhone 3.0, and a shitton of people bought iPhones too.  Not that many will buy Windows Mobile 7 devices, but still...

    How can you not put copy and paste in it, when (as the author of the Gizmodo article says) the phone you are trying to compete with (the iPhone) already has it!?

    Steller Microsoft, way to win.  Whatever, I wouldn't buy it anyway.

    Tuesday, March 16

    Random Picture from the Internet



    Don't know where the above picture came from (I received it via email), but.. Wow. That's a lot of Cash. This was probably a drug seizure or something like that.

    VRT: The New Disclosure Debate and the Evil Mr. Moore

    VRT: The New Disclosure Debate and the Evil Mr. Moore.

    I am not trying to get into the business of reblogging Sourcefire VRT's blog entries, but I blog things that I think are interesting, or that I think my readers will find interesting and hopefully debate.  I think this is yet, ANOTHER insanely great article by Mr. Matt Olney.  Please click the link above and read it!

    Wednesday, March 10

    Funny ‘Hacker’ Story

    Funny ‘Hacker’ Story.

    A funny story about a hacker named "bitchchecker", proving his mad skills by attacking someone on the Internet.

    Using the IP: 127.0.0.1

    Watch out for this guy.

    Tuesday, March 9

    VRT: APT: Should your panties be in a bunch, and how do you un-bunch them?

    VRT: APT: Should your panties be in a bunch, and how do you un-bunch them?.

    I don't know how to say it anymore than this:

    Matt Olney wrote a damn, a DAMN good post about APT on the VRT blog, and if you read my blog, and you don't go over to the VRT blog and read that post..  Heck I don't care if you don't read another post by the VRT that they have written in the past (although, you SHOULD!  They put a LOT of time into their posts!) you should read this one.

    Matt, whom I play Xbox with nearly every night, talk to on a regular basis, and consider to be my friend..  I just wanted to let you know, seriously...

    Damn fine job sir.

    10 reasons to avoid talking on the phone

    10 reasons to avoid talking on the phone - The Oatmeal.

    This is an awesome comic, pretty much sums up talking on the phone correctly.

    Click through, it's awesome.

    Sunday, March 7

    Sourcefire VRT Labs: MS to SID mappings

    Sourcefire VRT Labs.

    For those of you that are using Sourcefire VRT rules to protect your network with your Snort IDS/IPS installation, (as you should!).  There are mappings from MS vulnerability number to SID number, in the past, you either had to be a Sourcefire customer (we make this super easy in the Policy Editor GUI) or you had to be very patient and grep your way through the rules.

    However, VRT put these mappings in a super easy to use interface at the link above.  Check it out.

    Update:

    Nigel corrected me, these mappings have always been on Snort.org, VRT just moved the hosting.  Duh.

    Usability participants needed for Outlook:Mac

    go ahead, mac my day : usability participants needed for Outlook:Mac study in March.

    Blog entry from one of the developers that works on the Office:Mac suite at Redmond, asking for usability testing volunteers to test Outlook for the Mac.  (To be released this year IIRC.

    If you are in or near Mountain View, California, and you wish to participate, you need to be eligible by:



    • use a Mac for work purposes

    • connect your Mac to an Exchange server

    • use mail and calendar on your Exchange server several times per week


    Tuesday, March 2

    Offset, Depth, Distance, and Within

    Without going off the deep-end here and discussing every single Snort rule keyword, I just wanted to touch on a few modifiers that people sometimes misunderstand.  They aren't difficult, and hopefully after this explanation and a few examples, I can clear some of the air around these five modifiers.

    The five modifiers that I am talking about are
    1. Offset
    2. Depth
    3. Distance
    4. Within
    5. nocase
    These five modifiers are not keywords of themselves, but rather they apply as modifiers to another keyword.  That keyword is "content". The content keyword is one of the easiest pieces of the Snort rules language as all it does is look for a particular string.  So for instance if I wanted to look for the word "joel" within a packet.  A simple:
    content:"joel";
    Would allow me to do that.  The interesting part comes into play when you want to specify where inside of a particular packet you want the string "joel" to be looked for.  If you are running just a plain content match with a simple string, and not specifying where in the packet to look for that string, your Snort instance will receive a ton of alerts, and then you, the analyst, are stuck looking through all of those alerts to try and pick out the alert that is needed.  While a content match for "joel" might be pretty unique (that might not occur a lot on your network), but it will occur a bunch on mine.
    1. Offset
    Offset in the Snort manual is defined as:
    The offset keyword allows the rule writer to specify where to start searching for a pattern within a packet.
    So, given a certain packet, Offset tells the content match it's modifying where to start looking, given an offset from the beginning of the data payload of the packet.


    In the above example, if I wanted to find the word "GET" (highlighted).  I would write:
    content:"GET"; offset:0;
    Meaning, start at the beginning of the data payload of the packet (offset:0;) and find the word GET.  Now, in this example, the word "GET" is at the very beginning of the packet making the search very easy.  However, if I wanted to match on the word "downloads" that is found a bit later in the above screenshot, I could still start my content match at the beginning of the payload (offset:0;) but the content match would be more accurate and less computationally expensive if I were to make the offset more accurate.
    content:"downloads"; offset:13;
    Would tell Snort to start looking for the word "downloads" at the 13th byte in the data portion of the packet.  So, what if I chained these two together?
    content:"GET"; offset:0; content:"downloads"; offset:13;
    In other words, start looking for "GET" at the beginning of the data payload of the packet, and start looking for the word "downloads" at the 13th byte of the packet.  Now, why would I do this?   This example tells Snort, after the first content match, go back to the beginning of the packet, move over 13 bytes and then start looking again for a second content match.  There are several things wrong with this example, that I did on purpose. First off, if you are at the first content match in a Snort rule, or a content match you want to start at the beginning of the packet, you don't have to write "offset:0;".  Any content match that doesn't have a modifier after it automatically starts at the beginning of the data payload portion of the packet by default.  Offset:0; is implied for this type of match. Second, and a:
    <Common Misconception>
    Some tend to think that if they stack two contents next to each other, that Snort will look for those contents in the order they are provided.  For example, if I were to write:
    content:"GET"; content:"downloads";
    Some people generally think that in the above example, that the word "downloads" will have to occur after the word "GET" in the packet.  This is Wrong.  If no modifiers to contents are specified than the order of the matches within a given packet (or stream for that matter) doesn't matter.  "downloads" could be first, then "GET", and the rule will still fire. So given the above exampled screenshot, if I wanted to force the word "downloads" to occur after the word "GET".  I could use a distance modifier.  Which I will touch on a bit later.

     2. Depth

    Depth in the Snort manual is defined as:
    The depth keyword allows the rule writer to specify how far into a packet Snort should search for the specified pattern from a given offset.
    So, given the above example again:


    I want to match on "GET" but ONLY if it occurs as the beginning of the packet.  Notice when I was describing offset above I said that offset tells Snort where to start looking.  Not where to stop.  If I don't tell Snort where to stop using a content match, Snort will search the entire packet.  If I want to tell Snort where to stop looking for a content match, I have to use something like depth. So for the above example, if I want to match on "GET" but only at the beginning of the data portion of the payload:
    content:"GET"; depth:3;
    Notice some things.
    1. I didn't start with Offset:0;.  Remember, if I am beginning a content search at the beginning of the data payload of the packet, offset:0; is implied.
    2. Depth counts in positive integers.  While offset starts counting at "0" bytes, depth counts in positive integers, "GET" is three bytes long, so my depth is "3".
    3. Depth starts counting from the offset point.  Not from the beginning of the packet.  While, in the above "GET" example, the offset point IS the beginning of the packet, don't get confused by this.
    4. By telling Snort to only look in the first three bytes, if Snort is analyzing millions of 1500 byte packets, only matching on the first three bytes is a significant CPU saver.
    5. BTW -- Don't do the above example, as you will essentially match on every single GET request on your network, turning your IDS into a brick.  This is just an example.  Besides this is what http_method is for, which i'll cover in a later blog post.
    3. Distance

    Distance is defined in the Snort manual as:
    The distance keyword allows the rule writer to specify how far into a packet Snort should ignore before starting to search for the specified pattern relative to the end of the previous pattern match.
    (Emphasis added by me) Distance says to us, "okay, relative to the end of the previous content match, when should I start searching for the second content match?".  So bringing back my previous example:
    content:"GET"; depth:3; content:"downloads";
    If I were to do this:
    content:"GET"; depth:3; content:"downloads"; distance:0;
    That by itself would force the content match "downloads" to occur after the "GET" content match.  Doesn't matter where (distance:0;), just as long as the pattern match is AFTER the first one.  However, if I wanted to be more specific and more specifically match on the screenshot that I provided above:
    content:"GET"; depth:3; content:"downloads"; distance:10;
    This says to the Snort engine, "match on GET, in the first 3 bytes of the data payload of the packet, then move 10 bytes relative to the end of GET and start looking for "downloads"". Notice I said start looking.  Not limited to.  Kinda like putting an offset without a depth there... so we have within.

    4. Within

    Within in described in the Snort Manual as:
    The within keyword is a content modifier that makes sure that at most N bytes are between pattern matches using the content keyword.
    Within allows you to specify a range between content matches, it also allows you to tell a second (relative) content match where to stop.


    So, using the content matches we've built already:
    content:"GET"; depth:3; content:"downloads"; distance:10;
    The only problem here is "downloads" is being searched for in the entire packet, except for the first 13 bytes, essentially.  How can we make downloads only be searched for at that specific spot?  Within.
    content:"GET"; depth:3; content:"downloads"; distance:10; within:9;
    "Match on GET, in the first 3 bytes of the data payload of the packet, then move 10 bytes relative to the end of GET and start looking for "downloads", however, "downloads" must occur wholly within the next 9 bytes." Could I say "within:10;"? Yes, I could, and then downloads could be in it's present position, or if there was another byte in front of the actual content match. Also notice that within, like depth, also works in positive integers (distance starts counting at "1")

    5. nocase

    Finally, let me discuss "nocase";.  nocase, or "No case" simply means, for the content match specified, do not pay attention to case sensitivity.  "nocase" doesn't make the Snort engine work any harder in the grand scheme of things, and it's very handy for being able to make sure your rules do not get bypassed. Example? Let's say I wanted to match the above screenshot, no matter what.  Well, if I was an attacker, and I came to your webserver trying to access your "downloads" directory, as the rule is written, I could pass my "GET" string as lowercase "get" or mixed case "GeT", and depending upon your webserver, it might accept it, and I have effectively bypassed your rule. The easiest thing to do with this type of evasion is to use a nocase; statement.
    content:"GET"; depth:3; nocase; content:"downloads"; distance:10; within:9; nocase;
    So, I want you to notice a few things:
    1. We went from very generic to very specific, your use case will vary.
    2. Modifiers to contents come AFTER the content match.  Not before, they won't work, don't try it.
    3. Offset goes with Depth, distance goes with within.  Don't mix them.
    Hopefully this helped someone clear up any confusion surrounding these keywords.  For further information, please refer to the Snort Users manual. http://www.snort.org/start/documentation
    --

    SNORT and Sourcefire are registered trademarks of Sourcefire, Inc.

    Apple sues HTC for alleged infringement of 20 iPhone patents

    AppleInsider | Apple sues HTC for alleged infringement of 20 iPhone patents.

    ...And so it begins...  I was beginning to wonder when this was going to happen, of course, HTC, the makers of many phones, the most notable being the Google Nexus One, and the G1.

    We'll have to wait and see how this one shakes out.

    Monday, March 1

    Plugins add grunt to Google’s Quick Search Box

    Plugins add grunt to Google’s Quick Search Box « Hawk Wings.

    If you are a user of Google's Quick Search Box (similar to QuickSilver), and is in active development, you can download and use these series of scripts in order to interact with the rest of your OS.  (Things like sending a file through email in Mail.app).

    Or, you can just stick with QuickSilver.  It does all these things already.

    Friday, February 26

    Hogging the Snort Host Attribute Table

    Hogger is a new Snort supportive tool written in Perl.  It takes Nmap output and makes a Host Attribute Table.

    via Security - The Global Perspective: Hogging the Snort Host Attribute Table.

    I talked about the above here.

    Monday, February 22

    Writing Snort Rules Correctly

    Let me start off by saying I'm not bashing the writer of this article, and I'm trying not to be super critical.  I don't want to discourage this person from writing articles about Snort rules.  It's great when people in the Snort community step up and explain some simple things out there.  There are mistakes, it comes with the territory.  If you choose to be one of the people that tries to write Snort rules, you also choose to be someone who wants to learn how to do it better.  That's why I write this blog post, not to bash the writer, but to teach.

    I noticed this post today over at the "Tao of Signature Writing" blog, and to be honest I glanced over most of it figuring it was a rehash of things I've already read or things that have already been written from countless people about "Here's how you write Snort rules!".  I scrolled down quickly skimming, not reading at all really, and noticed this part:
    Now, let us look at the second question: “We have “aol” as the id and Import method name. Should we use “aol” along with “Import”?”. Just because we narrowed down to “clsid:” followed by CLSID number, does not mean that we have to narrow down in this case too. Just like how the Shellcode will change, the attackers might change the ID too, to just find out if they could evade the IDS/IPS. Why give them a chance? Hence, we should broaden our search to just the import method: content:”.Import(“. The reason why we have “.” and “(” around the key “Import” is to narrow the chances of triggering the signature on some term “Import” and to concentrate on the vulnerable method.

    This post is about ActiveX and CLSID detection with a Snort rule, trying to detect an AOL 9.5 ActiveX 0day.  Okay, fair enough, so the above paragraph is trying to find the Import command to call the javascript.  So I kept reading.

    Then I got to this part:
    In here, I would like to position the CLSID before the method. This would help me trigger the signature specific to “AOL 9.5 ActiveX 0day Exploit (heap spray)“. I can do this ordering by using “Offset”. We cannot set the “Depth” in this case, since the position of CLSID or Method in a packet will change according to the packet size or the way in which it is sent. Hence, the content of final signature would look something like this:

    content:”clsid:A105BD70-BF56-4D10-BC91-41C88321F47C”; nocase;content:”.Import(“; nocase; Offset:0;



    The writer is correct in a couple things.
    • First, they say they want to position the CLSID before the method, so they want to do with using offset.
    • Second, they say they cannot set a "depth" because the position and method in the packet will change according to the packet size, which is partially correct.

    However, the problem with this above signature is that the offset is placed after the second content match.

    So here's what would happen with the above signature so far.  The CLSID content match is the longest, so it would be fed into the fast pattern matcher.  If the fast pattern matcher came across a packet that matched the CLSID that is specified in the rule, <leaves stuff out>, then the packet would then be run through the detection engine (rule) for detection.  Contrary to popular belief, unless an offset/depth/distance/within modifier is specified, there is no order for the packet to match.  So if I were to write the above as this:





    content:”clsid:A105BD70-BF56-4D10-BC91-41C88321F47C”; nocase;content:”.Import(“;nocase;



    Snort doesn't care which order the content matches are in.  As long as both the contents are in the packet, then the rule will fire.  So putting a content:".Import("; nocase; offset:0; does absolutely nothing.  You can kind of think of offset:0; being implied, but if you don't have any relative content matches, then it really doesn't matter unless you are trying to be specific to a position match.  However, as the author already stated, you can't add a depth statement to the rule, so it plain, just doesn't matter.  I see this kind of thing all the time, so I figured common mistake.  So I kept on reading:
    Now, let us look into the direction of traffic. Client-side exploits generally flow from server to client: “flow:to_client,established;“.

    The author explains that "Client-side exploits generally flow from server to client".  Okay, correct in this instance, but not always, so let me explain:

    Flow has four direction operators you can specify:




    • to_server
    • from_server
    • to_client
    • from_client


    What happens is when I hear from people is that they think "server" as that 2U thing back in the server room (hence the name), and client being "you".  But that's not how Snort thinks about it.  Snort thinks about client server in the "who initiated the conversation" term.  So, at the beginning of a TCP conversation there is a 3-way handshake.  SYN, SYN-ACK, ACK.
    1. CLIENT ->  SYN -> SERVER
    2. CLIENT <- SYN, ACK <- SERVER
    3. CLIENT -> ACK -> SERVER

    The client is who initiated the conversation, the server is who is responding. So, in this case, since we are attempting to catch a web browser accessing a webpage and downloading a webpage which contains this CLSID, the flow would be to_client.  (Or from_server) Correct.  However, what if someone downloaded a PDF, and upon opening the PDF the PDF went and grabbed something off the internet.  This is a client side exploit, however, the flow would be reversed.  So, the author is correct in saying that "Client-side exploits are generally..." I wanted to explain to make sure no one was confused.  The "established" keyword means the the session is established.  So beginning on the 3rd part of the 3-way handshake.
    In this case some folks might believe that CLSID is already in the “content” part of the signature, and that this is a repetition if we use it in PCRE once again. We are not using this PCRE to repeat the value in the content, but to ensure that we do not miss any possibilities of matching this exploit. Let us look into the PCRE part of this signature:

    pcre:”/<OBJECT\s+[^>]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A105BD70-BF56-4D10-BC91-41C88321F47C/si”;

    In here, the signature is telling the PCRE compiler that there is “< object” followed by strings and “>” with multiple-strings possibly following it followed by “classid” & “=” with the “clsid”, “:” and “{“. The true classid is then inserted into the PCRE. The PCRE ends with /i to indicate the case-insensitive nature of this regular expression.

    The first paragraph is partially correct.  If you check for a content match, you can use a pcre to clarify what you are looking for.  This is done for a couple reasons.  One, as the author states above, is to not miss the possibilities of matching the exploit, but more accurately, it's to avoid obfuscation of the exploit.  So for example, let's go back and take a look at the content match before we look at the pcre portion.





    content:”clsid:A105BD70-BF56-4D10-BC91-41C88321F47C”; nocase;



    Problem with this content match is, well, I wouldn't have put the specific "clsid:" in there.  Reason?  If I was an attacker and I wanted to bypass your rule, I would put "clsid: A105BD70-BF56-4D10-BC91-41C88321F47C”. (Notice the space after the colon.)  Which completely bypasses the content match.

    So let's come back to the pcre and take a look at it.

    Now, this PCRE format was written by the VRT and a lot of people have copied it blindly without understanding what it does.  So let me explain, as what the author wrote in the second paragraph quoted above, is wrong.  As I said, I'm not trying to be mean or whatever, I am simply trying to teach.

    So, the pcre is this:

    /<OBJECT\s+[^>]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A105BD70-BF56-4D10-BC91-41C88321F47C/si

    (I am going to put double quotes around the things we are trying to match that are explicit, the quotes don't actually exist in the regular expression unless specified)

    So we are looking for "<OBJECT"

    Then a whitespace (\s).  That's what "\s" is.  (It says 'followed by strings' in the above quoted paragraph).  Whitespace is a tab, (0x09), space (0x20), new line character, or a line feed (0x0A), or a carriage return (0x0D).  The "+" sign after the "\s" means 'any character directly proceeding it as many times, but there must be at least 1'.  So there must be 1 or more "\s" there.

    Then you see this "[^>]", which the author says that we are positively looking for.  The thing about character classes "[ ]" is, they allow you to do some nifty things.  Range matching, ([0-9]), multiple matches, [abc] (this will look for either an a, b, or c, for one character), and you can also do negative matches.  Or "lack of" matches.  The way you specify a negative match within a character class is to use the carat within a character class.  So "[^>]" means, "the next character after any amount of positively matched "\s" cannot be a ">".  Directly after that is a "*" character.  The "*" is similar to a "+" but the difference is, while a "+" means you must have at least 1 match of the proceeding character (in this case the negative character class), the "*" means you don't have to have a positive match.  It means "0 or more".

    Following that we have a "classid\s*=\s*" match.  So look for classid(maybeaspacehere,it'soptional)=(maybeanotherspacehere)

    Then there is a "[\x22\x27]".  In regular expressions, if you want to specify a hex character you have to write "\x" before the hex.  So, you might see a space specified like this: 0x20.  You might see it specified in Unicode like this: %20.  In regular expressions, it would be "\x20".  Since there are two characters within the character class, 0x22 is the hex for a double quote.  "  and 0x27 is hex for a single tick. '

    Since this is a run of the mill character class match (not a range or something more complex) this means that the next character that the "[\x22\x27]" pattern match is looking for is either a ' or a ".  Notice the "?" after the character class?  That's a 'lazy optional'.  So without going into a long book about lazy and greedy (which, by the way, if you are interested, I suggest checking out the book "Mastering Regular Expressions" by Jeffery Friedl, it's the bible), the "?" basically means "The Character that is directly in front of the "?" is optional".  So, it essentially means, when all put together the match is either a ' or a " or not at all.

    Then we have (maybesomewhitepacehere)clsid(maybesomemorewhitespacehere):(maybesomemorewhitespacehere){(optionally)(maybesomemorewhitespacehere)A105BD70-BF56-4D10-BC91-41C88321F47C.

    Notice that I translated "\x3a" and "\x7B" (the latter of which has the "?" behind it, so it's optional) above.

    Then the modifiers of the whole Regular Expression at the end are "/si".

    "s" means "include new lines in the dot metacharacter".  However, there are no "." metacharacters in the regular expression, so that was probably put there by habit (and good practice), and the "i" means "anything within the regular expression treat with case insensitivity"  similar to the "nocase;" keyword in Snort's regular rule language.

    So the final signature that the writer comes up with is:





    alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:”ActiveX Exploit Signature Sample”; flow:to_client,established; content:”clsid:A105BD70-BF56-4D10-BC91-41C88321F47C”; nocase; content:”.Import(“; nocase; Offset:0;pcre:”/<OBJECT\s+[^>]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A105BD70-BF56-4D10-BC91-41C88321F47C/si”; reference:url,www.exploit-db.com/exploits/11204; rev:1;)



    Which I am going to rewrite:





    alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ActiveX Exploit Signature Sample"; flow:to_client,established; content:"A105BD70-BF56-4D10-BC91-41C88321F47C"; nocase; content:".Import("; distance:0; pcre:”/<OBJECT\s+[^>]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*A105BD70-BF56-4D10-BC91-41C88321F47C/si"; reference:url,www.exploit-db.com/exploits/11204; rev:2;)



    So, what did I do different?  Removed the "CLSID" content match, it won't speed up detection, and it checked for in the pcre anyway. So, if you are going to fire up the pcre engine to check the content match on the long content match, just knock out two birds with one stone.

    What's with the "distance:0;" stuff?  I made the content match directly proceeding that relative to the previous content match.  Since I don't have a within, I don't constrain the match.

    Why did you keep the ".Import(" stuff?  False positive reduction.  It will do nothing to speed up the match.

    So, be careful when writing rules.  Unless you understand all the pieces and parts you can walk yourself right into a dark hole and do it wrong.  You can do that to yourself, but take extra care that you don't walk anyone down the hole with you.

    Again, I post this, not to be mean, but to be constructive.

    Sunday, February 21

    Page for my Mustang

    Someone wrote me on Twitter and asked if I had a webpage about my 1968 Mustang, and I said I didn't, although it was a good idea for those that are interested.  So I made a quick page here on my website that I will keep updated with it's progress.

    Check out the page here.  Thanks.

    You can also find it under the "Pages" links on the right hand side of the homepage of the blog.

    Friday, February 19

    Why buying a DVD sucks




    This is an image that's been floating around the past couple days on the internet.  I have no idea where it originally came from.

    I don't pirate movies, I buy movies from iTunes, which, skips all the nonsense illustrated above and just gives you the movie.  Which, really, is all we want anyway right?

    I thought this image kind of sums it up correctly though.

    Thursday, February 18

    Stop Google Buzz From Showing the World Your Contacts

    Stop Google Buzz From Showing the World Your Contacts - google buzz - Lifehacker.

    If you are a person who values their privacy and want to secure you Google Buzz contacts, I.E.  Not show everyone in the world who is in your contact book, follow the directions above.

    I've done this, just for good citizen's sake, as well as manually blocked some people that I don't trust.  Keep on top of this stuff people!  As an online community becomes more ubiquitous, the more risk you present in revealing too much.

    Wednesday, February 17

    Tuning Snort with Host Attribute Tables - CSO Online - Security and Risk

    Tuning Snort with Host Attribute Tables - CSO Online - Security and Risk.

    Here is an article I wrote for CSO magazine, thought the readers of my blog might like to check it out as well.

    I was asked to write a fairly technical article for CSO magazine about Snort, the problem is, which part of Snort do you write the article for?  An article about Snort can be very technical or not so technical.  One of the advantages of having Open-Source software.

    In any case, enjoy.

    Tuesday, February 16

    Will Hack For SUSHI » MiFi Config Hack

    Will Hack For SUSHI » MiFi Config Hack.

    A post by friend and collegue at SANS Joshua Wright.  Joshua is one of the guys I know that is really proficient at hacking wireless.  Bluetooth, wifi, etc.  He does some really wonderful work at that, and he's fantastic at it.

    This post is about him hacking his Mifi (Verizon).  He has two posts on the subject you should check out if you have a Mifi.

    The other post is here.

    Monday, February 15

    Fun with Firewall Logs

    So, after my post about ask.com's network...  Here's another quiz for you.

    Feb 15 09:16:39 localhost kernel: IN=eth0 OUT= MAC=00:03:47:f1:52:0d:00:18:01:b6:c1:4d:08:00 SRC=121.242.15.135 DST=192.168.x.x LEN=72 TOS=0x00 PR

    EC=0x00 TTL=45 ID=32394 DF PROTO=TCP SPT=52764 DPT=22 WINDOW=46 RES=0x00 ACK PSH FIN URGP=0

    What kind of fun is that!

    Monday, February 8

    Hey, ask.com, what are you doing?

    So, in the spirit of another post I put up recently, I am monitoring my firewall logs for anything strange and I keep seeing this:
    Feb  8 14:47:55 localhost kernel: IN=eth0 OUT= SRC=66.235.120.71 DST=192.168.x.x LEN=455 TOS=0x00 PREC=0x00 TTL=49 ID=33745 DF PROTO=TCP SPT=80 DPT=58709 WINDOW=54 RES=0x00 ACK PSH URGP=0

    The Source is Ask.com, the DST is my webserver, but take a look at the Ports.  SRC port 80?  DPT 58709?  Anyone else see anything like this?  This is being denied at my firewall because of my ESTABLISHED,RELATED line.  So, the connection was not made from here.  It's initiated from the outside.

    What's going on over there at Ask.com?

    WP Greet Box is back

    I took away the WP Greet Box for awhile based on the fact that I didn't really have it configured optimally.  I wanted the Greet Box (which is a little pop up widget that say "Hello, welcome to the site, you can subscribe here" -- pretty much) because on several of the themes I have been partial to, had no obvious way to subscribe via RSS.  I've fixed that now with, as the blog will advertise that it has a feed in the URL bar now (for most modern browsers), also with a link over in the sidebar that points you to the feed.  But I wanted a little something, non-intrusive, that pointed to the RSS feed when you came from certain sites.  (Digg, StumbleUpon, things like that).  So it's there again, but only if you get directed from certain webpages to my site.  Which, actually, is the majority of the hits I receive.  Basically it's just an experiment.  Bear with me.

    Sunday, February 7

    A couple snow pictures

    Lots of Snow over the past couple days. 2nd biggest snowfall ever for this area.








    Friday, February 5

    One in five physicians likely to purchase Apple iPad - study

    AppleInsider | One in five physicians likely to purchase Apple iPad - study.

    This is what I said back here, so I am glad that someone did a study on it.  Very interesting what the future holds for this form factor of device.  I think the early critics are going to be eating their words in a year or so.

    If you never knew it occurred, did it occur in the first place?

    In my To-Do list, I have a section for Blog topics that I think of in $random_place and I want to jot down for brainstorming later. This topic has been on my to-do list for about a year.

    I was standing on a stage giving a speech at a military base, in about 2004.  The people I was giving a speech to were about 200-250 different "network" and "Systems" administrators from all over this military base in tons of different units.  In this audience I had military, civilian, and contractor.  I was asked to give a speech to the system administrators because some of them didn't see the value in security in their systems.  It was an afterthought and people weren't terribly excited about having to follow $regulation that ensured proper lock down of various controls in the operating system and network.

    I asked this question:  "If you never knew it occurred, did it occur in the first place?"  I paused for effect, waiting for an answer.  One didn't come.  Obviously they had no idea was I was talking about.

    I proceeded to explain the importance of reviewing logs, system and network information, explaining to them the importance of what I had found that week upon a security audit I was doing of their Army post.

    Hundreds of compromised machines, botnets, poor security controls, inadequate permissions, etc.  This was all from about 3 days of work.  I didn't even get into the trenches trying to find things, this was just surface level scanning and network monitoring.  Not even penetration testing, just scanning.

    They didn't know.  They thought their network was perfect.  They thought it was clean.  They didn't need to review logs.  They thought wrong.

    If you aren't going to review logs, if you aren't going to look at the system logs, the firewall logs, the IDS/IPS logs, then why collect them?  The problem is, we have things like SOX compliance now that mandates that we have some kind of logging system.  Which is fine, it's a great idea, but people are missing the point.  The point of the SOX compliance and log review is for people to REVIEW the logs.  Otherwise what is the point?  So you can go back and see when you were compromised?

    Some people will agree with me here and say "Yes, I'd like to have historical information so I can go back and see when the intrusion occurred."

    That's fine, I don't disagree, but stop for a second while reading this and meditate on this question "Why?"  What are you going to do about it?

    If you are going to look at your logs and dismiss them, instead of looking at your logs and doing something about the mistakes that you find, then what's the point in looking at the logs.  Don't waste your time.

    It's your JOB to be looking at these things, if you aren't going to DO your job, then quit.  We don't need you in our industry because it's people like YOU that are messing things up for the rest of us.

    I'm going to do it...  I am going to use APT (Advanced Persistant Threat).  APT was found by looking at logs.  APT has been around for a long time.  Before I worked at Sourcefire, I worked for the Department of the Army in computer security, and we were dealing with APT (only it wasn't called that back then) then.  We didn't have an advanced term for the threat, we used terms like 'rootkit' and 'trojan'.  We were looking at hacks that we had never thought possible offloading information to countries that weren't ours.  Some of the techniques were so interesting and secret, they haven't been made public to this day, so I can't talk about them here.

    But we found the compromises by looking through logs.  I've said this before, and I'll say it again, what's the point in having a security device that keeps logs if you aren't going to LOOK at it?

    Thursday, February 4

    Review: Jawbone ICON Bluetooth Headset

    I am not trying to jump on you like a bully and pummel you with reviews for a few posts recently, but I feel, as a geek, I have the need to tell my other geeky friends if something sucks, or if something is good. That way, not everyone spends money on things that are complete pieces of crap.

    For those of you seeking a Bluetooth headset, you may want to look no further than the Jawbone ICON headset. Little bit of background before I proceed.

    I've had all three versions of the Jawbone now. The Jawbone One, was big, bulky, but it did it's job right, however, it did not survive the trip through the washing machine. The second version fixed that, (not the washing machine part, the big and bulky part). Same awesome noise cancellation technology, much much lighter, the only problem was, it wasn't very solid in your ear, and it fell out of my ear a lot, simply because it just felt like it was Stallone in Cliffhanger, hanging on for dear life. The only other thing I didn't like about the second generation jawbone was the buttons. I could never find them. There were two buttons, one on the side and the other on the back, kinda. They were next to impossible to find with your fingers, as they didn't have any raised indication that said "hey, this is a button!"

    But let me tell you what, with this new one, they have really outdone themselves. The Jawbone ICON comes in six different designs. "The Hero", "The Bombshell", "The Catch", "The Ace", "The Thinker", and "The Rogue". All are various colors and designs, but they all have the same key features.

    The NoiseAssasin® technology is awesome. On by default, it uses a sensor that presses against your cheek to sense when you are talking, it compares that vibration with the mic's input, and thusly uses the difference to cancel out all the remaining background noise. It's awesome for wind, trains, or whatever. You can be in a noisy room and talk to someone on the phone, and the only thing that the people on the phone can hear is you. It's incredible. For a video demonstration of how this works, go to Jawbone's website and click on the lower right area. Check it out.

    This version of the jawbone adds a few awesome features:

    1) If you are using the jawbone with the iPhone, the battery indication is on the screen of the iPhone up next to the battery indicator for the iPhone itself. If you ever bought the iPhone bluetooth headset (which I didn't), you'll recognize what this indicator looks like.

    2) But that doesn't matter cause you can reach on the back of the jawbone, press the button once, and it announces in your ear how many hours of talk time you have remaining.

    3) When you receive a call, the ICON will read the caller id into your ear. Just the number. Not any names or anything, which kinda stinks. I wish it would at least try to pronounce some of my coworkers and friends names just so I could get a laugh out of it. But the number is just fine. It's a heck of a lot better than scrambling for your phone when the thing rings just to see who called. I mean isn't that the purpose of a bluetooth headset? So you don't have to fumble for your phone?

    4) It doesn't have any blinking lights on the outside. Which is nice, because then you aren't sitting on a train or something and have an annoying blue blinking light on your ear. Or even better, when you are in a hotel room and the blue blinking light is so bright it lights up your whole hotel room every 10 seconds or so.

    5) Voice control. The Jawbone has always had voice control, but now, coupled with the iPhone 3GS that I have, I can hold down the button for two seconds and say "Call Wife", which the iPhone then asks "Home, Mobile, or Work?" And I simply say what I want. I like the fact (and this is more on the iPhone than the Jawbone) that I don't have to hit ANOTHER button to say "Work". I just say it after the little 'beep'.

    6) It has an on-off switch. I don't have to hold down a button that I can't find to turn this thing on and off. The button is a toggle sliding switch on the inside (faces your face) side of the jawbone. Flick it on or off, and you KNOW which one it's doing.

    7) Redial is a double tap of the button on the back. The Jawbone then says "Redialing" in your ear

    8) When the battery does get low, it will tell you in your ear. No more guessing.

    9) You can connect this thing to multiple phones. YES SERIOUSLY. You can even manage calls from two different phones at the same time. Are you kidding me? This is 2010 right? We aren't in 2020 or anything?

    10) They converted from their annoying proprietary charger attachment to a Mini-USB plug. Very standard and easily replaceable if you lose it.

    So, overall, I'm very satisfied with this thing, and if you are looking for a new one, or if you are happy with your old one... this one is better, it's smaller Oh and one more thing?

    This thing stays in my ear! No loop around the top of my ear, I just put it in my ear and it stays there.

    Go, run, don't walk, to the nearest Best Buy/Apple Store/AT&T store. This thing is new, so it may not be in all the stores yet (so it's available online via their website) your milage may very. Check the websites.

    I got mine at a Best Buy.

    Review: Capitol Hilton, Washington, D.C.

    This week I had to come down to Washington, DC to work with a customer.  Now, I've been to loads and loads of Hotels, and most of the big ones in Washington, DC.  This week I decided to stay at the Capitol Hilton.  It's about three blocks North of the White House.

    So, being the traveler I am, I am a Diamond member with Hilton, for the past three years, which is the highest you can get as a "premier traveler" with Hilton Rewards.  I'm not saying that to brag, I'm saying that to illustrate a point.  As a diamond member, you automatically get certain things.  Free Gym access, free breakfast, free newspapers, and free room upgrades just to name a few.

    So, and you might call me spoiled, but whatever, I'm not trying to act that way, I'm giving a review.

    So, I get my room.  No refrigerator, shower was dirty, shower head sprayed water every which way (indicating that you have hard water, and the shower head hasn't been cleaned), and no electrical outlets in the bathroom.

    Now, how do you not have electrical outlets in the bathroom?  God forbid I should be a woman and need to plug in the hair dryer!  Where was the closest outlet? Behind the TV. Which was on a TV stand, which was immovable. So, there was no way to dry your hair (and curl it, with a curling iron, cause I think of stuff like that for my wife) anywhere close to in front of a mirror. Matter of fact, the only place you could have plugged it in, was behind a TV stand in the middle of the room.

    There were four outlets available in the whole room. Two on the lamp on the desk, and two behind the night stand. So, if you are technical person like me, you have stuff plugged in all around the room. Fairly annoying.

    The TV was ancient, you couldn't hook up any external media to the TV, which, is also annoying.

    Room service food was so-so. The menu consisted of things like foi-gras and the like. Seriously? Who is going to eat food of "that" caliber from the room service menu? People that order room service want things like wings, and quesadillas, pizza. Room service is like, a last resort and you just want something good. Oh, and by the way, a sandwich for 19 dollars? So, you add delivery fee onto that, drink.. You have a 30 dollar dinner? A bit much for a regular sandwich. I order room service fairly often (because I get tired of prowling through a city trying to find food -- you travel as much as me, you'll know what I mean) and the average price is around 19-25 bucks. 30+ dollars for dinner is overpriced for simple food.

    Internet. The Internet speed was pretty good actually, but it was something like $15 dollars a night. Again, not what I am used to, and not comparable to the other hotels in DC. The room rate per night was reasonable, (for DC), but the other things they charge you for a the hotel was overpriced.

    Now, saying all that, there was a note on the desk of my room saying that the hotel is currently undergoing a 36 Million dollar renovation. So let's hope they fix some things. The biggest request I have, of all hotels, is: PUT MORE OUTLETS IN THE HOTEL ROOMS. Accessible. Easy. In the Desk or something.

    So, until the renovations get done, I recommend the Marriott Metro Center.  It's nice (without going higher to the Mandarin, W hotel, or JW Marriott), or either of the Hyatt's.  They are nice, but they have the 'lack of outlet' problem as well.

    So, my review is pretty unhappy.  Now, finally, as I said in the beginning, I'm a Diamond member.  Would you like to see my view out of my hotel window of the lovely Washington DC?



    Lovely eh?

    I stay in a lot of Hilton's.  Most are nice.  This one is obviously old, and we'll forgive them for that.  So, maybe I'll try them again after they complete their renovation.

    Wednesday, February 3

    Steve Jobs: The Rolling Stone Interview : Rolling Stone

    Steve Jobs: The Rolling Stone Interview : Rolling Stone.

    This is an older interview (2003) with Steve Jobs.  This is shortly after the iTunes rollout on Windows, iPods were just taking off, before the iPhone, before the App Store, before the iPad.

    This is an interesting interview and you can see where Apple was at the time as far as Steve's thinking was concerned, and how that thinking has come to shape Apple.

    Great Anti-Email post

    Jeff Atwood, blogger and coder over at Coding Horror, one of the many blogs I read, had this post up sometime last year, and I thought it was such a good post that I've recommended it to a couple friends, but I realized I never actually blogged it.

    Jeff discusses a similar topic to what I've discussed in the past.  Checking email less often, shutting your email off for periods of time, turn off the "new message" ding.   All great points.

    Go check out his post here.  Jeff, great job!

    Tuesday, February 2

    YouTube in html5, enable it now

    I received this link on one of my mailing lists and thought it was the greatest thing since sliced bread.  Following up on my "Flash is dead" post, you can enable Youtube.com to work in HTML5.

    Go to: http://www.youtube.com/html5 and you can "opt-in".  I assume it places a cookie in your browser so that every time you try and view a video, the video plays in html5 instead of flash.  My browser doesn't run at 100% CPU or anything.  It's awesome.  Go do it now, help kill flash.

    Monday, February 1

    Google to kill off IE6 support in 2010

    In a big move by Google I just received an email letting me know that Google will be phasing out support for IE6 in Google Apps in 2010.
    "In order to continue to improve our products and deliver more sophisticated features and performance, we are harnessing some of the latest improvements in web browser technology. This includes faster JavaScript processing and new standards like HTML5. As a result, over the course of 2010, we will be phasing out support for Microsoft Internet Explorer 6.0 ​as well as other older browsers that are not supported by their own manufacturers."

    I think this is a phenominal move by a company as big as Google to say "not anymore". I wish other companies would take such a firm stance against my other pet peeves. You know, ActiveX, Flash, and Silverlight.

    Snort Ruleset tuning, by the VRT

    Awhile back here on this blog I wrote about PulledPork 0.3.4 being released and about the VRT making the "Connectivity, Balanced, and Security over Connectivity" policies.  Also about how you can use PulledPork to automate the updating of your open source Snort rules to take advantage of these recommendations.

    Around about the same time VRT put a post up entitled the "VRT Guide to IDS Ruleset Tuning".  It was a good post, and I didn't really highlight it.  They post some really great examples towards the bottom of the post.  If you run a Snort installation and you've read some of my posts about Snort tuning, and "I've installed Snort, now what".  This is a good read as well.

    Check it out here.