08 November, 2008
What does Wikipedia want $6 million for??...Simply Outrageous!!!
Please interrupt me if Im wrong here, but arent all of wikipedias' articles written by commoners like you and me? So, its a collective effort isnt it? They shouldnt be asking for donations unless to pay for server bills!! SO, WHAT DO THEY HAVE TO DO WITH $6 MILLION?? Are you donating to wikipedia? If so please STOP!! Stop this insanity in the name of free knowledge.
Wikipedia has 20 odd workers, all doing what.. building a CMS thats wikipedia. Sure, its a good source of information and all, but do they REALLY deserve $2 Million???
If your answer is YES, please check in to your nearest mental hospital. You are in need of medical attention.
23 August, 2008
Time Scale theory: Are software companies producing obselete software?
> Better user interfaces
> Better functionality
> Faster (?) than previous versions
> Supposed "overall" upgrades
Personally, I just stick to the first version of any software I use (that is barring windows of course!). Similarly, I was very impressed with System Mechanic 6.0 when it first came out. Even though IOLO came out with System Mechanic 7.0 and version 8 is on the docks, I still love the UI in System Mechanic 6.0 . Why? Due to the simple fact that I found this software worthwhile, unlike its
successors. This isnt just the case of IOLO and System Mechanic. Its the same with Nero 8. The software is jam packed with features that I dont use, and these end up hogging memory, installing shell extensions that I dont use, and in turn, I have to labor hard to uninstall these to keep my installations to the bare minimum. So, Why not just stick to the previous versions?This goes for each and every software I have used.
There is a theory I recently made up. Its called the "Time Scale Theory".It goes something like this:
"There is a peak in every software company's production cycle. At this peak, the software company has built up enough reputation to sell its most endorsed product in quantities of millions. It makes a lot of money and repute. After this peak time is over, the company merely survives on its earlier reputation. Any software produced henceforth will be completely obselete and will add features to make users' experiences worse than the previous versions."
The same thing goes for IOLO(System Mechanic 6.0), MicroSoft(Windows XP-Current, excluding windows Vista), IBM(The peak time seems to be neverending!, but it will end nonetheless!), Google(In its peak right now).
26 July, 2008
WWW = World Wide Wait?
But in all the hurry to increase the speeds are we forgetting some of the basic concepts which were the founding principle of the internet?
The internet was born out of necessity. The US military was the first organized network. But why do we find people still connecting to the internet through 56k modems?why doesnt everyone have broadband? Even though broadband is affordable these days, there are millions who are still using dial up connections. I would say this is mainly due to corporate incompetence.
The "big" companies such as AT&T want to make profits by giving the customers nothing but crappy speeds. Until and unless there is a revolution in the way companies think, the equivalent of a 56k modem will always be around.
And, to add to all this, the service providers have started providing internet connectivity to mobile systems, whose speeds are even more pathetic. Suddenly, there seems to be a big leap of faith towards the mobile computing platform.
Internet downloads remain pretty much a dream to people such as myself. It takes a lot of time to download even an Mb...
25 July, 2008
Bangalore bomb blasts
Over the years, Bangalore has been giving entrepreneurs and politicians major boosts in terms of infrastructure. IT industries flourished in what was once a deserted and barren city. I am put up in the outskirts of the city right now. But this fateful day, I happened to commute through 4 of the 6 blast sites. And I must say, the scene was horrible. I wanted to play hero, and go help with some of the rescue work. But the cops wouldnt let me, nor the others who wanted to help. They were busy chasing off people.
I saw a city weep today. I stopped at a restaurant on my way home, and I heard an old timer say, "These terrorists wont let us live in peace". How true. What a statement. This city, which has inspired millions upon millions to take up careers in the IT industry has suffered a fatal blow, in that, all these days, one could roam around in Bangalore like a free bird. This will no longer be so.
North India was the only place where the terrorists let their kind flourish. Such barbarism, and malice was unknown to us South Indians. Yet, terrorists have spread their fatal roots in Bangalore, and if you ask me, it will take all our efforts to weed it out.
Ive seen this city smile.Ive seen it weep. Ive walked with gods, and wept with angels. Rock on Bangalore city.
22 July, 2008
Common Firefox myths
WRONG!! Firefox is in fact slower than IE. The fastest browser in loading and in performance is Opera 9.5 !
Firefox is a non-profit organisation:
WRONG!! Firefox has a tie in with google refferals. Thats why you see so many websites supporting firefox.
Firefox's plugins dont slow my pc :
WRONG!! Firefox slows down with the first plugin you install. Overall, for a simple HTML page, it consumes about 20 MB of memory as opposed to 15 by IE and just over 7 MB by Opera!!
Firefox is very safe:
WRONG!! There have been many security loopholes detected over the years in Firefox. They(Mozilla foundation) dont release patches very often. Now which browser is safer IE(which gets constant updates and patches) or Firefox? I would say Firefox is just as vulnerable as any other browser is!
Firefox is open source:
WRONG!! Do your own research as to why this is not so.
Firefox is the only browser available for Linux:
WRONG!! Konquerer is an excellent browser available on all flavors of Linux.
12 July, 2008
Stupid reasons why JAVA beats .NET :
so called frameworkswere built for different purposes, there are a few
applications that can be built with both. For example web applications.
JAVA has the J2EE libraries and .net has, well ASP.net . Java counters with
JSP if I forgot to mention.
So, why do I like JAVA more than .net?
Reason #1: JAVA suppports an open source mindset, .NET does NOT
Reason #2: With all the inherant complications, JAVA seems like a tough nut
to crack. Ever heard the saying, girls dig complicated guys?? Something like that
Reason #3: .NET just makes things even more complicated by providing an IDE with
drag and drop, and at the same time introducing complex concepts such as assembly,
GAC's and what not. Im thinking of removing .net from my resume', you know why?
Ive never heard a saying which goes "Girls dig overly complex, nerds".
Reason #4: JAVA always gave me options, for example, if I wanted to develop a web
application, I can do it with a JSP page, or an HTML page with a servlet back end.
Yeah, .NET does it too, with its ASP.net, but I never got to use the full functionality
of the libraries, simply because, there are complex types which profess to do stuff, but dont,
or there are variables where there should have been none. If you're an avid .NET programmer you'll know.
Reason #5: JAVA was made by SUN microsystems, whose SOLARIS isnt that much of a money grabber.
And, .net you know, was made by Microsoft...Oh, I always hated Microsoft! Corporate dominance
makes me sick to my stomach!
If you were expecting a complete technology comparison like I do everytime, sorry to disappoint you,
wasnt in the mood today!!
07 July, 2008
The call of convergence
Over the last few quarters, there has been a big, but largely unnoticed shift in the communications landscape. We are seeing wider availability of services from one operator, and pilot runs of new technologies.Powering this change is the use of new generation technologies that are flexible, scalable- and considerably cheaper for operator deploy.Chief among them is the Internet Protocol(IP), which all service providers have embraced since it provides a cheaper and more efficient way to move data on networks.
Using IP, a telecom network can be configured to handle telephone conversations, internet access and data transfers, video conferencing and even television-all on the same physical link. In fact, IP technology can be used to integrate wireless and wired networks and deliver advanced services to mobile phone users too. The attraction of IP to service providers is patently obvious-it eliminates the need to build multiple dedicated networks for each service, and makes the addition of new services quick. This is one reason why you see cable operators offering internet access and telephony, and telecos promising you television over the telephone line.Device and equipment manufacturers have already jumped on the convergence bandwagon. Think media center PCs, VoIP phones, home theater amps that can connect to the internet and mobile phones that can receive TV broadcasts. For consumers this technological convergence between consumer electronic products and computing devices, and between diverse communication and entertainment services is interesting.For one, it obviates the need to buy multiple specialty gadgets and gizmo's, and second, it reduces obsolescence. For every new service, you don't need a new device, just a software.
On the infrastructure front of convergence will increase competition between service providers and provide the economic incentive to craft and deliver innovative services. For instance, wouldn't you like a mobile phone that automatically switches to a landline or a WiFi network when you go home ,or enter your office-even retaining its identity? How about a video phone service at your desk? or perhaps secure payments at cinema halls with your mobile phone instead of a credit card or even cash? convergence will also enable smaller companies with good ideas bring us useful services, and perhaps even greater personalization of the services we have today.
30 June, 2008
Made in china? Bye bye logitech!
I went to a couple of hardware stores today, and was fascinated at the variety of keyboards available. "Give me a keyboard thats cheap" is what I told the store guy. "Right away sir", he said, with a huge smile. I finally got my hands on my new keyboard. "How much?" I asked. "150" came the reply. 150 rupees is like $4 !I quickly opened the box, to find a fairly handsome piece of hardware in my hands.I was awestruck that such a good piece of hardwares' cost was so low. I turned over the keyboard to find the words "Made in China" written.
As soon as I saw that, I decided it must not be worth the money. So, I asked for a "branded" keyboard. "Logitech will do" I told the store keeper. I was flabberghasted to find the price of a basic keyboard was 450 rupees!! I went for the chinese model, and Im happy I saved myself the 300 rupees!
The moral of the story is that though "top brands" claim to produce quality hardware, there are many other vendors who are never noticed. These companies mainly cater to people like me, and what a bunch of happy customers we are!! Ive promised never to turn to logitech again. Oh, and did I mention?...The keyboard has a warranty of 5 years. Thats good enough for me!!
23 June, 2008
This is Why piracy is rampant :
Adding to that is the notion that being bad is actually good! Yes, its like going up to ones' girlfriend and telling her you robbed a bank, in which case she would try to get away from you as soon as possible, and report to the police and later testify against you in court or whatever. But this is different. When you tell somebody you are into software piracy, the listener actually starts looking upto you, as if you are some uber geek persona. So, there are a lot of posers out there, and some really talented programmers who are on the wrong side. Some of them that are noticeable are :
> CORE : Challenge of reverse engineering
These guys are living legends. These guys came to the scene at a time when reverse engineering was the field of uber geeks, thats not to say these guys aren't!
> Deviance
Another group which is very good at releasing cracked unreleased games! Yes, sometimes you will find a game on the pirate bay that you haven't ever heard of. You try to get a proper review of the game before downloading it, but Google doesn't seem to have a clue! You download the game, and the next month when youre watching TV, this games' trailer is being shown! WTF?!
> Dopeman
Does this guy need an introduction? If you are a regular to the bay, you'll know him!
> AxxO
An article on piracy is never complete without a mention of this guys' name. Another living legend in the movie piracy circuit.
I personally dont blame people for downloading crap off the internet, but I really do encourage them to pay for the software they use, maybe its a small amount, but developers need it to continue their work... Atleast thats MY perspective!!
Im going freelance!
How it works :
> Firstly, you need to get yourself an account on any of the freelancing sites such as
Elance [ Pretty good, has been in the field for a while ]
workbuggy [ Extensive ! ]
freelanceswitch [ Good... ]
There are many others, that are better, but these are my favorites.
>Secondly, start trolling for projects on these sites. Generally, they offer a limited amount of "credits", or "connects" to get you started. These are the tokens that you can use to "bid" on projects. Bidding is a process wherein you, the "provider" are going to "quote" a price for a project that interests you. Make sure you quote the lowest price, so that you get the project. Once you get a hold of things, you can quote higher prices.
>Thirdly, start building projects after deciding the means of payment. And remember, the more money you spend on memberships, the better your earnings will be. The site will start listing your name in premium categories, so that customers will be able to easily get in touch with you.
It amazes me that people/companies are willing to spend upto $500 - $1000 for a simple web page project. NO dynamic pages, NO complicated flash, for just pure HTML and a couple of images, that they will provide you.
Well, Im off to freelancing, until I can find myself a suitable job. Im considering it an important career option.
22 June, 2008
The hunt for a job ...
The job offer I had got from Sapient, is almost a distant dream now, as they have "postponed" the joining dates to NEXT july! This comes as a shock to me and many of my friends who were looking to get our BE degrees and go onto join companies as software developers. Our previous batches which had got placed in other companies have been asked to go "home", thanks to the US Dollar recession.
We've been waiting at the tips of our toes to join the companies and what do the seniors tell us?..That they have been kicked out of the companies for no reason whatsoever. The companies are quick to ascertain that their companies arent the only ones doing it... Its like the whole industry has come crashing down!
I got a call 2 weeks earlier from Sapient informing me of this "unfortunate" situation. I asked the HR person to honestly tell me whether or not I would really get a job as promised by them. She said in a confident manner that my employment with them was valid for life, unless I was caught for bad behavior, or ill performance, both of which cannot occur since I havent yet joined their company!
Weeks, After getting a satisfactory answer from them, I got a letter which said, all the things I mentioned above, and went on to drop a bomb at the end :
"......
But your employment with Sapient cannot be guaranteed. Thank you. ..."
Now, I have decided to bring into action my contingency plans. I had almost completed a GNIIT course which guaranteed me a developers job. It was a 3 year course and Ive already completed the 2 years. The third year is supposed to be an industry orientation, in which we'll be sent to a company for onsite projects, and if lady luck shines, we'll get placed in the same company. Im just waiting for my degree, after which I can do this...The results ought to come out by the next month...
21 April, 2008
Advanced Shell Coding Techniques
This paper assumes a working knowledge of basic shellcoding techniques, and x86 assembly, I will not rehash these in this paper. I hope to teach you some of the lesser known shellcoding techniques that I have picked up, which will allow you to write smaller and better shellcodes. I do not claim to have invented any of these techniques, except for the one that uses the div instruction.
The multiplicity of mul
This technique was originally developed by Sorbo of darkircop.net. The mul instruction may, on the surface, seem mundane, and it's purpose obvious. However, when faced with the difficult challenge of shrinking your shellcode, it proves to be quite useful. First some background information on the mul instruction itself.
mul performs an unsigned multiply of two integers. It takes only one operand, the other is implicitly specified by the %eax register. So, a common mul instruction might look something like this:
movl $0x0a,%eax
mul $0x0a
This would multiply the value stored in %eax by the operand of mul, which in this case would be 10*10. The result is then implicitly stored in EDX:EAX. The result is stored over a span of two registers because it has the potential to be considerably larger than the previous value, possibly exceeding the capacity of a single register(this is also how floating points are stored in some cases, as an interesting sidenote).
So, now comes the ever-important question. How can we use these attributes to our advantage when writing shellcode? Well, let's think for a second, the instruction takes only one operand, therefore, since it is a very common instruction, it will generate only two bytes in our final shellcode. It multiplies whatever is passed to it by the value stored in %eax, and stores the value in both %edx and %eax, completely overwriting the contents of both registers, regardless of whether it is necessary to do so, in order to store the result of the multiplication. Let's put on our mathematician hats for a second, and consider this, what is the only possible result of a multiplication by 0? The answer, as you may have guessed, is 0. I think it's about time for some example code, so here it is:
xorl %ecx,%ecx
mul %ecx
What is this shellcode doing? Well, it 0's out the %ecx register using the xor instruction, so we now know that %ecx is 0. Then it does a mul %ecx, which as we just learned, multiplies it's operand by the value in %eax, and then proceeds to store the result of this multiplication in EDX:EAX. So, regardless of %eax's previous contents, %eax must now be 0. However that's not all, %edx is 0'd now too, because, even though no overflow occurs, it still overwrites the %edx register with the sign bit(left-most bit) of %eax. Using this technique we can zero out three registers in only three bytes, whereas by any other method(that I know of) it would have taken at least six.
The div instruction
Div is very similar to mul, in that it takes only one operand and implicitly divides the operand by the value in %eax. Also like, mul it stores the result of the divide in %eax. Again, we will require the mathematical side of our brains to figure out how we can take advantage of this instruction. But first, let's think about what is normally stored in the %eax register. The %eax register holds the return value of functions and/or syscalls. Most syscalls that are used in shellcoding will return -1(on failure) or a positive value of some kind, only rarely will they return 0(though it does occur). So, if we know that after a syscall is performed, %eax will have a non-zero value, and that the instruction divl %eax will divide %eax by itself, and then store the result in %eax, we can say that executing the divl %eax instruction after a syscall will put the value 1 into %eax. So...how is this applicable to shellcoding? Well, their is another important thing that %eax is used for, and that is to pass the specific syscall that you would like to call to int $0x80. It just so happens that the syscall that corresponds to the value 1 is exit(). Now for an example:
xorl %ebx,%ebx
mul %ebx
push %edx
pushl $0x3268732f
pushl $0x6e69622f
mov %esp, %ebx
push %edx
push %ebx
mov %esp,%ecx
movb $0xb, %al #execve() syscall, doesn't return at all unless it fails, in which case it returns -1
int $0x80
divl %eax # -1 / -1 = 1
int $0x80
Now, we have a 3 byte exit function, where as before it was 5 bytes. However, there is a catch, what if a syscall does return 0? Well in the odd situation in which that could happen, you could do many different things, like inc %eax, dec %eax, not %eax anything that will make %eax non-zero. Some people say that exit's are not important in shellcode, because your code gets executed regardless of whether or not it exits cleanly. They are right too, if you really need to save 3 bytes to fit your shellcode in somewhere, the exit() isn't worth keeping. However, when your code does finish, it will try to execute whatever was after your last instruction, which will most likely produce a SIG ILL(illegal instruction) which is a rather odd error, and will be logged by the system. So, an exit() simply adds an extra layer of stealth to your exploit, so that even if it fails or you can't wipe all the logs, at least this part of your presence will be clear.
Unlocking the power of leal
The leal instruction is an often neglected instruction in shellcode, even though it is quite useful. Consider this short piece of shellcode.
xorl %ecx,%ecx
leal 0x10(%ecx),%eax
This will load the value 17 into eax, and clear all of the extraneous bits of eax. This occurs because the leal instruction loads a variable of the type long into it's desitination operand. In it's normal usage, this would load the address of a variable into a register, thus creating a pointer of sorts. However, since ecx is 0'd and 0+17=17, we load the value 17 into eax instead of any kind of actual address. In a normal shellcode we would do something like this, to accomplish the same thing:
xorl %eax,%eax
movb $0x10,%eax
I can hear you saying, but that shellcode is a byte shorter than the leal one, and you're quite right. However, in a real shellcode you may already have to 0 out a register like ecx(or any other register), so the xorl instruction in the leal shellcode isn't counted. Here's an example:
xorl %eax,%eax
xorl %ebx,%ebx
movb $0x17,%al
int $0x80
xorl %ebx,%ebx
leal 0x17(%ebx),%al
int $0x80
Both of these shellcodes call setuid(0), but one does it in 7 bytes while the other does it in 8. Again, I hear you saying but that's only one byte it doesn't make that much of a difference, and you're right, here it doesn't make much of a difference(except for in shellcode-size pissing contests =p), but when applied to much larger shellcodes, which have many function calls and need to do things like this frequently, it can save quite a bit of space.
Conclusion
I hope you all learned something, and will go out and apply your knowledge to create smaller and better shellcodes. If you know who invented the leal technique, please tell me and I will credit him/her.
31 March, 2008
A Guide to Internet Security: Becoming an Uebercracker
to becoming a uebercracker and the next part showing how to become a
ueberadmin and how to stop a uebercracker. A uebercracker is a term phrased
by Dan Farmer to refer to some elite (cr/h)acker that is practically
impossible to keep out of the networks.
Here's the steps to becoming a uebercracker.
Step 1. Relax and remain calm. Remember YOU are a Uebercracker.
Step 2. If you know a little Unix, you are way ahead of the crowd and skip
past step 3.
Step 3. You may want to buy Unix manual or book to let you know what
ls,cd,cat does.
Step 4. Read Usenet for the following groups: alt.irc, alt.security,
comp.security.unix. Subscribe to Phrack@well.sf.ca.us to get a background
in uebercracker culture.
Step 5. Ask on alt.irc how to get and compile the latest IRC client and
connect to IRC.
Step 6. Once on IRC, join the #hack channel. (Whew, you are half-way
there!)
Step 7. Now, sit on #hack and send messages to everyone in the channel
saying "Hi, Whats up?". Be obnoxious to anyone else that joins and asks
questions like "Why cant I join #warez?"
Step 8. (Important Step) Send private messages to everyone asking for new
bugs or holes. Here's a good pointer, look around your system for binary
programs suid root (look in Unix manual from step 3 if confused). After
finding a suid root binary, (ie. su, chfn, syslog), tell people you have a
new bug in that program and you wrote a script for it. If they ask how it
works, tell them they are "layme". Remember, YOU are a UeberCracker. Ask
them to trade for their get-root scripts.
Step 9. Make them send you some scripts before you send some garbage file
(ie. a big core file). Tell them it is encrypted or it was messed up and
you need to upload your script again.
Step 10. Spend a week grabbing all the scripts you can. (Dont forget to be
obnoxious on #hack otherwise people will look down on you and not give you
anything.)
Step 11. Hopefully you will now have atleast one or two scripts that get
you root on most Unixes. Grab root on your local machines, read your
admin's mail, or even other user's mail, even rm log files and whatever
temps you. (look in Unix manual from step 3 if confused).
Step 12. A good test for true uebercrackerness is to be able to fake mail.
Ask other uebercrackers how to fake mail (because they have had to pass the
same test). Email your admin how "layme" he is and how you got root and how
you erased his files, and have it appear coming from satan@evil.com.
Step 13. Now, to pass into supreme eliteness of uebercrackerness, you brag
about your exploits on #hack to everyone. (Make up stuff, Remember, YOU are
a uebercracker.)
Step 14. Wait a few months and have all your notes, etc ready in your room
for when the FBI, Secret Service, and other law enforcement agencies
confinscate your equipment. Call eff.org to complain how you were innocent
and how you accidently gotten someone else's account and only looked
because you were curious. (Whatever else that may help, throw at them.)
Step 15. Now for the true final supreme eliteness of all uebercrackers, you
go back to #hack and brag about how you were busted. YOU are finally a
true Uebercracker.
Now the next part of the paper is top secret. Please only pass to trusted
administrators and friends and even some trusted mailing lists, Usenet
groups, etc. (Make sure no one who is NOT in the inner circle of security
gets this.)
This is broken down on How to Become an UeberAdmin (otherwise know as a
security expert) and How to stop Uebercrackers.
Step 1. Read Unix manual ( a good idea for admins ).
Step 2. Very Important. chmod 700 rdist; chmod 644 /etc/utmp. Install
sendmail 8.6.4. You have probably stopped 60 percent of all Uebercrackers
now. Rdist scripts is among the favorites for getting root by
uebercrackers.
Step 3. Okay, maybe you want to actually secure your machine from the
elite Uebercrackers who can break into any site on Internet.
Step 4. Set up your firewall to block rpc/nfs/ip-forwarding/src routing
packets. (This only applies to advanced admins who have control of the
router, but this will stop 90% of all uebercrackers from attempting your
site.)
Step 5. Apply all CERT and vendor patches to all of your machines. You have
just now killed 95% of all uebercrackers.
Step 6. Run a good password cracker to find open accounts and close them.
Run tripwire after making sure your binaries are untouched. Run tcp_wrapper
to find if a uebercracker is knocking on your machines. Run ISS to make
sure that all your machines are reasonably secure as far as remote
configuration (ie. your NFS exports and anon FTP site.)
Step 7. If you have done all of the following, you will have stopped 99%
of all uebercrackers. Congrads! (Remember, You are the admin.)
Step 8. Now there is one percent of uebercrackers that have gained
knowledge from reading some security expert's mail (probably gained access
to his mail via NFS exports or the guest account. You know how it is, like
the mechanic that always has a broken car, or the plumber that has the
broken sink, the security expert usually has an open machine.)
Step 9. Here is the hard part is to try to convince these security experts
that they are not so above the average citizen and that by now giving out
their unknown (except for the uebercrackers) security bugs, it would be a
service to Internet. They do not have to post it on Usenet, but share
among many other trusted people and hopefully fixes will come about and
new pressure will be applied to vendors to come out with patches.
Step 10. If you have gained the confidence of enough security experts,
you will know be a looked upto as an elite security administrator that is
able to stop most uebercrackers. The final true test for being a ueberadmin
is to compile a IRC client, go onto #hack and log all the bragging and
help catch the uebercrackers. If a uebercracker does get into your system,
and he has used a new method you have never seen, you can probably tell
your other security admins and get half of the replies like - "That bug
been known for years, there just isn't any patches for it yet. Here's my
fix." and the other half of the replies will be like - "Wow. That is very
impressive. You have just moved up a big notch in my security circle."
VERY IMPORTANT HERE: If you see anyone in Usenet's security newsgroups
mention anything about that security hole, Flame him for discussing it
since it could bring down Internet and all Uebercrackers will now have it
and the million other reasons to keep everything secret about security.
Well, this paper has shown the finer details of security on Internet. It has
shown both sides of the coin. Three points I would like to make that would
probably clean up most of the security problems on Internet are as the
following:
1. Vendors need to make security a little higher than zero in priority.
If most vendors shipped their Unixes already secure with most known bugs
that have been floating around since the Internet Worm (6 years ago) fixed
and patched, then most uebercrackers would be stuck as new machines get
added to Internet. (I believe Uebercracker is german for "lame copy-cat
that can get root with 3 year old bugs.") An interesting note is that
if you probably check the mail alias for "security@vendor.com", you will
find it points to /dev/null. Maybe with enough mail, it will overfill
/dev/null. (Look in manual if confused.)
2. Security experts giving up the attitude that they are above the normal
Internet user and try to give out information that could lead to pressure
by other admins to vendors to come out with fixes and patches. Most
security experts probably don't realize how far their information has
already spread.
3. And probably one of the more important points is just following the
steps I have outlined for Stopping a Uebercracker.
Resources for Security:
Many security advisories are available from anonymous ftp cert.org.
Ask archie to find tcp_wrapper, security programs. For more information
about ISS (Internet Security Scanner), email cklaus@shadow.net.
29 March, 2008
The most ancient language?
Example:
Mother in German : Mutter
In English: Mother
In Sanskrit : Mathrushree
Its been alleged that since people in western countries started eating meat, their toungues grew thick, and were unable to pronounce the words, and twisted them to give meaning.
28 March, 2008
Resume writing tips for your son!
2. Write the resume convincingly. His job here is to convince the employer that he knows something that the employer might be interested in.
3. Mention why hes interested in working for the employer, and what makes him competant for the job. Give the employer reasons as to why hes the best choice.
4. Is it because of money that you want him to join the job? or cause he wants to make a career. Either way, let him mention it straight forward. Theres nothing like a lil dose of honesty
5.Has he organized any events in college? Was he a very social person, and a team player? Mention that! Employers consider such qualities when selecting candidates.
6.Mention all his contact information, correctly.
7. Mention about his positive traits, and negative ones. Make sure to highlight the positive traits.
8. Prepare a different resume for every potential employer. This gives you the chance to tailor your resumes to each employer, and probably impress them.
9. The first impression is the best impression. Make sure he carries multiple copies of the resume.
Hope that answered it!
My technology blog: http://pcriddler.blogspot.com
27 March, 2008
Font change on social networking sites
add this in your profile, where HTML coding is enabled, and voila! you'll have your font change!
This seems to work with most social networking sites, which have html code enabled for user level profile editing
My technology blog:http://pcriddler.blogspot.com/
22 March, 2008
Random Numbers in Java
Java has a rich toolkit for generating random numbers, in a class named "Random".
This document is a quick guide to using Random. Random can generate many kinds
of random number, not all of which I discuss here.
The best way to think of class Random is that its instances are random number
generator objects -- objects that go around spitting out random numbers of various
sorts in response to messages from their clients.
Gaining Access to Random
Random is defined in the "java.util" library package, so any Java
source file that uses Random must begin with a line of the form
import java.util.Random;or
import java.util.*;Creating Random Number Generators
The easiest way to initialize a random number generator is to use the parameterless
constructor, for example
Random generator = new Random();However, beware of one thing when you use this constructor: Algorithmic random
number generators are not truly random, they are really algorithms that generate
a fixed but random-looking sequence of numbers. When you create a random number
generator, it initializes its sequence from a value called its "seed".
The parameterless constructor for Random uses the current time as a seed, which
is usually as good a seed as any other. However, the time is only measured to
a resolution of 1 millisecond, so if you create two random number generators
within one millisecond of each other, they will both generate exactly the same
sequence of numbers.
If you prefer, there is also a constructor for Random that allows you to provide
your own seed. You can use any long integer as a seed with this constructor.
Note that there is no magic way of picking "good" seeds. For example,
the following creates a random number generator with seed 19580427:
Random generator2 = new Random( 19580427 );Generating Random Integers
To generate a random integer from a Random object, send the object a "nextInt"
message. This message takes no parameters, and returns the next integer in the
generator's random sequence. Any Java integer, positive or negative, may be
returned. Integers returned by this message are uniformly distributed over the
range of Java integers. Here is an example, assuming that "generator"
is an instance of Random:
int r = generator.nextInt();Often, programmers want to generate random integers between 0 and some upper
bound. For example, perhaps you want to randomly pick an index into an array
of n elements. Indices to this array, in Java, range from 0 to n-1.
There is a variation on the "nextInt" message that makes it easy to
do this: If you provide an integer parameter to "nextInt", it will
return an integer from a uniform distribution between 0 and one less than the
parameter. For example, here is how you could use a random number generator
object to generate the random array index suggested a minute ago:
int randomIndex = generator.nextInt( n );Generating Random Real Numbers
Random number generators can also generate real numbers. There are several
ways to do so, depending on what probablity distribution you want the numbers
drawn from.
To generate a random real number uniformly distributed between 0 and 1, use
the "nextDouble" message. This message takes no parameters. For example...
double r = generator.nextDouble();To generate a random number from a normal distribution, use "nextGaussian".
This message takes no parameters and returns a random number from a normal distribution
with mean 0 and standard deviation 1. In layman's terms, this means that the
results may be either positive or negative, with both being equally likely;
the numbers will almost always have small absolute values (about 70% will lie
between -1 and 1, about 95% between -2 and 2). For example...
double r = generator.nextGaussian();Translating and Scaling Random Numbers
Random number generators often return numbers in some limited range, typically
0 to b for some upper bound b. Sometimes you need your
random numbers to lie in a different range. You can make random numbers lie
in a longer or shorter range by multiplying them by a scale factor (scaling).
You can make random numbers lie in a range that is shifted to higher or lower
numbers than the original by adding (or subtracting) an offset from the random
numbers (translating).
Here are some examples of these operations:
- Suppose you are writing a game program that simulates throwing dice, and
so need a random integer in the range 1 to 6. "nextInt" can give
you one in the range 0 to 5, and you can translate this to the range you need:
int throw = generator.nextInt(6) + 1;- In drawing a pattern made up of random lines, you want to pick a random
angle between 0 and 360 degrees at which to draw a line. The angle can be
any real number. The "nextDouble" message will give you a random
real number, but between 0 and 1. You can use scaling to turn this into a
real number between 0 and 360:
double angle = generator.nextDouble() * 360.0;- Suppose the same pattern-drawing program also needs to pick random lengths
for the lines, but that the lines should never be shorter than 10 units, nor
longer than 50. Line lengths can be any real number between these limits.
Thus you need random lengths from a 40-unit range starting at 10. You can
use scaling and translation together to generate these numbers from "nextDouble":
double length = generator.nextDouble() * 40.0 + 10.0;21 March, 2008
Computer Acronyms
AGP - Accelerated Graphics Port
ALI - Acer Labs, Incorporated
ALU - Arithmetic Logic Unit
AMD - Advanced Micro Devices
APC - American Power Conversion
ASCII - American Standard Code for Information Interchange
ASIC - Application Specific Integrated Circuit
ASPI - Advanced SCSI Programming Interface
AT - Advanced Technology
ATI - ATI Technologies Inc.
ATX - Advanced Technology Extended
--- B ---
BFG - BFG Technologies
BIOS - Basic Input Output System
BNC - Barrel Nut Connector
--- C ---
CAS - Column Address Signal
CD - Compact Disk
CDR - Compact Disk Recorder
CDRW - Compact Disk Re-Writer
CD-ROM - Compact Disk - Read Only Memory
CFM - Cubic Feet per Minute (ft�/min)
CMOS - Complementary Metal Oxide Semiconductor
CPU - Central Processing Unit
CTX - CTX Technology Corporation (Commited to Excellence)
--- D ---
DDR - Double Data Rate
DDR-SDRAM - Double Data Rate - Synchronous Dynamic Random Access Memory
DFI - DFI Inc. (Design for Innovation)
DIMM - Dual Inline Memory Module
DRAM - Dynamic Random Access Memory
DPI - Dots Per Inch
DSL - See ASDL
DVD - Digital Versatile Disc
DVD-RAM - Digital Versatile Disk - Random Access Memory
--- E ---
ECC - Error Correction Code
ECS - Elitegroup Computer Systems
EDO - Extended Data Out
EEPROM - Electrically Erasable Programmable Read-Only Memory
EPROM - Erasable Programmable Read-Only Memory
EVGA - EVGA Corporation
--- F ---
FC-PGA - Flip Chip Pin Grid Array
FDC - Floppy Disk Controller
FDD - Floppy Disk Drive
FPS - Frame Per Second
FPU - Floating Point Unit
FSAA - Full Screen Anti-Aliasing
FS - For Sale
FSB - Front Side Bus
--- G ---
GB - Gigabytes
GBps - Gigabytes per second or Gigabits per second
GDI - Graphical Device Interface
GHz - GigaHertz
--- H ---
HDD - Hard Disk Drive
HIS - Hightech Information System Limited
HP - Hewlett-Packard Development Company
HSF - Heatsink-Fan
--- I ---
IBM - International Business Machines Corporation
IC - Integrated Circuit
IDE - Integrated Drive Electronics
IFS- Item for Sale
IRQ - Interrupt Request
ISA - Industry Standard Architecture
ISO - International Standards Organization
--- J ---
JBL - JBL (Jame B. Lansing) Speakers
JVC - JVC Company of America
- K ---
Kbps - Kilobits Per Second
KBps - KiloBytes per second
--- L ---
LG - LG Electronics
LAN - Local Are Network
LCD - Liquid Crystal Display
LDT - Lightning Data Transport
LED - Light Emitting Diode
--- M ---
MAC - Media Access Control
MB � MotherBoard or Megabyte
MBps - Megabytes Per Second
Mbps - Megabits Per Second or Megabits Per Second
MHz - MegaHertz
MIPS - Million Instructions Per Second
MMX - Multi-Media Extensions
MSI - Micro Star International
--- N ---
NAS - Network Attached Storage
NAT - Network Address Translation
NEC - NEC Corporation
NIC - Network Interface Card
--- O ---
OC - Overclock (Over Clock)
OCZ - OCZ Technology
OEM - Original Equipment Manufacturer
--- P ---
PC - Personal Computer
PCB - Printed Circuit Board
PCI - Peripheral Component Interconnect
PDA - Personal Digital Assistant
PCMCIA - Peripheral Component Microchannel Interconnect Architecture
PGA - Professional Graphics Array
PLD - Programmable Logic Device
PM - Private Message / Private Messaging
PnP - Plug 'n Play
PNY - PNY Technology
POST - Power On Self Test
PPPoA - Point-to-Point Protocol over ATM
PPPoE - Point-to-Point Protocol over Ethernet
PQI - PQI Corporation
PSU - Power Supply Unit
--- R ---
RAID - Redundant Array of Inexpensive Disks
RAM - Random Access Memory
RAMDAC - Random Access Memory Digital Analog Convertor
RDRAM - Rambus Dynamic Random Access Memory
ROM - Read Only Memory
RPM - Revolutions Per Minute
--- S ---
SASID - Self-scanned Amorphous Silicon Integrated Display
SCA - SCSI Configured Automatically
SCSI - Small Computer System Interface
SDRAM - Synchronous Dynamic Random Access Memory
SECC - Single Edge Contact Connector
SODIMM - Small Outline Dual Inline Memory Module
SPARC - Scalable Processor ArChitecture
SOHO - Small Office Home Office
SRAM - Static Random Access Memory
SSE - Streaming SIMD Extensions
SVGA - Super Video Graphics Array
S/PDIF - Sony/Philips Digital Interface
--- T ---
TB - Terabytes
TBps - Terabytes per second
Tbps - Terabits per second
TDK - TDK Electronics
TEC - Thermoelectric Cooler
TPC - TipidPC
TWAIN - Technology Without An Important Name
--- U ---
UART - Universal Asynchronous Receiver/Transmitter
USB - Universal Serial Bus
UTP - Unshieled Twisted Pair
--- V ---
VCD - Video CD
VPN - Virtual Private Network
--- W ---
WAN - Wide Area Network
WTB - Want to Buy
WYSIWYG - What You See Is What You Get
--- X ---
XGA - Extended Graphics Array
XFX - XFX Graphics, a Division of Pine
XMS - Extended Memory Specification
XT - Extended Technology
20 March, 2008
"Seven Blunders of the World"
1.
Wealth without work
2. Pleasure without conscience
3.
Knowledge without character
4.
Commerce without morality
5.
Science without humanity
6. Worship without sacrifice
7.
Politics without principle
—Mahatma
Gandhi
19 March, 2008
Conversion of binary or decimal to hex
OK, 1,453,752 is 101100010111010111000 is binary, now we turn it into a Hex number.
First Hex numbers goes like this:
1=1
2=2
.
.
9=9
10=A
11=B
12=C
13=D
14=E
15=F
Now you need to take the first octet (the far right 4) and place it under this little grid:
8 4 2 1
--------
1 0 0 0 = 8
See the 1 under the 8 column?
That is what you add.
So the next octet is 1011, put it under the grid:
8 4 2 1
--------
1 0 0 0 = 8
1 0 1 1 = B
See 8+2+1=11, so you can't just say 11 you have to put it in a Hex number, which is B.
So the full Hex number of 1,453,752 is:
8 4 2 1
--------
1 0 0 0 = 8
1 0 1 1 = B
1 1 1 0 = E
0 0 1 0 = 2
0 1 1 0 = 6
0 0 0 1 = 1 <-- Just add zero if it isn't a full octet
162EB8
So if you want to turn a number in to the shorter version of Hex, just turn it into binary, then use this grid and you'll do fine
P.S. Thanks Korrupt for the number to work with

