Pages

Showing posts with label Computers. Show all posts
Showing posts with label Computers. Show all posts

Thursday, May 10, 2012

Eject the Warp Core: A practical look at filesystem segregation and encryption.

Here's my presentation I gave at Ohio InfoSec Forum today about the "Ejectable Core Backtrack Machine" and how filesystem segregation and encryption can help keep your data out of the wrong hands.

To get the full experience, open up the speaker notes to read along with what I'll be saying. It won't replace actually being there, but hopefully it'll help you grasp the concepts.

Future considerations (from InfoSec):

  • tmpfs instead of /tmp
  • Find a way to disable direct memory access on the kernel level (firewire and PCI can exploit this)


Thursday, October 27, 2011

Kodingen


As a coder, I've never found cloud-based IDEs to be very useful. Sure, its a great idea, all of your data and project work accessible from any location and securely stored. It sounds like the perfect development environment. I had played around with Cloud9IDE, but I never felt that they were getting it quite right, they had moved in a good direction, but their scope was too limited. I didn't just want to store my open source projects in the cloud, I wanted shell and FTP access, I wanted a small hosting platform for testing, I wanted the ability to share and publish my creations at will. No cloud IDE could give me that... until now.

Enter: Kodingen. Kodingen is a web developer IDE, plus FTP server, plus SVN/Git/CVS host, plus web host, plus platform. Its hard to describe all the things Kodingen does, or... will do, rather. Lets get that point out of the way first. The first thing you should keep in mind when building things on Kodingen is that it is a beta platform. Work has been progressing fairly rapidly as they gear up for their big stable release, but in using this as a development platform, you'll run into things that just aren't built yet. For instance, the integrated domain purchasing/linking: I have no idea how this will work in the future, it looks like a good idea, but the final product has yet to be released. As far as version control systems go, don't count on it just yet, those are still in development. For every feature that Kodingen has, there's another feature that just isn't finished yet. I don't really see this as a downside, however, instead, I feel very excited for what the future holds.

For a very-much-in-beta project, Kodingen is one of the slickest HTML5 applications I've laid eyes on. Everything slides in panels, smooth animations permeate every little thing, right click menus are abound and easy to use, and the interface is extremely clean for how powerful it is. They rely on a bunch of open source tools and technologies, which is a huge benefit for them (no licensing) and for their users (we can move away if we want). The major gripe I have is that we haven't heard from the developers in quite a while, the last public post was from March 16th. When you get into the backstory of the project, though, you can't really fault the guys. Kodingen was built from savings, without investors, without VC funding, without Techcrunch Distrupt or the LAUNCH conference. This incredibly useful, incredibly cool project was built by a very small team of developers with their own money. Very cool.

One thing that I wish worked now was the ability to pay for an account, out of all the features to lock out in the beta, I was initially surprised this was one of them. When thinking about it, you wouldn't want people paying for a half-baked, unfinished product, though. These guys are smart, they aren't greedy, and they know how to make their users happy. Progress is slow, but the site is fast and stable, and I'm sure when they finally release 1.0, its going to make a lot of people happy (and hopefully make them a lot of money as well). In the mean time, why don't you sign up for the free account over at https://kodingen.com and consider throwing these guys some dough if you like what you see.

Tuesday, September 27, 2011

Ghost in the Wires - A book by Kevin Mitnick


Disclaimer: Above image links to Amazon with my affiliate code.
If you buy the book from the above link, I'll get a buck or two.

Just finished reading a wonderful book by Kevin Mitnick, hacker extraordinaire! As some of you may know, Kevin Mitnick was a fugitive hacker who ran for years and taught us all about social engineering, how to effectively use zero-day exploits, but most of all, how hackers need to target people first, computers second. In this book, Kevin is finally able to write about his firsthand experiences running from the law, compromising administrators and systems, and going into some great technical detail at the same time.
The very first thing you'll notice about this book is that it reads like a spy novel. Twists and turns! Backstabbing! RHosts files! Its all in here.
The book contains technical bits for those who 'get them' (I do! I do!), but the story is completely comprehensible to anyone without any technical experience whatsoever, thanks to Mitnick's brilliant writing style. If you've read any other books concerning this tale, you'll get the other perspective, straight from the source. It isn't a very deep book and should be looked upon as a spy-novel dealing with computer hackers. Its fun, its a ride, its about 400 pages, but it is a popcorn-style book. Have fun and run through this, I enjoyed it.

Friday, May 6, 2011

Why the Academic World is a Steaming Pile of Shit (For CS Majors)

Ah, school! Teaching me the most worthless things ever! Check this out, actual comment from one of my programming projects:

"Create your own sort. Don't use one that's in the API. (-5)"

Huh... Strange... At my job, what would happen if I re-wrote a piece of code specifically designed to be convenient and save time (thus, money)?

I'd get fired.


This is exactly why Academica is worthless for people in my field: Complete lack of perspective and field experience. If I walked up to my boss and said, "Hey, Boss! I'm going to re-do the work that Sun Microsystems already did for me by re-writing perfectly good API calls because I don't want to feel lazy! Oh, and you'd be paying me for these extra hours!", he'd fire my ass on the spot (and rightfully so).

Here's a cool academic exercise: Write a simple Twitter app (Using the given APIs), then make it work on Android. Its cool. Its relevant. Its academic. Its learning and experience.
Don't make me re-invent the wheel, college... Some motherfucker did that for me so I wouldn't have to. I'm not paying you gobs of money to duplicate the work that others have done before me, I'm paying you gobs of money to stand on the shoulder's of giants and build into the sky.

Tuesday, March 29, 2011

Chrome OS Bootable Flash Drive! (Built on: 3/28/2011)


Well, here it is again! Another build, this one a week later. I've heard some reports that the Chrome Web Apps weren't working quite perfectly on some machines, that's the risk when you're running daily-builds of an operating system. This is freshly built as of yesterday, and I've update the instructions to include how to create a bootable Chrome OS flash drive in both Linux and Mac OSX. As usual, the Windows instructions are still there as always. After the jump, I'll include a copy/paste of the Instructions.txt file for your convenience. Have fun and let me know what you think!

Chrome OS - 032811.7z

Credits and Utilities:
To unpack this file, you will need the totally awesome and free unzipping utility: 7zip
This pack contains the Image Writer for Microsoft Windows, which is a great, simple way to take or place images onto drives. Give these guys a hand!

Thursday, March 24, 2011

Chrome OS Bootable Flash Drive! (Built on: 3/24/2011)



I've taken to packaging my own vanilla builds of Chrome OS (Well... Chromium OS), and am going to start releasing them semi-regularly. Comes packed with the great Image Writer for Microsoft Windows (https://launchpad.net/win32-image-writer) and stupid-simple instructions on getting a bootable flash drive made to test drive Chrome OS. Ever since Hexxeh stopped major development (that I've seen, correct me if I'm wrong), I've been listening to people clamor for an easy way to test drive Chrome OS without having to build from the source code up. I want to help those people. Every so often, I will make a build of Chrome OS and post it here to my blog. Enjoy!!

This file is packed with 7-zip! The completely free (and open source) zipping utility! Grab it here: http://www.7-zip.org/
Chrome OS - 032111.7z - ~120MB
New Version Here

Saturday, July 10, 2010

Fedora 13


Recently, I've changed Linux distributions to Fedora for my main netbook distribution. Coming from a pretty strict regimen of Debian/Ubuntu for a very long time (after moving from SuSE some years ago), I always had a fond love of Debian-based systems, so I was a bit wary about going back to RPM systems (especially after the terrible time I had dealing with YaST). I'm happy to announce that I really do like what Fedora 13 brings to the table. Installation was wonderful, even better than Ubuntu 10.04's install, and even YUM isn't too bad to work with. From the get-go, Fedora 13 let me have full-drive encryption, something that you only get with the text-based Ubuntu alternate installer. To satisfy my full-drive-encryption requirement, I had to fight with the alt-installer for Ubuntu for quite a bit before I worked out a complicated workflow to get all the partitioning set up just the way I like it. Needless to say, it was a total pain in the ass to get working just right with Ubuntu. Just the opposite experience with Fedora 13, it was painless and easy, using the "Standard" installer, Fedora's install just gave me an encryption radio-button and all the necessary dialogs.
Using the system is just as much of a joy. You get a standard Gnome desktop, as usual, but with a bit more focus on enterprise options and business-like settings. With Ubuntu being the most widely-used Desktop distribution, the majority of development will done on that platform, which made some software utilities a bit different to install, but absolute worst case: You download the code and compile it yourself. Not too complicated at all. Fedora seems to run with a bit of a speed-boost as well. Ubuntu always felt like it was dragging its feet on my netbook, but I've had just the opposite reaction to Fedora 13: It really is quite speedy. Linux distributions are all a bit fuzzy in how different they really are from each other, but in my mind, that's a positive point. I don't have to re-learn everything, I can take what I've done with my customized Ubuntu boxes and apply the same theory and logic to Fedora. Having distributions built on one standardized kernel is what makes Linux great.
Bottom Line: If you're looking for a bit of a change in your daily use, want a speed-boost, or are looking for really easy encryption options, give Fedora 13 a shot, you'll be glad that you did.

Friday, May 28, 2010

The Dangers of Relying on "Vendorware"

In my experience, most businesses have a major reliance on Vendor Software. In case you don't know what vendor software is, let me take a quick minute to explain it (If you know already, skip the to the next paragraph). Vendor software is a software package that large businesses/organizations either lease out (on contract) or buy from a software vendor. These software packages can come with bundled software support, so if a problem were to arise, the business could call the software developers and obtain support and backup on a particular problem. This support isn't free, most of the time, and on occasion, not very helpful. The businesses that choose to implement 'vendorware' are usually lacking in staffing, technical ability, or both. Vendor software can give confidence to an otherwise technically-inexperienced business. That is the selling point, at least.
But this isn't to say vendorware is without its flaws. By the very nature of purchased, leased, or contractually-bound software, there are many many pitfalls a business can (and should expect) to encounter.

Monday, July 13, 2009

Tutorials?




Looking for new content to write about. I've got an amount of time in my day that I'd like to spend ranting, raving, and explaining about various projects I've got on my plate. Only one problem: I have no idea where to begin. That's why I need you to tell me. What do you want to read about? It could be anything from, "I want to build a media server" to "How to synchronize various folders/disks/filesystems easily" to "I want to make a DOOM server". Anything that's doable and you think I could be pretty apt at explaining. Remember, Linux is a plus, but anything that works across multiple operating systems is great too. I could even cover programs or general "I want to do this..." computer questions. Leave a comment! Go! Its up to you now.
I'm just letting you know... we're counting on you.

Wednesday, April 22, 2009

When is Good?

Have you ever wanted an easy way to set up a time to meet somewhere, do a project, plan a big dinner, or just about anything else that involves a group of people with busy schedules? If your group is part of the digital age, plan your next dinner party/act of terrorism with When is Good. A very simple site, but it does the best job of getting you an answer with the least amount of hassle, you don't even have to register!
First: Choose some dates and times that work for you by clicking them.
Next: Write down your super secret code (remember, you don't have to register!).
Then you'll receive some links to throw around. Need to change the event? No problem! Just be warned though... any already submitted responses will be deleted. Send the invites off and wait for everyone to chime in!
When you get responses, When is Good will bring up a helpful little chart of who can and can't make it.

If your invitees leave comments, you'll be able to see those as well with a mouseover.
Click on a day, and a synopsis of who can and can't make it will pop up. Leaving you the amazing task of who you should leave behind.
And that concludes the screenshot tour of "When is Good" . A simple little web app that comes in handy just often enough to be of use.

Tuesday, February 3, 2009

Pipl - The People Search Engine

    By now you all know that courts make their records public for those over the magical age of 18. If you've ever received a speeding ticket, you're in a publicly accessible internet database with the charge plastered all over some webpage. But how much information is truly out there about you? And more importantly, how easily accessible is it? If you've ever googled your name, you've either been totally creeped out, or more likely, reassured. Google does a lot of things very well, the one thing they suck at is people search. I can search all day on Google for Tom Webster, and I think I'm the 18th on the list. Not bad... but most everything else in the search results are not me. Granted.. those with a more common name will be harder to search out, but Google doesn't index court records, and if they do, they don't do it very well. Pipl (pronounced "people") is more than just a public records search engine, its (as the name implies) a search engine if you're looking for one thing and one thing only: A person. Pipl searches not only court records, but they also search public government databases, tons of social networking websites, photo websites (such as flickr), LexisNexis, Amazon.com public wish lists, and many other places to grab information about a particular person. Its an absolutely amazing tool if you're an employer, and a terrifying tool if you're a person who's running from what's available in the public record. Pipl is a wonderful technical achievement for making information more easily accessable, but its also a bit unnerving. I have a FriendFeed Profile which I laughably nickname "Stalker 2.0", but its never quite revealed this much information. Again.. the less common the search term, the better results you'll get. Try it out! I'm sure you'll be digging up terrible family secrets in no time!