This is the link I find in a phishing email.
http://%7a%68%61%6e%67%2e%6d%79%74%
77%2e%6e%65%74/
Average users can not tell what the % and codes after % mean. In fact, the sender is using the HEX value of ASCII characters. By looking at the ASCII table, the above link can be translated as : http://zhang.mytw.net
This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2006/08/09
2006/08/08
3-hour cycling class
CFC will host a big challenge cycling class on 19 August lasting for 3 hours. 85 bikes will be placed in the dance studio of Causeway Bay Club. There will be a 15-minute break for members to change their clothes or take some snack.
What should I bring to prepare for this challenge class ? Definitley 2 litres of water, 3 sports T-shirt and some energy bar. I surely need some energy bar because the whole class will help me to burn at least 2000 kcaloires.
What should I bring to prepare for this challenge class ? Definitley 2 litres of water, 3 sports T-shirt and some energy bar. I surely need some energy bar because the whole class will help me to burn at least 2000 kcaloires.
2006/08/07
rwhod
Strange. I remember that I have never installed or activated rwhod. On performing an Internet security scanning, this one appeared running and I have no idea if it was under xinetd. This was a highly vulnerable daemon which could result in buffer overflow.
What I could do is to chmod /usr/sbin/rwhod and /etc/rc.d/init.d/rwhod to make the binary and script not executable.
What I could do is to chmod /usr/sbin/rwhod and /etc/rc.d/init.d/rwhod to make the binary and script not executable.
2006/07/31
Because of you - Kelly Clarkson
This is a fantastic song filled with heart-breaking lyric. Just listen by heart and I am sure you will love it.
I will not make the same mistakes that you did and
I will not let myself cause my heart so much misery
I will not break the way you did
You fell so hard I've learned the hard way, to never let it get that far
Because of you I never stray too far from the sidewalk
Because of you I learned to play on the safe side so I don't get hurt
Because of you I find it hard to trust not only me, but everyone around me
Because of you...
I am afraid I lose my way
And it's not too long before you point it out I cannot cry
Because I know that's weakness in your eyes
I'm forced to fake a smile, a laugh erveryday of my life
My heart can't possibly break
When it wasn't even whole to start with
Because of you I never stray too far from the sidewalk
Because of you I learned to play on the safe side So I don't get hurt
Because of you I find it hard to trustNot only me, but everyone around me
Because of you...I am afraid
I watched you die I heard you cry every night in your sleep
I was so youngYou should have known better than to lean on me
You never thought of anyone else
You just saw your pain And now I cry
In the middle of the night For the same damn thing..
Because of youI never stray too far from the sidewalk
Because of you I learned to play on the safe side so I don't get hurt
Because of you I tried my hardest just to forget everything
Because of you I don't know how to let anyone else in
Because of you I'm ashamed of my life because it's empty
Because of you am afraid
Because of you....Because of you...you... mmmmmmmmmm.....
I will not make the same mistakes that you did and
I will not let myself cause my heart so much misery
I will not break the way you did
You fell so hard I've learned the hard way, to never let it get that far
Because of you I never stray too far from the sidewalk
Because of you I learned to play on the safe side so I don't get hurt
Because of you I find it hard to trust not only me, but everyone around me
Because of you...
I am afraid I lose my way
And it's not too long before you point it out I cannot cry
Because I know that's weakness in your eyes
I'm forced to fake a smile, a laugh erveryday of my life
My heart can't possibly break
When it wasn't even whole to start with
Because of you I never stray too far from the sidewalk
Because of you I learned to play on the safe side So I don't get hurt
Because of you I find it hard to trustNot only me, but everyone around me
Because of you...I am afraid
I watched you die I heard you cry every night in your sleep
I was so youngYou should have known better than to lean on me
You never thought of anyone else
You just saw your pain And now I cry
In the middle of the night For the same damn thing..
Because of youI never stray too far from the sidewalk
Because of you I learned to play on the safe side so I don't get hurt
Because of you I tried my hardest just to forget everything
Because of you I don't know how to let anyone else in
Because of you I'm ashamed of my life because it's empty
Because of you am afraid
Because of you....Because of you...you... mmmmmmmmmm.....
2006/07/30
Being beautiful is nothing next to feeling beautiful
I find these words printed in some Yoga mat :
"Being beautiful is nothing next to feeling beautiful."
What does that mean ? I will find it out.
"Being beautiful is nothing next to feeling beautiful."
What does that mean ? I will find it out.
2006/07/29
Sony VGN-UX90PS
Sony UX90PS can be claimed as the world smallest PC. This is the most attractive notebook PC I have ever seen so far.
Take a look at the config :
CPU : Intel Core Solo 1.2 GHz
Drive : 16 GB Flash Drive
Memory : 512 MB
Display : 1024 x 600 SVGA
Weight : 498 grams
Standard battery run-time : 3 hours
The weakest part is the battery which can only run for 3 hours. A fully charged standby battey is definitely needed for using this smallest PC on the move.
2006/07/27
php-mysql
I tried to install phpBB2 and the installation script prompted me that my php 5.0 version was not compiled with mysql database.
What a surprise ! In PHP4 and earlier versions, by default, it was compiled with mysql. Woo, I tried to search for work around solutions and some people suggest rpm removing php and mysql and re-install php with mysql compiled. This would be a great trouble.
After some deliberations, I realized that what I needed was the rpm of php-mysql packages. Hey, I did not want to trust rpm anymore because it would probably give dependencies failed and asked me to download other necessary shared libraries or utilities. A more direct and simple method was to yum install php-mysql which should take care of both versions and dependencies.
It worked. Thanks to great yum.
What a surprise ! In PHP4 and earlier versions, by default, it was compiled with mysql. Woo, I tried to search for work around solutions and some people suggest rpm removing php and mysql and re-install php with mysql compiled. This would be a great trouble.
After some deliberations, I realized that what I needed was the rpm of php-mysql packages. Hey, I did not want to trust rpm anymore because it would probably give dependencies failed and asked me to download other necessary shared libraries or utilities. A more direct and simple method was to yum install php-mysql which should take care of both versions and dependencies.
It worked. Thanks to great yum.
2006/07/24
Disable root login in sshd
People say that root login should be disabled in sshd. From security point of view, it is totally understandable as I have seen bad guys connecting to port 22 to try root password. But if the ssh port number can be hidden or changed to other alien port, it might not be necessary to disable root login.
I myself would like to use root login in sshd which does not binded to port 22. The reason is that even if a normal user can su to get root access via ssh, the working directory paths are not the same.
This is the working paths of root account using su :
/usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/bin:
/bin:/usr/bin:/usr/X11R6/bin:
and the following is the working paths of root account by direct login :
/usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:
/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:
Of course, the latter one provides much more convenience as I can invoke system commands or utilitiy only accessed by root account at any directory path. Unlike the latter, the former requires me to only issue the command ./ifconfig after I changed to /usr/sbin or I have to use : /usr/sbin/ifconfig
I myself would like to use root login in sshd which does not binded to port 22. The reason is that even if a normal user can su to get root access via ssh, the working directory paths are not the same.
This is the working paths of root account using su :
/usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/bin:
/bin:/usr/bin:/usr/X11R6/bin:
and the following is the working paths of root account by direct login :
/usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:
/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:
Of course, the latter one provides much more convenience as I can invoke system commands or utilitiy only accessed by root account at any directory path. Unlike the latter, the former requires me to only issue the command ./ifconfig after I changed to /usr/sbin or I have to use : /usr/sbin/ifconfig
2006/07/21
Seagate hard disk
In the past decade, I purchased 4 sets of Seagate hard disks. Seagate disk drives are notorious for generating noise and heat. Forget about these bad designs, all of the drives I purchased experienced failure after used for 2 or 3 years. Seagate hard disks are not my choice anymore. The best I can think of is IBM hard drive, and it is now re-branded as Hitachi.
2006/07/18
2006/07/14
Smart Antenna
Look at this new set of Linksys WLAN AP. The whole antenna array looks very smart. Actually Linksys has used smart antenna technology to boost the coverage and throughput.
Linksys claims coverage will be increased by 4 times while throughput will be boosted by 12 times. I have no doubt of the 4 times increase in coverage but 12 times increase in throughput is far beyond my expectation and imagination. Prove it, Linksys ?
2006/07/12
named in chroot environment
In past versions of named without chroot, named.conf is placed in /etc/ while zone records are placed in /var/named/.
In chroot operation, where are the default paths for named.conf and zone records. The config file name.conf should be in /var/named/chroot/etc/ while zone records are in /var/named/chrootvar/named/.
Difficult to remember the long string of the default paths. I'd better write them down onto a notebook.
In chroot operation, where are the default paths for named.conf and zone records. The config file name.conf should be in /var/named/chroot/etc/ while zone records are in /var/named/chrootvar/named/.
Difficult to remember the long string of the default paths. I'd better write them down onto a notebook.
2006/07/11
DocumentRoot
Network administrators are lazy. In building up web servers, they tend to use the default Document Root. In IIS, it is c:\inetpub\wwwroot\ and in Apache, it is /var/www/html. In case a web server is comppromised, hackers can build bogus web sites by following the Document Root to put the source files. This can be properly circumvented if the Document Root of a web server is different from the default settings.
2006/07/10
Phasing out of 3.5-inch floppy drive
I find that these days many people do not like to install a 3.5-inch floppy drive on their PC. The reason is that with 1.4 MB storage space, a floppy diskette can not serve any useful purpose, even not large enough for copying one single file. USB flash should provide much more convenience than floppy diskette. Other would use ftp account for copying temporary files or transferring to other machines.
So what are we going to do with the floppy drive slot on the case. Oh yeah.. it could be best used for card reader. We are not wasting any available space in the case.
So what are we going to do with the floppy drive slot on the case. Oh yeah.. it could be best used for card reader. We are not wasting any available space in the case.
2006/06/29
Body Combat 28 Tracks
I have been searching for BC28 tracks for some time but can not get a full list. Yesterday, I came across a site that gave the name of all the tracks :
01 - Listen To Your heart - ColorBox / Trouble - Pink
02 - The Final Countdown - HeavyDance
03 - Come With Me (Hixxy Remix) - Special D
04 - Push It Again - Dj Lawless Vs Oliver Swab
05 - Hymn - Tina Cousins
06 - Hung Up - SBI
07 - Fight - KopyKatz
08 - Reach Out - Maximum
09 - Switch - Will Smith
10 - Because Of You - Kelly Clarkson
The best I love in BC 28 are track 1,3,5 and 7. I guess BC29 will be released in early August.
01 - Listen To Your heart - ColorBox / Trouble - Pink
02 - The Final Countdown - HeavyDance
03 - Come With Me (Hixxy Remix) - Special D
04 - Push It Again - Dj Lawless Vs Oliver Swab
05 - Hymn - Tina Cousins
06 - Hung Up - SBI
07 - Fight - KopyKatz
08 - Reach Out - Maximum
09 - Switch - Will Smith
10 - Because Of You - Kelly Clarkson
The best I love in BC 28 are track 1,3,5 and 7. I guess BC29 will be released in early August.
2006/06/28
client port number
I always have the concept that client ports are from 1024 up to 65535. This is not correct. Only Windows machines use starting client port number of 1024. All Unix/Linux flavours have client ports starting from 32768. I have tested this using tcpdump on a Linux box.
Another interesting name related to this is ephermeral port which can mean port assigned temporarily to client.
Just wonder if Windows and Unix/Linux machines are on the same network segment, are there any special requirements or conflicts on firewall to manage traffic in the outbound direction as they are using different port number ranges. I guess NOT.
Another interesting name related to this is ephermeral port which can mean port assigned temporarily to client.
Just wonder if Windows and Unix/Linux machines are on the same network segment, are there any special requirements or conflicts on firewall to manage traffic in the outbound direction as they are using different port number ranges. I guess NOT.
2006/06/26
Error 404 web page
Browsers have ugly information pages presented to users for error 404 (Page Not Found). It is a good practice for webamsters to create their own 404 error handling page such that some basic information can be presented to visitors why the page are not found or they have mis-typed URLs spelling.
Mine is simple with a straight forward message, no graphic :
"Woops ... The page you request can not be found.
Please make sure you type the URLs with correct spelling. Good luck, friend...."
In Apache, the directive for this task in httpd.conf is in the line :
ErrorDocument 404 /errors/custom404.html
Mine is simple with a straight forward message, no graphic :
"Woops ... The page you request can not be found.
Please make sure you type the URLs with correct spelling. Good luck, friend...."
In Apache, the directive for this task in httpd.conf is in the line :
ErrorDocument 404 /errors/custom404.html
2006/06/23
low cost server co-location service
A data center offers 1/4 rack for server co-location services with 8 IP addresses and only charge HK$1,500 per month. I read carefully about the service level and spot this :
- 99.5% Uptime Guarantee:
- Proactive 24 X 7 monitoring system:
- Redundant power supplies:
- UPS Power Failure Backups:
- Multi Internet Backbones (Network Redundancy):
How can a data center only offer 99.5 % uptime guarantee.
This translates to 1.83 days or 44 hours in a year where service will not be available.
I can not accept such a service level.
- 99.5% Uptime Guarantee:
- Proactive 24 X 7 monitoring system:
- Redundant power supplies:
- UPS Power Failure Backups:
- Multi Internet Backbones (Network Redundancy):
How can a data center only offer 99.5 % uptime guarantee.
This translates to 1.83 days or 44 hours in a year where service will not be available.
I can not accept such a service level.
2006/06/22
yum port number
I am not sure which port number yum rides on. This triggers me to conduct a netstat test while doing yum installing packages.
Great, it works on port 80. Users need not worry that they will not be able to update or install packages since all ISPs allow port 80 in the outgoing direction. The same applies to icq, instant messages over port 80 and there is no need to worrying about firewall blocking.
Great, it works on port 80. Users need not worry that they will not be able to update or install packages since all ISPs allow port 80 in the outgoing direction. The same applies to icq, instant messages over port 80 and there is no need to worrying about firewall blocking.
2006/06/17
L7 filter and bandwidth manager
Just when I think iptables is the most powerful tool in Linux, then comes L7 filter. The name itself is interesting and L7 means Layer 7, the application layer. With L7 filter, one can turn a Linux box into a bandwidth manager thereby offering QoS, priority and queuing of traffic. Commercial grade bandwidth manager costs at least HK$100k.
Since it works in the application layer, every single packet will be analyzed. It eats up significant resources. The CPU must be fast and there must be large memory to support L7.
Since it works in the application layer, every single packet will be analyzed. It eats up significant resources. The CPU must be fast and there must be large memory to support L7.
Subscribe to:
Posts (Atom)