神舟五號返回艙,現安放在太古城中心展出。單看外型和艙面金屬嚴重燒焦,已知 強國航天技術嚴重落後。算把啦,倒不如將研究經費改善民生吧!
This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2012/06/23
2012/06/20
802.11n or Powerline Ethernet Adaptor
I note that powerline ethernet adpators
which some body call them as homeplug can now support 500 Mbps and 1000
Mbps. This is much better than 802.11n
WiFi connection. The best I can get from 802.11n at home is always below 30 Mbps though
the specification states the client can have a maximum speed of 300 Mbps. If the throughput of ethernet adpators is reduced
to half due to cable length or noise, the offered speed of 250 Mbps - 500 Mbps
is still far superior than the best WiFi devices. It is now the right time to
consider replacing 802.11n by powerline ethernet.
2012/06/17
IPv6 Router Advertizement Attack
I heard the IPv6 router advertizement attack
almost a year ago but did not jot it down in writing. Here it is. A single
Windows 7 machine can make all Windows machines in a local area network not
workable by flooding bogus RA messages with many bogus source addresses. Only about 20 seconds of flooding is capable
of doing great harm. The CPU usage of all machines are approaching 100 % and
then hang up
Microsoft has indicated that no patches
will be released to rectify this bug but Windows 8 will have this problem
removed. In other words, there is no
cure from the OS side. Shame on Microsoft.
For those organisations that need to use
IPv6 RA for address assignment, they should use an Ethernet switch with RA
guard.
Good luck to those who allow RA in their
internal network.
2012/06/13
Interactions of ntpdate with DNS round robin
To follow up on my last post of ntpdate interactions with DNS round robin, I wanted to find if the shortest path fails, whether ntpdate will take the second path as backup. The answer is affirmative. I have tested it with firewall blocking the reachability of the shortest path. Some captures are given below for reference.
Test : 118.143.17.82 is blocked by firewall to stimulate the shortest path failure
# ntpdate -4 time.hko.hk
13 Jun 08:53:48 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:49 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:50 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:51 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:52 ntpdate[3578]: adjust time server 223.255.185.2 offset -0.000177 sec
More details by :
#ntpdate -4 -d time.hko.hk
13 Jun 09:01:15 ntpdate[3699]: ntpdate 4.2.4p5@1.1541-o Wed Oct 8 11:22:55 UTC 2008 (1)
Looking for host time.hko.hk and service ntp
host found : 118.143.17.82
transmit(118.143.17.82)
13 Jun 09:01:15 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
transmit(118.143.17.82)
13 Jun 09:01:16 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
13 Jun 09:01:17 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
13 Jun 09:01:18 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
118.143.17.82: Server dropped: no data
server 118.143.17.82, port 123
stratum 0, precision 0, leap 00, trust 000
refid [118.143.17.82], delay 0.00000, dispersion 64.00000
transmitted 4, in filter 4
reference time: 00000000.00000000 Thu, Feb 7 2036 14:28:16.000
originate timestamp: 00000000.00000000 Thu, Feb 7 2036 14:28:16.000
transmit timestamp: d38264de.bd2b5c2c Wed, Jun 13 2012 9:01:18.738
filter delay: 0.00000 0.00000 0.00000 0.00000
0.00000 0.00000 0.00000 0.00000
filter offset: 0.000000 0.000000 0.000000 0.000000
0.000000 0.000000 0.000000 0.000000
delay 0.00000, dispersion 64.00000
offset 0.000000
server 223.255.185.2, port 123
stratum 1, precision -19, leap 00, trust 000
refid [GPS], delay 0.03297, dispersion 0.00114
transmitted 4, in filter 4
reference time: d38264db.09591159 Wed, Jun 13 2012 9:01:15.036
originate timestamp: d38264db.fb344598 Wed, Jun 13 2012 9:01:15.981
transmit timestamp: d38264db.fa50e9ce Wed, Jun 13 2012 9:01:15.977
filter delay: 0.04730 0.03297 0.03494 0.03299
0.00000 0.00000 0.00000 0.00000
filter offset: 0.006902 -0.00027 0.000801 -0.00029
0.000000 0.000000 0.000000 0.000000
delay 0.03297, dispersion 0.00114
offset -0.000275
13 Jun 09:01:19 ntpdate[3699]: adjust time server 223.255.185.2 offset -0.000275 sec
***** End of Capture ******
As can be seen, "ntpdate -4 -d time.hko.hk" will first establish handshakes with all available IP addresses to determine which one is the best for time sync. If the best IP address is broken, the other will be taken up.
# ntpdate -4 time.hko.hk
13 Jun 08:53:48 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:49 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:50 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:51 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:52 ntpdate[3578]: adjust time server 223.255.185.2 offset -0.000177 sec
More details by :
#ntpdate -4 -d time.hko.hk
13 Jun 09:01:15 ntpdate[3699]: ntpdate 4.2.4p5@1.1541-o Wed Oct 8 11:22:55 UTC 2008 (1)
Looking for host time.hko.hk and service ntp
host found : 118.143.17.82
transmit(118.143.17.82)
13 Jun 09:01:15 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
transmit(118.143.17.82)
13 Jun 09:01:16 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
13 Jun 09:01:17 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
13 Jun 09:01:18 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
118.143.17.82: Server dropped: no data
server 118.143.17.82, port 123
stratum 0, precision 0, leap 00, trust 000
refid [118.143.17.82], delay 0.00000, dispersion 64.00000
transmitted 4, in filter 4
reference time: 00000000.00000000 Thu, Feb 7 2036 14:28:16.000
originate timestamp: 00000000.00000000 Thu, Feb 7 2036 14:28:16.000
transmit timestamp: d38264de.bd2b5c2c Wed, Jun 13 2012 9:01:18.738
filter delay: 0.00000 0.00000 0.00000 0.00000
0.00000 0.00000 0.00000 0.00000
filter offset: 0.000000 0.000000 0.000000 0.000000
0.000000 0.000000 0.000000 0.000000
delay 0.00000, dispersion 64.00000
offset 0.000000
server 223.255.185.2, port 123
stratum 1, precision -19, leap 00, trust 000
refid [GPS], delay 0.03297, dispersion 0.00114
transmitted 4, in filter 4
reference time: d38264db.09591159 Wed, Jun 13 2012 9:01:15.036
originate timestamp: d38264db.fb344598 Wed, Jun 13 2012 9:01:15.981
transmit timestamp: d38264db.fa50e9ce Wed, Jun 13 2012 9:01:15.977
filter delay: 0.04730 0.03297 0.03494 0.03299
0.00000 0.00000 0.00000 0.00000
filter offset: 0.006902 -0.00027 0.000801 -0.00029
0.000000 0.000000 0.000000 0.000000
delay 0.03297, dispersion 0.00114
offset -0.000275
13 Jun 09:01:19 ntpdate[3699]: adjust time server 223.255.185.2 offset -0.000275 sec
***** End of Capture ******
As can be seen, "ntpdate -4 -d time.hko.hk" will first establish handshakes with all available IP addresses to determine which one is the best for time sync. If the best IP address is broken, the other will be taken up.
2012/06/12
DNS round robin has no effect on ntpdate
Just found out that if a NTP server has 2 IPaddresses, when clients conduct time sync with the NTP server, the IP address with lower delay will be used. That is to say, ntpdate has intelligence to to sync with an IP address with minimal delay. The effect is that ntpdate overrides DNS round robin rule. To me, this is a new finding.
Here is the example I used for time.hko.hk. When doing a ping by hostname, both IP addresses can be selected one by one. However, when doing ntpdate, only one IP address will be selected.
#ping time.hko.hk
PING time.hko.hk (118.143.17.82) 56(84) bytes of data.
^C
--- time.hko.hk ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1828ms
[warren@dnssec ~]# ping time.hko.hk
PING time.hko.hk (223.255.185.2) 56(84) bytes of data.
^C
--- time.hko.hk ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1137ms
# ntpdate -4 time.hko.hk
12 Jun 13:31:57 ntpdate[24994]: adjust time server 118.143.17.82 offset 0.000340 sec
# ntpdate -4 time.hko.hk
12 Jun 13:31:59 ntpdate[24995]: adjust time server 118.143.17.82 offset -0.000125 sec
Here is the example I used for time.hko.hk. When doing a ping by hostname, both IP addresses can be selected one by one. However, when doing ntpdate, only one IP address will be selected.
#ping time.hko.hk
PING time.hko.hk (118.143.17.82) 56(84) bytes of data.
^C
--- time.hko.hk ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1828ms
[warren@dnssec ~]# ping time.hko.hk
PING time.hko.hk (223.255.185.2) 56(84) bytes of data.
^C
--- time.hko.hk ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1137ms
# ntpdate -4 time.hko.hk
12 Jun 13:31:57 ntpdate[24994]: adjust time server 118.143.17.82 offset 0.000340 sec
# ntpdate -4 time.hko.hk
12 Jun 13:31:59 ntpdate[24995]: adjust time server 118.143.17.82 offset -0.000125 sec
2012/06/07
Use of gogoCLIENT after 6 June 2012
I like to remind users in Hong Kong who are using gogoCLIENT to access IPv6 and dual-stack websites. After 6 June 2012, GogoCLIENT makes your Windows 7 quite slow in accessing dual-stack websites like Google, Facebook and Yahoo as the nearest tunnel gateway of freenet6.net is in Taiwan. Yes, that is the reality for accessing dual-stack websites but same speed for accessing pure v4 website, still very slow for pure v6 websites. If is up to users to judge if they still want to use gogoCLIENT.
If you have an IPv6 ready router such as D-Link and Linksys, please use router-based 6in4 tunnel with an user account with Hurricane Electric. Since HE has 6in4 gateway in HK with high bandwidth, the v6 speed should be quite OK.
GogoCLIENT is widely used in Taiwan because all major ISPs there have their TSP tunneling gateway. Taiwan users who want access to v6 network can apply to their ISP for a user account. The v6 speed of course is OK unlike the case of Hong Kong whereby users must connect to Taiwan and then to other parts of the world.
If you have an IPv6 ready router such as D-Link and Linksys, please use router-based 6in4 tunnel with an user account with Hurricane Electric. Since HE has 6in4 gateway in HK with high bandwidth, the v6 speed should be quite OK.
GogoCLIENT is widely used in Taiwan because all major ISPs there have their TSP tunneling gateway. Taiwan users who want access to v6 network can apply to their ISP for a user account. The v6 speed of course is OK unlike the case of Hong Kong whereby users must connect to Taiwan and then to other parts of the world.
2012/06/06
World IPv6 Launch
Today is 6 June 2012 which is named as the World IPv6 Launch by the Internet community. A new era has just begun on the Internet starting from 6 June 2012. Thanks to Google, Yahoo, Facebook, Comcast, Cisco, D-Link and many other companies and organisations that support the new protocol. Enjoy IPv6.
2012/05/31
Windows XP and IPv6
I am helping an organization to write a 40-page consumer guide on IPv6. One sub-section deals with IPv6 in Windows XP and its limitations. This is what I have come up with today.
"While IPv6 functionality is present in Windows XP, it is not suitable for use in a corporate network environment. The following limitations are found in Windows XP in support of IPv6:
"While IPv6 functionality is present in Windows XP, it is not suitable for use in a corporate network environment. The following limitations are found in Windows XP in support of IPv6:
1. There is no graphical user interface for address assignment and these
tasks must be performed at command line.
2.
There is no DHCPv6 client in Windows XP. An IPv6 router can only use
Stateless Address Autoconfiguration (SLAAC) to assign address to a Windows XP
PC.
3.
Privacy protection mechanism in address assignment through SLAAC is not
enabled by default. Activity tracking based on the IPv6 address is possible
4.
The personal firewall of Windows XP is broken when IPv6 is installed.
When a port is open in IPv4, the same port is also open in IPv6.
5.
Windows XP can not have name resolution over IPv6. Some websites will
not be accessible by Windows XP if the domain names of the websites are hosted in
IPv6 only name servers."
After reading the above, I doubt people still want to use IPv6 in Windows XP.
2012/05/24
v4 SMTP server can send out v6 outgoing email
Some friends asked me the myth about my SMTP server running on IPv4 can send out IPv6 emails to dual-stack SMTP servers. There is no secret. My SMTP Server does not bind to any specific IP address so it just listen and use all available addresses in the Network Interface Card, both v4 and v6. In sending email to a dual-stack mail server, v6 path is logically selected first. However, I can not receive incoming emails from v6 path due to the lack of a MX record pointing to a v6 host. Interesting stuff !!
2012/05/23
Our IPv6 SMTP Server in service
May 23 22:57:46 i3way sendmail[19437]: q4NEvMol019435: to=
May 23 22:57:46 i3way sendmail[19437]: q4NEvMol019435: to=
May 23 22:52:48 i3way sendmail[19378]: q4NEqO8V019376: to=
May 23 22:57:46 i3way sendmail[19437]: q4NEvMol019435: to=
2012/05/21
Staying Alive
I was listening to his songs with my ipod this morning without knowing the sad news. The name "Bee Gees" is always staying alive in my mind and my heart.
To all with a broken heart, how can you mend a broken group ?
2012/05/10
Facebook Phishing
I've got quite a number of phishing email pretending from Facebook. The tactic is old and easily detected. The messages said I have some friend requests and asked me to click a link. In another message, it asked me to confirm email address by clicking a page in order to associate with my Facebook account. These tricks are obvious and the links will re-direct me to malware websites.
2012/05/01
Email honeypot HD storage problem
One of my friends has successfully set up an email honeypot acting as an open relay decoy. Spammers successfully seize the host and deposit spam messages. The email honeypot just does not deliver any messages but store up on a daily basis. Then comes a difficulty. A spam message has thousands of recipients and each spam message to a recipient consisting of the mail header part and message part (2 files) resulting in many millions of new files created a day which eat up several Gbytes of HD storage. I recalled that I resolved this problem many years ago. In sendmail.cf or sendmail.mc, there is an option to limit the number of recipients in a message. I rather like to edit sendmail.cf directly by adding these 2 lines:
# maximum number of recipients per SMTP envelope
O MaxRecipientsPerMessage=10
This should work fine as I am quite sure I have tried this many many times before.
# maximum number of recipients per SMTP envelope
O MaxRecipientsPerMessage=10
This should work fine as I am quite sure I have tried this many many times before.
2012/04/14
6rd tunneling will be available to Hong Kong Science and Technology Park
Hong Kong Science and Technology Park (HKSTP) is the second hi-tech center in Hong Kong with lots of technology companies doing R&D on new products and applications. Sadly, no native IPv6 connections and facilities are available there yet. How could the technology companies develop IPv6 products, solutions and applications.
Cyberport Hong Kong is aware of the situation. I have been told quite firm that Cyberport is now developing a 6RD solution for extending a network node to tenants in HKSTP which basically works like native IPv6 connections. 6RD is a well-proven quick tunneling solution built on existing IPv4 infrastructure and only a few hardware facilities are required. What a tenant needs is a simple router supporting 6RD connection in WAN side (D-LINK, Linksys, Netgear etc) whereas the LAN side can have DHCPv6, SLAAC or other methods of address allocation. I hope the project could be implemented as soon as possible such that important IPv6 network resource and connectivity could be available to the high-tech community in Hong Kong.
Cyberport Hong Kong is aware of the situation. I have been told quite firm that Cyberport is now developing a 6RD solution for extending a network node to tenants in HKSTP which basically works like native IPv6 connections. 6RD is a well-proven quick tunneling solution built on existing IPv4 infrastructure and only a few hardware facilities are required. What a tenant needs is a simple router supporting 6RD connection in WAN side (D-LINK, Linksys, Netgear etc) whereas the LAN side can have DHCPv6, SLAAC or other methods of address allocation. I hope the project could be implemented as soon as possible such that important IPv6 network resource and connectivity could be available to the high-tech community in Hong Kong.
2012/04/08
Missing the trailing dot in zone file
Missing the trailing dot in config authoritative
name servers is a common mistake committed by network administrators. I admit
that I always forget this important aspect.
As a reminder, I now jot down some easy reference to alert myself aware
of this carelessness.
Forward lookup of mx for zome example.com
; zone example.com.
@
IN MX 10 mailhost.example.com
[ the final part should be
mailhost.example.com.]
becomes
@
IN MX 10 mailhost.example.com.example.com.
Reverse lookup of 192.0.2.1 to produce host.example.com
; zone 2.0.192.in-addr.arpa.
1
IN PTR host.example.com
[ the final part should be host.example.com.]
becomes
1
IN PTR host.example.com.2.0.192.in-addr.arpa.
Keep the above in mind as much and as long as possible.
2012/04/05
My new IPv6 address is 2401:0300:0:1:8080
Netfront has assigned the block 2401:300:0:1::/64 to me. I see my NIC doing auto-config after learning the prefix from the router. The IPv6 address was 2401:300:0:1:215:f2ff:febc:38c which was derived from EUI-64.
Oh God, too difficult to remember the long string. I manually assigned 2401:300:0:1::8080 to the NIC. Afterwards, I just added the default gateway and everything was working so smoothly without reboot. Thanks to the power and flexibility of IPv6 in Linux
Oh God, too difficult to remember the long string. I manually assigned 2401:300:0:1::8080 to the NIC. Afterwards, I just added the default gateway and everything was working so smoothly without reboot. Thanks to the power and flexibility of IPv6 in Linux
2012/03/30
Some ISPs with /32 prefix do not take up the reverse delegation
I just notice some ISPs who have been allocated /32 prefixes from APNIC have not taken up the reverse delegation of their own address range. They will face problem if the addresses are used to set up SMTP servers by their corporate customers. One example is HGC who owns the prefix 2403:5000::/32.
[warren@dnssec ~]# nslookup
> set type=ns
> 0.0.0.5.3.0.4.2.ip6.arpa.
Server: 202.81.252.116
Address: 202.81.252.116#53
** server can't find 0.0.0.5.3.0.4.2.ip6.arpa.: NXDOMAIN
[warren@dnssec ~]# nslookup
> set type=ns
> 0.0.0.5.3.0.4.2.ip6.arpa.
Server: 202.81.252.116
Address: 202.81.252.116#53
** server can't find 0.0.0.5.3.0.4.2.ip6.arpa.: NXDOMAIN
Here is a good example of CPCNet with 2403:2c00::/32
[warren@dnssec ~]# nslookup
> set type=ns
> 0.0.c.2.3.0.4.2.ip6.arpa.
Server: 202.81.252.116
Address: 202.81.252.116#53
Non-authoritative answer:
0.0.c.2.3.0.4.2.ip6.arpa nameserver = ns1.hk.net.
0.0.c.2.3.0.4.2.ip6.arpa nameserver = ns2.hk.net.
Authoritative answers can be found from:
ns1.hk.net has AAAA address 2403:2c00:2::1
> set type=ns
> 0.0.c.2.3.0.4.2.ip6.arpa.
Server: 202.81.252.116
Address: 202.81.252.116#53
Non-authoritative answer:
0.0.c.2.3.0.4.2.ip6.arpa nameserver = ns1.hk.net.
0.0.c.2.3.0.4.2.ip6.arpa nameserver = ns2.hk.net.
Authoritative answers can be found from:
ns1.hk.net has AAAA address 2403:2c00:2::1
2012/03/29
IPv6 network time service available now from the Hong Kong Observatory
IPv6 NTP service is available from the Hong Kong Observatory (HKO) now at "time.hko.hk", the public announcement is at:
http://www.info.gov.hk/gia/general/201203/29/P201203290205.htm
OFTA and CUHK have been helping the tests and configurations in the past 3 months. We are happy to work with HKO colleagues and share experience on technical issues of IPv6. This IPv6 NTP system is highly resilient, running dual-stack with v4 and v6 redundant links from two different ISPs.
[warren@ ~]# ntpdate -q time.hko.hk
server 2403:5000:171:11::2, stratum 1, offset -0.000255, delay 0.03191
server 2407:8000:8001:80::8, stratum 1, offset -0.000517, delay 0.03520
server 223.255.185.2, stratum 1, offset -0.000185, delay 0.03293
server 118.143.17.82, stratum 1, offset -0.000069, delay 0.02800
29 Mar 21:57:16 ntpdate[24631]: adjust time server 118.143.17.82 offset -0.000069 sec
It took 27 months from my first proposal to HKO to successful implementation. A great feeling of relaxation, finally.
http://www.info.gov.hk/gia/general/201203/29/P201203290205.htm
OFTA and CUHK have been helping the tests and configurations in the past 3 months. We are happy to work with HKO colleagues and share experience on technical issues of IPv6. This IPv6 NTP system is highly resilient, running dual-stack with v4 and v6 redundant links from two different ISPs.
[warren@ ~]# ntpdate -q time.hko.hk
server 2403:5000:171:11::2, stratum 1, offset -0.000255, delay 0.03191
server 2407:8000:8001:80::8, stratum 1, offset -0.000517, delay 0.03520
server 223.255.185.2, stratum 1, offset -0.000185, delay 0.03293
server 118.143.17.82, stratum 1, offset -0.000069, delay 0.02800
29 Mar 21:57:16 ntpdate[24631]: adjust time server 118.143.17.82 offset -0.000069 sec
2012/03/28
v6 subnet calculator
Three years ago, when I taught about IPv6 subnetting, I asked the audiences to use binary or hexadecimal concept to subdivide a prefix into smaller subnets. This is not necessary anymore. People can use a v6 subnet calculator to do the job. It can be downloaded at http://www.accumuli.com/pages/files/IPv6SubnetCalculator.zip
2012/03/27
Find "Aaron Cheung" in Facebook, the 1st person to bring commercial Internet services to Hong Kong
I suddenly found an old friend whose name is "Aaron Cheung" in Facebook. He was the first person to bring commercial Internet services to Hong Kong. I met him in around 1993. At that time, I was a system
operator of Fidonet and my node was 488 in Hong Kong. During an informal gathering, he told me that he was setting up the first 64k leased line from HK to US west
coast to run the first commercial Internet service in HK, the the Hong Kong Internet Gateway Service (HKIGS). Later on, I was amongst the first 10
customers of HKIGS. I did not subscribe
to HKIGS service in around 1996 since
then I did not hear anything about him and HKIGS.
I still remembered the HKIGS handbook (less
than 20 pages) teaching us how to send email, using gopher and other services in a
Unix shell environment. Thanks for all
the great services of HKIGS in those years.
Subscribe to:
Posts (Atom)
