2012/06/23

神舟五號返回艙

神舟五號返回艙,現安放在太古城中心展出。單看外型和艙面金屬嚴重燒焦,已知強國航天技術嚴重落後。算把啦,倒不如將研究經費改善民生吧!


2012/06/20

802.11n or Powerline Ethernet Adaptor

I note that powerline ethernet adpators which some body call them as homeplug can now support 500 Mbps and 1000 Mbps.  This is much better than 802.11n WiFi connection. The best I can get from 802.11n at home is always below 30 Mbps though the specification states the client can have a maximum speed of 300 Mbps.  If the throughput of ethernet adpators is reduced to half due to cable length or noise, the offered speed of 250 Mbps - 500 Mbps is still far superior than the best WiFi devices. It is now the right time to consider replacing 802.11n by powerline ethernet.  

2012/06/17

IPv6 Router Advertizement Attack

I heard the IPv6 router advertizement attack almost a year ago but did not jot it down in writing. Here it is. A single Windows 7 machine can make all Windows machines in a local area network not workable by flooding bogus RA messages with many bogus source addresses.  Only about 20 seconds of flooding is capable of doing great harm. The CPU usage of all machines are approaching 100 % and then hang up


Microsoft has indicated that no patches will be released to rectify this bug but Windows 8 will have this problem removed.  In other words, there is no cure from the OS side. Shame on Microsoft.

For those organisations that need to use IPv6 RA for address assignment, they should use an Ethernet switch with RA guard.

Good luck to those who allow RA in their internal network.

2012/06/13

Interactions of ntpdate with DNS round robin

To follow up on my last post of ntpdate interactions with DNS round robin,  I wanted to find if the shortest path fails, whether ntpdate will take the second path as backup.  The answer is affirmative. I have tested it with firewall blocking the reachability of the shortest path. Some captures are given below for reference.

Test : 118.143.17.82 is blocked by firewall to stimulate the shortest path failure

# ntpdate -4 time.hko.hk
13 Jun 08:53:48 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:49 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:50 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:51 ntpdate[3578]: sendto(118.143.17.82): Operation not permitted
13 Jun 08:53:52 ntpdate[3578]: adjust time server 223.255.185.2 offset -0.000177 sec

More details by :

#ntpdate -4 -d time.hko.hk
13 Jun 09:01:15 ntpdate[3699]: ntpdate 4.2.4p5@1.1541-o Wed Oct  8 11:22:55 UTC 2008 (1)
Looking for host time.hko.hk and service ntp
host found : 118.143.17.82
transmit(118.143.17.82)
13 Jun 09:01:15 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
receive(223.255.185.2)
transmit(223.255.185.2)
transmit(118.143.17.82)
13 Jun 09:01:16 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
13 Jun 09:01:17 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
13 Jun 09:01:18 ntpdate[3699]: sendto(118.143.17.82): Operation not permitted
transmit(118.143.17.82)
118.143.17.82: Server dropped: no data
server 118.143.17.82, port 123
stratum 0, precision 0, leap 00, trust 000
refid [118.143.17.82], delay 0.00000, dispersion 64.00000
transmitted 4, in filter 4
reference time:    00000000.00000000  Thu, Feb  7 2036 14:28:16.000
originate timestamp: 00000000.00000000  Thu, Feb  7 2036 14:28:16.000
transmit timestamp:  d38264de.bd2b5c2c  Wed, Jun 13 2012  9:01:18.738
filter delay:  0.00000  0.00000  0.00000  0.00000
         0.00000  0.00000  0.00000  0.00000
filter offset: 0.000000 0.000000 0.000000 0.000000
         0.000000 0.000000 0.000000 0.000000
delay 0.00000, dispersion 64.00000
offset 0.000000

server 223.255.185.2, port 123
stratum 1, precision -19, leap 00, trust 000
refid [GPS], delay 0.03297, dispersion 0.00114
transmitted 4, in filter 4
reference time:    d38264db.09591159  Wed, Jun 13 2012  9:01:15.036
originate timestamp: d38264db.fb344598  Wed, Jun 13 2012  9:01:15.981
transmit timestamp:  d38264db.fa50e9ce  Wed, Jun 13 2012  9:01:15.977
filter delay:  0.04730  0.03297  0.03494  0.03299
         0.00000  0.00000  0.00000  0.00000
filter offset: 0.006902 -0.00027 0.000801 -0.00029
         0.000000 0.000000 0.000000 0.000000
delay 0.03297, dispersion 0.00114
offset -0.000275

13 Jun 09:01:19 ntpdate[3699]: adjust time server 223.255.185.2 offset -0.000275 sec

***** End of Capture ******

As can be seen, "ntpdate -4 -d time.hko.hk"  will first establish handshakes  with all available IP addresses to determine which one is the best for time sync.  If the best IP address is broken, the other will be taken up.

2012/06/12

DNS round robin has no effect on ntpdate

Just found out that if a NTP server has 2 IPaddresses, when clients conduct time sync with the NTP server, the IP address with lower delay will be used.  That is to say, ntpdate has intelligence to  to sync with an IP address with minimal delay.   The effect is that ntpdate overrides DNS round robin rule.  To me, this is a new finding.

Here is the example I used for time.hko.hk.  When doing a ping by hostname, both IP addresses can be selected one by one.  However, when doing ntpdate, only one IP address will be selected.

#ping time.hko.hk
PING time.hko.hk (118.143.17.82) 56(84) bytes of data.
^C
--- time.hko.hk ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1828ms

[warren@dnssec ~]# ping time.hko.hk
PING time.hko.hk (223.255.185.2) 56(84) bytes of data.
^C
--- time.hko.hk ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1137ms

# ntpdate -4 time.hko.hk
12 Jun 13:31:57 ntpdate[24994]: adjust time server 118.143.17.82 offset 0.000340 sec
# ntpdate -4 time.hko.hk
12 Jun 13:31:59 ntpdate[24995]: adjust time server 118.143.17.82 offset -0.000125 sec


2012/06/07

Use of gogoCLIENT after 6 June 2012

I like to remind users in Hong Kong who are using gogoCLIENT to access IPv6 and dual-stack websites. After 6 June 2012, GogoCLIENT makes your Windows 7 quite slow in accessing dual-stack websites like Google, Facebook and Yahoo as the nearest tunnel gateway of freenet6.net is in Taiwan. Yes, that is the reality for accessing dual-stack websites but same speed for accessing pure v4 website, still very slow for pure v6 websites. If is up to users to judge if they still want to use gogoCLIENT.

If you have an IPv6 ready router such as D-Link and Linksys, please use router-based 6in4 tunnel with an user account with Hurricane Electric. Since HE has 6in4 gateway in HK with high bandwidth, the v6 speed should be quite OK.

GogoCLIENT is  widely used in Taiwan because all major ISPs there have their TSP tunneling gateway. Taiwan users who want access to v6 network can apply to their ISP for a user account. The v6 speed of course is OK unlike the case of Hong Kong whereby users must connect to Taiwan and then to other parts of the world.

2012/06/06

World IPv6 Launch

Today is 6 June 2012 which is named as the World IPv6 Launch by the Internet community.  A new era  has just begun on the Internet starting from 6 June 2012.  Thanks to Google, Yahoo, Facebook, Comcast, Cisco, D-Link and many other companies and organisations that support the new protocol.  Enjoy IPv6.

2012/05/31

Windows XP and IPv6

I am helping an organization to write a 40-page consumer guide on IPv6.  One sub-section deals with IPv6 in Windows XP and its limitations. This is what I have come up with today.


"While IPv6 functionality is present in Windows XP, it is not suitable for use in a corporate network environment. The following limitations are found in Windows XP in support of IPv6:


1.  There is no graphical user interface for address assignment and these tasks must be performed at command line.
2.     There is no DHCPv6 client in Windows XP. An IPv6 router can only use Stateless Address Autoconfiguration (SLAAC) to assign address to a Windows XP PC.
3.     Privacy protection mechanism in address assignment through SLAAC is not enabled by default. Activity tracking based on the IPv6 address is possible
4.     The personal firewall of Windows XP is broken when IPv6 is installed. When a port is open in IPv4, the same port is also open in IPv6.
5.     Windows XP can not have name resolution over IPv6. Some websites will not be accessible by Windows XP if the domain names of the websites are hosted in IPv6 only name servers."

After reading the above, I doubt people still want to use IPv6 in Windows XP.  

2012/05/24

v4 SMTP server can send out v6 outgoing email

Some friends asked me the myth about my SMTP server running on IPv4 can send out IPv6 emails to dual-stack SMTP servers.   There is no secret. My SMTP Server does not bind to any specific IP address so it just listen and use all available addresses in the Network Interface Card, both v4 and v6.  In sending email to a dual-stack mail server, v6 path is logically selected first.  However, I can not receive incoming emails from v6 path due to the lack of a MX record pointing to a v6 host.  Interesting stuff !!

2012/05/23

Our IPv6 SMTP Server in service

OFCA IPv6 SMTP Server was successfully configured. The most difficult part was to ask the ISP to do the reverse v6 lookup matching to the host of MX record.  I did not touch the server work.  I just gave technical advice and everything worked to my satisfaction.


May 23 22:57:46 i3way sendmail[19437]: q4NEvMol019435: to=, ctladdr= (500/500), delay=00:00:24, xdelay=00:00:24, mailer=esmtp, pri=120315, relay=mail.ofca.gov.hk. [IPv6:2001:218:6009:2::51], dsn=2.0.0, stat=Sent (q4NEvSjc011727 Message accepted for delivery)
May 23 22:57:46 i3way sendmail[19437]: q4NEvMol019435: to=, ctladdr= (500/500), delay=00:00:24, xdelay=00:00:24, mailer=esmtp, pri=120315, relay=mail.ofca.gov.hk. [IPv6:2001:218:6009:2::51], dsn=2.0.0, stat=Sent (q4NEvSjc011727 Message accepted for delivery)
May 23 22:52:48 i3way sendmail[19378]: q4NEqO8V019376: to=,, ctladdr= (500/500), delay=00:00:24, xdelay=00:00:24, mailer=esmtp, pri=151351, relay=mail.ofca.gov.hk. [IPv6:2001:218:6009:2::51], dsn=2.0.0, stat=Sent (q4NEqePi011717 Message accepted for delivery)
May 23 22:57:46 i3way sendmail[19437]: q4NEvMol019435: to=, ctladdr= (500/500), delay=00:00:24, xdelay=00:00:24, mailer=esmtp, pri=120315, relay=mail.ofca.gov.hk. [IPv6:2001:218:6009:2::51], dsn=2.0.0, stat=Sent (q4NEvSjc011727 Message accepted for delivery)

2012/05/21

Staying Alive

Staying Alive - that's the promise of Robin Gibb, but he did not keep his promise. He left us. He meets Maurice and Andy now in another place, another world. 


I was listening to his songs with my ipod this morning without knowing the sad news.  The name "Bee Gees" is always staying alive in my mind and my heart. 


To all with a broken heart, how can you mend a broken group ? 

2012/05/10

Facebook Phishing

I've got quite a number of phishing email pretending from Facebook.  The tactic is old and easily detected. The messages said I have some friend requests and asked me to click a link.  In another message, it asked me to confirm email address by clicking a page in order to associate with my Facebook account.  These tricks are obvious and the links will re-direct me to malware websites.














2012/05/01

Email honeypot HD storage problem

One of my friends has successfully set up an email honeypot acting as an open relay decoy.  Spammers successfully seize the host and deposit spam messages. The email honeypot just does not deliver any messages but store up on a daily basis. Then comes a difficulty.  A spam message has thousands of recipients and each spam message to a recipient consisting of the mail header part and message part (2 files) resulting in many millions of new files created a day which eat up several Gbytes of HD storage.  I recalled that I resolved this problem many years ago.  In sendmail.cf or sendmail.mc, there is an option to limit the number of recipients in a message.  I rather like to edit sendmail.cf directly by adding these 2 lines:

# maximum number of recipients per SMTP envelope 
O MaxRecipientsPerMessage=10 

This should work fine as I am quite sure I have tried this many many times before.

2012/04/14

6rd tunneling will be available to Hong Kong Science and Technology Park

Hong Kong Science and Technology Park (HKSTP) is the second hi-tech center in Hong Kong with lots of technology companies doing R&D on new products and applications.  Sadly, no native IPv6 connections and facilities are available there yet.  How could the technology companies develop IPv6 products, solutions and applications.

Cyberport Hong Kong is aware of the situation.  I have been told quite firm that Cyberport is now developing a 6RD solution for extending a network node to tenants in HKSTP which basically works like native IPv6 connections.  6RD is a well-proven quick tunneling solution built on existing IPv4 infrastructure and only a few hardware facilities are required. What a tenant needs  is a simple router supporting 6RD connection in WAN side (D-LINK, Linksys, Netgear etc) whereas the LAN side can have DHCPv6, SLAAC or other methods of address allocation.  I hope the project could be implemented as soon as possible such that important IPv6 network resource and connectivity could be available to the high-tech community in Hong Kong.

2012/04/08

Missing the trailing dot in zone file

Missing the trailing dot in config authoritative name servers is a common mistake committed by network administrators. I admit that I always forget this important aspect.  As a reminder, I now jot down some easy reference to alert myself aware of this carelessness.

Forward lookup of mx for zome example.com

; zone example.com.
@  IN  MX 10  mailhost.example.com
[ the final part should be mailhost.example.com.]
becomes
@  IN  MX 10  mailhost.example.com.example.com.


Reverse lookup of 192.0.2.1 to produce host.example.com

; zone 2.0.192.in-addr.arpa.
1  IN  PTR    host.example.com
[ the final part should be host.example.com.]
becomes
1  IN  PTR    host.example.com.2.0.192.in-addr.arpa.

Keep the above in mind as much and as long as possible.

2012/04/05

My new IPv6 address is 2401:0300:0:1:8080

Netfront has assigned the block 2401:300:0:1::/64 to me. I see my NIC doing auto-config after learning the prefix from the router. The IPv6 address was 2401:300:0:1:215:f2ff:febc:38c which was  derived from EUI-64.

Oh God, too difficult to remember the long string. I manually assigned 2401:300:0:1::8080 to the NIC. Afterwards, I just added the default gateway and everything was working so smoothly without reboot. Thanks to the power and flexibility of IPv6 in Linux

2012/03/30

Some ISPs with /32 prefix do not take up the reverse delegation

I just notice some ISPs who have been allocated /32 prefixes from APNIC have not taken up the reverse delegation of their own address range.  They will face problem if the addresses are used to set up SMTP servers by their corporate customers.  One example is HGC who owns the prefix 2403:5000::/32.

[warren@dnssec ~]# nslookup
 > set type=ns
 >  0.0.0.5.3.0.4.2.ip6.arpa.
Server:         202.81.252.116
Address:        202.81.252.116#53

** server can't find 0.0.0.5.3.0.4.2.ip6.arpa.: NXDOMAIN

Here is a good example of CPCNet with 2403:2c00::/32

[warren@dnssec ~]# nslookup
 > set type=ns
 >  0.0.c.2.3.0.4.2.ip6.arpa.
 Server: 202.81.252.116
Address: 202.81.252.116#53

Non-authoritative answer:
0.0.c.2.3.0.4.2.ip6.arpa nameserver = ns1.hk.net.
0.0.c.2.3.0.4.2.ip6.arpa nameserver = ns2.hk.net.

Authoritative answers can be found from:
ns1.hk.net has AAAA address 2403:2c00:2::1

2012/03/29

IPv6 network time service available now from the Hong Kong Observatory

IPv6 NTP service is available from the Hong Kong Observatory (HKO) now at "time.hko.hk", the public announcement is at:

http://www.info.gov.hk/gia/general/201203/29/P201203290205.htm

OFTA and CUHK have been helping the tests and configurations in the past 3 months. We are happy to work with HKO colleagues and share experience on technical issues of IPv6. This IPv6 NTP system is highly resilient, running dual-stack with v4 and v6 redundant links from two different ISPs.

[warren@ ~]# ntpdate -q time.hko.hk
server 2403:5000:171:11::2, stratum 1, offset -0.000255, delay 0.03191
server 2407:8000:8001:80::8, stratum 1, offset -0.000517, delay 0.03520
server 223.255.185.2, stratum 1, offset -0.000185, delay 0.03293
server 118.143.17.82, stratum 1, offset -0.000069, delay 0.02800
29 Mar 21:57:16 ntpdate[24631]: adjust time server 118.143.17.82 offset -0.000069 sec

It took 27 months from my first proposal to HKO to successful implementation. A great feeling of relaxation, finally.

2012/03/28

v6 subnet calculator

Three years ago, when I taught about IPv6 subnetting, I asked the audiences to use binary or hexadecimal concept to subdivide a prefix into smaller subnets.  This is not necessary anymore.  People can use a v6 subnet calculator to do the job.  It can be downloaded at http://www.accumuli.com/pages/files/IPv6SubnetCalculator.zip



2012/03/27

Find "Aaron Cheung" in Facebook, the 1st person to bring commercial Internet services to Hong Kong

I suddenly found an old friend whose name is "Aaron Cheung" in Facebook.  He was the first person to bring commercial Internet services to Hong Kong. I met him in around 1993. At that time, I was a system operator of Fidonet and my node was 488 in Hong Kong.  During an informal gathering, he told me that he was setting up the first 64k leased line from HK to US west coast  to run the first commercial Internet service in HK, the the Hong Kong Internet Gateway Service (HKIGS).  Later on, I was amongst the first 10 customers of HKIGS.  I did not subscribe to HKIGS service in around 1996  since then I did not hear anything about him and HKIGS.

I still remembered the HKIGS handbook (less than 20 pages)  teaching us how to send email, using gopher and other services in a Unix shell environment.  Thanks for all the great services of HKIGS in those years.