This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2014/08/25
2014/08/21
2014/08/20
2014/08/04
2014/07/30
2014/07/24
2014/07/07
450 Mbps LTE download speed
If a mobile carrier has 20 MHz bandwidth in each of the 1.8 GHz, 2.1 GHz and 2.5 GHz bands, it can offer 450 Mbps download speed by Carrier Aggregation across different bands in LTE-A network. Any such resourceful carriers in the world?
2014/07/05
2014/07/01
2014/06/28
Chrome flash plugin
Google makes Chrome a piece of shit by embedding its own flash plugin into the browser which crashes with Adobe plugin. Chrome does not know which one to use ! I need to manually disable the embedded one.
2014/05/03
2014/05/01
RFC 1918 address leaked out
What the hell is that?
[localhost~]# dig a +short mail.hkbn.com.hk
192.168.99.100
RFC1918 address leaked out ? Misconfiguration ? Or an authoritative name server serving both Intranet and Internet ?
2014/04/25
.xxx generic top level domains
Whether you like it or not,
".xxx" triple x top level domain has been in services for over 2
years. Of course, it is for pornographic websites only. I like the idea because
only a simple filtering mechanism can be used to ban children from accessing
adult websites.
2014/04/22
DNS reply larger than 4096 bytes
I
thought I would never be able to generate a DNS query with reply size larger
than 4096 bytes. I was wrong ! Just look at this.
[warren@dnssec ~]# dig any doc.gov | grep SIZE
;; MSG SIZE rcvd: 9735
Of course, the reply has to fallback to TCP instead of UDP. Thanks to US Department of Commerce for letting me to play around with this.
Hackers, don't use this for amplification attacks. You will fail.
[warren@dnssec ~]# dig any doc.gov | grep SIZE
;; MSG SIZE rcvd: 9735
Of course, the reply has to fallback to TCP instead of UDP. Thanks to US Department of Commerce for letting me to play around with this.
Hackers, don't use this for amplification attacks. You will fail.
2014/04/17
2014/04/13
2014/04/10
heartbleed bug
Announcement : If network administrators have difficulty to check whether their SSL private keys are affected by the heartbleed vulnerability, they can send me an email attaching the keys and let me know the websites. I will check for them, free of charge, of course.
2014/03/30
2014/03/22
home routers as open resolvers
A friendly note to home users with broadband routers : Quite a large number of home routers in use for years have open resolver fault. Please go to
http://www.thinkbroadband.com/tools/dnscheck.html
check your router status and upgrade the firmware to plug the hole.
By having your router as an open resolver, you are helping cybercriminals to launch DDoS attacks.
This is evidence of ASUS RT-N66U routers able to do DNS amplification attacks.
http://www.thinkbroadband.com/tools/dnscheck.html
check your router status and upgrade the firmware to plug the hole.
By having your router as an open resolver, you are helping cybercriminals to launch DDoS attacks.
This is evidence of ASUS RT-N66U routers able to do DNS amplification attacks.
2014/03/18
Open resolvers again
I repeat my statement again: Don’t compare
open resolvers with Google Public DNS (8.8.8.8 and 8.8.4.4) and OpenDNS, they
are not the same. Google and OpenDNS
have all sorts of security features that are beyond imaginations.
Subscribe to:
Posts (Atom)











