Australian ISP Internode brings surprise to the IPv6 world. It rolls out a native IPv6 trial service over ADSL. Users will be offered a /60 prefix and it is up to the broadband routers of users to allocate IPv6 addresses to their hosts. This is the first time that IPv6 trial service involves prefix delegation to end users. However, as reported by some Australian users, the only compatible CPE is Cisco 877 ADSL router running IOS 12.4 which can handle prefix delegation and IPv6 address allocation to hosts.
The trial service of Internode is more advanced than the current residential IPv6 service of NTT. NTT only offer one single IPv6 address instead of a /60 or /64 prefix.
This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2009/11/30
2009/11/25
Number of friends in a facebook account
I recently found that there is a limit on the number of friends in a facebook account. The limit is set at 5000. My question is if someone opens two accounts, how can the status update be propagated to friends of both accounts.
Still on facebook. The word "unfriend" now appears in Oxford dictionary. It has the meaning of pulling out a friend from the facebook friend list. Personally, I think "defriend" might be better. I can quote good examples of starting with de to mean doing something opposite.
Still on facebook. The word "unfriend" now appears in Oxford dictionary. It has the meaning of pulling out a friend from the facebook friend list. Personally, I think "defriend" might be better. I can quote good examples of starting with de to mean doing something opposite.
2009/11/11
Facebook scam
I received serveral email about Facebook scam for stealing login information:
"Dear Facebook user,
In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.
Before you are able to use the new login system, you will be required to update your account.
Click here to update your account online now.
If you have any questions, reference our New User Guide.
Thanks,
The Facebook Team"
The sending domain is "facebookmail.com". This domain is very questionable and is registered with malicious intent. Just wonder why domain name registra can not deny the registration.
"Dear Facebook user,
In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.
Before you are able to use the new login system, you will be required to update your account.
Click here to update your account online now.
If you have any questions, reference our New User Guide.
Thanks,
The Facebook Team"
The sending domain is "facebookmail.com". This domain is very questionable and is registered with malicious intent. Just wonder why domain name registra can not deny the registration.
2009/11/10
40th anniversary of Sesame Street
Any organizations remind us about the 40th anniversary of Sesame Street. Google does.
Look at this lovely picture in Google page:
Look at this lovely picture in Google page:
2009/11/05
rsync to download Fedora Core iso image
More and more mirror sites of Fedora Core offer the rsync capability for getting the iso images. It is therefore necessary for me to practise downloading by rsync. I have tried the following with success :
#rsync -zvP rsync://fedora.mirrors.hkt.cc/fedora/releases/11/Fedora/i386/iso/Fedora-11-i386-DVD.iso .
Note the -P attribute which is quite important to monitor progress of transfer and the estimated time remaining.
#rsync -zvP rsync://fedora.mirrors.hkt.cc/fedora/releases/11/Fedora/i386/iso/Fedora-11-i386-DVD.iso .
Note the -P attribute which is quite important to monitor progress of transfer and the estimated time remaining.
2009/11/03
HKDNR now supports IPv6 glue records
Last Friday, I was informed by the IT Manager of HKDNR that the .hk TLD nameservers can now support the hosts with IPv6 addresses as glue records. I have tetsted the glue functionality and the results were perfect.
This is a major development in the DNS infrastructure. By allowing IPv6 glue, HKDNR is helping the Internet community in Hong Kong to better prepare for transition to IPv6. By now, I can tell my friends that Hong Kong is not far lagging behind in IPv6 preparedness.
This is a major development in the DNS infrastructure. By allowing IPv6 glue, HKDNR is helping the Internet community in Hong Kong to better prepare for transition to IPv6. By now, I can tell my friends that Hong Kong is not far lagging behind in IPv6 preparedness.
2009/10/26
naming of Windows 7
Microsoft said Windows 7 is named because it is the 7th generation of Windows OS. Can anyone still recall all the previous six generations. It's not difficult. I can say they were Windows 3, Windows 95, Windows 98, Windows 2000, Windows XP, Windows Vista.
Still history again, TCP/IP stack was added starting from Windows 95. IPv6 stack was available in Windows 2000, Windows XP and Windows Vista but Windows 2000 and Windows XP require users to install and enabled it. For Vista, IPv6 is enabled by default. Of course, as Windows 7 is an improvement over Windows Vista, all IPv6 features are retained.
Wa.., the photo below is interesting, a burger with 7 layers of beef:
Still history again, TCP/IP stack was added starting from Windows 95. IPv6 stack was available in Windows 2000, Windows XP and Windows Vista but Windows 2000 and Windows XP require users to install and enabled it. For Vista, IPv6 is enabled by default. Of course, as Windows 7 is an improvement over Windows Vista, all IPv6 features are retained.
Wa.., the photo below is interesting, a burger with 7 layers of beef:
2009/10/20
HSBC's dual-password logon
Recently, I was shocked by the HSBC's dual password logon to its Internet banking services. For this scheme, the authentication page requires users to give the first password in the exact string sequence while for the second password, users are only required to input 3 characters and the positions of which characters to be inputted are random. I have a screen capture to illustrate.

Malware-infected keyloggers can capture all the key strings including usernames, 1st password, and any inputted characters of the 2nd password. What a hacker needs to do is to find the position in the screen and inject the known characters in order to get access. I am of the view that this protection scheme is much weaker than using security tokens. HSBC advises that this is to give more convenience to the users given that some users might not bring their tokens with them all the time.
I myself would not use this kind of authentication.
Malware-infected keyloggers can capture all the key strings including usernames, 1st password, and any inputted characters of the 2nd password. What a hacker needs to do is to find the position in the screen and inject the known characters in order to get access. I am of the view that this protection scheme is much weaker than using security tokens. HSBC advises that this is to give more convenience to the users given that some users might not bring their tokens with them all the time.
I myself would not use this kind of authentication.
2009/10/18
Safe Internet banking by using Linux live CD
Some security experts have suggested to use Linux live CD for safe Internet banking. This makes good sense considering that malware is targeted to steal data from Windows-based systems and won't load or work when the user is booting from LiveCD.
Some might argue that not many people have understanding of burning iso image of Linux live CD and use it for a single application. If that is the case, they should consider using an Apple Mac PC instead of Windows PC.
Some might argue that not many people have understanding of burning iso image of Linux live CD and use it for a single application. If that is the case, they should consider using an Apple Mac PC instead of Windows PC.
2009/10/15
IPv6 Proxy
I have added one of my website to an IPv6 Proxy (http://www.ipv6proxy.nl/).
If a website is configured with an IPv4 address, there is no way hosts in the IPv6only cloud can access this web site. IPv6 Proxy turns out to be a solution.
The IPv6 proxy listens to 2a00:d00:ff:131:94:228:131:131 and it will fetch website contents over IPv4 and then pass to the visiting IPv6 browser clients. The website owner is required to add an AAAA record 2a00:d00:ff:131:94:228:131:131 to the website such as:
"www.example.com. 1H IN AAAA 2a00:d00:ff:131:94:228:131:131"
The last step is of course to register the website name with the proxy.
This is a cool application from an IPv6 implementation perspective.
If a website is configured with an IPv4 address, there is no way hosts in the IPv6only cloud can access this web site. IPv6 Proxy turns out to be a solution.
The IPv6 proxy listens to 2a00:d00:ff:131:94:228:131:131 and it will fetch website contents over IPv4 and then pass to the visiting IPv6 browser clients. The website owner is required to add an AAAA record 2a00:d00:ff:131:94:228:131:131 to the website such as:
"www.example.com. 1H IN AAAA 2a00:d00:ff:131:94:228:131:131"
The last step is of course to register the website name with the proxy.
This is a cool application from an IPv6 implementation perspective.
2009/10/09
Facebook Extended Maintenance
For the past 5 days, I was not able to login facebook. Today, the situation had not changed but Facebook tried to give a different error message:
"Sorry, due to site maintenance your account is unavailable at this time. We are currently experiencing an extended site maintenance issue that is preventing some users from accessing their accounts or Pages they may administer. Rest assured that your account has not been deleted or compromised. Your original account will be restored as soon as possible so there is no need to create a new one. We sincerely apologize for any inconvenience you've encountered while attempting to log in to Facebook during this time.
You can stay updated with the progress of this bug by visiting the Help Center."
I am sure that a huge number of account holders could not wait for so many days and they have already created new accounts. Sigh... the proper message prompt comes a bit too late.
"Sorry, due to site maintenance your account is unavailable at this time. We are currently experiencing an extended site maintenance issue that is preventing some users from accessing their accounts or Pages they may administer. Rest assured that your account has not been deleted or compromised. Your original account will be restored as soon as possible so there is no need to create a new one. We sincerely apologize for any inconvenience you've encountered while attempting to log in to Facebook during this time.
You can stay updated with the progress of this bug by visiting the Help Center."
I am sure that a huge number of account holders could not wait for so many days and they have already created new accounts. Sigh... the proper message prompt comes a bit too late.
2009/10/08
Setting up 6to4 tunnel in FC10
My FC10 server is binded with the IP address 202.81.252.116. With this IPv4 address, the whole 2002:ca51:fc74::/16 range of IPv6 address belongs to me. Yesterday, I arbitrary took the first host in the range and therefore the IPv6 address for my server in 6to4 tunnel mode became 2002:ca51:fc74::1/16. Then I performed the following:
#ip tunnel add 6to4 mode sit remote any local 202.81.252.116
#ip link set dev 6to4 up
#ip addr add 2002:ca51:fc74::1/16 dev 6to4
#ip -6 route add 2002::/3 via ::192.88.99.1 dev 6to4 metric 1026
Afterwards, ifconfig showed the IPv6 address 2002:ca51:fc74::1/16 was binded to a 6to4tunnel and ping6 ipv6.google.com was successful. Great learning experience.
#ip tunnel add 6to4 mode sit remote any local 202.81.252.116
#ip link set dev 6to4 up
#ip addr add 2002:ca51:fc74::1/16 dev 6to4
#ip -6 route add 2002::/3 via ::192.88.99.1 dev 6to4 metric 1026
Afterwards, ifconfig showed the IPv6 address 2002:ca51:fc74::1/16 was binded to a 6to4tunnel and ping6 ipv6.google.com was successful. Great learning experience.
2009/10/01
check ssl private key and public key are matched
This is a tough question. How can I verify a SSL private key (e.g server.key) and a public key (e.g. server.crt) are matched. The steps are :
#openssl x509 -noout -text -in server.crt
Look for the string of modulus which is 1024 bit and then
#openssl rsa -noout -text -in server.key
Again, look for the string of modulus which should match exactly that of the previous step for the public key.
A sample of the modulus of my server certificate is as follows:
Public Key Algorithm: rsaEncryption
RSA Public Key: (1024 bit)
Modulus (1024 bit):
00:a9:47:4f:dc:2d:20:4d:90:50:40:d5:e5:8c:09:
f3:fb:ca:03:b3:4c:aa:7d:29:b9:37:fb:cc:01:a4:
87:1a:3a:72:0c:c4:fd:7a:35:a0:2d:14:13:63:4c:
a9:16:0b:52:c7:ef:67:ee:29:cc:a5:29:4d:8d:b7:
eb:0f:52:35:11:12:2c:9e:a6:53:6b:d9:80:5b:da:
ba:1b:91:29:2e:08:7b:97:a3:73:bf:77:b1:50:dc:
75:14:d4:42:c2:4b:a4:5b:68:a2:22:bc:d7:72:97:
42:95:ed:a0:32:7d:bf:29:53:12:9a:ea:f0:97:6f:
d2:c8:95:8a:c6:a4:6d:23:59
Exponent: 65537 (0x10001)
#openssl x509 -noout -text -in server.crt
Look for the string of modulus which is 1024 bit and then
#openssl rsa -noout -text -in server.key
Again, look for the string of modulus which should match exactly that of the previous step for the public key.
A sample of the modulus of my server certificate is as follows:
Public Key Algorithm: rsaEncryption
RSA Public Key: (1024 bit)
Modulus (1024 bit):
00:a9:47:4f:dc:2d:20:4d:90:50:40:d5:e5:8c:09:
f3:fb:ca:03:b3:4c:aa:7d:29:b9:37:fb:cc:01:a4:
87:1a:3a:72:0c:c4:fd:7a:35:a0:2d:14:13:63:4c:
a9:16:0b:52:c7:ef:67:ee:29:cc:a5:29:4d:8d:b7:
eb:0f:52:35:11:12:2c:9e:a6:53:6b:d9:80:5b:da:
ba:1b:91:29:2e:08:7b:97:a3:73:bf:77:b1:50:dc:
75:14:d4:42:c2:4b:a4:5b:68:a2:22:bc:d7:72:97:
42:95:ed:a0:32:7d:bf:29:53:12:9a:ea:f0:97:6f:
d2:c8:95:8a:c6:a4:6d:23:59
Exponent: 65537 (0x10001)
2009/09/24
DVD to iso image
Suppose I have a DVD of FC10, how can I convert it into an iso image and then burn more DVD. The way to do it is to "dd if=/dev/hdc of=/home/FC-10.iso".
No doubt I need to use the above skill several times a year. Pretty practical and simple to understand if you have tried dd before. Of course, if I have two DVD read/write drives, I can do a read from one drive and then write to another. But that straight forward way of getting things done is not what I want.
No doubt I need to use the above skill several times a year. Pretty practical and simple to understand if you have tried dd before. Of course, if I have two DVD read/write drives, I can do a read from one drive and then write to another. But that straight forward way of getting things done is not what I want.
2009/09/20
Grub failure in FC10
Yesterday, I tried to upgrade a server from FC9 to FC10. The upgrade process was ok. However, grub did not boot up. Some hints from searching redhat suggested to use FC9 dvd to rescue. The steps are as follows:
- Boot with FC9 DVD, select rescue mode
- chroot /mnt/sysimage
- grub-install /dev/sda
- reboot again to fix the problem
It worked and the grub was rescued.
I have to memorize these steps. The same problem might happen again when I upgrade FC10 to FC11.
- Boot with FC9 DVD, select rescue mode
- chroot /mnt/sysimage
- grub-install /dev/sda
- reboot again to fix the problem
It worked and the grub was rescued.
I have to memorize these steps. The same problem might happen again when I upgrade FC10 to FC11.
2009/09/19
monitor the progress of dd
I have to use Helix to clone a hard disk by dd. As usual, the format is:
#dd if=/dev/hda of=/dev/hdc
However, no progress can be monitored.
I open another terminal window and by means of top, I find the PID of dd. Next,
#kill -SIGUSR1 pid
Now switching back to the terminal that is running dd, the progress of how many bytes have been written on the destination drive is disclosed.
#dd if=/dev/hda of=/dev/hdc
However, no progress can be monitored.
I open another terminal window and by means of top, I find the PID of dd. Next,
#kill -SIGUSR1 pid
Now switching back to the terminal that is running dd, the progress of how many bytes have been written on the destination drive is disclosed.
2009/09/17
man toilet
The most interesting command in Unix/Linux is "toilet". If I want to check the usage, I will interrogate by manual page. This gives another funny combination of "man toilet".
Of course, we don't have such funny things in Windows.
Of course, we don't have such funny things in Windows.
2009/09/16
facebook passed 300 million users
Congratulation to Facebook
Facebook founder Mark Zukerberg said that facebook has got 300 million users. In addition, facebook starts to make money ahead of schedule. Profit can be seen in 2010.
For sure, facebook is the world biggest social networking platform.
Facebook founder Mark Zukerberg said that facebook has got 300 million users. In addition, facebook starts to make money ahead of schedule. Profit can be seen in 2010.
For sure, facebook is the world biggest social networking platform.
2009/09/12
Global IPv6 routing table passed 2000 prefixes
According to Hurricane Electric, the global IPv6 routing table has passed 2000 IPv6 prefixes. This shows a steady growth in the deployment of IPv6 backbones.
Other useful data about IPv6 infrastructure are as follows :
- There are now over 1500 IPv6 glue records in the TLD zone files. The
addition of IPv6 glue records at the TLD level is a good gauge of
hosting infrastructure IPv6 growth, since it indicates operational
commitment on the part of individual nameserver operators.
- Top Level Domains (TLDs): 280, TLDs with IPv6 nameservers: 223, Percentage of TLDs with IPv6 nameservers: 79.6%
- TLDs with nameservers with IPv6 glue in the root zone: 170, Percentage of TLDs that have nameservers with IPv6 glue in the root zone: 60.7%
I do have two domain names with IPv6 glue records at the .com TLD. My contribution is therefore 2 /1500 or 0.13 %.
Other useful data about IPv6 infrastructure are as follows :
- There are now over 1500 IPv6 glue records in the TLD zone files. The
addition of IPv6 glue records at the TLD level is a good gauge of
hosting infrastructure IPv6 growth, since it indicates operational
commitment on the part of individual nameserver operators.
- Top Level Domains (TLDs): 280, TLDs with IPv6 nameservers: 223, Percentage of TLDs with IPv6 nameservers: 79.6%
- TLDs with nameservers with IPv6 glue in the root zone: 170, Percentage of TLDs that have nameservers with IPv6 glue in the root zone: 60.7%
I do have two domain names with IPv6 glue records at the .com TLD. My contribution is therefore 2 /1500 or 0.13 %.
2009/09/10
Email scam
For almost 3 years, I have not received any email scam. Then, this week, I received one.
******** Quote ********
From: kone_musa1@cantv.net
Dear Friend (Being A Foreigner),
With your Profile today I am satisfied that you have an understanding of the need for absolute secrecy in this pending project, hence my firm belief that I can count on your total support and confidentiality.
I am Mr Kone Musa, A staff of one of the commercial bank in COTE D'IVOIRE.I am pleased to get across to you for a very urgent and profitable business proposal, though I don't know you neither have I seen you before but my confidence was reposed on you.A contract file worth ( US$6.350.000) Dollars with the name has been noticed lying waste in our contract and account department.Please Get back to me for more information.
Thanks
From Kone Musa
******* End of Quote ********
******** Quote ********
From: kone_musa1@cantv.net
Dear Friend (Being A Foreigner),
With your Profile today I am satisfied that you have an understanding of the need for absolute secrecy in this pending project, hence my firm belief that I can count on your total support and confidentiality.
I am Mr Kone Musa, A staff of one of the commercial bank in COTE D'IVOIRE.I am pleased to get across to you for a very urgent and profitable business proposal, though I don't know you neither have I seen you before but my confidence was reposed on you.A contract file worth ( US$6.350.000) Dollars with the name has been noticed lying waste in our contract and account department.Please Get back to me for more information.
Thanks
From Kone Musa
******* End of Quote ********
Subscribe to:
Posts (Atom)