On Friday, all of a sudden, my Android phone could not sync gmail. Intuitively, I had the impression that access to market would also fail as market relies on gmail account for authentication. Finally, it was proven that all Gmail and Facebook could not sync while access to market completely failed.
After investigation, I noted that my phone had the date set to 1 Jan 2000. Shit, auto-sync requires accurate time information on the terminal devices. After changing the date properly, everything was restored.
A good learning experience and exercise.
This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2011/10/30
2011/10/16
In memory of Dennis Ritchie, Father of Unix
It was sad to read news about Dennis Ritchie, Father of Unix, who passed away on 12 October 2011.
I was addicted to Unix in 1992 but only got my first reference book in 1994. As my appreciation to Dennis Ritchie, Father of Unix, I shall keep this book for the rest of my life.
I was addicted to Unix in 1992 but only got my first reference book in 1994. As my appreciation to Dennis Ritchie, Father of Unix, I shall keep this book for the rest of my life.
2011/10/11
Blackberry outage in three continents
Yersterday, there was a massive RIM's network outage in Europe, Middle East and Africa which lasted for 3 hours :
http://edition.cnn.com/2011/10/10/tech/mobile/blackberry-outage/index.html
Millions of users were affected.
As usual, RIM will never disclose the root of the failure using the excuse that RIM's network is based on a proprietary design and it needs to keep its network design and architecture confidential.
Though Asia was not affected in the incident yesterday, we can not be sure we get the same luck next time.
http://edition.cnn.com/2011/10/10/tech/mobile/blackberry-outage/index.html
Millions of users were affected.
As usual, RIM will never disclose the root of the failure using the excuse that RIM's network is based on a proprietary design and it needs to keep its network design and architecture confidential.
Though Asia was not affected in the incident yesterday, we can not be sure we get the same luck next time.
2011/10/04
iPhone 5 can not support 4G LTE
With the coming release of iPhone 5, IT and technology savvy people are guessing if it can support high speed 4G LTE. My view is that iPhone 5 will not be equipped with 4G LTE air interface. The reason is that there are now just a few 4G LTE networks. Apple must make a logical decision and careful investment. May be iPhone 6 released in next year can do that.
2011/10/02
IPv6 Speed Test
ipv6-test.com is hosted in France and it can offer speed tests on both IPv4 and IPv6 connection. It is now seeking help from other web administrators to set up such facility in other region. As I do not have high speed native IPv6 connection otherwise I will volunteer to make my server as a mirror test site in Hong Kong.
The speed tests done today were the best I have ever conducted. The overseas IPv4 and IPv6 connection speeds were almost the same at around 4.5 Mbps. This speed is sufficient for DVD-quality full screen video.
The speed tests done today were the best I have ever conducted. The overseas IPv4 and IPv6 connection speeds were almost the same at around 4.5 Mbps. This speed is sufficient for DVD-quality full screen video.
2011/10/01
gogoclient on WiFi
This is a good news. Gogoclient can work on WiFi which enables me to have IPv6 tunnel connection on WiFi. I had tested several times before but all failed. I did not know what went wrong. Then after changing a new WiFi router, everything works now.
I note that there is a new version of Gogoclient which supports DS-Lite. I will download and try it.
I note that there is a new version of Gogoclient which supports DS-Lite. I will download and try it.
2011/09/17
sharepod to replace iTunes
iTunes is too bulky to manage ipod songs. I have now changed to sharepod, small file size, just 5MB file size plus the interface is neat and clean.
Another headache of iTunes is that if some songs in a PC's folder are inadvertently deleted, iTunes attempts to delete the same songs in ipod because of auto-sync. No such hassle in sharepod.
The only shortcoming is that I have to connect ipod to sharepod if I want to listen to music through my PC.
Another headache of iTunes is that if some songs in a PC's folder are inadvertently deleted, iTunes attempts to delete the same songs in ipod because of auto-sync. No such hassle in sharepod.
The only shortcoming is that I have to connect ipod to sharepod if I want to listen to music through my PC.
2011/09/12
25GB Cloud Storage
I got 25GB cloud storage from PCCW. It is a free service. Once connected, there will be a u drive with the name uhub. Just like plugging in a USB flash drive.
Doesn't sound much increase in storage capacity if one is using desktop or notebook. However, the cloud storage is accessible by iPhone and Android and this feature is very significant since smartphones do not come with hard drive.
The speed of access is a bit slow which can not be compared to accessing a local hard drive. The transfer of files is not aided by encryption. If this option is available, it makes access even slower. However, the experience of commercial paid cloud storage should be much better and encryption is a MUST.
Doesn't sound much increase in storage capacity if one is using desktop or notebook. However, the cloud storage is accessible by iPhone and Android and this feature is very significant since smartphones do not come with hard drive.
The speed of access is a bit slow which can not be compared to accessing a local hard drive. The transfer of files is not aided by encryption. If this option is available, it makes access even slower. However, the experience of commercial paid cloud storage should be much better and encryption is a MUST.
2011/09/11
watching Youtube freezed after installing Windows 7 SP1
For the past 3 months, my Windows 7
notebook freezed whenever watching Youtube
videos or videos of appledaily news. I
thought it could be due to system drivers corruption. I re-installed Windows 7 again and in the first
3 days, everything was fine. Afterwards, automatic update installed SP1 and
the problem appeared again. Shit, some
bloggers say this SP1 problem had been confirmed by Microsoft because of a weakness of memory manager performs frequent paging in and
paging out requests when memory usage is high.
Microsoft has released a
hotfix to it downloadable at :
http://support.microsoft.com/kb/2575077
I did not apply the hotfix. I
just uninstalled SP1 and my Windows 7 is now stable and performing well.
2011/09/08
Shall name-based virtal hosting be used in a web server even only a single website is hosted on the IP address
This is a web server security question.
Shall name-based virtal hosting be used in a web server even only a single
website is hosted on the IP address ?
The typical cases are www.hkexnews.hk
and www.hkex.com.hk. The websites respond to clients even the HTTP headers do
not contain a hostname, just an IP address only . The answer to me is quite obvious.
2011/09/05
Multiple SSL websites on a single IP address
Apache 2.2.12 or higher version can support Server Name Identification (SNI) in Transport Layer Security (TLS). That is to say, multiple SSL websites can be hosted on a single IP address. This is a great help. In fact, SNI in TLS has become an IETF standard (RFC 3546) dated back to end 2003.
There is now a tool to test if browsers can support SNI in the TLS handshake:
https://sni.velox.ch/
During the test, I noticed IE8 prompted an error message of invalid certificate, I just pressed the continue browsing button and I saw more details about IE failure.
What I observed is that the current version of Firefox, Chrome and Safari are capable of SNI while IE still lacks this function. On server side, I track that Microsoft IIS 7.5 is not able to do this SNI thing, but Microsoft has committed to make it in the next version. For browsers in smartphones, I can not test one by one since there are so many different packages.
This is just a bit of development. There is a long way to go before a single IP address can support multiple SSL websites on all different platforms while some browsers might still fall behind.
There is now a tool to test if browsers can support SNI in the TLS handshake:
https://sni.velox.ch/
During the test, I noticed IE8 prompted an error message of invalid certificate, I just pressed the continue browsing button and I saw more details about IE failure.
What I observed is that the current version of Firefox, Chrome and Safari are capable of SNI while IE still lacks this function. On server side, I track that Microsoft IIS 7.5 is not able to do this SNI thing, but Microsoft has committed to make it in the next version. For browsers in smartphones, I can not test one by one since there are so many different packages.
This is just a bit of development. There is a long way to go before a single IP address can support multiple SSL websites on all different platforms while some browsers might still fall behind.
2011/09/03
Apache Killer killed
After waiting for 6 days, Apache Software Foundation finally released Apache 2.2.20 which removes the HTTP Range Exploit. The fix is that if the sum of all ranges in a request
is larger than the original file, the server ignores the ranges and sends the complete file.
All system administrators should be relaxed now. The most devastating bug in the history of the open source community has been eliminated.
All system administrators should be relaxed now. The most devastating bug in the history of the open source community has been eliminated.
2011/08/29
Apache Killer again
Regarding interim fixes for protecting against Apache Killer (Range Exploit), many system administrators are frustrated whether to ban range completely or to allow a certain number of range. Last Friday, I took the approach of banning HTTP Range Header completely. After discussions with some system administrators, they were of the view that the method of 5 ranges restriction is recommendable. The reason is that Microsoft IIS allows not more than 5 ranges in header and IE browsers are in strict conformance with IIS. That is to say, IE browsers will not send out HTTP headers with more than 5 ranges.
This is sound and reasonable and so I decided to follow the approach.
This is sound and reasonable and so I decided to follow the approach.
It might be argued that why not care Firefox, Chrome, Safari, Opera and mini-browsers in smartphones. The situation is so complicated. There is no perfect answer.
2011/08/28
two partitions in ASUS notebook
A friend got a new ASUS notebook but he disliked two partitions on it. He wanted to merge the two partitions to make a bigger C drive. I cautioned him not to do so.
The use of two partitions on a notebook PC is a good operational practice. The first partition is for holding system files where the other partition is for files of user applications and data. If Win 7 system crashes due to viruses, spyware or inadvertent corruption of system files, the recovery disk containing the factory default image can be dumped back to the first partition while keeping the user data unaffected as far as possible. This might be complicated in the event that only one partition is used for holding all kinds of files. For Linux system, multiple partition requirement is more important not just for backup, recovery but also for scalability and expansion.
2011/08/27
Rescue Windows XP Again
I wonder why XP boot up process gets into trouble so easily. Or else the hard disk in question is not so reliable ?
2011/08/26
Apache Killer
Some friends alerted me of the “Apache Killer” bug which can be viewed at the URL below:
http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3C20110824161640.122D387DD@minotaur.apache.org%3E
This bug exploits Apache's flaw in handling the RANGE field in HTTP request header. By sending a crafted request with a large number of fields within the Range header, the attacker is amplifying the request as each byte range field forces Apache to make separate copies of the requested resource which eventually consumes all CPU and memory resources.
The bad news is that system administrators need to wait for another 48 hours for Apache Foundation to release the patches. In the mean time, they can apply interim measures such as not allowing the use of Range headers.
This bug was first found in 2007. Wonder why Apache Foundation did not pay attention to it.
http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3C20110824161640.122D387DD@minotaur.apache.org%3E
This bug exploits Apache's flaw in handling the RANGE field in HTTP request header. By sending a crafted request with a large number of fields within the Range header, the attacker is amplifying the request as each byte range field forces Apache to make separate copies of the requested resource which eventually consumes all CPU and memory resources.
The bad news is that system administrators need to wait for another 48 hours for Apache Foundation to release the patches. In the mean time, they can apply interim measures such as not allowing the use of Range headers.
This bug was first found in 2007. Wonder why Apache Foundation did not pay attention to it.
2011/08/19
XP Security 2012 Malware
My office desktop PC was infected with a malware called "XP Security 2012". This malware stopped all the three browsers and running any executable files resulted with the error message "Application not found".
2 hours were spent to remove the malware by using malwarebytes to scan the whole hard disk. Next, the failure of running executable files was due to corruption of .exe file association in the registry. Running the Windows File Association Fixes for .exe extension would bring the machine back to normal.
This is a deadly malware since it kills browser function and disable all executable programmes. I guess I would not have contracted the malware if I were using Chrome for web browsing.
2 hours were spent to remove the malware by using malwarebytes to scan the whole hard disk. Next, the failure of running executable files was due to corruption of .exe file association in the registry. Running the Windows File Association Fixes for .exe extension would bring the machine back to normal.
This is a deadly malware since it kills browser function and disable all executable programmes. I guess I would not have contracted the malware if I were using Chrome for web browsing.
2011/08/13
HKEx attack incident
When asked for comments onf HKEx hacking incident, the Financial Secretary Mr John Tsang said he disagreed with suggestions that the website was not secure enough and added that many large organisations around the world have had their sites hacked into.
What the fuck has Hong Kong learnt from the HKEx attack case.
Oh my God, this is a poor attitude. If top Hong Kong government official has such view or mindset, there is no hope for Hong Kong to maintain a higher cyber security standard. HKEx runs some mission critical systems for the finance market, it should have emergency plans and backup measures to minimize the impact of large scale cyber attacks. Besides, these plans and measures should have been drilled on a regular basis to test system and human responses. HKEx should disclose what actions they made after discovering the hacking.
What the fuck has Hong Kong learnt from the HKEx attack case.
TSIG-based zone transfer and clock sync
For a long time, I was puzzled why accurate time sync is needed between master and slave nameservers in Transaction Signature (TSIG) based zone transfer. I finally got the answer.
To recap on the concept of TSIG, we must recognize that slave server trusts a master server based on IP in the config file. But IP address can be spoofed and there is a likelihood of attackers passing hacked zone file to the slave server. A better approach is for master and slave to use a common key. Master server would generate signature of hash while slave will decrypt the signature and get back the hash and compare with the received zone file.
That is why the master and slave must sync with a NTP server in a more frequent manner.
When signature is generated, there is a times tamp in particular field. The time stamp is useful to avoid replay attack later on as the time stamp is far deviated from the current system clock. If I still remember correctly, the tolerance for time stamp is 5 minutes in Bind. Only if the attacker can do the replay attack within the next 5 minutes, otherwise the zone file together with signature will be ignored. By same logic, if the difference of system clock in master and slave is more than 5 minutes, the legitimate TSIG-based zone transfer will also fail.
That is why the master and slave must sync with a NTP server in a more frequent manner.
2011/07/27
No flash for 64-bit IE9
My 64-bit IE9 could not play flash video when browsing. Logically, as IE9 is so new, I thought it was necessary to download Adobe flash player 64-bit version. Surprise, there is no such software as 64-bit flash. Please see the dump below :
I do have 32-bit version of IE9 and this one has flash 10.3 properly running. Without support for flash, I think 64-bit IE9 is almost handicapped considering that there can be up to one fourth of the world websites using flash to display content.
Subscribe to:
Posts (Atom)





