Diary of a Network Geek

Make Your Own Apple I

Written by Ryumaou Published:

Wow, classic, retro computing!
Hey, this brings back memories.... I was in high school when the Apple first hit significant production. In fact, we had an Apple I in our fledgling computer lab when I was a Freshman, though it was quickly replaced with an Apple IIe. (Yeah, I'm poor-folk, but I grew up in a pretty affluent neighborhood. Thanks, Mom and Dad!) That was back in the days when there weren't such things as "floppy drives" or "CD-ROM drives". Nope, you loaded your programs from tape. Audio tape! Yep, it was the Dark Ages, allright. And I was there to see it. God I feel old all of a sudden....
Anyway, now you can relive those glory days of yesteryear with your very own, home-built AppleI. Yessirree, according to this article on Wired News, there is now a book out that teaches you how to build your very own Apple I. It'd be a challenge for most of us, now that we've gotten used to all the fancy bells and whistles, but it could be fun. A neat learning project, or even a science fair project for someone. And, you never know, it might just inspire someone to invent the Next Big Thing in computing!

Besides, it's Friday and if you're reading this blog you're geeky enough to think building your Apple I is cool. Just like me. So, go ahead, indulge your guilty geek pleasure and click the link.

Categories:

Evil Twin Solution(?)

Written by Ryumaou Published:

Here's the answer to the "Evil Twin" problem.
Remember some weeks back I mentioned the whole deal with so called evil twin routers? Well, there's a solution. At least, according to this article on the ITToolbox Knowlegebase, there is a fix for it. Or, rather, there is a theoretical fix for it. Two computer scientists have come up with something they call the 'delayed password disclosure protocol' which they claim will remove the environment that allowed the evil twin router exploit to even exist. They hope to have beta code before the end of Summer this year, but it may be quite some time before that beta code goes gold and hits the actual market. So, keep an eye out for it.
Or, if you're a bit of a computer genius, come up with your own competeing solution first! It could mean a lot of money to whoever beats these two to the punch. You know, for a change, I'm glad that I don't deal with routers and these kinds of headaches all day long. I just have projects with unclearly defined goals, at least in my mind. Easy peasy compared to routing security issues.

Categories:

Status Update 2

Written by Ryumaou Published:

A new player heard from!
Well, interestingly enough, my Bloglines password was comprimised, too. But, I got that fixed and even managed to recover some of the deleted feeds and posts from those blogs that have also been deleted. Well, and I have hard-copy of all the good ones.

Categories:

Status Update 1

Written by Ryumaou Published:

Well, I've already gotten one comprimised account squared away.
The other should follow shortly, though, it's with a larger company so it may take a bit longer than I'd like. In any case, it wasn't a big deal at all. Just a minor incovenience.

Categories:

Hmmm, let's check the logs....

Written by Ryumaou Published:

Well, it seems I've "upset" someone.
Apparently, an un-named someone at IP 68.106.38.39 is a little upset with me. Said person changed a couple of e-mail addresses and passwords last night. That same person seems to reside at hostname ip68-106-38-39.ph.ph.cox.net. Interestingly enough, this is the same IP address and hostname that changed the Yahoo account of another person who used to live in this house recently. Coincidence or pattern? Remember what I was writing about this very thing earlier in the week? Well, apparently, our would be malcontent doesn't read very well, because they've left a very traceable trail. Does anyone know what areas are covered by Cox Cable? How many Western states do they handle? Ah, yes, logs are a wonderful thing.
Now, the question is, does it merit such things as, say, prosecution? I believe that said person, or persons, are now in violation of several laws. Having restricted my access to accounts at which I should be able to expect a reasonable amount of security and/or privacy. I don't have the statutes in front of me, but, the last time I checked that was illegal. Now, I'll get it straightened out, eventually, but that's not the point. The point is, after being accused of hacking and breaking the law myself, someone has gone and done what I've been accused of doing. Ironic, isn't it?
But, at least I have the joy of knowing that I've upset someone's apple cart. It makes all the hassle of changing a couple of passwords back worth while. Suddenly, no matter what the weather is here in Houston, it's a bright, sunny day for me! Have a fantabulous day!

Categories:

Nero for Linux

Written by Ryumaou Published:

Oh, yeah!
Man, Linux is just getting a massive boost this week! Yahoooooo! According to this announcement on Nero's webiste, they're now offering Nero for Linux. If you don't understand how cool that is, then you've either never used Linux or Nero or both. This is the coolest thing since sliced bread, at least in the Linux world. And, if you're already a Nero Ultra user, they're GIVING Nero for Linux to you for FREE! How cool is that?!
Jeez, I remember ten or twelve years ago when this plucky, little OS was something that hard-core geeks were into and no one in the business world had even heard of it before. Now, major corporations are supporting it and some even live or die by how well Linux fares in the marketplace. Back then, the idea that anyone would give away an entire operating system for free was just, well, unheard of. No one thought it would amount to much. No one but us hard core geeks. And, now, here we are. Linux is a player in the Big Game and doing better every day.
We've come a long way, baby!

Categories:

Novell's Aggressive Linux Stance

Written by Ryumaou Published:

...Really, really excites me!
Novell believes in Linux so much that they've added extra support for it in their ZENWorks for Desktops suite of programs. According to this press release on Novell's website, they've added "imaging, configuration lockdown, remote management, inventory and software management" to their software which will enable folks to use Novell ZENworks 7 Linux Management to manage most Linux platforms, including SUSE LINUX and Red Hat* Enterprise Linux. Now, this might not seem like much to some of you, but, trust me, this is a quantum leap forward in the Linux world. Five years ago, I couldn't hardly concieve of a major networking company doing something like this. Now, I can completely cut Microsoft out of the picture, if I want. I can have Linux desktops and servers all managed with Novell software.
I'm so happy I could just plotz.
And, I have to say that I'm really, really glad that I not only have maintained my Novell certification, but also gotten at least one Linux certification, too. I didn't know it at the time, but I couldn't have planned it any better. Once again, my career choices have been affirmed.
Well, off to the uranium mines! Have a very high-tech day!

Categories:

Preparing for a Siege

Written by Ryumaou Published:

For some reason, I seem to be preparing for a siege.
Yesterday, I spent $296 on food at Sam's Club. My freezer is packed so full, that things lean against the door! I have mass quantities of all kinds of staples. So, for the next three months or so, all I should need are short-term perishables like milk, eggs, and yogurt. Everything else, mostly, I have jammed into my pantry and upright freezer. But, my siege mentality goes further than that.
I've taken to locking the door behind me when I get home. I have a double-key deadbolt, so I don't have a little toggle handle to lock the deadbolt on my back door. Instead, I have to actually use a key on the inside, too. That makes it difficult for anyone to smash a window and then open the door from the inside. It's kind of weird, really, since I have no reason to be like this. I mean, it's not like I'm actually afraid that someone is going to try and kill me or anything, but, still, I've been a little paranoid.
My .357 is still loaded and in the key-code gun safe next to my bed. I have candles in every room of the house, so I can find my way when the power goes out. But, the power hasn't gone out in ages and I don't remember the last time I heard anything about any kind of violent crime in my neighborhood. Still, I'm ready should anything happen. I don't know, maybe it's just that I've been living alone for a bit now and I'm just preparing to take care of anything, no matter what it is, all by myself. Certainly, that's some of what motivated the food hoarding.
Everything I bought at Sam's is convenient food. For me, at least. Soups and ravioli and single-serving macaroni and cheese. Hot Pockets and White Castle Cheeseburgers. Frankly, everything I make these days has to be quick and easy or it's not worth it! I'm just too busy! All the running around with H.O.P.E. and doing pro bono computer work for a non-profit organization and church and therapy and support groups and just everyday life keep me really busy. And, even with all that, I still manage to lose weight. Of course, it fluctuates, but I bounced off 170 this weekend. It'll be back up tomorrow, but still, I'm keeping trim in spite of eating relatively "fast" food.
Wow, I got tired just thinking about all that. Off to bed for me. I need my rest!

Categories:

How Would You Do It?

Written by Ryumaou Published:

Attack someone's network or website, that is.
Okay, this has been on my mind lately, not because I've done any actual hacking recently, since: a) that would be illegal and b) I haven't done that sort of thing in, well, years. No, I've been thinking about it because, according to a friend of mine, at least one fan (short for "fanatic") seems to think that I am not only capable of doing such things, but that I, in fact, have. And recently, too! As the French say, "It is to laugh..." So, as a thought experiment (that's a mental exercise for you vocabulary impaired), here's how I'd go about doing this, if I were, in fact, to do "ownz" someone's "box".
First off, I wouldn't use a computer that I own, that can be traced to my ownership, or that uses an IP address that has ever been associated with my name. There are several ways around this, of course, including IP spoofing, anonymous remailers and other redirectors, and a compromised, third-party's machine. That last one is the best, and, ironically, the easiest method. Surprised? You shouldn't be. Compromised Windoze machines are a dime a dozen. There are hordes of script kiddies out there just hammering away at every weak Windoze machine they can ping. Also, there are more and more insecure Linux machines floating around out there, too. (Have you applied all the latest patches to your penguin box?) Or, if you know of any systems that you left behind at an unhappy employment situation, that are still vulnerable, you can use them. Usually, a corporation will have a nice, fat data pipe which makes your "job" faster and easier. Of course, if they have half a brain, after you leave, they'll change all the passwords, but sometimes someone slips. (The last place I knew of like that from my own past finally, after three years, changed the passwords as part of an upgrade.) Or, you could simply go to a coffee house that offers free Internet access via a wireless network. Every time you change coffee houses, you change IPs. And, while I normally am just fine with industrial-strength institutional coffee, a nice cafe au lait from Cresent City is always nice. Or, according to this article on Slashdot, Panera Bread Company is a good place to find a free wifi link.
So, now you have one or more launching platforms from which to case your mark. (That there's criminal slang that means "look at your ultimate hacking goal".) What do you use to look for a way in? Well, there's three that I'd recommend, based on reviews; Snacktime, Nessus and NMAP. Of the three, NMAP is, arguably, the more robust and well known. In fact, NMAP was used in The Matrix movies. Now, that, my faithful readers, is "geek cred"! Though Snacktime is interesting to me because it's PERL-based. Now, if you're not familiar with these three tools, just stop reading and go play with your IIS 6.0 webserver. We're about to talk "big boy" stuff here and you just won't be up to it. So, if you're still man enough to be following this, you'd load up your lookeeloo tool of choice on your remote launch platform at this point and get a fingerprint of your target system's OS.
Now, we get to the meat of this little mental exercise... Okay, you've got your "open door", or "doors", as it were, into your target system. At this point it's a matter of taking the information from the nice, clean results that NMAP, or whatever, gives you and applying your exploit. What and how you do that really depends on what you're attacking, but it's pretty much a paint-by-numbers affair now, thanks to the legions of script kiddies that keep us up to date. Right, root access (or Administrator, if your target is foolish enough to run Windoze). Now what? Well, that sort of depends, doesn't it? Do you want data? Start a background transfer to a third party that you can collect later. (Use ftp, tftp, or, for loads of sneaky fun, telnet, to transfer your data. Many admins disable logs on these protocols because they don't think they're running. Double check.) Want to install something? Go for it! (Try a keylogger. Now you'll get loads of target passwords to compromise other machines for further adventures!) Just want to crash the system? You should have skipped all this hassle and just hit your target with a DDoS attack from your many compromised machines, stupid. (Incidentally, for you Windoze admins out there, the entire Code Red scare you sloppy bastards caused was all about a Distributed Denial of Service "issue". )

Of course, this is all very illegal and somewhat morally questionable as well, so I would NOT do it. What's more, I would not recommend that anyone else attack, hack, assault, fold, spindle or mutilate any system other than your own. In short, the Network Geek, RyuMaou.com and Jim Hoffman (yes, we're all the same entity) does not in any way endorse any of the above listed activities, except the cafe au lait from Cresent City. In fact, I suggest that you do NOT do anything that I've written about in this entry, including flinging wild accusations that cannot be proven. That's called "libel", or, if you say it instead of write it "slander". That's against the law, too, the last time I checked.

Categories:

Moral Dilemma

Written by Ryumaou Published:

I have a moral dilemma.
Well, actually, I have several. Really, on any given day I may have as many as a dozen moral dilemmas at a time! Lately, what with my personal life in the state it's in these days, thanks to poor choices on my part, it's a wonder I don't have more. As a side note, did you know that once upon a time, the phrase "gone to Texas" was essentially slang for "crazy"? I know why now.
But, I digress, my dilemma is this: My step-daughter is into music, specifically, loud hard-rock. Well, she's discovered a little band called "Rammstein". If you're not familiar with them, they're a cheery little German band that was a favorite of the skinheads when I was in high school. Lately, though, they've been repopularized because they had a song on the Matrix soundtrack. It's their most well known and popular tune, "Du hast". Well, the full translation of the song is basically a very sarcastic denial of eternal love and based on a mockery of the traditional German wedding vows. In a nutshell, they're asking "Will you be faithful until death do you part?" and the response is "Nein". So, here's my dilemma, the rest of the songs on that CD, which I have, translate to, well, less happy themes. Now, do I rip them for her and just not tell her what the translation is? Or, do I just stop talking about it alltogether and introduce her to techno which has no lyrics to get us into trouble? I have to admit, it was pretty neat going from unhip to über-cool just by mentioning Rammstein and Du Hast off-hand, only to find them in her cheap iPod clone.
Ah, yes, the dilemmas I face. Perhaps, the lesser of two evils is the most appropriate in this case. That would be the good parental thing to do, right? Of course, she already has the boots to go with the music.... I never realized being cool was frought with such dangers!

Categories: