Showing posts with label Programming. Show all posts
Showing posts with label Programming. Show all posts
Oct 7, 2011
Sep 11, 2011
So I got this error while trying to login at 10:07am
Sorry, something went wrong.And I want to show them this. And I've spent 17 minutes looking for a link. And I'm getting a little punchy with my keyboard and I wanted to blog this because I need to not be doing this right now but I know that I will want to have the option to later. And I should, in all fairness note that I was able to login after a few minutes. But it still pisses me off; since i was only trying to help the programmers & developers with some feedback (which may help them resolve this or other isssue) I just wanted to see and click on a link that would let me send back what the server coughed up (which you can check out below in yellow-ish)
BTW: The website I was trying to access - http;//youtube.comA team of highly trained monkeys has been dispatched to deal with this situation.If you see them, show them this information:
jYqHpFE7Dl2zMnmimU6GBbNmjmqjgUJ1IbWRDDyF7FeZ-zkX-_WhHp6iVaBE opD5uov9NWgZAk1WlNBt0nZd32D3oZ-KjT7gC0835_q4NMgCViQTAg62MJBQ 3NlncGGRSpAmGUEOBAUXUzmlRKLByQdhhmTl8Vwg15mbNEQJx4hqCS2Id5U- reHg0QRBBfKjyNtqpkLdo7aWWjb5t1iY4Wty_C0HvSC3PE-4wnB-b86mbQur GtTO3Z6ab-O-CjTnoJv-VoNnJ8ZO-le0Vr7hB14p6J3EW0grwAYCUX4fFnTE uTUg89fnO-k-_lYDpE_M-tX6kYWUNyvNud_Lq2FRAhsugn-ncCS3r6nDaTjK vMSvFe2kleu9gkmtbaIa3uNMwXGvtmfHJTgr852hxOpPLf9tfHShMqjCFNlv 6eTPZ-TR06Mev1-3Rh-UlJvAdScU8zOXCeUBT6u8lisM7xC4SCS375gW9aw- EyynsqtwCACUIbjIgVrOWwNnJcLcEdWQGpRYhyBcoMHXj4d86b4CQ_1xbxHk 4ViTz3Suat23qV4mArC7OMHyynMt6vWrjv0aNF0-8azz58Fabl_8yZWH9Qjn wOlp2IpzlTNYZ1JSBaIDj860EIH1pi0TqaYojIAOfnpKSnw3dhg7YTZA981f 8E_hHqISa7vPC4uEM65hAbJ7W7YclPDXiogdVCjkcwwqRWP3oR3qRSOC6tVv 4KEKDJy5rbqhb5QHrOtVQCSLNr81jU2eN6POxHVdDh0apRLCuuvjdG0gZCWt YQwvXO4cWnDhFvEGKmphu9zxKtyjttXWN8htiJhhDPWfcBN2r1puwV5iaprB 0hsKjLMq_A3wAft_N8YEbZh1jxw9TaskD-yi14Y1FVXRn4GsQIT1yMpWCagY _hBlHWbrek7CjoKjkmNOl7KJCnY9qUJCp5kDpw-3G-idYdLcAOHvic6l20_2 KdVYZyDPkAsOGGwMBajRR97u22vbu_LY2hD_dGnNfSQg3HiWaqx2yxuAhsAo Kkcyy3EfKaIhc67wCu9c9l3xNL_jhvXTzpnFXFLeq7ci8K2SoQ16OIHQn64J FDfSJBo4CgA2AfFgFn53sULTrUQf6oRt2KsUMWg5xPYtVSRJXtgwCjRQzDOm QDyJiaQcPS1ZfAALKHEz_xjadUhgovHBaq1SJ1-adRL9RCXMbEJvm-uOTshj xg0EzU6YsMDOtCOWkVqwBRBRPcnow-4KEIbAobJlh_PUZUi_pfUKU4tMvbVp _rFTjK6bzxFbULlDXLPYEzL2-NGrlwoPfeA9EFp_bhH-HLVA17YR8kI7uVhO HC9nleCtoUcoD2uAV9lqsNy4T_2Jf_1Q2geUILlqP5I68HgKKE-YtaA-11TM wIzPSaXYD4w7XF6FQrTxAkm--jGfBE2B73JBbIxAymyyYGe3PkxmzCESsuNu LaYa0f5tXhX1ZoSXNZRViVZJgDhUGQ0CokGZF9pLxkNYq5dTjgarVajncuHQ YpPpfPmhrfspiUtvVaNmdf84qkVexBgWOzxOAXMu6bysVmnEqYaxNVFWj8QT 5Iu5hKWkA6aBGuUG-OXztPpdADD3Udu1-1El6YAybAqCZqonjMS7wal_iw4y 6jnaPLHkoldfQduQ9nxSL2CGzPCFDt4xUTPOh9z4w2HiGS2ZetW46BwgrCnm gKF67IxOOMofMtaS3W7n8p0E_il5ZLxmBf3JSahszSb5qol1Q_8Mq5IHCj-l vTpJxbXiJzMhtHZUm05Vb7WAIiilp97_mJTgyqZYOGLB-zIWPBb390hPgCbR LcQoMXILAq7VhcvSTXPIniOi3BFM8g9JEN4mXxCHvLcaUOFFPijekEXB8iOT zcfA37L2sCkfMzt-_jV1VEYSP-fzi3tFRTe5_3LhTviLOmCwsBAxFhgFHt-G Fbm2-JCXLimvmxjPbhysZ2o51VZjRAlNQukQXZr2AJAgW6hXcT5Rk9PkdePm 6UzEXj4sZkIuvGXjNOk4-7xjvT6UngyYQESHzFhZmzafPu_A4w7msd0o8Ua2 Hlokd-AMvzQRjBG8lK-07RivaguJwCVRhxQT4gcHet1eQBy5eMQR9z1Ao31T mV_2Bag0AQXFx9J50dsioCusIjUzdUDPUn8v7unxGLRXYwAWQAZRN1jqG7bS tANJEPI2IOtBWp_vCZN9sTzQpGDDzeGijVFfywBoKmrtlOybwy83qcLGt19X dacnmHC6tSDv9i1rPrOYJtLd4ztDELKeO8kcZyxiol2fViqi2IanwcswPf3o tooQQEjMt86hlk4zUGq4C3sU14i8l3D90ZExp-GkICDmsK0P16_st8lZQxDX zXlD2jQxwFL9M6wEqN9YkY_7JYo5bGgxLbrLsELnfEBNDvgKNwtPI6_qy9tJ oHsV9WqpHapHiut1VCQzyUw-2br4WeHBW-A4QyW8K8BDMilZ-8fK2F8Sm1V8 4StWBr2eSI1YaVRmtXs3av5Y6O7hhezoyDosVwVr3LKE-mNu69XKDEb4lKOl XsuB2zdgwjv2HEUsstir_U-1IQOXLQ_01Yyo22C8xKnCe9H0qM_4zjOnCKfe w5Sk6vTA0YwV-SffiVN3f0c3l5mpNdY0lPxa53JQFwjHzZM_BtF0hpMLx2v3 3T3OZp6HUp6VpsCKlpo7xWezQ19vJJ_NqG2Nb6jhPIj3dU7ak8L3x0PhcQ5F NtDQZvqkH4vt5EsDT0eQ5cAtDdjCcgpkzVaP2c-_Bu9GkLzzVmXydEyxApOj 1A530XQ0pgOLNl3vnI2oJPrF9eagrabZfWNGbksHfFiAOH2C6ltRd1ysFwrI cvdbQBj8vWD4BfceWrH44LFyNa5ac3YvmDwXhCv08Au1zAdaZqLohtkDlF6R If3uzCpQ6jECM73f1o17tr-eIdqfz8zhKcBpl6RVzNntHJrALhn3Z7CEt-56 vzziL7gu1CbvbKT2khJb4IDEM4SyeLTLY9ja40pdBjnKdGwOkfNNNA3sAqsP nNxqpi4nHdis6JRXEgwHul_N-iB68Qn41xQ5kRwidt6hmGgp8phLLBKG_Xb4 GVg27NRugV4Q-8Mkj1mdLaRwkIQTjnA8cMfHuyQoEhyqGHUAvDs9KrJsVrgK ayXYoMsxju5sUaKETbP5GmnupilXyzI3lEMV31uIc6Wc10IyondYLGjeAFrK QNnfydH5yctq6IrpEcfwNgYpmnVh2x-zeFidIIYimoENx7mcT_W8PE7USbVT SeqKHchRZcrB1QkU6Ffgrrf8YTems16x42QEbfEENC8j3aFwnRsbjabrTODA _jDJRYdBVZWntWkgfE5UU_4ZciMsQZhNSlELId9iNsk-Ft9HgQ==
Posted by
gavinmatix
at
10:38 AM
Nov 11, 2010
DJ CescOzone
Free MP3's For Download
All I was looking for was a song. 'Under' by Brian Eno. But my Search Query
Which looked like this:
purchased yesterday (from Salvation Army on Broadway for $6.99) has a dead shift key that I know of so far. And even though this post will direct you to a Myspace page- the tracks aren't half bad for three year old australian house mixes.
And that project with Isaac.... well I'll let him tell you about it, after I call him and setup a time to get together this afternoon.
And I poached this graphic from one of the ftp directories the Australian DJ;s archive their tracks
Enjoy.
All I was looking for was a song. 'Under' by Brian Eno. But my Search Query
Which looked like this:
brian eno under intitle:"index.of" "parent directory" "size" "last modified" "description" [snd] (mp4|mp3|avi) -inurl:(jsp|php|html|aspx|htm|cf|shtml|lyrics|mp3s|mp3|index) -gallery -intitle:"last modified" -intitle:(intitle|mp3)wasn't working like quite right, and part of the problem is that my "previously owned' Apple Extended Keyboard I
purchased yesterday (from Salvation Army on Broadway for $6.99) has a dead shift key that I know of so far. And even though this post will direct you to a Myspace page- the tracks aren't half bad for three year old australian house mixes.
And that project with Isaac.... well I'll let him tell you about it, after I call him and setup a time to get together this afternoon.
And I poached this graphic from one of the ftp directories the Australian DJ;s archive their tracks
Enjoy.
Posted by
gavinmatix
at
12:03 PM
Oct 27, 2010
what the "Bleet"?!
Just so you know...this post was originally composed by Eric Butler and he has a blog, I've just been cutting/pasting/revising periodically.
This was certainly an interesting day.Since being released just over a day ago, Firesheep has been downloaded over 129,000 times. Firesheep has consistently been one (if not more) of the “Top Tweets” on Twitter, on top of Hacker News, was at one point the #10 trending search on Google in the US, and is the second suggestion on Bing when you start typing “fire”. Firesheep has been mentioned on countless blogs and news sites in numerous languages, and has received almost universal praise.The first bug reports have started rolling in:
- "Backend exited with error 1" — This happens on Windows when you stop capturing. This message doesn’t actually indicate a real problem and can be ignored. This was a known issue that I wasn’t able to get to before the ToorCon release.
- "Run --fix-permissions first" — This problem appears to affect only Mac OS X users who are using FileVault. The current release of Firesheep is unfortunately incompatible with FileVault.
- "Funky custom tool bar icon explosion." — This one is actually a bit amusing.
There have also been a few common problems:
- No results on some Windows systems — Some users have reported that they aren’t seeing any results even when on an open network that has known insecure traffic. This may be because the wrong interface is selected. Click the gear icon at the bottom of the Firesheep sidebar and choose Preferences. From here you’ll be able to change the interface Firesheep listens on.
- Sidebar not displayed — If you’ve installed Firesheep but don’t see it, click the View menu then select Sidebar then Firesheep.
- Install error claiming Firesheep is not compatible with your version of Firefox — Several people ran into this problem because they were unknowingly running out of date (and insecure) versions of Firefox. Apparently Mozilla’s auto-update system is leaving some people behind. Currently the latest version of Firefox is 3.6.11. Firesheep is not yet compatible with the 4.0 beta.
- Compile error on Linux — Firesheep is not currently supported on Linux and will not work. Patches/pull requests gladly accepted!
The real story here is not the success of Firesheep but the fact that something like it is even possible. The same can be said for the recent news that Google Street View vehicles were collecting web traffic. It should not be possible for Google or anybody to collect this data, whether intentional or not. Going forward the metric of Firesheep’s success will quickly change from amount of attention it gains, to the number of sites that adopt proper security. True success will be when Firesheep no longer works at all.
Background on HTTP Session Hijacking
HTTP Session hijacking, as a vulnerability, is nothing new in the year 2010. It is a security vulnerability that people have been aware of for quite some time, with notable tools and papers existing at least since 2004 on this exact subject. OWASP (The Open Web Application Security Project) categorizes the issues responsible for HTTP Session Hijacking in to one of it’s Top 10 Web Security Risks, “A3: Broken Authentication and Session Management”.Firesheep is by no means the first tool to exploit this issue and raise controversy. "Ferret" and "Hamster" were a pair of tools released by Errata Security in 2007 which let users exploit Sidejacking attacks easily (well, easily for geeks, and undoubtably easy for attackers). In 2008, "Cookie Monster" was released by Mike Perry which lets you again do this same attack. Last year, (around May 2009) Azim Poonawala released the tool FBController which yet again exploited this same issue, though this time specifically targeting Facebook. Very little has changed after each of these tools were released. They got their media hype, and then people forgot or didn’t care. For the most part, the tools were only used by tech-savy people, hackers and geeks.
Firesheep
Firesheep is doing the exact same thing as these other tools, but with a simpler user interface. Firesheep is more generic than FBController, but it still needs to be aware of what sites to target.Because of its simplicity, Firesheep has already succeeded in demonstrating the risks of insecure websites to a much wider audience than any previous tool, in a single day.
Why is it hard to stay safe?
Websites that don’t have properly designed security architectures and implementations can make it very difficult for users to protect themselves. There’s a few levels of failure here that are worth noting.- Complete absence of SSL/HTTPS — This is rare nowadays for popular sites, but it’s not unheard of by any means. Until recently, Foursquare fell into this category. Naturally, if you use such sites you’re exposing everything needed to identify your session with the site, potentially even your password. This is particularly bad when you consider many people use the same password for many different accounts. It’s terrifying to think that something as mundane as a Foursquare password could get you in to that person’s email, or even financial websites.
- Charging for SSL - GitHub and Evernote are some examples where you must pay to have full-session SSL. We have not confirmed if this is implemented properly once you pony up the cash but can confirm that on GitHub a free account that is associated with a paying organization leaves that entire company at risk. A basic expectation of privacy should not be a premium feature.
- Forced SSL/HTTPS for posting of Login/Password credentials only - Most big sites are in this bucket. Facebook, Twitter, Github, etc. Years back, people realized that sending usernames and passwords in plaintext was a bad idea, and so everyone started encrypting the transmission of those particular assets, and boasting how secure they were because they use SSL with 128-bit encryption or whatever it may be, and pictures of locks everywhere. These sites may serve other content over HTTPS if you explicitly request it, but they’ll rarely be opportunistic about serving content over HTTPS. These sites fail to protect you because after you’ve authenticated, you’re issued a cookie that identifies you throughout your browsing session, but if you think about it that’s just as good as your username/password for 99% of the time.
- Full HTTPS for everything — Some sites support full encryption everywhere, but don’t implement it properly by failing to set the “Secure” flag on authentication cookies, negating most of the benefits and leaving users at risk. What that means is that any time you type the URL (e.g. “manage.slicehost.com”) into your web browser (without explicitly typing https:// beforehand, which people rarely do) you will inadvertently leak your cookies with that first request, prior to being redirected to the HTTPS page. Slicehost and Dropbox are good examples of this mistake.
Even if you’re proactive and think to log yourself out of a website, this rarely does anything but delete the cookies from your web browser - meaning any stolen copies of them are still going to work for accessing the website. Twitter, Amazon, Foursquare, Github, Flickr, Yahoo, Windows Live (Hotmail) and many others do not properly delete your session from their severs when you use their “Logout” features. Facebook, while having other problems, does appear to properly delete sessions on their servers when you “Logout”.
People forget things. It’s easy to be logged in to many of these services, sleep your laptop, and wake it up somewhere where it will instantly associate with an open access point and start spewing your cookies over the air. Hackers even fall victim to this at hacker conferences where everyone knows they shouldn’t be doing anything on the wifi. The DEFCON Wall Of Sheep is a prime example of this.
Suggestions to help protect yourself right now
While companies are implementing fixes (described below) you can do a few things to increase your level of security, but there’s no silver bullet (aside from stopping use of the services which you don’t want hijacked.)- HTTPS-Everywhere - This is a Firefox extension created by the Electronic Frontier Foundation which makes Firefox use only HTTPS connections for certain websites. Like Firesheep, it only works on a defined list of websites, so it won’t protect you if you use any websites that it doesn’t support. It does not appear to be immediately simple for users to add sites without some development experience. HTTPS-Everywhere is well respected for doing what it claims to do safely.
- Force-TLS - As mentioned earlier, some websites support SSL but don’t implement it properly, leaving you at risk. This Firefox extension is similar to HTTPS-Everywhere but allows you to specify your own list of domain names to force encryption on.
- VPN - In some situations a VPN (or something similar such as an SSH tunnel) can be great. All traffic sent through a VPN is likely secure from your computer to the VPN server. But be aware that this is not a silver bullet and there are potential problems. See below for our warnings on using a VPN.
Things NOT to do (debunking suggestions from other people/sites in response to Firesheep)
Stop using open WiFi
In response to Firesheep, lots of people are quick to say “Don’t use open wifi”. While open wifi is the prime proving ground for Firesheep, it’s not the problem. This isn’t a direct vulnerability in wifi, it’s the lack of security from the sites you’re using. Abundant, free, open wifi is great to have, it can be very useful. Low-risk activities like reading the news, looking up a nearby business or finding a bus route can be done without being logged in to such sites and risking loss of any important sessions, for example.A password-protected (WPA2) wireless network or even a wired network just requires that attackers perform one more step to carry out this attack. This might be ARP poisoning or DNS spoofing, neither of which are difficult to carry out. Go and download Cain & Abel and try it out on your network, it’s not that much harder than using Firesheep, and it’s been around for nearly a decade. There are other tools that’ve been around longer.
Another problem is that anyone who has your wireless password could set up their own rogue access point. If they have the stronger signal than the “official” access point everyone in the room will automatically connect to it instead and begin sending all their traffic to the attacker. WPA2 Enterprise was designed to solve this problem by allowing clients to verify the authenticity of the access point they are connected to. Unfortunately in addition to being very difficult to configure, a flaw known as "Hole 196" was recently discovered allowing users on the same network to spy on each other.
For these reasons it’s not very helpful to just enable WPA2 and write the password on the wall. Doing so might actually give users a dangerously false sense of security.
Use a VPN/SSH Tunnel (Without known risks) While we metnioned that VPNs and SSH tunnels can be helpful just above this, we want to emphasize that it’s just pushing the problem to that VPN or SSH endpoint. Your traffic will then leave that server just as it would when it was leaving your laptop, so anyone running Firesheep or other tools could access your data in the same way. These are solutions that require at least some understanding of networking and risks at hand. A blind suggestion of “Use a VPN” doesn’t really solve the problem and may just provide a false sense of security.
Another problem with VPNs is that they don’t work all the time. Sometimes they just disconnect, and your traffic is all routed over your normal interface without any notice. The built in VPN clients on OSX, the iPhone, and iPad are particularly bad at this.
How do website operators fix the problem?
The only correct solution to this problem is true end-to-end security. On the web, this is called HTTPS or SSL/TLS. When SSL is used properly, all traffic is encrypted (unreadable by attackers) and integrity checked (can’t be modified by attackers) from your web browser all the way to the website’s datacenter (either their actual web servers, or specialized network equipment such as SSL accelerators/load balancers).Designing with security as a requirement, rather than bolting it on after the fact, is also important. While it’s not fair to say this is always what happens, it’s not uncommon for sites to be quickly designed and developed while letting security slip by at a lower priority than other things. Design such that when you scale out, you can scale out securely. Adopt and adhere to a Secure Development Lifecycle process to ensure that security is considered at all points during a product/site’s lifecycle.
Reasons operators may say they can’t do the above
- Typically the response to implementing SSL for everything on your website has been that it’s a big performance hit. There’s an awful lot of debate about this, but there are a number of sites that require HTTPS for everything, most notably Google’s Gmail service went 100% SSL earlier this year. While it’s true Google has an amazing engineering team and impressive resources, they outline a system that should be approachable by many other sites.
- Lack of IP addresses for SSL hosts. In the past, an SSL service required a dedicated IP address. This isn’t true any more with the advent of Server Name Indication (RFC 3546) and improvements in TLS.
- Ignorance. Many people believe they are doing things correctly when they simply are not. Forcing HTTPS for everything but not marking cookies as secure is key example.
Dec 4, 2009
Because I feel like kicking it old school
You can even download it here...
I shot some video the other night during a HD volume recovery. I got about ten minutes of footage- and i really want to assemble a rough cut by this weekend. I also don't want to get delayed or too involved with the sound design. So I scoured
my legacy apps archive and found CFXR
Cfxr is a Mac port of DrPetter's sfxr. In his own words:
Its original purpose was to provide a simple means of getting basic sound effects into a game for those people who were working hard to get their entries done within the 48 hours and didn't have time to spend looking for suitable ways of doing this.
Which is perfect for my needs. I'm going to get back to work (and the document the now completed volume recovery project for which the client is paying me for).
Oh and here's a video about the application.
I shot some video the other night during a HD volume recovery. I got about ten minutes of footage- and i really want to assemble a rough cut by this weekend. I also don't want to get delayed or too involved with the sound design. So I scoured
my legacy apps archive and found CFXR
Cfxr is a Mac port of DrPetter's sfxr. In his own words:
Its original purpose was to provide a simple means of getting basic sound effects into a game for those people who were working hard to get their entries done within the 48 hours and didn't have time to spend looking for suitable ways of doing this.
Which is perfect for my needs. I'm going to get back to work (and the document the now completed volume recovery project for which the client is paying me for).
Oh and here's a video about the application.
Posted by
gavinmatix
at
5:09 AM
May 27, 2009
As far as I can tell, it was Yeats...who first came up with the concept of
'Negative Capacity'. It's just about all I can do at this time. Because I'm not angry. I knew this was going to happen- the moment one of us decided to offset the timetable. Oh..I should go ahead and note that this may take awhile, and I may indeed write/post/rant/bitch and/or vent in what would appear to be a random, haphazard musings of a struggling middle-aged artist living in, I swear to fucking god- no. wait that's why I have headphones. or to be more specific, that's why I'm wearing headphones. I like my Blackberry. got the headphone jack situation under control. SO I'm not angry because we're not going to be using the Costco bulk-kill-fuck-all indoor fogger pesticide bomb.0000 Which I was rather looking forward to. (because i require that much motivation to buy new dishes. (yes, they're beyond the doing of being "done", or "doing them". Of this one thing I stand triumphant as a slacker/slob/ ...00.0.00.00.0000...0.0..0.0..00++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++000
000

Sorry about that. I had to take a client support call. So let's do a time check: It's now 1:46pm. the original 'reschedule' was for 12:00pm. I returned from my errands at 11:30. Because. Because I'm using this energy and momentum constructively, systematically. I believe this course of action is not only practical but preferable to the alternative. The alternative would be more chaotic, malicious and destructive . To yell or arguue; assign blame or point fingers is to be wasteful and ultimately counter-productive. So , why is it that i continue to, even on a subconscious level, perpetuate or maintain the conditions that generate and subsequently foster this 'negative capacity'. I think I know why.I see that I am the Ouroboros of opportunity and initiative. I laid the bricks myself. Therefore, I'm not angry. And the reason I feel somewhat better about the whole fucking thing. The time is now 2:oopm
BTW: I was searching for this track, that was once on my LaunchCast Radio station,but guess what?! Here's the punchline and end of part one
000

Sorry about that. I had to take a client support call. So let's do a time check: It's now 1:46pm. the original 'reschedule' was for 12:00pm. I returned from my errands at 11:30. Because. Because I'm using this energy and momentum constructively, systematically. I believe this course of action is not only practical but preferable to the alternative. The alternative would be more chaotic, malicious and destructive . To yell or arguue; assign blame or point fingers is to be wasteful and ultimately counter-productive. So , why is it that i continue to, even on a subconscious level, perpetuate or maintain the conditions that generate and subsequently foster this 'negative capacity'. I think I know why.I see that I am the Ouroboros of opportunity and initiative. I laid the bricks myself. Therefore, I'm not angry. And the reason I feel somewhat better about the whole fucking thing. The time is now 2:oopm
BTW: I was searching for this track, that was once on my LaunchCast Radio station,but guess what?! Here's the punchline and end of part one
Posted by
gavinmatix
at
1:14 PM
Subscribe to:
Posts (Atom)

