Breaking: Google Has Begun Purging Ad-Blocking Apps From The Play Store
Thursday, March 14, 2013
Sunday, March 03, 2013
Bullet lists dilute thought
Edward Tufte forum: Lists: design and construction, by Edward Tufte
As a heavy http://orgmode.org user I'm going to have to chew on this one. It is my subjective experience that org-mode promotes thought. It allows me to quickly capture, arrange, document and support my thinking (and coding). In addition it effortlessly promotes transformation of my outlines into a myriad of output formats (TeX, PDF, HTML, text and, yes, ms-word and PPT if one must).
Maybe the difference is I'm usually describing code, data and analytical processes rather than business plans or marketing pitches.
But this (as most things Tufte says) is well worth pondering.
And I just used sentences, not bullet points to begin exploring the thoughts.
Monday, February 18, 2013
ShmooCon 2013: Experiences and Reflections
Here are some thoughts and experiences from ShmooCon 2013.
1 Labs
I spent Thursday morning to Sunday evening working ShmooCon Labs. The labs are a group of volunteers that stand up the networking infrastructure for ShmooCon: fiber, switches, routers, DHCP, DNS, IDS, network monitoring. This is all done in under 36 hours by volunteers using donated hardware (shout out to Matt Hum and Entarasys for providing a metric-boatload of switches, defined as an entire pallet.)
My main support to the effort was helping with the layer 1 and 2 setup early on. Nothing else works until the photons, electrons, frames and packets start flowing. Switch-configs-R-Us. The making of sausages, laws and the innards of hotel wiring closets, telco rooms and NOCs are similarly not pretty.
Enterasys also loaned 50 wireless access points (WAPs). We wound up only needing to deploy 40. The end result was a redundant 10G core (Matt was shooting for 20G but had issues) feeding a 20Mb up-link. There were 3 wireless networks, one open, two secure (well, maybe not, considering the [ab]users). There were VLANs for admin, each of the teams, the wireless networks, and the various sub-events. Palo Alto Networks the the layer-3 firewall, and Liam Randall had Bro running on the Security Onion doing data capture and monitoring. AOL also monitored the network using their newly released tool, Moloch, capturing packets and indexing them. The team brought up IPv6 on the wireless network, because they could. The network "Hum-ed" (sic) along for the required 48 hours, supporting the 1700 attendees needs and various events. Then we tore it all down.
I would highly recommend working labs if you:
- like to play with networking gear
- like to make things work
- want to learn something new
- have some tool, tech, etc. you want to try out
- want to work with some great people for a long weekend
The kicker is, of course, that you need to get a ShmooCon ticket before you can register for labs. Thanks to Liam Randall (@hectaman), for giving me his speaker +1 ticket).
2 Talks
The surface level justification for attending cons and workshops is the talks. Here are a few things that caught my attention:
2.1 Opening Remarks
- Bruce Potter said, among other things, that ShmooCon is moving more towards defensive technologies.
2.2 Panel Discussion: Hackers get Schooled: Learning Lessons from Academia
This was an interesting subject. What are the differences between academic papers and conferences and "hacker cons". What's good about peer-reviewed work vs. a random tweet or pastebin entry describing a new exploit? A few quotes (see the video for attribution)
- "Research is the art of failing until you don't"
- "My job as an academic is to disclose. To think of things and tell people.", Matt Blaze (@mattblaze) In the context of discussion of full-disclosure and release of exploits.
- "A new way to own a Cisco router is a one-off, not new, fundamental results". This is part of the difference between what makes a good talk at a hacker-con and an academic result.
- "If it changes the way you think, it's research"
- "Hackers aren't serious, academics aren't useful", Matt Blaze, quoting a possibly-true-at-times truism
- "The best stuff at hacker cons is just as deep as the best academic papers" … in the context of discussion of peer review.
- "Academics and hackers leave different artifacts and have different rewards."
- "The research process can be overbearing/stifling to the hacker process"
- "It's hard to cite a tweet. The hacker body of knowledge can be very ephemeral ", Bruce Potter.
2.3 Panel Discussion: Running a Capture-The-Flag (CTF) Event
A number of the core labs team got together after labs last year and decided to participate in the construction and execution of a capture-the-flag event. This talk shared their lessons learned. Many interesting observations. Watch the video. The one really high level take-away for me is that CFT events are, fundamentally, sociology experiments where technology is only the medium. I'm becoming convinced that this is true of the field as well.
2.4 Talk, Demo: Moloch: A New and Free Way To Index Your Packet Capture Repository
If you thought it was fun to read AIM messages from your friends, why not read all the AIM messages from everyone on your network, and their DNS queries, and their email, and their downloads, and their malware ? Full packet capture, archiving and indexing can be fun and useful for network defense and forensic investigation. Who's running old versions of Java? Who downloaded malware that matches known malware hashes? That's some of what the Moloch tool does. It was released by AOL as open source on github with the aim of doing all that in a scalable fashion (as in, on the scale of AOLs network).
2.5 Talk, Demo: NSM And More With Bro Network Monitor
Liam Randall talked about Bro. He said to "Think of it as a domain specific Python" [for processing packets and network events]. He cover the "Bro Model", which comprised events for packets and higher level network objects, scripting, and the Bro IDS as one ("the first great") application of the object and scripting model, he discussed the scripting model, where analyzers unroll protocols, events are placed in queues and event handlers pull events from the queue. Earlier he had rolled a twitter-bot to post live events to twitter as Bro watched the ShmooCon network (such as people connecting to known malware sites, etc). He provided a number of example scripts, including the twitter-bot, scripts to examine various extracted protocol elements and http brute force detection at https://github.com/LiamRandall/bro-scripts
3 People
The real justification for attending cons and workshops is the people. Networking. Social networking. The in-your-face-not-faceboook kind of social networking kind. I did lots of that. It's amazing how small the social diameter of the profession is.
4 Bling
- How many black T-shirts do you need ?
- The best bling were mice with LEDs and a real scorpion embedded.
- One of my coworkers got a copy of Control-Alt-Hack card game for correctly answering a trivia question.
- The proprietor of SkyDogCon was handing out interlocking M.C.Escher-esq interlocking lizard puzzle pieces.
- Palo Alto Networks was giving away copies of the multiple-ending book "Data Center of Doom", advertising, but entertaining advertising.
5 Pictures
Here are some some pictures of the Future of Banking Summit in Paris, France (do you believe everything you read online ?). Permission given by all human subjects. I didn't ask the sea-gulls.
The sign on the hotel networking rack was amusing, they seem to have forgotten that "All your ports are belong to us."
6 Proceedings, Videos
The presentations and videos will, presumably, be available at http://www.shmoocon.org/archives soon. Some are available now wt https://www.google.com/search?q=shmoocon+2013+youtube
7 FloCon
Lastly, shameless plug. If you like, ShmooCon, consider attending http://flocon.org next year. We focus on large-scale defensive technologies (usually involving Netflow analysis), but, alas, no Shmoo Balls…
Wednesday, February 13, 2013
Esse aut non esse
Esse aut esse non, illa quaestio est = To be or not to be, that is the question.http://www.textkit.com/greek-latin-forum/viewtopic.php?f=3&t=11013
Is the Latin correct in the above equation?
Monday, February 11, 2013
Locking Cells in OOCALC
Thursday, February 07, 2013
Saturday, January 26, 2013
Security Onion on Virtual Box
Friday, April 01, 2011
Dear pcapr users,
As you already know, pcapr has become the largest online repository for packet captures, with over 60 million packets online. With 420+ protocols and 2800+ distinct packet captures, pcapr has become a reference platform for those that seek packet traces and want to collaborate on them. We have global service providers, government agencies, networking vendors, IT and security folks as active users and we continue to see new users rapidly embrace this platform.
Recently, we embarked on transforming all of the pcaps into the pcap-ng format, which is capable of storing meta data into each capture. We thought it would be really cool to tag these packet captures with the user that uploaded it into pcapr, but made a grave error.
Through a not-so-common programming mistake (off-by-31337 error), each of the 60 million packets was tagged with *every* pcapr user's email as well as the password. While we never stored your password in the clear, the MD5-hash of your password in the meta data is prone to brute-force cracking attacks to reveal the plain text password. We are terribly sorry for this grave mistake and we are taking all the right measures to ensure that this will never happen again. We are also stunting innovation across the entire pcapr team and rolling back all of the pcap-ng migration efforts.
We highly recommend that you manually inspect each of the 60 million packets on pcapr to ensure that your credentials are safe. We deeply apologize for the inconvenience and we sincerely hope that this will not discourage your future pcapr experience.
Thanks,
The Pcapr Team
April 1, 2011
http://www.pcapr.net
http://twitter.com/pcapr
http://labs.mudynamics.com
Thursday, September 16, 2010
Saturday, November 21, 2009
Turnkey Linux appliances
For all those times you don't want to do your own split horizon DNS configs....
in reference to: Turnkey Linux Virtual Appliance Library | Best of Open Source: Simplified (view on Google Sidewiki)Sunday, November 01, 2009
How much does it usually rain ?
Cut the weather marketing crap.
How much does it usually rain ?
How much has it actually rained ?
Cut through all the weather marketing.
How much as it actually rained ?
(he says, having camped 3 weekends in
October in the pouring rain, currently listening
to more rain outside)
Tuesday, October 13, 2009
Tuesday, October 06, 2009
Sunday, May 31, 2009
#! /usr/bin/python
# $Id: sunspots.py,v 1.1 2009/05/31 12:08:08 george Exp george $
#
# Plot sunspot data.
#
# Adapted from
#
# http://linuxgazette.net/115/andreasen.html
#
# this was the original program. Dataset from
#
# http://linuxgazette.net/115/misc/andreasen/sunspots.dat
#
# Nice examples of using the newer plotting libraries can be found here:
#
# http://www.daniweb.com/code/snippet691.html
#
# History:
# Created: George Jones, 5/30/09
#
# $Log: sunspots.py,v $
# Revision 1.1 2009/05/31 12:08:08 george
# Initial revision
#
#
import math
import pylab # matplotlib
from scipy import *
import scipy.io.array_import
# Generate x,y datasets (year,wolfer)
tempdata = scipy.io.array_import.read_array('sunspots.dat')
year=tempdata[:,0]
wolfer=tempdata[:,1]
#
# Plot year vs number of sunspots
#
pylab.xlabel("Year")
pylab.ylabel("Wolfer number")
pylab.plot(year, wolfer, 'b')
# save the plot as a PNG image file (optional)
pylab.savefig('sunspots_time.png')
# show the pylab plot window
# you can zoom the graph, drag the graph, change the margins, save the graph
pylab.show()
#
# Take FFT of #s of sunspots, generating real and imaginary
#
Y=fft(wolfer)
pylab.xlabel("real(FFT)")
pylab.ylabel("img(FFT)")
pylab.title("Meas")
pylab.plot(Y.real, Y.imag, 'ro')
pylab.xlim(-4000,2000)
pylab.savefig('sunspots_FFT.png')
pylab.xlim(-4000,2000)
pylab.show()
#
# Compute the frequency of sunspots
#
n=len(Y)
power = abs(Y[1:(n/2)])**2
nyquist=1./2
freq=array(range(n/2))/(n/2.0)*nyquist
pylab.xlabel("Frequency [1/year]")
pylab.ylabel("|FFT|**2")
pylab.title("Meas")
pylab.plot(freq[1:len(freq)], power, 'b')
pylab.xlim(0,0.20)
pylab.savefig('sunspots_freq.png')
pylab.xlim(0,0.20)
pylab.show()
#
# Given the frequency, compute the period
#
period=1./freq
pylab.xlabel("Period [year]")
pylab.ylabel("|FFT|**2")
pylab.title("Meas")
pylab.plot(period[1:len(period)], power, 'b')
pylab.xlim(0,40)
pylab.savefig('sunspots_period.png')
pylab.xlim(0,40)
pylab.show()
Friday, August 15, 2008
About Me
Followers
Blog Archive
-
▼
2013
(17)
- ► 10/13 - 10/20 (1)
- ► 07/28 - 08/04 (1)
- ► 05/26 - 06/02 (1)
- ► 04/21 - 04/28 (1)
- ► 03/31 - 04/07 (1)
- ► 03/17 - 03/24 (1)
- ► 03/10 - 03/17 (1)
- ► 03/03 - 03/10 (1)
- ► 02/17 - 02/24 (1)
- ► 02/10 - 02/17 (3)
- ► 02/03 - 02/10 (2)
- ► 01/20 - 01/27 (2)
-
►
2011
(1)
- ► 03/27 - 04/03 (1)
-
►
2010
(1)
- ► 09/12 - 09/19 (1)
-
►
2009
(6)
- ► 11/15 - 11/22 (1)
- ► 11/01 - 11/08 (2)
- ► 10/11 - 10/18 (1)
- ► 10/04 - 10/11 (1)
- ► 05/31 - 06/07 (1)
-
►
2008
(7)
- ► 08/10 - 08/17 (3)
- ► 08/03 - 08/10 (2)
- ► 07/13 - 07/20 (2)
-
►
2006
(23)
- ► 12/17 - 12/24 (1)
- ► 12/03 - 12/10 (2)
- ► 11/26 - 12/03 (1)
- ► 10/22 - 10/29 (1)
- ► 10/01 - 10/08 (1)
- ► 08/06 - 08/13 (1)
- ► 07/09 - 07/16 (1)
- ► 06/25 - 07/02 (1)
- ► 06/11 - 06/18 (3)
- ► 06/04 - 06/11 (1)
- ► 05/21 - 05/28 (5)
- ► 04/30 - 05/07 (1)
- ► 03/05 - 03/12 (2)
- ► 02/19 - 02/26 (1)
- ► 02/05 - 02/12 (1)
-
►
2005
(20)
- ► 12/25 - 01/01 (1)
- ► 12/18 - 12/25 (2)
- ► 11/27 - 12/04 (1)
- ► 11/13 - 11/20 (1)
- ► 10/09 - 10/16 (1)
- ► 09/11 - 09/18 (3)
- ► 05/22 - 05/29 (1)
- ► 05/08 - 05/15 (2)
- ► 05/01 - 05/08 (3)
- ► 04/24 - 05/01 (2)
- ► 03/13 - 03/20 (1)
- ► 02/13 - 02/20 (2)
-
►
2004
(3)
- ► 08/15 - 08/22 (1)
- ► 05/16 - 05/23 (2)
-
►
2002
(6)
- ► 09/29 - 10/06 (1)
- ► 09/22 - 09/29 (1)
- ► 09/15 - 09/22 (2)
- ► 09/08 - 09/15 (2)
