<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-5731464</atom:id><lastBuildDate>Tue, 06 Dec 2011 21:30:45 +0000</lastBuildDate><category>Nikto</category><category>AA</category><category>Macworld</category><category>Research</category><category>Airport</category><category>Breadboard</category><category>SQL</category><category>AES</category><category>Hack</category><category>Regular Expressions</category><category>Amazon</category><category>Google Docs</category><category>finder</category><category>Lala</category><category>Windows</category><category>NAS</category><category>Apple</category><category>AdWords</category><category>WPA2</category><category>Gateway</category><category>PCI-DSS</category><category>Apps</category><category>Google Bookmarks</category><category>Networking</category><category>Marketing</category><category>Gawker</category><category>Visibo</category><category>Last.fm</category><category>Apache</category><category>EC2</category><category>DSU</category><category>sites</category><category>Virtual Machine</category><category>WTC</category><category>VMWare</category><category>mysql</category><category>CAD</category><category>CSS</category><category>PDF</category><category>Lynx</category><category>Asimov</category><category>CVS</category><category>Gmail</category><category>Slowloris</category><category>Perl</category><category>Extensions</category><category>BASE</category><category>SuSE</category><category>bash</category><category>IP Exclude</category><category>USB</category><category>Dashboard</category><category>Automator</category><category>Sun xVM Virtual Box</category><category>Netgear</category><category>Development</category><category>Firefox</category><category>Ping</category><category>iTunes</category><category>Urchin</category><category>Snort</category><category>WHOIS</category><category>Utiltiy</category><category>Hardy Heron</category><category>CODASPY</category><category>Link Generator</category><category>CMS</category><category>mp3</category><category>Ulteo</category><category>Branding</category><category>Breach</category><category>Kit</category><category>4Chan</category><category>911</category><category>Apache2</category><category>Python</category><category>Unix</category><category>NIDS</category><category>Vista</category><category>Google Labs</category><category>return</category><category>IDS</category><category>XP</category><category>WYSIWYG</category><category>Pandora</category><category>Button</category><category>HIPPA</category><category>Samba</category><category>CISSP</category><category>Incredible Start Page</category><category>eCalc</category><category>Statistics</category><category>Toolbar</category><category>Encryption</category><category>Amateur Radio</category><category>Security</category><category>Leopard</category><category>OS X</category><category>Guild Wars</category><category>Electronics</category><category>Mathematics</category><category>Chrome</category><category>Links</category><category>D.Sc</category><category>Software</category><category>SIGSAC</category><category>Crontab</category><category>XHTML</category><category>Mojave</category><category>Added Bytes</category><category>FCC</category><category>Distribution</category><category>Cloud</category><category>linux</category><category>KDE</category><category>LAMP</category><category>ACM</category><category>domain authentication</category><category>php</category><category>HAM Radio</category><category>music</category><category>information systems</category><category>YouTube</category><category>Google</category><category>Lego</category><category>doctoral</category><category>EndNote</category><category>Fallout</category><category>Ping.fm</category><category>paypal</category><category>SEO</category><category>Google Desktop</category><category>DoS</category><category>HAM</category><category>Ubuntu</category><category>Sourceforge</category><category>SSID</category><category>weebly</category><category>WiFi</category><category>Google Buzz</category><title>The Ramblings of a Geek with A.D.D.</title><description>Technology and Education Blog of Chris Copeland</description><link>http://roninuta.blogspot.com/</link><managingEditor>noreply@blogger.com (Chris)</managingEditor><generator>Blogger</generator><openSearch:totalResults>71</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/roninuta" /><feedburner:info uri="roninuta" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><geo:lat>32.57701</geo:lat><geo:long>-97.134859</geo:long><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-5681165827934371081</guid><pubDate>Sun, 20 Nov 2011 23:24:00 +0000</pubDate><atom:updated>2011-11-20T17:33:36.969-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">Software</category><category domain="http://www.blogger.com/atom/ns#">php</category><title>Paros Web Proxy</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-dTIIqsUzAKg/TsmMRdReRqI/AAAAAAAAAis/b9UiU3h2Er4/s1600/paros.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-dTIIqsUzAKg/TsmMRdReRqI/AAAAAAAAAis/b9UiU3h2Er4/s1600/paros.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;
As this semester wraps up at both universities I found myself rapidly trying to grade papers as well as complete my own projects. One of the projects I needed to complete was a network and web security course at DSU. I used nikto in a&lt;a href="http://www.blogger.com/blogger.g?blogID=5731464#editor/target=post;postID=2634796146142313587"&gt; previous post&lt;/a&gt; to discuss the use of the software in vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
I have used proxy software in the past, but never in the capacity of vulnerability assessment. Now the project was to break a PHP script and gain remote access. This actually turned out to be more simplistic than I anticipated, but what was surprising was how useful the &lt;a href="http://www.parosproxy.org/"&gt;paros proxy software&lt;/a&gt; was in accomplishing that particular goal.&lt;br /&gt;
&lt;br /&gt;
The software is designed to allow you to see all the GET and POST messages, content, delivery of regular web traffic between your host and the remote server. It has two nifty features though; cookie storage and spider crawl. I used the spider functionality to grab the listing of html the did a directory grep for *.php to find my script call. This saved hours of time looking though the site and really let me get to the heart of the assignment.&lt;br /&gt;
&lt;br /&gt;
Paros should be added to any suite of network vulnerability tools for use in pen testing. I highly recommend it.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-5681165827934371081?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=LqRxHGtf6ho:K3CTi3YLaDk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=LqRxHGtf6ho:K3CTi3YLaDk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=LqRxHGtf6ho:K3CTi3YLaDk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=LqRxHGtf6ho:K3CTi3YLaDk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=LqRxHGtf6ho:K3CTi3YLaDk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/LqRxHGtf6ho/paros-web-proxy.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-dTIIqsUzAKg/TsmMRdReRqI/AAAAAAAAAis/b9UiU3h2Er4/s72-c/paros.PNG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/11/paros-web-proxy.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-1865409274863783459</guid><pubDate>Thu, 06 Oct 2011 13:26:00 +0000</pubDate><atom:updated>2011-10-06T11:38:02.003-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">OS X</category><category domain="http://www.blogger.com/atom/ns#">Apple</category><title>My Apple Story</title><description>To all of you in Cupertino and Austin and to the family of Steve, my heart and thoughts are with you.&lt;br /&gt;
&lt;br /&gt;
The world is mourning the passing of &lt;b&gt;Steve Jobs&lt;/b&gt; today, and so am I. Steve passed away yesterday after a long battle with cancer. For those of you who use apple products, the iPhone, iPad, iPod, Macs, this is a sad day. For those of us who spent time at Apple, it's almost a personal loss.&lt;br /&gt;
&lt;br /&gt;
My first computer was a Commodore 64 with dual floppy (5.25) drives. It was soon and quickly replaced with the first Macintosh. I was in love. I bounced from the 128 to the 512k model in a year, then to the SE, SE/30, and ultimately to the LC I. My first personal computer at home was the LCII followed by a Performa 6116CD (my first PPC chip), 8150 WGS, beige G3/233, and finally Blue&amp;amp;white G3 with a G4 upgrade. Twenty years of history and memories defined by the Apple products I used at home and at work. I learned almost everything I know about computing (which is a lot, but not exhaustive) on the Macintosh Platform.&lt;br /&gt;
&lt;br /&gt;
In 1995 I started a contract with Apple at a call center for the AAC (I still have my 1990s Apple Assistance coffee cup). I worked for Apple during the dark times. The times of licensing the OS, clones, Pippen, OS 7.5, and Gil Amelio. It was a hard time for Apple, there was a loss of focus on innovation, easy of use, and technology. Stock prices and market share were at an all time low and nay-sayers were constantly predicting the closure of Apple's doors. Yet there was always this spirit of hope. In the last few months of my tenure there, Apple bought NeXT, and it was announced that Steve would be returning as a consultant. I left that job to go work elsewhere. I received my hardware and software certifications during that time and was happy to see things beginning to change.&lt;br /&gt;
&lt;br /&gt;
Then the most amazing thing happened, &lt;b&gt;iMac&lt;/b&gt;. Ditch the beige boxes of yesterday and make the internet and home computing fun again for the everyday person. Apple stopped trying to compete with the PC market and made something fun and interesting again. iTunes and iPod were just around the corner bringing to the masses the wonders of mp3s. iPod was not the first mp3 player. I owned a Rio (which worked with iTunes at the time), but in my opinion, the iPod changed the world. Mobile devices were never so easy to use, so well integrated with the GUI and operating environment.&lt;br /&gt;
&lt;br /&gt;
With the dissolving of the AIM alliance and the release of OSX, Macintosh computers exploded on the scene as well. Innovation and design was alive again at Apple.&lt;br /&gt;
&lt;br /&gt;
I could go on about the innovation of the iPhone and iPad as well, but those are much less personal to me. I turned many people to the Mac platform. I've used it for 27 years now.&lt;br /&gt;
&lt;br /&gt;
The world became a better place for the technology and innovation developed by the Steves (yes I hold Woz in the same regard). My only hope is that Apple continues to foster and nurture the abilities of other visionaries and innovators.&lt;br /&gt;
&lt;br /&gt;
Thank you Steve, you will be missed. Rest now our friend.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-1865409274863783459?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=7CtMkE7V0i8:edqAcnd1Cqs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=7CtMkE7V0i8:edqAcnd1Cqs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=7CtMkE7V0i8:edqAcnd1Cqs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=7CtMkE7V0i8:edqAcnd1Cqs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=7CtMkE7V0i8:edqAcnd1Cqs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/7CtMkE7V0i8/my-apple-story.html</link><author>noreply@blogger.com (Chris)</author><thr:total>1</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/10/my-apple-story.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-2634796146142313587</guid><pubDate>Mon, 26 Sep 2011 12:49:00 +0000</pubDate><atom:updated>2011-09-26T07:50:47.719-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">linux</category><category domain="http://www.blogger.com/atom/ns#">Unix</category><category domain="http://www.blogger.com/atom/ns#">Nikto</category><title>Nikto2</title><description>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://cirt.net/images/alienlogo.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://cirt.net/images/alienlogo.gif" /&gt;&lt;/a&gt;&lt;/div&gt;I have been working on a project for my information security class. It requires me to test and gather information on a server before attempting to penetrate it. I have managed to build a good list of information on the server, but I have not managed to penetrate it yet. Of course I'm trying to do this without the use of scripts or applications designed for this server's vulnerabilities, so I'm doing it the hard way, but honestly, did anyone expect anything less of me?&lt;br /&gt;
&lt;br /&gt;
So I'm working though trying to find all the tools I can use to discover all the possible vulnerabilities and I remember nikto. For those who are not familiar with &lt;b&gt;Nikto&lt;/b&gt;, it is a web server vulnerability tool, a very vertically aligned form of metasploit (which I wish had student licenses). &lt;b&gt;&lt;a href="http://cirt.net/nikto2"&gt;Nikto 2&lt;/a&gt; &lt;/b&gt;has come along way since the last time I looked at it and seems to be very stable. The thing I like most about Nikto is the mutation capability, being able to change what I need to accomplish my goal. This goes beyond just adding parameter tags, to being able to actively get content loaded on the server. It also has a export to metasploit function which enables this to be added to a pen tester's suite of tools. Nice.&lt;br /&gt;
&lt;br /&gt;
Within a few minutes and a good nmap scan I was able to determine a mostly complete range of vulnerabilities on the project server. Of course the hard part is actually utilizing these vulnerabilities and exploiting them, but then again, that what I'm being graded on. &lt;b&gt;Nikto 2&lt;/b&gt; is working flawlessly on my ubuntu server, my Solaris VM, and my OSX laptop (10.7 Lion).&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-2634796146142313587?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=MwYIyJ1RCko:Symdmo-rsXs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=MwYIyJ1RCko:Symdmo-rsXs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=MwYIyJ1RCko:Symdmo-rsXs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=MwYIyJ1RCko:Symdmo-rsXs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=MwYIyJ1RCko:Symdmo-rsXs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/MwYIyJ1RCko/nikto2.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/09/nikto2.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-8150098455624029378</guid><pubDate>Tue, 30 Aug 2011 11:57:00 +0000</pubDate><atom:updated>2011-08-30T06:57:34.713-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Snort</category><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">Slowloris</category><category domain="http://www.blogger.com/atom/ns#">DoS</category><title>Slowloris and RDP</title><description>I was reading up on one of the latest worms to be released this week. It uses RDP to initiate a session and then attempts a dictionary attack against windows based hosts. It would seem that this is one of the first attempts to utilize what is really thought of as a utility to initiate a penetration. If one were to be cleaver enough, RDP as a utility and terminal services could become a more prominent attack vector.&lt;br /&gt;
&lt;br /&gt;
I remembered reading about a HTTP SYN flood utility in an IRC channel once a few months ago. Slowloris had been demonstrated at a defcon at one point (I'm not sure which one), but it made me wonder if there have been attempts to initiate half open sessions to terminal services in the past. It could be argued that since the TCP stack in slowloris actually initiates and completes a connection, many of the more common remote options could be targeted via DoS. Since most use the TCP stack and then hand off to another service, most of them could be real targets, especially ones which are not used in the main arena of remote connectivity, like TeamView or something similar.&lt;br /&gt;
&lt;br /&gt;
Now I know that there are defenses against Slowloris, but it requires looking at the number of open connections and determining if that number is too many. This defense would need to be set against each type of remote connection across any number of ports for RDP, ARD, and VNC. Whitelists and constant monitoring would also have to be setup.&lt;br /&gt;
&lt;br /&gt;
It also make me wonder if NetFlow can detect the number of simultaneous connections rather than leaving it to a script running on the host. I will look to see if snort has any specific signatures to determine a slowloris attack and if that sig can be tweaked to look at other services beyond HTTP. I also wonder if Metasploit has a similar vulnerability in the framework.&lt;br /&gt;
&lt;br /&gt;
I guess it's time to go read more...&lt;br /&gt;
&lt;br /&gt;
&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-8150098455624029378?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=wGaz4KRZdGA:TDMteeP0RL8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=wGaz4KRZdGA:TDMteeP0RL8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=wGaz4KRZdGA:TDMteeP0RL8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=wGaz4KRZdGA:TDMteeP0RL8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=wGaz4KRZdGA:TDMteeP0RL8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/wGaz4KRZdGA/slowloris-and-rdp.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/08/slowloris-and-rdp.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-4683544046619677728</guid><pubDate>Wed, 06 Jul 2011 11:30:00 +0000</pubDate><atom:updated>2011-07-06T06:30:39.754-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Regular Expressions</category><category domain="http://www.blogger.com/atom/ns#">Amazon</category><category domain="http://www.blogger.com/atom/ns#">Added Bytes</category><title>Regular Expressions</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-GpS1JWFRCv8/ThRFlLNGxoI/AAAAAAAAAfs/IoGiS6Q9cBg/s1600/Sams+Teach+Yourself+Regular+Expressions+in+10+Minutes.jpeg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-GpS1JWFRCv8/ThRFlLNGxoI/AAAAAAAAAfs/IoGiS6Q9cBg/s200/Sams+Teach+Yourself+Regular+Expressions+in+10+Minutes.jpeg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;I was setting up a sed script last week when I realized that I needed a regular expression. No big deal right, Google is your friend and I should just be able to find it quickly. I can never do things the easy way though.&lt;br /&gt;
&lt;br /&gt;
I went on a search to improve my limited understanding of regex. I found it...a book. &lt;b&gt;Sam's Teach Yourself Regular Expressions in 10 minutes&lt;/b&gt;. I'm not normally a fan of the Sams Teach Yourself line. First off with work, school, and classes finding extra time to read something "on the side" is more than problematic (just ask my growing collection of unread Asimov's Sci-Fi). Secondly, I have found&amp;nbsp;&amp;nbsp;in the past&amp;nbsp;that the tutorials in the Sams books have been inadequate for what I was needing. I am pleasantly wrong about this book.&lt;br /&gt;
&lt;br /&gt;
The examples are simple, to the point, and reasonably well explained with each lesson building on the last with good results. Being able to use this in command line with grep is solidifying my grep practice as well. I'm hitting one chapter each morning just after normal studies and before my sysadmin jobs starts. Completing a chapter and being able to use what I learned throughout the day is a pleasant feeling and quite rewarding.&lt;br /&gt;
&lt;br /&gt;
Now I just need to see if they produce a vi book, I'm probably the last emacs holdout in North Texas and the pressure is mounting, the senior unix admin refuses to let me install emacs or nano on any of the solaris boxes.&lt;br /&gt;
&lt;br /&gt;
If you want to beef up on regex, check out the book. I believe I got it from &lt;a href="http://www.amazon.com/Teach-Yourself-Regular-Expressions-Minutes/dp/0672325667/ref=sr_1_4?ie=UTF8&amp;amp;qid=1309951323&amp;amp;sr=8-4"&gt;Amazon for about $11&lt;/a&gt;. I would also recommend getting a copy of the &lt;b&gt;&lt;a href="http://www.addedbytes.com/cheat-sheets/"&gt;Added Bytes Cheat Cheets&lt;/a&gt;&lt;/b&gt;, which is an excellent resource for regex as well as many other programming topics. You can find Added Bytes &lt;a href="http://www.addedbytes.com/cheat-sheets/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-4683544046619677728?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=-gSD1ZPKnVs:_z-men6mJtE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=-gSD1ZPKnVs:_z-men6mJtE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=-gSD1ZPKnVs:_z-men6mJtE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=-gSD1ZPKnVs:_z-men6mJtE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=-gSD1ZPKnVs:_z-men6mJtE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/-gSD1ZPKnVs/regular-expressions.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-GpS1JWFRCv8/ThRFlLNGxoI/AAAAAAAAAfs/IoGiS6Q9cBg/s72-c/Sams+Teach+Yourself+Regular+Expressions+in+10+Minutes.jpeg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/07/regular-expressions.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-3364847941658159023</guid><pubDate>Mon, 30 May 2011 19:40:00 +0000</pubDate><atom:updated>2011-05-30T14:40:04.748-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">Cloud</category><category domain="http://www.blogger.com/atom/ns#">SuSE</category><category domain="http://www.blogger.com/atom/ns#">linux</category><category domain="http://www.blogger.com/atom/ns#">Amazon</category><category domain="http://www.blogger.com/atom/ns#">Ubuntu</category><category domain="http://www.blogger.com/atom/ns#">EC2</category><title>Summer Semester: Shift in Focus</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-b28LsH7q3PE/TePjBpc0wGI/AAAAAAAAAes/lzBPZIL9GJs/s1600/Amazon+Web+Services.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-b28LsH7q3PE/TePjBpc0wGI/AAAAAAAAAes/lzBPZIL9GJs/s1600/Amazon+Web+Services.gif" /&gt;&lt;/a&gt;&lt;/div&gt;EC2...wow, just wow. As I sit here trying desperately to wade through the massive amount of material I must read and prep in 23 days, I sit in awe of how Amazon has implemented the EC2. You are probably wondering why I have sprung this topic without any sort of prelude or previous mention, well that's a funny story actually and it all revolves around being flexible.&lt;br /&gt;
&lt;br /&gt;
So I registered for a seminar course this summer, INFS 890. I must take and pass six of these courses to meet the requirements for the DSc program. What I did not realize involves two things: 1. I have completed my core and 2. It's all specialization and dissertation work from here on out. INFS 890 prepares you for dissertation by allowing you to schedule time and resources for your dissertation topic. I now have a dissertation area, professor, and direction.&amp;nbsp;So when discussing the needs of the course with the instructor I came to a choice, a fork in the road if you will, between network security and cloud security. Given the resources and position of my current work projects I chose cloud security, and to quote Indiana Jones, it would seem that I have chosen wisely.&lt;br /&gt;
&lt;br /&gt;
I started playing with &lt;a href="http://aws.amazon.com/ec2/"&gt;EC2&lt;/a&gt; last week after reading the &lt;a href="http://aws.amazon.com/message/65648"&gt;apology letter from Amazon regarding the recent outage&lt;/a&gt;. The way that the infrastructure is set up is amazing. I started creating my own instances and modifying other AMIs to meet my curiosity. Wow...30 seconds to VM creation. So many distributions and so inexpensive. Being able to set the instances in a good arrangement then setting that arrangement as a cloud formation. Wow. I loved being able to setup &lt;a href="https://help.ubuntu.com/community/EC2StartersGuide"&gt;Ubuntu&lt;/a&gt; in just minutes. I doubt I will ever need a home machine to do OS testing and learning. I have been trying to get back into &lt;a href="http://www.novell.com/linux/"&gt;SuSE &lt;/a&gt;and instead of buying or re-purposing a machine to do this, I can now just launch a AMI, make the changes I need, and continue on my merry way.&lt;br /&gt;
&lt;br /&gt;
This does leave some serious security questions though, and if the literature at this point is any indication, EC2 security is being left in the hands of the users. The literature on this is far from sparse (YAY), meaning it's a hot topic and there is no great silver bullet answer. I have seen some excellent ideas in the articles so far and I am starting to implement them myself in my own test cloud. Of course I do have to watch the cost, but that's why I applied to the &lt;a href="http://aws.amazon.com/education/"&gt;AWS in Education&lt;/a&gt; program, perhaps with a little luck, Amazon will allow me to play and learn at a reduced cost.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-3364847941658159023?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=jfLdUmbRksU:tiy8BUwUYD0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=jfLdUmbRksU:tiy8BUwUYD0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=jfLdUmbRksU:tiy8BUwUYD0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=jfLdUmbRksU:tiy8BUwUYD0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=jfLdUmbRksU:tiy8BUwUYD0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/jfLdUmbRksU/summer-semester-shift-in-focus.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-b28LsH7q3PE/TePjBpc0wGI/AAAAAAAAAes/lzBPZIL9GJs/s72-c/Amazon+Web+Services.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/05/summer-semester-shift-in-focus.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-582651545220929473</guid><pubDate>Thu, 24 Mar 2011 12:03:00 +0000</pubDate><atom:updated>2011-03-24T09:42:18.350-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">ACM</category><category domain="http://www.blogger.com/atom/ns#">SIGSAC</category><category domain="http://www.blogger.com/atom/ns#">CODASPY</category><category domain="http://www.blogger.com/atom/ns#">CISSP</category><title>Spring Update: So Far Behind!</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh6.googleusercontent.com/-9x1tfDQlDQY/TYsuQJHuh1I/AAAAAAAAAdY/eUqoU5Mx9fM/s1600/acm_logo.jpeg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="https://lh6.googleusercontent.com/-9x1tfDQlDQY/TYsuQJHuh1I/AAAAAAAAAdY/eUqoU5Mx9fM/s200/acm_logo.jpeg" width="100" /&gt;&lt;/a&gt;&lt;/div&gt;I managed to pull away from work and studies for two stimulating days and drive to San Antonio for the 1st annual &lt;a href="http://www.codaspy.org/"&gt;ACM SIGSAC CODASPY&lt;/a&gt; conference. I learned quite a lot and managed to meet some&amp;nbsp;fascinating&amp;nbsp;academics and&amp;nbsp;practitioners.&lt;br /&gt;
&lt;br /&gt;
The conference itself was good and the papers were a great read. Dr. Sandhu made an excellent keynote presentation about the upcoming challenges in security, especially on application security in a mobile market. I also really enjoyed several of the discussions I had with the presenters. I was also extremely excited to know that my curiosity in certain fields, mainly security related to mobile and embedded devices, seems to be a expanding field. I even managed to meet the author of a textbook I plan on using at my local university in the next year to meet my teaching requirement.&lt;br /&gt;
&lt;br /&gt;
I also walked away having met some fantastic people in the realm of practitioner security. I am now, more than ever, ready to take and pass my CISSP exam. I received a lot of great advice and encouragement from current CISSP holders and was taken up on my offer to assist in the working of the conference next year.&lt;br /&gt;
&lt;br /&gt;
All in all - an awesome experience.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-582651545220929473?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Qw5N5W57ESA:Pte_HRn0U-M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Qw5N5W57ESA:Pte_HRn0U-M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=Qw5N5W57ESA:Pte_HRn0U-M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Qw5N5W57ESA:Pte_HRn0U-M:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=Qw5N5W57ESA:Pte_HRn0U-M:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/Qw5N5W57ESA/spring-update-so-far-behind.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://lh6.googleusercontent.com/-9x1tfDQlDQY/TYsuQJHuh1I/AAAAAAAAAdY/eUqoU5Mx9fM/s72-c/acm_logo.jpeg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/03/spring-update-so-far-behind.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-2819820625676407984</guid><pubDate>Wed, 19 Jan 2011 16:41:00 +0000</pubDate><atom:updated>2011-01-19T10:41:10.260-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">DSU</category><title>DSU Spring 2011 Semester</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_aCL71nAQpLg/TTcTTtJ6CaI/AAAAAAAAAag/d4uM6C2uXCM/s1600/dsu-logo.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_aCL71nAQpLg/TTcTTtJ6CaI/AAAAAAAAAag/d4uM6C2uXCM/s1600/dsu-logo.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;Well I am registered for this semester and taking System analysis and design as well as Information technology Strategy and Policy. It looks like it is going to be a great semester although a very busy one. After this semester I will be in specialization coursework only (Yay for core completion)!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;I am going to throw my spring project ideas out to my FB friends and see what comes up as a possible spring project. I will post here what the results of that will be.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-2819820625676407984?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=k2XUPNWV0uk:m2Iih4XeUqA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=k2XUPNWV0uk:m2Iih4XeUqA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=k2XUPNWV0uk:m2Iih4XeUqA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=k2XUPNWV0uk:m2Iih4XeUqA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=k2XUPNWV0uk:m2Iih4XeUqA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/k2XUPNWV0uk/dsu-spring-2011-semester.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_aCL71nAQpLg/TTcTTtJ6CaI/AAAAAAAAAag/d4uM6C2uXCM/s72-c/dsu-logo.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2011/01/dsu-spring-2011-semester.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-481423731502885942</guid><pubDate>Mon, 27 Dec 2010 14:05:00 +0000</pubDate><atom:updated>2010-12-27T08:17:32.708-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Hack</category><category domain="http://www.blogger.com/atom/ns#">Breach</category><category domain="http://www.blogger.com/atom/ns#">4Chan</category><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">Gawker</category><title>Gawker Breach and Strong Passwords</title><description>I used Lifehacker and Gizmodo, of course I was a member before the war between Nick/Adrian and 4Chan, before the dark times.&amp;nbsp;What can we learn from this incident, well several things!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;1. The first is that strong password security is a must.&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
It's not just a good idea that some person in a classroom somewhere mandates. It should be good policy for every person connected to the internet.&amp;nbsp;I downloaded the files from gnosis, the group claiming responsibility for the Gawker breach. They has access to those systems for a long time (weeks if not months). Long enough to crack good, strong passwords. I was surprised to see how many people use children names, their own names, colleges, and the word "password" as their password.&lt;br /&gt;
&lt;br /&gt;
People, these are not strong. &lt;u&gt;&lt;b&gt;No word easily found in any dictionary is "strong"!!!&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
I typically use strong passwords. Even after 48 hours of brute force against my own passwords which were in the list obtained from gnosis, I went through every site which I felt had security issues, and changed passwords ahead of my 90-120 day schedule. &lt;u style="font-weight: bold;"&gt;Yes, you should change your passwords at least every 90 days.&lt;/u&gt;&amp;nbsp;This is no laughing matter. I spent most of the weekend changing my passwords.&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;This is my forumla for making strong passwords:&amp;nbsp;&lt;span class="Apple-style-span" style="color: #333333; line-height: 18px;"&gt;&lt;b&gt;Letters + Numbers + Capitals and for grins throw in a !@#$%&amp;amp;&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 18px;"&gt;&amp;nbsp;character or two. Make it more than 8 characters.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 18px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;This is an example of a strong password: !iWng24Cea@39&lt;/span&gt;&lt;br /&gt;
&lt;div style="color: black; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Note the use of capitals, print characters (!@#$%&amp;amp;*), and numbers. The password is also longer than 8 characters.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black; line-height: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;DO NOT REUSE PASSWORDS ON MULTIPLE SITES, EACH SITE NEEDS A SPECIFIC PASSWORD. &amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;This is what ultimately lead to the massive amount of personal information on the gawker media employees to be leaked and posted.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;i&gt;&lt;b&gt;2. Pay attention to emails and news regarding the sites we use on a daily or weekly basis.&amp;nbsp;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
Keeping apprised of a situation is no small feat, but we do this in so many ways already. You would certainly notice if the front door to your home was open all day long. I am not saying that everyone should learn intrusion detection, but be aware of the sites and services you use, and be aware of any issues they have.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;3. Site designers, make password changing/entry friendly to strong passwords.&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
In the process of changing the passwords to sites this weekend, I noticed a disturbing trend. Many sites do not allow the storing of what I consider strong characters, mainly the !@#$%* characters. This is a serious issue to me. I realize that storing these types of characters is more difficult in the short term, but in the long term this adds the longevity of the cracking attempt. Do not limit me on password length either. Making a limit of 12 characters is silly and outdated. If I am capable of remembering a 32 character string then let me have 32 characters.&lt;br /&gt;
&lt;br /&gt;
Sticking to these tips will help you in the long run maintain some measure of safety. Remember that security is not a matter of stopping someone cold, but making it as difficult as possible to breach the measures taken. No security is full proof, but do not make it easy for anyone to breach your data.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-481423731502885942?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=fdyE5ljkMKs:mLWto1A1bGc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=fdyE5ljkMKs:mLWto1A1bGc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=fdyE5ljkMKs:mLWto1A1bGc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=fdyE5ljkMKs:mLWto1A1bGc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=fdyE5ljkMKs:mLWto1A1bGc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/fdyE5ljkMKs/gawker-breach-and-strong-passwords.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/12/gawker-breach-and-strong-passwords.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-5966018326336519772</guid><pubDate>Fri, 05 Nov 2010 12:42:00 +0000</pubDate><atom:updated>2010-11-05T07:42:01.866-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Snort</category><category domain="http://www.blogger.com/atom/ns#">mysql</category><category domain="http://www.blogger.com/atom/ns#">php</category><category domain="http://www.blogger.com/atom/ns#">Ubuntu</category><category domain="http://www.blogger.com/atom/ns#">BASE</category><title>Fall Personal Project: Update 4 PHP/MySQL Install</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s1600/pig-in-circle.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s1600/pig-in-circle.png" /&gt;&lt;/a&gt;&lt;/div&gt;So we have discussed the need to watch the install order. I have found that when installing things which require LAMP, inevitably you will need to make a change to the database at some point.&lt;br /&gt;
&lt;br /&gt;
Since BASE, the software which stores and provides segmented analysis of the snort traffic, uses a MySQL backend (you can use postgres), it is a good idea to install an interface to the database if you are unfamiliar with the command line. This is even more useful if you are like me and have forgotten almost everything about the open source database systems (although MySQL isn't really open anymore). I prefer the phpmyadmin GUI. Of course there is a specific order to getting things installed here too, if you want it to work&amp;nbsp;programmatically.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Step 1: PHP5&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;The current PHP core is 5, so make sure that is fully installed first. A full install of PHP will usually cover the database dependencies for MySQL, postgres and Apache2. Here are useful commands:&lt;br /&gt;
&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;sudo apt-get install php5&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;sudo apt-get install php5-mysql&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 17px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;sudo apt-get install libapache2-mod-php5&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Once you have this install completed. Run the phpinfo.php script we discussed in the last post. Verify. I know I have said the instructions for this before, but 20 seconds of verification can save you time later.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Step 2: MySQL&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
The MySQL install is just as simple. Since you have already run the installer for the PHP libraries, this will just consist of the DBMS itself. The current version of MySQL DBMS is 5.1.x.&lt;br /&gt;
&lt;i&gt;sudo apt-get install mysql-server&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
That's it. Seriously that is all it takes. Verify in the command line that the DBMS is working by typing &lt;i&gt;mysql &lt;/i&gt;or &lt;i&gt;sudo mysql &lt;/i&gt;depending on the user level. If you get "MYSQL&amp;gt;" it is working.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Step 3: phpmyadmin&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
The next step for easier DBMS manipulation is to install phpmyadmin located here: &lt;a href="http://www.phpmyadmin.net/"&gt;http://www.phpmyadmin.net&lt;/a&gt;. This will allow you to have a web front end to the DBMS and it makes the lives of visual people a lot nicer. Installing this uses (yes you guessed it) apt-get&lt;br /&gt;
&lt;i&gt;sudo apt-get install phpmyadmin&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
I will not go into the configuration of it because this is well documented here on the &lt;a href="https://help.ubuntu.com/10.04/serverguide/C/phpmyadmin.html"&gt;Ubuntu Server Forums&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Follow that guide for the configuration and you will be ready to configure snort having your DB backend ready, your dependencies ready, and a front end to all of it. The next (and last installment) will cover the actual snort installation as well as the configuration guide and the resources I used to get it all working.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-5966018326336519772?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=DINFhflYMic:PBdOsA9UFJM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=DINFhflYMic:PBdOsA9UFJM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=DINFhflYMic:PBdOsA9UFJM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=DINFhflYMic:PBdOsA9UFJM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=DINFhflYMic:PBdOsA9UFJM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/DINFhflYMic/fall-personal-project-update-4-phpmysql.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s72-c/pig-in-circle.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/11/fall-personal-project-update-4-phpmysql.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-194010481983115779</guid><pubDate>Fri, 29 Oct 2010 13:09:00 +0000</pubDate><atom:updated>2010-10-29T08:09:29.131-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Snort</category><category domain="http://www.blogger.com/atom/ns#">LAMP</category><category domain="http://www.blogger.com/atom/ns#">mysql</category><category domain="http://www.blogger.com/atom/ns#">php</category><category domain="http://www.blogger.com/atom/ns#">Apache</category><category domain="http://www.blogger.com/atom/ns#">Ubuntu</category><title>Fall Personal Project: Update 3</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s1600/pig-in-circle.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s1600/pig-in-circle.png" /&gt;&lt;/a&gt;&lt;/div&gt;As promised today's post will be about some of the things I learned during the installation of Snort on my Ubuntu box. The things I learned are more about the process of the setup more than anything else and the correct order in which to run the installs. You have to love dependencies right? Let's get started.&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal; font-weight: normal;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Acquired Knowledge Bit #1:&lt;/i&gt;&lt;/b&gt;&lt;i&gt;&amp;nbsp;Client install over Server install&lt;/i&gt;&lt;br /&gt;
The client install went a little better for me on the Zino for one reason only, I have to install a second NIC. On the Zino that is an issue because of it's form factor and the lack of a second ethernet port. I used the &lt;a href="http://homestore.cisco.com/en-us/adapters/linksys-USB300M-Ethernet_stcVVproductId65364379VVcatId552009VVviewprod.htm"&gt;Cisco 300M USB to RJ45 adapter&lt;/a&gt;. This functions as a second NIC. Although all the documentation I read said that this would work hands down on the server install, I could only get it to work &lt;u&gt;easily&lt;/u&gt;&amp;nbsp;in the client install of ubuntu. This is not to say it will not work, just that I could not get it to work in a reasonable amount of time. On the client install the process was simple. I plugged it in, scanned for new hardware, and let the updater download and install the drivers. This was my primary reason for sticking with the client install over the server install. Installation on the Zino was nice, fast, and easy.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Acquired Knowledge Bit #2: &lt;span class="Apple-style-span" style="font-weight: normal;"&gt;LAMP, Package Manager, and apt-get&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
The nice thing about a server install for the ubuntu distro is that it comes ready to install LAMP. In fact it's a toggle option during package selection. For those of you who do not know LAMP is an acronym for Linux Apache MySQL PhP. The four basic packages which will accomplish most anything. On the client this is not an option but the installation of the necessary components can be run after the OS is running. If you want a decent install guide, there's an &lt;s&gt;app&lt;/s&gt;...un site for that...head over to &lt;a href="http://www.lamphowto.com/"&gt;www.lamphowto.com&lt;/a&gt;&amp;nbsp;to get some guidance. Now here is what I learned in my post install LAMP, nothing works quite right unless you learn to love the &lt;i&gt;apt-get &lt;/i&gt;command. Learn to use this over the package manager in the GUI. The command is faster, easier to script and chain, and leaves nothing to question. I found that the feedback from the terminal session was more informative than that of the GUI. Stick to apt-get install, you will be thankful.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Acquired Knowledge Bit #3:&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&amp;nbsp;LAPM&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;LAMP should really be called LAPM. The order matters. I like to make sure things are working. Apache 2.0 first. Be sure to check the browser first to make sure the host is responding on that port and that you can see the default index.html page in your browser. PHP is second. This is critical in my opinion. Installing PHP next will allow you to make sure that it is working and that you can install the necessary tools you will need to maintain your MySQLDB, mainly &lt;a href="http://www.phpmyadmin.net/"&gt;phpmyadmin&lt;/a&gt;. Even if you are missing some dependencies, you will want to follow Apache with PHP. Next you will want to create the phpinfo.php page with the following code:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_aCL71nAQpLg/TMrHRbWO3TI/AAAAAAAAAaQ/Inq_9MVRke8/s1600/Screen+shot+2010-10-29+at+8.07.47+AM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_aCL71nAQpLg/TMrHRbWO3TI/AAAAAAAAAaQ/Inq_9MVRke8/s1600/Screen+shot+2010-10-29+at+8.07.47+AM.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;This will show you all the php configurations you have running. A great tool to use when trying to install LAMP (LAPM). &amp;nbsp;Call this page (phpinfo.php or whatever you called it) in your browser. This will verify that Apache and PHP are talking and that you have PHP installed correctly.&lt;br /&gt;
&lt;br /&gt;
MySQL deserves it's own time, so I will talk about that in the next installment as well as setting the snort.conf file and some of the pitfalls I learned there as well. So in the meantime have a great one!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-194010481983115779?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=7xatul4P2hM:bEo-5eY0T6w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=7xatul4P2hM:bEo-5eY0T6w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=7xatul4P2hM:bEo-5eY0T6w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=7xatul4P2hM:bEo-5eY0T6w:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=7xatul4P2hM:bEo-5eY0T6w:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/7xatul4P2hM/fall-personal-project-update-3.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s72-c/pig-in-circle.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/10/fall-personal-project-update-3.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-3372481096328115287</guid><pubDate>Fri, 22 Oct 2010 22:06:00 +0000</pubDate><atom:updated>2010-10-22T17:06:12.850-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Snort</category><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">IDS</category><category domain="http://www.blogger.com/atom/ns#">Ubuntu</category><title>Fall Personal Project: Update 2</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s1600/pig-in-circle.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s1600/pig-in-circle.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;u&gt;&lt;i&gt;&lt;b&gt;And working!&lt;/b&gt;&lt;/i&gt;&lt;/u&gt;....The Snort home project is a success. At least the setup and configuration of the project is a success. I have not tried to mess with the rules yet, but I will get there. I'm sidetracked at the moment by a layoff, contract work, classes, and job hunting. Honestly I'm surprised I got any of it done at all.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;All said and done this is pretty sweet, and I would like to thank the guys at the snort forums and on the snort mailing list for all the help. I would also like to thank the &lt;a href="http://it.thelibrarie.com/weblog/2010/06/installing-snort-on-ubuntu-10-04/"&gt;guide writer&lt;/a&gt; for the in depth guide.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;Here is a list of the equipment I used:&lt;/b&gt;&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: left;"&gt;1. Dell Zino (aka Inspirion 400)&lt;/div&gt;&lt;div style="text-align: left;"&gt;2. 1 Router (any type with a built in switch)&lt;/div&gt;&lt;div style="text-align: left;"&gt;3. 1 unmanaged hub or a switch which you can set as a repeater (I used a Netgear DS108)&lt;/div&gt;&lt;div style="text-align: left;"&gt;3. 1 Cisco USB to Ethernet dongle (USB 300M)&lt;/div&gt;&lt;div style="text-align: left;"&gt;4. Ubuntu 10.4 or higher&lt;/div&gt;&lt;div style="text-align: left;"&gt;5. UTP patch cables&lt;/div&gt;&lt;div style="text-align: left;"&gt;6. 1 UPS for the networking equipment.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;I will go through the configuration in an upcoming post, but needless to say it does work. There are some tricks I learned outside of the guide which will help along the way.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Here some photos of the setup all completed:&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_aCL71nAQpLg/TMIJy-2uXNI/AAAAAAAAAaI/_nafUn9ESKA/s1600/Snort-Project-2010.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="122" src="http://2.bp.blogspot.com/_aCL71nAQpLg/TMIJy-2uXNI/AAAAAAAAAaI/_nafUn9ESKA/s320/Snort-Project-2010.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_aCL71nAQpLg/TMIKLf2kyLI/AAAAAAAAAaM/cC19Fnxs3hk/s1600/Basic+Analysis+and+Security+Engine+(BASE)+1.4.5+(lilias)_1287783534172.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="204" src="http://3.bp.blogspot.com/_aCL71nAQpLg/TMIKLf2kyLI/AAAAAAAAAaM/cC19Fnxs3hk/s320/Basic+Analysis+and+Security+Engine+(BASE)+1.4.5+(lilias)_1287783534172.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;I have cleared the DB several times and started traffic over and it is working like a charm. The next post will cover the guide, software installs, and getting LAMP running.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-3372481096328115287?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=DJhsyjivBmQ:L_aXuvmotko:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=DJhsyjivBmQ:L_aXuvmotko:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=DJhsyjivBmQ:L_aXuvmotko:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=DJhsyjivBmQ:L_aXuvmotko:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=DJhsyjivBmQ:L_aXuvmotko:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/DJhsyjivBmQ/fall-personal-project-update-2.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_aCL71nAQpLg/TIZNMvTOzII/AAAAAAAAAZc/N9vXPt0R_YE/s72-c/pig-in-circle.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/10/fall-personal-project-update-2.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-8756953963242737552</guid><pubDate>Wed, 15 Sep 2010 13:00:00 +0000</pubDate><atom:updated>2010-09-15T08:00:08.761-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">SSID</category><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">WiFi</category><category domain="http://www.blogger.com/atom/ns#">Networking</category><title>Why I use SSID</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_aCL71nAQpLg/TI4t2gGe6AI/AAAAAAAAAZ0/DXf3XVj4Llc/s1600/wifi-logo.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="90" src="http://1.bp.blogspot.com/_aCL71nAQpLg/TI4t2gGe6AI/AAAAAAAAAZ0/DXf3XVj4Llc/s200/wifi-logo.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;This is going to be a long one. It comes from a debate I had on irc a few days ago. I've heard this time and time again, to increase security, disable SSID broadcast. &lt;u&gt;It's true, if you want to be absolute in your wifi network security, you should disable SSID broadcast&lt;/u&gt;. Now let me tell you why I don't.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;I like things to work:&lt;/i&gt;&lt;/b&gt; Yes, in a nutshell this is my primary reason. I like it when I know my Wii can see my wifi network. I like it when my mother brings her iPod over and it works seamlessly. There is something to be said about technology doing what it was designed to do, making my life easier and improving the quality of it. I dislike having to stop what I am doing to troubleshoot a wifi connection, if the device can see the SSID, then I know the hardware is at least functioning somewhat properly. It saves time and effort, something geeks like to do.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;b&gt;How do &lt;u&gt;I&lt;/u&gt; secure my wifi network? &lt;/b&gt;&lt;/i&gt;Simple steps will always work:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. Change the default password on your router.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;This should be the first thing you do. All it takes is determining the router type and someone can lookup the factory username and password. Once they get into your router, find your connected IP, turn off your SPI firewall, and lock you out, well, it's game over. Seriously speaking this keeps so much from happening. Usually you cannot change the default username, but make your password strong.&lt;b&gt; Letters + Numbers + Capitals and for grins throw in a !@#$%&amp;amp;&lt;/b&gt; character or two. Make it more than 8 characters too.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. Change the SSID broadcast name.&lt;/b&gt;&lt;br /&gt;
Do this as soon as you have changed the default password.&lt;br /&gt;
&lt;b&gt; &lt;/b&gt;&lt;br /&gt;
&lt;b&gt;3. Set the radio encryption level to high.&lt;/b&gt;&lt;br /&gt;
It boils down to this, a wifi network still uses plain old fashioned radio waves for communication (which is why you have channels on your router). Just like regular radio waves they can be intercepted by anyone with the basic knowledge and equipment. &lt;b&gt;Encryption of the radio signal is crucial!&lt;/b&gt; When you set the encryption of a router you are encrypting the radio transmission and reception, the information floating (waving) through the air is encrypted. This protects against interception. The current standard for high encryption is WPA2, go as high as you can. This will not stop a determined person, but it will make it extremely difficult, which is the basics of security.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4. Use MAC Filters.&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;u&gt;Here is where I depart from the "standard"&lt;/u&gt;&lt;/i&gt;. Each and every device which connects to a network uses a media access control address (&lt;a href="http://en.wikipedia.org/wiki/MAC_address"&gt;MAC&lt;/a&gt;). Most modern routers allow a person to setup a list of MACs which will be allowed on the network. If the MAC isn't on the list, it is not allowed on. &lt;u&gt;Now here is the problem with MACs, they can be spoofed, easily spoofed&lt;/u&gt;. Here is the counter argument. Most will not take the time to try and discover the connected MACs, they will move on to another target. Spoofing a MAC requires someone to take the time and effort to capture radio traffic, find the correct MAC, and spoof it. Remember if you have done the previous steps, this is just another road block in the way of a intruder. It is better to have it than to not have it. &lt;i&gt;&lt;u&gt;&lt;b&gt;It should not be implemented on its own as a security plan&lt;/b&gt;&lt;/u&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;&lt;u&gt;rather it should be implemented as a part of a security methodology&lt;/u&gt;&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;5. Check your logs/activity.&lt;/b&gt;&lt;br /&gt;
So many people do not take the time to review their router. I do mine about once a month, but I take security very seriously. At least check it every few months. There are ways to set routers to email you when certain activity happens. Do so! Just like you check your windows and door by looking at them, do the same for your network.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-8756953963242737552?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=UcN5Ja2vEhM:i53jw4vmNLA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=UcN5Ja2vEhM:i53jw4vmNLA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=UcN5Ja2vEhM:i53jw4vmNLA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=UcN5Ja2vEhM:i53jw4vmNLA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=UcN5Ja2vEhM:i53jw4vmNLA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/UcN5Ja2vEhM/why-i-use-ssid.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_aCL71nAQpLg/TI4t2gGe6AI/AAAAAAAAAZ0/DXf3XVj4Llc/s72-c/wifi-logo.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/09/why-i-use-ssid.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-8188417456691752487</guid><pubDate>Mon, 13 Sep 2010 13:25:00 +0000</pubDate><atom:updated>2010-09-13T08:25:07.157-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Snort</category><category domain="http://www.blogger.com/atom/ns#">Netgear</category><category domain="http://www.blogger.com/atom/ns#">NIDS</category><category domain="http://www.blogger.com/atom/ns#">Networking</category><title>Fall Personal Project: Update 1</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_aCL71nAQpLg/TI4kLEIJkQI/AAAAAAAAAZs/XYF1hIAeqmY/s1600/pig-in-circle.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_aCL71nAQpLg/TI4kLEIJkQI/AAAAAAAAAZs/XYF1hIAeqmY/s320/pig-in-circle.png" /&gt;&lt;/a&gt;&lt;/div&gt;So the fall home NIDS project is going well. I have removed the old router and replaced it with a newer Netgear b/g/n router. I also took the opportunity to do some cable management.&lt;br /&gt;
&lt;br /&gt;
There is one feature I wish manufacturers would add to the routers and that is to export the machine address ACL to a file. It would have been really nice. As it s I just copied the table from the html, but still, since I use MAC ACL filters, it would make things easier.&lt;br /&gt;
&lt;br /&gt;
So the 10/100 hub is on the way, I will order my dell zino this week after I finish some papers which are due. I would really like to thank all the folks over at the snort forums for their assistance and guidance in this project. They really know what they are doing.&lt;br /&gt;
&lt;br /&gt;
I spent some time this weekend looking up the literature in some major journals on snort usage. I'm almost positive that my final dissertation will somehow involve the use of snort, but I'm not sure how yet.&lt;br /&gt;
&lt;br /&gt;
More updates as the equipment comes to me. I will post a topology diagram later on the next update once I make sure everything is running.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-8188417456691752487?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=b45SfrPS1nw:rYLJeSnJEmI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=b45SfrPS1nw:rYLJeSnJEmI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=b45SfrPS1nw:rYLJeSnJEmI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=b45SfrPS1nw:rYLJeSnJEmI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=b45SfrPS1nw:rYLJeSnJEmI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/b45SfrPS1nw/fall-personal-project-update-1.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_aCL71nAQpLg/TI4kLEIJkQI/AAAAAAAAAZs/XYF1hIAeqmY/s72-c/pig-in-circle.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/09/fall-personal-project-update-1.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-7219546033610409896</guid><pubDate>Tue, 07 Sep 2010 14:48:00 +0000</pubDate><atom:updated>2010-09-13T08:50:41.132-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Snort</category><category domain="http://www.blogger.com/atom/ns#">NIDS</category><category domain="http://www.blogger.com/atom/ns#">Ubuntu</category><title>Fall Personal Project</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_aCL71nAQpLg/TIZNS6LjU0I/AAAAAAAAAZk/NYmk0XG41yU/s1600/pig-in-circle.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_aCL71nAQpLg/TIZNS6LjU0I/AAAAAAAAAZk/NYmk0XG41yU/s320/pig-in-circle.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
So this fall's personal project will be to install a personal IDS at my home, then try like crazy to penetrate it. Snort snort snort. After writing several papers on the software I have come to respect it even more.&lt;br /&gt;
&lt;br /&gt;
I often check the basics of a site or of a home network setup by using the "&lt;a href="https://www.grc.com/x/ne.dll?bh0bkyd2"&gt;shields up&lt;/a&gt;" but I know that my router kills the majority of the traffic which the service tests for in a vulnerability test. I am looking to setup a fully functioning DMZ with a snort based NIDS and then slam it until I can break it (without cheating of course). I have ordered a new router simply because I have been a little lapse on keeping my encryption as strong as I can and it's time to do so. I also reall like some of the new functions in netgear's newer routers which allows the creation of a DMZ out of the box.&lt;br /&gt;
&lt;br /&gt;
Also, I will probably use Ubuntu and some sort of small form factor like a mac mini or a dell zino since I need power to be a consideration. I would love to keep it in the ubuntu family line though, I need to beef up my skills in administrating one since it has been almost a year since I set a box up with ubuntu.&lt;br /&gt;
&lt;br /&gt;
We will see how it goes. I will post to a page here or keep it updated in the blog.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-7219546033610409896?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Hk_98n_8_Xs:Yyf1ILI3vtg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Hk_98n_8_Xs:Yyf1ILI3vtg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=Hk_98n_8_Xs:Yyf1ILI3vtg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Hk_98n_8_Xs:Yyf1ILI3vtg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=Hk_98n_8_Xs:Yyf1ILI3vtg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/Hk_98n_8_Xs/fall-personal-project.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_aCL71nAQpLg/TIZNS6LjU0I/AAAAAAAAAZk/NYmk0XG41yU/s72-c/pig-in-circle.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/09/fall-personal-project.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-6574707854708492263</guid><pubDate>Thu, 12 Aug 2010 13:28:00 +0000</pubDate><atom:updated>2010-08-12T08:28:28.851-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">sites</category><category domain="http://www.blogger.com/atom/ns#">paypal</category><category domain="http://www.blogger.com/atom/ns#">weebly</category><category domain="http://www.blogger.com/atom/ns#">CMS</category><title>Weebly: Simple and Easy Sites</title><description>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://4.bp.blogspot.com/_aCL71nAQpLg/TGP07B1Wm5I/AAAAAAAAAZA/mD0Aq2qWmdw/s1600/logo_home.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="71" src="http://4.bp.blogspot.com/_aCL71nAQpLg/TGP07B1Wm5I/AAAAAAAAAZA/mD0Aq2qWmdw/s200/logo_home.gif" width="200" /&gt;&lt;/a&gt;&amp;nbsp;As you can tell, my site has gone through yet another revision. The long and short of it is that I am reducing the number of servers I run entirely. I am shutting down my primary portal site and converting everything to W&lt;b&gt;eebly&lt;/b&gt; accounts, both for my clients and myself.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;What is &lt;b&gt;Weebly&lt;/b&gt;? I'm so glad you asked. &lt;b&gt;Weebly &lt;/b&gt;is&amp;nbsp;ridiculously&amp;nbsp;simple web hosting. Now if you want to run a php application or something in the .NET framework, &lt;b&gt;Weebly &lt;/b&gt;is not for you. If you want a simple site, clean, efficient, and gets the job done with very little issues, &lt;b&gt;Weebly &lt;/b&gt;is right up your alley.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;What &lt;b&gt;Weebly &lt;/b&gt;does is allow people, with very little coding experience, to create rich and easy to maintain content driven sites. It includes integration to the paypal shopping cart engine, easy to set meta tags for SEO purposes, and a module based layout similar to most CMS features, allowing more flexibility for those that want to do special things, like my twitter feed on the front page.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Easy part, it's free with a point and click interface. I highly recommend this for anyone wanting a quick and painless site.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-6574707854708492263?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=p4zVHRrbzD0:IvQA4lEuBdc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=p4zVHRrbzD0:IvQA4lEuBdc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=p4zVHRrbzD0:IvQA4lEuBdc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=p4zVHRrbzD0:IvQA4lEuBdc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=p4zVHRrbzD0:IvQA4lEuBdc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/p4zVHRrbzD0/weebly-simple-and-easy-sites.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_aCL71nAQpLg/TGP07B1Wm5I/AAAAAAAAAZA/mD0Aq2qWmdw/s72-c/logo_home.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/08/weebly-simple-and-easy-sites.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-2175587008983337885</guid><pubDate>Mon, 07 Jun 2010 13:33:00 +0000</pubDate><atom:updated>2010-06-07T08:53:56.187-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Incredible Start Page</category><category domain="http://www.blogger.com/atom/ns#">Extensions</category><category domain="http://www.blogger.com/atom/ns#">Chrome</category><category domain="http://www.blogger.com/atom/ns#">Visibo</category><title>Chrome Extension: Incredible Startpage</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_aCL71nAQpLg/TAz1XkOv2LI/AAAAAAAAAYY/l9xEJ4WsRoc/s1600/visibo.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 209px; height: 120px;" src="http://4.bp.blogspot.com/_aCL71nAQpLg/TAz1XkOv2LI/AAAAAAAAAYY/l9xEJ4WsRoc/s320/visibo.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5480024631814379698" /&gt;&lt;/a&gt;&lt;br /&gt;I am finding that for search and daily tasks, &lt;b&gt;&lt;a href="http://www.google.com/chrome"&gt;Google Chrome&lt;/a&gt;&lt;/b&gt; is rapidly replacing Firefox as my default browser. I'm still amazed at how this transition has happened. I still use Firefox for download management, debugging, and the like, but my main browser now is &lt;b&gt;Chrome&lt;/b&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This leaves some slight functionality issues with Chrome. All in all I have managed to find what I need to complete my tasks and make things seamless. Then I find this little jewel of an extension. The company is &lt;b&gt;Visibo&lt;/b&gt;, the extension is the &lt;i&gt;&lt;b&gt;&lt;a href="http://blog.visibotech.com/p/incredible-startpage.html"&gt;"Incredible Startpage"&lt;/a&gt;&lt;/b&gt;&lt;/i&gt;. This little add-on grew rapidly on me. I find the native and default startpage on Chrome spacious to a fault. I cannot really reorder my list, and the thumbnails of web lages are unnecessary for me. The bookmarks bar is limited to the length of the window, so things are not as elegant as they could be in my humble opinion. Incredible Startpage fixes most of my issues. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First the bookmark frame, this allows me to keep a double column list of my most commonly used bookmarks on a new tab. This is nice. It keeps the fav icon as a reference and offers more than what the bookmarks bar offers in terms of space (I like a fixed width window). &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The next is the columns for closed tabs and a longer bookmarks list, which I can use to add and remove bookmarks to my bookmark frame. Lovely! &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The next cool feature is the post-it. This allows me to write in small things and then post them as an email or calendar item to Gmail or Google Calendar, both services I use extensively.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Add to this the fully customize CSS and background images which allow you to tailor your new tab page as you like, and I feel right at home (of course I've totally geeked it out with Dr. Who wall papers). By default the extension has an array of images, but you can also direct link to any image out on the net, the downside is no local image support, but that's fine by me.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;All in all this is a great extension for my daily operations (email, web, search, school). I love the arrangement and layout as well as the personal touch. Great Job Visibo!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-2175587008983337885?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=noDYElzLXts:4arvLnWaoqM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=noDYElzLXts:4arvLnWaoqM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=noDYElzLXts:4arvLnWaoqM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=noDYElzLXts:4arvLnWaoqM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=noDYElzLXts:4arvLnWaoqM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/noDYElzLXts/chrome-extension-incredible-startpage.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_aCL71nAQpLg/TAz1XkOv2LI/AAAAAAAAAYY/l9xEJ4WsRoc/s72-c/visibo.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/06/chrome-extension-incredible-startpage.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-1393783530540309407</guid><pubDate>Thu, 03 Jun 2010 13:00:00 +0000</pubDate><atom:updated>2010-06-03T08:40:43.711-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security</category><category domain="http://www.blogger.com/atom/ns#">Encryption</category><category domain="http://www.blogger.com/atom/ns#">HIPPA</category><category domain="http://www.blogger.com/atom/ns#">PCI-DSS</category><category domain="http://www.blogger.com/atom/ns#">WiFi</category><category domain="http://www.blogger.com/atom/ns#">Networking</category><title>Wardriving (whitehat of course)</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_aCL71nAQpLg/TAetewoPKfI/AAAAAAAAAYI/jEqlSWENVp4/s1600/wifi.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 84px;" src="http://4.bp.blogspot.com/_aCL71nAQpLg/TAetewoPKfI/AAAAAAAAAYI/jEqlSWENVp4/s200/wifi.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5478538215680846322" /&gt;&lt;/a&gt;&lt;br /&gt;Wednesday night, I thought I would kill two birds so to speak. I needed to pick up my lovely wife from the airport and at the same time, complete an assignment for my networking class regarding wardriving. Let me preface this by stating I know the difference between scanning for a network and connecting to it. I have done this many times in the past and I am not about to break the law now. So I fire up VIStumbler on my laptop, jump in my nifty car and drive 26.1 miles to DFW international airport. The results were more than interesting. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;I found what I expected getting out of my neighborhood, lots of unsecured open wireless networks. On the drive to the highway I found plenty of businesses which would offer WiFi to their customers; McDonalds, Starbucks, Hyatt, even a KFC. Then I get some more than interesting hits; Bank of America, Wells Fargo, a local doctor's office. These were just a few of the businesses which I would think would at least encrypt their network. Leaving it open for access is one thing, it makes it easy for customers to connect, but traffic encryption should be a no quarter point of interest. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Having spent lots of time as a network and system admin, I would find it very unnerving to have an open and unsecured WiFi network for a doctor's office, bank, or any retail operation which accepts credit cards (and stores them locally). I understand that many businesses simply offer internet service to their customers, the local coffee shop for example. I have personally seen local businesses though, connect their POS system to their WiFi network. Here is where things can get tricky.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Here are some reasons why. For all those doctor's offices out there, &lt;a href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act"&gt;HIPPA&lt;/a&gt; is no laughing matter. If the network inadvertently transmits HIPPA related patient information on an unsecured network and that transmission is intercepted...well good night Sally. This is a major issue. For businesses which accept credit cards, you must follow &lt;a href="https://www.pcisecuritystandards.org/"&gt;PCI-DSS&lt;/a&gt; standards for card data security set by VISA, MasterCard, Discover, and American Express (The PCI council). The fines you could receive for a breach could literally put the business down for the count. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;b&gt;Do not take WiFi security lightly&lt;/b&gt;. Set up encryption, use it, access points and wireless routers have it built in for a reason. Set up authentication when you can, again these access points come with this ability out of the box. For you data paranoid types (like me), use good encryption and authentication with a IDS setup on the inside of the network. None of this may stop a determined intruder, but it can slow them down and make them move on to a more viable target, which is what security is all about.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-1393783530540309407?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Z-pgqHBMmio:yRgPKbR7y-s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Z-pgqHBMmio:yRgPKbR7y-s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=Z-pgqHBMmio:yRgPKbR7y-s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=Z-pgqHBMmio:yRgPKbR7y-s:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=Z-pgqHBMmio:yRgPKbR7y-s:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/Z-pgqHBMmio/wardriving-whitehat-of-course.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_aCL71nAQpLg/TAetewoPKfI/AAAAAAAAAYI/jEqlSWENVp4/s72-c/wifi.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/06/wardriving-whitehat-of-course.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-5492321227684556716</guid><pubDate>Tue, 04 May 2010 14:01:00 +0000</pubDate><atom:updated>2010-05-04T09:40:33.705-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Google Bookmarks</category><category domain="http://www.blogger.com/atom/ns#">Google Labs</category><category domain="http://www.blogger.com/atom/ns#">EndNote</category><category domain="http://www.blogger.com/atom/ns#">Google Docs</category><category domain="http://www.blogger.com/atom/ns#">Google</category><title>Google Bibliography?</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_aCL71nAQpLg/S-Apqd-oP6I/AAAAAAAAAXs/Bp3mht8YzQc/s1600/Google+Scholar.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 80px;" src="http://4.bp.blogspot.com/_aCL71nAQpLg/S-Apqd-oP6I/AAAAAAAAAXs/Bp3mht8YzQc/s200/Google+Scholar.gif" border="0" alt="" id="BLOGGER_PHOTO_ID_5467415757206339490" /&gt;&lt;/a&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;No, &lt;b&gt;Google Bibliography&lt;/b&gt; is not a real product. I really wish it was though. I am currently starting to collect documents for my doctoral dissertation proposal and I keep running into the same issue over and over again, redundancy. I am absolutely fearful that my EndNote library is going to get squashed by any number of possible deaths. Call me paranoid, but when it comes to data, well...ok I guess I'm paranoid. &lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Large journal sources such as ACM&lt;/span&gt;&lt;/span&gt; already have a system for exporting to any number of citation storage packages, including the ever popular &lt;a href="http://www.blogger.com/www.endnote.com/"&gt;EndNote&lt;/a&gt;, here is the issue I have though, EndNote does a great job of keeping my references together, but does so in such an inelegant way. After 3 years of Gmail, 3 years of Google Docs,  and access to a lot of these services on the fly via mobile, I came to rely on elegance of Google software, even more than that elegance, I rely on the cloud to store the most critical information as a backup device. The culmination of my academic career is more than "critical" to me. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;What to do? I could just continue to use EndNote X3 which my university makes available to me for free. I then have the issue of storing my library, and all pdf articles associated with it in a central repository and "syncing" them.  I use multiple computers for this process, so now I am almost tied to those little flash drives for my sync. Ug. I suppose I could "upload" my library files to Google Docs as a backup, but that again seems "inelegant". Why could I not have a solution where I can store, modify, read, relate, tag, and organize my citations in the cloud, as an integrated service with the apps I already rely on from Google?&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;b&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; &lt;/span&gt;&lt;/span&gt;W&lt;/b&gt;&lt;/span&gt;&lt;b&gt;hat I want:&lt;/b&gt; I want a service which ties in to a document storage package like Google docs, can easily be updated like Google Bookmarks for Scholar searches, easily tagged (like all Google products). &lt;i&gt;&lt;b&gt;I want a Google citation database!&lt;/b&gt;&lt;/i&gt; In the cloud, massive storage, tags, easily searchable (search through the pdf uploads too), and linked to Google Talk for collaboration. I think this need fits right in the middle between Google Docs and Google Apps. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Please don't make me carry all my research and literature on a flash drive...please?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-5492321227684556716?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=otq9njhpnlk:9hW_A-TgDcg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=otq9njhpnlk:9hW_A-TgDcg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=otq9njhpnlk:9hW_A-TgDcg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=otq9njhpnlk:9hW_A-TgDcg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=otq9njhpnlk:9hW_A-TgDcg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/otq9njhpnlk/google-bibliography.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_aCL71nAQpLg/S-Apqd-oP6I/AAAAAAAAAXs/Bp3mht8YzQc/s72-c/Google+Scholar.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/05/google-bibliography.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-3350212999895793143</guid><pubDate>Fri, 30 Apr 2010 13:45:00 +0000</pubDate><atom:updated>2010-04-30T09:04:12.037-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Last.fm</category><category domain="http://www.blogger.com/atom/ns#">Pandora</category><category domain="http://www.blogger.com/atom/ns#">music</category><category domain="http://www.blogger.com/atom/ns#">Apple</category><category domain="http://www.blogger.com/atom/ns#">Lala</category><title>Goodbye Lala, You were good to me</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_aCL71nAQpLg/S9rfKG80eVI/AAAAAAAAAXc/shn2C7wjgcU/s1600/End-Of-Lala.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 220px; height: 51px;" src="http://1.bp.blogspot.com/_aCL71nAQpLg/S9rfKG80eVI/AAAAAAAAAXc/shn2C7wjgcU/s320/End-Of-Lala.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5465926462524914002" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;My Friend &lt;b&gt;Tivo25&lt;/b&gt; introduced me to &lt;b&gt;lala.com&lt;/b&gt; a few months ago. I am always looking for new music and even spins on old music. Lala is great, it offers a queue for sampling music, social networking to find people with interests and get introduced to music and share it with other networks (facebook), and most of all a great way to easily and comfortably purchase music on a tier.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Chairman Steve at Apple thinks it's good too. Apple recently purchased Lala.com. Like myself, many users had hoped this site would become an extension of iTunes or simply just left alone.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Nope....&lt;a href="http://www.lala.com/shutdown"&gt;it goes down May 31st&lt;/a&gt;. Thank you Apple, you &lt;b&gt;cheeky B&amp;amp;^@6@!(&amp;amp;%#s&lt;/b&gt;. This is something I expected from the likes of Microsoft, not Apple. The iTunes store has many merits, and I am loyal fan, but social networking really leads to music discovery, something Apple has yet to grasp in it's push to appease the big labels, which I hope die in a fiery, brimstone laden, smelly, smoky ball of financial ruin. Sorry, lost it there for a second. Nothing stifles new music faster than shutting down avenues of discovery. Not everyone can go to SxSW every year and we rely on services like lala to produce new music for us.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Today, another avenue was roadblocked, and unfortunately it looks like music lovers on the web will ultimately suffer the consequences. Had it not been for lala and a local radio station (PBS funded 91.7 in Dallas-FortWorth), I would have never discovered St. Vincent, Passion Pit, Little Dragon, Aqualung, Fanfarlo, Efterklang, Shiney Toy Guns, or Ok Go. This leaves &lt;a href="http://www.pandora.com/"&gt;Pandora&lt;/a&gt; and perhaps &lt;a href="http://www.last.fm/"&gt;last.fm&lt;/a&gt;. I will be showing my support for Pandora now with a paid subscription and will create an account on Last.fm probably this weekend.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Bye Lala, I hope to see you on the other side. :(&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-3350212999895793143?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=NlSyMYeL13o:yzM4FiVyRso:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=NlSyMYeL13o:yzM4FiVyRso:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=NlSyMYeL13o:yzM4FiVyRso:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=NlSyMYeL13o:yzM4FiVyRso:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=NlSyMYeL13o:yzM4FiVyRso:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/NlSyMYeL13o/goodbye-lala-you-were-good-to-me.html</link><author>noreply@blogger.com (Chris)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_aCL71nAQpLg/S9rfKG80eVI/AAAAAAAAAXc/shn2C7wjgcU/s72-c/End-Of-Lala.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/04/goodbye-lala-you-were-good-to-me.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-7090201744740188027</guid><pubDate>Thu, 25 Mar 2010 14:12:00 +0000</pubDate><atom:updated>2010-03-25T09:33:24.348-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">OS X</category><category domain="http://www.blogger.com/atom/ns#">eCalc</category><category domain="http://www.blogger.com/atom/ns#">Statistics</category><category domain="http://www.blogger.com/atom/ns#">Software</category><category domain="http://www.blogger.com/atom/ns#">Mathematics</category><title>eCalc</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.ecalc.com/pics/media/calculator_logo3.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 62px; height: 75px;" src="http://www.ecalc.com/pics/media/calculator_logo3.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;This last weekend I was working on some ANOV problems for my class. I found that I was having problems looking at my handheld calculator (only purchased for my proctored exams) and the standard calculator on windows was lacking a square root function.Now I know I can get around it by giving a power of .5 to whatever number to which I'm trying to find the root, but I find this silly. It's literally more work. This is why software was created. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This annoyance put me on a 30 minute chase on the web to find a software calculator which is not connection dependent. I wanted to find one which was available on the web for both windows and OS X. Someone read my mind. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I found &lt;b&gt;&lt;a href="http://www.ecalc.com/"&gt;eCalc&lt;/a&gt;.&lt;/b&gt; Web based, OS X dashboard ready, runs in windows. I found it nice, easy, and intuitive. This is great software! It does the following effortlessly:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Scientific Functions (Algebra, Trigonometry, Engineering)&lt;/div&gt;&lt;div&gt;RPN or Algebraic Operating Modes&lt;/div&gt;&lt;div&gt;Interactive Unit Converter&lt;/div&gt;&lt;div&gt;Linear and Root Equation Solver&lt;/div&gt;&lt;div&gt;Complex Number Math with Polar and Rectangular Formats&lt;/div&gt;&lt;div&gt;Drop-Down Stack with History&lt;/div&gt;&lt;div&gt;Interactive Decimal to Fraction Converter&lt;/div&gt;&lt;div&gt;Free Online Calculator&lt;/div&gt;&lt;div&gt;Windows Desktop Version (Win98,ME,NT4,2k,XP,Vista) (Also works in Win 7-64b)&lt;/div&gt;&lt;div&gt;Mac OS X Dashboard Version&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Plus: A square root button...I'm so easily entertained.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;$14.95. Done. Sold. My handheld crappy TI-blah-blah cost me $9 at target. I have to admit I do like well designed software and I have a tendency to purchase based on functionality and design and this calculator won my devotion on both fronts. There is even an iPhone app ready and available. &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-7090201744740188027?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=jskzt7NLPsE:GvW9HATI35M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=jskzt7NLPsE:GvW9HATI35M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=jskzt7NLPsE:GvW9HATI35M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=jskzt7NLPsE:GvW9HATI35M:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=jskzt7NLPsE:GvW9HATI35M:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/jskzt7NLPsE/ecalc.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/03/ecalc.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-188728704759681168</guid><pubDate>Wed, 24 Mar 2010 16:41:00 +0000</pubDate><atom:updated>2010-03-24T11:50:23.704-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Distribution</category><category domain="http://www.blogger.com/atom/ns#">Statistics</category><category domain="http://www.blogger.com/atom/ns#">Mathematics</category><title>Benford's Law</title><description>&lt;div&gt;A friend of mine recently introduced me to &lt;a href="http://en.wikipedia.org/wiki/Benford's_law"&gt;&lt;b&gt;Benford's law&lt;/b&gt;&lt;/a&gt;, also known as first digit law a few days ago. I had never heard of it until then, granted I'm not up on the majority of statistical probability laws, but I found it fascinating. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It made me wonder. I have a wonderful book, "Tables of Integrals and Other Mathematical Data" by Dwight Herbert (1961 ed). I used this book heavily in college and still hit it for reference every so often. Is there anything like it for statistical models specifically? &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thanks to Don for the Benford's Law intro too!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-188728704759681168?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=5NEa0Z9WqXE:IGmqTlK1DgQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=5NEa0Z9WqXE:IGmqTlK1DgQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=5NEa0Z9WqXE:IGmqTlK1DgQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=5NEa0Z9WqXE:IGmqTlK1DgQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=5NEa0Z9WqXE:IGmqTlK1DgQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/5NEa0Z9WqXE/benfords-law.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/03/benfords-law.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-396068099013693195</guid><pubDate>Wed, 10 Feb 2010 21:02:00 +0000</pubDate><atom:updated>2010-02-10T15:25:21.284-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Ping.fm</category><category domain="http://www.blogger.com/atom/ns#">Google</category><category domain="http://www.blogger.com/atom/ns#">Google Buzz</category><category domain="http://www.blogger.com/atom/ns#">Gmail</category><title>Google Buzz, bright idea but why?</title><description>Maybe I'm just not getting it. Maybe I never will. I read the information, watched the video, and have been "buzzing" with my friend TiVO25 for nearly 20 min now. What does Buzz accomplish?&lt;br /&gt;&lt;br /&gt;Let me share with you a few things it does do well first. The application does share and start conversations well. I can follow the conversation with absolute ease and the user interface is easy and clean. Everything is within Gmail so I'm not really having to learn anything new. Very intuitive and fast. The response time is quick and I'm not left wondering it buzz is working. There are features which I would expect to see like email this and reply commenting as well. Yep, that's about it.&lt;br /&gt;&lt;br /&gt;Now here are the things I do not like. As Buzz is rolled out to people, they are automatically added to my followers. I never manually added anyone to my followers or to be followed, it was automatic. By default all conversations are public and are stored on the web along with a profile page. Here is  mine as an example &lt;a href="http://www.google.com/profiles/111529312968232778962#buzz"&gt;(http://ping.fm/veXvi)&lt;/a&gt;&lt;a href="http://ping.fm/veXvi)."&gt;.&lt;/a&gt; I never asked for the profile page, and all my conversations in buzz to be auto added to a page, which can now be crawled and added to the search cache. Oops when I added the other sites to Buzz it auto posted my last tweet and blog entry, thanks for asking first! I auto spammed my gmail friends with materials. There is a link in my mailbox side nav for buzz, so why am I also getting it in my mail inbox? My blackberry is having seizures trying to keep up with Gmail mobile because I'm having a buzz conversation? No thanks.&lt;br /&gt;&lt;br /&gt;My biggest concern is that this only takes information from other sites, it doesn't send it out. It would have been better if this was like ping.fm (where I am writing this now as we speak). I want ease of use. It is easy for me to login to mail and send an update to all my syndicated sites (facebook, twitter, blogger, etc). What does it accomplish to have my buzz updated from these sites, where my friends, family, and followers already exist? Who is reading my buzz then? Is it to try and convert more people to Gmail? Why would I do that? Email is a personal choice. Do I believe Gmail is better? Yes! Am I going to say that buzz is a reason to migrate over to gmail as a mail platform? No.&lt;br /&gt;&lt;br /&gt;All in all buzz looks great, works fast, and does what exactly? My already used, flexible, and well established services are not enhanced by this product, neither am I for that matter.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-396068099013693195?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=tCvQNFxFdkc:fNJ5Dfz5cww:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=tCvQNFxFdkc:fNJ5Dfz5cww:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=tCvQNFxFdkc:fNJ5Dfz5cww:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=tCvQNFxFdkc:fNJ5Dfz5cww:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=tCvQNFxFdkc:fNJ5Dfz5cww:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/tCvQNFxFdkc/google-buzz-bright-idea-but-why.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/02/google-buzz-bright-idea-but-why.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-3883933524520757141</guid><pubDate>Tue, 09 Feb 2010 15:21:00 +0000</pubDate><atom:updated>2010-02-09T09:21:07.884-06:00</atom:updated><title>Program of Study</title><description>Well after some reworking and decisions on my part I have decided on my program of study direction at DSU. I will be specializing in Information Assurance and Computer Security (yay!). Now to work through all the fun stuff.&lt;br /&gt;&lt;br /&gt;Of course I will need to complete the smaller coursework which everyone has to take along the way, but at least I can start preparing my literature review now though. I am learning EndNote however I really wish there were a solution in the cloud for this. EndNote does a fantastic job and I love the fact that I can download trees of citations from the library and post them directly into the application, I just feel that there is a better way to accomplish this goal.&lt;br /&gt;&lt;br /&gt;There is going to be a proposal defense sometime this week and I love sitting in on these. The proposal will be on "Virtual Teams: Towards Improving Work Effectiveness through Collaboration Process Structure Training”. This sounds so interesting. I wish Dawn all the best on the defense.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-3883933524520757141?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=wBrvo_1zkW8:A-sNB0Q9SeU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=wBrvo_1zkW8:A-sNB0Q9SeU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=wBrvo_1zkW8:A-sNB0Q9SeU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=wBrvo_1zkW8:A-sNB0Q9SeU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=wBrvo_1zkW8:A-sNB0Q9SeU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/wBrvo_1zkW8/program-of-study.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2010/02/program-of-study.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5731464.post-8826408207163068401</guid><pubDate>Mon, 14 Dec 2009 16:52:00 +0000</pubDate><atom:updated>2009-12-14T11:01:29.239-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Asimov</category><category domain="http://www.blogger.com/atom/ns#">Fallout</category><category domain="http://www.blogger.com/atom/ns#">Statistics</category><category domain="http://www.blogger.com/atom/ns#">SQL</category><category domain="http://www.blogger.com/atom/ns#">DSU</category><title>Christmas Break</title><description>Wow what a semester. My first one at DSU has gone well and I learned quite a bit. For Xmas I get to sit and learn SQL reporting services in an attempt to save my company some money. I also get to relax a bit and catch up on fun things again, at least for a few weeks.&lt;br /&gt;&lt;br /&gt;I am already registered for Spring, Management and Evaluation of Information Systems and Applied Statistics. More stats....&lt;sarcasm&gt;sound like fun&lt;/sarcasm&gt;. Although I did learn a lot more than I anticipated in my project management class. I am quite surprised by how intuitive the Visual Studio Express editions were to use and work with.&lt;br /&gt;&lt;br /&gt;In the meantime I'm gonna be resting at home playing my old fav. Fallout 2, catching up on my large pile of unread Asimov monthly, and watching Avatar.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://www.chriscopeland.com"&gt;chriscopeland.com&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5731464-8826408207163068401?l=roninuta.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=lYbhwF0hS7U:WLilxoTCpeo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=lYbhwF0hS7U:WLilxoTCpeo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=lYbhwF0hS7U:WLilxoTCpeo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/roninuta?a=lYbhwF0hS7U:WLilxoTCpeo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/roninuta?i=lYbhwF0hS7U:WLilxoTCpeo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/roninuta/~3/lYbhwF0hS7U/christmas-break.html</link><author>noreply@blogger.com (Chris)</author><thr:total>0</thr:total><feedburner:origLink>http://roninuta.blogspot.com/2009/12/christmas-break.html</feedburner:origLink></item></channel></rss>

