<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0" xml:base="http://www.uno-code.com">
<channel>
 <title>Uno-Code - </title>
 <link>http://www.uno-code.com</link>
 <description />
 <language>en</language>
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/uno-code" type="application/rss+xml" /><feedburner:emailServiceId>uno-code</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
 <title>Issues with hardened-sources-2.6.28-r9</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/bI9F0pvUUEk/</link>
 <description>&lt;p&gt;I recently upgraded kernel on one of my servers from hardened-sources-2.6.28-r7 to hardened-sources-2.6.28-r9 and immediately had problems after reboot. Rebooting that server, I was greeted with the following message:&lt;/p&gt;

&lt;p&gt;&lt;div class="codeblock"&gt;&lt;code&gt;Booting &amp;#039;Gentoo (bzImage-2.6.28-hardened-r9)&amp;#039;&lt;br /&gt;&lt;br /&gt;root (hd0,0)&lt;br /&gt;Filesystem type is ext2fs, partition type 0x83&lt;br /&gt;kernel (hd0,0)/boot/bzImage-2.6.28-hardened-r9 root=/dev/sda4&lt;br /&gt;[Linux-bzImaeg, setup=0x2a00, size=0x165990]&lt;br /&gt;&lt;br /&gt;Decompressing Linux... Parsing ELF... done.&lt;br /&gt;Booting the kernel.&lt;/code&gt;&lt;/div&gt;&lt;/p&gt;

&lt;p&gt;I went ahead and posted this issue to the Gentoo forum and worked on a few ideas how to remedy this. You can follow that thread here:
&lt;a href="http://forums.gentoo.org/viewtopic-p-5762324.html" target="_blank"&gt;http://forums.gentoo.org/viewtopic-p-5762324.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I noticed that the hardened-source ChangeLog mentioned the following:&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/167"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/167#comments</comments>
 <pubDate>Sun, 31 May 2009 07:19:17 -0700</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">167 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/167</feedburner:origLink></item>
<item>
 <title>My first time with GoToMeeting</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/7Hi7GKIgdfM/</link>
 <description>&lt;p&gt;&lt;a href="http://www.dpbolvw.net/nl79qgpmgo3659C6553547C4986" target="_blank" rel="nofollow"&gt;&lt;img src="http://www.tqlkg.com/o398xjnbhf03269322021491653" alt="GoToMeeting - Online Meetings Made Easy" border="0" style="float: left; margin-right: 10px;"/&gt;&lt;/a&gt;So I've seen the commercials on TV about &lt;a href="http://www.dpbolvw.net/nl79qgpmgo3659C6553547C4986" target="_blank" rel="nofollow"&gt;GoToMeeting&lt;/a&gt; for a while, but I never had a opportunity to try it out. Yesterday, I had a conference call with a web client about a application we're developing and going over some server requirements to pull it off. Early in the call, the client recommend that we have this meeting using &lt;a href="http://www.dpbolvw.net/nl79qgpmgo3659C6553547C4986" target="_blank" rel="nofollow"&gt;GoToMeeting&lt;/a&gt;, since there were some graphic design topics that they needed to discuss with me and a marketing director.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/166"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/166#comments</comments>
 <pubDate>Sat, 30 May 2009 07:00:00 -0700</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">166 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/166</feedburner:origLink></item>
<item>
 <title>Recent package updates are making me nervous (Snort and Mod_Security)</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/NJCPD2DfdRk/</link>
 <description>&lt;p&gt;A few weeks ago, I saw that snort needs to update to 2.8.4.1 (up from 2.6.1.3-r1), but with this update, it no longer has support for snortsam. This sucks! I posted a thread about this on the Gentoo forums, but no response yet. Because of this I'm not updating my production boxes, that use snortsam as part of it's IPS. On a box that was running just snort, I had troubles getting it started. The whole thing left a unpleasant taste in my mouth.&lt;/p&gt;
&lt;p&gt;Here are some relevant links about this:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://forums.gentoo.org/viewtopic-t-764081-highlight-snort.html" target="_blank" rel="nofollow"&gt;http://forums.gentoo.org/viewtopic-t-764081-highlight-snort.html&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://bugs.gentoo.org/245752" target="_blank" rel="nofollow"&gt;http://bugs.gentoo.org/245752&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/165"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/165#comments</comments>
 <pubDate>Sun, 24 May 2009 09:17:41 -0700</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">165 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/165</feedburner:origLink></item>
<item>
 <title>Good site, admin</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/iJs904xVBcE/</link>
 <description>&lt;p&gt;I started seeing emails posted via contact forms with this message body. All sites on multiple servers starting experiencing this. I believe this is just a probe to test if contact forms are requiring captcha or this could be a initial set up for backscatter, etc. Either way, I don't like it. The first piece of investigation was to look at the IP of the originating requests. Unfortunately, they're all random. Clearly the program is using a proxy, or this could be a virus/worm related activity. So blocking based on origin is not a good solution.&lt;/p&gt;

&lt;p&gt;The next route that made the most sense for me was to create a mod_security rule to block this traffic based on POST payload. I'm running mod_security-2.1.2, so this rule may not work depending on what brand of mod_sec you're running. I created the following rule in my custom rule config.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/164"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/164#comments</comments>
 <pubDate>Mon, 18 May 2009 07:59:43 -0700</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">164 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/164</feedburner:origLink></item>
<item>
 <title>How to set up Spamassasin-FuzzyOcr for Gentoo</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/xVMMsOOXnj8/</link>
 <description>&lt;p&gt;After seeing a increase in image spam, I decided to add the Fuzzy OCR plugin for spamassassin. Basically, it will read the image and see if there are any words or phrases that are labeled as spam and append a score to it. I was surprised that I didn't see any how tos for Gentoo, and I ran across multiple issues setting this up, so here we go.&lt;/p&gt;

&lt;p&gt;We need to use spamassassin-fuzzyocr-3.5.1-r1 to get things working. Currently, Gentoo has 2.3b as the stable version, make sure you use the latest greatest. I added the following to /etc/portage/package.keywords:&lt;/p&gt;
&lt;p&gt;&lt;div class="codeblock"&gt;&lt;code&gt;=mail-filter/spamassassin-fuzzyocr-3.5.1-r1		~x86&lt;br /&gt;dev-perl/MLDBM-Sync								~x86&lt;/code&gt;&lt;/div&gt;&lt;/p&gt;

&lt;p&gt;I added the following USE flags to /etc/portage/package.use&lt;/p&gt;
&lt;p&gt;&lt;div class="codeblock"&gt;&lt;code&gt;media-libs/netpbm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; jpeg jpeg2k png tiff xml zlib -jbig -rle -svga&lt;br /&gt;mail-filter/spamassassin-fuzzyocr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; amavis dbm gocr logrotate mysql ocrad tesseract&lt;br /&gt;app-text/tesseract&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tiff&lt;/code&gt;&lt;/div&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/163"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/163#comments</comments>
 <pubDate>Fri, 24 Apr 2009 08:41:24 -0700</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">163 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/163</feedburner:origLink></item>
<item>
 <title>Grep the line and the line before or after.</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/5WAPXIoIhc8/</link>
 <description>&lt;p&gt;Here is a sweet trick I learned to day to grab the line you're looking for as well as the line after or before. It's using the -A or -B flag within grep. Glad I found this before writing a stupid script using awk, etc.&lt;/p&gt;

&lt;p&gt;&lt;div class="codeblock"&gt;&lt;code&gt;grep &amp;#039;some value in a line&amp;#039; -B 1 /var/log/messages&lt;/code&gt;&lt;/div&gt;&lt;/p&gt;

&lt;p&gt;This will grab the line and one line before. Use -A NUM for after the target.&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/162#comments</comments>
 <pubDate>Fri, 10 Apr 2009 12:07:19 -0700</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">162 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/162</feedburner:origLink></item>
<item>
 <title>Dealing with Qmail's TAI64N format</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/oRqVC04dCVs/</link>
 <description>&lt;p&gt;Today I had to do some work on my qmail, which I hate to work with. Basically, I needed to go through the logs and and verify some deliveries, etc. Well, the timestamps for qmail is using TAI64N (which I just learned about). You can use tai64nlocal to convert them to readable timestamps. Again, this is mostly for my reference in case I need to do this again.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/161"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/161#comments</comments>
 <pubDate>Fri, 10 Apr 2009 12:04:52 -0700</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">161 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/161</feedburner:origLink></item>
<item>
 <title>Potential DNS DDoS (query (cache) './NS/IN' denied)</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/YHiodNtyaUw/</link>
 <description>&lt;p&gt;I started getting a ton of these in my DNS logs a few days ago:&lt;/p&gt;

&lt;p&gt;&lt;div class="codeblock"&gt;&lt;code&gt;Jan 19 05:33:47 comp named[4488]: client 76.9.31.42#55056: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;br /&gt;Jan 19 05:33:53 comp named[4488]: client 76.9.31.42#30931: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;br /&gt;Jan 19 05:33:59 comp named[4488]: client 76.9.31.42#31789: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;br /&gt;Jan 19 05:34:06 comp named[4488]: client 76.9.31.42#38458: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;br /&gt;Jan 19 05:34:12 comp named[4488]: client 76.9.31.42#31734: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;br /&gt;Jan 19 05:34:18 comp named[4488]: client 76.9.31.42#52640: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;br /&gt;Jan 19 05:34:24 comp named[4488]: client 76.9.31.42#12441: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;br /&gt;Jan 19 05:34:30 comp named[4488]: client 76.9.31.42#20453: query (cache) &amp;#039;./NS/IN&amp;#039; denied&lt;/code&gt;&lt;/div&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/160"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/160#comments</comments>
 <pubDate>Mon, 19 Jan 2009 08:08:02 -0800</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">160 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/160</feedburner:origLink></item>
<item>
 <title>Apache-2.2.10 / Chroot and cURL is giving me some grief (SOLVED)</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/aqzI5Lz_fLY/</link>
 <description>&lt;p&gt;So my woes with Apache-2.2.10 and chroot is continuing. Now I can start Apache in the chroot environment, and I thought all was well, but after additional testing, I found out that cURL does not work. Basically, cURL will return a empty string while it's chroot'd. This is very weird to me, since the jail is EXACTLY the same as it was when mod_chroot was set up initially. This would mean the libraries should all be good still. I tested with the apache out of the jail and cURL works great. I've seen multiple mention of this problems, but usually related to https requests while in the jail. I've encountered those in the past (usually related to certs, urandom, etc missing from the jail). This problem is with straight http requests. I did find one very similar post here: &lt;a href="http://kerneltrap.org/mailarchive/openbsd-misc/2007/3/21/146482/thread" target="_blank" rel="nofollow" rel="nofollow"&gt;http://kerneltrap.org/mailarchive/openbsd-misc/2007/3/21/146482/thread&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.uno-code.com/?q=node/159"&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/159#comments</comments>
 <pubDate>Sun, 18 Jan 2009 13:29:19 -0800</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">159 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/159</feedburner:origLink></item>
<item>
 <title>Use mysqldump to get single table</title>
 <link>http://feedproxy.google.com/~r/uno-code/~3/_0wYNFqr254/</link>
 <description>&lt;p&gt;Hello all, this is primarily so I don't forget how to do this in the future. I needed to get a dump of a single table out of a remote database. This is the mysqldump command to pull that off:&lt;/p&gt;
&lt;p&gt;&lt;div class="codeblock"&gt;&lt;code&gt;mysqldump -p --user user databaseName tableName &amp;gt; out.sql&lt;/code&gt;&lt;/div&gt;&lt;/p&gt;</description>
 <comments>http://www.uno-code.com/?q=node/158#comments</comments>
 <pubDate>Fri, 16 Jan 2009 15:07:40 -0800</pubDate>
 <dc:creator>admin</dc:creator>
 <guid isPermaLink="false">158 at http://www.uno-code.com</guid>
<feedburner:origLink>http://www.uno-code.com/?q=node/158</feedburner:origLink></item>
</channel>
</rss>
