Monday, July 28, 2008

Fun Christmas Project

If you are offended by Christmas then LOG OFF!!!!!

I just ordered some circuit boards for making one of those Christmas Light Displays that are synchronized with music. The boards are coming from another country. Once they arrive, I am going to order enough parts to populate one board and build it for a total of 16 channels. If it works, I will build the remaining boards. I will post my progress here. Yes... I'm starting early - but this could be a big project. Hopefully the local overstock store will have a ton of cheap Christmas Lights for sale around Thanksgiving like they did last year.

I already have an FM transmitter and found some cool Christmas Music. I am not revealing the songs on the internet because I want to be the first to do these songs. I'm probably going to include "Wizards in Winter" by Trans Siberian Orchestra because "everyone does it" and I can get a good start on a sequence by downloading it.

(The following video link is not of my house) For those of you who have no idea what I am talking about, check this video out (I REPEAT, not of my house).

If I get anything decent working, I will upload some YouTube videos and post the link to my channel.

Since I just moved in June, I will surely make an "impression" on my new neighbors. Cracks me up... I found out that my house is known as "the computer science house" by several neighbors because the previous owner taught computer science at an elementary school. Boy, are they in for a surprise - HA HA HA

Saturday, June 14, 2008

DMZ Host and OpenWRT

I now have my ActionTec router that Verizon gave me with my FiOS set to use my OpenWRT router as the DMZ Host. So far, so good. The only major "problem" so far is that if I portscan myself, all of the ports that I am not running services on show up as "closed". The ports I run services on and a few others drop the packets on the floor and show up as "stealth". I need to figure that one out but at least I'm connected through a secure connection now. I tried turning the ActionTec into a bridge but it doesn't seem to be worth the trouble. My bandwidth seems to be about the same with this config. The bridging methods I've seen appear to be a real PITA as you have to reset some things after power failures etc. Not worth it to me at this point.

Update: Quick tweak to a couple of lines in my firewall config on OpenWRT and everything is as it should be once again. grc.com reports my router is totally stealth.

Tuesday, June 10, 2008

MH Alert: Major FiOS WiFi Security Hole

I recently got FiOS through Verizon. I am very pleased with the service. If you have FiOS, please take a look at your router... in particular the sticker with the default WEP key on it. Notice another number that is very similar that happens to be on the same sticker????? AHA - they use the last 10 characters of the MAC address as the default WEP key!!!!

So:

1. You aren't foolish enough to be using WEP, are you? Switch to WPA or WPA2.
2. If you have to use WEP, you aren't foolish enough to use the default WEP Key, are you?
3. The first 6 characters of the MAC typically are the same for the manufacturer/model so they are probably all the same.
4. WiFi 802.11b and 802.11g broadcast the MAC in the clear so your router is basically announcing it's default WEP key to the world!

I mentioned this to my installer and he said "yeah... people are stupid and they don't change it." He was fairly technical as far as installers go and knew it was an issue when I mentioned it.

This is so awesomely stupid on Verizon's part. Surely these things have serial numbers that could be used as the WEP key. "Can you hack (sic) me now? Good..."

"Verizon... It's the network" and it's not secure at all - BWAHAHAHAHAHA!!!!

Most WEP protection can be broken after collecting many thousands of packets. Verizon's can be broken after one packet - BWAHAHAHAHAHA!!!!

Personally... I'm going to turn off the WiFi on this beast altogether and use my OpenWRT router as the "DMZ Host" and use it's WiFi. If I can spot this hole during the installation of my service, what other gaping holes are out there waiting to be discovered? Verizon should have gotten a router that uses OpenWRT, the service would then rock my face off.

Be careful out there!

Update... In Verizon's admin interface, it has RECOMMENDED next to WEP and not next to any of the WPA options.

Saturday, May 17, 2008

Microsoft's "4th Gen. After Success: Sucks" Pattern

I have held this theory for a while and wanted to document it. I have noticed over the years that after a particular technology that Microsoft releases "catches on", the 4th generation of it becomes a horrid piece of trash. Here are my examples:

1. MS-DOS 1.x - Tremendously caught on - started the whole PC Revolution. MS DOS 4.x was the worst version of MS-DOS EVER. Version 5.x and 6.x were major improvements and brought things back under control.

2. Windows 3.x - Windows finally catches on. The following releases of the technology were (#2) Windows 95, (#3) Windows 98/98SE, (#4) Windows ME. I don't think too many people will argue with me that Windows ME was the worst.

3. Windows NT Technology - This really did not take off until Windows NT 4 so we will call that #1. The following releases of the technology were (#2) Windows 2000, (#3) Windows XP, (#4) Windows Vista. Need I say more? Look at how horrible Vista is doing.

What is it with Microsoft and the number 4? The only thing I can figure is this: Look what happens when you count to 4 in binary on your fingers - ha ha.

Saturday, April 26, 2008

Hilarious Spam Story

It's been a while since I've posted - been busy but have a funny story to share. A while back, some company started spamming one of my domains. Several companies, actually. Some dirty spammer sold an address list using addresses from my domain and presenting them as doctor's email addresses. So these "legit" companies start sending me a lot of medical spam. This one company ignored my emails to cease and desist a while back, so I called and yelled at them on their voicemail. The next day I get an email from a hobo account with the VP of this "company's" IT department as the username asking me to identify myself. I ignore it and the spam stops until YESTERDAY.

I start getting spam from this same "company" again. I go to their website and click on the "contact us form" and type in a KNOCK IT OFF message. I hit submit and all I get is this red message near the submit button - no data clears, no redirect. Red message says "your request has been submitted". I hit the submit button a couple of dozen times.

I get an email from the same dude above, using his "company" email. He tells me that I need to submit each email separately as a request to stop, and that I've been acting unprofessionally. He then accuses me of a denial of service attack for sending him a couple of dozen requests.

I go back to his web form and address him by name. I tell him that I don't have to act professionally - he's spamming my house. That he has a dodgy web form and that 2 dozen messages to get someone's attention does not constitute a DOS Attack. I tell him to fix the problem, stop buying addresses from spammers and to grow up.

Dude has the nerve to write back and basically say "OK... but technically we're not spamming you". I can't believe this bozo - it was hilarious.

If you are reading this, Mr. White Trash Big Shot IT VP From (_|_) As*ville North Carolina, be glad I am not using your real name or company name. I will next time - 3 strikes you're out.

ROTFLMAO

Friday, February 22, 2008

Enoying my new server

It's been alive for about a week. My virtualized Red Hat 7.3 install is chugging along inside VMWare Server as is my virtualized FreeBSD 6.1 machine. The older hardware has been given a rest (well the 850mhz PIII became the new Kid Computer). My buddy Chris at work helped me diagnose a video problem I was having because I thought I was running the nvidia driver but really running the nv driver - causing havoc with vnc. Other than my virtualized FreeBSD machine's clock racing ahead a couple of minutes a day (no matter what I do - solved the problem in RedHat - that one was racing MUCH faster) everything is chugging along fine.

Sunday, February 17, 2008

VMWare Server Sound on CentOS

Kind of disappointing that VMWare Server can only use the sound on one VM concurrently and that's only of nothing else is touching the sound card. Turns out after googling around a bit that VMWare uses OSS for it's sound. I installed the alsa-oss package for FC7 and the alsa-oss-libs package for FC7 as well (got them from rpmfind.net). I then renamed my vmware script to vmware.orig. I wrote a new script called vmware to run the aoss wrapper and have aoss invoke vmware.orig and pass all of the args it received. Works like a champ. Now at least all of the VMs can have sound. They can't use the sound at exactly the same time, but at least it's better than it was before. Afterall, what's a home automation system without sound :-)