Subscribe: Carl's Whine Rack
http://mbrisby.blogspot.com/feeds/posts/default
Added By: Feedage Forager Feedage Grade A rated
Language: English
Tags:
don  file  firefox  lock file  lock  openssl passwd  openssl  passwd  password  pretty  problem  running  twitter  ubuntu 
Rate this Feed
Rate this feedRate this feedRate this feedRate this feedRate this feed
Rate this feed 1 starRate this feed 2 starRate this feed 3 starRate this feed 4 starRate this feed 5 star

Comments (0)

Feed Details and Statistics Feed Statistics
Preview: Carl's Whine Rack

Carl's Whine Rack



Using GNU/Linux through creative laziness (and other topics as they strike my fancy)



Updated: 2018-04-20T02:16:48.886-05:00

 



The difficulties of operating an Olive Garden on the moon

2014-11-30T10:37:58.980-06:00

(This is satire, fan mail, and a get-well card for Maureen Johnson. Here is some context for this nonsense.)

Maureen Johnson,

It is my displeasure to report that--at least temporarily--I've been forced to close my Olive Garden franchise on the moon. As you've always been such a strong supporter, I felt I owed you an explanation.

As the owner of many fine dining establishments in a variety of locales, I've found that running a restaurant has many challenges under the very best of circumstances. Running a restaurant on the moon has a few extra difficulties, and it goes far beyond the gravity problem (although breadsticks are notorious for floating right off the table).

There's only one health inspector on the moon (which caused plenty of scheduling problems), and he is MONSTROUSLY corrupt. When I refused to pay his "protection" fee, I found myself featured prominently in the "health inspection failures" report of the local newspaper. When I asked a fellow lunar restaurant owner how she dealt with the inspector, she (the restauranteur) said that she would just pay him. She regarded it simply as a business expense. I won't reveal which restaurant, but let's just say that I often imagined the inspector leaving that establishment, gleefully counting his money on his way out the door, saying "I'm loving it."

(This particular problem--the health inspection racket--seems quite specific to the moon. For example, even when the health inspector [DIFFERENT inspector] found at my Red Lobster restaurant in Atlantis that the kitchen, bathrooms, maitre D' station, bar, and dining area were LITERALLY CRAWLING with shrimp that weren't on the menu, he was entirely professional about the whole thing.)

(I had to close the Atlantean Red Lobster as well, but that's a different story. In retrospect, a seafood restaurant in Atlantis may have been a poor choice. Those folks prefer barbecue.)

Rampant smash-and-grab theft caused a problem with parking at the lunar Olive Garden. I've seen this problem at my Chili's restaurant on comet 67P/Churyumov-Gerasimenko, but it's far worse on the moon, where that nice little Philae lander would likely have been relieved of its harpoons before the driver even got his or her drink order. (There's a nearby pawn shop whose owner doesn't ask a lot of questions.)

Getting a liquor license on the moon is tough. All applications have to be approved by a council whose members are primarily other restaurant owners who don't want any new competition. Also, in a place where one day is nearly thirty times longer than on Earth, "Happy Hour" can result in some awfully thin margins. I thought serving cold beer at an Applebee's on Antarctica's Ross Ice Shelf would be difficult, but that's a cake walk (turns out that penguins are quite fond of Guinness).

And just try getting anything other than blue cheese on the moon. I mean I love blue cheese, but some of my customers prefer Parmesan on their salads. For someone who managed to find inexpensive chopsticks for a P.F. Chang's in freaking Asgard, you'd think cheese wouldn't be that big a deal, but it's a supply problem I still haven't solved.

So I'm hoping that this is a temporary setback. I've got a lead on a fromager somewhere in Mare Frigoris, I'm investing in some security cameras for the parking lot, and I'm sure the other problems will sort themselves out one way or another. I hope to reopen soon and that you'll honor us with your patronage. Thanks for all your support.

Management, Olive Garden on the moon




CentOS 7, openssh/openssl

2014-10-25T11:34:27.005-05:00

Yesterday I finally gave CentOS 7 a try as a Virtualbox VM. (In the following, when I talk about a guest or a host, it's in the virtualization vernacular.)I did what I usually do with VB guests: I gave it two network interfaces. The first is configured as NAT, so that the guest can reach the internet without the host needing a second IP for a bridged interface (bridging would be fine at home, but might cause me some trouble at work). The second is configured as host-only with a static IP, so that the host (and other guests) can initiate to the guest. (There’s probably a much easier way of doing this, but it’s worked so far.)My CentOS experience is primarily with CentOS 5, and several things were really different in C7. (CentOS and Red Hat documentation is typically pretty good and will no doubt help me through some of the following. These are just some of the things I’m stumbling on at the moment.)There’s no /etc/cron.daily/rpm, which creates a list of packages in /var/log/rpmpkgs. I use that a lot, so I copied that over from a C5 box.I had a pretty hard time with networking. Neither interface seemed to come up on its own at first. I had to set ONBOOT=yes in the corresponding /etc/sysconfig/network-scripts files, and then the second interface mangled the first interface’s NAT connection. I ended up setting ONBOOT to yes for the first interface (the NAT connection) and to no for the second (host-only) interface. I put an ifconfig statement in rc.local to bring up the second interface, and that (eventually) worked.ifconfig, netstat, and probably a bunch of other useful stuff is in the net-tools package, which isn’t included in a minimal install. And although there’s an rc.local, it’s not executable, and won’t run at boot until you “chmod +x” the thing.And the interface names are now really weird. Instead of something memorable, traditional, predictable, and sensible like eth0 and eth1, now they are called enp0s3 and enp0s8. (I just had to look those up, because I couldn’t remember them.)The new C7 guest has a very long list of iptables rules, but /etc/sysconfig/iptables doesn’t exist, so I don’t know where those rules are coming from. Thankfully port 22 is open by default, but I don’t like to run openssh on the default port, so at some point I’ll need to figure out how to fiddle with iptables rules.I use GNU screen all the time. (I know the cool kids like tmux, but, frankly, screw them.) I typically have a screen session in which I’m logged in to several different hosts, and each window is named for the remote host. C7 rewrites the window name in screen, so “Ctrl-A ‘, hostname” no longer works. I don’t know if I need to (somehow) tell screen (on my Ubuntu host) not to allow the window process to rewrite the window title, or if I need to (somehow) tell bash in the C7 guest to be less assertive.I’m also having some trouble building openssh from source in C7. The version of openssh that comes with C5 lacks some desirable features in the newer versions, so we tend to build it from source. In just the last version or two of openssh, something has changed such that it won’t build against the version of openssl that comes with C5. So the other day (before messing with C7) I built the newest version of openssl on a C5 box and built openssh against that. That worked, but I see now that by default openssl doesn’t create shared libraries, so the openssh I built linked to openssl statically (which made sshd nearly three times bigger than a dynamically-linked sshd).So far I’ve been unable to build openssh against a source-built openssl on C7. I get one error if I try to link statically, and another error if I try to link dynamically. The version of openssl that comes with C7 is pretty current, so I could just build against that and probably have no problem. Likewise I could just use C7’s version of openssh. But although I’ve enjoyed the stability of C5, everything about it is pretty old at this point. I think that in the future I’d like to bui[...]



PHPUnit via phar with suhosin

2014-05-02T08:04:14.446-05:00

The PHPUnit developer has announced the end of life for the PEAR installation method for PHPUnit. So I tried the phar method, but phpunit (and phar) would fail silently. After a little searching, I found a useful post* suggesting that suhosin might be the problem (I only have PHPUnit on my development platform, but I also have suhosin there, so that it more-or-less matches production). That post's suggestion of adding suhosin.executor.include.whitelist=phar to php.ini did the trick.


*That post is for an entirely different package, but it was the same problem I was having.



Problem with twitter's login verification feature (resolved)

2013-07-15T17:26:03.205-05:00

This is another "maybe this will help someone" kind of post. Long story short--if you stop getting login verification text messages from twitter, try texting GO to 40404.

At some point I enabled the login verification feature for my twitter account (@carl_welch). So whenever I want to log in to twitter.com on a PC or laptop, I type my username and password, and then twitter sends a 6-digit numeric code to my cell phone via SMS. Then I type that code into the form on twitter.com, and I'm logged in. I have my browsers set to delete cookies when I close the browser, so I end up doing this somewhat frequently.

(It works a little differently logging in to the twitter app on my phone. I have to log in to twitter.com on a laptop or PC and generate a one-time password that I use for logging in on the app. I generally only have to do this once, because I don't log out of the app on my phone.)

I got a new phone a couple of weeks ago: same number but a different provider. And I immediately stopped getting the login verification messages from twitter. So I couldn't log in. I'd managed to get logged in on the phone's app before restarting the browsers where I was logged in to twitter, so I could still use twitter while this was going on. But before I realized that I had a problem, I'd restarted my  browsers, and I couldn't log in (on a PC or laptop).

I submitted a help request to twitter explaining the problem, speculating that it might be because I changed provider, and asking them to disable login verifications for my account. I'm quite disappointed that--other than automated responses--I never heard back from them at all. Lame.

So I kept poking around on their help pages, and I stumbled upon a page talking about how to tweet via SMS. Seems like you start that process by adding a phone number to your account (which I'd already done) and then texting GO to 40404. For lack of a better idea I tried doing that on my new phone. And login verifications started working again immediately.

Lucky.



Software Choices

2013-01-01T13:06:24.947-06:00

I switched to Xubuntu a few days ago, and I've been trying a few changes in some of the other software that I use, too. Audio PlayerAfter using rhythmbox for a couple of years, I really tried to like gmusicbrowser, but I just couldn't. Even with the rhythmbox skin, I just didn't like the way the browser worked. I like to click on an artist and see the albums, and then click on an album and see the songs. gmusicbrowser didn't seem to do that (or I couldn't make it do that, anyway).So I looked at the Best Audio Player page of the recent readers' choice awards from Linux Journal to see what other people are using.I tried VLC, but it seems like more of a file player. I didn't see a way to import and browse my music library. I may not have given it enough of a chance, but I was disappointed with it.I rejected Amarok, because I'm not running KDE. I looked at installing banshee, but I was turned off by the long list of mono-related dependencies.So I gave up and went back to rhythmbox. To my pleasant surprise, the list of dependencies didn't look too long (no longer than banshee's, anyway), so I decided to stick with what I know. CD RipperI got a couple of CDs as gifts last week, and I wanted to rip and encode them, so I tried ripperX (which I'd used previously). For ripperX to work correctly, you need cdparanoia (to rip the CD to WAV files) and lame (to encode the WAV files to MP3 files). I'd installed cdparanoia, but had overlooked lame. When I tried ripping a CD with ripperX, it dutifully created MP3 files without a word of complaint. But then the audio player refused to import them. It took me a while to figure out that lame was missing, and it's disappointing that ripperX couldn't give me an error message about it. Even after installing lame, ripperX wasn't adding the ID3 tags: the CDDB lookup worked, but the generated MP3 files had no ID3 tags. That's important, because audio players use the ID3 tags to organize the music files.Next I tried asunder (which I'd also used previously), and it worked on the first try, ID3 tags and all.BTW, easytag is good at fixing problems with ID3 tags (and so is id3). Personal Financial ManagerI've used grisbi for years, but I've never much liked it. I looked at GnuCash a year ago. I even exported a QIF file from grisbi and imported into GnuCash. But despite the excellent documentation from GnuCash, I was overwhelmed by the transition, so I stuck with grisbi for another year.A couple of the gripes I had with grisbi (I was running v0.5.9 in Ubuntu 10.04) were minor, but annoying. The transaction dates are formatted for Europeans, and I just couldn't get used to that (in fairness, it looks like that has changed in the meantime). And I never had much success with the reporting feature. I typically ended up exporting the data in CSV format and then getting what I needed from a spreadsheet.A more significant problem involved what is for me a common practice. When I go grocery shopping, I typically buy groceries and beer or wine and get cash back at the register. The credit union sees that all as one transaction, but I like to track groceries, booze, and cash separately. In grisbi I'd have to make three separate transactions and then remember to put them together when reconciling with the bank statement.So this year I started a little earlier and read through the sections of the GnuCash documentation in time to make the transition at the new year. GnuCash has "split transactions" which should address my gripe about what to do with my grocery bill. I'll still have to do arithmetic to figure out how much is booze and how much is other stuff, but it may make it easier to reconcile when the end-of-month statement arrives. Dates look the way they "ought to," and the documentation makes the reports look easy and helpful. This one is a pretty big experiment, so we'll see how it goes.Other StuffI think I'll try LibreOffice this time, rather than OpenOffice. I don't use either enough to feel str[...]



Xubuntu

2012-12-28T18:10:52.742-06:00

I've been running Ubuntu 10.04 for a couple of years, but it goes end-of-life soon. I knew that upgrading would more-or-less mean learning a new window manager: Unity or something else. I decided to try going with XFCE in Xubuntu 12.04 (which will have support until April 2017).

I have so far been pretty happy with it. I backed up everything I could think of to a second hard drive, and then did a fresh install off of a USB drive. It didn't take long, and then I spent a couple of hours restoring files and setting up software and stuff, such as...

  • installing google chrome and importing bookmarks (I'd exported them prior to the upgrade)
  • restoring ~/.purple so that pidgin would work
  • installing postfix and configuring it to relay off of gmail, so that logwatch and my cron jobs would land in my gmail inbox (I'd already done this, so I just had to restore a couple of files)
  • installing VirtualBox and restoring ~/.virtualbox (and my guest machines booted without much complaint)
  • pointing gmusicbrowser at my MP3 collection and skinning it to look like rhythmbox (there are some minor differences I'm still getting used to, but it looks like the playlists I exported from rhythmbox import right into gmusicbrowser, so that's a pleasant surprise)
  • setting up an encrypted subdirectory in $HOME
I find that I don't much care for the panel at the bottom (the one that's supposed to look like OS X), so I may end up removing it. And I'm finding that the keyboard shortcut for "maximize window" is flaky for some reason. But those are about the only two wrinkles I've found. It was otherwise pretty painless, and it took less time than I expected.



Red Hat and CentOS process locks do not belong in /var/lock/subsys

2012-12-20T09:14:23.860-06:00


I have a bash script that runs via cron every night. It's a software package repository mirroring process, so it has the potential to run for a long time. I don't want two of them running at the same time, and I want to know if one is running for more than 24 hours.

So the first thing the script does is to check for the presence of a lock file in a particular location. If the lock file exists, that means that the previous instance didn't complete, so it spits out an error message (which will land in my email) and quits. If the script does not find the lock file (which is the normal condition), it creates the lock file (via touch) on the very next line. The very last thing the script does is to remove the lock file.

if [ -f /var/lock/subsys/mirror ] ; then
echo 'previous instance running--quitting'
exit
fi
touch /var/lock/subsys/mirror

# long-running mirroring process...

rm -f /var/lock/subsys/mirror

We have scheduled downtime from time to time to do operating system upgrades and other maintenance. I typically create the lock file manually at the beginning of maintenance, because I don't want my local repository changing while I'm running updates. And then I manually remove the lock file at the end of maintenance.

We did maintenance last night, and the server that runs this mirroring process was having some kind of problem. We ended up rebooting the server (which, in this case, resolved the problem we were experiencing).

Turns out that part of the reboot process on Red Hat (and CentOS) is to clear out the /var/lock/subsys directory, which is where I'd been putting the lock file for the mirroring process. Oops.

Fortunately, the reboot happened after the cron job, and so the cron job didn't run unexpectedly. But that was just a matter of lucky timing.

So today I'm moving the lock file to /var/run. And I may as well make it work like the other files in that directory. So instead of

touch /var/lock/subsys/mirror

I'll do

echo $$ > /var/run/mirror.pid





Travel-related tech

2012-11-25T17:25:33.501-06:00

I recently took a trip, and here are a few notes about some of my technology-related experiences.

I knew I'd probably want Internet access at the hotel, but I figured it would be wireless, and I was hoping for some kind of VPN. In the past I've used ssh's socks proxy feature, but I've found it to be pretty slow. So I thought I'd give wonderproxy a try. You can get a VPN account for a month for around $5, and I thought it worked really well. It was fast, and it made me feel a little better about using the hotel's wireless.

I bought a Macbook Air not long ago, and I like it. So I took it with me on the trip. I took some pictures, and I used iPhoto to copy the pictures off the camera onto the laptop. Then I tried using iPhoto to upload the photos to flickr, and that didn't work well for me. iPhoto crashed at one point during an upload of a bunch a photos, and there was no obvious way to resume the upload. I was able to figure out where it quit, and then I just told it to upload the photos it missed. But many of the photos on flickr don't have the original size--the largest version of many of them is 1024x768 (there should be three larger sizes). So I have to upload those images again or just be OK with the smaller sizes on flickr. So I'm glad I hadn't told iPhoto to delete them off the camera.

I also told iPhoto to mark several of the photos as private, and they ended up as public on flickr.

So I probably won't be using iPhoto any more.

And although southwestvacations.com did a great job of booking the trip, they totally FAIL in password security. When I created the account, I used a password generator to create a long password with all four character classes, and I saved the password in my password wallet. At one point during the trip, I needed to access something in my account. But when I tried to log in, I got invalid username/password errors. I ended up using the "forgot my password" link, thinking it would send me a login token. Nope, it sent me my password. It wasn't even my original password (which is why I was having trouble logging in). The original was around 20 characters long, but what they sent me was the first 10 characters of the password I'd created. So southwestvacations.com

  • restricts password complexity (they truncated my password at 10 characters--the 11th was a percent sign, so I don't know if it was the length or the character)
  • they truncated my password without warning me
  • they store non-hashed passwords
  • and they'll send passwords by email
FAIL.

Otherwise, it was a lovely trip. Have a look, if you like.



shadow passwords with openssl

2012-11-03T16:30:36.633-05:00

I once had to break in to a CentOS box, because I'd forgotten root's password and didn't know the passwords to any other users (I think it had been shut down for a while). So I booted with a rescue disc (I think it was a CentOS installation disk, and I typed "linux rescue" at the prompt). The rescue disc mounted the filesystems, and I tried running passwd in a chroot. I got some kind of error message, and it wouldn't reset the password for root in /etc/shadow on the filesystem. I ended up editing /etc/shadow by typing in a password I got out of /etc/shadow on another box.As I'm writing this, it occurs to me that if I knew the password to some other user (at this point I don't remember if I did or not), I could have just edited /etc/sudoers to give root to that other user, rebooted, logged in as that user, and done "sudo passwd" to reset root's password.But if you ever need to create /etc/shadow entries by hand for some weird situation, here are a few suggestions involving openssl's passwd utility.Incidentally, if you have trouble finding the man page for openssl's passwd ("man passwd" is likely to get you the man page for thing that resets your login password), try "man 1ssl passwd" (Ubuntu) or "man sslpasswd" (Red Hat 5).The hashed passwords in /etc/shadow look something like this:$1$.oDCRZmb$mYZm6IzfMWVfe38Pr4fHt0The shadow entry has three parts delimited by dollar signs. The 1 indicates that this shadow entry was computed with the MD5 password algorithm. The next section (".oDCRZmb") is the salt, and the final portion is the hashed password.You can generate these yourself. If you type the following (the "-1" requests the MD5 algorithm)echo password | openssl passwd -1 -stdinyou should get something resembling$1$DcuakEM4$c4WDkEXKd6YXNYjAfN2Sh/You can reproduce this by providing the salt:carl@stilgar:~$ echo password | openssl passwd -1 -stdin -salt DcuakEM4$1$DcuakEM4$c4WDkEXKd6YXNYjAfN2Sh/And it looks like openssl is smart enough to strip the newline:carl@stilgar:~$ echo -n password | openssl passwd -1 -stdin -salt DcuakEM4$1$DcuakEM4$c4WDkEXKd6YXNYjAfN2Sh/Without the "-1" argument, openssl uses the standard crypt algorithm. The first two characters from crypt output are the salt, and this is what the Apache webserver's htpasswd uses for making passwords (at least, crypt seems to be the default algorithm for the Ubuntu and Red Hat 5 packages):carl@stilgar:~$ echo password | openssl passwd -stdinBxZPctq22eZ4Mcarl@stilgar:~$ echo password | openssl passwd -stdin -salt BxBxZPctq22eZ4Mpasswd also knows the Apache variant of the MD5 algorithm:carl@stilgar:~$ echo password | openssl passwd -apr1 -stdin$apr1$z4cUIQjr$fXbDk6ypzyZIIIb/OIp0I.carl@stilgar:~$ echo password | openssl passwd -apr1 -stdin -salt z4cUIQjr$apr1$z4cUIQjr$fXbDk6ypzyZIIIb/OIp0I.Looks like Ubuntu uses the sha-512 algorithm for hashing passwords, and openssl's passwd doesn't support this. If you want to try making /etc/shadow entries w/ sha-512, try saving the following file as passwd.c:#define XOPEN_SOURCE#include #include int main(int argc, char *argv[]) { if ( argc < 2 ) { printf("usage: %s password salt\n", argv[0]); return; } printf("%s\n", (char *)crypt(argv[1], argv[2])); return;}And then try this:gcc -lcrypt -o passwd passwd.c./passwd password '$6$salt$'[...]



setting the session.cookie_path in PHP (redirection loop)

2011-08-24T07:53:10.386-05:00

This is a quick note about a bug in some PHP code I was working on the other day. It took me a while to figure it out. I was developing and initially testing in google chrome, which is evidently forgiving of this kind of error. Maybe writing this will help someone (and maybe it'll help me not to make the same mistake again).

This was for an application which requires authentication. The controller sends the browser a redirect (to the login URL) if the user is not authenticated. I had set the cookie path with something like the following:


$baseUrl = 'https://www.example.com/gakkk/';

// several lines later...
ini_set('session.cookie_path', $baseUrl);


This worked OK in chrome, but Firefox and MSIE both got locked up in redirection loops. After scratching my head for a while, I finally figured out that I should be doing this:

ini_set('session.cookie_path', '/gakkk/');

The cookie_path (it has that name for a reason) should exclude the protocol, hostname, and port. Information security auditors like to complain about web applications that don't set the cookie path.




Testing an SSL-enabled service for cipher strength

2011-07-14T07:42:20.379-05:00

Vulnerability scans sometimes find that an SSL-enabled service allows clients to connect using ciphers which have key lengths shorter than 128 bits. Most services have configuration directives to disable these connections. Here's how to test a service for key length (without doing a new nessus scan, or whatever).

openssl ciphers -v

This gives a list of ciphers that the openssl client can use, and the output indicates the key length. openssl's s_client command can take an argument which specifies the cipher(s) to use. So after reconfiguring the server, run the following two commands (the first should fail, and the second should succeed):

openssl s_client -ign_eof -connect target:port -cipher RC4-MD5

openssl s_client -ign_eof -connect target:port -cipher DHE-RSA-AES256-SHA

(You should replace target:port with something like www.example.com:443)





Safari Issues

2011-02-04T08:57:02.813-06:00

I learned a couple of things about Safari yesterday. When using the @import syntax for CSS, make sure you remember the semi-colon after the URL (outside the quotes):





Firefox and Internet Explorer are forgiving about a missing semi-colon, but Safari won't load the stylesheet without it.

And by default Safari has only limited support for tabbing through Web pages (something that's probably pretty important to keyboard users). The default setting will allow you to tab from form field to form field, but you can't focus on links by tabbing. You can enable this behavior (which is behavior I've come to expect from using Firefox and Internet Explorer) by going to the Advanced tab of the Preferences menu and clicking the checkbox that says something like "Press Tab to highlight..."



added READONLY option to password wallet

2010-03-14T18:58:00.666-05:00

Made an update to my password wallet. You can now have the READONLY attribute in your .walletrc file: this disables updates to the wallet (w/ the -e option). I keep my wallet in two places (work and home), and a cron job copies from work to home daily. So I need to make sure that I only update the wallet at work. I once updated it at home, and the next run of that cron job overwrote the update (a new password).



panopticlick

2010-01-29T16:41:55.547-06:00

I've seen several posts about the panopticlick project in the last few days. If you go to the panopticlick Web page and click the "test me" button, it'll tell you how identifiable your Web browser is. The idea is that it might be possible for someone to track your Web browsing based solely on certain characteristics of your Web browser (without using cookies or even IP addresses).

So I hit the "test me" page with several different kinds of browsers to see what kind of results I would get. The results are given below (all Firefox browsers below have the NoScript extension). In terms of security, these are like golf scores: you want low numbers in the second (BII="bits of identifying information") and third (NIF="number of identical fingerprints") columns. And in terms of security, being unique is bad (it makes it easy to identify you).




















































browser/platformBIINIF
MSIE7 on XP17.64unique in 204,788
Firefox 3.6 on XP8.62one in 392
Firefox 3.6 on Ubuntu12.64one in 6,364
MSIE6 via wine on Ubuntu17.66unique in 207,713
lynx on Ubuntu14.67one in 26,001
elinks on Ubuntu17.67unique in 208,111
wget on Ubuntu9.57one in 761
curl on CEntOS17.67unique in 208,688



Firefox 3.6 on XP did pretty well, so I captured the HTTP request headers from that browser:

GET / HTTP/1.1
Host: vmware:8000
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (.NET CLR 3.5.30729)
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive


Then I installed the Modify Headers extension to Firefox on Ubuntu and set the User-Agent header to the value from the request headers above. After doing that, Firefox 3.6 on Ubuntu got panopticlick scores like Firefox 3.6 on XP.

An interesting side effect of this is that the Firefox Add-Ons site uses the User-Agent header. So if you do this and want to add extensions later, you will probably need to disable the header. And I've just done this today, so I don't yet know what effect this will have on updating extensions.



pager in wallet program

2009-11-03T22:06:24.038-06:00

I recently got an email from someone who has been using the password wallet program. The reader asked about the possibility of using a different pager when viewing the password file (the "less" pager is hard-coded into the program).

I thought this was a good idea, so I've changed the wallet program to allow the user to specify the pager using the WALLET_PAGER environment variable (which defaults to "less"). You can also put this in the .walletrc file. The reader wants to use w3m, so this should now work in .walletrc:

WALLET_PAGER="w3m -o bg_color=blue"

I've updated the program in the google code repository.



Zendcon 2009

2009-10-26T19:01:25.682-05:00

Got home last night from Zendcon 2009. Good conference.

Here are a few of the main things I'm taking away from it:

  • I'm a fool not to be using APC (and maybe memcache)
  • Zendconners really like twitter (I got sucked in: @carl_welch)
  • I need to learn more about dependency injection and better OOP methods
  • I need to give git a try (had a good visit with the guy at the github booth)


Update (Monday 26 October): I took some pictures, and I've posted them to flickr.

(image)

(image)



Barnswallows' return

2009-05-16T12:58:26.950-05:00

The barnswallows are back. Considering the placement of the nest, I assume that it has to be the same ones as last year. I've been taking a few pictures.



belated Earth Day

2009-04-26T12:11:48.787-05:00

Here are a few interesting articles I found this past week:



bad news for iron fertilization

2009-03-29T10:58:03.468-05:00

I follow a few environmental blogs, and for a while I was occasionally seeing posts about the possibility of using iron fertilization for carbon sequestration. The idea (as I understand it) is that scientists would dissolve a bunch of iron near the ocean surface, phytoplankton would consume the iron (causing the phytoplankton to flourish), the phytoplankton would inhale a bunch of carbon dioxide, and the phytoplankton would sink to the bottom of the ocean, taking the CO2 with it, forever.

So they tried it.

They dumped a bunch of iron in the ocean, and the phytoplankton dutifully multiplied (and presumably inhaled a lot of CO2). But before the phytoplankton could sink, it ended up at the bottom of the food chain of a series of increasingly large sea creatures that live near the surface.

Nice try.



Batman logos

2009-03-25T11:28:14.544-05:00

There's a post on /Film highlighting a youtube video showing various incarnations of the Batman logo. The video includes logos from various comic book titles, TV series, and films. It's not exhaustive, but it's a cool presentation of a good sampling.



saving space in firefox

2009-03-18T07:30:00.991-05:00

I found a cool Firefox extension a day or two ago. It's called Menu Mod, and it's good for saving some space on the Firefox window (particularly if you have a small screen, like on a netbook). It can collapse all the standard menu items into a single menu item (after installing/restarting, do Tools->Add-ons, click Menu Mod, click Preferences, select "Place all menus inside another"). This isn't all that helpful on its own, but try also doing the following:
  1. do Menus->View->Toolbars->Customize
  2. drag all the stuff from the navigation bar (Back/Forward/Refresh/Stop/Home buttons, address bar, etc.) up next to the newly-collapsed menu
  3. get rid of the search field by dragging it to the "Customize Toolbar" window
  4. do Menus->View->Toolbars and uncheck the Navigation toolbar
If you do this and start to miss the search toolbar, try this:
  1. go to www.google.com (or whatever your favorite search engine is)
  2. right-click in the search field and select "Add a keyword for this search..."
  3. add something descriptive for the Name field (like "search" or "google")
  4. add something short for the Keyword field (I used "g")
  5. next time you want to do a search, open a new tab (Ctrl-T is as easy as Ctrl-K), then type the keyword ("g" for me) followed by a space and your search term(s)
If you use the Web Developer extension, do Menus->View->Toolbars->Customize and drag the "Web Developer" item so that it's to the left of the URL bar. Clicking this new item is a quick way to hide/display the Web Developer Toolbar.



xampp

2009-03-17T07:30:01.114-05:00

At times I've wanted to try doing some development work on my eeepc, but the default distribution doesn't come with a LAMP stack (and so far I've been too chicken to try installing something else).

Today I tried installing xampp, and that seems to work pretty well. So far my only complaint is that it doesn't seem to come with any version control tools (like svn), and I don't see an easy way to add/compile them (the eeepc doesn't have gcc).



ESC key alternative in vim

2009-03-16T07:30:01.839-05:00

I've been using vim for a couple of years now, and I really like it. But one thing that's always been a nuisance to me is reaching for the escape key. I often hit the wrong key (like the tilde or F1), and/or I have to glance at the keyboard to find it.

A recent post by Matthew Weier O'Phinney suggested binding the 'jj' sequence to . I've been trying that for the last day or so, and I'm finding that to be a pretty good trick. Here's what I added to ~/.vimrc to make it work:

:map! jj



Star Trek Old School

2009-02-01T09:47:32.092-06:00

Funny stuff.

Uhuru is my favorite.



Belize: Day Off, Return

2008-12-19T07:30:00.504-06:00

(This is part 6 of a 6-part description of a trip I took to Belize with friends just after Thanksgiving 2008. I put my pictures a flickr.)

We didn't plan anything for Thursday, so we slept in. After a leisurely breakfast, we headed north into the shopping areas of San Pedro. We visited several shops looking for souvenirs and gifts. I found that most of the offerings seemed to be overpriced tourist junk, but I did splurge on a couple of Belikin Beer T-shirts. This shopping trip was also a pub crawl: we hit four or five bars, having lunch in one of them. There are lots of dogs in San Pedro. One would adopt us for a while as we walked along, and another would pick us up as we left a shop or bar. We finished out our last full day of the trip with a delicious dinner at the restaurant of a nearby coastal resort.

We took it easy again Friday morning. I partook of some wireless Internet by the Xanadu pool (my friends were impressed that I'd held out for nearly a week), L and KL swam a bit, and H and K did a little more shopping. Then we packed up and took a cab back to the San Pedro airport. Another Tropic Air flight with more breathtaking views of the Caribbean took us directly to the Belize City International Airport. Other than K having a bit of trouble with immigration/customs in Houston, we had an uneventful trip home. The temperature change was pretty startling: from somewhere around 85F to 33F. Ouch. Back to reality. *shrug*

(image)

It was a fabulous trip. I'd do it again.