May 27

Its now quite easy to use the webcams on Linux these days. One of the application which has caught my attention for a while now is “Cheese“. If its installed on your Ubuntu,  you can find it in Applications -> Graphics menu.

I took a pic while driving back home using the web cam which is on my laptop. It was quite easy to take the snap as I can rotate my cam 180 degree without any issues.

Read the rest of this entry »

Mar 8

News of Owning Vista from the boot with VBootKit developed by NVlabs Nitin and Vipin is still buzzing around our ear and this year you’ve an another hot news. Guess what?

Yet another tool to unlock the windows box without password is now on internet. It’s HOT.

Boileau, a New Zealand based consultant with Immunity Inc., demoed a tool way back in 2006 to gain Firmware memory access. Years have passed but no solution to this serious issue from Microsoft. Finally Boileau decides to release this tool on his websit. Its called Winlockpwn, bypasses windows authentication via firewire, as demoed at Ruxcon 2006, and released on Risky Business, 2008.

This tool lets you inject the code to modify the Window’s password protection code. All you need is to connect to the target machine via its Firmware port from your Linux-based computer and gain the full write access to its memory.

Read more about this project and tool here

Feb 14

I was able to peep into this event on 11th and 12th here in IISc Bangalore. I was wondering what Microsoft has got to say about its OpenSource initiatives. Also it Sundip Menon from Novel made it clear why Novell really joined its hands with Microsoft in CTOSummit. “OSIW-2008″ its just awesome! I got to learn whats really happening out there in the world of OpenSource in India.

OSIW is just a new name adopted by “LinuxAsia” - India’s biggest OpenSource Event. I think it really made lot more sense. Its being held across three cities New Delhi, Mumbai and Bangalore till 15th FEB. It was really needed to show off what Indians are contributing to OpenSource community and how Indians can do lot more with it.

Read this Deccan Herald News which updates you on “OpenSource Breaking Barriers“. Two business models coming up together to bring in new innovations ;) lol, yes OpenSource has got lot in it. You will explore it when you read through this news. Co-existence of Microsoft’s Proprietary model and OpenSource model have brought healthy competition in the world.

WorkShops, CTOSummit, Talks about technopreneurship, Expo, IT Admin and IT Developer tracks did help people from different streams to explore new advancements and event was really very interesting. It would have been better if it was conducted during the weekends.

I got benefited by Mysql session conducted by David Axmer (Co-Founder Mysql) and Brian Arker and Panel talk on Virtualization at CTOSummit. Collabnet, Mysql, Knoppix founders really brought in their real stories to tell us what made them “billion dollar babies

Cheers… World will see us growing big every day, Come on India you too can make more money with OpenSource ;)

OSIWeek Website

Feb 3

We talk about technology and talk big about bringing that nearer to common man. How much successful we are? Piracy is one of the biggest problem which we keep discussing all the time. Are we really fighting against piracy? We also know that there is a community which works for nothing to bring good things for Society and does help us to stop using pirated softwares on our machines. How many of us share info about it with others?

Linux, Free and OpenSource software who doesn’t know about these words these days. But how many really think of going and adopting a technology which might turn out to be a headache?. Just a sec., Headache? Linux? OpenSource? Hey, come on you have better things in this free world and there are enough freedoms for you to choose what you want also you can decide what you want to do with it once you have it in your hands.

Not many encourage use of Linux and there are not many people who can show off what can be done with Linux and how it is far better than other proprietary operating systems. Even many of the governments doesn’t have ‘CS’ factor to analyze what is good and what is not for the society and end up using our tax money to purchase insecure solutions from corporates.

When you think at the root level, many people in our country can’t even understand “What is technology?”. The knowledge is not reachable, this might be the main reason behind this. Most of the books related to many technologies are available in “English” and it does take a good amount of time for any one to learn English and then start reading about technologies. I have been reading Poornachandra Thejaswi’s scientific books from few months now and I did learn how much it is important to teach our people about the technology and advancements. That too in their own language.

Yesterday I started writing about “Linux” in Kannada on my blog space at Sampada. It is a series of write ups on Linux and it’s usage for every one in ‘Kannada’. My small effort to spread knowledge to my own community. The series is called as “LinuxaayaNa“.

Knowledge is Power! Share it

Jan 13

It was scary to upgrade some firmware when there were no one to help you on board at DC on a weekend and you are sitting in a remote location connected via broadband facing technical glitches. Firmware upgrades failed yesterday as I had directly started upgrading the RAID Controller firmware upgrades. I did learn that I have to finish few other upgrades like BIOS, Baseboard Management Controller, Dell Remote Access Controller 4/I were supposed to be upgraded before setting off with PERC upgrades meant for raid controllers.  When ever a firmware upgrades fails you should not forget to remove the temporary files else it will bring you nightmares.

When I started off with the firmware upgrades today, I started getting these lines turning up on console. This is a my first Firmware upgrade on Dell PowerEdge series servers on Linux.

 An Update Package is already running.
Wait until it is complete before proceeding with another update.

I had to remove a lock file which was left on the server due to yesterdays test run :  /var/lock/.spsetup

It all started when I started facing load issues on one of my Mysql Server and found that “iowait” was too high to cope up with the high traffic at peak hours. PowerEdge-2850

I had to contact Dell to check out if there is any fix which they can provide in order to resolve this issue as there was no software related changes made to the server. You can also find that iowait is a very common issue on Linux servers and many times its directly related to the hardware and the OS installed.

We use this server to provide database solutions to Soho launch installations which we have for various websites. It was funny to find various stats generation queries coming to Mysql server and hanging over there for quite a long time that too around peak hours and causing slow response issues from servers. When I contacted Joe Lain of Soholaunch asking for a solution to the issue which I have been facing with my server, he too found it funny to see SQL queries. He was found to be working on a significant server slow down issue which was already traced back to the same SQL queries which I had pointed out.  Waiting for an update from him to get this thing resolved at the earliest.

Anyways, I’m done with the firmware upgrades as I had promised. Yes issue is still not fixed. Now, I got to monitor the load on the server at peak hours and wait for update from Soho Launch to get the issue resolved completely.  Wish me luck ;) I shall update you once I’m through with it.

Jan 12

KDE 4 is out at last. The most awaited release of K Desktop Environment which enables the end users to enjoy and experience hundreds of rich applications designed for Internet, entertainment, education, graphics and software development etc in much better way.

KDE

Its beauty, Its improved and its Free. Feel it, take a tour.

Arklinux, Debian, Kubuntu, Gentoo, Mandriva, Fedora, OpenSuse have announced the availability of KDE 4.0 on their builds or on some of their Live CD’s. Check the respective distro websites for more updates on it.

Read more about Kde 4.0 here.

Jan 6

BackTrack, a Slackware based Linux security distribution focused on penetration testing. With its 3rd release its becoming more stable, usable and compatible with various hardwares. Bundled with more than 300 up-to-date tools its ready for security professionals use. Read its history on the project page. Its very interesting.

BlackTrack You can now find the most anticipated BT3 beta release on Remote-Exploit.org . Its a easy to use Live-CD distribution and you can also find it in USB, Vmware image formats. Its wiki provides extensive documentation on the distribution.

Security enthusiasts never miss to check on this. Every one finds it easy to use and its always up-to-date. Now its your turn.

 

Watch out BackTrack 3 Teaser Video highlighting the new features of this distro.

Its rocking on my Dell XPS 1210. Share your experiences.

“No other commercial or freely available analysis platform offers an equivalent level of usability with automatic configuration and focus on penetration testing. ” - From BackTrack project page

Jan 2

Pidgin IM I use this for logging into all my messenger ID’s. Its an easy and convenient messenger tool. It does come with a rich set of plugins to enhance my chatting experience. It has been my favorite for years now. Pidgin was formally know as Gaim Messenger. You can talk to your friends using AIM, ICQ, Jabber/XMPP, MSN Messenger, Yahoo!, Bonjour, Gadu-Gadu, IRC, Novell GroupWise Messenger, QQ, Lotus Sametime, SILC, SIMPLE, MySpaceIM, and Zephyr. Its available as Adium on OS X.

I always wanted to use secure communication channels to interact with my colleagues , clients and also with friends as security has been the major concern. I needed something which provides me the private channel to communicate. There are many companies like yahoo etc providing enterprise communication messengers. But all I needed was a free solution to this along with my existing messenger.

I really did find one on the net.  Off-the-Record (OTR) Messaging. Which allows you to have encrypted private conversations with your favorite messengers.

These are the main features provided by OTR :

  • Encryption
  • Authentication
  • Deniability
  • Perfect forward secrecy

Implemented and tested on Pidgin, Trillion (Windows), Adium (OS X), mICQ for command line and many more. Its released under GPL.
Installing this plugin on Ubuntu is very easy :

sudo aptitude install pidgin-otr

Once the installation is over, just enable this plug-in from your pidgin’s plug-in list. You will find OTR on your IM windows once this is done. Usage is very simple, click on OTR button to start the private conversation. It requests the key from your buddy. Once you confirm that the key received by you is trusted, you can continue enjoying the off-the-record messaging. You can also secure it further by adding a pass phrase for the authentication.

You might be wondering, why I choose this when there is an another plugin for pdigin is available for encryption isn’t it?. pidgin-encryption does not provide deniability or perfect forward secrecy features.

This is from the FAQ on OTR website to provide you more details:

“If an attacker or a virus gets access to your machine, all of your past pidgin-encryption conversations are retroactively compromised. Further, since all of the messages are digitally signed, there is difficult-to-deny proof that you said what you did: not what we want for a supposedly private conversation! ”

IM securely with off-the-record. Ping me on fizworks (AIM id) if you want give it a try. I would be glad to help you.

Happy Private Messaging!

Close
E-mail It