SiD3WiNDR Gears  Hacker Emblem  
RealVNC & Security
Date: May 21st, 2006 by SiD3WiNDR
Categories: Security, Software

A few days ago a vulnerability in RealVNC was discovered allowing anyone to take over a desktop without any authentication at all (the client is allowed to select the authentication mechanism, of which one is "none"). Not too smart, but ohwell :s I wonder how much this effects the other VNC derivatives, since I thought their code was based off the "original" VNC. However, if they’re fixed, why didn’t they alert the RealVNC maintainers?

In the meanwhile I saw a basic scanner and a refined multithreaded scanner appear on Bugtraq . Fun for the kiddies! I don’t really do any firewall logging at the moment, but as noted in Filbert’s blog, scanning has certainly taken a steep curve upwards.

Comments Off on RealVNC & Security
Mommy mommy
Date: May 19th, 2006 by SiD3WiNDR
Categories: Fun

I want >this< .

Comments Off on Mommy mommy
Eurosong
Date: May 19th, 2006 by SiD3WiNDR
Categories: Fun, Uncategorized

As usual, Belgium already lost in Eurovision Song contest preselections. Good job, Kate! (Although I must say I can’t understand how Turkey was any better).I only saw the Turkey blonde, the Shakira imitation after that, and Lordi (thought those were pretty good, although I wouldn’t call it "hard" rock). But ohwell. 😛

 That’s what you get for forgetting your kniezwengel, Kate!

Comments Off on Eurosong
Areca and SLES9
Date: May 17th, 2006 by SiD3WiNDR
Categories: Computing, Linux, Stupid

Been trying to fix up an installation for the last few days now. SLES9 on a box with an 8 port Areca SATA controller in it, and SUSE Linux Enterprise Server 9 as OS (will run Oracle). Areca supplies a driver floppy to use with the installer; all very nice. However, the SuSE installer does not copy the driver module into the initrd (even though it is regenerated on install, and even set to be loaded on boot in the config!), so after the installer reboots you get a kernel panic saying it can’t find the root fs. Which is correct, since the module isn’t loaded. Areca has some details in their README about "do this when the SuSE installer reaches 70%: press Ctrl-Alt-F2 and …", but the SuSE installer reboots automatically without question or warning, and by the time I could follow their instructions (some files needed to be on the disk first) I couldn’t fix it up before the thing rebooted by itself. PITA. Rescue mode gives kernel oops when I try to mount it the XFS filesystem on it. Debian Install CD finds the controller, but I cannot chroot into it (to run LILO) since the system is 64bit and the Debian one is 32-bit. Argh.

I love Debian, and the Areca ISO from tienhuis.nl … 

Post a comment (2 comments)
Akismet rocks
Date: May 17th, 2006 by SiD3WiNDR
Categories: Interweb, Uncategorized

Seems the comment/guestbook spammers have rediscovered my blog since I upgraded to WordPress (they thought I was interesting enough to create a custom formfiller when this blog was still running self-written software, but now, they can use their standard wordpress bombers, yippie). Fortunately, I was never bothered even with a request to moderate, thanks to Akismet. Recommended!

Comments Off on Akismet rocks
IRCnet exploit?!
Date: May 14th, 2006 by SiD3WiNDR
Categories: Fun, IRC

[13|20:49:16] <@redLED> exit
[13|20:49:46] [-] [x] Netsplit *.club-internet.fr <-> *.se quits: @tmind
[13|20:51:25] <@pepijn> new hole in the ircd code ?   when typing ‘e x i t’ the net splits ?
[13|20:51:39] <@pepijn> terrible thing, let’s get offline
[13|20:53:42] [-] [x] Netsplit over, joins: @tmind
[13|23:27:19] <@SiD3WiNDR> :))
[13|23:27:26] <@SiD3WiNDR> exit !
[13|23:34:23] [-] [x] Netsplit *.pl <-> *.at quits: @tmind
[13|23:34:38] <@frankske> it worked, a tad slow
[13|23:34:55]  ! SiD3WiNDR grins
 

Comments Off on IRCnet exploit?!
Artificial Dumbness
Date: May 13th, 2006 by SiD3WiNDR
Categories: Fun, IRC

[13|14:28:26] [-] [:] terorist [michael@users.daforest.org] has joined #eggies
[13|14:29:08] < terorist> hello
[13|14:29:11] < terorist> anyone here..?
[13|14:33:05]  ! ObiWan is back
[13|14:33:07] < ObiWan> I can’t reach this itch :O
[13|14:33:45] < terorist> ObiWan can you help me with something ?
[13|14:33:49] < ObiWan> certainly
[13|14:33:51] < ObiWan> Let’s make biscuits… LET’S MAKE BISCUITS.
[13|14:34:21] < terorist> i loaded country tcl script
[13|14:34:22] < terorist> for eggdrops
[13|14:34:43] < terorist> but i don’t know how to add that .sql file to my MySQL database
[13|15:08:03] < ObiWan> fantastic
[13|15:08:54] < terorist> thanks for help
[13|15:08:54] < terorist> 🙂
[13|15:08:57] < ObiWan> 😉
[13|15:09:07] < terorist> i`ll fix it later when i`ll talk with my admin
[13|15:09:16] < terorist> i cannot make a sql database don’t have rights:)
[13|15:36:03] < ObiWan> KazOO.
[13|15:41:14]  ! terorist is away (out)
[13|15:41:17] < ObiWan> Talk to you later.
[13|16:42:03] < ObiWan> bleh.

ObiWan is my fully automatic bot, running the bMotion script plus some own coding. It’s fun when "she" gives support all on her own 🙂

Comments Off on Artificial Dumbness
Magic moment
Date: May 3rd, 2006 by SiD3WiNDR
Categories: Fun

tom@tequila:~$ date +"%H:%M:%S %d/%m/%y"
01:02:03 04/05/06

Whee. or so. 

Comments Off on Magic moment
So this is why we buy Dell…
Date: May 3rd, 2006 by SiD3WiNDR
Categories: Hardware, Work

A client at work needed a super powerful machine for demo purposes. Dell couldn’t really give it to us (especially since we needed in an as-small-as-possible case), so we decided to build it ourselves. This is probably one of the most powerful machines out there (without overclocking, just standard hardware):

  •  AMD Athlon FX-60 (Dual core, 64-bit, 2600MHz)
  • 2x 2x1GB (Dual Channel Set) OCZ DDR400 with golden heatspreaders
  • Geforce 7900GTX with 512MB Video RAM
  • Gigabyte something-something mainboard with nForce 430 chipset
  • 2x Western Digital Raptor X 150GB in RAID0

The system is running a 32-bit Windows however. 3DMark hovered around the 10300 points mark, HD Tach reported 120MB/sec average throughput, 6% CPU utilization for the disks and I/O bursts of up to 215MB/sec. Not bad, eh? All this will be placed in a Silverstone SG01 case, but it hasn’t arrived yet – we needed to test the hard- and software beforehand, so it’s all layed out on a table near my desk… Surely has attracted a lot of visitors, and everone passing by needed to know some more. Geeks and hardware…

But not all is that well.. The RAID controller drivers need to be on a floppy for the XP setup to recognize the controller… but

  • We didn’t have a working floppy drive. I dug up 2 old ones from the serverroom storage but neither did the job.
  • Gigabyte packed the wrong drivers on their CD for the RAID controller. So we needed to get them from the ‘net.
  • Once the "Windows kernel" part of the setup is loaded, Windows no longer sees a USB floppy drive anymore, so can’t get the drivers
  • Slipstreaming the NVidia drivers into the XP setup CD is quite difficult, in fact we wasted 7 CD’s on it and did not completely succeed.

I went home in the evening and we installed from my One And Only Working Floppy Drive+Cable Combination(tm). A few bluescreens later (Thank you, BIOS-graphics-booster overclock-thingamajig option set to Enabled) we got the thing working… finally. Caused a LOT of frustration.

We also bought an Adaptec SATA RAID controller for it, which plugged into the PCI bus. PCI bus means it’ll be capped to 133MB/sec (or thereabouts) with no way of bursting over it… Which was indeed the case. Same average throughput, but no bursting at all. Pity there wasn’t a PCI-X or PCIe x8 slot on the board (MicroATX..) or an Areca controller would really have kicked some major ass. I must note slipstreaming the Adaptec drivers into the XP cd went without ANY problem, and XP installed first time. Thumbs up Adaptec! 

Comments Off on So this is why we buy Dell…
DNS.be on a roll
Date: May 1st, 2006 by SiD3WiNDR
Categories: Interweb, Networking, Stupid

It seems DNS.be has made a bit of a booboo… They have billed all agents for march (instead of april), resulting in negative credit balances (somehow march is a month with way more registrations than april) for many agents. Affected are at least Openminds , Priorweb and Stone IS – probably more. If your .be registrations don’t work today and/or tomorrow, this is why.

 Of course, today being a public holiday doesn’t help things, as there will probably be noone there to fix the mistake before tomorrow. Unfortunately, business on the internet goes on, 24/7, and people will expect domain names to be registered…

Comments Off on DNS.be on a roll
Weblog Calendar
March 2025
M T W T F S S
« Aug    
 12
3456789
10111213141516
17181920212223
24252627282930
31  
Sales
Pages
Archives
Categories
Links
Meta
© 2002-2025, SiD3WiNDR - Proudly powered by WordPress - XHTML Compliant - RSS (Entries) - RSS (Comments)