donderdag 15 mei 2008

Kampioen EK2008: Rusland

Today is speculation day :D

Zwitserland - Tsjechie 2 - 1
Roemenie - Frankrijk 0 - 2
Portugal - Turkije 1 - 1
Nederland - Italie 3 - 2
Tsjechie - Portugal 2 - 1
Italie - Roemenie 2 - 1
Zwitserland - Turkije 3 - 2
Nederland - Frankrijk 0 - 2
Zwitserland - Portugal 1 - 2
Nederland - Roemenie 2 - 1
Turkije - Tsjechie 0 - 0
Frankrijk - Italie 1 - 2

Oostenrijk - Kroatie 1 - 1
Spanje - Rusland 1 - 2
Duitsland - Polen 1 - 0
Griekenland - Zweden 1 - 3
Kroatie - Duitsland 1 - 2
Zweden - Spanje 0 - 2
Oostenrijk - Polen 3 - 1
Griekenland - Rusland 1 - 2
Polen - Kroatie 1 - 1
Griekenland - Spanje 0 - 2
Oostenrijk - Duitsland 3 - 4
Rusland - Zweden 2 - 1


Zwitserland - Oostenrijk 3 - 1
Duitsland - Tsjechie 2 - 0

Frankrijk - Spanje 3 - 1
Rusland - Italie 2 - 1


Zwitserland - Duitsland 3 - 1
Spanje - Rusland 0 - 1

Zwitserland - Rusland 2 - 3

Kampioen EK2008: Rusland

Speculation SSL Ubuntu & Thawte

Hmm, considering the fact that Mark Schuttleworth is the founder of both Thawte and Ubuntu...

And Ubuntu is Debian based

And Debian's SSL suffers from a giant randomness issue

And www.thawte.com runs on Ubuntu

And Ubuntu is a large Certificate Authority

Does that insinuate all Thawte certificates are ready for a review? :P

A great day for scripters!

Last months have been good for the security market. SPAM rose [it has been since 30 years but who is counting?], BOTNETS grew, CC snooping went bigger and the list was nicely added with two, well, astounding issues within the last 24 hours.

First we have a crypto nub who decides to remove basically all randomness [the seed used for PRNG (Pseudo Random Number Generator) used when creating SSL keys] from SSL in Debian. That did not happen last week, nor last month, not even last year, but on Tue May 2 16:34:53 2006 UTC. For reasons that have been mentioned over and over again, not security people should not, repeat NOT fiddle with security issues. Specially not packagers who just want things to install cleanly and silently. That bad.

In this case an unnamed individual did not like what he saw as uninitialized data, he removed one line:
MD_Update(&m,buf,j);
That was enough to make ALL SLL certificates [and thus too the SSH keys that are based on SSL] generated on these systems a randomness that is limited to 32.768 options [all possible PID's on UNIX... That sounds a lot to humans, to computers that is nothing and to crypto it is fcuk all. It is so small that all possible keys have been generated in about two hours for the 1024-bit DSA and 2048-bit RSA keys for x86. HD Moore used 31 Xeon cores clocked at 2.33Ghz to do this.

Luckily for the researchers, HD Moore of metasploit moved quickly and created the OpenSSL Debian toolset WITHIN 24 HOURS[!!!] to toy with the issue.

Thank you. Scripters of the world: unite and have a ball!

To bring the issues a little closer to your mom & pop [who hardly depend on SSH], Aviv Raff decided to post a real nice and nifty 0-day for IE. Scripters of the world, you know what to do.

This is a particular nasty one, not just because it affects about 60% of all browsers in the world but also because our friends in Redmond just pushed out their monthly 'updates' so it will take at least another month before a patch is available, let alone the time it takes for mom & pop to actually update their IE.

So life is good, money there is to be made for us security people. Or is it?

woensdag 14 mei 2008

Beta testers wanted for FERRET

Last October David Maynor went to the the NASCAR truck series. Of course he brought his iPhone with and was shocked to see so many open WiFi networks:


So what do you do when you made the headlines with your Ferret & Hamster releases in August 2007? You port Ferret [hamster too? Maybe? Please?] to the iPhone.

Now they are looking for beta testers with open iPhones. Feel up to the challenge?

Check here!

Happy Birthday Ha'Aretz!



Never will I forget how we met, how the initial moments where, how deeply I was moved by you and how a profound impact you made on me and my live.

It was a coincidence, no really, it was. It was not as if my live was aimed at that particular event, not that was I was brought up to come to you, not that I had any known desire to experience you. It was purely coincidental that we met. Or was it? Was it not so that in my family your name was uttered in soft words of the highest respect? Was it not so that the 'coded' words my grant parents & parents whispered to each other, hidden for us kids, when saying goodby, where words that ended with something like '...Jerusalem'?

It does not matter. Fact is, that on December the 27th, in the year 1989 you welcomed me. Fact is that ever since that day there is no place on earth that has touched me deeper, felt better, shines brighter then you.

Happy birthday, state of Israel. May you and your inhabitants live, prosper & find the peace and integrity you deserve.

vrijdag 9 mei 2008

Maths is the music of reason




musician wakes from a terrible nightmare. In his dream he finds himself in a society where music education has been made mandatory. “We are helping our students become more competitive in an increasingly sound-filled world.” Educators, school systems, and the state are put in charge of this vital project. Studies are commissioned, committees are formed, and
decisions are made— all without the advice or participation of a single working musician or composer.
Since musicians are known to set down their ideas in the form of sheet music, these curious black dots and lines must constitute the “language of music.” It is imperative that students become fluent in this language if they are to attain any degree of musical competence; indeed, it
would be ludicrous to expect a child to sing a song or play an instrument without having a thorough grounding in music notation and theory. Playing and listening to music, let alone composing an original piece, are considered very advanced topics and are generally put off until college, and more often graduate school.

As for the primary and secondary schools, their mission is to train students to use this language— to jiggle symbols around according to a fixed set of rules: “Music class is where we take out our staff paper, our teacher puts some notes on the board, and we copy them or transpose them into a different key. We have to make sure to get the clefs and key signatures right, and our teacher is very picky about making sure we fill in our quarter-notes completely. One time we had a chromatic scale problem and I did it right, but the teacher gave me no credit because I had the stems pointing the wrong way.”

In their wisdom, educators soon realize that even very young children can be given this kind of musical instruction. In fact it is considered quite shameful if one’s third-grader hasn’t completely memorized his circle of fifths. “I’ll have to get my son a music tutor. He simply won’t apply himself to his music homework. He says it’s boring. He just sits there staring out the window, humming tunes to himself and making up silly songs.”

In the higher grades the pressure is really on. After all, the students must be prepared for the standardized tests and college admissions exams. Students must take courses in Scales and Modes, Meter, Harmony, and Counterpoint. “It’s a lot for them to learn, but later in college when they finally get to hear all this stuff, they’ll really appreciate all the work they did in high school.” Of course, not many students actually go on to concentrate in music, so only a few will ever get to hear the sounds that the black dots represent. Nevertheless, it is important that every member of society be able to recognize a modulation or a fugal passage, regardless of the fact that they will never hear one. “To tell you the truth, most students just aren’t very good at music.

They are bored in class, their skills are terrible, and their homework is barely legible. Most of them couldn’t care less about how important music is in today’s world; they just want to take the minimum number of music courses and be done with it. I guess there are just music people and non-music people. I had this one kid, though, man was she sensational! Her sheets were impeccable— every note in the right place, perfect calligraphy, sharps, flats, just beautiful. She’s going to make one hell of a musician someday.”


Waking up in a cold sweat, the musician realizes, gratefully, that it was all just
a crazy dream. “Of course!” he reassures himself, “No society would ever reduce such a beautiful and meaningful art form to something so mindless and trivial; no culture could be so cruel to its children as to deprive them of such a natural, satisfying means of human expression. How
absurd!”

Meanwhile, on the other side of town, a painter has just awakened from a similar
nightmare…

***********
And all this leads us into a wonderful written essay on how we are messing up the love and purity of math for our kids. Written by Paul Lockhart [and NO, that is NOT the space invader Paul Lockhart], an assistant professor at Brown Brown who left to teach a mathematician's point of view to very young children. In his own words, "I want them to understand that there is a playground in their minds and that that is where mathematics happens. So far I have met with tremendous enthusiasm among the parents and kids, less so among the mid-level administrators." Is that so :P

BTW If anybody speaks to Paul, can you please ask him to start blogging or publishing more in any other way shape or form?

An eye opener and good read to boot. Enjoy it!

donderdag 8 mei 2008

HELP: Linkedin removed my profile! [well, not mine, really]

What gives? A colleague of mine ran into my office and asked me to check Linkedin to see if I could find his profile. We are connected so, sure, I checked my connections. Since I am known to make a spelling error or two, specially with names, I was not convinced that something was wrong when I did not find him in my connections list.



So I used Google, who loves LinkedIn profiles, to see if I got his name correct: I did.







As a matter of fact, Google nicely cached his profile page on LinkedIn. CCIE # et all. So for sure he nor me is not nuts and he did have a LinkedIn profile and we are connected. Something must be wrong with my seach on LinkedIn, right?

Let's copy & paste that name, and CCIE serial, and repeat the search.


No matter what we tried, all we found was this "Dell sales dude" but never the hardcore network'er that stood behind me, I had linked to, and Google had cached.






So I tried some Google-fu to see if more people had their profile removed by LinkedIn, but all I found was people who asked for them selfs to be removed and happy faces that LinkedIn finally let's you remove links to people you once linked to. Silently, to make sure you piss nobody off :P

This is an interesting issue however.

I always check peoples LinkedIn profiles when I do job interviews or have business meetings planned with people I do not know. It often helps to make sure you use the correct wording [or metaphor's when clueless] when you know a little bit about their [public] background. I know many future employers do the same [Hi guys! I see you browse my profile before you call :D].

But what happens if you can't find that potential new employee on LinkedIn and you know nothing about her|him? Will it influence your initial selection on who to talk to and who not? I am sure it does for lots of companies. Never mind how smart that is, but it is done.

So what do you do when you drop of the most valuable professional showroom of the net? How does one prevent that from happening and having a too big an impact on your money making abilities?

woensdag 7 mei 2008

Imagion being Vodafony and bending over Apple...

What do you get after you've been initially big mouthing Steve at the launch of the iPhone, claiming you know it all for you have been in the GSM cloud business so long?

You get the left overs, the 2G countries, like: Australia, the Czech Republic, Egypt, Greece, Italy, India, Portugal, New Zealand, South Africa and Turkey. And those you get not even exclusively, muwaa!!!

Being able to offload 2G handsets into secondary markets will be very useful for Apple if they do launch a 3G version of the iPhone as generally expected.

Now, Arun Sarin has been labeled strange and basically clueless before. Being out of touch with reality really scares the shiit out of people working in his company but who know, now that he found the way in to Apple's $ stream, maybe the good people working at Vodafone will get a break and develop something nice. Maybe. Then again it is more likely the big shot sees no need for cool iPhone apps and will be happy with the pennies and cents he is allowed to keep for the devices he sells, business like usual.

dinsdag 6 mei 2008

opendns resolve issue? no, it's squid.

For reasons only known to my shrink, I wanted Firefox to use a tunnel from a Windows XP machine to a OpenSuse linux host resolving via OpenDNS and squid to make things complete.

Funny stuff, that I do just because I can.

It is all really easy to get it up and running, nice to have your own tools on a sticky and funnel your wild browsing behavior encrypted to a known end point where you set it free into the world wild web. But trust is good, a functional test is better, but checking is better, as my audit teacher taught me. So the first thing I did was monitoring for data leakage on my local [windows host's] interface: nada. Schade.

Then I went to the remote's host interface to see what showed there: horor, nice! What I saw was part of the resolve queries going to my old and reliable [and we all hate reliable, right?] colocate DNS and part of the queries to OpenDNS. Hmm, makes you wonder. So checking the resolve file showed that I had correctly added the two opendns entries, and correctly removed the entries passed to the file via DHCP. I flushed the DNS cache, still no joy. Hmm, makes you wonder. Turned out it was squid not nicely obeying the new entries in the resolver file. Naughty squid!

My setup in more detail:

Firefox [2.0.14 on winXP SP2] well, actually it is FireFoxPortable on a 16Gb Flash Voyager.
putty [version 0.60] for a tunnel to an external host, listening on 127.0.0.1:8888, talking to 127.0.0.1:3128 where squid [Version 2.5.STABLE10] on Suse [2.6.13-15.18 i386]

I have added a boolean option into the URL "about:config" page in Firefox named "network.proxy.socks_remote_dns" and set it to true.

The resolver file on the remote host contains:
cat /etc/resolve
### BEGIN INFO

#
# Modified_by: dhcpcd
# Backup: /etc/resolv.conf.saved.by.dhcpcd.eth0

# Process: dhcpcd
# Process_id: 4326
# Script: /sbin/modify_resolvconf

# Saveto:
# Info: This is a temporary resolv.conf created by service dhcpcd.

# The previous file has been saved and will be restored later.
# # If you don't like your resolv.conf to be changed, you
# can set MODIFY_{RESOLV,NAMED}_CONF_DYNAMICALLY=no. This # variables are placed in /etc/sysconfig/network/config.
# # You can also configure service dhcpcd not to modify it.
# # If you don't like dhcpcd to change your nameserver # settings
# then either set DHCLIENT_MODIFY_RESOLV_CONF=no
# in /etc/sysconfig/network/dhcp, or
# set MODIFY_RESOLV_CONF_DYNAMICALLY=no in
# /etc/sysconfig/network/config or (manually) use dhcpcd

# with -R. If you only want to keep your searchlist, set
# DHCLIENT_KEEP_SEARCHLIST=yes in /etc/sysconfig/network/dhcp or

# (manually) use the -K option.
# ### END INFO
nameserver 208.67.222.222

nameserver 208.67.220.220

And yes, I have set both options to 'no'

To clear the dns 'cache' I used:
/etc/init.d/nscd restart

What puzzled me is the following output when I use my local browser [that tunnels it's requests to the remote host] and monitor the DNS queries on the remote host's interface [the remote host being my-host.xxx, my provider's dns server being lookup2.colo.xxx]:

tcpdump -p -i eth0 port 53

15:52:19.525862 IP my-host.xxx.33278 > lookup2.colo.xxx.domain: 28225+ A? mokumvonamsterdam.blogspot.com. (48)
15:52:19.526356 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 28417+ PTR? 188.250.202.213.in-addr.arpa. (46)
15:52:19.542138 IP lookup2.colo.xxx.domain > my-host.xxx.33278: 28225 2/7/7[|domain]
15:52:19.739094 IP resolver1.opendns.com.domain > my-host.xxx.39176: 28417 1/0/0 (75)
15:52:19.739459 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 17259+ PTR? 81.240.202.213.in-addr.arpa. (45)
15:52:19.949697 IP resolver1.opendns.com.domain > my-host.xxx.39176: 17259 1/0/0 (67)
15:52:19.950334 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 48705+ PTR? 222.222.67.208.in-addr.arpa. (45)
15:52:19.973525 IP resolver1.opendns.com.domain > my-host.xxx.39176: 48705 1/0/0 (80)
15:52:20.698247 IP my-host.xxx.33278 > lookup2.colo.xxx.domain: 63234+ A? www.blogger.com. (33)
15:52:21.028751 IP lookup2.colo.xxx.domain > my-host.xxx.33278: 63234 2/7/7[|domain]
15:52:23.133656 IP my-host.xxx.33278 > lookup2.colo.xxx.domain: 57393+ A? www.youtube.com. (33)
15:52:23.134089 IP lookup2.colo.xxx.domain > my-host.xxx.33278: 57393 3/3/3 A youtube.com,[|domain]
15:52:23.134563 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 51875+ PTR? 253.153.65.208.in-addr.arpa. (45)
15:52:23.157911 IP resolver1.opendns.com.domain > my-host.xxx.39176: 51875 1/0/0 (70)
15:52:24.315674 IP my-host.xxx.33278 > lookup2.colo.xxx.domain: 48709+ A? twitter.com. (29)
15:52:24.502987 IP lookup2.colo.xxx.domain > my-host.xxx.33278: 48709 1/5/5 A[|domain]
15:52:25.981131 IP my-host.xxx.33278 > lookup2.colo.xxx.domain: 25981+ A? www.google.com. (32)
15:52:25.981560 IP lookup2.colo.xxx.domain > my-host.xxx.33278: 25981 5/7/7 CNAME www.l.google.com.,[|domain]
15:52:28.057148 IP my-host.xxx.33278 > lookup2.colo.xxx.domain: 20445+ A? www.google-analytics.com. (42)
15:52:28.057758 IP lookup2.colo.xxx.domain > my-host.xxx.33278: 20445 5/7/7 CNAME[|domain]
15:52:29.280144 IP my-host.xxx.33278 > lookup2.colo.xxx.domain: 59181+ A? toolbarqueries.google.com. (43)
15:52:29.408904 IP lookup2.colo.xxx.domain > my-host.xxx.33278: 59181 5/7/7[|domain]

Turned out that I had to restart squid [/etc/init.d/squid restart] to make the resolving act nicely and forward _all_ lookups to opendns.com

16:12:04.543848 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 8407+ A? mokumvonamsterdam.blogspot.com. (48)
16:12:04.567414 IP resolver1.opendns.com.domain > my-host.xxx.39176: 8407 2/0/0[|domain]
16:12:05.282740 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 58294+ A? www.blogger.com. (33)
16:12:05.306651 IP resolver1.opendns.com.domain > my-host.xxx.39176: 58294 2/0/0 CNAME[|domain]
16:12:08.624282 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 59333+ A? central.ujcfedweb.org. (39)
16:12:08.843032 IP resolver1.opendns.com.domain > my-host.xxx.39176: 59333 2/0/0 CNAME[|domain]
16:12:10.189203 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 58807+ A? twitter.com. (29)
16:12:10.212537 IP resolver1.opendns.com.domain > my-host.xxx.39176: 58807 1/0/0 A 128.121.146.100 (45)
16:12:10.213033 IP my-host.xxx.39177 > resolver1.opendns.com.domain: 18146+ PTR? 100.146.121.128.in-addr.arpa. (46)
16:12:10.236480 IP resolver1.opendns.com.domain > my-host.xxx.39177: 18146 NXDomain 0/0/0 (46)
16:12:12.703541 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 11197+ A? www.google.com. (32)
16:12:12.727000 IP resolver1.opendns.com.domain > my-host.xxx.39176: 11197 3/0/0 CNAME[|domain]
16:12:13.629888 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 24465+ A? www.justsayhi.com. (35)
16:12:13.738147 IP resolver1.opendns.com.domain > my-host.xxx.39176: 24465 1/0/0 A 4.78.241.72 (51)
16:12:13.738702 IP my-host.xxx.39177 > resolver1.opendns.com.domain: 42572+ PTR? 72.241.78.4.in-addr.arpa. (42)
16:12:14.273047 IP resolver1.opendns.com.domain > my-host.xxx.39177: 42572 NXDomain 1/0/0 CNAME[|domain]
16:12:15.706642 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 54172+ A? www.google-analytics.com. (42)
16:12:15.730274 IP resolver1.opendns.com.domain > my-host.xxx.39176: 54172 5/0/0 CNAME[|domain]
16:12:18.673145 IP my-host.xxx.39176 > resolver1.opendns.com.domain: 40629+ A? toolbarqueries.google.com. (43)
16:12:18.696662 IP resolver1.opendns.com.domain > my-host.xxx.39176: 40629 5/0/0[|domain]


Hope this helps someone trying to use opendns.com too.

vrijdag 2 mei 2008

Google ad's my Inbox(1) !!!


Here is a nice variation on misleading google ad's: claiming your Inbox has (1) unread email, smart move [thanks to Twitter, Twinkle & Jeroen Mirck for making this possible :P ].


I liked the people who used the ASCII adds last year, I do, I am inn the market for funny ads that make me wonder, think or just laugh.
Unfortunatly, ASCII art ad's are over since Google altered the 'puncuation' rule.

donderdag 1 mei 2008

Maltego v2 - is ready!


Oh boy I am so exited!

Get it at: http://www.paterva.com/maltego/

All,

After 15 months of work Maltego version 2.0 is ready. It's been a long and interesting road. Many of you have seen the product grow from beta 1 to beta 2, then KZ3 and JS1. I've shared with you the challenges, the ups and downs. Finally, today, I am happy to release version 2.0.
Version 2.0 is commercial and I feel it's got the right be commercial because it's by far the coolest and most useful application I've ever used (OK so perhaps I am just slightly biased). As I've mentioned before - it goes live to this list first. Everything is set up, but not linked to the main site. I will link it on Monday.

Also - as promised - a list of new features/improvements:

* Load/Save of entire graphs means you can always go back to your investigation.
* Printing of graphs (over multiple pages)
* Export of entities (CSV format) makes it easy to import Maltego data into other databases.
* Commercial grade layout library:
o The layout and navigation have been optimized for speed and usability.
o Four layout types to rearrange data the way YOU want it.
o Two view types for finding relevant info on large graphs.
* More entities and 20 brand new transforms for even deeper searches and more information.
* Search/Find (on entity value, detailed info and additional fields) helps you to get to key nodes quicker.
* Multiple open graphs on different tabs for easy switching between graphs.
* Dedicated clear-all, zoom buttons for notebook users.
* Hollywood quality look & feel will impress your friends and your boss.
* Integrated help on transforms and entities to increase your learning curve.
* Complete user guide ensures you are never lost.
* Prepopulated and preconfigured transforms and transform sets saves you time.
* Population of API key integrated with license key so it’s never lost.
* Platform independent installer means you can install it anywhere.

If you want to see what it looks like before making a commitment you should look at the user guide and the screen shots. You should also read the system requirements.

The documentation can be found at http://ctas.paterva.com/wiki

Enjoy responsibly,
Roelof.

woensdag 30 april 2008

Avoiding speed traps, different

57 year old dude tries to avoid a speedtrap by applying the front break and sliding past below the radar:



Did not really work well. Broke his arm _and_ got a ticket.

zaterdag 26 april 2008

Locks, SKG, the chalange

Whenever I move in to a new appartement, a new office building or take on the responsibility of other property that is secured by a cylinder lock, I exchange it.

The old cylinder and all it's associated keys will be documented and stored for later retrieval.

The new cylinder will be bought by me, at a store I trust and with a security certificate I like and I pay attention that _nothing_ that can identify me or my location gets associated with the certificate for I would not like to have to worry about the where abouts of that data since it is not under my control [the certificate can be used to remake a key without having a copy of the key].

So I pay by cash and have a second lock smith do the installation.

The appartment I moved in recently is a newly build complex. About a 1.000 appartments have been build by 45 different subcontracters who dig holes, lay pipes, pull wires, connect walls, paint doors and insert locks. For whatever it is worth: I do not trust them. The change that one of the workers copies the cuts of my particular key is just something that makes me feel uncomfortable.

Personally I know too little about the inner workings of locks to be able make a valid judgement about the grade of the lock, so I will buy only stff that does comply with the toughest international standards, including ISO 9001/2000, UL, CEN, VDS, SKG, CPC and A2P. Or when in Holland, the SKG [Stichting Kwaliteit Gevelbouw].

It is amazing to see that the price difference between a SKG ** and *** is rather low in comparison to the added features. One of the features I find a must have is the bump key proofing of locks. But all of this is just to prevent the damage free opening of the door.

Other measures need to be taken to prevent the more common 'crowbar style' and the 'Bulgarian' method [drilling]. A good resource of more information on the topic is The Open Organisation Of Lockpickers' that is credited with spreading the word on the issue in Holland, but even more important the concept behind high security lock design by Ross Kinard.

vrijdag 25 april 2008

Googlology!

Never mind those old and dusty religions, for get the olt skool printed stuff, do not bother with the 10 rules, forget about diet stuff, reincarnation is of the past, after life is obsolete.

What rules now is Googlology. It's religion on steroids. No need for G*d in heaven, no need for spirits in the sky. Googlology designs and runs it's own heaven, and it's name is 'The Cloud'

The cloud will take care of your data, no matter where you need it, it will be there. The cloud will provide your services with more computing power then it needs, and the some. The cloud will harbour your applications, your email, your videostream, your rants, your pictures, your secrets and your dates, your world, your drawings, your finances, your money, and a whole lot more.

And I should know, since I drink all the Google Gulp from a hose.

But what if the cloud, errr, sort of not does what the EULA sort of makes you believe? What if the lawyer@TheCould p0wnzers you? And your data? What if, insert-your-personaly-favorite-upper-being-here, strikes back and lets some unknown entity take control over, well, you, basically?

How does one secure the absolute power of the cloud? There are some very smart people talking about it but lots of discussion is still about the definition, much less about the consequences, let alone what it actually means or how to do it.

Do you want to be the one who turns of the light now that everybody has left the old arena, or will you participate in shaping the future?

dinsdag 22 april 2008

Replace your MAC harddisk, easy


I should do stuff more often, at least it makes far hotter stuff come out.

Couple of days ago I decided that both MAC laptops in the house needed more storage. The G4 PowerBook and the MacBook. So I ordered a Western Digital Scorpio 250GB 5400RPM and a Western Digital Scorpio 320GB 5400RPM. The replacement of the MacBook one can do with a sharp kitchen knife, no problem. Just remove the batery [do not bother shutting the OS down, it's as stable as my weight] and take a sharp kitchen knife [I used the new Global one I gave my wife a couple of days ago]. Unscrew 3 little screws, pull out the harddisk, take a strong plyer, remove the 4 screws, take the plastic thingy, wrap it on the new disk, sort of re attach the 4 screws, stick the thing back in. Ram the old battery in and of you go [never mind about the 3 little screws and the metal strip, all just surplus weight].

Reinstall and do not mind about the updates that want you to reboot your DVD version of the OS 4 times!

Now the Powerbook, that is another story. About 23 philips screws [tiny fuckers!] and then 2 torx 6, that is SIX, not 8, but 6, the smallest possible tool made only in Switzerland and it will set you back about the same amount of euroos as the 320Gb disk.

Then you get to pull of two, well, 'connectors' that are actually used open ended flatcables: class construction. Putting the whole thing back is a joy. Takes the precision of a live-bomb-defuser, nice enginering.

Installing the OS of course requieres the PPC version. Inserting the iMac Intel version yields a nice panic message. Never mind about the I-do-not-know-how-many updates and reboots [even for the so called 3.1.x SAFARY update one gets a reboot!], for they slow down the secure OS X anyway.

Right after finishing something flashy caught my eye: the MHZ2 CJ.

A 2.5 inch Serial-ATA Revision 2.6 (Gen1i and Gen2i) hard disk with embedded AES 256-bit hardware-based encryption, high-speed rotational speed of 7200rpm, it supports SATA 3.0Gbit/s and the capacities go up to 320GB with a 16MB buffer... How is that for cool?

You know what that means as soon as you see it: dumping the current disk for no reason on ebay, including all the private data it has accumelated in a months time and over pay for the new disk since it is new and hot.

vrijdag 18 april 2008

Searching & Finding, part II

So there is Maltego, the coolest tool for finding information and there are machines that find lots of data. Of course Google uses some very smart alogrithims and Udi Manber really knows what he's talking about. On April 16, 2008 he answered the question "When I come to a Google in the future the context of my social network could be folded into the search?" with "I can imagine if you give us permission to do that, and we find that that’s useful for some queries. The question is, what percentage of queries and what kind of queries? When should you use it and when should you not use it?"

This had me completly baffeld. WHAT? I was saying to myself WHAT IS WRONG WITH THIS DUDE? I mean, after one look at the concept of Maltego I knew that that is the only way forward. Maybe he drank a little too much Google Gulp? Maybe he was trying to hide something since Google does not do pre-annoucements? Or maybe, he'd seen Maltego of Delver too and was just trying to surpress their market value so the goog's could snatch it up for little money in a little time?

"We have no intention of competing with the Googles of the world, because Google is doing a very good job of indexing the Web and bringing you the Wikipedia page of every search query you're looking for," says Liad Agmon, CEO of Delver. But we've been there, seen it, and even do it ourselfs now.

But that does not satisfy anymore. You know the procedure yourself: go to google.com, type a couple of keywords, check the first listing, alter the keywords [order even], check the listing and on and on. Most of the listings you get will be actively manipulated by crooks and link spammers.

So we need something else. As Anand Rajaraman puts it: if you have limited resources, add more data rather than fine-tuning the weights on your fancy machine-learning algorithm. Of course, you have to be judicious in your choice of the data to add to your data set. And this is exactly the point I am trying to drive home. More data sources [and some very decent post processing] enhances the results in amazing ways. [he works on his own SE too, called kosmix].

Some say, it is a terrible idea, like KublaiKhan. "This sort of searching will result in information from 'opposingsides' of controversies or arguments being deprecated, resulting inskewed information being available--because people tend to associatethemselves with other people of the same opinion."He goes on: "This new search engine will be wildly popular amongst thetype of person who enjoys violent flamewars, and will be useless forany person who wishes to consider both sides of a situation beforeforming an opinion... so it's going to be an enormous success and if I had the cash I'd invest in it. :-/"

Personally I would like to quote merreborn in reply to that remark:
"Sorry, I can't friend you, you'll screw up my search results"

Update:
Seems there is much much more going on and wrong between google and social websites...

vrijdag 11 april 2008

Everything you ever wanted to know about the Enigma


As great a machine the Enigma was, it too could not prevent users from messing it up. Examples:

Part of the first class encryption of the Enigma was the possibility for the clerk to make up his own six-letter settings. This let to the Polish cryptanalysts occasionally being able to guess the settings. The military did not allow an obvious setting such as ABC. However, cipher clerks sometimes chose settings like QWE (the first three letters on the keyboard) or names. In the example above, if the first three letters were HIT, the cryptanalysts could guess that KOS and RLB were the ciphers to LER, spelling out HITLER. BER was usually followed by the ciphers of LIN. One particular German code clerk continually used his girlfriend’s name, Cillie, for his messages, and so these easy-to-guess indicators became known as "Cillies."

After the English had boarded the U-110 [thanks Fritz-Julius Lemp for being a pussy!] and got their hands on a working Enigma [with all dials in the correct setting for the whole month], they where able to destroy lots of U boats that where decimating the US-UK ships. Admiral Doenitz just knew something was wrong and made a change by added a thin fourth rotor between the leftmost rotor and the reflecting plate.

Bletchley Park learned of the impending change from decrypts and captured material, but until it was actually implemented there was little they could do to prepare. Fortunately, the Germans made an error. In December 1941, before the change had been made official, a U-boat sent a message using the four-rotor machine. To compound the mistake, the same message was retransmitted using only three rotors. From this seemingly innocuous error, the cryptanalysts at BP determined the wiring of the fourth rotor. :P

In order to set up the U.S. Navy Bombe, cryptanalysts first had to determine a "crib." A crib is the unenciphered text that is assumed, or known, to appear in the message.

Cribs could come through a variety of methods. Some of the best cribs came from errors made by the Germans themselves. On more than one occasion, a German signal clerk sent the same message twice in two different codes. If the code for one was known, it provided a crib for the unknown system.

Another frequent German mistake came in standardized messages. For example, a shore weather station in the Bay of Biscay sent out a message every day at 07:00 which began, "The weather in the Bay of Biscay will be. . . ." Knowing the exact wording of a message made a perfect crib for the Allies, so it became a high priority to intercept the daily message from this weather station.

A final example of a common German error involved the practice of submerged U-boats. When the submarines resurfaced after extended periods of time under water, they requested all the important messages they had missed while below the waves. The transmissions that followed inevitably involved communications previously sent and deciphered. Cryptanalysts merely checked the back files for messages with the same number of letter groups and used them as cribs for the new message. Since the resulting message would be identical to the previous one, it helped reveal the Enigma setting for the current day. With the daily setting, all the current day's messages could be read.

Other cribs came from knowing the current activities of the enemy. If, for example, a battle occurred, it could be assumed that messages following the attack reported on the battle. It was more difficult for the cryptanalysts to build cribs for these types of messages since it involved guesswork.

Because the Enigma rotors moved with each keystroke, a letter typed twice usually enciphered to two different letters. Also, the Enigma could not encrypt a letter to itself. Finally, the Germans indicated a space between words with the letter X and spelled out numbers.

Knowing these details played an important role in ultimately breaking the Enigma's daily settings.

Now why do we see these same weaknesses made over and over again?

Sometime ago there was one for sale too. Damn that would have been the hottest geek present ever. Prices have not been too extreme either...

dinsdag 8 april 2008

Improvised Explosive Device 2.0


As much harm as the improvised explosive devices (IED) do, now it is time for version 2.0

The interactive IED, the IED that will blow up the people of the nationality you want dead, not just a passerby. Till now it has been difficult at times to determine the timing to actually kill the guy you hate the most. Come to the resque:

E-Passports

Already in 2006 it was shown that the then 'new' RFID'ed passports where both hackable, and possed a security threat. Since a couple of weeks the Dutch have entered the arena and are being sold E-Passports too.

You gotta love it when goverment people do security.

Ross Anderson: Security Engineering 2.0

At BlackHat, I had some pretty interesting discussions with FX and others, about how 'olt skool' simply breaking stuff is after you've done your share of pentesting & reverse engineering. How much more interesting it is to _secure_ stuff, one way _and_ the other. Because no matter what you do: things will break.

As a matter of fact, since most of us are working for clients and we sell our services, they too are better of when we do not 'just' display how things break, but how we make things break safely.

In that light, the interview my good friend [and smart B to boot] Craig Balding did with Mr. Ross Anderson about security engineering comes right on time. Enjoy.

PS
It was brought to my attention that Amazon does some weird dating stuff. The book will be Released on April 14th, but they have one in stock now, if you order today you can have it delivered on the 9th of April... how's that for JIT!

zondag 6 april 2008

Burning down the house!


You know, today I bought a lighter, a Varaflame Ronson.
You know the brand?

I think everbodies father had one, so did mine.
I was about 6 or so and he got one. A nice shiny silver one.

I woke up early one day and took it from the living room into my room. We had some sort of 'grass' flooring, typical for hippies at that time [think early 70's]

Somehow I managed to set it alight.

Everybody is a sleep, my 4 year old sister, my parents: everybody in my whole wide world.
The room starts filling up with smoke, heat, flames and a one scared boy: moi.

I used the same trick as I still do:
“Dear Lord, let me survive this now and I know that in the future I will pay back humanity!”
Suddenly I moved to the hallway, my mother always left two glasses of water there for when we would wake up early. I took them and threw them in the fire. My feet and some other stuff took care of the remaining fire.

...

A couple of minutes [or hours?] my parents woke up, smelled the smoke, saw the hole and realized very quickly what had happened and who started it all.

Never mind who stopped it, but they knew all right who started it.

The punishment I got for that was something that... I cherished. I loved it, for I was a live! And so where they. I knew I had something to make up to, but I also knew that there was nothing in the world what could kill me until I was ready.

And today I bumped into one of those lighters. And now I own one.

Getting old and knowing it...


There is moments in live, that somehow your surroundings, tells you more about you then about the actual artefacts that make it up. One of those moments just happened to me.

It was a fleemarket, like you see many of them, when you are into fleemarkets. Big, cold, and stuffed with... stuff. I have been to a my fare share of those. Sometimes by accident, sometimes because someone tells you there is something special to be had, sometimes with new [girl-]friends who take you places you do normally not go to.





This visit was inspired by new friends.

It is a big ass flee market, with over 3.000 parking spots, with admission fees, with people rubber stamping each other, with rules and regulations: the works.

Anyway, people try to sell all kinds of stuff, old & fake, polished & rotten. Basically whatever was unwanted at one point of it's existence.




So I am surrounded by stuff and suddenly it strikes me: lots of it might be old,_now_, some of it broken _new_ and some of it unwanted _now_ by OMG*d: this is stuff that I saw enriching the world... when I was growing up!



The stuff that once you thought "WTF?" about and later made it, the things with features that you young people that for granted now but where _new_ and unheard of before.












I found out that I can remember each and every single Matchbox car I had, and the ones I did not have too. I saw most of them tattered and brushed, like mine where after 'they had an accident' but at least mine where loved and owned. The ones on the market where love-less.













The worst thing was this car. I got it on a Monday, loved it to death because it was so advanced. It was a little bigger then the normal cars. It had stuff in it that you could get out from the back. I took it to school, played with it day and night. One day my [Thursday] teacher Boudy de Vries took it from me. He disliked us boys playing with cars instead of listening to the same old, some old.

On Monday I collected all my witt and guts and asked it back. The sucker simply said [and I remember the smuck smile on his bearded face up and till today!] "I do not have it and never took it!"

The son of a bitch never gave it back. Boudy de Vries, I hate that guy with a passion.

vrijdag 4 april 2008

But not without Manager 2.0

World 1.0 VS World 2.0
Knowledge sharing and learning is imposed additional work VS Knowledge sharing and social learning is a welcome natural part of people's everyday work

Work takes places behind closed doors VS Work takes place transparently where everyone can see it

IT Tools are imposed on people VS People select the tools that work best for them

People are controlled out of fear they will do wrong VS People are given freedom in return for accepting responsibility

Information is centralized, protected and controlled VS Information is distributed freely and uncontrolled

Publishing is centrally controlled VS Anyone can publish what they want

Context is stripped from information VS Context is retained in the form of stories

People think quietly alone VS People think out load together
People tend to write in the third person, in a professional voice VS People write in the first person in their own voice

People especially those in authority are closed to new ideas and new ways of working VS Everyone is open to new ideas

Information is pushed to people whether they have asked for it or not VS People decide the information they need and subscribe to it

The world is seen through a Newtonian cause and effect model VS The world is recognized to be complex and that different approaches are needed

Now all looks good and well in World 2.0. Everybody spimply changes from consumer to prosumer and takes an active role. Business as usual 2.0. Cool. But where does one find managers 2.0?

donderdag 3 april 2008

Do Know Evil!

So I got the sites:



DoKnowEvil.nl
DoKnowEvil.biz
DoKnowEvil.org
DoKnowEvil.de
DoKnowEvil.eu

Now all that is missing is the T-Shirt, Krassimir :P

Google searches best, Maltego finds

A couple of days ago I wrote kinda ecstatic about the possibilities of Maltego. Turns out, I am right [duh!].

Anand Rajaraman is the Consulting Assistant professor at the Computer Science Department at Stanford University, and he drives the point home much better in this article. To sum ot up, if you have limited resources, add more data rather than fine-tuning the weights on your fancy machine-learning algorithm. Of course, you have to be judicious in your choice of the data to add to your data set.

That is exactly what Maltego does and lets you do. It gives a plenitude of data sources and lets you, the human, decide what information weights most, considering your particular query.

dinsdag 1 april 2008

There is never enough time, thank you for yours...

Cybersecurity in a New Digital Age, by Dr. Dan Geer.

zondag 30 maart 2008

If you are going to be late, come with flowers.

Samsung phones look nice, feel good and are populair.

A crying shame is the absolute lack of OSX support. No sync for most of them via iSync and a bunch of self hacked config files to make is sort of work.

Shame on samsung, my money is going elsewhere.

zaterdag 29 maart 2008

People that change the way we persive the world.

Roelof Temmingh & Chris Böhme

http://www.paterva.com

Maltego, Maltego will change the [online] world as we know it. What google once did to searching Maltego will do to finding.

Currently all that is being shown & displayed is fast amounts of data: exactly the thing that computers like and do a good job with, but unusable for humans. Enters Maltego. Maltego will take a seed [individual's name, a domain name, email address, whatever] and finds related data, just like everybody and his dog does.

But then the 'post processing' starts, and Maltego will show it's muscle: based up some smart correlating and weighting, it will show you the results it found, in a graphical way, in a nice patern. In comes the thing we humans do good: patern regonision. We excel at seeing paterns and since Maltego excels at displaying it, we now have a man-machine combination.

Give me some time and I'll show you...

http://www.paterva.com/web2/maltego/maltego.html

vrijdag 28 maart 2008

In the end, Joe 6-pack decides...

More later.

"It's better to ask for forgivenes then to ask for permission" anon

"We do not want our _users_ to break the EULA" Roelof Temmingh

"We rely on the inteligence of our router to play nice. Even if we know hop 5 is not playing "nice" with our packets, there is nothing we can do but stop... that sounds like DoS to me" FX

"Nobody uses the latest version of IOS. It is "banana" software: it ships green, and after it lays a long time at the customer, it gets yellow and eatable :P"

"In 12.4 they create heap logs in the data section, since it has space after loading"

"Uncompressing data in READ ONLY memory & writing it back.. because we can!"

"A problem with IOS is that you can not find what was wrong 5 minutes ago, if the processes start behaving good again"

CIR is a cool tool under development.

"Law-full interception: the government snooping IOS, what do you know about it?"

"It enabled us to see if & what is wrong, or that we have plenty time to replace everything with Juniper boxes :D"

"Software that needs to parse large numbers of formats are potentialy dangerous [think AV, Indexing software, media players]"

"Media parsing should be done sandboxed"

"Media files|streams are as dangerous as any other zip file"

dinsdag 25 maart 2008

BlackHat: hacking by numbers

So, two guys from sensepost are doing this training on hacking by numbers.

Interesting stuff, it basically boils down to: get as much as possible information on your target. Do this by utilizing public sources [think google [link:], netcraft, ARIN, msn.livesearch.com [ip:], kartoo.com and the likes] and reverse the pointers you find there. See what else is hosted on these IP addresses, see what other domains are registered and|or linked. Check for 'backlinks' that might indicate strong ties between companies.

And keep doing the:
:start
Single domain
Expand
Lots of domains
Reduce
Find what we really need
goto start

Both Nick & Jeremy keep saying: "Remember, domain names are IP addresses and IP addresses are points of attack"

Last but not least:
Find out private information of key individuals for social engineering.

Oh and for our hosts, this is for you :D


Peeps & posts [from] here:
Nathan McFeters
Petko D. Petkov
PortSwigger & Marcus
Mikko Hyykoski
Sandro

And some who are not:
Dimitri Sklyarov

maandag 24 maart 2008

WRT54GS + MESH + SOLAR == cool

I got a bunch of Linksys WRT54GS [version 4] laying around. Got a decent Internet pipe too. Got some altitude available. No AC power where I need it.

So.

Sveasoft I like as replacement firmware, and they released a MESH version.
There are plenty of people who attempted to run a WRT of of solar.

Soon my SSID will popup all over :P

Power consumption and solar needs

vrijdag 21 maart 2008

The book thief

So, I read the book, "The book thief" [and so should you!].

I'll drink the wine:
Montepulciano D'Abruzzo
that is Red
and TRebbian D'Abruzzo
that is white

What's next?

donderdag 20 maart 2008

Inside the Twisted Mind of the Security Professional

Uncle Milton Industries has been selling ant farms to children since 1956. Some years ago, I remember opening one up with a friend. There were no actual ants included in the box. Instead, there was a card that you filled in with your address, and the company would mail you some ants. My friend expressed surprise that you could get ants sent to you in the mail.

I replied: "What's really interesting is that these people will send a tube of live ants to anyone you tell them to."

Security requires a particular mindset. Security professionals -- at least the good ones -- see the world differently. They can't walk into a store without noticing how they might shoplift. They can't use a computer without wondering about the security vulnerabilities. They can't vote without trying to figure out how to vote twice. They just can't help it.

SmartWater is a liquid with a unique identifier linked to a particular owner. "The idea is for me to paint this stuff on my valuables as proof of ownership," I wrote when I first learned about the idea. "I think a better idea would be for me to paint it on your valuables, and then call the police."

Really, we can't help it.

This kind of thinking is not natural for most people. It's not natural for engineers. Good engineering involves thinking about how things can be made to work; the security mindset involves thinking about how things can be made to fail. It involves thinking like an attacker, an adversary or a criminal. You don't have to exploit the vulnerabilities you find, but if you don't see the world that way, you'll never notice most security problems.

[...]

The security mindset is a valuable skill that everyone can benefit from, regardless of career path.

woensdag 19 maart 2008

maandag 17 maart 2008

If remittances brought development, Mexico would be Switzerland.

It isn't, still the global sums now exceed $300 billion a year. India ($27 billion), China ($26 billion) and Mexico ($25 billion) are the leading beneficiaries. Some small countries increasing their national incomes by more than 20 percent. Egypt gets more from remittances than it does from the Suez Canal.

But when I ask you to name a single country that has developed through remittances: the answer is no — there's none.

zondag 16 maart 2008

Open Source, what would live be without it?


SSL-Explorer is the world's first open-source, browser-based SSL VPN solution. This unique remote access control solution provides you with a means of securely accessing intranet applications and resources using a standard web browser.

No client-side software needs to be installed on your user's systems and maintenance is centralised and simple. SSL-Explorer relies on the ubiquitous Java™ web technology and hence requires just a standard web browser to take advantage of full remote access. Network traffic can be tunnelled through the SSL connection with ease and your email and intranet web/file resources are securely accessible from outside the corporate network with just a single firewall configuration required post-installation.

Now you can carry your favorite computer programs along with all of your bookmarks, settings, email and more with you. Use them on any Windows computer. All without leaving any personal data behind.

PortableApps.com provides a truly open platform that works with any hardware you like (USB flash drive, iPod, portable hard drive, etc). It's open source built around an open format that any hardware vendor or software developer can use.

The Portable Apps Suite™ is free. It contains no spyware. There are no advertisements. It isn't a limited or trial version. There is no additional hardware or software to buy. You don't even have to give out your email address. It's 100% free to use, free to copy and free to share.

zaterdag 15 maart 2008

DE RIDDER

de ridder bekende ruiterlijk
dat hij niet ridderlijk was
maar ruiter

de ruiter bekende ridderlijk
dat hij niet ruiterlijk was
maar ridder

dinsdag 11 maart 2008

You might not know who is right, but you always know who is the boss

Today gotta be one of the blackest days of my live.

You know, one of those days that you anticipated, that you knew was coming, that was inevitable.

One of them days you had thought of, prepaired for, and applied "your worst case scenario solution book" to, a thousand times.

One of them days you saw coming, and you knew would bring hell on earth, but you live by the coercion or escalation domination doctrine.

The day that you would be as sharp as a raisor. Clean. Ready. Just. And most of all: do the right thing.

The day you'd have G*d on your side.

But then s|he took a day off and you tripped, of balance. And somehow things got really out of hand. You lost control over everything. You:

Used the wrong words.
Fcuked up the timing.
Lost the oversight.
Held the book upside down.
Wet your pants.

Today, march 11th, will go down in my history book as the day that was and should not have been.

maandag 10 maart 2008

FireFox FullScreen on OSX

I knew I should have pushed the publish button.

Start FireFox, create a new bookmark [I like it on the bookmarktoolbar], enter a goodname [FullScreen seems nice] and enter this line of code:

javascript:self.moveTo(0,0); self.resizeTo(screen.availWidth,screen.availHeight);


Et voilla: Sarah got her fullscreen browser!

zondag 9 maart 2008

Video on the iPhone? SURE!

Get handbrake and set the preset to iPhone/iPod touch.
It's smaller and optimized for the iPhone native resolution.

Enjoy!

maandag 25 februari 2008

Pakistan Hijacks YouTube's IP's

Of course this is not a first. And of course there is are some good solutions, one I like best is called "Pretty Good BGP" read more about it [PDF alert], if you like.

Was it a typo on a filter over at AS17557? Most likely we will never know, since those people in Pakistan are not really the kind of open minded guys, hence the hijack of YouTube's IP's in the first place.

Maybe this will lead to a global split of the I-network as we know it.

maandag 11 februari 2008

Van: DODGE WB 300






Wat dacht je van een rode occasion van November 1980, met 28600 KM op de teller, een automaat met 4 wiel aandrijving op benzine door 8 cylinders, met 5 deuren en 10 zitplaatsen van 2200kg zwaar voor ongeveer 10.000 euro?

woensdag 6 februari 2008

rar zip whatever!

I hate to have tools on my machines that costs too much and|or leave me locked into something I do not like.

Archiving & compressing comes in many flavours and some are better then others but one tool really stands out since it reads about everything under the sun [archive formats like: 7-ZIP, A, ACE, ARC, ARJ, B64, BH, BIN, BZ2, BZA, C2D, CAB, CDI, CPIO, DEB, ENC, GCA, GZ, GZA, HA, IMG, ISO, JAR, LHA, LIB, LZH, MDF, MBF, MIM, NRG, PAK, PDI, PK3, RAR, RPM, TAR, TAZ, TBZ, TGZ, TZ, UUE, WAR, XXE, YZ1, Z, ZIP, ZOO], and is free [as in beer]:

http://www.izarc.org/

Oh ,did I mention that it allows you to drag and drop files from and to Windows Explorer, create and extract archives directly in Windows Explorer, create multiple archives spanning disks, creating self-extracting archives, repair damaged zip archives, converting from one archive type to another, view and write comments and many more?

Some more good, small & free stuff:
http://utorrent.com <--- super lean & mean torrent client
http://infrarecorder.sourceforge.net/ <-- Infra-Recorder, an ISO & DVD burner
http://www.codecguide.com <--- get the ultimate codex pack, k-lite here

Thank you guys!

dinsdag 5 februari 2008

Happy birthday!


And this is your present! I hope you really really like your MagicWheel and that you will have lots of fun with it!

maandag 28 januari 2008

It’s awfully nice to forgive.

“Forgiveness is the economy of the heart…forgiveness saves the expense of anger, the cost of hatred, the waste of spirits.” — Hannah More

Word!

zondag 27 januari 2008

Holocaust Memorial Day



Never forget, nor forgive.

http://en.wikipedia.org/wiki/Holocaust_Memorial_Day

zaterdag 26 januari 2008

Jumping Amsterdam



Echt wel kicken die vierspan demonstratie van IJsbrand Chardon vs Koos de Ronde!

Volgend jaar weer.

zondag 20 januari 2008

sound <> noise <> good neighbours

De beoordeling van de verbetering moet zijn gebaseerd op Nederlandse normen, met name NEN-EN-ISO 717-2.
U heeft een certificaat nodig waarin staat dat het dempende materiaal in combinatie met de gebruikte harde vloerbedekking volgens de genoemde norm voldoende dempend is.
Kijk bij leveranciers van dempende materiaal dus altijd uit naar de vermelding NEN-EN-ISO 717-2 en of deze voldoet voor de combinatie met de bovenvloer en de ondergrond. Voor beton boven een kruipruimte is ook een dampremmende folie, direct onder de laminaat vloer aan te bevelen.

Het gaat bij geluidsdemping niet om de klossende geluiden die u zelf hoort, maar om de contactgeluiden die doorklinken naar de andere bewoners van een gebouw. Verlijmen mag dus hoogst waarschijnlijk niet.
Bij toepassing van een geluiddempende ondervloer neemt het contactgeluid naar de buren dus af, maar kan het klossendegeluid in het eigen appartement zelfs iets toenemen.
bron

De functie van een ondervloer is kleine oneffenheden in de basisvloer egaliseren, en zorgen voor akoestische en thermische isolatie. Om problemen met opstijgend vocht te vermijden moet ALTIJD begonnen worden met een plastic folie. Indien een “combi” ondervloer gebruikt wordt, is een passend dampscherm reeds aan de ondervloer gekleefd.

Wat akoestiek betreft, moet men onderscheid maken tussen DOORGANGSGELUID (naar onder toe, op verdiepingen) en REFLECTIEGELUID (in de kamer zelf). De isolatie van beide types geluid is contradictorisch: om doorgangsgeluid te isoleren heeft men “lucht” nodig en om reflectiegeluid te isoleren “massa”.
bron

De in Nederland geldende eis is dat bij vloeren in etagebouw het geluid dat doorklinkt naar de ondergelegen woonlaag met minimaal 10 dB wordt verminderd. De reductie-eis heeft geen wettelijke status, maar is algemeen aanvaard. Veel VVE’s (Vereniging van Eigenaren) stellen de vermindering volgens de norm verplicht. Let erop dat het geluidreducerende ondermateriaal voldoet aan de Nederlandse en Europese norm (NEN-EN-ISO 140/717-2 1997). Als het goed is wordt deze norm op alle producten vermeld. Let op: er zijn ook andere resultaten m.b.t. geluidsreductie, die veel hoger uitvallen, maar niet geldig zijn volgends deze norm (want volgens andere testmethoden bereikt).
bron

Welke ondervloer?


Redupax+ ® Ondervloerplaten 10db


Uitstekende geluiddemping; zowel contact- als loopgeluid. Redupax+® is dè geluidsreducerende ondervloer speciaal voor laminaat uitgerust met een (lijmloos) 'klik/lock' verbindingssysteem. Sterk egaliserend. Goede thermische werking.
(pakinhoud: 4,40 m2 - 10 platen van 560 x 790 x 8 mm).

Adviesprijs € 9,20 / m² ( € 40,48 / pak)
Onze prijs: € 7,45 / m² (€32,78 / pak) incl. BTW, excl. levering.
bron


Contactgeluid isolerende ondervloeren

Geluidsoverlast is hinderlijk. Om overlast te voorkomen eisen woning-bouwverenigingen en Verenigingen van Eigenaren vaak een vloerafwerking die het geluid 10 decibel (dB) dempt. Voor harde toplagen zoals parket, zeil of laminaat is dat een zware eis: een ondervloer is noodzakelijk. Kies zorgvuldig, want om kosten te sparen worden ondervloeren vaak zo dun mogelijk uitgevoerd. En hoe dunner hoe minder demping. Wie een ondervloer aanschaft met een TNO-keurmerk weet dat die 10 dB ook echt 10 dB zal zijn. Zo komt u na de verhuizing niet voor een groot probleem te staan. Let wel op dat TNO de ondervloer getest heeft voor het type toplaag dat u erop wilt leggen. De geluidsisolatie kan verschillen.

TNO test en certificeert ondervloeren volgens de internationale norm NEN-EN-ISO 140-8 en 717-2. Dat gebeurt met referentievloerbedekkingen waarover met fabrikanten afspraken zijn gemaakt. TNO belast de vloeren zodat een heel realistische situatie ontstaat. TNO test de geluidsisolatie van ondervloeren in combinatie met laminaat (verlijmd of met klikverbinding), lamel parket (verlijmd of met klikverbinding), massief parket (verlijmd), tapis parket (gelijmd of genageld), verend vinyl (los gelegd), vol vinyl (verlijmd), linoleum (verlijmd), kurk (verlijmd) en keramische tegels (verlijmd).
bron


‘Zwevende’ betonvloer
Vooral te vinden in moderne appartementen. Deze vloer is opgebouwd uit de dragende constructie met daarop een laag geluiddempend materiaal. Daaroverheen komt de dekvloer. Deze hoort vrij te liggen van de wanden.

Volgens het Bouwcentrum kan een houten vloer op een zwevende vloer zonder ondervloer worden gelegd. Omdat de ondervloer kan zorgen voor extra resonantie kan dit zelfs meer geluidsoverlast veroorzaken.

Let op:
Een te slechte geluidsprestatie van een zwevende dekvloer kan niet worden gecompenseerd met een extra dempende ondervloer. Een houten vloer leggen is dan dus eigelijk onmogelijk en tapijt of vinyl de enige remedie.
bron

En als alles mislukt, geen je je buren een CD met anti-geluid :D