Showing posts with label it. Show all posts
Showing posts with label it. Show all posts

Thursday, November 14, 2013

荷蘭情報機關準備對 IP 網路進行大規模監聽

Dutch secret service prepares for wiretapping of IP networks on a large scale!

News:
http://www.volkskrant.nl/vk/nl/2686/Binnenland/article/detail/3541591/2013/11/09/Nederland-bestelt-een-nog-verboden-spionagesysteem.dhtml

In Summary:

The Dutch AIVD (dutch NSA counterpart) has ordered equipment to wiretap IP links for €17 million. Doing "undirected" surveillance is currently only legal in the Netherlands for signals that are not carried over cables (eg broadcast signals). With this move, the agency is anticipating a law change, which will allow it to wiretap cables to do undirected (mass) surveillance.


<人腦翻譯>
荷蘭情報機關已經採購類似美國情報局的設備, 以便對於網路與電話進行監聽. 雖然目前該行為仍然為法令所禁止, 但是情報主管認為該法令已經過時.
</人腦翻譯>

So... finally, it comes...


Tuesday, December 14, 2010

ipv6 nat (nat66) by Juniper ScreenOS

ScreenOS is the operation system in Juniper SSG & NS device (was NetScreen).

There is no clear document states ScreenOS could perform nat66 (at least Juniper does not use the term "nat66".) However, if one could follows ScreenOS release notes carefully, it became consequences.
set policy id 1 from "Trust" to "Untrust"  \
    "Any-IPv6" "Any-IPv6" "ANY" nat src permit 
set policy id 1
Where obviously, key word "nat" does the trick!

Tuesday, November 16, 2010

ipv6 nat (nat66) by FreeBSD pf

although nat66 is still under draft, but FreeBSD pf already support it for long time.
(edit the pf.conf and insert following codes)
v6_wan_if="your-v6-wan-interface-name"
v6_wan_ip="your-v6-wan-ip-address"

no nat on $v6_wan_if inet6 from $v6_wan_ip to any
nat on $v6_wan_if inet6 from any to any -> $v6_wan_ip    
You are all set!

Monday, November 15, 2010

紙霸跑去 Cisco 上班了

唔~ 紙霸跑去 Cisco 上班了...賈老準備好要告了嗎? :p :p
http://www.theregister.co.uk/2010/11/15/apple_cisco/

The Register (http://theregister.co.uk/)

Apple antennagate scapegoat scooped up by Cisco
Boardroom-hopping exec joins networking giant


Mark Papermaster, whom Apple had such a hard time wresting from IBM in 2008, and who took much of the flak for the iPhone's dodgy antenna, has moved on to Cisco...

Sunday, August 29, 2010

Sync calendar/task/contact/notes between Google and MS-Outlook

這兩天搞 Outlook --> Google 的 Calendar Sync 想把兩邊的行事曆整合在一起.

不過 Google 自己的 sync 工具實在太陽春, 對於跨日的 event 會錯亂, 然後 Google Calendar 又很白癡, 只要一手動去修改就會亂發垃圾信出去... 對收到我垃圾信的朋友深感抱歉... Orz...

剛找到一個要錢的軟體 gSyncit 試用了一下看起來還不錯!

Sync 跨日的 Event 不會亂掉, 處理 timezone 資料也正確. 而且還可以選擇性的不要把參加者的資料送上去 Google, 這樣就算調整了東西, Google Calendar 也沒辦法亂發垃圾信, 讚!

gSyncit 要價 US$14.99, 先用一陣子看看要不要花錢買正式版 ^_^

gSyncit: http://www.daveswebsite.com/software/gsync/index.shtml

Sunday, August 15, 2010

recover from accidentally upgraded Iphone iOS 4.0.2

In case accidentally "upgrade" Iphone4 to iOS 4.0.2, use following procedure to recover it back to 4.0.1.

a) download iOS 4.0.1 from http://tinyurl.com/38rlu54
b) power-off phone, plug to PC, press and hold "home"+"power" till iTune recognizes it
c) select iOS 4.0.1 file with "shift" key on PC keyboard
d) iTune will verify the firmware and and recover iphone4 with it
 

Wa La~ you are all set~

Friday, August 13, 2010

啟用 Iphone 4 內建 Tethering

參考: http://forums.macrumors.com/showthread.php?t=984943

會操作 UNIX 的人可以略加變化, 不需要動用 Cyberduck 或是其他 SFTP 軟體, 只要有一台連在網上的 ssh server 就可以了. 所有的備份也都可以直接上傳到那個 ssh server.

Monday, July 26, 2010

Ruling Allows "Jailbreaking" of iPhones

Citation:  The New York Times.

Ruling Allows "Jailbreaking" of iPhones

WASHINGTON (AP) -- Owners of the iPhone will be able to legally break electronic locks on their devices in order to download software applications that haven't been approved by Apple Inc., according to new government rules announced Monday.

(read more on NY Times)

Tuesday, June 15, 2010

終於對 iphone 動心

最近高齡四歲的舊手機的電池越來越沒檔頭, 講電話一兩分鐘就乾掉, 上網收個 email 看看大約十來分鐘就乾掉. 變成名副其實的緊急專用電話, 非到必要關頭不願意拿出來用. 煩惱的是連阿嬤粽都已經買不到相容的電池了. 眼看只有換新手機一途.

看了許多手機的比較, 終於對 Iphone 4 動心了. 吸引我的不是他的各種 apps, 而是電池的續航力. 姑且不論不能自己換電池這個缺點, 這是個很嚴重的缺點, 嚴重到我過去幾年一直不把他列入考慮. 但是這陣子深深覺得, 能夠長時間連續講電話是一件很重要的事情, 電話講一半因為手機沒電掛點, 有時候會發生奇異的悲劇. Orz...

Iphone 4 電池續航力官方數據如下:
7 hrs 3G Talk / Internet browsing
12 hrs 2G Talk
10 hrs WiFi Internet browsing
40 hrs Music Playback
10 hrs Video Playback
先不看其他部分, 光是講電話這個數據就打趴一大堆競爭對手, 如果以 Smart Phone / PDA phone 來比的話, 大概全趴了...雖然很討厭 Apple 這公司, 尤其是他家的執行長真是霸道, 小心眼, 外加沒修養到極點, 但是他家的工程團隊真是了得, 可以在這麼小的機身裡面塞進這麼多功能跟這麼長壽的電池. 這點不拍手就真的是違背良心了!

現在還在預購階段要等到 6/24 才會正式出貨, 再來猶豫幾天吧~~~

Thursday, June 10, 2010

從 Bloglines 跳槽到 Google Reader

話說 Bloglines 用了好幾年, 但是越用問題越多. 一來是搜尋不易, 再來是出現 server timeout 或是其他怪事的頻率越來越高. 這幾天更慘, 幾乎天天都遇到 server timeout.

前兩天從 Bloglines 跳槽到 Google Reade, 經過兩天的適應已經擺脫不熟悉的感覺. 用起來沒有太大的問題. 希望財大氣粗的 Google 沒有 server capacity 或是網路資源不足的問題.

這兩天的使用經驗是, Google Reader 明顯比  Bloglines 快非常多, 介面上稍為簡單清晰一點. 唯一不太適應的是 Google Reader 顯示的 RSS 抓取的時間, 而不是文章發布的時間. 這點論壇裡面也有人討論跟反映, 但是似乎一直沒有選項可以去改 (至少我還沒找到選項).

Wednesday, June 9, 2010

Pop Quiz: separate odd and even IP numbers

In Juniper JUNOS, ip/mask could be used to separate odd/even IP numbers. similar to wildcard in Cisco IOS.

[edit firewall family inet]
filter Separate-Numbers {
    /* match even IPs 10.10.10.{0,2,4,6,8,...} */
    term Even-Numbers {
        from {
            source-address {
                10.10.10.0/255.255.255.1;
            }
        }
        then {
            xxxxx;
        }
    }
    /* match odd IPs 10.10.10.{1,3,5,7,9,...} */
    term Odd-Numbers {
        from {
            source-address {
                10.10.10.1/255.255.255.1;
            }
        }
        then {
            xxxxx;
        }
    }
}

Tuesday, June 8, 2010

現在記者發稿都不校對的嗎? (9.3 公分厚的 iPhone 4G)

不只記者的水準日漸下降, 整個報業的水準也令人抓狂... 圖片上明明清楚的寫著 iPhone 4 但是標題跟內文通通寫成 iPhone 4G 試怎麼回事? 再加上完全莫名其妙的 9.3 公分厚度, 這賣的是建築材料行裡面就可以買到的磚塊嗎?

Tuesday, May 11, 2010

ICANN 開通非拉丁語系頂級域名 - 巴別塔的狂想

這不是太新的新聞了,不過這東西有他正反兩面的論述. 最簡單的來說, 在於可能發生的輸入問題. 以中文來說, 輸入中文比輸入英文的困難度大 (假設不考慮語言的使用問題, 比如說不懂英文不懂中文.)

另外就是中文有字體上面的問題, 舉例來說簡體字跟繁體字到底是代表同一個網站或是不同網站? 或是說俗體字跟正體字呢 (例如 台灣 跟 臺灣 到底是不是同一個網站/網域.) 相關的論述很多, 沒必要在這邊舊調重彈.

今天想到的是聖經的故事.
那時、天下人的口音言語、都是一樣。他們往東邊遷移的時候、在示拿地遇見一片平原、就住在那裏。他們彼此商量說、來吧、我們要作磚、把磚燒透了。他們就拿磚當石頭、又拿石漆當灰泥。他們說、來吧、我們要建造一座城、和一座塔、塔頂通天、為要傳揚我們的名、免得我們分散在全地上。耶和華降臨要看看世人所建造的城和塔。耶和華說、看哪、他們成為一樣的人民、都是一樣的言語、如今既作起這事來、以後他們所要作的事、就沒有不成就的了。我們下去、在那裏變亂他們的口音、使他們的言語、彼此不通。於是耶和華使他們從那裏分散在全地上。他們就停工、不造那城了。因為耶和華在那裏變亂天下人的言語、使眾人分散在全地上、所以那城名叫巴別。
    – 創世記 11:1-9(中文和合本)
網域名稱本來只能用英文, 某個程度來說是使用著相同的表達方式. 上帝警覺到了! 於是非拉丁語系的次網域開通了, 接下來頂級域名也開通了. 是不是巴別塔的重現?

Thursday, April 22, 2010

神奇的 50Gbps 網路卡

顯然 Windows 7 已經瘋掉了... 我這種小電腦哪來的 50Gbps 能力...

Tuesday, April 20, 2010

Windows7 英文版裡面中文字型很醜的解法

本來上周末天氣預報是不好的, 想說應該找點事情來做做, 就跟同事拿了 MSDN 光碟準備來惡搞一下 T61 弄個 Windows 7 來玩玩看. 當然這跟辦公室的測試 PC 不同, 裝好之後當然是拿來亂玩, 開個 Mobile 01看看八卦是一定要的. 這不看還好, 一看驚嚇度百分百... 中文字醜到翻過去! 整個字體扭得跟毛毛蟲一樣, 還會挫來挫去, 不管用內建的 IE 或是另外安裝的 Firefox 都一樣... Orz

後來發現不只看網頁, 如果用一些軟體選單是中文的也都會出現嚇死人的醜陋中文字選單.

弄了半天, 發現有個解法是把 Control Panel 的 Region and Language 裡面 Administrative 設定項目下的 Language for non-Unicode programs 改成 "Chinese (Traditional, Taiwan)" 就可以有比較美觀一點的中文字顯示.

這實在是一件很奇怪的事情, 為什麼中文字顯示的美醜度跟 non-Unicode programs 的 Language 有關係呢? 實在是怪異的設計邏輯啊!

 


後記: 氣象預報不準這件事情在每個地方都差不多, 周末天氣其實好的很, 陽光普照! 所以星期天就跟朋友跑去 outlet 灑錢了 $_$

Monday, March 29, 2010

Juniper J-series routers in packed-based mode

Star from JUNOS 9.4, the packet-mode (traditional) JUNOS for J-series is no longer exist; the only version is flow-mode J-series JUNOS (the ES version.) However, packet-based mode is quite handy if people simple need a small router without worry about those session-table, symmetric routing, and etc.

In JUNOS 9.6, a statement under [security] section could bring the J-series box back to pure packet-based mode. Actually that is a side effect of another statement, but it is a good side effect, from this point of view. Which is a statement that make MPLS family to be run under packet-mode, and the side effect is to bring inet family also into packet-mode.

Under this mode, all other security policy (under [security] section) is no longer available, but stateless firewall filter works well (under [firewall] section.)

The configuration is,
[edit]
delete security
set security forwarding-options family mpls mode packet-based
There do have other side effects that IPsec VPN is no longer avalible, because IPsec VPN in 9.6 is flow-based.

Saturday, March 27, 2010

俗語說的好『xx改不了吃xx』

 大約 3/24 左右開始, facebook, youtube, 跟 twitter 就發現間歇性的被導到中國去. 從觀察看起來類似 DNS poison 的現象. 整件事情的源頭不意外是從中國來的. 下面的討論串有比較詳細的技術資料

  https://lists.dns-oarc.net/pipermail/dns-operations/2010-March/005260.html

然後今天有人拿出 GFW 的東西出來佐證. https://lists.dns-oarc.net/pipermail/dns-operations/2010-March/005323.html

這事情只能說『xx改不了吃xx』... 對中國任何事情都要小心防備.

1. BGP peer 要 filter 掉不該有的東西
2. 最好不要用任何中國的企業提供的服務

不要以為從中國 VPN 出來就很安全, 因為

1. 在當地只能用當地業者提供的線路跟服務
2. man in the middle 只要有心, 技術上都做的到


就算拉專線也不見得 100% 安全. 說到底, 能夠不要跟中國有往來是最好的... 當然這可能辦不到...

Wednesday, March 24, 2010

FreeBSD 7.3-RELEASE

FreeBSD 7.3-RELEASE 發行了.

使用 7.2 的機器都建議升級到 7.3 或是 8.0 (下面是從 announcement email 裡面剪貼出來的內容)
The FreeBSD Security Team currently plans to support FreeBSD 7.3 until March 31st 2012. Users of FreeBSD 7.2 are strongly encouraged to upgrade to either FreeBSD 7.3 or FreeBSD 8.0 before the FreeBSD 7.2 End of Life on June 30th 2010. For more information on the Security Team and their support of the various FreeBSD branches see:
http://www.freebsd.org/security/

升級的方法很簡單, 使用 freebsd-upgrade 這個工具就可以, 基本上就是下面幾個步驟,
# freebsd-update upgrade -r 7.3-RELEASE
# freebsd-update install (這步驟會把 kernel 裝進去)
# shutdown -r now  (重新開機, 變成新的 kernel)
# freebsd-update install  (把其他的元件裝進去)
# shutdown -r now  (再重新開機一次, 大功告成)
如果是 6.x 也可以這樣幹, 不過最後要重新把 ports 裝的軟體重新編譯一次. 詳細的東西就看 release notes 囉 ~~

Thursday, March 11, 2010

把 ScreenOS 的 route preference 改成跟 JUNOS 一樣

以下的指令可以把 ScreenOS 的 rote preference 改成跟 JUNOS 一樣

set vr trust
 set preference static 5
 set preference ospf 10
 set preference ospf-e2 150
 set preference ebgp 170
 set preference ibgp 170
 set preference rip 100
exit

Monday, March 8, 2010

用 snmp 看 NetScreen ScreenOS 的 VPN tunnel 的流量

用 SNMP 看 NetScreen / SSG 的 ScreenOS 的 VPN 介面流量的時候, 沒辦法直接用 ifmib 看, 要用下面的 mib,

1.3.6.1.4.1.3224.4.1.1.1.4 --> 看有哪些 vpn tunnel
1.3.6.1.4.1.3224.4.1.1.1.35 --> 對應的 vpn 的 Byte-In
1.3.6.1.4.1.3224.4.1.1.1.36 --> 對應的 vpn 的 Byte-Out
1.3.6.1.4.1.3224.4.1.1.1.37 --> 對應的 vpn 的 Packet-In
1.3.6.1.4.1.3224.4.1.1.1.38 --> 對應的 vpn 的 Packet-Out

In = remote to local
Out = local to remote

以上~筆記一下以免忘記.