Monday, September 21, 2009

Ubuntu and kvm virtualization - know who you are and where it runs

Maybe I should have read the documentation. Might have saved me a few confused hours. I doubt it though as my issue seemed to be something straight forward enough that it is probably not documented.

I had created a virtual machine using the Virtual Machine Manager GUI. It was a CentOS system, minimally configure that I simply wanted to clone as I needed a couple of machines to test Openfire. Unfortunately, all my vast knowledge (Google) ;-) seemed to let me down.

The command that should have cloned the system
sudo virt-clone -o CentOSServer -n CentOSServer2 -f /home/user/CentOS2.img --connect=qemu:///system
failed with an error:

ERROR Domain CentOSServer is not found
Yet, the virtual machine that I was attempting to clone existed. I connected to it with the Virtual Machine Manager and was able to start it and access it without any issues.

I tried various alternatives including specifying --connect=qemu:///session but nothing seemed to work.

I tried virsh to connect in an attempt to use the "list -all" command. I was thinking that the gui could find the virtual machine so it had to be somewhere:
sudo virsh --connect=qemu:///session list --all


Unfortunately, that did not list any virtual machines.

The answer was fairly simple once I noticed that the GUI had specified "localhost (User)" in the name of the host to which I had connected and that the virtual machines were part of. I realized that by running the commands using sudo, I was connecting with root's profile while I was running the Virtual Machine Manager as my own user profile.

Once I realized that I should connect as my own user the "virsh list --all" command showed the virtual machine that I wanted to clone. Then, the following command cloned the system:

sudo virt-clone -o CentOSServer -n CentOSServer2 -f /home/user/CentOS2.img --connect=qemu:///session

I need to do a little research to understand the difference between the session and the system but it worked. Now back to Openfire



Friday, January 16, 2009

Lock Firefox Proxy and other Settings

Locking Firefox settings in a multi-user Linux system can be a bit difficult and the information out there varies in quality. A while ago I found a script written by Andy Rabagliati of http://wizzy.org.za that automatically created the correctly formated config file and updated the Firefox settings to import the config file.

Recently when I used it on Ubuntu I ran into issues so I modified the script to account for the way Ubuntu separates the browser from xulrunner.

Here is a link to the updated script http://timlegge.googlepages.com/moz-lock.pl.

To run the script simply pass it the ip address of the proxy server as follows:
sudo ./moz-lock.pl 192.168.0.254
There are numerous additional settings that can be enabled at the bottom of the script. Currently the following settings are enabled:
  1. Set the cache size to 10 megs
  2. Do not hide the tabs if only one is open
  3. Proxy settings
To reverse the settings simply open the all.js files that are modified (modified files are listed when the scrip runs) and remove or comment out the last line in the file or copy the backup version over the modified file,

Sunday, August 31, 2008

The Ultimate Hacker Key

The Ultimate Hacker Key (aka who needs a key chain)

While listening to PaulDotCom Security Weekly 114 I "discovered" UNetbootin - Universal Netboot Installer. Paul talked about installing Backtrack 3 on his USB key and how easy UNetbootin was to use. A colleague of mine recently expressed an interest in having Backtrack running on a USB Key so I thought I would take a look.

Installing Backtrack 3

Getting Backtrack installed and ready to boot from usb is so simple using UNetbootin it almost does not require directions. But here they are:
  1. Goto http://unetbootin.sourceforge.net/
  2. Click Download (for windows or Linux)
  3. Insert your USB Key
  4. Run UNetBootin
  5. Select BackTrack from the Distribution Download
  6. The Version populates automatically
  7. Select the drive that is your USB key (hint: it is probably not C:\)
  8. Click Okay
  9. Wait
  10. Reboot and if USB is a boot option the Backtrack menu should appear
So who needs a Key Chain

On several PaulDotCom Security Weekly podcasts, Larry referenced and described his key chain. It has some pretty cool things but who needs a key chain when you have a 8 GB Kingston USB key ($19.99 CDN at FutureShop last week). It got me thinking, whether I could get all those things on one device.

First up - Ophcrack

Ophcrack is a free Windows password cracker based on rainbow tables. So, lets get it installed:
  1. Plug in the USB Key
  2. Download the ophcrack LiveCD iso from http://ophcrack.sourceforge.net/download.php
  3. Mount the iso image (mount -o loop ophcrack-xp-livecd-2.0.1.iso /mnt/cdrom)
  4. Copy the main directory to the USB key (cp -ra /mnt/cdrom/ophcrack /media/usbkey/)
  5. Copy and rename the boot directory (cp -ra /mnt/cdrom/boot /media/usbkey/bootoph)
  6. umount /mnt/cdrom
  7. Edit the syslinux.cfg from Backtrack 3 (vim /media/usbkey/boot/syslinux/syslinux.cfg)
  8. Comment out any extra Backtrack 3 boot images that you don't plan to use
  9. Add in the boot section from /media/usbkey/bootoph/ophcrack.cfg like:
    LABEL xconf
    MENU LABEL Ophcrack Graphic mode
    KERNEL /bootoph/vmlinuz
    APPEND initrd=/bootoph/initrd.gz ramdisk_size=6666 root=/dev/ram0 rw autoexec=xconf;startx changes=/slax/
  10. Note that the /boot/ references were changed to /bootoph/
  11. Reboot

Second - Offline NT Password & Registry Editor

This is a utility to (re)set the password of any user that has a valid (local) account on your Windows NT/2k/XP/Vista etc system. You do not need to know the old password to set a new one.

This is a very small live CD so putting it on its own USB key seems like a waste.
  1. Download the CD image from http://home.eunet.no/pnordahl/ntpasswd/bootdisk.html
  2. Unzip the zip the zip file to obtain the cd080802.iso
  3. mount the iso file (mount -o loop cd080802.iso /mnt/cdrom)
  4. create a boot directory called bootnpwd on the USB key (mkdir /media/usbkey/bootpwd)
  5. Copy all files froom the iso to the new directory (cp -ra /mnt/cdrom/* /media/usbkey/bootnpwd)
  6. umount /mnt/cdrom
  7. Edit the syslinux.cfg from Backtrack 3 (vim /media/usbkey/boot/syslinux/syslinux.cfg)
  8. Add in the boot section from /media/usbkey/bootnpwd/syslinux.cfg like:
    LABEL bootnwd
    MENU LABEL Offline NT Password and Registry Editor
    KERNEL /bootnpwd/vmlinuz
    APPEND rw vga=1 initrd=/bootnpwd/initrd.cgz,/bootnpwd/scsi.cgz
  9. Note that the /boot/ references were changed to /bootnpwd/
  10. Reboot
To Do List
  1. Add extra RainBow tables for OphCrack
  2. Add Ubuntu or some other General Purpose Distro
Notes
  1. For Windows users there are a number of utilities to mount an iso image as a drive. Do a Google Search or get a real OS ;-)
  2. The instructions above are from memory and while I have read it several times to remove obvious errors some may still exist. Leave feedback with corrections but use it has a guide...

Saturday, March 22, 2008

Starting mvprelay via init.d

I have created a script to start and stop mvprelay via the init.d process. The script is for Ubuntu 7.10 - the Gutsy Gibbon.
  1. Download mvprelay_init.tar.gz to /tmp
  2. cd /
  3. sudo tar xvfz /tmp/mvprelay_init.tar.gz
  4. vim /etc/default/mvprelay
    1. Update the MEDIA_SERVER variable with your server's IP address
    2. save the file
  5. sudo update-rc.d mvprelay start 50 2 3 4 5 .
  6. /etc/init.d/mvprelay start
This process should extract the files to the correct location under /etc (/etc/init.d and /etc/default). The update-rc.d command sets mvprelay to start in run modes 2, 3, 4 , 5 and priority 50 (which should be after the dhcpd, tftp mysql servers have started).

I have test the script, it starts, it stops, it restarts. mvpmc boots up from a cold boot. Other than that it is completely untested so your results may differ. No warranty provided, but I will help where I can.

Saturday, March 08, 2008

Breaking Windows with Firewire and Ubuntu

Adam Boileau (http://www.storm.net.nz/projects/16) recently released source code for a tool that can unlock a password locked Windows machine in seconds. While quite simple to use the documentation is not clear on how exactly it is used or how the parts work. I hope this helps:

These instructions are for Ubuntu 7.10 - the Gutsy Gibbon:

First install the required libraries:
apt-get install libdc1394-13 libraw1394-dev swig
Second download and install Python 2.3:
wget http://www.python.org/ftp/python/2.3.6/Python-2.3.6.tgz
tar xvfz Python-2.3.6.tgz
mv Python-2.3.6 python-2.3
cd python-2.3
./configure
make
sudo make install
This will install python in /usr/local which means you need to update each script to reference this location.

Third, Fixup the libraw1394:
vim /usr/local/include/libraw1394/raw1394.h
search for and comment out the__attribute__ ((deprecated)); and be sure to put an ending semicolon on the previous line

Fourth, download the software from http://www.storm.net.nz/projects/16
wget http://www.storm.net.nz/static/files/pythonraw1394-1.0.tar.gz
tar xvfz pythonraw1394-1.0.tar.gz
cd pythonraw1394
wget http://www.storm.net.nz/static/files/winlockpwn
chmod +x ./winlockpwn
vim Makefile (reference /usr/local instead of /usr for python)
make
Fifth, load the module and set some permissions:
sudo modprobe raw1394
sudo chmod 666 /dev/raw1394
Sixth, plug into the Windows machine

Seventh, load the ipod image to the firewire port
vim romtool (update the location of python to be /usr/local/bin/python)
./romtool -s 0 ipod.csr
Eighth, run businfo to check the port configurations:
vim businfo (update the location of python to be /usr/local/bin/python)
./businfo
At this point you should see two nodes listed. Node 0 is the ipod image that you loaded with romtool. Node 1 is the Windows machine.

Ninth, run the utility:
vim winlockpwn (update the location of python to be /usr/local/bin/python)
./winlockpwn 0 1 1
You can get more information on the winlockpwn parameters by running the command without parameters. The first parameter is the firewire port, the second is the node (in this case the node for Windows) and the third is the type of Windows password screen.

Tenth, login to Windows

Use any password you want...

Tuesday, December 11, 2007

Windows Cannot Recognize Wireless USB mouse

Problem: Windows Stops Recognizing USB Mouse

Symptoms: When the USB receiver is plugged in, Windows pop pops up a message in the system tray that it is unable to recognize the USB device. This is despite the fact that plugging it into a different port may (but mostly will not) work.

Solution:

This is direct from "Newbie Poster" at http://www.daniweb.com/forums/post41808-5.html. The solution worked for me despite not deleting the oem inf files or any registry entries.:

I found a fix for USB devices not working, actually came from Microsoft technicians. Apparently there's a problem with the Intel USB chipsets going flakey


Step 1: Remove Hidden Devices

  1. Open a Command Prompt.
  2. Type "set DEVMGR_SHOW_DETAILS=1" (without quotation marks) and press Enter.
  3. Type "set DEVMGR_SHOW_NONPRESENT_DEVICES=1" (without quotation marks) and Press Enter.
  4. Type "start devmgmt.msc" (without quotation marks) and click press Enter.
  5. Click View. Click Show hidden devices.
  6. Click "+" to expand devices, Unknown devices and USB devices.
  7. Are there any devices and unknown devices (including grayed out devices)? If so, please right click it and click Uninstall them.

Step 2: Remove all oem*.inf files

=========================

1. Click start and click run then under the run line type in the command "cmd" (without the quotation marks)

2. In the command line, type in the following (without the quotes) and press enter after each command:

"cd \windows\inf"
"ren infcache.1 *.old"
"ren oem*.inf *.old"
"del C:\windows\setupapi.log"
"exit"

Step 3: Removing all entries under HKEY_LOCAL_MACHINE/Enum/USB that start with VID using REGEDIT.

==================================================================

Removing the VID entries from the registry will cause them to be redetected at restart.

CAUTION: If you have a USB keyboard, mouse, scanners, and other things you know are working, do not remove the VID entry for these devices, otherwise, Windows may not restart correctly.

1. Click Start and click Run. Type regedit and click OK. The Registry Editor window will open.

2. Go to HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\USB.

3. Highlight and delete all the VID_.... entries for usb devices that you cannot identify. Remember not to delete the entries mentioned above.

You may not have permssion to delete keys, do the following.
Permissions may be set allowing the deletion of the VID_ entries by following the steps below:

a) Right-click the key to be deleted, and then click Permissions. The VID_... Permissions window will open.
b) With Everyone highlighted in the Group or User name section, select Full Control in the Permissions section.
c) Click Apply, and then click OK.

5. Restart your compuer.

Step 4: Reconnect the USB device that was not previously working. Windows should automatically rerinstall the drivers.


This worked for me and hope it helps you out. Good luck with it.

Sunday, July 29, 2007

The GrandStream BudgetTone-200 (part 2)

The Firmware Update

I am pleased to say that this was painless and was quite simple to do. I was a little worried about it, but GrandStream seems to have done an excellent job of making it simple to perform.

Defining Simple
If you have the right setup, the update is painless
The requirements for this seem simple enough. You need:
  1. a working dhcp server
  2. a working tftp (or http) server
  3. the ability to configure both
The dhcp server is not strictly necessary as long as the phone is configured with an IP address, subnet, etc.

If you have a working setup already, the firmware update is easy. If you do not have a working setup, you need to start there.

Instructions:
  1. Download the latest firmware update
  2. Unzip the files to the root of the tftp server
  3. login to the phone's web interface (default admin password)
  4. update the Firmware Upgrade and Provisioning to be Upgrade Via tftp
  5. Set the Firmware Server Path to the tftp server ip address
  6. Set the Config Server Path to tftp server ip address
  7. Save settings via Update button
  8. Click Reboot
That's it! The phone will reboot two or three times and at the end (not really evident) you can login to the phone's web site and check the Software Version on the Status tab.

Alternatives

I have not tried the http update of the firmware but I suspect that replacing tftp with http in the instructions above should make it possible.

Friday, July 27, 2007

The GrandStream BudgetTone-200 (part 1)

The purchase:

I recently purchased two GrandStream BudgetTone-200's from http://www.voipdepot.ca. This was an amazing experience and I cannot hesitate to recommend voipdepot.ca. I placed the order Wednesday at 10:21 AM and the package was delivered to my door Thursday at 10:19 AM. A couple of things makes that impressive:
  1. It was less than 24 hours
  2. They are located in Mississauga, Ontario
  3. I am located in Moncton, New Brunswick
  4. Google tells me that it is 1,544 km – about 16 hours 2 mins to drive
Granted, they gained an hour in the time zone but I sill had my order in less than 24 hours.

The GrandStream BT-200; First Impressions:


The phone itself seems to be sturdy and well designed with large buttons. I plugged in the parts, the manual says to connect all the parts and the network before the power and that makes sense.

As soon as the power is supplied the following occurs:
  1. a red light appears
  2. you hear a little noise (like a speaker)
  3. No IP appears on the display
  4. The default date and time 1900-01-01 0:00 AM appears on the display
  5. The correct date and time (more or less) appears
At this point, there is a dial tone and if you left the receiver and press the MENU button you find the IP Address of the phone.

The GrandStream BT-200; Initial Configuration:


The first thing I noticed was that the time was off by an hour or two. It was just an annoyance but it was the first thing I tackled. Pressing the menu butting displayed a number of configurable items but nothing related to time and I also noted there did not seem to be any SIP configuration available.

Upon reviewing the manual I noted that the phone has a web server that is used for configuration. More experience with VOIP would have probably made that obvious but it was not. I opened Firfox and entered http://192.168.2.254 (the IP address revealed by lifting the receiver and pressing MENU).

That brought me to the Grandstream Device Configuration page and yet another review of the manual told me that "123" was the user password.

Logging in, I set the Time Zone and enabled Daylight Savings Time. Upon applying the setting it explained that a reboot was necessary. Rebooting caused my IP address to change (DHCP is the default) so I need to discover it again (Lift Receiver press MENU) to continue exploring the config.


The GrandStream BT-200; Exploring the Configuration:


Logging in as an "End User" (the default 123 password) allows you access to the Status and Basic Settings tabs. I clicked on the Advanced Settings and Account but received a rather unhelpful message: Access Denied Content-Type: text/html;charset=iso-8859-1 Server: Grandstream/1.10. It took some time to realize that you need to login as the "Admin" (the default admin password) on the initial login page. You cannot login as an End User and then escalate to the Admin. A nice "You need to login as the Admin" page would have been helpful.

Accessing the "Status" tab displays some information about the phone. In particular, it displays the Software Version. In my case, the installed Program-- 1.1.1.14 and Bootloader-- 1.1.1.5 versions seemed well behind the current version of the firmware displayed in the site (1.1.4.18). It seems that one of the first tasks will be to upgrade the firmware.


The GrandStream BT-200; Initial Tests:


Browsing through the manual, I noticed that it is possible to make IP to IP calls if you have multiple devices on the same network (subnet). To place a direct IP to IP call, first off-hook, then press the “MENU” key, then enter a 12-digit target IP address to make the call and press the SEND button.

This is where having multiple devices really has advantages when you are trying to understand VOIP and you want to verify that the phones actually work. With this out of the way (and a nice conversation with my 2 year old with the new phones) I was ready to look at the firmware upgrade.

Saturday, July 21, 2007

Migrating Evolution Contacts to Gmail

Evolution exports its contacts in a VCard format. You can simply select all contacts that you want to export and save a VCard. All VCards a saved in the same file.

Getting the contacts out of VCard format and into something that is usable for GMail takes a little Perl code. The following code creates a comma separated value format file in GMails native format. It currently only supports two sections Personal and Work.

The inspiration for this was is was based on the Linux Journal article at http://blog.ibao.net/linux/2004/07/19/export-evolution-address-book-to-gmailbut it was completely rewritten (well some cut and paste and editing) to take advantage of the GMail csv format that allows you to import your information into named sections. In addition, it properly formats the address (Canadian Standards)

No doubt you may need to modify it for your own use. That is fine, but this code is licensed under the terms of the GNU General Public Licence

You can download the code from: http://timlegge.googlepages.com/evol_gmail.pl

You should note that an issue in GMail results in being unable to view some imported contacts. The work around is to clear your cache and restart the browser.

I have updated the script recently to use alternative email addresses if they are available...

Saturday, October 23, 2004

Is knowledge creation unsustainable?

I don't often take exception to some of the opinions people have. Well, I guess I often take exception but I am rarely moved to write about it.

However, I read an article by on ft.com by Richard Epstein "Why open source is unsustainable" that essentially equates working on open source to a workers commune that produces some tangible goods.

I work on the free software Etherboot project and the code that I write or borrow from other GPL developers cannot be equated to a sack of potatoes.

Computer programming is essentially the creation of knowledge. Whether it is the knowledge of how to interact with a network card or how to download a file via tftp, it is documented in the source.

When I write an Etherboot driver for a network card I sometimes have access to the often flawed technical specifications from a vendor. However, I have written drivers with no technical reference other than the knowledge contained in a Linux driver. The difference is that while the knowledge contained in the driver C code may differ from the technical specifications, I know that the Linux driver works.

People outside the computer industry have been adding to the sum total of human knowledge for eons and I am doing my small part to help that. The fact that the knowledge can be "compiled" into an application that is useful to thousands of people is somewhat immaterial. The knowledge, unlike a sack of potatoes, lasts far past supper.

The creation of knowledge may be unsustainable but I suspect we have not yet reached that limit.