Archive for March, 02005

ECE540 Lecture #2: Topics in Network Security, WiFi Security, and High Speed Interconnects

Thursday, March 31st, 02005

Attendance/Participation/Homework

To obtain full credit for attendance and class participation, you must:

  1. Fill out your name and email address on an attendance sheet I'll pass out half way through class.
  2. Comment on this weblog entry, using the comment form.

Outline

Today's lecture will include detailed screenshots of some of the applications I talked about last time and cover:

  1. Lessons about giving tech demos
  2. What's WEP worth, if a potential eavesdropper has the key?
  3. Empirical versus theoretical research
  4. Ethereal usage
  5. More on nmap
  6. More on Netstumbler on Windows
  7. More on Kismet on Linux
  8. WiFi scanning with PDAs
  9. WEP and WEP weaknesses - technical details
  10. More on WEP cracking with Aircrack
  11. Improvements to WEP
  12. Modern high-speed interconnects
  13. Accuracy in specification and proper SI usage
  14. Concluding randomness / a fun idea for a summer project

Presentation materials

Presentation in PDF format (~ 1.5 MB)

Ward Churchill in San Francisco

Thursday, March 31st, 02005

Behold America's fringe, and draw your own conclusions, as Zombie gets it done with photo, audio, and video documentation of Ward Churchill speaking in the Bay Area:

You can't make this stuff up.

Backyard Sunset

Wednesday, March 30th, 02005

Here's a picture of Monday's sunset from my backyard, looking down into and across Albuquerque to Mount Taylor in the east.

Sunset

This kind of display is not atypical.

RAGBRAI resources

Wednesday, March 30th, 02005

I'm starting to really geek out about RABGRAI XXXIII. Plane tickets have been purchased, and I'm ready to travel. Some resources I found this morning:

RAGBRAI 2005 Route Map

ECE540 Lecture #1: Live Security Tool Demos + WiFi Security

Tuesday, March 29th, 02005

Yesterday morning, Dr. Jordán asked to give this week's ECE540 (Advanced Networking Topics) lectures. I only had a few hours last night to prepare, but I still think today's lecture will be very informative. I was hoping to give an equal balance to demo, theory, and technical detail, but due to limited prep time, today will mostly be demos and hands on material. Thursday's lecture will cover more of the theory.

Attendance/Homework

  1. Fill out the in-class attendance sheet
  2. Make at least one comment to this blog entry with a question or comment about today's lecture or a suggestion for Thursday. If possible, use your real name in the comments, so I know who has commented. If you'd rather use a pseudonym, because you don't want your name on my website, send me an email message letting be know how your pseudonym maps to your real name.

Outline

I'll try to cover the following topics in today's lecture:

  1. Live security audit of ECE network and bohnsack.com using the namp port scanner and other tools:
    • ECE webserver / bohnsack.com webserver
    • open services
    • firewalled services
    • OS fingerprint
    • service version detection
    • tape backup service?
    • problems with multiple services on a single box
    • How to hide/protect exposed services
    • dig
    • Network sweep (nmap -sS -O 192.168.1.0/24)
  2. Reacting to port scans: IDS, blackhole routes, etc.
  3. What good is WEP?
  4. Live packet sniffing using Ethereal (802.11b's layer 2 not shown, but possible. Is there a difference between sniffing a WEP-encrypted link and an open link?)
  5. War driving
  6. Live 802.11x scanning with Netstumbler on Windows (weak)
  7. Live 802.11x scanning with Kismet on Linux (much more 'leet)
  8. Live WEP attack demos:
  9. Alternative secure wireless architectures that don't rely on layer 2 encryption

Keith Jarrett

Wednesday, March 23rd, 02005

I've recently become a giant Keith Jarrett nut (so much so, that I almost no longer wish for the Glenn Gould De-Vocalizer 2000 Jarrett Module). I really must see him perform live, but Carnegie Hall on June 22nd might be a bit of a stretch. Do I risk assuming that the trio will play more US dates next year?

Vitamins

Sunday, March 20th, 02005

GIF animation of weekly vitamins (less the lunch time ones)

Morning on the left. Evening on the right. Lunchtime not shown.

Update with current program as of 02006-10-25

Supplement Dosage ~ Cost for 30-day Month
Super Nutrition, Easy Swallow Opti-Pack Iron Free 3 packets per day (morning, noon, evening) $ 30
Nature's Way, Alive! Multi-Vitamin 3 per day (morning, noon, evening) $ 12
Nordic Naturals, Ultimate Omega, 1000 mg 3 per day (morning, noon, evening) $ 31
Super Nutrition, Think Clearly 3 per day (morning, noon, evening) $ 14
Source Naturals, Alpha Lipoic Acid, 100 mg 2 per day (morning, evening) $ 15
Now Foods, Grape Seed Standardized Extract, 100 mg 2 per day (morning, evening) $ 6
Enzymatic Therapy, Garlinase Fresh 2 per day (morning, evening) $ 13
Now Foods, Phosphatidyl Serine, 100 mg, 1 per day (morning) $ 9
Now Foods, Curcumin, 665 mg 2 per day (morning, evening) $ 8
Now Foods, CoQ10, 30 mg 2 per day (morning, evening) $ 6
Now Foods, L-Carnosine, 500 mg 2 per day (morning, evening) $ 15
Nature's Way, Cayenne Extra Hot, 450 mg 2 per day (morning, evening) $ 3
Now Foods, Cinnamon Bark, 600 mg 2 per day (morning, evening) $ 4
Source Naturals, Vinpocetine, 10 mg 2 per day (morning, evening) $ 5
Now Foods, Spirulina 100% Natural Hawaiian, 500 mg 6 per day (3 morning, 3 evening) $ 5
Now Foods, DMG, 125 mg 1 per day (morning) $ 2
Nature's Way, Resveratrol Synergistic Formula 2 per day (morning, evening) $ 10
TOTAL $ 188

Archives

Sunday, March 20th, 02005

Steven recently left a worthwhile comment on one of my earliest blog entries from Aug 02000.

This caused me to look at my archives and realize that the transition from MovableType to WordPress left a lot of them in a strange state with respect to line breaks and formatting. I'm just officially noting this. I'll fix things eventually, but it might take some time.

US National Debt

Thursday, March 17th, 02005

As of today, the current US National debt is $7,755,070,133,634.15. This figure can be alternatively stated as:

  • $7.755 x 10^12
  • Seven point eight trillion US dollars
  • $26,248.59 for each of our estimated 295,684,246 citizens
  • 64% of 2005's estimated 12.04 trillion dollar US GDP (and this is only March!)

Also check out the U.S. National Debt Clock.

One's first reaction is "Holy sh#t!, bring out Ross Perot", but if you analyze things carefully, you'll see that although we're in some serious debt, we're not doing all that bad, if you look at debt as a percentage of GDP. Historically, we're doing OK against this benchmark.

Here's a graph I made, after combining data from two sources. The spreadsheet I used to make the graph is also available. Click on the graph for a larger version.

National Debt as a Percentage of GDP vs time

I'm not apologizing for deficit spending. I don't manage my personal finances this way, and I wish our government wouldn't either. However, while I'm still rooting for a little more of Greenspan's influence on our fiscal policy, I can see that the sky is definitely not falling from a historical perspective.

Animal vs Buddy Rich

Wednesday, March 16th, 02005

A must for fans of the Muppets and/or Buddy Rich (requires QuickTime):

Animal vs Buddy Rich

Odd Weather

Monday, March 14th, 02005

odd ABQ weather

odd ABQ weather

WTF is this? It was near 80 degrees last week. I turned my furnance off last Tuesday. It looks like I'll be turning it back on tonight.

Update Tue 02005/03/15 - The wettest winter in recorded New Mexico history continues with this freak snow storm:

snow! snow! snow!
snow!

Springtime UNM Campus

Monday, March 14th, 02005

Here are some photos I took of the UNM campus yesterday:

UNM Campus UNM Campus
UNM Campus UNM Campus UNM Campus

17th Annual National Fiery Foods and Barbecue Show

Monday, March 14th, 02005

I went to the 17th Annual National Fiery Foods and Barbecue Show yesterday.

It was downtown at the ABQ convention center:

downtown ABQ

There was lots of hot sauce. I bought about $50 worth:

Fire Fire Fire Fire
Fire Fire Fire Fire

I ate a chocolate covered Habanero, because I am 'leet. Jerry wouldn't eat one, 'cause he's a pansy:

Fire

1/8 Done with Grad School

Friday, March 11th, 02005

I finished my second midterm yesterday. Assuming I continue to take 2 classes each semester and ignoring the time needed to do my thesis, I'm around 1/8 of the way through my masters degree.

Sqeezebox2

Wednesday, March 9th, 02005

The sqeezebox2 is out...

sqeezebox2

New stuff:

Fairly elite DAC
802.11g
can work as a wireless bridge
built in FLAC support
Way better display
More on their website.

Fairly pricy at $299, but I might have to make it happen.

Juniper Pollen Count

Tuesday, March 8th, 02005

Anello's got this graph of the Albuquerque juniper pollen count thing going on. Nice, 'cause you can see trends vs time.

pollen count vs time

You'll note that it's started to suck fairly hard recently.

I think he's collecting the data from this page. It would be more elite if he put the captured data in an RRD, which can be used to create beauty graphs like this, but I'm not complaining. It would be nice, if the city of Albuquerque considered keeping this kind of historical data on their website.

I've had all but one juniper removed from my yard a few weeks ago and am planning on removing the last one this weekend.

White Board Walls

Monday, March 7th, 02005

I'm so covering the walls of my home office with whiteboards.

Market Hits 3.5 Year High

Friday, March 4th, 02005

In case you don't pay attention to this kind of thing, the stock market hit a 3.5 year high today, after a surprisingly strong job creation report.

S&P 500 1,222.12
Dow 10,940.55
Nasdaq 2,070.61

Candle Madness

Wednesday, March 2nd, 02005

Those were the best of times, but I'm still pissed that they didn't include me in the photo that made the paper.