Whether you call it "Fat Tuesday", "Mardi Gras", "Carnival", or "Day before Ash Wednesday", today is the last day before the fasting and penitential season of Lent. It is also Pancake Day!
The later may be more significant to many these days, but there was a time when the known universe operated in fear of, or under the rule of the Roman Empire that was fuelled primarily by the Catholic church, and no pancakes were served.
In any other measure, it is 47 days into the new year and the hours are ticking away. If you planned on making a difference this year, carpe diem and all that, it is time to start (if you have not already). In the days of the Roman Empire, when every day was critical to your survival, the 44 days of Lent had other important geo-political functions, and Fat Tuesday was a pretty significant day. Today, it is a good reminder that there are only 365 days in a year and this means we are well past the 10% point.
In the business world, it is critical to understand that this is also the point at which business gets back to business. The holidays are over, summer is on the distant horizon and there is a window of opportunity for the next few months to make your mark on the year. After three decades of working for a living, I've noticed these patterns emerge in every company I have worked for in every industry. There are always those people who don't take advantage of this opportunity and find them selves scrambling in the fall to make up for lost time.
It is a fabulous time of year to be creative. Writers, painters, and sculptors find inspiration in this time of year and with good reason. Not only is it the beginning of a season of fasting, it is also a season of new growth, rebirth and the melting away of icy oppression. Any hungry creative person should take heed of the chance to teach, build, write and generally do whatever they can to mold the world around them.
The Chinese call this the year of the Tiger (4707 post Huangdi) and in the tradition of the tiger, I plan to stalk and pounce on every opportunity. I think I wave written more this year already than I did most of last year. Unfortunately I have less time for pancakes.
Tuesday, February 16, 2010
Saturday, January 2, 2010

Happy New Year!
Welcome to 2010. Wow - There were a few times over the past decade that I thought I would not be saying that, but here we are - fat and happy in 2010.
Like most people I try to take some time today to be introspective, to take stock of who I am, where I'm going and where I've been. I like to crack open my resume and touch it up with all the new things I've learned over the past year, and to write a few "thank you" cards to people who have helped, inspired or somehow improved me as a person. This year will be no different except that I have been thinking over the past 10 years a little more.
What a decade this has been. We started by battling fears that 2000 would see a worldwide computer crash leading to feast, famine, accidental wars, and general badness. Well the crashes were minor and deserved, the plagues of locusts never appeared, and it turned out to be a lot more media hype than anything.
In 2000 I was working with First generation (28 million transistor) Pentium CPUs, movies were watched on TV and theatre screens, and a "Walkman" was still the device of choice for portable music. Ten years later, even compact notebook computers use multi core processors with nearly a billion transistors on a chip. YouTube has replaced all other forms of video entertainment as far as volume goes, and the iPod has completely revolutionized how we store, carry and listen to music.
I personally have seen a number of changes in my life that track with technology including a move from the sunny Okanagan Valley to Calgary in 2002, a complete transformation of my business between 2002 and 2006 and a new lifestyle that has me spending more time in jets than cars. I've been able to watch "robotics" grow from a hacker hobby into an actual industry, Ive seen the Internet transform from "tool" to "environment" and I've witnessed the birth of real virtual communities. This year I think I will spend a lot of time thinking about what the next decade will look like and what part I will play in it.
The past year has been an interesting adventure for me personally and in business. I have met many new people and learned many new things. I could easily argue that 2009 was the most tumultuous year of my life. Working with cutting edge technologies and with companies who are shaping the future is both exhausting and incredibly rewarding. I am privileged to be associated with a group of people who will create what they need if it does not exist yet or help a community fix technology that is broken. I am thrilled to see what is on the horizon just out of reach of the general population, but still find myself guessing at what is coming next. In 2009 I litterally spent more time in airports and on flights than I did driving my own car, yet I have more contact with my family and friends than ever before.
I am an inventor and a writer, a builder and a teacher. I have seen the world change dramatically over the past decade and I fully expect twice that volume of change again in the next 10 years. I plan to spend more time writing about what I see, know, and predict. I will spend more time with my family, even if I am on a plane. I will enjoy more music, food and video choices because of the emerging technologies around me. My creative energies will be focused on making lives easier through invention. Most of all I will learn to be even more accepting of change, embrace the unknown and forge ahead into the wilderness.
Happy New Year.
Sunday, November 29, 2009
Windows 7 - Finally something done right
About a year ago I dove into MS Vista with ugly results. I finally bailed completely on Vista in February of this year and blogged several different ways to remove it and replace with something else. When Windows 7 Beta released this year, I initially avoided it thinking the MS team couldn't possibly recover from the disaster known as Vista. I was wrong.
When I finally took the plunge and installed Win7 onto test box I was pleasantly surprised by the quick and clean install. Then I was even more impressed by the quick response to a restart and reconnect back into the network. After running Win7 through it's paces it appears that all the problem issues that were chronic with Vista have disappeared with this new version. In fact it is very clear that this isn't just a new version, this is a whole new ball game.
I was so impressed that I upgraded a number of systems to Win7 and have not looked back. That was a month or so ago and I have not had a single BSOD, network fail, inexplicable random restart or anything else I can really complain about. When it does break, it's completely acceptable and it does it with grace.
To put it in a nutshell, Win 7 is like all the great functional things from XP with all the cool views of Vista but all in "turbo" mode. The same box with Win7 runs considerably faster then on Vista or XP. Startup and shutdown both work faster and cleaner and applications respond faster.
I still love my Mac, but I'm not afraid to install Windows 7.
When I finally took the plunge and installed Win7 onto test box I was pleasantly surprised by the quick and clean install. Then I was even more impressed by the quick response to a restart and reconnect back into the network. After running Win7 through it's paces it appears that all the problem issues that were chronic with Vista have disappeared with this new version. In fact it is very clear that this isn't just a new version, this is a whole new ball game.
I was so impressed that I upgraded a number of systems to Win7 and have not looked back. That was a month or so ago and I have not had a single BSOD, network fail, inexplicable random restart or anything else I can really complain about. When it does break, it's completely acceptable and it does it with grace.
To put it in a nutshell, Win 7 is like all the great functional things from XP with all the cool views of Vista but all in "turbo" mode. The same box with Win7 runs considerably faster then on Vista or XP. Startup and shutdown both work faster and cleaner and applications respond faster.
I still love my Mac, but I'm not afraid to install Windows 7.
Monday, October 19, 2009
Malware and Social Engineering
They are getting smarter, so you need to be even smarterer. You are probably used to seeing bogus emails and web pop-ups telling you that your computer is infected and you need to download and install an antivirus program. Conveniently they always have one attached that is perfect for your computer. If you are not already aware - these are all malware - virus infectected files, spyware, trojans, and generally bad stuff.
No anti-spam/virus software company will ever send you a file directly to your email address and ask you to install it. They just don't. Even if you see a message pop up on your screen, the safest course of action is to open the security software you already have (you do have some right?) and manually run updates and scans from there.
What triggered this blog post was an email I received this morning from "Microsoft" essentially accusing me of spreading viral files. It occurred to me that many, many people may be convinced to open the attachment and infect them selves unwittingly just based on the fact that it appeared to have come from Microsoft. Here is the actual message:
Dear Microsoft Customer,
Starting 18/10/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.
To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.
Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.
Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division
Of course it is completely bogus. Microsoft does not monitor viral activity, particularly not down to an individual PC level. Even if Microsoft did see a problem, they would distribute a patch through their "update" services. However, all you have to do is to actually read it because people at Microsoft would not have let this go out with grammar and spelling mistakes.
This is typical of the growing trend in social engineering used by malware distributors. There are two common ways to infect computers - send an infected file to someone, or trick them in to infecting themselves. Don't be the later.
No anti-spam/virus software company will ever send you a file directly to your email address and ask you to install it. They just don't. Even if you see a message pop up on your screen, the safest course of action is to open the security software you already have (you do have some right?) and manually run updates and scans from there.
What triggered this blog post was an email I received this morning from "Microsoft" essentially accusing me of spreading viral files. It occurred to me that many, many people may be convinced to open the attachment and infect them selves unwittingly just based on the fact that it appeared to have come from Microsoft. Here is the actual message:
Dear Microsoft Customer,
Starting 18/10/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.
To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.
Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.
Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division
Of course it is completely bogus. Microsoft does not monitor viral activity, particularly not down to an individual PC level. Even if Microsoft did see a problem, they would distribute a patch through their "update" services. However, all you have to do is to actually read it because people at Microsoft would not have let this go out with grammar and spelling mistakes.
This is typical of the growing trend in social engineering used by malware distributors. There are two common ways to infect computers - send an infected file to someone, or trick them in to infecting themselves. Don't be the later.
Saturday, October 17, 2009
Calgary ... favouritism is okay... really...
The Calgary City council has just awarded a $300,000 re-branding contract ... to a US company. Not only is it a complete waste of taxpayer money to replace a perfectly good logo/brand that is very under utilized, but the award went to a US based company! In what dream scape is City council living?
1) We don't need it. The current branding may be 10 years old, but is still relevant, directed, and speaks to exactly what Calgary is all about.
2) Why send money away? How does it make any sense to send $300,000 to a private company in San Fransisco when there are a plethora of graphic design companies right here in Calgary that would take on this project? Did they completely ignore the adjacent impact of spin-off business this would create? If the money had been spend here in Calgary, many other subcontractors would have benefited as well. What happened to supporting the local economy? What gives them the right to send local tax payer dollars out of the city never mind out of the country? Where is their responsibility to the local taxpayer?
3) Waste, Waste, Waste. This seems to be a theme for Bronco and his gang. The last time a decision had me this incensed was when they spent half a million dollars on office chairs. WTF? There are hundreds of homeless people in this city who will need extra help this winter. There are community programs that need bolstering. There are schools that need new roofs. Seriously - $300,000 for a new sign? Come on!
4) It's irresponsible. They are using money that came from local taxpayers who work for local businesses and support other local businesses. We faithfully pay our taxes to the city with the expectation that they will spend it wisely on programs and services to help the local community. Sending my hard earned money to California, where it will not help any one in Calgary in any way shape or form is just irresponsible. They might as well have set fire to it.
If you haven't noticed yet, I'm pissed - and you should be too. How would city council take it if we just decided not to send them any tax money at all? That is basically what they have done to us here - taken our money and tossed it over the border like it doesn't even matter. I don't know about you but I work pretty hard for my money and I pay a good chunk to city and provincial taxes. It would be nice if our elected officials had enough respect for that money to spend it were it will benefit Calgarians most - right here at home.
1) We don't need it. The current branding may be 10 years old, but is still relevant, directed, and speaks to exactly what Calgary is all about.
2) Why send money away? How does it make any sense to send $300,000 to a private company in San Fransisco when there are a plethora of graphic design companies right here in Calgary that would take on this project? Did they completely ignore the adjacent impact of spin-off business this would create? If the money had been spend here in Calgary, many other subcontractors would have benefited as well. What happened to supporting the local economy? What gives them the right to send local tax payer dollars out of the city never mind out of the country? Where is their responsibility to the local taxpayer?
3) Waste, Waste, Waste. This seems to be a theme for Bronco and his gang. The last time a decision had me this incensed was when they spent half a million dollars on office chairs. WTF? There are hundreds of homeless people in this city who will need extra help this winter. There are community programs that need bolstering. There are schools that need new roofs. Seriously - $300,000 for a new sign? Come on!
4) It's irresponsible. They are using money that came from local taxpayers who work for local businesses and support other local businesses. We faithfully pay our taxes to the city with the expectation that they will spend it wisely on programs and services to help the local community. Sending my hard earned money to California, where it will not help any one in Calgary in any way shape or form is just irresponsible. They might as well have set fire to it.
If you haven't noticed yet, I'm pissed - and you should be too. How would city council take it if we just decided not to send them any tax money at all? That is basically what they have done to us here - taken our money and tossed it over the border like it doesn't even matter. I don't know about you but I work pretty hard for my money and I pay a good chunk to city and provincial taxes. It would be nice if our elected officials had enough respect for that money to spend it were it will benefit Calgarians most - right here at home.
Saturday, September 26, 2009
Exposing spammers
As a follow up to my last post on scripting firewall changes to drop spammer addresses.... here is a current list of all the IP addresses I have identified as spam sources. Feel free to use these in what ever way you like to block these evil bastards. All of the following addresses have been blocked from any access to my networks:
UPDATE!!!
I originally posted a list here but in the week after I wrote the script, the list grew to over 10,000 IP addresses - obviously too long a list to post in the blog. This list appears to be mostly "Zombies" so if you are having any difficulty accessing my website (mairs.ca or aasland.com) then it is very likely your IP has been blocked through this list and your PC may have been turned into a zombie mailer - and you may not even know it. If your public IP appears on this list, please let me know.
The current list is posted at http://www.mairs.ca/zombies.txt
UPDATE!!!
I originally posted a list here but in the week after I wrote the script, the list grew to over 10,000 IP addresses - obviously too long a list to post in the blog. This list appears to be mostly "Zombies" so if you are having any difficulty accessing my website (mairs.ca or aasland.com) then it is very likely your IP has been blocked through this list and your PC may have been turned into a zombie mailer - and you may not even know it. If your public IP appears on this list, please let me know.
The current list is posted at http://www.mairs.ca/zombies.txt
Thursday, September 24, 2009
Hitting back at spammers
I manage a network of servers that include mail servers, web services, and file sharing and I have been doing so for a number of years. One of the most prevalent maintenance issues for me has always been dealing with spammers. These guys have no respect for the general rules and will insist on sending their crap to you even if you are very specific about not wanting it. The thing with spam is that it is not just an email problem. When a spammer slams an email server with millions of bogus messages, often to bogus accounts, it takes a huge toll on the firewall, spam and antivirus processors, and can seriously degrade overall network performance. Simply sending back a "550 - no such mailbox" message only adds to the network traffic and encourages them to try a different mix of fake addresses.
So say goodbye to "Mr. Nice Guy", I am taking the gloves off and delivering an uppercut right to the jaw. I recently wrote a chunk of batch script to identify the hard core spammers who waste all my system resources and just drop their connections cold. This way they will still hit my firewall for a while, but when they realize the server effectively no longer exists, they will take my IP off their list and I will be free of the annoyance.
How does it work? It's really pretty simple. Here is an an example from a Sendmail server I am still using. When one of those annoying people connect to my server, one of the first things they do is check to see if I'll relay mail so it can turn me into a zombie mailer... not gonna happen bud. What ends up happening is that my logs fill up with this garbage:
Sep 24 21:37:20 mairs sendmail[17608]: ruleset=check_relay, arg1=[114.238.85.247], arg2=114.238.85.247, relay=[114.238.85.247], reject=550 5.7.1 Fix reverse DNS for 114.238.85.247,or use your ISP server
Sep 24 21:37:37 mairs sendmail[17610]: ruleset=check_relay, arg1=[190.213.91.165], arg2=190.213.91.165, relay=[190.213.91.165], reject=550 5.7.1 Fix reverse DNS for 190.213.91.165,or use your ISP server
Sep 24 21:38:34 mairs sendmail[17612]: ruleset=check_relay, arg1=[123.17.228.211], arg2=123.17.228.211, relay=[123.17.228.211], reject=550 5.7.1 Fix reverse DNS for 123.17.228.211,or use your ISP server
The cool think about this is that regardless of what hostname they are trying to spoof, the originating IP address is right there for me to grab and use against them. So that is exactly what I did... I wrote a script to pass through my daily logs, pick out the IP addresses on these offending lines, and add them to my firewall rules with a silent "DROP". They never get any feedback, not even a ping response, so to them, the server is dead - a non existent IP.
In the first day, it dropped my spam volume to about a quarter and now it is virtually non-existent. The 30 or 40 spam messages a day I get now are nothing compared to the hundreds of thousands that were filling my logs 2 weeks ago.
Here is the actual script in case you want to run it on your own server. This was built for a CentOS 5.3 i386 server - make the appropriate adjustments for your platform. This should be run on a cron daily just before the log rotation. Alternately you could run it just after log rotation and alter the script to read maillog.1.
The /etc/cron.d job:
45 23 * * * root /home/tmairs/spamkiller >/dev/null 2>&1
The script:
#!/bin/bash
# get list of spammer IP addresses and save to temporary file
exec cat /var/log/maillog | grep check_relay | awk '{ print $8 }' | sort | uniq > /tmp/spammerlist
fname=/tmp/spammerlist
# read file sequentially
while read line
do
# pick off the first address
badaddr=${line/,/}
badaddr1=${badaddr/arg2=/}
# add a rule to drop them at the firewall
exec /sbin/iptables -A INPUT -s ${badaddr1} -j DROP | echo
# loop till it's done.
done <$fname
# save the new IP tables config
exec /sbin/iptables-save
# kill the temp IP file
exec rm /tmp/spammerlist -f
# end
So say goodbye to "Mr. Nice Guy", I am taking the gloves off and delivering an uppercut right to the jaw. I recently wrote a chunk of batch script to identify the hard core spammers who waste all my system resources and just drop their connections cold. This way they will still hit my firewall for a while, but when they realize the server effectively no longer exists, they will take my IP off their list and I will be free of the annoyance.
How does it work? It's really pretty simple. Here is an an example from a Sendmail server I am still using. When one of those annoying people connect to my server, one of the first things they do is check to see if I'll relay mail so it can turn me into a zombie mailer... not gonna happen bud. What ends up happening is that my logs fill up with this garbage:
Sep 24 21:37:20 mairs sendmail[17608]: ruleset=check_relay, arg1=[114.238.85.247], arg2=114.238.85.247, relay=[114.238.85.247], reject=550 5.7.1 Fix reverse DNS for 114.238.85.247,or use your ISP server
Sep 24 21:37:37 mairs sendmail[17610]: ruleset=check_relay, arg1=[190.213.91.165], arg2=190.213.91.165, relay=[190.213.91.165], reject=550 5.7.1 Fix reverse DNS for 190.213.91.165,or use your ISP server
Sep 24 21:38:34 mairs sendmail[17612]: ruleset=check_relay, arg1=[123.17.228.211], arg2=123.17.228.211, relay=[123.17.228.211], reject=550 5.7.1 Fix reverse DNS for 123.17.228.211,or use your ISP server
The cool think about this is that regardless of what hostname they are trying to spoof, the originating IP address is right there for me to grab and use against them. So that is exactly what I did... I wrote a script to pass through my daily logs, pick out the IP addresses on these offending lines, and add them to my firewall rules with a silent "DROP". They never get any feedback, not even a ping response, so to them, the server is dead - a non existent IP.
In the first day, it dropped my spam volume to about a quarter and now it is virtually non-existent. The 30 or 40 spam messages a day I get now are nothing compared to the hundreds of thousands that were filling my logs 2 weeks ago.
Here is the actual script in case you want to run it on your own server. This was built for a CentOS 5.3 i386 server - make the appropriate adjustments for your platform. This should be run on a cron daily just before the log rotation. Alternately you could run it just after log rotation and alter the script to read maillog.1.
The /etc/cron.d job:
45 23 * * * root /home/tmairs/spamkiller >/dev/null 2>&1
The script:
#!/bin/bash
# get list of spammer IP addresses and save to temporary file
exec cat /var/log/maillog | grep check_relay | awk '{ print $8 }' | sort | uniq > /tmp/spammerlist
fname=/tmp/spammerlist
# read file sequentially
while read line
do
# pick off the first address
badaddr=${line/,/}
badaddr1=${badaddr/arg2=/}
# add a rule to drop them at the firewall
exec /sbin/iptables -A INPUT -s ${badaddr1} -j DROP | echo
# loop till it's done.
done <$fname
# save the new IP tables config
exec /sbin/iptables-save
# kill the temp IP file
exec rm /tmp/spammerlist -f
# end
Subscribe to:
Posts (Atom)