Saturday, August 8, 2009

Fun with grep

I got a copy of the Grep Pocket Reference back in early July via PDF format (from O'Reilly's Safari Bookshelf). I read through it but didn't really learn that much.

Last week the hard copy version arrived (2 weeks after I ordered it from Amazon). I've been reading it the last week. The parts I'm going through right now talks about Regular Expressions (regex). I've read about regex more times than I can count, in classes, in shell scripting books, on the web. This time it made sense.

My firewall log parsing for ip addresses has really improved. For example. I'd usually do "grep '< my ip address >' /external/logs/firewall1". The problem my address at work is .18, but it would pull .181 - .189 also. The first thing I did was back slash the . (dots) in the ip address. It cleaned up some stuff from the logs but not much. It's nicer to know that's not looking for any character and only matching what I want it too.

Which was a problem I was having when I wrote failed a few years ago.

Yesterday I read about word boundaries. I tested it this morning with my work IP address, and no longer am I getting the .181 - .189 addresses. Which is fun. It'll make looking for some things easier in the logs at work.

-------

Just for fun, here is what the finished version of Failed looked like (modified slightly):

#! /bin/sh
# checks for /var/log/auth.log for login failures.
# version 0.2
# < my email address removed >

# prints failed invalid users
echo "Failed Invalid User Attempts"
sudo grep "Failed" /var/log/auth.log | grep -i 'invalid' | grep -v '< work login id removed >' | awk '{print $1,$2,$3,$13,$11}' | sort -u

echo ' '
#prints failed vailid users, except for me.
echo "Failed Valid User Attempts"
sudo grep "Failed" /var/log/auth.log | grep -vi 'invalid' | grep -v '< work login id removed >' | grep -v '< home login id removed >' | awk '{print $1,$2,$3,$11,$9}' | sort -u
echo ' '

------

I sudo the 2 lines, because I need to be root to access that log file. I didn't want to setuid the script to run, nor did I want to be root when I ran it. It also requires me to type my password to run it, since sudo only remembers my password for 5 minutes.

To make this work on Redhat based systems, change auth.log to secure.log

Thursday, August 6, 2009

One thing I'd like to see..

There is one thing I'd like to see die out during this recession (besides the robber barons who own the banks and our government).

The hundreds of IT Contract firms.

I'll look at my daily email from Dice.com, and I'll see the same job posted 4 or 5 times for by different contract places. It's just as bad when a large company posts a job opening. I'll get emailed and called by about 5 to 10 (been closer to 5 lately which is a good thing in my book) head hunters who all want me to apply for the same position. Half the time, the position isn't where they were told it would be.

I had one Contract firm in the past tell me if I applied through them, I was only allowed to use them. I don't see them around much, nor did they ever have many positions listed. When the contact point I was "working with left" I got an email from the person who picked up her "assets". She asked what the person was working on with me. I said I hadn't heard from the person in over a year. I never heard back from her either.

The other thing that irked me. I had just passed the first part of the LPI level 1 exam (this was back when there were only 2 levels), and I had to take their test to prove I was "qualified" for a Linux admin position. Their test was easier than the LPI exam, and I know I did good on it, but I was told I failed it. But the first contact point never said by how bad, or gave me a % or told me were my weak areas were. Thinking about it now, I wonder why her replacement asked how I did on the exam, instead of looking it up herself.

Companies use the contract firms because it's cheaper (especially in MI where there is a new employee tax). Hopefully like out sourcing to India, I hope they realize this is a bad thing and start doing direct hires again. Because seriously with as high as the current unemployment rate is (15.2% according to my latest google search (for June 2009)), the contract firms aren't giving a good indicator of recovery by having the same job posted multiple times.

Wednesday, August 5, 2009

used to be better.

69 push ups today.

week 1, day 2 of the 100 push-ups.
31 in the last round.

blood and burpees

Tang Soo Do last night was strange. I was told that the kids' class was off the hook. Must have been a full moon or something.

I walked into the adult class at 7:20. Class starts at 7pm, and I'm usually there for the kids class, but was stuck at work trying to get a server to build. (Still having problems with the server today).

First thing that happens, as soon as I set my water bottles down, one of the white belts turns and hits the another one. These are the new problem children we have. Spoiled if you ask me. They don't tend to listen very well, and will try to argue with the instructors, including the Master.

They were supposed to be in formation waiting to start forms, as Master Tom was telling Bran (3rd gup) what to go over( and they both came over to say hi, you're late). They were left in Chun Be, knowing that forms were coming, the one decided to show off that he knew how the form started. Doing so, caused him to hit the other white belt, who was holding his stance. Which lead the other white belt to using an open hand strike to the first one's arm. Smacked pretty loud.

I watched it happen. First words out of my mouth, were "down for push-ups" not the first time I've given push-ups before even having time to change (although this was the first time I got blank looks from the students, although Bran dropped quickly). When I said down, the one that started it dropped to the ground grabbed his arm and started crying. This was about 30 seconds after being hit. The Master took the crying kid out of the class, and talked to him. The other one started to do push-ups with us, and then stopped and stood back up. I held the 7th and 9th gups in a high plank (Bran was doing them with us too). I lost count telling the 10th gup we were waiting on him. So we started over. We did 20 more. (Bran said it worked out to 30+).

Then the Master took the other kid out into the hall and had a talk with him. Then I talked with the master, before running to the locker room to change.

Came back in training clothes (toe balk and belt), and Bran came over said they've been that way the whole night. The kids class got about a 10 minute talking to before being dismissed at the end.

The adult class got to work Bo form. I was told I'm testing for 1st gup on September 1st, and it's ok if I don't know bo, knife, or chilson E ru, I'll get those down before my 1st Dan test later (about 3 months after 1st gup). Just a little excited. Of course Saturday, the Master said he keeps thinking I'm a 1st gup already.

We spared some at the end of class. I got a little too predictable in fighting Jay (3rd gup). He's rather tall, so has reach. In the fights he'll back off and catch his breath. I've gotten into the habit of shuffling in to make my attacks against him. He backed off, and we both started moving towards each other at the same time. Me with a shuffle to jam, him with a back fist. His back fist got past my guard and nailed my nose. It felt like it was running but there was nothing coming out of it. Tested it a few times during the match. My eyes were watering. I was more mad at him stopping the fight than I was being hit.

I can understand wanting to stop and make sure I'm ok. He kept apologizing about it, but it happens, and I wasn't bothered by it. See Jay used to be one of the clubs better tournament fighters, so he'll get a couple hits in, maybe score a point and then backs off. He says he does that on the street too, and wants to break that habit. So after being hit, I checked my nose, and came right back at him. Teared up eyes and all. I try to base my fighting more on what I think the street style is, don't stop until someone can't get back up.

After the sparring was over, I checked my nose again, and it was bleeding quite well. Blood on the front of my Toe Balk, and both sleeves. The Master saw it, asked who was bleeding. I said it was mine (used the non-blood sleeve to prove it).

Then we got to do tradition. In class on or after your Birthday (rarely the day before), we do push-ups. 1 for every year. When Master P's bday comes around we all hate it, since the numbers are in the 70s. This year, to mix it up some. We did burpees, my request. My original goal was to do all 32 with out stopping at a slower pace for everyone to keep up. However with the bleeding nose (I figured I'd worry about it after class), it was a little hard to breath. So we did sets of 10, 10 and 12. Bran and I were the only 2 to do all 32, and he got done before me.

After the first step, I went to the sink and spit up the blood that ran down the back of my nose, while trying to breath) and found some paper towel to blow into. Repeat the blow after the second set. bowed out after the 3rd set to go home. While we were supposed to be meditating and getting comments on class from the master (the after class speech), I held my nose to get the bleeding to stop.

Last night was so much fun.

Monday, August 3, 2009

let's try this again.

push ups. week 1, day 1...

10
12
8 (should have been 7 but hit a groove).
7
20

Hard and out of breath. I'm just not used to it any more. It has been 3 weeks since I hurt my elbow. It still hurts to touch it, if the arm is out straight, bent doens't matter. At least it doesn't just hurt all the time anymore.

But taking 3 weeks off, and eating badly last week didn't help matters (fast food everyday for lunch).

body fat check

233.5 lbs (I've got the number right this time).

41 waist (at navel)
43 hips
13 forearm
8 wrist

You have 19.4% body fat.

You have 45.2 Pounds of fat and 187.8 Pounds of lean (muscle, bone, body water).

according to the body fat check site I've been using, anyway.

I weighed less a few weeks ago. Probably should have done it then. Still in the 2 months it's been since my last check, I'm 7 lbs lighter, with 1 inch gone from the wait and hips.

Saturday, August 1, 2009

I'm jumping on the band wagon...

...I'm just late that's all.

So I'm thinking about passwords lately. With Black Hat and Defcon this week, the report that some big name Infosec people had their accounts broke into, a friend's tweet on getting 400 followers, and me having to change my FB password today, I thought I'd share how I come up with passwords.

Now for fun the other night, driving back from Tang Soo Do on a long and lonesome highway east of Omaha... I came up with about 15 or so passwords based off a tv show I liked. They were between 8 to 10 characters each.

So there are a few ways I do it. There are 2 examples in each.

Method One:
I'll take a phrase, the longer the better, and modify it.
The quick red fox jumps over the lazy brown dog (a well known pangram , ie uses all the characters in the English language) or I'm here to chew bubble gum and kick arse and I'm all out of bubble gum (mainly because I'm fond of quotes).
I'll take the phrase, and use camel case (mixed case), with numbers, special characters (anything over the number keys), and letters. I'll then mix them up like below:

Th3Qu!ckBrownF0xJump3s_Over_the_L2zy_red_dog

I'm_h3r3_2ch3w_BubbleGum&kick@rse.&I'm@ll0ut_ofBubbleGum

I can mix them other ways too. For example, I swapped brown and red, just to make it a little different.

Method Two:
I'll take a song lyric or a line from a movie, tv show, or whatever and I'll modify it by using just the first letter of each word, and the some of the other steps above. Examples I'll uses are Seger's Turn the Page, and a line from Cool Hand Luke.

"On an long and lonesome highway east of Omaha" becomes:

0@L&lh3oO!

"What we've got here is... failure to communicate. Some men you just can't reach. So you get what we had here last week, which is the way he wants it... well, he gets it"

Wwgh!F2c.SmUjcr=SugWwhHlw,W!twhWi_whg!! (to be honest, I'd modify it a little more, and weighing in around 30 characters, I'd use that for a pass phrase for my encrypted hard drive).

There are some other rules I use, if you notice, I have 2 characters side by side, 1 will be cap, 1 will not be. I tend to use the 2 interchangeably at home and at work, so we have phrase on some boxes, and the vegitable soup on others.

Lastly Method 3, which I only use on rare occasions is:
pwgen (password generator) from the linux command line. I'll add options like at least 1 special character, 1 upper case, 1 number and set it to be 10 to 12 characters long.

and finally...
I tend to use password safes, with things divided in them. Keepass and Password Safe.

I have had a few users complain when I give them a 10 to 12 character password based on something they said in the conversation. 1 about being long, and 2 about being so random, but when I tell them I use 24 to 26 character passwords regularly they tend to think it's not that bad and they seem to remember what they got fairly well.

There are other ways to make passwords too, and if you google them, I suggest googling site:lifehacker.com

Have fun, be safe online and for extra credit, figure out why I think this is a bad password. BwDn$b! (there are 2 reasons I don't like it).