|
So hiera wasn’t working when used through my puppetmaster. It worked perfectly when I was running my scripts manually with: puppet apply site.pp but the moment I switched over to regular puppetmasterd usage, everything went dead. I realized a while back, that I could always expect some hiera failures from time to time. Whether this is hiera’s fault or not is irrelevant, the relevant part is that I quickly added:
|
|
So hiera wasn’t working when used through my puppetmaster. It worked perfectly when I was running my scripts manually with: puppet apply site.pp but the moment I switched over to regular puppetmasterd usage, everything went dead. I realized a while back, that I could always expect some hiera failures from time to time. Whether this is hiera’s fault or not is irrelevant, the relevant part is that I quickly added:
|
|
What the heck is the INTERNAL_FUNCTION in execution plan predicate section?
-
tanelpoder.com
-
13 years ago
-
eng
Sometimes you see something like this in an execution plan: -------------------------------------------------------------------------- | Id | Operation | Name | Rows | Bytes | Cost (%CPU)| Time | -------------------------------------------------------------------------- | 0 | SELECT STATEMENT | | | | 2 (100)| | |* 1 | TABLE ACCESS FULL| T | 1 | 22 | 2 (0)| 00:00:01 | -------------------------------------------------------..
|
|
What the heck is the INTERNAL_FUNCTION in execution plan predicate section?
-
tanelpoder.com
-
13 years ago
-
eng
Sometimes you see something like this in an execution plan: -------------------------------------------------------------------------- | Id | Operation | Name | Rows | Bytes | Cost (%CPU)| Time | -------------------------------------------------------------------------- | 0 | SELECT STATEMENT | | | | 2 (100)| | |* 1 | TABLE ACCESS FULL| T | 1 | 22 | 2 (0)| 00:00:01 | -------------------------------------------------------..
|
|
Interesting and apparently very lucrative application of a business practice all too prevalent throughout this nation by an individual. Permalink.
|
|
Speaking of talking about other writers’ tools and processes, here’s Shawn Blanc searching for a replacement to an integral part of his workflow as a writer, Simplenote. Not a day goes by that I don’t use Simplenote, and unfortunately I’ve noticed some of the synching problems he has. Nevertheless Simplenote remains the best on the market, and for that single reason I will continue to keep all my notes, to write all my articles, and to stor..
|
|
Always interesting to read about another writer’s tools and setup, and Matt Gemmell’s style makes this piece all the more pleasurable to read. “What you’re seeing through the window is Outside. Now, I’m not a massive fan of Outside, generally speaking - I’m of the belief that we coped with Outside for a long time, until we finally invented Inside, and then breathed a huge sigh of relief - but it can really clear your head and restore so..
|
|
In the previous post I gave a glimpse of the Javascript Promises Pattern (JPP). Now we are going to take a more in deep look into it and implement our (simplified) version of this pattern. First of all, let’s sow the code I we defined works: we had three operations (to make the example simpler, they all share the same code, but this is not a requisite), each of them expecting a set of arguments which are processed by an asynchronous ope....
|
|
Kas Thomas on how to write an opening sentence, drawing on his extensive writing career as well as a number of books on the subject. I particularly liked how he pointed out the openers prominent writers use over and over again. Definitely something to keep in mind when writing. “These aren’t all the possible ways to start a piece, but if you’re completely stuck, one of them should work. If not? Surprise the world with something outlandi..
|
|
Why We're Raising the Signature Threshold for We the People
-
www.whitehouse.gov
-
13 years ago
-
eng
After the petition to build a Death Star and the petition to remove Ortiz from her position at the Department of Injustice (oops, a typo) all garnered the required 25,000 signatures, I suppose it’s not surprising. Sam Byford has more on this in his post After Death Star and deportation petitions, White House raises signature threshold to 100,000 on The Verge. Permalink.
|
|
The Days When We Had Rest, O Soul, for They Were Long
-
jacobbacharach.wordpress.com
-
13 years ago
-
eng
An interesting article posted over on Blogarach in response to Aaron Swartz’s death. Even more impressive is that it’s a single, extremely well-written sentence. Worth the read even if you are not following the tragedy that is Aaron Swartz’s suicide. Permalink.
|
|
Thirty-eight minutes and eleven seconds in to the eighteenth episode of The B&B Podcast , Shawn Blanc, in response to Ben Brooks talking about the salient point of his Lion review, said, “If you can’t boil down your whole article into a tweet, what are you doing writing the article in the first place?” Amidst a discussion regarding Ben and Shanw’s recent Lion and Web OS reviews, respectively, this humble observation is easy to miss as it..
|
|
An article from Ben Brooks posted in November of last year I had near the middle of my Simplenote list, burried beneath a slew of notes, ideas, and half-baked articles. I’m not interested in writing when it’s not about the writing. iBooks Author is neat, but I don’t want to learn it - instead I’ll just “publish” the book here as a series of posts, where I know what I am doing (somewhat) and where writing is about writing and not layout,..
|
|
Another year, another batch of packet related stunts. A preview: A Temporal Attack against IP It is commonly said that IP is a stateless protocol. This is not entirely true. We will discuss a mechanism by which IP's limited stateful mechanisms can be exploited to fingerprint operating systems and to evade most intrusion detection systems. Application-layer attacks against MD5 We will show how web pages and other executable environme....
|
|
Another year, another batch of packet related stunts. A preview: A Temporal Attack against IP It is commonly said that IP is a stateless protocol. This is not entirely true. We will discuss a mechanism by which IP's limited stateful mechanisms can be exploited to fingerprint operating systems and to evade most intrusion detection systems. Application-layer attacks against MD5 We will show how web pages and other executable environme....
|
|
Dr. Linton Wells II, Assistant Secretary of Defense for Networks and Information Integration / CIO Dr. Linton Wells, II was named Principal Deputy Assistant Secretary of Defense for Command, Control, Communications and Intelligence (C3I) on August 20, 1998, and serves in that capacity in the C3I successor organization, Networks and Information Integration (NII). In addition, Dr. Wells serves as Acting Deputy Assistant Secretary of Defe....
|
|
Dr. Linton Wells II, Assistant Secretary of Defense for Networks and Information Integration / CIO Dr. Linton Wells, II was named Principal Deputy Assistant Secretary of Defense for Command, Control, Communications and Intelligence (C3I) on August 20, 1998, and serves in that capacity in the C3I successor organization, Networks and Information Integration (NII). In addition, Dr. Wells serves as Acting Deputy Assistant Secretary of Defe....
|
|
While many security practitioners use Nmap, few understand its full power. Nmap deserves part of the blame for being too helpful. A simple command such as "nmap scanme.insecure.org" leaves Nmap to choose the scan type, timing details, target ports, output format, source ports and addresses, and more. You can even specify -iR (random input) and let Nmap choose the targets! Hiding all of these details makes Nmap easy to use, but also easy to ....
|
|
While many security practitioners use Nmap, few understand its full power. Nmap deserves part of the blame for being too helpful. A simple command such as "nmap scanme.insecure.org" leaves Nmap to choose the scan type, timing details, target ports, output format, source ports and addresses, and more. You can even specify -iR (random input) and let Nmap choose the targets! Hiding all of these details makes Nmap easy to use, but also easy to ....
|
|
In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....
|
|
In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....
|
|
Wesley Tanner and Nick Lane-Smith: End-to-End Voice Encryption over GSM: A Different Approach
-
www.defcon.org
-
13 years ago
-
eng
Where is end-to-end voice privacy over cellular? What efforts are underway to bring this necessity to the consumer? This discussion will distill for you the options available today, and focus on current research directions in technologies for the near future. Cellular encryption products today make use of either circuit switched data (CSD), or high latency packet switched networks. We will discuss the advantages and disadvantages of....
|
|
Wesley Tanner and Nick Lane-Smith: End-to-End Voice Encryption over GSM: A Different Approach
-
www.defcon.org
-
13 years ago
-
eng
Where is end-to-end voice privacy over cellular? What efforts are underway to bring this necessity to the consumer? This discussion will distill for you the options available today, and focus on current research directions in technologies for the near future. Cellular encryption products today make use of either circuit switched data (CSD), or high latency packet switched networks. We will discuss the advantages and disadvantages of....
|
|
Robert E. Lee & Jack C. Louis:Introducing Unicornscan - Riding the Unicorn
-
www.defcon.org
-
13 years ago
-
eng
Unicornscan is an open source (GPL) tool designed to assist with information gathering and security auditing. This talk will contrast the real world problems we've experienced using other tools and methods while demonstrating the solutions that Unicornscan can provide. We will use Unicornscan to collect information from large networks, data mine the collected information, and test systems for susceptibility to specific vulnerabilities.....
|
|
Robert E. Lee & Jack C. Louis:Introducing Unicornscan - Riding the Unicorn
-
www.defcon.org
-
13 years ago
-
eng
Unicornscan is an open source (GPL) tool designed to assist with information gathering and security auditing. This talk will contrast the real world problems we've experienced using other tools and methods while demonstrating the solutions that Unicornscan can provide. We will use Unicornscan to collect information from large networks, data mine the collected information, and test systems for susceptibility to specific vulnerabilities.....
|
|
This presentation describes the possibilities of steganographically embedding information in the "noise" created by automatic translation of natural language documents. An automated natural language translation system is ideal for steganographic applications, since natural language translation leaves plenty of room for variation. Also, because there are frequent errors in legitimate automatic text translations, additional errors inserted by....
|
|
This presentation describes the possibilities of steganographically embedding information in the "noise" created by automatic translation of natural language documents. An automated natural language translation system is ideal for steganographic applications, since natural language translation leaves plenty of room for variation. Also, because there are frequent errors in legitimate automatic text translations, additional errors inserted by....
|
|
Ofir Arkin, A New Hybrid Approach for Infrastructure Discovery, Monitoring and Control
-
www.defcon.org
-
13 years ago
-
eng
An enterprise IT infrastructure is a complex and a dynamic environment that is generally described as a black hole by its IT managers. The knowledge about an enterprise network's layout (topology), resources (availability and usage), elements residing on the network (devices, applications, their properties and the interdependencies among them) as well as the ability to maintain this knowledge up-to-date, are all of critical for managing a....
|
|
Ofir Arkin, A New Hybrid Approach for Infrastructure Discovery, Monitoring and Control
-
www.defcon.org
-
13 years ago
-
eng
An enterprise IT infrastructure is a complex and a dynamic environment that is generally described as a black hole by its IT managers. The knowledge about an enterprise network's layout (topology), resources (availability and usage), elements residing on the network (devices, applications, their properties and the interdependencies among them) as well as the ability to maintain this knowledge up-to-date, are all of critical for managing a....
|
|
Ofir Arkin, On the Current State of Remote Active OS Fingerprinting
-
www.defcon.org
-
13 years ago
-
eng
Active operating system fingerprinting is a technology, which uses stimulus (sends packets) in order to provoke a reaction from network elements. The implementations of active scanning will monitor the network for a response to be, or not, received from probed targeted network elements, and according to the type of response, and the conclusions following (part of an implementation"s intelligence), knowledge will be gathered about the underl....
|
|
Ofir Arkin, On the Current State of Remote Active OS Fingerprinting
-
www.defcon.org
-
13 years ago
-
eng
Active operating system fingerprinting is a technology, which uses stimulus (sends packets) in order to provoke a reaction from network elements. The implementations of active scanning will monitor the network for a response to be, or not, received from probed targeted network elements, and according to the type of response, and the conclusions following (part of an implementation"s intelligence), knowledge will be gathered about the underl....
|
|
Bastille has been re-released as an assessment and hardening tool. With the help of the US Government's TSWG, we've added full hardening assessment capabilities, complete with scoring. This allows Bastille to measure and score an individual system's security settings against user-provided guidelines, possibly before allowing a system onto the network. Security or system administrators can use this to assess the relative state of a given sys....
|
|
Bastille has been re-released as an assessment and hardening tool. With the help of the US Government's TSWG, we've added full hardening assessment capabilities, complete with scoring. This allows Bastille to measure and score an individual system's security settings against user-provided guidelines, possibly before allowing a system onto the network. Security or system administrators can use this to assess the relative state of a given sys....
|
|
Marshall Beddoe, Reverse Engineering Network Protocols using Bioinformatics
-
www.defcon.org
-
13 years ago
-
eng
Network protocol analysis is currently performed by hand using only intuition and a protocol analyzer tool such as tcpdump or Ethereal. This talk presents Protocol Informatics, a method for automating network protocol reverse engineering by utilizing algorithms found in the bioinformatics field. In order to determine fields in protocol packets, samples are aligned using multiple string alignment algorithms and their consensus sequences are ..
|
|
Marshall Beddoe, Reverse Engineering Network Protocols using Bioinformatics
-
www.defcon.org
-
13 years ago
-
eng
Network protocol analysis is currently performed by hand using only intuition and a protocol analyzer tool such as tcpdump or Ethereal. This talk presents Protocol Informatics, a method for automating network protocol reverse engineering by utilizing algorithms found in the bioinformatics field. In order to determine fields in protocol packets, samples are aligned using multiple string alignment algorithms and their consensus sequences are ..
|
|
Daniel Burroughs, Development of An Undergraduate Security Program
-
www.defcon.org
-
13 years ago
-
eng
At the University of Central Florida, an undergraduate program in security is currently being developed. This program will offer students a bachelor's degree through the College of Engineering. It is intended to be an interdisciplinary degree combining coursework from the School of Engineering and Computer Science, College of Health and Public Affairs, and the National Center for Forensic Studies. The purpose of this talk is to present....
|
|
Wes Brown & Scott Dunlop, Mosquito - Secure Remote Code Execution Framework
-
www.defcon.org
-
13 years ago
-
eng
Mosquito is a lightweight framework to deploy and run code remotely and securely in the context of penetration tests. It makes a best effort to ensure that the communications are secure. Special care is taken to ensure that deployed code is not stored outside of process memory space, making it difficult for an eavesdropper to obtain the code. It protects the confidentiality and trade secrets of code that is deployed and run on the target, w....
|
|
Daniel Burroughs, Development of An Undergraduate Security Program
-
www.defcon.org
-
13 years ago
-
eng
At the University of Central Florida, an undergraduate program in security is currently being developed. This program will offer students a bachelor's degree through the College of Engineering. It is intended to be an interdisciplinary degree combining coursework from the School of Engineering and Computer Science, College of Health and Public Affairs, and the National Center for Forensic Studies. The purpose of this talk is to present....
|
|
Wes Brown & Scott Dunlop, Mosquito - Secure Remote Code Execution Framework
-
www.defcon.org
-
13 years ago
-
eng
Mosquito is a lightweight framework to deploy and run code remotely and securely in the context of penetration tests. It makes a best effort to ensure that the communications are secure. Special care is taken to ensure that deployed code is not stored outside of process memory space, making it difficult for an eavesdropper to obtain the code. It protects the confidentiality and trade secrets of code that is deployed and run on the target, w....
|
|
Daniel Burroughs, Auto-adapting Stealth Communication Channels
-
www.defcon.org
-
13 years ago
-
eng
Intrusion detection systems and firewalls generally follow one of two methods of attack detection, signature or anomaly. Signature detection detects known attacks and anomaly detection covers unusual activity (with the hope that it will discover new attacks). Often what is detected by the IDS or firewall is not the original attack, but rather the communication that occurs afterwards. Known methods are easily picked up by signature detect....
|
|
Daniel Burroughs, Auto-adapting Stealth Communication Channels
-
www.defcon.org
-
13 years ago
-
eng
Intrusion detection systems and firewalls generally follow one of two methods of attack detection, signature or anomaly. Signature detection detects known attacks and anomaly detection covers unusual activity (with the hope that it will discover new attacks). Often what is detected by the IDS or firewall is not the original attack, but rather the communication that occurs afterwards. Known methods are easily picked up by signature detect....
|