After you had finally gotten your very first 64GB SD card, you will eventually hit this problem sooner or later. Yes, everyone, unless you are the type who is not concern that your tablet just doesn't work with your card or simple could stand how slow the card is somehow.
The major problem with exFat is that its a more Windows format and it's teh default format for formatting SDXC card anyway, even from the official SDCard.org:
https://www.sdcard.org/downloads/formatter_4/
But most tablets are Android based and as such more towards *nix and somehow exFat just doesn't play well there.The problem will start anytime from not detecting the SDCard at all to very slow performance especially when many files are involved. In some extreme case, its even because there are 2 partition created and it start to seriously confuse the OS. Just search "SDXC exFat Problem" and you will know what I mean.
I know its probably not right, but I recommend to keep your 64GB SDXC on Fat32. And Microsoft definitely does not agree with me because they had disable such a feature on their default format utility. You can only format it to exFat or NTFS, which neither works well on Android. But of course there is a easier way here:
http://www.ridgecrop.demon.co.uk/index.htm?fat32format.htm
Make sure you read through and decide on whether you want to use the DOS utility or the GUI one. Just format it to Fat32 and suddenly many of your problem is gone.
NemesisV
All about me, me and me and other stuff which I find interesting.
Sunday, April 28, 2013
SDXC exFat Problem
Labels:
android,
format. SDCard,
SDXC,
Windows
| Reactions: |
Remove the Hidden Partition
Don't you always hate it when your laptop or PC comes with a recovery partition which you may not actually need anymore because you had upgrade your OS or not? Well, you will also find that inside Windows (normally) you will not be able to remove this partition safely. Well, the worry is over because under the administrator command prompt there is a way to do so.
- Open a command prompt as administrator.
- Run Diskpart application by typing Diskpart in the command prompt.
- In the “Diskpart” prompt, enter rescan command and press Enter key to re-scan all partitions, volumes and drives available.
- Then type in list disk and press Enter key to show all hard disk drive available.
- Select the disk that contains the partition you want to remove. Normally, with just 1 hard disk, it will be disk 0. So the command will be:select disk 0Finish by Enter key.
- Type list partition and press Enter key to show all available and created partition in the disk selected.
- Select the partition that wanted to be deleted by using the following command, followed by Enter key:select partition xwhere x is the number of the EISA based recovery partition to be removed and unlocked its space. Be careful with the number of this partition, as wrong number may get data wipes off.
- Finally, type in delete partition override and press Enter key.
Once the partition has been deleted, exit from Diskpart, and now users can use the much familiar and much easier Disk Management tool in Windows (diskmgmt.msc) to manipulate the freed unallocated partition. Users can create a new volume (partition) with this space, or simply merge it to existing partition by extending the size of the existing partition.
Labels:
hidden partition,
laptop,
oem,
pc
| Reactions: |
Monday, March 25, 2013
Evernote v4.6.4 Upgrade Issues
Evernote allows you to easily capture information in any environment using whatever device or platform you find most convenient, and makes this information accessible and searchable at any time, from anywhere. Use Evernote to jot notes, create to-do lists, clip entire Web pages, manage passwords, and record audio. Everything added to Evernote is automatically synchronized across platforms and devices and made searchable. Evernote will even recognize printed or handwritten text in photos and images.
Due to a recent bleached, all users are advised to change password and upgrade to the latest version, but however to some specific users of v4.6.3 (maybe more, but I won't know first hand), the upgrade process seems to failed in every way possible giving MSI error codes.
I tried upgrade inside the application or even downloading the standalone version, but no success. In the end, I figured that they probably omitted a certain version in the upgrade path, so I uninstall v4.6.3 completely. And I reinstalled. And it works!
Well, I guess this is a typical example of a upgrade management issues in software, but at least it didn't need a formatting or Windows Refresh to save the day. If you are having problem with Evernote, try this and hopefully you will still be a happy user of Evernote like me.
Due to a recent bleached, all users are advised to change password and upgrade to the latest version, but however to some specific users of v4.6.3 (maybe more, but I won't know first hand), the upgrade process seems to failed in every way possible giving MSI error codes.
I tried upgrade inside the application or even downloading the standalone version, but no success. In the end, I figured that they probably omitted a certain version in the upgrade path, so I uninstall v4.6.3 completely. And I reinstalled. And it works!
Well, I guess this is a typical example of a upgrade management issues in software, but at least it didn't need a formatting or Windows Refresh to save the day. If you are having problem with Evernote, try this and hopefully you will still be a happy user of Evernote like me.
Tuesday, March 19, 2013
Adobe Photoshop Flickers in Windows 8
Did you encounter flickering or basically image not staying put inside Adobe Photoshop CS6? Well, I guess that's the reason you are here in the first place. But fundamentally, the problem neither lies with Adobe nor Microsoft. I can bet you are almost 100% using a AMD graphics card!
Basically its the AMD graphics driver for now. As of today, its still not fixed and to temporary fix this, Adobe actually recommend to disable graphics acceleration inside Adobe Photoshop for now.
While its not the best way to do it, I guess everyone will have to live with it until AMD fixes this or get a Nvidia card to replace it.
Basically its the AMD graphics driver for now. As of today, its still not fixed and to temporary fix this, Adobe actually recommend to disable graphics acceleration inside Adobe Photoshop for now.
Change the GPU Drawing Mode to Basic:
- In Photoshop, choose Edit > Preferences > Performance.
- Select Advanced Settings.
- Choose Basic from the Drawing Mode pop-up menu.
- Click OK to close the dialog boxes.
While its not the best way to do it, I guess everyone will have to live with it until AMD fixes this or get a Nvidia card to replace it.
Who Reset My Password
Today I am going to talk about yet another simple and effective hack. This time, we are going to go into the scenario of grabbing password from forums, portals etc. Imagine this scenario. You are user A and you want to get into user B's account. We can safely assume that User B's email is inaccessible, otherwise, we all know we do not have a problem then.
Suppose as A, I decide I wanted to go reset my password instead. More often than not, it will be sent to A's email address, a link that enable user A to reset my password. In other times, they may even allow other means as well such as mobile phone or messenger, but the concept is still pretty much the same, except it just complicate the trace hiding part sometimes.
Now, after A check the email and a link will appear. If the link is embedded in HTML, uncode it and look for something like this:
Now. isn't that cute. But what we are interested is the UID most of the time. And I don't need to point finger at what sort of program usually have this type of parameters. Now comes the interesting part. I have a link for A to reset A's password, but what if I CAN reset B's password instead? OK, this is where the complication may or may not help. Basically what you are interested is to obtain B's UID. To my surprise, it's something more easy than you think. Some portal, you will even be able to get that from the "reset password" page, while others, its just a matter of keying in the password incorrectly once on the login page.
Now, lets UID replace. Note that if the site uses some sort of hash check on the URL, this is probably not going to work. But then again the hash is usually going to be a combination of the parameters plus some unique identifier, with some luck, you might even be able to break the hash. In one case I encounter, the hash is basically the whole URL excluding the hash=ZZZZ parameter right at the end.
Assuming its not, replace B's uid with A's uid and you are sent to the password reset page. Go ahead and don't be shy about it. After which, go back to the login page and log into B's account successfully. And B may or may not even know the password had been changed.
You may laugh and think the hack is silly. 10 sites I saw and 10 I entered within last 3 days is not so laughable. If you maintain a portal, I think you should re-look at your password reset workflow seriously.
Suppose as A, I decide I wanted to go reset my password instead. More often than not, it will be sent to A's email address, a link that enable user A to reset my password. In other times, they may even allow other means as well such as mobile phone or messenger, but the concept is still pretty much the same, except it just complicate the trace hiding part sometimes.
Now, after A check the email and a link will appear. If the link is embedded in HTML, uncode it and look for something like this:
uid=12314800&uname=xxxxxxxx&mail=yyyyyyyy
Now. isn't that cute. But what we are interested is the UID most of the time. And I don't need to point finger at what sort of program usually have this type of parameters. Now comes the interesting part. I have a link for A to reset A's password, but what if I CAN reset B's password instead? OK, this is where the complication may or may not help. Basically what you are interested is to obtain B's UID. To my surprise, it's something more easy than you think. Some portal, you will even be able to get that from the "reset password" page, while others, its just a matter of keying in the password incorrectly once on the login page.
Now, lets UID replace. Note that if the site uses some sort of hash check on the URL, this is probably not going to work. But then again the hash is usually going to be a combination of the parameters plus some unique identifier, with some luck, you might even be able to break the hash. In one case I encounter, the hash is basically the whole URL excluding the hash=ZZZZ parameter right at the end.
Assuming its not, replace B's uid with A's uid and you are sent to the password reset page. Go ahead and don't be shy about it. After which, go back to the login page and log into B's account successfully. And B may or may not even know the password had been changed.
You may laugh and think the hack is silly. 10 sites I saw and 10 I entered within last 3 days is not so laughable. If you maintain a portal, I think you should re-look at your password reset workflow seriously.
Monday, March 18, 2013
Adobe Flash Player Download Woe
At version 11.6 now, still full of bugs, yet Adobe Flash player is still plagued with a fundamental fatal error in their update. People all over are still getting the XX % failed to download and to make it worse, Adobe fail to check if the update was even successful at all before deleting the install. In short, when you need to retry, you can't just retry. You will need to download the installer again. Well, of course you can make a copy of it, but if the download problem doesn't get solve, you will still be stucked.
To make things worse, Flash is plagued with critical vulnerability and perhaps one of the biggest issue is that user is not able to update their player thus helping in the exposure of the threat. While Adobe may not see this in this light, it is definitely something I feel they should fix since it had been there since a long time ago.
The most direct solution is to download directly from the source, but instead the full installation package instead of the minimum internet download installer.
Download the full package from:
http://www.adobe.com/products/flashplayer/distribution3.html
OR simply stop using Flash altogether.
To make things worse, Flash is plagued with critical vulnerability and perhaps one of the biggest issue is that user is not able to update their player thus helping in the exposure of the threat. While Adobe may not see this in this light, it is definitely something I feel they should fix since it had been there since a long time ago.
The most direct solution is to download directly from the source, but instead the full installation package instead of the minimum internet download installer.
Download the full package from:
http://www.adobe.com/products/flashplayer/distribution3.html
OR simply stop using Flash altogether.
Wednesday, March 13, 2013
Windows 8 BSOD DPC WATCHDOG VILOLATION
One fine day at work, one fine Windows 8 which was shutdown properly last night, but it did not boot up like it always had in the morning. Instead, what greeted me was a BSOD, well the new BSOD anyway saying something about a "DPC_WATCHDOG Violation". Now, isn't that puzzling. First, its about a watchdog, which I obviously did not bought one and then there was a violation. Did a bad dog run into Windows 8?
After some 30 minutes of read up (using another OS on another partition), I finally found the root of the problem. Well, at least for most other users. It comes down to 3 software.
Well , there are not in order, but for me, I had AVG. And luckily I had this OS (Windows 7) on another partition and simply out of my mind, I rename c:\program files (x86)\AVG to AVG1 and restarted Windows 8.
TADA. OMG, it was really AVG! I had seen success stories from other users for KAV, KIS as well. Seems like these AV companies tried to compete on who gets their product Windows 8 compatible and they made some pretty fatal mistakes along the way. For ATI, it may be a bit more involved to skip start it, but since I did not encounter that I would let other users who had to tell their stories.
Guess, what is the first thing I did after I recovered my Windows 8?
UNINSTALL AVG 2013!
From that day onwards, AVG and Kaspersky is banned from all my Windows 8 machines.
After some 30 minutes of read up (using another OS on another partition), I finally found the root of the problem. Well, at least for most other users. It comes down to 3 software.
- AVG Antivirus or similar suites
- Kaspersky Antivirus or similar suites
- ATI Radeon Catalyst
Well , there are not in order, but for me, I had AVG. And luckily I had this OS (Windows 7) on another partition and simply out of my mind, I rename c:\program files (x86)\AVG to AVG1 and restarted Windows 8.
TADA. OMG, it was really AVG! I had seen success stories from other users for KAV, KIS as well. Seems like these AV companies tried to compete on who gets their product Windows 8 compatible and they made some pretty fatal mistakes along the way. For ATI, it may be a bit more involved to skip start it, but since I did not encounter that I would let other users who had to tell their stories.
Guess, what is the first thing I did after I recovered my Windows 8?
UNINSTALL AVG 2013!
From that day onwards, AVG and Kaspersky is banned from all my Windows 8 machines.
| Reactions: |
Monday, March 04, 2013
My Letter to my Hacker
A while ago, I found a readme.txt sitting right on top of my D**-NET Honeypot and this was the beginning of a whole turn of event that is, let's say, funny at the very least. I opened the readme.txt in a text editor and this is what I saw:
FUCKING PIG
Don't you have anything else beside than porn on your PC?
For the past 2 month all the fuck shit you have given me is nothing but porn!
600GB of fucking porn you shit head.
You did not even download The Avengers 2012 1080p BRrip X264 2 2GB YIFY even though you search it! All you did was downloaded another fuck show!
Fuck! Are you a seller in the night market or what?
And you had even given me the fuck shit trojan you gotten from the porn site!
I am so fucking pissed that I want to fucking delete all your donwloaded porn for you now!
Eat shit and die you pig!
Some part of the swearing I did not appreciated and obvious I deleted it here. Well, angry? Actually not... I had him / her monitored for the past 2 months and I guess since he had left me a note, I should be a polite guest and write him one. but he / she was actually so frustrated that he / she actually delete my files and removed the RAT from the honeypot.
Well, lucky Whisperer 4 was on the Honeynet and it got his / her email when he / she updated the RAT config via email SMTP. That's why you should NEVER use unencrypted SMTP. :P So naturally, I send he / her an email, POLITELY.
Thanks for staying on my PC for the past 2 months.
Firstly I must thank you for being a nice hacker by uploading your RAT msi with both your client and server inside. It was a well written piece of code, but I am pretty sure you did not wrote that anyway.
Secondly, I thank you for actually screening through those files on D: and confirmed that they were ALL porn. I did not really have a look through all of them myself.
In order to evade me, you must had packed your files several times when you perform a remote upgrade, but that was why my AV had flagged you on the second week you were in on XX XX 2012. I had to even put in an exception rule in my AV for your RAT, but I guess you did not found out.
Your random changing of ports was good, perhaps a function build in to your RAT, but it gave me lots of trouble to put in firewall rules so that your RAT can connect properly outside.
You other tools wasn't impressive but I guess its your fault for not testing it against a W2K8 server.
I guess you should at least had thank me for the 600GB of porn which you so patiently downloaded. I thought you would had realized by the first 50GB or so...
Lastly, I would like you to know I actually downloaded The Avengers 2012 1080p BRrip X264 2 2GB YIFY, but its on M: drive. Why did you not look there, but kept staying on my C: and D: ? Was it for the porn?
Thank you for participating on the malware collection exercise on my honeynet.
How many of you laughed? I don't know. I sure did the hell laughed my head off.
FUCKING PIG
Don't you have anything else beside than porn on your PC?
For the past 2 month all the fuck shit you have given me is nothing but porn!
600GB of fucking porn you shit head.
You did not even download The Avengers 2012 1080p BRrip X264 2 2GB YIFY even though you search it! All you did was downloaded another fuck show!
Fuck! Are you a seller in the night market or what?
And you had even given me the fuck shit trojan you gotten from the porn site!
I am so fucking pissed that I want to fucking delete all your donwloaded porn for you now!
Eat shit and die you pig!
Some part of the swearing I did not appreciated and obvious I deleted it here. Well, angry? Actually not... I had him / her monitored for the past 2 months and I guess since he had left me a note, I should be a polite guest and write him one. but he / she was actually so frustrated that he / she actually delete my files and removed the RAT from the honeypot.
Well, lucky Whisperer 4 was on the Honeynet and it got his / her email when he / she updated the RAT config via email SMTP. That's why you should NEVER use unencrypted SMTP. :P So naturally, I send he / her an email, POLITELY.
Thanks for staying on my PC for the past 2 months.
Firstly I must thank you for being a nice hacker by uploading your RAT msi with both your client and server inside. It was a well written piece of code, but I am pretty sure you did not wrote that anyway.
Secondly, I thank you for actually screening through those files on D: and confirmed that they were ALL porn. I did not really have a look through all of them myself.
In order to evade me, you must had packed your files several times when you perform a remote upgrade, but that was why my AV had flagged you on the second week you were in on XX XX 2012. I had to even put in an exception rule in my AV for your RAT, but I guess you did not found out.
Your random changing of ports was good, perhaps a function build in to your RAT, but it gave me lots of trouble to put in firewall rules so that your RAT can connect properly outside.
You other tools wasn't impressive but I guess its your fault for not testing it against a W2K8 server.
I guess you should at least had thank me for the 600GB of porn which you so patiently downloaded. I thought you would had realized by the first 50GB or so...
Lastly, I would like you to know I actually downloaded The Avengers 2012 1080p BRrip X264 2 2GB YIFY, but its on M: drive. Why did you not look there, but kept staying on my C: and D: ? Was it for the porn?
Thank you for participating on the malware collection exercise on my honeynet.
How many of you laughed? I don't know. I sure did the hell laughed my head off.
Friday, July 06, 2012
Google Chrome Your profile cannot be opened correctly
There had been a recent error affecting quite some users on Chrome, after a upgrade. It seems that the user web data is corrupted or not readable by the new Chrome. While its ok to just click ok and go on, each time you relaunch this, it will happen. I finally found the solution and its nothing more than just deleting a file away.
Solution:
1. Close Chrome
2. Go to %LOCALAPPDATA%\Google\Chrome\User Data\Default
3. Delete the file "Web Data"
That's all. Just relaunch Chrome and its solved.
Solution:
1. Close Chrome
2. Go to %LOCALAPPDATA%\Google\Chrome\User Data\Default
3. Delete the file "Web Data"
That's all. Just relaunch Chrome and its solved.
Wednesday, June 06, 2012
A little update about myself
I know I had not been updating my blog much and probably quite disappointing to my loyal followers as a results. Most of my updated had been placed on Facebook, but that I notice is only for limited amount of people I know. So I will actively try to come back to Blogger and post my articles here.
Recently I had gotten several hardware and had immerse myself deeping in the world of Android (hacking). I have a few phones on GB, ICS from WildFire S to Galaxy S2, several tablets from Nook Tablet to Gemei G9. In short, plenty of room to play with experimental Android stuff. I had also gotten myself lots of chance to try out patching and flashing with Odin, Zerg rush etc and custom ROM had really open my eyes to many things. I will find some chance to post some steps on some of the steps I took. Probably fun.
I also went deeper into Android hacking about masking IMEI, IMSI etc All these I probably will be talking about it in the near future about using specific software and even rom patching to archive. All these can have many uses in term of gaming, overcoming software limitations or maybe it's just simply privacy.
In any case, I wanted to say is that, Thanks for not giving up on my blog yet. I'll back!
Recently I had gotten several hardware and had immerse myself deeping in the world of Android (hacking). I have a few phones on GB, ICS from WildFire S to Galaxy S2, several tablets from Nook Tablet to Gemei G9. In short, plenty of room to play with experimental Android stuff. I had also gotten myself lots of chance to try out patching and flashing with Odin, Zerg rush etc and custom ROM had really open my eyes to many things. I will find some chance to post some steps on some of the steps I took. Probably fun.
I also went deeper into Android hacking about masking IMEI, IMSI etc All these I probably will be talking about it in the near future about using specific software and even rom patching to archive. All these can have many uses in term of gaming, overcoming software limitations or maybe it's just simply privacy.
In any case, I wanted to say is that, Thanks for not giving up on my blog yet. I'll back!
Wednesday, March 21, 2012
Empty Recycle Bin at Logoff and Shutdown on Windows XP
I had been looking for a simple solution for legacy systems (Windows XP) to perform a simply empty recycle bin during a shutdown and even better if it can be integrated into a logoff. To my surprise there were tons of requests for years and nobody gave a solution properly which does not require any 3rd party tools.
Most of the users suggest to turn off Recycle bin totally, but it can save lives sometimes, so that not what we want. Secondly, if we need to install a tool, we are just expanding our exposure to risk since the tool may have vulnerability and who knows what it can do when run as SYSTEM during a shutdown.
I found the simplest solution is to make use of Microsoft's built in shutdown and logoff script function:
Shutdown scripts:
https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/gptext_assigncomputershutdownscripts.mspx?mfr=true
Logoff scripts:
https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/gptext_logoffscripts.mspx?mfr=true
However, do take note that Shutdown scripts are run as SYSTEM and logoff scripts are run as the user logging off.
A simple "Empty the Recycle Bin" scripts using just batch file:
ATTRIB %systemdrive%\RECYCLER\* -R -S -H /S /D
DEL %systemdrive%\RECYCLER\* /F /S /Q
RD %systemdrive%\RECYCLER /S /Q
It's 3 lines to make sure it deletes and finish the job. Just copy and paste into a batch file which is your logoff / shutdown script.
There we have it. A simple and do-no-need-3rd-party solution. I hope you will find it useful.
Most of the users suggest to turn off Recycle bin totally, but it can save lives sometimes, so that not what we want. Secondly, if we need to install a tool, we are just expanding our exposure to risk since the tool may have vulnerability and who knows what it can do when run as SYSTEM during a shutdown.
I found the simplest solution is to make use of Microsoft's built in shutdown and logoff script function:
Shutdown scripts:
https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/gptext_assigncomputershutdownscripts.mspx?mfr=true
Logoff scripts:
https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/gptext_logoffscripts.mspx?mfr=true
However, do take note that Shutdown scripts are run as SYSTEM and logoff scripts are run as the user logging off.
A simple "Empty the Recycle Bin" scripts using just batch file:
ATTRIB %systemdrive%\RECYCLER\* -R -S -H /S /D
DEL %systemdrive%\RECYCLER\* /F /S /Q
RD %systemdrive%\RECYCLER /S /Q
It's 3 lines to make sure it deletes and finish the job. Just copy and paste into a batch file which is your logoff / shutdown script.
There we have it. A simple and do-no-need-3rd-party solution. I hope you will find it useful.
Tuesday, March 20, 2012
Reverse Bruteforcing of Accounts
I may had talked about this in the past somewhere, not sure if its here, but in any case, this still works even today and there is no harm mentioning it again.
Given a black box system for pentest, you know there are some minimum security set in:
Point 3 is where we would base this attack on. In order to show them how bad their passwords are, we probably need to crack some majority of it and bruteforcing is required unless we can dump the hashes (in Windows) or offline crack their salted password (from Linux). Traditionally, bruteforce will choose a useraname (example admin) and try to guess the password (admin, password, admin123, iamgod...) and before you know it, the account is locked (Shit! damn...). See point 1 above.
So, lets think out of the box. How many user would use lets say the password "password" (if its allowed by the password policy). Probably a lot. That's why I am going to introduce another to bruteforce such a system. This is what I call Reverse Bruteforcing. Instead of using a username and bruteforcing the password, we choose a password and bruteforce the username instead. Of course, in some case, we might even have the username (from the emails servers, or client contact list etc). But in the worst case, this will work.
So, we would go:
"password" - user1, user2, user3 etc...
This will not lock out the accounts as quickly as traditional bruteforcing, but it will eventually depending on how they set it up. If its time based (x attempts in x mins), then by spacing out the bruteforce, we might actually overcome it totally. Go online and get a list of commonly used password and mix in some variation with the company's name, slogan etc and you have a good list to start with.
Actually in some of my previous pentests, this methods proves to be quite effective and can be easily automated and while it run, you can proceed with your Metasploit or other attacks. Its a quick win any day! (P.S. My best win is root, root without locking the account up :P)
Given a black box system for pentest, you know there are some minimum security set in:
- There is a lockout for X retries (usually not 65535...)
- There are a large amount of user (easily deduced from company size)
- The users are lazy and like to choose easy passwords (always a given. Even if there is password limit, it will still be simple passwords like P@ssword123 or qwerty12345 which passed the password requirement)
Point 3 is where we would base this attack on. In order to show them how bad their passwords are, we probably need to crack some majority of it and bruteforcing is required unless we can dump the hashes (in Windows) or offline crack their salted password (from Linux). Traditionally, bruteforce will choose a useraname (example admin) and try to guess the password (admin, password, admin123, iamgod...) and before you know it, the account is locked (Shit! damn...). See point 1 above.
So, lets think out of the box. How many user would use lets say the password "password" (if its allowed by the password policy). Probably a lot. That's why I am going to introduce another to bruteforce such a system. This is what I call Reverse Bruteforcing. Instead of using a username and bruteforcing the password, we choose a password and bruteforce the username instead. Of course, in some case, we might even have the username (from the emails servers, or client contact list etc). But in the worst case, this will work.
So, we would go:
"password" - user1, user2, user3 etc...
This will not lock out the accounts as quickly as traditional bruteforcing, but it will eventually depending on how they set it up. If its time based (x attempts in x mins), then by spacing out the bruteforce, we might actually overcome it totally. Go online and get a list of commonly used password and mix in some variation with the company's name, slogan etc and you have a good list to start with.
Actually in some of my previous pentests, this methods proves to be quite effective and can be easily automated and while it run, you can proceed with your Metasploit or other attacks. Its a quick win any day! (P.S. My best win is root, root without locking the account up :P)
Sunday, March 18, 2012
CM9 for Nook Tablet First Alpha
The first Alpha for Nook Tablet CM9 is out. However as stated being an alpha, not everything works and the hardware video decoding is of course still unfixed. However, if you feel that you want to have a shot at how CM9 looks like, go ahead and grab the binaries from xda-developers:
http://forum.xda-developers.com/showthread.php?t=1534192
http://forum.xda-developers.com/showthread.php?t=1534192
Labels:
android,
ICS,
Nook Tablet
| Reactions: |
Saturday, March 10, 2012
Download Adobe Photoshop Lightroom 4
Since Lightroom 4 had been out there are many good reviews all over the net, so I will not repeat them. But I found out that I actually have a problem downloading the trial version to see for myself. After some minutes of debugging, I realized that the Coldfusion download server used by Adobe does not seems to be Chrome friendly.
The links are here:
http://trials2.adobe.com/AdobeProducts/LTRM/4/win32/Lightroom_4_LS11.exe
http://trials3.adobe.com/AdobeProducts/LTRM/4/win32/Lightroom_4_LS11.exe
So, I have to fire up the trusty IE (its not bad, just not my choice of browser). And all a sudden it starts to download the 718MB trial happily.
Well this is just an update for anyone who has similar issue with the download.
Do drop a comment here (for encouragement) if this post helps you!
The links are here:
http://trials2.adobe.com/AdobeProducts/LTRM/4/win32/Lightroom_4_LS11.exe
http://trials3.adobe.com/AdobeProducts/LTRM/4/win32/Lightroom_4_LS11.exe
So, I have to fire up the trusty IE (its not bad, just not my choice of browser). And all a sudden it starts to download the 718MB trial happily.
Well this is just an update for anyone who has similar issue with the download.
Do drop a comment here (for encouragement) if this post helps you!
| Reactions: |
Tuesday, February 28, 2012
Attended World Premiere of John Carter
I do not usually blog about movies nowadays much because I hardly attended any. However, recently, I was somehow lucky enough to get hold of tickets to the World Premiere of John Carter, based on novels which was written say, yes exactly 1 century ago by Edgar Rice Burroughs. When I first viewed the trailer, I was amazed and I thought avatar kinda ripped it off this movie since it was created 100 years ago. However, I must say I was kind of disappointed when I saw the Disney label on it because basically it would say : "No blood, no extreme violence and definitely no sex!" Well I can't say I was totally disappointed with the Pirates of the Caribbeans, so maybe I should give it a chance.
To be honest, this was not the first movie based on the first book "A Princess from Mars". In fact in 2009, there was a STV movie made with the same title, which obviously flopped, gaining a 3.2 / 10 on IMdb. I was fortunate enough not to have watched that. I had not read any of the books too, so this movie is a fresh start for me.
Firstly, I must say, I am impressed with the 3D. It had came so far and in this movie, its not just cosmetics. The 3D effects actually tries to put the user into the world by feeling it. The story line is kinda old, but what would you expect from a 100 years old tale. However, you can see how this old story could had brought about others like Narnia, Stars Wars and Avatar. The creature created are not anything we had not seen before, but there are believable and some more cute than others. But I guess in the end, the leads had put in good effort into their characters and it eventually plays out well in the whole.
I really enjoyed the show and look forward to a sequel soon.
To be honest, this was not the first movie based on the first book "A Princess from Mars". In fact in 2009, there was a STV movie made with the same title, which obviously flopped, gaining a 3.2 / 10 on IMdb. I was fortunate enough not to have watched that. I had not read any of the books too, so this movie is a fresh start for me.
Firstly, I must say, I am impressed with the 3D. It had came so far and in this movie, its not just cosmetics. The 3D effects actually tries to put the user into the world by feeling it. The story line is kinda old, but what would you expect from a 100 years old tale. However, you can see how this old story could had brought about others like Narnia, Stars Wars and Avatar. The creature created are not anything we had not seen before, but there are believable and some more cute than others. But I guess in the end, the leads had put in good effort into their characters and it eventually plays out well in the whole.
I really enjoyed the show and look forward to a sequel soon.
Labels:
john carter,
movie
| Reactions: |
Thursday, February 23, 2012
Goodbye Bullguard, Hello Bitdefender
One of the main Internet Security Suite I had been using is Bullguard Internet Security ( www.bullguard.com ). It may not had been the BEST and most accurate detector in the market, but it certainly had done its job protecting me when I somehow miss a click and allowed something to run. Bullguard is backed with Outpost's firewall and Bitdefender's AV engine, which in my opinion is one of the BEST in the market. Bullguard had its glory, claiming VB100 awards (http://www.bullguard.com/news/latest-press-releases/press-release-archive/24-06-2011.aspx) and what is most important is that it is user friendly. There aren't millions of click allows like some other AV suite such as Kaspersky or Qihun 360 which basically made the product totally unusable since I will be spending most of my time clicking "Yes, Allow, Remember (PLEASE!)".
But sad to say, my subscription is coming to an end soon and I am in the process to reacquire another AV product for my mainstream machines. I do not mind going again with Bullguard, but since the Windows Home Server 2011 issue, it had basically crippled all my PC Backups.
After some research, I decided to go with Bitdefender for a while since it was the same engine. just directly from the original AV company now. Moreover, the 2011 version had gotten really lots of good review. However, since I will be using the latest version, I will be using the 2012. Well, I will be posting some review of my own soon.
But sad to say, my subscription is coming to an end soon and I am in the process to reacquire another AV product for my mainstream machines. I do not mind going again with Bullguard, but since the Windows Home Server 2011 issue, it had basically crippled all my PC Backups.
After some research, I decided to go with Bitdefender for a while since it was the same engine. just directly from the original AV company now. Moreover, the 2011 version had gotten really lots of good review. However, since I will be using the latest version, I will be using the 2012. Well, I will be posting some review of my own soon.
Wednesday, January 04, 2012
Where is my shell - Ubuntu 11.10
I know this is late, but I had been real busy in the past month over things which matters and does not matters. Eventually, I even missed to download and install Ubuntu 11.10 when it was out in Oct... But its better late than never since 12.04 is in alpha1 only and will only be available in April 2012.
The first thing I saw after a reboot as a culture shock.
The familiar top menu is gone and how do I start a shell? I tried right clicking and look for it on the top right, but its not there...
Well thats the good part about installing this late, but other people had done it and had wrote up documents on how-to do this and that. It seems that the terminal is not hidden inside the DASH icon.
http://complete-concrete-concise.com/ubuntu-2/ubuntu-11-10-how-to-get-a-command-line-shell-or-terminal
Anyway, this is the new desktop interface call Unity. At the first look, I like the new Ubuntu 11.10. Its about time Linux gets it right.
The first thing I saw after a reboot as a culture shock.
The familiar top menu is gone and how do I start a shell? I tried right clicking and look for it on the top right, but its not there...
Well thats the good part about installing this late, but other people had done it and had wrote up documents on how-to do this and that. It seems that the terminal is not hidden inside the DASH icon.
http://complete-concrete-concise.com/ubuntu-2/ubuntu-11-10-how-to-get-a-command-line-shell-or-terminal
Anyway, this is the new desktop interface call Unity. At the first look, I like the new Ubuntu 11.10. Its about time Linux gets it right.
Sunday, December 25, 2011
Racist Nandos made it onto my banned list
I had heard of the $2.50 for plain water incident in Singapore, but I had not visited it myself to find out how bad it really was. However, since I was in KL this weekend, I thought I should pop by Nandos and find out.
Anyway, here is the incident details about the $2.50 plain water incident.
http://caveat-emptor-singapore.blogspot.com/2011/06/poor-service-at-nando.html
So, I was at KLCC, and next in the line with J and had indicated to the waitress that I want a table for 2. I saw a table clearing up and I knew it would be my turn soon. And then another family of 3 arrived and they just walked in. Then they were told they need to wait in line first. Disappointed, they walked out, but before you know it, the waiter then came out and told then they have a table for them, totally walked passed me and tell them to come in.
I mean, WTF? Am I invisible or something. Or I get it. Most of the waitress actually have the same skin color and wear the same type of head dress with the family of 3. And I certainly did not see any triangle table which is designed for table of 3. If they can fit in a table for 3, why can't they fit in for a table of 2 first?
I told myself this is rubbish. I am a spending customer and I will not stand or this type of Bullshit. I can fucking spend my money elsewhere were I like it and I do not have to stand for your poor service and fucking racist attitude. This is clearly a case of discrimination against us and I swear that if this is somewhere else, I would meet them in court and make they pay dearly for this!
Anyway, FUCK IT. Nandos is on my banned list now.
Anyway, I was lucky though. Because I missed Nandos, I have a damn great dinner at Uncle Duck.
Anyway, here is the incident details about the $2.50 plain water incident.
http://caveat-emptor-singapore.blogspot.com/2011/06/poor-service-at-nando.html
So, I was at KLCC, and next in the line with J and had indicated to the waitress that I want a table for 2. I saw a table clearing up and I knew it would be my turn soon. And then another family of 3 arrived and they just walked in. Then they were told they need to wait in line first. Disappointed, they walked out, but before you know it, the waiter then came out and told then they have a table for them, totally walked passed me and tell them to come in.
I mean, WTF? Am I invisible or something. Or I get it. Most of the waitress actually have the same skin color and wear the same type of head dress with the family of 3. And I certainly did not see any triangle table which is designed for table of 3. If they can fit in a table for 3, why can't they fit in for a table of 2 first?
I told myself this is rubbish. I am a spending customer and I will not stand or this type of Bullshit. I can fucking spend my money elsewhere were I like it and I do not have to stand for your poor service and fucking racist attitude. This is clearly a case of discrimination against us and I swear that if this is somewhere else, I would meet them in court and make they pay dearly for this!
Anyway, FUCK IT. Nandos is on my banned list now.
Anyway, I was lucky though. Because I missed Nandos, I have a damn great dinner at Uncle Duck.
Thursday, December 08, 2011
eNet problem with Chrome browser - Solved
Sometimes, we just do not have a choice. Some of the eGovernment services happens to use something known as eNets, which in my very humble opinion is still fucked up as ever. Out of the 2 times I have to use it in the pass 1 month, one of then returned a 404 page not found and the other one certain made me bang table.
Just put the 404 one aside since I do not care, as long as I attempted to pay, if the payment failed, I would point finger at Nets. The second case was actually much worse. But since I am here to bitch about it, I might as well start from the beginning.
It all started when I needed to renew some something which is not important in the story. And I ended up on the payment gateway. Its none other than eNets. I actually wonder why the Singapore government continue to use such a lousy payment system. Even some of the primitive China payment gateway works better than this. Anyway that aside it could be a left pocket right pocket things, it still doesn't solve my problem.
When I made the payment after filling up the big long form, a golden bar pops up on my Chrome browser. Well, it seems like it needs Java and Chrome had to be sure to ask me. +1 for Chrome. When I click run, it loads Java, but the form is still stuck, The fields are not enabled and I cannot type in anything at all. Now that sucks. I know I should go and complain, but I also know they will go tell me to use IE6. So just fuck it.
The most natural thing to do was to press F5 to refresh the page. And guess what, it failed once again and now I am unable to pay because there is an active sessions. Ok, thats a good precaution, but it suggest that I close the browser and try again. And so I did, losing all the entered data and I had to go through the forms once more. This time I tried to enable the Java run, but still it doesn't load. That's just fucked up.
Ok, if I am going to bitch about it, I might as well give everyone a solution here. On the payment form. there is actually a Cancel button. Go click that and you will be returned to the page which you came in from. You can submit the payment once more and since you already allowed the Java to run, it will load successfully this time, thus enabling you to complete you payment.
I know by the time you find this page, its probably already too late, but having a workaround sure beats having to go queue up and submit anything manually. I just hope that company like Nets wake up their idea and make their application compatible with other browsers! And IE6 is in no way the dominating browser anymore since a few years back!!!
Summary:
If Java does not load on eNets page, DO NOT REFRESH or PRESS F5!!! Instead, click cancel and you will be allowed to resubmit the payment request.
Just put the 404 one aside since I do not care, as long as I attempted to pay, if the payment failed, I would point finger at Nets. The second case was actually much worse. But since I am here to bitch about it, I might as well start from the beginning.
It all started when I needed to renew some something which is not important in the story. And I ended up on the payment gateway. Its none other than eNets. I actually wonder why the Singapore government continue to use such a lousy payment system. Even some of the primitive China payment gateway works better than this. Anyway that aside it could be a left pocket right pocket things, it still doesn't solve my problem.
When I made the payment after filling up the big long form, a golden bar pops up on my Chrome browser. Well, it seems like it needs Java and Chrome had to be sure to ask me. +1 for Chrome. When I click run, it loads Java, but the form is still stuck, The fields are not enabled and I cannot type in anything at all. Now that sucks. I know I should go and complain, but I also know they will go tell me to use IE6. So just fuck it.
The most natural thing to do was to press F5 to refresh the page. And guess what, it failed once again and now I am unable to pay because there is an active sessions. Ok, thats a good precaution, but it suggest that I close the browser and try again. And so I did, losing all the entered data and I had to go through the forms once more. This time I tried to enable the Java run, but still it doesn't load. That's just fucked up.
Ok, if I am going to bitch about it, I might as well give everyone a solution here. On the payment form. there is actually a Cancel button. Go click that and you will be returned to the page which you came in from. You can submit the payment once more and since you already allowed the Java to run, it will load successfully this time, thus enabling you to complete you payment.
I know by the time you find this page, its probably already too late, but having a workaround sure beats having to go queue up and submit anything manually. I just hope that company like Nets wake up their idea and make their application compatible with other browsers! And IE6 is in no way the dominating browser anymore since a few years back!!!
Summary:
If Java does not load on eNets page, DO NOT REFRESH or PRESS F5!!! Instead, click cancel and you will be allowed to resubmit the payment request.
Monday, November 28, 2011
File association hell - File Types Change Grayed out
Ever encounter a really screwed up system where the file association sucks? For example, opening a ZIP file, it goes ahead and launches Acrobat reader... Ya, I think you know what I mean. And worse of all, not everyone has the power to go change it in the registry and ever so it may not solve the problem at all.
According to various forum, one way to save it is to set:
"NoFileAssociate" value DWORD=0
at these two keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explore
r
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\Explor
er
But if you notice, when you run regedit in admin mode, the current_user is admin, and not whatever user you may be. Also, let's say you do not even have admin right, then what? Come to think of it, how the hell did you manage to mess it up so badly?
If you are not admin and you manage to mess it up, it can only mean that you have the power and thus the responsibility to set it right. I am going to show you one of the way which I found out that works.
Find one of those file you need to associate. Create a fake one if you have to. Right click on it, Property.
Now, do you see the change button there? I had tried even in non-admin mode that the button is not disabled. So go ahead and use that to change it to whatever you need.
Another way which did not work for me is to go to any explorer window. Tool->Folder Option. Click on the File Types tab and there you can see the buttons Change as well. But for my non-admin case, the button is disabled and getting it enable is more trouble than worth it.
In any case, I hope this helps you. Drop me a comment if you find it useful.
According to various forum, one way to save it is to set:
"NoFileAssociate" value DWORD=0
at these two keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explore
r
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\Explor
er
But if you notice, when you run regedit in admin mode, the current_user is admin, and not whatever user you may be. Also, let's say you do not even have admin right, then what? Come to think of it, how the hell did you manage to mess it up so badly?
If you are not admin and you manage to mess it up, it can only mean that you have the power and thus the responsibility to set it right. I am going to show you one of the way which I found out that works.
Find one of those file you need to associate. Create a fake one if you have to. Right click on it, Property.
Now, do you see the change button there? I had tried even in non-admin mode that the button is not disabled. So go ahead and use that to change it to whatever you need.
Another way which did not work for me is to go to any explorer window. Tool->Folder Option. Click on the File Types tab and there you can see the buttons Change as well. But for my non-admin case, the button is disabled and getting it enable is more trouble than worth it.
In any case, I hope this helps you. Drop me a comment if you find it useful.
Subscribe to:
Posts (Atom)




