Upgrading Woody to Sarge

Debian have just released sarge as the new stable distribution which means I need to start upgrading my machines. Before I upgraded the main machine though I decided to run through it on a UML machine first to see where the gotchas are.
Things to watch out for
1. The sshd config file gets an extra parameter added to it ie.
UsePAM yes
When I tested ssh after the upgrade I was unable to log into the machine and I found that I had to remove this option or set it to “no” to get ssh to work. This surprised me because I was not expecting Debian to modify config file without my knowledge.
2. The RECORD option is no longer valid
xinetd[5691]: Bad log_on_failure flag: RECORD [file=/etc/xinetd.conf] [line=13]
xinetd[5691]: A fatal error was encountered while parsing the default section. xinetd will exit.
xinetd[5691]: Exiting…
this prevents xinetd from starting up. This was also noticed while testing the machine after the upgrade.
What follows is roughly the files the upgrade offered to update to new versions. Since I had modified most of these I selected the default option which is “N” ie do not upgrade to the maintainers version. This may have been the reason the ssh upgrade wasn’t too smooth. However I would not recommend taking the maintainers version if you have customized the files.
Configuration file `/etc/pam.d/login’
Configuration file `/etc/securetty’
Configuration file `/etc/pam.d/passwd’
Configuration file `/etc/bash.bashrc’
Configuration file `/etc/init.d/sysklogd’
Configuration file `/etc/services’
Configuration file `/etc/init.d/bind9′
Configuration file `/etc/bind/named.conf’
Configuration file `/etc/bind/db.root’
Configuration file `/etc/init.d/xinetd’
Configuration file `/etc/xinetd.conf’
During the upgrade you may also be asked to add any users and groups that are
missing from the default debian lot. The following bits are just the output of some other configurations options and warnings of things that have changed between the woody and sarge.
Configuring ssh
Environment options on keys have been deprecated This version of OpenSSH
disables the environment option for public keys by default, in order to avoid
certain attacks (for example, LD_PRELOAD). If you are using this option in an
authorized_keys file, beware that the keys in question will no longer work
until the option is removed. To re-enable this option, set
“PermitUserEnvironment yes” in /etc/ssh/sshd_config after the upgrade is
complete, taking note of the warning in the sshd_config(5) manual page.

Configuring man-db
This version of man-db is incompatible with your existing database of manual
page descriptions, so that database needs to be x rebuilt. This may take some
time, depending on how many pages you have installed; it will happen in the
background, possibly slowing down the installation of other packages. If you do
not build the database now, it will be built the next time
/etc/cron.weekly/mandb runs, or you can do it yourself using ‘mandb -c’ as user
‘man’. In the meantime, the ‘whatis’ and ‘apropos’ commands will not be able to
display any output. Incompatible changes like this should happen rarely. Should
mandb build its database now?

So far I have upgraded two machines and had the same trouble with ssh and xinetd both times. If I encounter any mmore trouble I will add more here.

Blogs SpamAssassin and Trackbacks

I disabled the trackback facility on my blog months ago because I was getting a lot of trackback spam. Around the same time I wrote a SpamAssassin Plugin for Movable Type. I effectively took MT-Blacklists regex database and converted into a form compatible for SpamAssassin and then wrote the plugin. Of course at the time I had disabled trackbacks so I only wrote it to handle comments and it has been going a great job because I get virtually zero blog spam now that the database is trained.
Of course now that I have turned on the trackback facility again I now have trackback spam to deal with. Of course this time I am not going to forget about it so await an update and I will release anther version that will handle trackbacks as well.
As promised this is the extended entry. I have now just added trackbacks to the spamassassin plugin. It was easier than I thought. It took 2 hours to finish it, now all I need is someone to test it. As soon as I have packaged it up into a tar ball I will release it.

df reports wrong size

I had a weird problem the other day when I seemed to be getting inconsistencies between du and df. The two command where in disagreement about what the disk usage was on my box.
thing:/# du -hax –max-depth=1 /
104M total
thing:/# df -h
Filesystem Size Used Avail Use% Mounted on
/dev/sda2 3.7G 3.4G 118M 97% /
The first thing I thought was that there was a corruption on the partition table or some other terrible bug. I asked around and got no answers so I went Googling. I came up with nothing although there seemed to be plenty of people with a similar problem.
It then dawned on me what I might have done. I had originally created the Postgres database under /var/lib/postgres under the root file system. As this database got bigger and bigger I had to move it onto its own file system and mount it there. What I had forgot to do was remove the files from the root filesystem after I had confirmed the move was successful. This meant that 2.4Gb of disk space had not been freed on the root file system. Of course when you use du it only adds up the sizes of the files it sees whereas df reports the device usage. So there where no bugs in this case just simple human error.
thingthong:/home/harry# df -h
Filesystem Size Used Avail Use% Mounted on
/dev/sda2 3.7G 1.1G 2.6G 31% /

Spell Counterfeiting

Having read Bruce’s article on Belgium’s latest way of trying to reduce counterfeiting I got the impression he’s not particularly impressed and I don’t blame him.
Professionals will spot the speling mistakes, particularly now that they know they should be looking for them. They might be thinking that several foreign languages might fool the bilingual counterfeiter but its hardly rocket science for the more accomplished crook to refer to bablefish or a foreign dictionary or some other external reference…….. oh…oh perhaps a real card!
It would appear that Belgium may be assuming their counterfeit operations are run by a bunch of half wits who only speak “da wocal wanguage”, have no access to the internet and are not particularly well educated.
I suppose if every card had a semi-random spelling on it then it might introduce a bit more labour on the part of the counterfeiter but that only works until they figure out how to scan it and of course you’re then back to the gimpy race
I would love to see some stats on the success rate of this new idea.

Oxford Dictionary

I noticed tonight that the Oxford English Dictionary (OED) is being replaced by www.webster.com.
How do I know this? Well, have a look for
ClAMOUR
what on earth do they mean chiefly British variant of CLAMOR
BOLLIX. What they should really mean is
CLAMOUR
proper spelling of our americanised terrible spelling of CLAMOR
All jokes aside I use webster.com almost religiously and have even adopted color over colour. Having looked at the OED website it’s little wonder why people are now using the webster.com dictionary over the OED. The OED has pushed a small search box over to the right hand side corner and filled the screen with:
1: A word of the day
If I wanted a word of the day I would go looking for it. Its a bit daft to place this “nice feature” above the dictionary.
2: A quote From.
I own the “Oxford Dictionary of Quotations” and if I am after a quote I am not looking for a Dictionary.
3, A word From (some foreign language).
Who cares how the French say “shit”, wheres the ENGLISH dictionary …..(I o)
I think the OED is selling itself short. I know that for some people Webster is the be all and end all but I am still a believer in the OED. I would like the OED to retain the definitive English dictionary crown but judging from their website this looks unlikely. They should really place more emphasis on it than they do or they risk becoming runner up to webster.com or some other more techno savvy company.

fortune 500 feeds

I was bored yesterday……………………………. so whats new?
the difference this time was that I decided to do something about it and build yet another website (moan).
The idea!
I like to read certain types of news and for the most part the news I am interested in seems to gravitate towards big companies ie, the A list, more commonly known as the Fortune 500. I am not sure why this is the case because there is plenty of really interesting stuff taking place in small companies but for the most part Google seems to steer me up rather than down. Perhaps I am a headonist (please forgive my humour) and don’t know it.
Anyway.
I don’t have a blog roll because I don’t regularly read any blogs on a regular basis. I think this is because people tend to be either eclectic 1 or eclectic 2:
Eclectic: (from webster)
1 : selecting what appears to be best in various doctrines, methods, or styles
2 : composed of elements drawn from various sources; also : HETEROGENEOUS
neither of which lends towards regular reading. Unfortunately E1 is particularly rife amongst the blogging commnuity so some strong filtering is required. Thankfully E2 is much more readable than E1 if done correctly which for the most part is true but if I am to read something regularly then I would prefer something along the lines of E2 but with a general topic in mind.
So with all the above crap in mind I decided that we all need another website (not) that will take the collective wisdom of the fortune 500 and produce dynamic feeds from it.

Ransom-Ware

Just read a very interesting article on Bruce Schneier’s blog.
The most alarming part for me was the following:

Internet attacks have changed over the last couple of years. They’re no longer about hackers. They’re about criminals. And we should expect to see more of this sort of thing in the future.

Unfortunately the above is only too true and we are going to see a marked increase in cybercrime. When you think about it you can almost take any of our old style crimes and with enough imagination and know how make it work over the wire.
Take blackmail.
Using a similar method you could break into someones PC and look for something the owner would really not want shown in public. The criminal then downloads the files and blackmails the owner. If you don’t find anything you might be able to hold his files for ransom anyway.
You could also use it to destroy someones reputation. Lets say John is the CEO of a large corporation with some less than honest competition who would love to see the company damaged in any way possible.
One of the competition hires a cracker to gain access to Johns machine. This would most likely be the home machine since if they managed to break into the work machine then I am sure there are other things that they could do that would cause much more damage.
The cracker then downloads lots of child pornography to Johns machine and makes the logs etc look as if John is a regular child pornographer. Of course the times would need to coincide with John being at home but this sort of information is easily obtained from the machine itself.
The cracker then deletes all trace of him being in and even updates the Virus checker and secures the machine for John so that, when the investigation takes place the police cannot see how the machine could have been cracked.
A phone call to the police on an anonymous line from a child professing that John sexually assaulted them and he would then be under investigation for sexually assaulting a minor. This would lead to confiscation of his machine and of course they are going to find plenty of stuff on it to keep them busy for a while.
Regardless of whether they determine he was set up or not Johns good name is being dragged through the gutter and a certain amount of damage is done.
I am sure that the criminals out there would be able to come up with more imaginative ways than the above to do these sorts of things but as Bruce said we are going to see more of this sort of thing in the future. What frightens me is that we are going to see much more damaging crimes than ransom-ware or identity theft.
As our dependence on computers grow so does our vulnerability and there are criminals with no conscience about what they do or how they do it and I am not including terrorists in this bunch.

I Need a Job

My contract here runs out at the end of July and I am now looking for employment. I will be putting an updated CV online soon or at least as soon as I have got it onto a few of the major search engines.
I am also considering putting it on UKlug since it gets a fair few hits and I own the site.
Wish me luck.