<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>extricate.org &#187; Computing</title>
	<atom:link href="http://extricate.org/category/computing/feed/" rel="self" type="application/rss+xml" />
	<link>http://extricate.org</link>
	<description>A subtle blend of technical geekery, judo and the life of a football referee.</description>
	<lastBuildDate>Wed, 02 May 2012 14:07:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<copyright>Copyright &#xA9; extricate.org 2011 </copyright>
	<managingEditor>tristan@extricate.org (extricate.org)</managingEditor>
	<webMaster>tristan@extricate.org (extricate.org)</webMaster>
	<image>
		<url>http://extricate.org/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>extricate.org</title>
		<link>http://extricate.org</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>A subtle blend of technical geekery, judo and the life of a football referee.</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &#38; Culture" />
	<itunes:author>extricate.org</itunes:author>
	<itunes:owner>
		<itunes:name>extricate.org</itunes:name>
		<itunes:email>tristan@extricate.org</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://extricate.org/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Bringing a Netbook back from the dead</title>
		<link>http://extricate.org/2011/09/09/bringing-a-netbook-back-from-the-dead/</link>
		<comments>http://extricate.org/2011/09/09/bringing-a-netbook-back-from-the-dead/#comments</comments>
		<pubDate>Fri, 09 Sep 2011 14:33:59 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[broken screen]]></category>
		<category><![CDATA[lcd]]></category>
		<category><![CDATA[netbook]]></category>
		<category><![CDATA[repair]]></category>

		<guid isPermaLink="false">http://extricate.org/?p=1314</guid>
		<description><![CDATA[Tweet Accidents will happen. Right at the end of the tremendous TruLondon unconference, I managed to drop my Netbook. It was only from chair height but it sadly struck the metal parts of the chair on the way down. Ouch. It powered up fine but half the screen was either glowing white or corrupted. That [...]]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton1314" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2011%2F09%2F09%2Fbringing-a-netbook-back-from-the-dead%2F&amp;text=Bringing%20a%20Netbook%20back%20from%20the%20dead&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2011%2F09%2F09%2Fbringing-a-netbook-back-from-the-dead%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p><a href="http://extricate.org/wp-content/uploads/2011/09/cracked_broken_lcd_monitor_screen.jpg"><img src="http://extricate.org/wp-content/uploads/2011/09/cracked_broken_lcd_monitor_screen-150x150.jpg" alt="" title="cracked_broken_lcd_monitor_screen" width="150" height="150" class="alignleft size-thumbnail wp-image-1315" /></a></p>
<p>Accidents will happen.  Right at the end of the tremendous <a href="http://www.jobsite.co.uk/events/trulondon/">TruLondon</a> unconference, I managed to drop my <a href="http://en.wikipedia.org/wiki/Netbook">Netbook</a>.  It was only from chair height but it sadly struck the metal parts of the chair on the way down.</p>
<p>Ouch.</p>
<p>It powered up fine but half the screen was either glowing white or corrupted.  That was promising in a way as there was no obvious structural damage.  As a result, I attempted the <a href="http://lifehacker.com/152062/fix-your-lcds-dead-pixels">LCD Massage</a> trick.  This involves gently massaging the LCD to try and prod it back to life <strong>(DO NOT TRY THIS AT HOME)</strong>.  It managed to resuscitate half of the damaged area.</p>
<p>&#8220;Great!  I am the master of technology!&#8221;, I thought.  </p>
<p>It did not bring results on the remaining dodgy part of the screen.  I pushed a little harder.  Still nothing.  I pushed slightly harder and&#8230;.. <strong>CRRRAAAAACCCCCCKKK!</strong></p>
<p>Oops.</p>
<p>On the plus side, half of the screen was still working.</p>
<div id="attachment_1319" class="wp-caption aligncenter" style="width: 310px"><a href="http://extricate.org/wp-content/uploads/2011/09/netbook_in_pieces.jpg"><img src="http://extricate.org/wp-content/uploads/2011/09/netbook_in_pieces-300x179.jpg" alt="" title="netbook_in_pieces" width="300" height="179" class="size-medium wp-image-1319" /></a><p class="wp-caption-text">In pieces...</p></div>
<p>Thankfully, screens are pretty easy to replace on these devices.  I ordered a replacement screen for my <a href="http://www.samsung.com/uk/consumer/pc-peripherals/notebook-computers/netbook">Samsung N220 Plus</a> from <a href="http://www.laptopscreenonline.com/">laptopscreenonline.com</a> for just under £50.    </p>
<p>I was very impressed with their service as it arrived Next Day.  In classic tradition, fitting it was the reverse of taking the broken one out, and everything worked great first time.</p>
<p>Unexpected bonus: The replacement screen is of the reflective variety which brings out the colours better.  Not everyone likes the shiny screens but I do!</p>
<div id="attachment_1322" class="wp-caption aligncenter" style="width: 310px"><a href="http://extricate.org/wp-content/uploads/2011/09/netbook_fixed.jpg"><img src="http://extricate.org/wp-content/uploads/2011/09/netbook_fixed-300x179.jpg" alt="" title="netbook_fixed" width="300" height="179" class="size-medium wp-image-1322" /></a><p class="wp-caption-text">Good as new!</p></div>
<p>Now to give the poor machine some tender loving care&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2011/09/09/bringing-a-netbook-back-from-the-dead/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Books: Secret History of the Internet and Virtual Shadows</title>
		<link>http://extricate.org/2010/01/04/books-secret-history-of-the-internet-and-virtual-shadows/</link>
		<comments>http://extricate.org/2010/01/04/books-secret-history-of-the-internet-and-virtual-shadows/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 18:38:26 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[book]]></category>
		<category><![CDATA[history]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://extricate.org/?p=354</guid>
		<description><![CDATA[TweetI picked up some books recently based on some reviews via the British Computer Society. On the Way to the Web: The Secret History of the Internet and its Founders details the development of the various online systems which paved the web to the Internet and web that we know today. This was not a [...]]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton354" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2010%2F01%2F04%2Fbooks-secret-history-of-the-internet-and-virtual-shadows%2F&amp;text=Books%3A%20Secret%20History%20of%20the%20Internet%20and%20Virtual%20Shadows&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2010%2F01%2F04%2Fbooks-secret-history-of-the-internet-and-virtual-shadows%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p>I picked up some books recently based on some reviews via the <a href="http://www.bcs.org/">British Computer Society</a>.</p>
<p><a href="http://www.amazon.co.uk/gp/product/1430208694?ie=UTF8&#038;tag=extricate-21&#038;linkCode=as2&#038;camp=1634&#038;creative=19450&#038;creativeASIN=1430208694">On the Way to the Web: The Secret History of the Internet and its Founders</a> details the development of the various online systems which paved the web to the Internet and web that we know today.  This was not a linear progression.  The classic <a href="http://en.wikipedia.org/wiki/Bulletin_Board_System">bulletin boards</a> and the like (based on screeching <a href="http://en.wikipedia.org/wiki/Modem">modems</a>, ah memories&#8230;) were not on the same path and eventually fell by the wayside but certainly gave many their first tastes of the online world.  Oh, and the telephone bills to match.</p>
<p>Yes, the likes of <a href="http://en.wikipedia.org/wiki/Prestel">Prestel</a> and <a href="http://en.wikipedia.org/wiki/Delphi_online_service">Delphi</a> do feature.  It is an interesting read and also details the political and personal wranglings that were going on.  It is a shame that <a href="http://en.wikipedia.org/wiki/Compunet">Compunet</a> (my first online experience) is not featured but I did learn about the more official <a href="http://en.wikipedia.org/wiki/Commodore_64">Commodore 64</a> services that existed.</p>
<p><a href="http://www.amazon.co.uk/gp/product/1906124094?ie=UTF8&#038;tag=extricate-21&#038;linkCode=as2&#038;camp=1634&#038;creative=19450&#038;creativeASIN=1906124094">Virtual Shadows: Your Privacy in the Information Society</a> deals with, predictably, privacy in the Information Society!  Some of the material will be a bit obvious to those with a background in this stuff (e.g. why blogs are popular and how they work) but some of the detail in risk assessment of the information you leave online is absorbing.  Naturally, social networking sites form a key part of this as does the protection of children.  I found the later parts of the book the best as they dealt with the current and upcoming threats to our privacy in general, be they ID cards or the &#8216;feature creep&#8217; of CCTV and other surveillance systems.  I had never heard of <a href="http://en.wikipedia.org/wiki/Sousveillance">&#8216;Sousveillance&#8217;</a> before either!</p>
<p>I recommend both books so check them out.</p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2010/01/04/books-secret-history-of-the-internet-and-virtual-shadows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Workshop: The Evolution of an Exploit</title>
		<link>http://extricate.org/2009/06/26/workshop-the-evolution-of-an-exploit/</link>
		<comments>http://extricate.org/2009/06/26/workshop-the-evolution-of-an-exploit/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 21:44:43 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[debugging]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[fuzzing]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[mwr security]]></category>
		<category><![CDATA[remote shell]]></category>
		<category><![CDATA[shellcode]]></category>
		<category><![CDATA[workshop]]></category>

		<guid isPermaLink="false">http://extricate.org/?p=283</guid>
		<description><![CDATA[TweetI attended a workshop provided by MWR InfoSecurity on &#8216;The Evolution of an Exploit&#8217; recently (Full details in PDF format). A lot of security presentations can be a bit weak in terms of technical content, essentially just being &#8220;SECURITY IS GOOD. CAREFUL, OR THE MONSTERS WILL GET YOUR DATA&#8221;. The sort of scaremongering designed to [...]]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton283" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2009%2F06%2F26%2Fworkshop-the-evolution-of-an-exploit%2F&amp;text=Workshop%3A%20The%20Evolution%20of%20an%20Exploit&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2009%2F06%2F26%2Fworkshop-the-evolution-of-an-exploit%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p>I attended a workshop provided by <a href="http://www.mwrinfosecurity.com">MWR InfoSecurity</a> on &#8216;The Evolution of an Exploit&#8217; recently (<a href="http://www.mwrinfosecurity.com/files/Events/mwri_technical-half-day-agenda-EOAE.pdf">Full details in PDF format</a>).</p>
<p>A lot of security presentations can be a bit weak in terms of technical content, essentially just being &#8220;SECURITY IS GOOD.  CAREFUL, OR THE MONSTERS WILL GET YOUR DATA&#8221;. The sort of scaremongering designed to get those who are perhaps not particularly technically aware to open their wallets in fear.</p>
<p>Don&#8217;t get me wrong: Security is vital but it must be understood properly.</p>
<p>Anyway, this was an excellent workshop.  It followed a particular vulnerable product and the stages taken from analysing the network traffic and producing &#8216;fuzzy&#8217; packets, through analysing the crash data in a debugger, to crafting an actual exploit. The network-based exploit gave a remote shell with Administrator privileges to the target box.  Game over!</p>
<p>I particularly liked the fact that at each stage the software packages used were fully demonstrated to get the desired result. So I&#8217;ve got a few more toys to play with when I can find the time! Also, the workshop did not shy away from assembly to demonstrate how overflow exploits actually work.</p>
<p>Things which particularly grabbed my attention:</p>
<ol>
<li>Fuzzing is not just a case of sending random data.  To make it more useful, it is always based around the packet format which the target will accept. Best use of your time.</li>
<li>The <a href="http://www.metasploit.com/">Metasploit</a> platform. Very cool framework.  In particular I liked how once you have your exploit packet, you can fill the shellcode section with, well, whatever exploit in their database that fits. Download something, give a remote shell, scan a network&#8230; so many possibilities.</li>
<li>Just how &#8220;Duh&#8221; the mistake made by the developers of the vulnerable software was. The client essentially passed the memory address of the function that should be executed next to the server .  &#8220;Never trust the client&#8221; is a classic security mantra, so this one particularly takes the biscuit.</li>
</ol>
<p>I recommend the workshop, and the <a href="http://www.marksandspencer.com/">Marks and Spencer</a> provided cuisine was not bad either <img src='http://extricate.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2009/06/26/workshop-the-evolution-of-an-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Turning an old laptop into a router with pfSense</title>
		<link>http://extricate.org/2009/04/14/turning-an-old-laptop-into-a-router-with-pfsense/</link>
		<comments>http://extricate.org/2009/04/14/turning-an-old-laptop-into-a-router-with-pfsense/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 22:25:41 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ipcop]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[netbsd]]></category>
		<category><![CDATA[pfsense]]></category>
		<category><![CDATA[smoothwall]]></category>

		<guid isPermaLink="false">http://extricate.org/?p=256</guid>
		<description><![CDATA[TweetI&#8217;ve generally been very happy with my Netgear DG834G ADSL router. It does ADSL. It does routing. It serves as a wireless access point. However, I felt myself wanting a little more. The web interface is a little rudimentary, so initially I looked into the OpenWRT project. It turns out that the DG834G, as well [...]]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton256" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2009%2F04%2F14%2Fturning-an-old-laptop-into-a-router-with-pfsense%2F&amp;text=Turning%20an%20old%20laptop%20into%20a%20router%20with%20pfSense&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2009%2F04%2F14%2Fturning-an-old-laptop-into-a-router-with-pfsense%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p>I&#8217;ve generally been very happy with my <a href="http://www.netgear.com/Products/RoutersandGateways/WirelessGRouters/DG834G.aspx">Netgear DG834G</a> ADSL router.  It does ADSL.  It does routing.  It serves as a wireless access point.  However, I felt myself wanting a little more.</p>
<p>The web interface is a little rudimentary, so initially I looked into the <a href="http://openwrt.org/">OpenWRT</a> project.  It turns out that the DG834G, as well as many other routers, runs Linux and there is custom firmware out there to do much cooler things.  Perfect!</p>
<p>Well, not quite.  The support for the DG834G appears rudimentary at this time.  Mainly due to some evil checksum routines on the DG834G which will not allow custom firmwares to run.  These can be bypassed, but it is at this point I started reading more and more pages with the phrase, &#8220;This could brick your router!&#8221; and more forum threads along the lines of, &#8220;My router stopped responding!&#8221;.</p>
<p>The next step was to look into firewalls which can be run on old PC hardware.  I had an old Pentium III-800 laptop kicking around not doing much (I remember ordering a PIII-800 as a server &#8216;back in the day&#8217; for its sheer power). It had Ethernet on board.  So, stick two more PCMCIA cards in (one for Ethernet, one for Wireless) and I&#8217;ve got a router and access point in one.  It is also whisper quiet and generates very little heat.</p>
<p>There are quite a few firewall packages designed to run on old hardware like this.  Initially considered was <a href="http://www.smoothwall.org/">SmoothWall</a>.  However, not for long: No PCMCIA support.</p>
<p><a href="http://www.ipcop.org/">IPCop</a> was next as it features PCMCIA support.  Perfect.  Unfortunately, it would not install.  It made the laptop hard disk perform a &#8216;click of death&#8217; during formatting.  Although worrying, I could not reproduce this with any of the other firewall packages I looked at, or even a full install of <a href="http://www.ubuntu.com/">Ubuntu</a>.</p>
<p>The latter two are based on <a href="http://www.linux.org/">Linux</a>.  I then decided to look at <a href="http://www.pfsense.org/">pfSense</a>, which runs on <a href="http://www.freebsd.org/">FreeBSD</a>.</p>
<p>pfSense supports PCMCIA.  It also scored many bonus points as you can try it out without installing.  It will boot off the CD and you can configure it and go (storing the configuration on removable media).  I was impressed and installed it properly.</p>
<p>The web interface is excellent and has all the fancy graphs that I was after from before.  It was easy to get it to treat the wireless PCMCIA card as an access point, and to bridge it over to my LAN.  pfSense then performed firewall duties between my network and the WAN.</p>
<p>Now, this was a slightly awkward bit.  The Netgear router itself was acting like a bridge.  So I ended up with a 192.168.1.* &#8216;insecure&#8217; network, and my main internal 192.168.0.* secure LAN.  pfSense sorted that out but it felt a bit clunky.  Plus you then hit a &#8216;double NAT&#8217; problem which means NAT will just not work properly on the LAN (as you have one NAT router sitting right behind another).</p>
<p>Thankfully, <a href="http://forums.whirlpool.net.au/forum-replies-archive.cfm/396952.html">the DG834G can be put into pure modem mode</a>.  It won&#8217;t act as a router at all.  It will present itself to pfSense with the ADSL IP address and &#8216;play dumb&#8217;.  This is great as now I just have my 192.168.0.* subnet as before, yet behind pfSense.  Phew.</p>
<p>Again, pfSense made this easy.  Just configure the WAN as PPPoE (You fill in your username and password in pfSense instead of on your ADSL router, as remember the ADSL device is just being a dumb modem).  Note that some ISPs, including mine, state they are PPPoA (which pfSense does not support).  Thankfully, PPPoE worked with my ISP anyway.</p>
<p>My 360 still complained about being in a &#8216;strict NAT&#8217; zone.  That was fixed by some <a href="http://forum.pfsense.org/index.php?topic=13887.0">further NAT configuration</a> and now all is perfect!</p>
<p>There are various cool packages available for pfSense.  For example, a transparent proxy mode for <a href="http://www.squid-cache.org/">squid</a> to cache web content.</p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2009/04/14/turning-an-old-laptop-into-a-router-with-pfsense/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Transparent web proxying: Ubuntu, DG834G, Squid</title>
		<link>http://extricate.org/2009/04/10/transparent-web-proxying-ubuntu-dg834g-squid/</link>
		<comments>http://extricate.org/2009/04/10/transparent-web-proxying-ubuntu-dg834g-squid/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 19:37:44 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[dg834g]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[proxying]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://extricate.org/?p=253</guid>
		<description><![CDATA[TweetI&#8217;ve been tinkering with my home network and in particular with setting up Squid for caching duties. This was easy enough but also required manual configuration on any other systems to actually use it. Wouldn&#8217;t it be easier for this to happen automatically? The answer lies in transparent proxying which turned out to be possible [...]]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton253" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2009%2F04%2F10%2Ftransparent-web-proxying-ubuntu-dg834g-squid%2F&amp;text=Transparent%20web%20proxying%3A%20Ubuntu%2C%20DG834G%2C%20Squid&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2009%2F04%2F10%2Ftransparent-web-proxying-ubuntu-dg834g-squid%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p>I&#8217;ve been tinkering with my home network and in particular with setting up <a href="http://www.squid-cache.org/">Squid</a> for caching duties.  This was easy enough but also required manual configuration on any other systems to actually use it.</p>
<p>Wouldn&#8217;t it be easier for this to happen automatically?</p>
<p>The answer lies in transparent proxying which turned out to be possible with my setup.</p>
<p>I went with Squid3 and that just needed to be told to expect to work in this fashion:</p>
<blockquote><p>
# Squid normally listens to port 3128<br />
http_port 3128 transparent
</p></blockquote>
<p>The next step as to get outbound web traffic redirected to the Squid box, which would then perform its duties.</p>
<p>This would normally require a dedicated firewall, and although most ADSL routers nowadays have rudimentary routing capabilities, I thought I was going to have to end up installing <a href="http://www.smoothwall.org/">Smoothwall</a> or similar.</p>
<p>Thankfully, the <a href="http://www.netgear.co.uk/wireless_adslrouter_dg834g.php">DG834G</a> is running a form of embedded Linux.  Although the web interface doesn&#8217;t allow complex firewall rules changes, it is possible to <a href="http://www.nat32.com/nat32e/htm/dg834g.htm">telnet in directly</a> to play with iptables.</p>
<p>Once in, just a case of setting up the following rules:</p>
<blockquote><p>
iptables -t nat -A PREROUTING -i eth0 -s ! squid-box -p tcp &#8211;dport 80 -j DNAT &#8211;to squid-box:3128<br />
iptables -t nat -A POSTROUTING -o eth0 -s local-network -d squid-box -j SNAT &#8211;to iptables-box<br />
iptables -A FORWARD -s local-network -d squid-box -i eth0 -o eth0 -p tcp &#8211;dport 3128 -j ACCEPT
</p></blockquote>
<p>(With squid-box and local-network replaced with the relevant numbers!)</p>
<p>The above courtesy of: <a href="http://www.faqs.org/docs/Linux-mini/TransparentProxy.html#s6">http://www.faqs.org/docs/Linux-mini/TransparentProxy.html#s6</a>.</p>
<p>Once done, it just works!  One bad thing is that it is not possible to save such custom rules from the telnet interface, so upon a reboot they will need to be manually put back.  There are ways round this as you can roll your own custom firmware but that is something for another time.</p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2009/04/10/transparent-web-proxying-ubuntu-dg834g-squid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Port forwarding with Linux, but no iptables, with socat</title>
		<link>http://extricate.org/2009/03/16/port-forwarding-with-linux-but-no-iptables-with-socat/</link>
		<comments>http://extricate.org/2009/03/16/port-forwarding-with-linux-but-no-iptables-with-socat/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 20:22:15 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[port forwarding]]></category>
		<category><![CDATA[socat]]></category>

		<guid isPermaLink="false">http://extricate.org/?p=250</guid>
		<description><![CDATA[TweetI&#8217;ve recently been experimenting with using Ubuntu as my main desktop at home. I&#8217;ve always been a fan of Linux since my university days and it is great to see how far it has come. I&#8217;m particularly happy that there is now Cisco VPN support. Complete with working with the SecurID keyfobs. Getting connected to [...]]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton250" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2009%2F03%2F16%2Fport-forwarding-with-linux-but-no-iptables-with-socat%2F&amp;text=Port%20forwarding%20with%20Linux%2C%20but%20no%20iptables%2C%20with%20socat&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2009%2F03%2F16%2Fport-forwarding-with-linux-but-no-iptables-with-socat%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p>I&#8217;ve recently been experimenting with using <a href="http://www.ubuntu.com/">Ubuntu</a> as my main desktop at home.  I&#8217;ve always been a fan of <a href="http://www.linux.org/">Linux</a> since my university days and it is great to see how far it has come.</p>
<p>I&#8217;m particularly happy that there is now <a href="http://www.unix-ag.uni-kl.de/~massar/vpnc/">Cisco VPN support</a>.  Complete with working with the <a href="http://en.wikipedia.org/wiki/SecurID">SecurID</a> keyfobs.</p>
<p>Getting connected to my work VPN was trivial once I was pointed in the right direction of which packages to use.  Unfortunately, a snag was that I needed to Remote Desktop to my Windows workstation, but the work firewall was not up to date.  It was blocking me.</p>
<p>I could, however, ssh to our Linux development server, so surely there was a way to use it as a proxy between my home PC and my work PC?</p>
<p>This is normally ideal ground for <a href="http://www.ssh.com/support/documentation/online/ssh/winhelp/32/Tunneling_Explained.html">SSH tunneling</a> but I was not in the position to get <a href="http://www.openssh.com/">OpenSSH</a> installed on the work PC when I couldn&#8217;t get access to it!</p>
<p>The solution: <a href="http://www.dest-unreach.org/socat/">socat</a>.</p>
<p>Easily compiled, establishing an appropriate tunnel was just a matter of invoking:</p>
<blockquote><p>
socat TCP4-LISTEN:5000 TCP4:my-work-pc.somewhere.net:3389
</p></blockquote>
<p>Pointing my Remote Desktop client to that server, on port 5000, meant that the traffic ultimately ended up at the correct place.  Perfect.</p>
<p>Caveats here: <strong>This sort of tunnel is not encrypted</strong>.  In this instance, no problem, as the Internet portion is still going over the secured VPN, and the work network itself is considered trusted.  <a href="http://en.wikipedia.org/wiki/Remote_Desktop_Protocol">RDP</a> traffic is encrypted.</p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2009/03/16/port-forwarding-with-linux-but-no-iptables-with-socat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bill Gates&#8217; Last Day</title>
		<link>http://extricate.org/2008/01/10/bill-gates-last-day/</link>
		<comments>http://extricate.org/2008/01/10/bill-gates-last-day/#comments</comments>
		<pubDate>Thu, 10 Jan 2008 10:19:52 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[bill gates]]></category>
		<category><![CDATA[ces]]></category>
		<category><![CDATA[last day]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://www.extricate.org/2008/01/10/bill-gates-last-day/</guid>
		<description><![CDATA[TweetHere is the best quality video that I could find of the &#8220;Bill Gates&#8217; Last day&#8221; feature, which formed part of Bill&#8217;s Keynote at CES 2008.]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton33" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2008%2F01%2F10%2Fbill-gates-last-day%2F&amp;text=Bill%20Gates%26%238217%3B%20Last%20Day&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2008%2F01%2F10%2Fbill-gates-last-day%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p>Here is the best quality video that I could find of the &#8220;Bill Gates&#8217; Last day&#8221; feature, which formed part of Bill&#8217;s Keynote at <a href="http://www.cesweb.org/">CES 2008.</a></p>
<p><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/IqMDyy1IHAU&#038;rel=1"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/IqMDyy1IHAU&#038;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2008/01/10/bill-gates-last-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lexmark Z1480 Wireless Colour Printer Review</title>
		<link>http://extricate.org/2008/01/01/lexmark-z1480-wireless-colour-printer-review/</link>
		<comments>http://extricate.org/2008/01/01/lexmark-z1480-wireless-colour-printer-review/#comments</comments>
		<pubDate>Tue, 01 Jan 2008 17:11:34 +0000</pubDate>
		<dc:creator>Tris</dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Printers]]></category>
		<category><![CDATA[lexmark]]></category>
		<category><![CDATA[printer]]></category>
		<category><![CDATA[printing]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[z1480]]></category>

		<guid isPermaLink="false">http://www.extricate.org/2008/01/01/lexmark-z1480-wireless-colour-printer-review/</guid>
		<description><![CDATA[TweetMy first, and last printer was a Citizen Swift 9 dot-matrix which used to be rigged up to my old Commodore Amiga computer. A quick Google only found a slightly more modern version of it: Citizen Swift 90E. Those were the days. When printers were printing, they MEANT it. Every line was accompanied with the [...]]]></description>
			<content:encoded><![CDATA[<div id="tweetbutton27" class="tw_button" style="float: right; margin-right: 10px;"><a href="http://twitter.com/share?url=http%3A%2F%2Fextricate.org%2F2008%2F01%2F01%2Flexmark-z1480-wireless-colour-printer-review%2F&amp;text=Lexmark%20Z1480%20Wireless%20Colour%20Printer%20Review&amp;related=&amp;lang=en&amp;count=vertical&amp;counturl=http%3A%2F%2Fextricate.org%2F2008%2F01%2F01%2Flexmark-z1480-wireless-colour-printer-review%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://extricate.org/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div><p>My first, and last printer was a Citizen Swift 9 dot-matrix which used to be rigged up to my old <a href="http://en.wikipedia.org/wiki/Amiga">Commodore Amiga</a> computer.  A quick Google only found a slightly more modern version of it: <a href="http://www.xma.co.uk/product.aspx?XMACode=CIT1371&#038;L1=PR&#038;L2=DM">Citizen Swift 90E</a>.</p>
<p>Those were the days.  When printers were printing, they MEANT it.  Every line was accompanied with the clatter of pins striking the ribbon and paper.  It was only really suitable for text printing, as graphics never came out very well, and I did dream of one day having a <a href="http://en.wikipedia.org/wiki/Laser_printer">laser printer</a> &#8211; prohibitively expensive at the time.</p>
<p>That printer lasted a long time, but was never the same after an unfortunate sticky label incident (the labels came off inside the printer mechanism).  That was&#8230;messy.</p>
<p>So, since then I&#8217;ve never owned a printer.  I&#8217;ve just printed anything I needed either at university or work.</p>
<p>But I succumbed today.</p>
<p>I picked up the <a href="http://www.pcworld.co.uk/martprd/product/seo/016724">Lexmark Z1480</a> which was on special offer from <a href="http://www.pcworld.co.uk/">PC World</a>.  Nicely, it comes with everything in the box (bar paper), so no <a href="http://onlinedictionary.datasegment.com/word/nickel-and-diming">nickel and diming</a> for cabling and the like.  As is the way with printers, replacement cartridges will be where the expense comes in.</p>
<p>One of the main requirements was a printer with network connectivity as laptops rule the roost here.  Alas, none of the laser printers tended to have this unless extra money was spent.  However, the <a href="http://en.wikipedia.org/wiki/Inkjet_printer">Inkjet</a> printers had this as quite a common feature, even wireless.  Then it was just a case of finding a printer which didn&#8217;t have the tacked on scanner, fax machine, toaster, microwave etc.</p>
<p>The Z1480 is a straightforward wireless colour printer (although it can be connected via USB).  Set-up is pretty easy (The CD walks you through it, including wireless network connection &#8212; it detected the encrypted one here just fine, prompting for the passphrase).  After that, it Just Works as any other printer (Tested under Windows XP and Vista).  Note that a USB cable is supplied for use during this set-up phase.</p>
<p>The desk footprint is quite respectable, and is a simple rectangular shape.  This is another problem with some of the All-In-One units which seem to be trying to out-do each other in how fanciful they look.</p>
<p>Quality is better than I expected considering the cheap price.  One thing I&#8217;ve disliked about Inkjets generally is &#8220;wobbly text syndrome&#8221; when text is misligned and, well, just wobbly.  But it is crisp here.  A few test photographs came out okay as well, although this is not something I have done on proper glossy photo paper yet.  To be honest, for keep-worthy photographs, I&#8217;d send them off to <a href="http://www.photobox.co.uk/">Photobox</a> as per usual.</p>
<p>Now to see just how long the printer cartridges last, and whether anything falls off it.</p>
<p>One thing is for sure: I&#8217;ll be avoiding sticking any sticky labels inside it.</p>
]]></content:encoded>
			<wfw:commentRss>http://extricate.org/2008/01/01/lexmark-z1480-wireless-colour-printer-review/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

