<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BrainDeadProjects.com &#187; What?!</title>
	<atom:link href="http://www.braindeadprojects.com/blog/category/what/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.braindeadprojects.com/blog</link>
	<description>A place for low-grade evil.</description>
	<lastBuildDate>Mon, 21 Jun 2010 00:36:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>The New Voice LAN</title>
		<link>http://www.braindeadprojects.com/blog/what/the-new-voice-lan/</link>
		<comments>http://www.braindeadprojects.com/blog/what/the-new-voice-lan/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 00:33:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Asterisk]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[VLAN]]></category>
		<category><![CDATA[VOIP]]></category>
		<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=475</guid>
		<description><![CDATA[I&#8217;ve been meaning to look at the voice capabilities of the 1750&#8242;s I&#8217;d purchased while studying for my CCNA (In previous posts I misspoke and claimed they were 1751&#8242;s, they are in -fact 1750&#8242;s).  The Cisco 1750&#8242;s have a slot for Voice Interface Cards, something I&#8217;ve not worked with &#8211; and something that influenced my [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been meaning to look at the voice capabilities of the 1750&#8242;s I&#8217;d purchased while studying for my <a href="http://">CCNA</a></p>
<p>(<em>In previous posts I misspoke and claimed they were 1751&#8242;s, they are in -fact 1750&#8242;s</em>).  The Cisco 1750&#8242;s have a slot for Voice Interface Cards, something I&#8217;ve not worked with &#8211; and something that influenced my purchase of the routers.</p>
<div id="attachment_485" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/dsc03224.jpg"><img class="size-medium wp-image-485" title="Bones of a 1750" src="http://www.braindeadprojects.com/blog/wp-content/dsc03224-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">PVDM module goes in the top empty slot, DIMM in the right empty slot</p></div>
<p>I quickly realized I&#8217;d need a Digital Signal Processor (<a href="https://supportforums.cisco.com/docs/DOC-5211/diff;jsessionid=EAB5487FBCDE5A8BC2DEF57AAF4CDA95.node0?secondVersionNumber=3" target="_blank">PVDM</a>) card (~$90 on ebay) in addition to the VICs &#8211; AND I didn&#8217;t have enough memory OR flash to run an appropriate IOS image. The Flash upgrade to 32M was appx $30.00, with memory running about the same. Things started to quickly add up.</p>
<div id="attachment_488" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/dsc03219.jpg"><img class="size-medium wp-image-488" title="Bottom of a 1750" src="http://www.braindeadprojects.com/blog/wp-content/dsc03219-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">Right side is where the replaceable Flash goes</p></div>
<p>Which made me look at the Cisco 2621 also sitting on my work-bench.  Research quickly revealed I was looking at a much more affordable path.  I got a pretty good deal on an NM-2V with 2 FXO cards (ebay &#8211; about $115.00 &#8211; with the added bonus that the seller lives in my same city, so I saved on shipping and we met in an <a href="http://www.aldifoods.com/" target="_blank">Aldi&#8217;s </a> parking lot):</p>
<p>The NM-2V supports two VIC cards&#8230; the FXO (Foreign eXhange Office ~= PSTN origination/termination) and FXS (Foreign eXchange Service ~= provices dialtone service)  cards generally run about $50.00 on ebay, with the NM-2V averaging around $14-$45. So all in all, I paid at or below the average price for the entire package, and it all arrives at the same time. (There are other types of cards as well, but FXO and FXS are the only types I&#8217;m concerned with)</p>
<p>My first task is to get enough memory installed in my 2621 to support an IOS image with VOIP and ADSL capabilities. I&#8217;d searched around for some time before finding a site that I really like &#8211; <a href="http://www.parts-quick.com/cisco-2621-router-memory.html" target="_blank">www.parts-quick.com</a>. They provide full specs on each router, the  max and min memory capabilities, flash upgrades, etc.. and the prices aren&#8217;t bad either.</p>
<div id="attachment_482" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/dsc03217.jpg"><img class="size-medium wp-image-482" title="Inside the bones of a 2621" src="http://www.braindeadprojects.com/blog/wp-content/dsc03217-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">The Glowing Bones of a Cisco 2621</p></div>
<p>My overall goal is to have one device that handles everything related to the telephone line: DSL termination/bridging, PSTN gateway, and dialtone server &#8211; a device I&#8217;m affectionately calling &#8220;<a href="http://en.wikipedia.org/wiki/Beige_box_(phreaking)" target="_blank">beigebox</a>0&#8243;. This will allow me to replace my Zyxel DSL bridge and Linksys PAP-2T, plus actually hook the PBX  into the PSTN. My current layout (an Asterisk box + Linksys PAP-2T)  has only SIP origination/termination, leaving an unused POTS line coming into my house. The new setup will still utilize the Asterisk PBX for voicemail and dialplan processing (as well as long distance over SIP, and an IAX2 trunk to <a href="http://telephreak.org" target="_blank">Telephreak</a>) , but use the Cisco 2621 for local call termination (calls in my native ratecenter).</p>
<div id="attachment_513" class="wp-caption aligncenter" style="width: 460px"><a href="http://www.braindeadprojects.com/blog/wp-content/new_voice_lan-3.png"><img class="size-medium wp-image-513" title="The New Voice LAN" src="http://www.braindeadprojects.com/blog/wp-content/new_voice_lan-3.png" alt="" width="450" height="337" /></a><p class="wp-caption-text">The New Voice Lan (We don&#39;t need no stinkin&#39; Visio)</p></div>
<p>Routing (and PPPoE) will still be handled by the <a href="http://www.braindeadprojects.com/blog/what/multiple-wan-linux-based-router/" target="_blank">Quagga router</a>.  The Quagga also has a Courier V.32 Voice modem connected to it for troubleshooting dialup POPs, <a href="http://www.softwink.com/iwar/" target="_blank">wardialing</a> the 900 or so phone numbers my company owns (for auditing purposes),  and adding a backup connection in the event the DSL line goes dead (of course if dialtone is gone also, I&#8217;m out of luck). The modem _could_ be moved over to the 2621&#8242;s AUX port, but as all routing occurs at the Quagga, this layout makes more sense.</p>
<p>The link between the 2621 and the PBX could have been done a number of different ways. In the end, I opted to treat the 2621 as being on the WAN side of things, and I am using its management IP for that SIP endpoint. This gives me the ability to filter traffic between the PBX and the &#8220;beigebox&#8221; at the router. Directly connecting the 2621 to the PBX would reduce hop-count, however also add another location where firewall rules need to be managed and monitored aggressively.</p>
<p>Calls made from the home phone hit the 2621 via the FXS port, and are SIP-ed over the FastEthernet interface through the router and to the PBX.  If the call is long-distance it heads  BACK out the router to my SIP provider, with local calls heading back to the 2621 for connection to the PSTN. <em>All</em> call routing (local and long distance) is determined at the PBX. (The one exception being 911, which is immediately bridged at beigebox0)</p>
<div id="attachment_521" class="wp-caption aligncenter" style="width: 460px"><a href="http://www.braindeadprojects.com/blog/wp-content/Call-flow.png"><img class="size-medium wp-image-521" title="Call flow" src="http://www.braindeadprojects.com/blog/wp-content/Call-flow.png" alt="" width="450" height="337" /></a><p class="wp-caption-text">Basic flow of an outbound call</p></div>
<p style="text-align: center;">
<p>Incoming calls from the PSTN (via the FXO voice-port)  will soon be  sent to the PBX for handling &#8211; which will initially sends the call back to beigebox0 to ring the home phone (via the FXS port), and following a number of rings sent to voicemail on the PBX.</p>
<p>So far, the layout has functioned perfectly. Next up &#8211; finish inbound handling of calls on the PBX (voicemail, etc)</p>
<p><strong>Cisco 2621 config snippet:<br />
</strong></p>
<blockquote><p>hostname beigebox0</p>
<p>voice rtp send-recv<br />
!<br />
voice service voip<br />
sip<br />
bind all source-interface FastEthernet0/0</p>
<p>voice-port 1/0/0<br />
description POTS line<br />
ring number 10<br />
!<br />
voice-port 1/0/1<br />
!<br />
voice-port 1/1/0<br />
description HomePhone<br />
timeouts call-disconnect 10<br />
!<br />
voice-port 1/1/1<br />
description ModemLine<br />
timeouts call-disconnect 10<br />
!</p>
<p>!<br />
!<br />
dial-peer voice 100 pots<br />
description Dialing 411<br />
destination-pattern ^411$<br />
port 1/0/0<br />
!<br />
dial-peer voice 101 pots<br />
description Dialing 911<br />
destination-pattern ^911$<br />
port 1/0/0<br />
!<br />
dial-peer voice 102 voip<br />
description TelePhreak<br />
destination-pattern ^666$<br />
session protocol sipv2<br />
session target sip-server<br />
session transport udp<br />
dtmf-relay rtp-nte<br />
codec g711ulaw<br />
no vad<br />
!<br />
dial-peer voice 200 pots<br />
description PBXManualCallRouting<br />
destination-pattern ^70001&#8230;&#8230;.$<br />
port 1/0/0<br />
forward-digits 7<br />
!</p>
<p>dial-peer voice 300 voip<br />
description PBXConnector<br />
destination-pattern .T<br />
session protocol sipv2<br />
session target sip-server<br />
session transport udp<br />
dtmf-relay rtp-nte<br />
codec g711ulaw<br />
no vad<br />
!<br />
sip-ua<br />
calling-info pstn-to-sip from name set beigebox<br />
calling-info pstn-to-sip from number set 70001<br />
sip-server ipv4:&lt;PBX IP&gt;:5060<br />
!<br />
!<br />
telephony-service</p></blockquote>
<p><strong>Asterisk sip.conf config snippet:</strong></p>
<blockquote><p><strong> </strong>[beigebox]<br />
type=friend<br />
host=&lt;2621 Management IP&gt;<br />
nat=no<br />
qualify=no<br />
insecure=invite<br />
canreinvite=no<br />
context=beigebox</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/the-new-voice-lan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetflowLive!</title>
		<link>http://www.braindeadprojects.com/blog/what/netflowlive/</link>
		<comments>http://www.braindeadprojects.com/blog/what/netflowlive/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 21:08:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=573</guid>
		<description><![CDATA[The good news is this &#8211; we&#8217;re now up to 30 subscribers on the neighborhood wifi. With an average of 1.75 users online at any given moment: I&#8217;ve also started working on writing a Netflow analyzer application, based off a similar application I wrote for work.  At the current time, this version  only streams real-time [...]]]></description>
			<content:encoded><![CDATA[<p>The good news is this &#8211; we&#8217;re now up to 30 subscribers on the neighborhood wifi.</p>
<div id="attachment_624" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/30.png"><img class="size-medium wp-image-624" title="Now up to 30 users" src="http://www.braindeadprojects.com/blog/wp-content/30-300x81.png" alt="" width="300" height="81" /></a><p class="wp-caption-text">Currently 30 subscribers on the wireless</p></div>
<p>With an average of 1.75 users online at any given moment:</p>
<div id="attachment_626" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/onlines.png"><img class="size-medium wp-image-626" title="Users online at any given moment" src="http://www.braindeadprojects.com/blog/wp-content/onlines-300x81.png" alt="" width="300" height="81" /></a><p class="wp-caption-text">Users online at any given moment.</p></div>
<p>I&#8217;ve also started working on writing a <a href="http://en.wikipedia.org/wiki/Netflow">Netflow</a> analyzer application, based off a similar application I wrote for work.  At the current time, this version  only streams real-time connection endpoints and DNS statistics (last resolved sites, most resolved sites), as well as detects TCP SYN scans. Each flow record is also colorized (similar to what you would see in <a href="http://www.wireshark.org/" target="_blank">Wireshark</a>), to further categorize the type of connection.</p>
<p>Instead of calling the <a href="http://php.net/manual/en/function.gethostbyaddr.php" target="_blank"><em>gethostbyaddr()</em> function</a> on a destination IP  (which simply pulls a PTR record, and in the world of vhosts is a poor representation of where a user is actually connecting),  subscriber DNS queries are syslogged offsite and parsed.  The Netflow Live application I&#8217;m building uses those parsed and stored queries to give a fairly accurate determination of what site is being visited when.</p>
<p>Visited URLs could also be determined and logged  if a transparent <a href="www.squid-cache.org/">Squid proxy</a> was utilized on the Access Points. I have <strong>NO</strong> intention of doing this, however. I&#8217;m only concerned with endpoints and protocols being used. The number one protocol in use on the network:  <a href="http://en.wikipedia.org/wiki/Hypertext_Transfer_Protocol" target="_blank">HTTP</a> (Shocking!)</p>
<div id="attachment_574" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/netflow3.png"><img class="size-medium wp-image-574" title="Netflow" src="http://www.braindeadprojects.com/blog/wp-content/netflow3-300x208.png" alt="" width="300" height="208" /></a><p class="wp-caption-text">Netflow Live (streaming recent connections)</p></div>
<p>For those of you unfamiliar with <a href="http://en.wikipedia.org/wiki/Netflow">Netflow</a>, it&#8217;s a solution put forth by <a href="http://www.cisco.com" target="_blank">Cisco</a> for IP traffic profiling. The two main elements are an exporter (usually a router) and a collector (which the exporter sends flow data to). Netflow <strong><em>does not include data  payloads</em> </strong>, ONLY a log of the endpoints used in each connection. (Think of it this way: When you make a long distance phone-call, you receive a monthly bill that details your phone number called another phone number at a specific time, for a specific duration. The phone company doesn&#8217;t actually have record of the conversation, however).</p>
<p>The data collected <em><strong>does</strong> </em>include IP source and destination addresses, Transport layer source and destination ports, byte countes, packet counts, TCP flags, and MAC addresses. (Below is all the fields actually captured)</p>
<p style="text-align: center;">
<div id="attachment_640" class="wp-caption aligncenter" style="width: 470px"><a href="http://www.braindeadprojects.com/blog/wp-content/mysql.png"><img class="size-full wp-image-640" title="mysql" src="http://www.braindeadprojects.com/blog/wp-content/mysql.png" alt="" width="460" height="272" /></a><p class="wp-caption-text">This is all the data that&#39;s actually stored from each connection.</p></div>
<p>So what does this allow? Utilizing Netflow, I can determine subscribers on the network with certain <a href="http://www.symantec.com/connect/articles/detecting-worms-and-abnormal-activities-netflow-part-1">network signatures for viruses</a>, detect some <a href="http://en.wikipedia.org/wiki/Dos_attack" target="_blank">DoS attacks</a> and <a href="http://en.wikipedia.org/wiki/Port_scanner#SYN_scanning" target="_self">SYN scans</a>, and graph the most commonly used protocols on the network.</p>
<p>I can also shape traffic based on determinations made by looking at the data. Is someone experiencing bad <a href="http://www.skype.com" target="_blank">Skype</a> calls due to someone streaming video over HTTP? I can use the netflow data to reshape things as needed.</p>
<p>So what&#8217;s in the works? Using NetGeo data, I plan on mapping connection endpoints on a US world map, allowing a visual display of where in the world most connections are destined.</p>
<p style="text-align: center;">
<div id="attachment_637" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/orion-netflow.png"><img class="size-medium wp-image-637" title="orion-netflow" src="http://www.braindeadprojects.com/blog/wp-content/orion-netflow-300x95.png" alt="" width="300" height="95" /></a><p class="wp-caption-text">Orion Netflow offers the same functionality I&#39;m going for - but at a hefty pricetag.</p></div>
<p>But next up:  I  need to fix the  bug preventing a software reboot of the access points &#8211; hopefully I can get to that this weekend.</p>
<p><strong>Update  6/9/2010</strong>:</p>
<p><a href="http://www.braindeadprojects.com/blog/what/netflowlive/#comments">Jake Wilson pointed out</a> the free NetFlow analyzer <em>Scrutinizer</em> by <a href="http://plixer.com">Plixer</a>. I&#8217;ve not had a chance to look it over yet &#8211; but check out <a href="http://www.youtube.com/watch?v=ilxknbKJ0Pc">this video</a> about the product.  I first came across that video a month or two ago&#8230; it was like staring at the sun, initially I couldn&#8217;t tell if I liked it or not &#8211; but I watched it like 20 times that day.  GREAT work guys, catchy AND entertaining.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/netflowlive/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Bow to the new Queen</title>
		<link>http://www.braindeadprojects.com/blog/what/bow-to-the-new-queen/</link>
		<comments>http://www.braindeadprojects.com/blog/what/bow-to-the-new-queen/#comments</comments>
		<pubDate>Mon, 24 May 2010 00:30:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=597</guid>
		<description><![CDATA[After attending the season ending of the Harrisburg Symphony Orchestra, grabbing a bite at Harrisburg&#8217;s best sushi joint (props to my other favorite though, which is much less expensive), and heading home, my girlfriend pointed out &#8220;there&#8217;s a HUGE ant in the corner by the front door.&#8221; It was this time last year that my [...]]]></description>
			<content:encoded><![CDATA[<p>After attending the season ending of the <a href="http://www.harrisburgsymphony.org/" target="_self">Harrisburg Symphony Orchestra</a>, grabbing a bite at <a href="http://www.dineindie.com/MiyakoSushionSecondStreet" target="_blank">Harrisburg&#8217;s <strong>best</strong> sushi joint</a> (props to <a href="http://www.fujidosushi.com/" target="_blank">my other favorite</a> though, which is much less expensive), and heading home, my girlfriend pointed out &#8220;there&#8217;s a HUGE ant in the corner by the front door.&#8221;</p>
<p>It was this time last year that my <em>almost</em> successful attempt at <a href="/blog/what/the-intel-qx3-microscope/" target="_blank">rearing an ant colony in a plaster-cast formicarium </a>failed.  Since then, other projects have taken precedence, and all my equipment (test-tubes, tubing, home-made asperators, numerous containers, etc&#8230;) have been packed away in the basement). I immediately ran downstairs and grabbed out the first container and spool of tubing I could find.</p>
<div id="attachment_594" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/3512404575_9fc57b0243.jpg"><img class="size-medium wp-image-594" title="Ant Formicarium" src="http://www.braindeadprojects.com/blog/wp-content/3512404575_9fc57b0243-300x274.jpg" alt="" width="300" height="274" /></a><p class="wp-caption-text">One of the earlier plaster cast nests</p></div>
<p>I&#8217;m still not entirely sure what killed off the last colony -  only 2 ants hatched prior to them all being found dead.  There&#8217;s a couple likely possibilities: I fed them a few pieces of birdseed &#8211; learning later that some birdseed contains pesticide; there may have been a lack of oxygen in the formicarium (I was hoping the large amount of evaporating water would provide an ample amount of oxygen), the clay used to form the chambers in the formicarium <a href="http://antfarm.yuku.com/topic/9077" target="_blank">possibly contained sulphur</a>&#8230;.</p>
<p>So, I&#8217;m picking up and starting all over. The gang at <a href="http://antfarm.yuku.com">antfarm.yuku.com</a> have put together a <em><strong>great</strong></em> forum on ant care, building formicariums, general tips &#8211; AND <a href="http://antfarm.yuku.com/topic/7397" target="_blank">they do ant identifications</a>.</p>
<div id="attachment_598" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/dsc03231.jpg"><img class="size-medium wp-image-598" title="Ant Queen" src="http://www.braindeadprojects.com/blog/wp-content/dsc03231-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">The New Ant Queen</p></div>
<div id="attachment_599" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/dsc03232.jpg"><img class="size-medium wp-image-599" title="The New Ant Queen" src="http://www.braindeadprojects.com/blog/wp-content/dsc03232-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">She appears to have laid a couple eggs.</p></div>
<p>After providing the pictures and <a href="http://antfarm.yuku.com/topic/9930" target="_blank">a brief description</a> &#8211; it appears this may be Camponotus Pennsylvanicus. (I believe that&#8217;s a carpenter ant). Not exactly the best thing to have in one&#8217;s house, but I&#8217;ve seen no visible wood damage anywhere.</p>
<p>Instead of re-using the former plaster-cast nest, I&#8217;m starting over. The plastic box is readily available at the local <a href="http://www.michaels.com" target="_blank">Michaels Arts and Crafts Store</a>, I purchased 3 initially, so I have another one laying around. To form the chambers in your formicarium, you simply apply clay to the walls. After filling the enclosure with plaster of paris and allowing time for it to dry, you pull the cast out of the box and remove the clay.</p>
<p style="text-align: center;">
<div id="attachment_609" class="wp-caption aligncenter" style="width: 310px"><a href="http://antfarm.yuku.com/topic/885"><img class="size-medium wp-image-609" title="Clay in mould" src="http://www.braindeadprojects.com/blog/wp-content/mould-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">Image is of yuku.com member &quot;The Darkwun&quot; applying clay.</p></div>
<p style="text-align: left;">My former nest (see the topmost  picture) had a drilled hole to allow for application of water at the base. The top portion (the lid) of the nest had a thermometer and humidity meter. I also had a connector tube allowing me to connect the formicarium to a food scavenging area. The nest itself had many wraparound tunnels going around each side.</p>
<p style="text-align: left;">My current plans are to keep the exact same idea, although use deeper chambers. Honestly, I couldn&#8217;t have been happier with the former nest, but I&#8217;d rather not risk the possibility of contamination.</p>
<p style="text-align: left;">I&#8217;ll post pictures of the new build in the coming week. In the meantime take a look at <a href="http://www.youtube.com/watch?v=pqSZC7btVsA" target="_blank">this video of ants farming aphids.</a></p>
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/bow-to-the-new-queen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Wireless Toy</title>
		<link>http://www.braindeadprojects.com/blog/what/new-wireless-toy/</link>
		<comments>http://www.braindeadprojects.com/blog/what/new-wireless-toy/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 18:17:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[RF]]></category>
		<category><![CDATA[What?!]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=426</guid>
		<description><![CDATA[I&#8217;ve really been enjoying the feedback on the free wireless access from my neighbors. As always, everytime I start a new hobby, I end up with a handful of new toys &#8211; and I got one just today: The Wi-Spy 2.4x is a portable USB spectrum analyzer for the 2.4Ghz range (They have other models [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve really been enjoying the feedback on the <a href="http://www.braindeadprojects.com/blog/rf/a-new-look-for-wireless/" target="_blank">free wireless access</a> from my neighbors. As always, everytime I start a new hobby, I end up with a handful of new toys &#8211; and I got one just today:</p>
<div id="attachment_440" class="wp-caption aligncenter" style="width: 256px"><a href="http://www.braindeadprojects.com/blog/wp-content/wi-spy.jpg"><img class="size-medium wp-image-440" title="wi-spy" src="http://www.braindeadprojects.com/blog/wp-content/wi-spy-246x300.jpg" alt="" width="246" height="300" /></a><p class="wp-caption-text">The Wi-Spy 2.4x</p></div>
<p>The <a href="http://www.metageek.net/products/wi-spy-24x" target="_blank">Wi-Spy 2.4x</a> is a portable USB spectrum analyzer for the 2.4Ghz range (They have other models that cover 900mhz and 2.4/5Ghz). The 2.4x model includes an external antenna (SMA), whereas the 2.4i has an internal antenna only.</p>
<div id="attachment_425" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/Chanalyzer.png"><img class="size-medium wp-image-425" title="Chanalyzer" src="http://www.braindeadprojects.com/blog/wp-content/Chanalyzer-300x225.png" alt="" width="300" height="225" /></a><p class="wp-caption-text">The Accompanying Chanalyzer software</p></div>
<p>With the use of a wireless card, one can overlay SSID&#8217;s atop the channels in the Topographical  graph and determine what radiation  belongs to which Access Point. The bottom graph (Planar view) allows one to view which Zigbee channel, wifi channel, or frequency range is most in use.</p>
<p>There&#8217;s a similar device on the market which is substantially cheaper, the <a href="http://www.ubnt.com/airview" target="_blank">Airview</a>,  manufactured by Ubiquiti Networks (~$39 vs. ~$160), but from what I&#8217;ve seen, the <a href="http://www.metageek.net/products/chanalyzer-3" target="_blank">Chanalyzer</a> sofware in use with the Wi-Spy appears to have more features (the ability to record your captures, the ability to overlay RF &#8220;fingerprints&#8221; of various devices atop your captures), etc. The Airview software is written in Java (Read:  supported in Linux), whereas Chanalyzer is written in .NET (good luck with that one under WINE).</p>
<p>There <strong>are</strong> Linux tools for use with the Wi-Spy (<a href="http://www.kismetwireless.net/spectools/" target="_blank">Spectrum-Tools</a>) which I can defnitely appreciate,  but again the recording/playback and fingerprinting along with SSID overlays really make Chanalyzer nice. (For the record, you <em>can </em>actually record the data using one of the tools in the Spectrum Tools suite&#8230; I don&#8217;t believe you can playback easily though)</p>
<div id="attachment_430" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/spectools.png"><img class="size-medium wp-image-430" title="Spectrum Tools" src="http://www.braindeadprojects.com/blog/wp-content/spectools-300x268.png" alt="" width="300" height="268" /></a><p class="wp-caption-text">Spectrum Tools: from the author of Kismet</p></div>
<p style="text-align: center;">
<p>I&#8217;m supposed to be working on a number of other things at the moment (studying for an exam being the major item on my to-do list) so unfortunately this post is more of a &#8220;guess what I just got&#8221; as opposed to a &#8220;look at what this can do&#8221;.  In the next few weeks, I plan on picking up an AirView also, and will provide a side-by-side comparison of the two.</p>
<p>In the meantime, check out this <a href="http://www.youtube.com/watch?v=X_tnugzQIKU&amp;feature=player_embedded" target="_blank">video</a> advertising the Wi-Spy, and if you have any experience, recommendations or thoughts on it or the AirView &#8211; hit me up in the <a href="http://www.braindeadprojects.com/blog/?p=426#respond" target="_self">comments</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/new-wireless-toy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Music: Ripping and Audioscrobbling</title>
		<link>http://www.braindeadprojects.com/blog/what/music-ripping-and-audioscrobbling/</link>
		<comments>http://www.braindeadprojects.com/blog/what/music-ripping-and-audioscrobbling/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 21:31:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=384</guid>
		<description><![CDATA[I&#8217;m a big fan of Last.fm &#8211; a social networking site that allows you to stream audio and share your music interests with others. You may have noticed the inclusion of my recently listened to tracks on the bottom right side of this screen: One of the major benefits to LastFM is it&#8217;s API &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a big fan of <a href="http://last.fm" target="_blank">Last.fm</a> &#8211; a social networking site that allows you to stream audio and share your music interests with others.</p>
<div id="attachment_398" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/grip-3.jpg"><img class="size-medium wp-image-398" title="LastFM Social Site" src="http://www.braindeadprojects.com/blog/wp-content/grip-3-300x228.jpg" alt="" width="300" height="228" /></a><p class="wp-caption-text">The LastFM Social Site</p></div>
<p>You may have noticed the inclusion of my recently listened to tracks on the bottom right side of this screen:</p>
<div id="attachment_395" class="wp-caption aligncenter" style="width: 286px"><a href="http://www.braindeadprojects.com/blog/wp-content/grip-41.jpg"><img class="size-medium wp-image-395" title="The LastPlayer Flash Display" src="http://www.braindeadprojects.com/blog/wp-content/grip-41-276x300.jpg" alt="" width="276" height="300" /></a><p class="wp-caption-text">My recently listened to songs.</p></div>
<p>One of the major benefits to LastFM is it&#8217;s API &#8211; instead of being tied down to using <em>only</em> the LastFM player to &#8216;scrobble, I can use pretty much any open-source audio player I want  &#8211; and still share my recent tracklist with others. (Googling &#8220;pandora API&#8221; reveals that as of a few months ago,  Pandora <a href="http://www.soatothecloud.com/2009/08/sorry-no-pandora-api-here-folks.html" target="_blank">has yet to release an API</a>)</p>
<div id="attachment_392" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/lastfmplayer.png"><img class="size-medium wp-image-392" title="LastFM Player" src="http://www.braindeadprojects.com/blog/wp-content/lastfmplayer-300x294.png" alt="" width="300" height="294" /></a><p class="wp-caption-text">The LastFM player</p></div>
<p>The open <a href="http://www.last.fm/api" target="_blank">API</a> has allowed a number of really nice applications to be developed &#8211; you can AudioScrobble from an IPhone, a BlackBerry, <a href="http://build.last.fm/item/36" target="_blank">graph</a> your listened-to artists history, etc, etc&#8230;</p>
<p>Personally, my most commonly used item is one of the most minimal: an <a href="http://www.last.fm/group/Mplayer/forum/17668/_/376917" target="_blank">MPlayer CLI wrapper</a> used in conjunction with <a href="http://www.red-bean.com/decklin/lastfmsubmitd/" target="_blank">LastFMSubmitD</a>. This allows me to run my player behind a screen and &#8216;scrobble at the same time. (And running the player behind a screen gives me the freedom to bounce in and out of X)</p>
<div id="attachment_393" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/mplayer.png"><img class="size-medium wp-image-393" title="mplayer behind a screen" src="http://www.braindeadprojects.com/blog/wp-content/mplayer-300x145.png" alt="" width="300" height="145" /></a><p class="wp-caption-text">MPlayer behind a Screen</p></div>
<p>Over the years, I&#8217;ve been <em>slowly</em> working on digitizing all of my audio library. Initially, I was doing the process using only <a href="http://lame.sourceforge.net/" target="_blank">LAME</a> (especially since I generally prefer a command-line tool for most things), however not having anything to add the ID tags to tracks, I finally migrated to using <a href="http://nostatic.org/grip/" target="_blank">GRip</a>.</p>
<div id="attachment_397" class="wp-caption aligncenter" style="width: 297px"><a href="http://www.braindeadprojects.com/blog/wp-content/grip-11.jpg"><img class="size-medium wp-image-397" title="Grip" src="http://www.braindeadprojects.com/blog/wp-content/grip-11-287x300.jpg" alt="" width="287" height="300" /></a><p class="wp-caption-text">Grip and the Velvet Undergound</p></div>
<p>Grip allows you to set whatever format string for filenames you want, handles the CDDB lookups and automates ID3 tagging. I generally don&#8217;t use the audio player, but it&#8217;s there also.</p>
<p>My overall goal is to install an outdoor speaker system in the next few weeks and have my <a href="http://www.braindeadprojects.com/blog/what/mounting-a-raw-dump-using-dd-and-losetup/" target="_blank">WebpadDT</a> streaming my entire audio library over the wireless from a control point in the kitchen.  The Webpad is ready, the library is 1/3 ripped, now it&#8217;s time to find some good speakers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/music-ripping-and-audioscrobbling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Home layout: Layer 2</title>
		<link>http://www.braindeadprojects.com/blog/what/home-layout-layer-2/</link>
		<comments>http://www.braindeadprojects.com/blog/what/home-layout-layer-2/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 21:03:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PPPoE]]></category>
		<category><![CDATA[VLAN]]></category>
		<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=300</guid>
		<description><![CDATA[I&#8217;m just finishing up a CCNA preparatory class at the local community college (I had no idea what to expect on the exam, so thankfully I stumbled across this class). I&#8217;d definitely recommend the course &#8211; the instructor (Shawn Cannady) has done an excellent job covering a wide volume of material in a rapid pace. [...]]]></description>
			<content:encoded><![CDATA[<p><em>I&#8217;m just finishing up a CCNA preparatory class at the <a href="http://hacc.edu/" target="_blank">local community college</a> (I had </em><em><strong>no</strong> idea what to expect on the exam, so thankfully I stumbled across this class). I&#8217;d definitely recommend the course &#8211; the instructor (Shawn Cannady) has done an excellent job covering a wide volume of material in a rapid pace.</em></p>
<p><em>One of my classmates recently asked about how I was segmenting off the <a href="http://www.braindeadprojects.com/blog/what/finally-saying-no-to-nocatsplash/" target="_blank">public wireless </a>from my home LAN. As VLANs, VTPs and PPP were subjects covered in the course, I wrote the following article for the class Wiki:</em></p>
<hr /></hr>
<p>In the United States, many (but not all) providers use PPPoE to establish the layer 2 connection over ADSL. The upside to this method is increased accountability/manageability, as well as the ability to resell the connection to 3rd parties (For non-resold lines, Telcos are shifting to DHCP-only connections however, as there&#8217;s less overhead involved)</p>
<p><strong>Background:</strong> Many smaller ISPs use the local Telco DSLAM equipment along with dedicated circuitry and L2TP tunnels back to the smaller ISP routers &#8211; which terminate the PPP sessions. In such an instance, connections are routed to individual ISPs based on the realm in the authenticating username [username@realm.com/password]. The smaller ISP can then use their ARIN assigned network to assign globally routed IP addresses.</p>
<p>Working for such an ISP, I often take advantage of this setup &#8211; creating new PPPoE username and passwords on our system for individualized connections. Instead of having 3 separate ADSL lines for 3 different Internet connections, I use 1 single ADSL line for 3 different Internet connections. Each &#8220;unique&#8221; connection has it&#8217;s own PPPoE username/password and IP. (The only downside: Each connection shares the bandwidth of the 1 line).</p>
<p>The upside to this configuration is the isolation of Layer 3 &#8211; not all connections pass through the same router on my end of the connection. They do, however, pass through the same switch(es) and ADSL modem (however, at layer 2). Instead of worrying about access-lists to prevent different subnets from communicating with each other, I simply worry about inbound traffic from the WAN side on each connection.</p>
<p>My current home layout (simplified here) contains 2 switches. Switch A is located in my office, while Switch B is located where the phone line enters the upstairs. VLAN 2 connects devices directly to the ADSL modem. VLAN1 connects my home LAN to the LAN ethernet of my main home router.</p>
<p style="text-align: center;"><a href="http://www.braindeadprojects.com/blog/wp-content/creative-use-of-vlans.png"><img class="aligncenter size-medium wp-image-326" title="A creative use of VLANs" src="http://www.braindeadprojects.com/blog/wp-content/creative-use-of-vlans-300x187.png" alt="" width="300" height="187" /></a></p>
<p>In the above layout, any device connecting to the DSL Link (members of VLAN2), must maintain it&#8217;s own PPPoE link to be able to access the Internet. (To simplify this image &#8211; imagine that the Wifi router is plugged directly into the DSL modem and configured to connect using PPPoE. Then, imagine the same thing for all members of VLAN 2)</p>
<p>An 802.1q trunk allows the server in my office direct connection to the ADSL modem, and allows my office LAN to connect to the main router (which in turn, routes traffic out the WAN interface PPPoE connection). There are numerous other devices on the LAN.</p>
<p><em>But why do this???</em></p>
<p>When I initially decided to provide free wireless access to my neighborhood, I had a few requirements. First of all, I did <em><strong>not</strong></em> want my neighbors connecting to my home LAN. Second, for liability reasons I wanted to the free WIFI to have it&#8217;s own globally routed IP address (not an RFC-1918 address NATed with my home static IP). A third requirement was the use of <a href="http://www.pmacct.org/" target="_blank">Netflow version 9</a> to collect various headers from each packet and frame (but not the data payload itself) in the event someone attempted something malicious or a user had major virus issues.</p>
<p>In addition to the WIFI access, on occassion I run dedicated <a href="http://www.braindeadprojects.com/blog/usermode-linux/uml-block-device-issues/" target="_blank">honeypots</a> and <a href="http://dionaea.carnivore.it/" target="_blank">malware collectors</a> &#8211; obviously servers you want <em><strong>completely isolated</strong></em> from your home LAN.</p>
<p>The above layout is by no means entirely bulletproof, but the added complexity means I don&#8217;t have to look over my shoulder as much &#8212; and I don&#8217;t have to maintain access-lists just for the LAN to live in &#8220;separated harmony&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/home-layout-layer-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Tiny Tracker 3+ APRS encoder</title>
		<link>http://www.braindeadprojects.com/blog/what/the-tiny-tracker-3-aprs-encoder/</link>
		<comments>http://www.braindeadprojects.com/blog/what/the-tiny-tracker-3-aprs-encoder/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 19:02:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[RF]]></category>
		<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=201</guid>
		<description><![CDATA[I&#8217;ve been planning on building an APRS beacon into my car for some time, initially contemplating using a WebPadDT + XASTIR to do the work, but that idea quickly posed an issue &#8211; the WebPad was too big to reasonably it in the car with another passenger (at least in my car). Yes, I&#8217;m well [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been planning on building an <a href="en.wikipedia.org/wiki/APRS" target="_blank">APRS</a> beacon into my car for some time, initially contemplating using a <a href="http://www.braindeadprojects.com/blog/what/mounting-a-raw-dump-using-dd-and-losetup/" target="_blank">WebPadDT</a> + <a href="http://www.braindeadprojects.com/blog/what/aprs-using-xastir/" target="_blank">XASTIR</a> to do the work, but that idea quickly posed an issue &#8211; the WebPad was too big to reasonably it in the <a href="http://www.braindeadprojects.com/blog/what/the-fish-turns-111111/" target="_blank">car</a> with another passenger (at least in my car).</p>
<p>Yes, I&#8217;m well aware that APRS is <strong>not</strong> really meant as a vehicle tracking device, and in many circles it&#8217;s frowned upon.</p>
<p>I&#8217;ve enjoyed working with PIC microcontrollers since I was first introduced to the 16f84A years ago. But in all honestly, I&#8217;ve not done more than &#8220;blinky lights&#8221; and very basic modifications to an RC car with them. (Take a look at a great <a href="http://www.micahcarrick.com/04-25-2005/pic-c-programming-linux.html" target="_blank">article</a> to get started working with PICs)</p>
<p><a href="http://www.byonics.com/cables/tinytrak3.php" target="_blank">Byonics</a> has a cool kit &#8211; the Tiny Track3+. Figuring I&#8217;d use it as a chance to exercise my soldering skills (which need a bit of work), and liking the fact that I wouldn&#8217;t have to hunt for each individual component on my own, I picked one up (with GPS unit).</p>
<p>The project build steps are <em>extremely</em> well documented. Literally, every step along the way is fully explained along with color images in the downloadable <a href="http://www.byonics.com/tinytrak/tinytrak3plus.zip" target="_blank">PDF</a>. Build time takes under 1 hour (actually closer to 30 minutes, although I incorrectly soldered the female DB9 connector to J2 and had to waste time de-soldering it).</p>
<p><a href="http://www.braindeadprojects.com/blog/wp-content/tinytrack.png"><img class="aligncenter size-medium wp-image-241" title="The TinyTrack build manual" src="http://www.braindeadprojects.com/blog/wp-content/tinytrack-300x263.png" alt="" width="300" height="263" /></a></p>
<p>Prior to installing the accompanying PIC16f628A chip, I made sure to back up the currently running software (these chips are dirt cheap, and I&#8217;m not entirely sure Byonics will just give me the software if I ever have to replace the chip) Looks like my old serial programmer still works (remember &#8211; the USB to serial adapters generally don&#8217;t put out enough voltage to program a chip, so make sure you have on-board serial):</p>
<div id="attachment_205" class="wp-caption aligncenter" style="width: 235px"><img class="size-medium wp-image-205" title="Old serial PIC programmer" src="http://www.braindeadprojects.com/blog/wp-content/0131001936-225x300.jpg" alt="Old serial PIC programmer" width="225" height="300" /><p class="wp-caption-text">Old serial PIC programmer</p></div>
<p>After backing up the code, I pop the chip into place on the TinyTracker, and voila -the finished product looks like this:</p>
<div id="attachment_204" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-204" title="TinyTracker3+ Fully assembled" src="http://www.braindeadprojects.com/blog/wp-content/0131001457a1-300x225.jpg" alt="TinyTracker3+ Fully Assembled" width="300" height="225" /><p class="wp-caption-text">TinyTracker3+ Fully Assembled (I&#39;m using Lysol in my coffee since I&#39;m out of Half and Half)</p></div>
<p>The Byonics crew have also written software to configure the TinyTracker. Luckily it runs under WINE so I didn&#8217;t have to reboot. To configure, power the J1 DB9 connector with a 9volt battery.</p>
<div id="attachment_206" class="wp-caption aligncenter" style="width: 235px"><img class="size-medium wp-image-206" title="TinyTracker3+ in it's case, being configured serially" src="http://www.braindeadprojects.com/blog/wp-content/0131001500-225x300.jpg" alt="TinyTracker3+ in it's case, being configured serially" width="225" height="300" /><p class="wp-caption-text">TinyTracker3+ in it&#39;s case, being configured serially</p></div>
<p>And run the configuration program (again, it&#8217;s fairly well documented in the manual):</p>
<p><a href="http://www.braindeadprojects.com/blog/wp-content/tinytrackconfig.png"><img class="aligncenter size-medium wp-image-249" title="Tiny Track 3 configuration" src="http://www.braindeadprojects.com/blog/wp-content/tinytrackconfig-300x230.png" alt="" width="300" height="230" /></a></p>
<p>After being hung-up in customs (and a brutal snowstorm), I finally got the radio component of my APRS system &#8211; the <a href="http://www.eham.net/reviews/detail/7191" target="_blank">FD-150A</a> (It took almost a month to get here from Hong Kong)</p>
<p><a href="http://www.braindeadprojects.com/blog/wp-content/0222001300.jpg"><img class="aligncenter size-medium wp-image-221" title="FD-150A" src="http://www.braindeadprojects.com/blog/wp-content/0222001300-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>The output voltage  on the FD-150 battery is ~6.25V, too low to power the TinyTracker3 (which requires 7+V). A voltage multiplier would probably fix that, but my overall goal is to encase all components in a NEMA style box, powering it off the car.  So for the rest of the testing period, I&#8217;m using an external power-supply.</p>
<p>Hopefully in the next few weeks, I&#8217;ll have time to finish the entire setup. Keep checking back, I&#8217;ll post updates when I can.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/the-tiny-tracker-3-aprs-encoder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Happy Birthday webdt.org!!!</title>
		<link>http://www.braindeadprojects.com/blog/what/happy-birthday-webdt-org/</link>
		<comments>http://www.braindeadprojects.com/blog/what/happy-birthday-webdt-org/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 20:34:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=231</guid>
		<description><![CDATA[It was a year ago this month that I received a comment on the braindeadprojects  site from a user named quotaholic. Quotaholic had also picked up a WebpadDt  with the hopes of expanding upon it&#8217;s capabilities. My initial goal was a cheap touchpad screen for a car-pc. Quotaholic was thinking about bigger possibilities &#8211; and [...]]]></description>
			<content:encoded><![CDATA[<p>It was a year ago this month that I received a <a href="http://www.braindeadprojects.com/blog/what/mounting-a-raw-dump-using-dd-and-losetup/#comments" target="_blank">comment</a> on the braindeadprojects  site from a user named quotaholic.</p>
<p>Quotaholic had also picked up a WebpadDt  with the hopes of expanding upon it&#8217;s capabilities. My initial goal was a cheap touchpad screen for a <a href="http://www.braindeadprojects.com/blog/what/mounting-a-raw-dump-using-dd-and-losetup/" target="_blank">car-pc</a>. Quotaholic was thinking about bigger possibilities &#8211; and built himself an entire community site.</p>
<p>So somewhere on or around March of 2009,  <a href="http://www.webdt.org/" target="_blank"> www.webdt.org</a> was born.</p>
<p><a href="http://www.braindeadprojects.com/blog/wp-content/webdt.png"><img class="aligncenter size-medium wp-image-233" title="The webdt site" src="http://www.braindeadprojects.com/blog/wp-content/webdt-300x210.png" alt="" width="300" height="210" /></a></p>
<p>While I don&#8217;t necessarily agree with some of the goals of the site (I personally don&#8217;t understand the point of testing to see which Linux distro&#8217;s will run on the webpad &#8211; and would like to see the community get behind one distro and build releases specifically aimed at the webpad)&#8230; the level of ambition is amazing.</p>
<p>I&#8217;ve not had much time to continue with the webpad on my own. Quotaholic however, has released a <a href="http://webdt.org/index.php?topic=351.0" target="_blank">100M version of Debian Lenny </a>with the <a href="http://lxde.org/lxde" target="_blank">LXDE</a> Desktop Environment geared towards the webpad (penmount drivers working and all)</p>
<p>So what am I doing with my DT now? Using it to stream audio (over my wireless) to my kitchen stereo. And the Gentoo Image that I&#8217;ve put a <strong><em>lot</em> </strong>of work into? Well, that filesystem is on my storage server while I use Quotaholics release.</p>
<p>Happy Birthday <a href="http://webdt.org" target="_blank">webdt.org</a>!!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/happy-birthday-webdt-org/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finally Saying No to NoCatSplash</title>
		<link>http://www.braindeadprojects.com/blog/what/finally-saying-no-to-nocatsplash/</link>
		<comments>http://www.braindeadprojects.com/blog/what/finally-saying-no-to-nocatsplash/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 17:57:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[RF]]></category>
		<category><![CDATA[WRT-54G]]></category>
		<category><![CDATA[What?!]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=211</guid>
		<description><![CDATA[For the last 6 months or so, I&#8217;ve been running a free wireless access point for my neighborhood. In an effort to get my local community to know each other (and local goings-on), I&#8217;ve back-ended the system using the elgg social networking platform. To use the free wifi, you have to register on the social [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.braindeadprojects.com/blog/wp-content/logo-nocat.png"><img class="aligncenter size-full wp-image-226" title="logo-nocat" src="http://www.braindeadprojects.com/blog/wp-content/logo-nocat.png" alt="" width="144" height="144" /></a></p>
<p>For the last 6 months or so, I&#8217;ve been running a free wireless access point for my neighborhood. In an effort to get my local community to know each other (and local goings-on), I&#8217;ve back-ended the system using the <a href="http://elgg.org/" target="_blank">elgg</a> social networking platform.</p>
<p>To use the free wifi, you have to register on the social site.</p>
<div id="attachment_279" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.braindeadprojects.com/blog/wp-content/midtownwifi.png"><img class="size-medium wp-image-279" title="midtownwifi" src="http://www.braindeadprojects.com/blog/wp-content/midtownwifi-300x228.png" alt="" width="300" height="228" /></a><p class="wp-caption-text">The Captive Portal</p></div>
<p>Uptime however has been a major pain &#8211; for quite some time <a href="http://nocat.net">NoCatSplash</a> has been broken in <a href="http://dd-wrt.com/site/index">DD-WRT</a>. Ever since version 24 (at the very least), it&#8217;s been grouchy &#8211; all of the sudden not working and requiring a reboot (or possibly clearing and resetting the iptables targets and restarting splashd)  to fix. The wiki documents a few <a href="http://www.dd-wrt.com/wiki/index.php/NoCatSplash#Work-Around" target="_blank">workarounds</a>, but I&#8217;ve gotten tired of the overall bugs.</p>
<p>Initially I planned on simply fixing it, but after a little bit of thought,  I decided to give <a href="http://openwrt.org" target="_blank">OpenWRT</a> another look. I&#8217;m sure I could have gotten away with using the mini or micro versions of DD-WRT and adding to it, but last time I used OpenWRT&#8217;s build environment I was really impressed &#8211; so I spent this weekend working with it again.</p>
<p>Building your own image is simple &#8211; using the <a href="http://downloads.openwrt.org/kamikaze/8.09.2/brcm-2.4/OpenWrt-ImageBuilder-brcm-2.4-for-Linux-i686.tar.bz2" target="_blank">ImageBuilder</a> system (I&#8217;m working with WRT-54G&#8217;s)  simply &#8220;make image&#8221; setting the target <strong>PROFILE</strong> and <strong>PACKAGES</strong> via environment variables. This method uses existing binary packages to build a .bin or .trx file for easy installation (via the web interface or mtd command). &#8220;<em>make info</em>&#8221; will give you a long list of profiles, and packages that are readily available are contained in the packages subdirectory.</p>
<p>Recompiling packages is extremely easy &#8211; download the SDK:</p>
<blockquote><p>mkdir ~/devel &amp;&amp; cd ~/devel</p>
<p>wget http://downloads.openwrt.org/kamikaze/8.09.2/brcm-2.4/OpenWrt-SDK-brcm-2.4-for-Linux-i686.tar.bz2</p>
<p>tar xjvpf OpenWrt-SDK-brcm-2.4-for-Linux-i686.tar.bz2</p></blockquote>
<p>If the package already exists, check it out via subversion:</p>
<blockquote><p>cd OpenWrt-SDK-brcm-2.4-for-Linux-i686</p>
<p>svn export svn://svn.openwrt.org/openwrt/packages/net/&lt;packagename&gt;  package/&lt;packagename&gt;</p></blockquote>
<p>And to compile simply execute:</p>
<blockquote><p>make package/&lt;packagename&gt;/compile V=99</p></blockquote>
<p>(On older versions it&#8217;s &#8220;make package/&lt;packagename&gt;<strong>-</strong>compile V=99&#8243;)</p>
<p>After hitting my head against the nocatsplash package&#8217;s failure to build correctly, I finally opted to look at <a href="http://kokoro.ucsd.edu/nodogsplash/" target="_blank">nodogsplash</a>. &#8220;Because it will at least build&#8221; is probably not the best way to choose captive portal software, but it&#8217;s mine.</p>
<p>First thing requiring a fix is a bug that causes nodogsplash to crash when one sends a request to the auth-server without a &#8220;redir&#8221; GET variable being set &#8211; a bug evidenced by:</p>
<blockquote><p>links &#8220;http://192.168.1.1:2050/nodogsplash_auth/?tok=fffffff&#8221;</p></blockquote>
<p>Thankfully the crash is &#8220;gracefully&#8221; handled in safe.c&#8217;s safe_strdup()&#8230;. but it still causes the daemon to crash.</p>
<p>So &#8211; a quick patch, as well as some added &#8220;features&#8221; (including a magic token) and I&#8217;m set. Patches to source can be added to package/&lt;packagename&gt;/patches. Upon make, patches in this directory are first applied.</p>
<p>So instead of waiting around for a fix to NoCatSplash in DD-WRT, I&#8217;m moving on. So far NoDogSplash has proven effective &#8211; although I&#8217;m far from actually migrating to it (the old access point is still running for the time being). In the next few weeks I should have a custom web interface built, as well as <a href="www.pmacct.net/ " target="_blank">pmacctd </a>configured (I am exporting Netflow version 9 data to a collector as a <a href="www.pmacct.net/ " target="_blank">C.Y.A </a>measure), and bandwidth shaping properly enabled.</p>
<p>Custom patches to NoDogSplash are forthcoming.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/finally-saying-no-to-nocatsplash/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chasing Ghosts this afternoon&#8230;</title>
		<link>http://www.braindeadprojects.com/blog/what/chasing-ghosts-this-afternoon/</link>
		<comments>http://www.braindeadprojects.com/blog/what/chasing-ghosts-this-afternoon/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 22:21:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[What?!]]></category>

		<guid isPermaLink="false">http://www.braindeadprojects.com/blog/?p=190</guid>
		<description><![CDATA[Starting yesterday evening, I&#8217;ve been noticing a LOT more attempted connections to :445 (tcp). Initially I was under the impression that the issue was isolated to the network I was on, although I&#8217;ve had confirmations from another non-related network (plus another host I have offnet) that :445 traffic is slightly higher than what is believed [...]]]></description>
			<content:encoded><![CDATA[<p>Starting yesterday evening, I&#8217;ve been noticing a LOT more attempted connections to :445 (tcp).</p>
<p>Initially I was under the impression that the issue was isolated to the network I was on, although I&#8217;ve had confirmations from another non-related network (plus another host I have offnet) that :445 traffic is slightly higher than what is believed to be normal, but then again &#8211; what&#8217;s normal (without a good netflow collector and historical data, you probably have no idea)</p>
<p>A quick scan of the DSL routers I have access to, shows 314 unique IPs originating such scans to multiple destinations (this is one quick run of &#8220;show ip cache flow  | i  01BD&#8221; on each of 3 routers). I&#8217;m seeing the same thing on a VPS host I have located in Virginia.</p>
<p>Being a little more than curious, I&#8217;ve fired up <a href="http://nepenthes.carnivore.it/" target="_blank">nepenthes</a> and within 8 minutes I had 3 SMB exploit attempts, where the affected machine tries to download <a href="http://www.threatexpert.com/files/myreceve.com.html">&#8220;myreceve.com&#8221;</a></p>
<p>These exploits were hitting vulnerabilities on :139 (tcp), however, and I don&#8217;t believe are related (also they&#8217;re from the same class B network)</p>
<blockquote><p>66.xx.xx.xx -&gt; 66.xx.xx.xx ftp://1:1@66.xx.xx.xx:9015/myreceve.com</p></blockquote>
<p>Connecting to this host in particular gives a warm welcome:</p>
<blockquote><p>nc 66.xx.xx.xx 9015<br />
220 fuckFtpd 0wns j0</p></blockquote>
<p>Back to what prompted my initial interest &#8211; :445, I can&#8217;t seem to figure out whats really going on &#8211; packet captures indicate more than a normal SYN scan, but without some additional review, I have no idea why so many requests from so many hosts identical to this:</p>
<blockquote><p>NetBIOS Session Service<br />
Message Type: Session message<br />
Length: 47<br />
SMB (Server Message Block Protocol)<br />
SMB Header<br />
Server Component: SMB<br />
SMB Command: Negotiate Protocol (0&#215;72)<br />
Error Class: Success (0&#215;00)<br />
Reserved: 00<br />
Error Code: No Error<br />
Flags: 0&#215;00<br />
Flags2: 0&#215;0000<br />
Process ID High: 0<br />
Signature: 0000000000000000<br />
Reserved: 0000<br />
Tree ID: 0<br />
Process ID: 604<br />
User ID: 0<br />
Multiplex ID: 0<br />
Negotiate Protocol Request (0&#215;72)<br />
Word Count (WCT): 0<br />
Byte Count (BCC): 12<br />
Requested Dialects<br />
Dialect: NT LM 0.12<br />
Buffer Format: Dialect (2)<br />
Name: NT LM 0.12</p></blockquote>
<p>I&#8217;ve only slightly glanced over other SMB sessions, and this seems like a normal request&#8230; I&#8217;m a little baffled as to why every pcap I have from an apparently compromised host uses process id &#8220;604&#8243;, but otherwise each request appears valid.</p>
<p>So&#8230;. it&#8217;s probably nothing (usually is), but it definitely piqued my interest for a time today. Happy Thanksgiving!</p>
<p><strong>Update at 22:25</strong></p>
<p>At the advice of others, I&#8217;m installing <a href="http://dionaea.carnivore.it/">dionaea</a>, which apparently has better SMB support, to see if I can determine exactly what these connections are. I&#8217;ll post an update when I&#8217;m finished.</p>
<p><strong>Update 06:00 11/25/2009</strong></p>
<p>I&#8217;ve got dionea running and collecting bitstreams. Same basic signature (process id: 604), but now with a _lot_ more information in the captures (as dionaea is a little more fluent in the SMB protocol). Tonight: Cooking and reading pcaps.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.braindeadprojects.com/blog/what/chasing-ghosts-this-afternoon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
