Somewhere around version 2.8.4 or something, WordPress introduced a "feature" to focus the username form and wipe the username. I dont want to type my username every time again and again and again. So what can we do to kill wp_attempt_focus? There is no hook available to disable that part of the code, but we can use some dirty tricks:
I created the following 'plugin' to get rid of it: function kill_wp_attempt_focus($in){ return preg_replace('/function wp_attempt_focus/','function wp_attempt_focus(){} function wp_attempt_focus_killed',$in); } if($_SERVER["PHP_SELF"]=='/wp-login.php'){ ob_start('kill_wp_attempt_focus'); }
It grabs the output of /wp-login.php, renames the original wp_attempt_focus() to wp_attempt_focus_killed() and creates a new empty function to prevent errors.
Today I borrowed a USB video device, just to see if I can get it working on Linux. And I did! The device's package shows that is supports PAL (720x576@25fps) and NTSC (720x480 @ 30fps), but not much more.
According to lsusb, the device is built by eMPIA Technology, Inc and it has id eb1a:2861. Because I have another webcam attached, the device is connected to /dev/video1 is a character device with major 81 and minor 1. In the /sys filesystem, there's information on the device. I can find the right node using the next command:
cd /sys/dev/char/81:1
This is a symlink to (in my case) /sys/devices/pci0000:00/0000:00:1d.7/usb2/2-5/2-5:1.0/video4linux/video1. In this directory, I find some more useful information. The file name tells me the device is actually a em28xx-based device.
The device has 2 inputs: a serie of RCA connectors with a composite signal and a SVideo connector. This is represented by showing two "sub-devices". The composite signal is /dev/video1, while the SVideo connector is /dev/vbi0.
To display the screen of my Sony* HDR-SR11 camera, I use the command:
Last week, I was snowboarding with my family in Scheffau, Austria. In the appartment, there was one single cat-5 cable, while 5 of us wanted to use the internet. So I figured out how to build a ad-hoc wifi network with my laptop in order to share the network connection.
My configuration
On my laptop, I'm running Fedora 13 with dnsmasq installed. All other software is pretty standard. My wifi driver creates a wlan0, but other laptops may create wmaster0 interfaces etcetera.
Step 1: Enable routing
We set up IP forwarding: echo 1 > /proc/sys/net/ipv4/ip_forward iptables -I FORWARD -j ACCEPT iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE For a permanent situation, you may want to be a little more picky in what to forward and what not.
Step 2: Set up the wifi
First, we switch from managed mode to ad-hoc mode: /sbin/iwconfig wlan0 mode Ad-Hoc Then we choose a name for the new network. I chose my own name: /sbin/iwconfig wlan0 essid "David" I use WEP, which is pretty insecure, but is just good enough to keep neighbours from connecting by accident. (I would not use this for a network that stays up for more than an hour.): iwconfig wlan0 key 1351351350 And we set the wifi channel to "automatically select a channel": iwconfig wlan0 channel auto
Step 3: Configure the network
Then we must configure an IP. Since 192.168.0.0/16 and 10.0.0.0/8 are mostly used in ADSL environments, I use the third IANA assigned block: 172.16.0.0/12 (172.16.0.0-172.31.255.255): ifconfig wlan0 172.31.1.254 up
I just found back an old note about using iptables in combination with dyndns to open up access from a remote location. For instance, if you have a laptop that you take everywhere and you want to connect to your home or office. The script the other site suggested was broken, so let's write a new one.
Step 1: Create a new chain in the firewall
Create a new chain in the firewall where we can plug in the dynamic rules. On my Fedora machine, the firewall is located in /etc/sysconfig/iptables. I added the bold lines to this example.
*nat
:PREROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
COMMIT
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
<b>:DYNAMIC - [0:0]
-A INPUT -j DYNAMIC</b>
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
Step 2: Write a script
#!/bin/bashHOSTNAME=myname.dyndns.org
CHECK_INTERVAL=60#once a minute/sbin/iptables -F DYNAMIC #flush all existing rulesIP=""#initialize $IPwhile[true]; doOIP=$IPIP=$(host $HOSTNAME|grep-iE"[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+"|cut-f4-d' '|head-n1)if["$OIP"!= "$IP"-a"$IP"!= ""]; thenecho"Changing ip to $IP"/sbin/iptables -F DYNAMIC #flush all old rules/sbin/iptables -I DYNAMIC -s$IP-j ACCEPT #the new rulefisleep$CHECK_INTERVALdone
#!/bin/bash HOSTNAME=myname.dyndns.org
CHECK_INTERVAL=60 #once a minute /sbin/iptables -F DYNAMIC #flush all existing rules
IP="" #initialize $IP
while [ true ]; do
OIP=$IP
IP=$(host $HOSTNAME | grep -iE "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+" |cut -f4 -d' '|head -n 1)
if [ "$OIP" != "$IP" -a "$IP" != "" ]; then
echo "Changing ip to $IP"
/sbin/iptables -F DYNAMIC #flush all old rules
/sbin/iptables -I DYNAMIC -s $IP -j ACCEPT #the new rule
fi
sleep $CHECK_INTERVAL
done
In this case, the firewall accepts all traffic from $IP, but of course you could restrict it to 1 port. Also, I focussed on IPv4, but you could easily rewrite this script to IPv6 using ip6tables. I saved the file to /usr/local/bin/dynfirewall.sh
Step 3: Run the script
I'd prefer running the script from inittab, but since Fedora doesn't work like this anymore, I put the following line in /etc/rc.d/rc.local:
Last weekend, one of my 3com 4250T switches stopped functioning. I used a multimeter and the fuse seems okay, but it's dead as a doorknob. Since my switches are stacked to one virtual unit, I bought a second hand 4250T to replace the broken one.
As often with second hand crap, this switch contained settings from the last location. Including an unknown password.
Fortunately, the switches have a recovery mode (which can also be disabled, so below instructions may not work on another switch).
Recovery mode
I connected the switch to a RS232 port using a null-modem cable. If you know the switches IP, you can also use telnet.
Login: recover Password: recover
*** Password Recovery Mode *** The administrative password will be cleared if a hard reset operation is carried out on the device within 30 seconds.
If a hard reset operation is not carried out during this period, the device will return to the CLI login prompt
countdown = 30...29...28...
Pull the plug of the switch before the countdown reaches 0. When you boot it again, you can login using the default user "admin" and simply press enter for 'password'.
Today, my dear wife asked me to help her with her facebook addiction. She wondered if I could block facebook, gmail, some news sites and more during her work hours. Sure, I can. And since she's running Linux as well, I could even do it on her own computer.
Step 1: Install squid
Squid is a FLOSS proxy server that runs on Linux and several other sytems. It's capable of filtering and behaving transparently. Just what we need.
# Example rule allowing access from your local networks. # Adapt to list your (internal) IP networks from where browsing # should be allowed acl localnet src 10.0.0.0/8 # RFC1918 possible internal network acl localnet src 172.16.0.0/12 # RFC1918 possible internal network acl localnet src 192.168.0.0/16 # RFC1918 possible internal network acl localnet src fc00::/7 # RFC 4193 local private network range acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines
acl SSL_ports port 443 acl Safe_ports port 80 # http acl Safe_ports port 21 # ftp acl Safe_ports port 443 # https acl Safe_ports port 70 # gopher acl Safe_ports port 210 # wais acl Safe_ports port 1025-65535 # unregistered ports acl Safe_ports port 280 # http-mgmt acl Safe_ports port 488 # gss-http acl Safe_ports port 591 # filemaker acl Safe_ports port 777 # multiling http acl CONNECT method CONNECT
# Here I define the times and what file contains the rules acl playtime1 time SMTWHFA 8:30-9:30 acl playtime22 time SMTWHFA 16:00-17:00 acl addiction url_regex -i "/etc/squid/addiction"
# Only allow cachemgr access from localhost http_access allow manager localhost http_access deny manager
# Deny requests to certain unsafe ports http_access deny !Safe_ports
# Deny CONNECT to other than secure SSL ports http_access deny CONNECT !SSL_ports
# We strongly recommend the following be uncommented to protect innocent # web applications running on the proxy server who think the only # one who can access services on "localhost" is a local user #http_access deny to_localhost
# # INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS #
# The next few lines actually do the work http_access allow playtime1 addiction http_access allow playtime2 addiction http_access deny addiction # If this ACL is triggered, show the user the WORKONLY error message. deny_info WORKONLY addiction
# Example rule allowing access from your local networks. # Adapt localnet in the ACL section to list your (internal) IP networks # from where browsing should be allowed http_access allow localnet http_access allow localhost
# And finally deny all other access to this proxy http_access deny all
# Squid normally listens to port 3128 # I added the word "transparent", so squid behaves a little different: # it makes itself transparent. NOTE TO SELF: This is the line you're looking for. Used to be httpd_accel_uses_host_header in squid 2
http_port 3128 transparent
# We recommend you to use at least the following line. hierarchy_stoplist cgi-bin ?
# Uncomment and adjust the following to add a disk cache directory. #cache_dir ufs /var/spool/squid 100 16 256
# Leave coredumps in the first cache dir coredump_dir /var/spool/squid
# Add any of your own refresh_pattern entries above these. refresh_pattern ^ftp: 1440 20% 10080 refresh_pattern ^gopher: 1440 0% 1440 refresh_pattern -i (/cgi-bin/|\?) 0 0% 0 refresh_pattern . 0 20% 4320
# Don't show squid to the outside world forwarded_for delete
# I don't need to log what she's doing access_log none # Nor do i need icap logs icap_log none # And i don't want to know what is stored in cache cache_store_log none # To not break web apps, I don't want caching either cache deny all
Step 3: Define blocked sites
Type a list of blocked websites in /etc/squid/addiction. You can use complete urls, domains or even just words. Ie. "facebook" blocks http://www.facebook.com, but also http://wikipedia.org/wiki/facebook
Step 4: Leave a message
In the configuration, I put: deny_info WORKONLY addiction. This means that I can leave the user a message in /usr/share/squid/errors/templates/WORKONLY and /usr/share/squid/errors/en/WORKONLY. Since it's my wife's PC, I decided to leave her a sweet message :-D
Step 5: Route network traffic
I could configure her Firefox to use the proxy. But then she'd use Google Chrome or Konqueror to surf the web. And she could turn the proxy off. So I need to catch all http-traffic that did not pass squid. I used iptables:
#Allow user 'root' to surf the web, for yum update etc.
iptables -t nat -A OUTPUT -m tcp -p tcp --dport80-m owner --uid-owner root -j RETURN
# Allow user 'squid' to pass on http requests
iptables -t nat -A OUTPUT -m tcp -p tcp --dport80-m owner --uid-owner squid -j RETURN
# Redirect all other traffic to the proxy.
iptables -t nat -A OUTPUT -m tcp -p tcp --dport80-j REDIRECT --to-ports3128
#Allow user 'root' to surf the web, for yum update etc.
iptables -t nat -A OUTPUT -m tcp -p tcp --dport 80 -m owner --uid-owner root -j RETURN
# Allow user 'squid' to pass on http requests
iptables -t nat -A OUTPUT -m tcp -p tcp --dport 80 -m owner --uid-owner squid -j RETURN
# Redirect all other traffic to the proxy.
iptables -t nat -A OUTPUT -m tcp -p tcp --dport 80 -j REDIRECT --to-ports 3128