Online via UMTS surf stick with Debian using wvdial and O2 Mobile Flat
Since my new DSL line is activated only in a few weeks, I have the option to Alice "Quick Start" is selected. Was switched here you get a SIM card that you can surf for free for 3 months, as a stopgap until the DSL connection.
Of course I did not make the Internet connection from a client, but as usual on my home server, which acts for the entire home network and router.
The biggest problems I had with the Alice hotline. The SIM card was a quick guide on how to activate it via the Alice portal. Unfortunately, neither the site in Firefox, Chrome or Opera is working properly. I'm not advanced to the activation of the SIM card.
So, unfortunately, calls to the hotline 01 805. Very annoying for 42ct./Min.
The hotline, the Akivierung the map was done quickly, fortunately, there I was, unfortunately, could not immediately call the APN needed for the configuration of wvdial. I wanted to make sure I had some fear of exorbitant bills at the wrong configuration of the value. Here I could help the technology to happiness. For the Alice / O2 QuickStart Mobile Internet APN is the flat, according to the Hotline "internet.partner1". When assigning the name was probably no one involved in the marketing ![]()
As a next step, I have inserted the SIM card into a mobile phone to wait for the activation and those aware of it. It went pretty quickly, after about 30 minutes, my SIM was already active and logs in to the grid. Amazingly fast, since the activation of Alice initially promoted to O2. To force the phone to new einzubuchen into the net, it can be off and on again. I have now with the phone still disables the SIM PIN code request because I had some time ago already bad problems with wvdial and a PIN.
The rest worked amazingly well.
I have the SIM in my Huawei Surf Drive (T-Mobile Surf Stick III)
Bus 001 Device 004: ID 12d1: 1003 Huawei Technologies Co., Ltd.. E220 HSDPA Modem / E270 HSDPA / HSUPA Modem
inserted. After plugging in a USB port with a current kernel Debian provides the device / dev/ttyUSB0 available.
This may appeal to you with wvdial
# / Etc / wvdial.conf [Dialer Defaults] Init1 = ATZ Init2 = ATQ0 V1 E1 S0 = 0 & C1 & D2 + FCLASS = 0 Init3 = AT + CGDCONT = 1, "IP", "internet.partner1" Phone = * 99 *** 1 # Password = blank Username = blank New PPPD = yes Modem = / dev/ttyUSB0 Baud = 460800 Modem Type = USB Modem Auto Reconnect = on
Can then be a "wvdial" the connection is established:
gbn-root-00: 19:27 ~ -> wvdial -> WvDial: Internet dialer version 1.60 -> Can not get information for serial port -> Initializing modem. -> Sending: ATZ ATZ OK -> Sending: ATQ0 V1 E1 S0 = 0 & C1 & D2 + FCLASS = 0 ATQ0 V1 E1 S0 = 0 & C1 & D2 + FCLASS = 0 OK -> Sending: AT + CGDCONT = 1, "IP", "internet.partner1" AT + CGDCONT = 1, "IP", "internet.partner1" OK -> Modem initialized. -> Sending: ATDT * 99 *** 1 # -> Waiting for carrier. ATDT * 99 *** 1 # CONNECT -> Carrier detected. Waiting for prompt. -> Do not know what to do! Starting pppd and hoping for the best. -> Starting pppd at Sun January 29 2012 00:19:58 -> Pid of pppd: 3749 -> Using interface ppp0 -> Pppd: ȧ -> Pppd: ȧ -> Pppd: ȧ -> Pppd: ȧ -> Pppd: ȧ -> Pppd: ȧ -> Local IP address 10.43.145.228 -> Pppd: ȧ -> Remote IP address 10.64.64.64 -> Pppd: ȧ -> Primary DNS address 193 189 244 225 -> Pppd: ȧ -> Secondary DNS address 193 189 244 206 -> Pppd: ȧ
After this is over the air interface to the Internet PPP0 device is available that you can now use for routing and firewall rules.
Downstream is in the center of Dusseldorf just fine, the upstream can be desired, however, VERY:
Download speed: 2082 kbit / s (260 kByte / s) Upload speed: 71 kbit / s (9 kbytes / s)
But ... Do not look a gift horse in the mouth. I would pay for this performance, however.
Supplement
Unfortunately, the compound is not stable. After less than an hour, no more data to flow over PPP0, wvdial gets them unfortunately with nothing and thinks the connection is still active, choose one that is not itself continuously. To debug this problem was too complicated, because this workaround in any case only a few weeks until the circuit has to work the DSLers. The following small script checks whether the connection is still valid. If not, run wvdial and killed again.
# / Bin / bash ping-c 1 www.google.de> / dev / null if $ [? -Ne 0]; then killall wvdial echo `date` >> / var / log / connection_lost.log wvdial & fi
I call this script automatically via a cron job and am always on:
# / Etc / crontab # REDIAL CRAPPY O2 Online ***** Root / root / scripts / redial_ppp
Pitfalls:
- SIM PIN protection is not disabled
- The mobile connection provider is unfortunately geNATtet. The private server is not directly accessible from the outside. Server services can be offered only with difficulty.
Online registration information in Dusseldorf makes bad impression
It was not clear what personal data may pass on the registration office to whom. I'm after some research on this action pushed the PIRATES, which calls for you to object to the disclosure of their data at the registration office. Many registration offices provide the data that is now all! Pays. This can only be avoided by a contradiction.
Data from the registration office will be forwarded to:
State authorities, in case of legitimate interest in the context of assistance
So for example, police, prosecutors, statistical offices, etc.
The GEZ
The brothers, we already know all too well.
Parties, groups of voters and other sources of nominations in Relating to parliamentary and local elections, § 35 para.1 MG NRW
To get the pretty glossy campaign advertising.
to claimants and parties in connection with petitions and With referendums and citizens decide, § 35 section 2 MG NRW
In order to obtain high-gloss will help you make the frequent referenda.
in the way of automated searching on the Internet; § 34 Abs.1b MG NRW
That is the point that I was not yet known. Can have an Internet portal
Anyone familiar with some characteristics of a person automatically over the Internet
Gather intelligence reporting. The query currently costs € 4 per record in Dusseldorf.
The Registration Act NRW says at this point:
§ 34 Abs.1b MG NRW (1b) If the call be made possible through the Internet, ensure that the application procedures and the provision of information carried in encrypted form. The opening of access should be publicly known. A call is not allowed if the individual has objected to this form of information exchange. The registration authority to note the latest one month before the opening of Internet access by public notice on the right to object. Moreover, § 35 paragraph 6, sentence 2 applies.
An appeal against the transfer of data is possible by filling out a form. For Düsseldorf, this is here: https://formulare.duesseldorf.de/forms/frm/7PRPfAZH5gQA8Ja8AkNGaH1rNpDcHR3 This can be delivered free of charge in public offices. Thereafter, no online access is possible to own more data. Apparently, the data requests of the respective regional cities and counties organized.
When I asked the (very friendly) back office clerk in the civil, could
I was not sorry to tell the URL of the portal query. A quick search then led me quickly to the site but the city of Düsseldorf:
https://www.duesseldorf.de/emra/emra.jsp?stadt=D% FCsseldorf & type = city
The portal was technically a very dubious to say the least impression.
First of all, there seems no captcha or similar to give. A ground query seems to be possible with appropriate scripts.
In addition, the web application approved by my test queries with the Tomcat error message because I had not enabled cookies:
I read this but then increasingly doubt the professionalism of an application that provides access to the data of all citizens of the city offers. A script should not crash if conditions do not exist on the user's machine (in this case, my lack of cookie). Script error messages from Web servers that are in production use not to deactivate is negligent because it can reveal a lot about the system environment used. Especially when one jsp (as in the screenshot above), depending on the configuration of the server also comments of the programmer and Quelltextschnippsel to get. Here was a sloppy job. At an interface to personal data should not happen.
Let me sit up and use the Tomcat version, which also appears in the error message below. (Apache Tomcat/6.0.24) This is an older version of the web server on 21/01/2010. The current version is 6.0.33. The server has four registers long versions are not updated. If you look at the vulnerabilities that were fixed in this latest version, it's getting uncomfortable. The server is obviously not in the best condition:
http://tomcat.apache.org/security-6.html Fixed in Apache Tomcat 6.0.33 released August 18, 2011 Moderate: multiple weaknesses in HTTP Digest authentication CVE-2011-1184 The implementation of HTTP DIGEST authentication was discovered to have several weaknesses: replay attacks were permitted server nonces were not checked client nonce counts were not checked qop values were not checked realm values were not checked the server secret was hard-coded to a known string The result of these weaknesses is that only what DIGEST authentication as secure as BASIC authentication. This was fixed in revision 1158180th This was identified by the Tomcat security team on 16 March 2011 and made public on 26 September 2011. Affects: 6.0.0-6.0.32 low: information disclosure CVE-2011-2204 When using the Memory User Database (based on tomcat-users.xml) and creating users via JMX, an exception during the user creation process may trigger an error message in The JMX client that includes the user's password. This error message is then written to the Tomcat logs. User passwords are visible to administrators with JMX access and / or administrators with read access to the tomcat-users.xml file. Not that these users do have permissions but are able to read log files may be able to discover a user's password. This was fixed in revision 1,140,071th This was identified by Polina Genova on 14 June 2011 and made public on 27 June 2011th Affects: 6.0.0-6.0.32 low: information disclosure CVE-2011-2526 Tomcat provides support for sendfile with the HTTP and NIO HTTP connectors in April. sendfile is used for content automatically served via the DefaultServlet and deployed applications may use it directly via web setting request attributes. These attributes were not validated request. When running under a security manager, this lack of validation allowed a malicious web application to do one or more of the following that would normally be Prevented by a security manager: return files to users that the security manager should make inaccessible terminate (via a crash ) the JVM Additionally, these vulnerabilities only occur when all of the following are true: untrusted web applications are being used the Security Manager is used to limit the untrusted web applications the HTTP NIO or HTTP April connector is used sendfile is enabled for the connector (this is the default) This was fixed in revision 1,146,703th This was identified by the Tomcat security team on 7 July 2011 and made public on 13 July 2011th Affects: 6.0.0-6.0.32 Important: information disclosure CVE-2011-2729 due to a bug in the code capabilities, jsvc (the service wrapper for linux that is part of the Commons Daemon project) does not drop capabilities Allowing the application to access files and directories owned by superuser. This vulnerability only when all of the OCCURS following are true: Tomcat is running on a Linux operating system was compiled with libcap jsvc-user parameter is used Affected Tomcat versions shipped with source files for jsvc that included this vulnerability. This was fixed in revision 1153824th This was identified by Wilfried Weissmann on 20 July 2011 and made public on 12 August 2011. Affects: 6.0.30-6.0.32 Fixed in Apache Tomcat 6.0.32 released February 3, 2011 Note: The issue below was fixed in Apache Tomcat 6.0.31 release but the vote for the 6.0.31 release candidate did not pass. Therefore, users must download 6.0.32 Although to obtain a version that includes a fix for this issue, version 6.0.31 is not included in the list of affected versions. Important: remote denial of service CVE-2011-0534 The NIO connector expands its endlessly buffer request line during processing. That behavior can be used for a denial of service attack using a carefully crafted request. This was fixed in revision 1066313th This was identified by the Tomcat security team on January 27, 2011 and made public on 5 Feb 2011. Affects: 6.0.0-6.0.30 Fixed in Apache Tomcat 6.0.30 released January 13, 2011 Low: Cross-site scripting CVE-2011-0013 The HTML Manager web application interface provided data displayed, analyzed as display names, without filtering. A malicious web application could trigger script execution by an administrative user when viewing the manager pages. This was fixed in revision 1057270th This was identified by the Tomcat security team on November 12, 2010 and made public on 5 Feb 2011. Affects: 6.0.0-6.0.29 Moderate: Cross-site scripting CVE-2010-4172 The Manager application used the user provided parameters and sort orderBy directly without filtering THEREBY permitting cross-site scripting. This was fixed in revision 1037779th This was first reported to the Tomcat security team on November 15, 2010 and made public on 22 Nov 2010. Affects: 6.0.12-6.0.29 Low: Security Manager file permission bypass CVE 2010-3718 When running under a security manager, access to the file system is limited but web applications are granted read / write permissions to the work directory. This directory is used for a variety of temporary files investigated as the intermediate files generated when compiling JSPs to servlets. The location of the work directory is specified by a ServletContect attribute that is meant to be read-only to web applications. However, due to a coding error, the read-only setting was not applied. Therefore, a malicious web application may modify the attributes before Tomcat Applies the file permissions. This can be used to grant read / write permissions to any area on the filesystem Which a malicious web application may then take advantage of. This vulnerability is only applicable when hosting web applications from untrusted sources examined as shared hosting environments. This was fixed in revision 1022560th This was discovered by the Tomcat security team on 12 May 2010 and made public on 5 Feb 2011. Affects: 6.0.0-6.0.29 Fixed in Apache Tomcat 6.0.28 released July 9, 2010 Important: Remote Denial of Service and Information Disclosure Vulnerability CVE-2010-2227 Several flaws in the handling of the 'Transfer-Encoding' header were found Prevented that the recycling of a buffer. A remote attacker could trigger this flaw Which would cause subsequent requests to fail and / or to leak information between requests. This flaw is mitigated if Tomcat is behind a reverse proxy (Apache httpd 2.2 as tested) as the proxy should reject the invalid transfer encoding header. This was fixed in revision 958,977th This was first reported to the Tomcat security team on June 14, 2010 and made public on 9 Jul 2010. Affects: 6.0.0-6.0.27 Note: The issue below was fixed in Apache Tomcat 6.0.27 release but the vote for the 6.0.27 release candidate did not pass. Therefore, users must download 6.0.28 Although to obtain a version that includes a fix for this issue, version 6.0.27 is not included in the list of affected versions. Low: information disclosure in authentication headers CVE-2010-1157 The WWW-Authenticate HTTP header for BASIC and DIGEST authentication includes a realm name. If aelement is specified in web.xml for the application it will be used. However, a is not specified then Tomcat will generate realm name using the code snippet request.getServerName () + "" + request.getServerPort (). In some circumstances this can expose the local host name or IP address of the machine running Tomcat. This was fixed in revision 936,540th This was first reported to the Tomcat security team on 31 May 2009 and made public on 21 Apr 2010. Affects: 6.0.0-6.0.26
All this is very uncertain and it is for me an example of the lived privacy will of the state. The data is sold and there is hardly anyone known. The technical implementation leaves much to be desired and runs on very technical systems that are known to be faulty and need to be updated urgently. Also seems to be a final inspection and acceptance qualified in IT projects (known to the State are usually quite expensive) do not always take place.
As the only plus point I can note that there seems to be no central nationwide portal with online reading for all the reporting data. Then we would certainly not far removed from what the Israelis happened recently .
I'm glad I've held me, but if someone is not something with criminal energy and technical knowledge could still occur (free) to me (and everyone else), I think at least questionable. At first glance, the Düsseldorf system not hardened against attack.
Company Connect - Fun with the telecom sales
A customer had a problem. Because of a specific application, a faster ping to Taiwan was needed. A conventional telecom DSLer brought constant 290 - 320ms to Hinet, a large Taiwanese provider. A stress-free use of the application package was with these terms is not possible, so they searched for alternatives to a faster connection. I was skeptical from the outset whether an improvement of the situation was even possible. With the DSLer the packages were initially routed through the telecommunications network in New York. From there we went with AT & T continues across the U.S., then across the Pacific Hinet. From California to Taiwan was the main part of packet delay - almost 200ms. In my opinion, an improvement would be possible only if Telekom would entertain themselves with a backbone of its network in Taiwan. In my search for vendors that could make the impossible, I came across the Telecom Product Company Connect , which consists of a dedicated line, which is directly related to the telecom backbone. Phone assured me that they achieved with "CoCo" readily under 50ms ping to Asia. I was pleasantly surprised, but still skeptical. A few days later, a young and dynamic telecom salesman came in and confirmed the claim by the hotline again. "I have inquired for you, that's no problem. Telekom maintains global backbone." When leaving the building, he told me that he had just ordered a new BMW. Very nice. The next day via e-mail directly to the treaty came into the house. We sent him back with the addition that we can cancel the contract if no pings could be reached at 100 ms after Taiwan. Telekom signed. After this happened once a long time nothing more. The salesman had assured a circuit within a month. After a month, we asked, the salesman, however, was from then on (until now) is not accessible. Even e-mails to his department were not answered. After 2 1/2 months we were impatient and threatened to cancel the order, if not could be arranged within one week of a date for the circuit. Then it suddenly went very quickly. The "escalation point" organized an appointment for us, the line was switched. For a first test, I stuck a router and my brand new netbook on the line.
box-ww-11: 57:35 ~ -> ping www.hinet.net PING www.hinet.net (202.39.224.7) 56 (84) bytes of data. 64 bytes from 202-39-224-7.HINET IP.hinet.net (202.39.224.7): icmp_req = 1 ttl = 237 time = 306 ms 64 bytes from 202-39-224-7.HINET IP.hinet.net (202.39.224.7): icmp_req = 2 ttl = 237 time = 306 ms
LOL. What else would you expect? Exactly the same ping values as before. Exactly the same international route as before. No technical problem. Just a lot of bullshit-Blah-Blah. I'm curious if the termination is as "smooth" function like the circuit.
USB Cheat Sheet: The look of USB connector
The picture shows from left to right: Micro USB "B" - mini-USB "B" - mini-USB "B" 5 pin - USB "A" Female - USB "A" male - USB "B" Male
How does a Schufa information?
For a new lease my new landlord demanded a Schufa information from me. A self-Schufa information you get from the Schufa ( https://www.meineschufa.de/index.php ) free of charge by mail or online for 5 EUR. I chose the mail option, which was initially associated with some obstacles. About. Two weeks after filing, I received a letter from the Schufa I was asked my old addresses to communicate, because the data could be clearly assigned to my person. Actually I found it very pleasant that the credit reference agency probably not particularly know much about me, but I needed the information I have submitted later with the required information by e-mail. A few days later I received my Schufaauskunft, which contained much less data than I would have thought. In the end it was just my (reported by me), former addresses, my two checking accounts and a page with my scores for the various areas of life money. How these experiences come about scores can not, of course.
Only 4 days: order ID card without RFID.
An "old" ID card without RFID radio chip can only be applied to Fridays at the local registration office. As of 1.11. It is only for the new (from 10 cm distance readable) passport staff. The old passport is valid for 10 years and costs 13 €, if the current one is even longer than 6 months. If the current card only has less than 6 months validity, you pay 8 euros. Even when moving is the "new old" valid. The address is stamped as usual with a sticker pasted over.
Finally, a new box!
After nearly seven years ago with my good old Asus M6N (1.6 GHz single-core and ATI graphics). I've made the release of Starcraft 2 a reason to treat me finally back a new box. Since I've barely played with the PC, actually no faster hardware was needed, but the difference, even on the desktop is pretty cool. My compilation of work to 100% on Ubuntu, not just the graphics card works with the nouveau driver, which I can but give thanks to the proprietary NVidia driver with no problems. Nice.
Starcraft 2 on Ubuntu and Wine. The (almost) perfect setup
Starcraft II runs surprisingly well under Lucid with wine. However, there are some problems that are creating the world. After that, the gameplay, at least, a relatively recent NVidia graphics card almost perfect. My attempts to get an ATI card with the whole are unfortunately failed.
The installation
To install Starcraft II is very simple. In order to install it directly from the DVD, you have to outsmart something easier it is to get over his Battle.net account the digital download version. These patches can be started with Wine, is also good high up to the current version, leaving the current game client on the plate.
The graph
In order to gamble, you need the proprietary NVidia driver. The version of the Lucid at it, is unfortunately a little dusty. With the current version gives a much better performance. Fortunately, there is a PPA, which always must furnish the latest version of the driver and installed automatically.
sudo add-apt-repository ppa: ubuntu-x-swat/x-updates sudo apt-get update sudo apt-get upgrade
Now you have the latest NVidia drivers.
To improve the graphics performance further, we created the "Windows" registry some keys.
wine regedit HKEY_CURRENT_USER/Software/Wine/Direct3D create. Then enter below "Direct3d" following string values: DirectDrawRenderer opengl Multisampling disabled OffScreenRenderingMode pbuffer UseGLSL disabled Vertex Shader Mode hardware Video Memory Size 1024 (the RAM of the graphics card)
The sound
ALSA, the sound system is compatible with Wine, unfortunately, not very good with PulseAudio. The sound works, but you can run no MP3s or other sound in Ubuntu, as you play. A fork of Wine, with direct support PulseAudio but fixes this problem so that the sound in Starcraft is compatible with all other sounds of the system. This particular wine version is again a separate PPA :
sudo add-apt-repository ppa: c-korn/ppa sudo apt-get update sudo apt-get upgrade
Now you have the Wine version of PulseAudio support and should be in the wine configuration under "Audio" to select Pulse Audio. In addition, we Applications / Windows version to "Windows 7" and add in "libraries" create a new settlement for "mmdevapi" and makes them available to the "off"
Scrolling in-game with Compiz Cube
In-game it can in certain configurations, Compiz, come with me to the desktop cube to problems with the scroll. The mouse jumps away at the edges of the desktop. To fix this, it opens the compizconfig settings manager and navigate to "rotate cube - rotate> cube -> Bindings." Here you set the values for rotation (left / right tilt) to "nothing".
Now playing Starcraft II Full Screen with working sound and nice graphics. Unfortunately, just a bit slower than under Windows, but with more modest graphics settings, you get a very good game experience.
Have fun!
















