<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>21st century digital boy</title>
	<atom:link href="http://www.daniel-ritter.de/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://www.daniel-ritter.de/blog</link>
	<description>I dont know how to live but I've got a lot of toys...</description>
	<lastBuildDate>Tue, 01 Dec 2009 16:40:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cookie Monsters Computer Nightmare</title>
		<link>http://www.daniel-ritter.de/blog/artikel/189</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/189#comments</comments>
		<pubDate>Sun, 29 Nov 2009 15:10:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=189</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="attachment wp-att-190 centered" src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/cook.jpg" alt="cook" width="353" height="500" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/189/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When computers were young and angry</title>
		<link>http://www.daniel-ritter.de/blog/artikel/183</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/183#comments</comments>
		<pubDate>Sat, 28 Nov 2009 16:07:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=183</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="attachment wp-att-187 centered" src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/10-burroughs-angy-young-computer3.jpg" alt="10-burroughs-angy-young-computer3" width="347" height="500" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/183/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Ubuntu 9.10 Karmic Koala annoyances and how i fixed them</title>
		<link>http://www.daniel-ritter.de/blog/artikel/163</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/163#comments</comments>
		<pubDate>Wed, 25 Nov 2009 17:31:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[9.10]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[cpu]]></category>
		<category><![CDATA[freq]]></category>
		<category><![CDATA[karmic]]></category>
		<category><![CDATA[koala]]></category>
		<category><![CDATA[temperature]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=163</guid>
		<description><![CDATA[
Lets face the truth. Desktop Linux has made an incredible progress in the last few years. It still gives you all the freedom, happiness and elegance it inherited from it&#8217;s UNIX-foundation &#8211; and it tries hard to compete with the Windows Plug-And-Play mentality.
The standard user shouldn&#8217;t need to do complicated things on the console. Basic [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a title="Patching the Koala" rel="lightbox[pics163]" href="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/patching_the_koala.jpg"><img class="attachment wp-att-164  alignnone" src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/patching_the_koala.jpg" alt="Patching the Koala" width="201" height="252" /></a></p>
<p style="text-align: left;">Lets face the truth. Desktop Linux has made an incredible progress in the last few years. It still gives you all the freedom, happiness and elegance it inherited from it&#8217;s UNIX-foundation &#8211; and it tries hard to compete with the Windows Plug-And-Play mentality.</p>
<p style="text-align: left;">The standard user shouldn&#8217;t need to do complicated things on the console. Basic things should just work. Especially Ubuntu did great, they really improved many GUI aspects of the GNOME-desktop. Most modern machines run and work just &#8220;out of the box&#8221; with a fresh Ubuntu install. BUT there are still these little annoyances and things that don&#8217;t work as expected. I will collect my personal annoyances with Ubuntu 9.10 &#8220;Karmic Koala&#8221; in this post and add solutions, if I find them.</p>
<p style="text-align: left;">
<p style="text-align: left;"><strong>Annoyance #1<br />
Logs are spammed with messages about CPU temperature</strong></p>
<p style="text-align: left;">This one is an ugly one. It started for me with Karmic. <em>/var/log/kern.log</em> and <em>/var/log/syslog</em> got spammed with millions of messages from the kernel stating things like:</p>
<p><span style="color: #808000;"><em><code>CPU0: Temperature above threshold, cpu clock throttled (total events = 208[ 8973.550089] CPU0: Temperature/speed normal</code></em></span></p>
<p><span style="color: #808000;"><em><code>CPU0: Temperat cpu clock throttled (total events = 2080190)</code></em></span><br />
This was a real problem, because about 100 messages per second were written to the logs, making them hard to read for other purposes. Syslog archiving them pushed my CPU to 100% and they filled up my root partition very quickly. This behaviour seems to originate from a kernel bug that should be fixed anytime soon. There is an Ubuntu Bug-Report on the problem already:<a href="https://bugs.launchpad.net/ubuntu/+source/rsyslog/+bug/453444"> https://bugs.launchpad.net/ubuntu/+source/rsyslog/+bug/453444</a>. There is no real fix for it, as this is a kernel bug, but there is a workaround that fixed the odd behaviour of my system. I just disabled the logging of lines, that contain the bogus information:</p>
<ul>
<li>Create a file /etc/rsyslog.d/10-temperature.conf</li>
<li>Paste the following code into it:<span style="color: #99cc00;">:msg,contains,&#8221;Temperature/speed normal&#8221; ~<br />
:msg,contains,&#8221;Temperature above threshold&#8221; ~</span></li>
</ul>
<ul>
<li><span style="color: #99cc00;"><span style="color: #000000;">Save it</span></span></li>
<li><span style="color: #99cc00;"><span style="color: #000000;">Do an <span style="color: #99cc00;">sudo restart rsyslog <span style="color: #000000;">to make the new rule active.</span></span></span></span></li>
</ul>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;"><span style="color: #99cc00;"><strong><span style="color: #000000;">Annoyance #2<br />
CPU Frequency Scaling Monitor didn&#8217;t remember my password</span></strong></span></p>
<p style="text-align: left;">There is a very useful little applet for the Gnome panel, that allows you to change the speed of your CPU while working. As I am using a notebook most of the time, this thingy came in quiet handy for me. Because changing of the CPU policy requires root-privileges, you had to enter your password once with old Ubuntu versions. After that you were able to check a checkbox and Ubuntu remembered your policy. Things changed in Karmic. With the new policykit2 environment, there was no possibility anymore to remember the password. I had to reenter it every time i wanted to change my CPU policy. I found out, that I could set the permisson right in the config files for policykit2:</p>
<ul>
<li>Create a file  /var/lib/polkit-1/localauthority/50-local.d/gnome-cpufreq.pkla</li>
<li>Paste the following code into it (be sure to replace YOURUSERNAME with your username):<span style="color: #99cc00;">[Allow users to set the CPU frequency]<br />
Identity=unix-group:YOURUSERNAME<br />
Action=org.gnome.cpufreqselector<br />
ResultAny=no<br />
ResultInactive=no<br />
ResultActive=yes</span></li>
</ul>
<ul>
<li><span style="color: #99cc00;"><span style="color: #000000;">Save it</span></span></li>
<li><span style="color: #99cc00;"><span style="color: #000000;">There is no password needed anymore for changing CPU policies</span></span></li>
</ul>
<p><strong> </strong></p>
<p><strong>Annoyance #3<br />
Streamtuner couldn&#8217;t load the Shoutcast streamlist anymore</strong></p>
<p>This started with Intrepid or so. Shoutcast changed the hostname of it&#8217;s streamlist-servers. The old hostname seems to be hardcoded into Streamtuner, so it couldn&#8217;t get the streamlist anymore. This was  unconvenient  for me, because i got used to tune into my favourite internet radio stations (like <a href="http://www.myspace.com/lemixx">Lemixx Paris France</a>) with Streamtuner. There seems to be no effort to fix this in the Ubuntu package, as the bug is now several months old already. I fixed it by adding the right IP to <em>/etc/hosts</em>.</p>
<ul>
<li>Open up /etc/hosts with a text editor</li>
<li>Add the following line to it:<span style="color: #99cc00;">205.188.234.120 www.shoutcast.com</span></li>
</ul>
<ul>
<li><span style="color: #99cc00;"><span style="color: #000000;">Save it</span></span></li>
<li><span style="color: #99cc00;"><span style="color: #000000;">Streamtuner can access Shoutcast streams again<span style="color: #99cc00;"><span style="color: #000000;"> </span></span></span></span></li>
</ul>
<p><strong>Annoyance #4<br />
USB Startup Disk Creator is unable to create an USB Startup Disk</strong></p>
<p>Ubuntu brings it&#8217;s own tool to clone itself onto an USB flashdrive. You basicly get a fully working Ubuntu Installation on your flashdrive. A very useful thingy to carry around if you want to connect to the internet from untrusted machines or if you want to fix a brokeen down computer. So far so good, it didn&#8217;t work. When you start the USB Startup Disk Creator from Ubuntus menu, the tool starts but is unable to format or write to partitions on your flashdrive. The solution is surprisingly simple: It needs to be run as root to make it work:</p>
<ul>
<li>Open up a terminal</li>
<li>Enter the following command:<br />
<span style="color: #99cc00;">sudo usb-creator-gtk</span></li>
<li><span style="color: #99cc00;"><span style="color: #000000;">Create and enjoy your flashdrive</span><br />
</span></li>
</ul>
<p><strong>Annoyance #5<br />
Couldn&#8217;t click on any web link in Pokerstars with wine</strong></p>
<p>Poker is one of my hobbies and the guys from Pokerstars did a great job on making it a good experience on Linux with wine too. There are a few downgrades though. When clicking on links in the Pokerstars software, no webbrowser opened up in Gnome. You need to edit the registry to fix that.</p>
<ul>
<li>Run <span style="color: #99cc00;">wine regedit</span> <span style="color: #000000;">to open the registry editor</span></li>
<li><span style="color: #000000;">Navigate to <em> </em></span><em>HKEY_CLASSES_ROOT\http\shell\open\command</em></li>
<li>Add a &#8220;%1&#8243; after -nohome in that registry key</li>
<li>Links work now in Pokerstars</li>
</ul>
<p><strong>Annoyance #6<br />
Couldn&#8217;t make Pokerstars tables fullscreen with wine</strong></p>
<p>Another Pokerstars problem. Scaling tables didn&#8217;t work well. There was no way to make a table fullscreen. There is a way to fix that, implemented espcially for wine users by Pokerstars.</p>
<ul>
<li>Open up the file user.ini in your Pokerstars directory ($HOME/.wine/Program&#8230;.)</li>
<li>Add a line with  <span style="color: #99cc00;">f5redrawtable=1 <span style="color: #000000;">to the file</span></span></li>
<li><span style="color: #99cc00;"><span style="color: #000000;">Save it</span></span></li>
<li><span style="color: #99cc00;"><span style="color: #000000;">Tables are redrawn now after resizing them when you press F5<br />
</span></span></li>
</ul>
<p>To be continued&#8230;</p>
<p style="text-align: left;">
<p style="text-align: left;">
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/163/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>6 Useful Things You Can Do With SSH</title>
		<link>http://www.daniel-ritter.de/blog/artikel/148</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/148#comments</comments>
		<pubDate>Thu, 19 Nov 2009 02:11:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[prox]]></category>
		<category><![CDATA[secure shell]]></category>
		<category><![CDATA[socks]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[tunnel]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=148</guid>
		<description><![CDATA[SSH must be my favourite piece of software ever. It&#8217;s free, it gives you freedom, it&#8217;s simple to use yet powerful in the things it can do. It helps you to encrypt and secure your communication. It can do this in an universal way and for nearly every usage case. In this post, I want [...]]]></description>
			<content:encoded><![CDATA[<p>SSH must be my favourite piece of software ever. It&#8217;s free, it gives you freedom, it&#8217;s simple to use yet powerful in the things it can do. It helps you to encrypt and secure your communication. It can do this in an universal way and for nearly every usage case. In this post, I want to show you 6 things you can do with SSH without too much hassle. SSH can do more than just serve as an encrypted remote session. Try the following examples for yourself and explore the power of the Secure Shell.</p>
<p><strong>Thingy #1 &#8211; A secure remote shell</strong></p>
<p><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/ssh_console1.jpg" alt="ssh_console1" /></p>
<p>OK, this is the most obvious thing you can do with SSH and i bet most of you have already done it: Connect to a remote machine via a SSH-secured connection and type on it&#8217;s console to administer it.</p>
<p>This is very simple:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh user@box_B</span></p>
<p><span style="color: #000000;">This will connect you to Box B as user &#8220;user&#8221;. After having entered your password, you will be able to use BOX B&#8217;s console.</span></p>
<p>Sometimes you don&#8217;t want to connect to the remote machine for an interactive session, because you just want to run a single command on the remote machine. In that case you can just do a</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh user@box_B command</span></p>
<p><span style="color: #000000;">This will connect to Box B as &#8220;user&#8221;, run &#8220;command&#8221;, show you &#8220;command&#8221;&#8217;s output and disconnect.</span></p>
<p><strong>Thingy #2 &#8211; Copy files between your boxes</strong></p>
<p><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/ssh_copy.jpg" alt="ssh_copy" /></p>
<p>Great, we can administer a remote machine with SSH but we can also move data between machines in an encrypted and secure way. It basicly works like the standard &#8220;cp&#8221; command, but it has got a different name: &#8220;scp&#8221;</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">scp /home/me/a_file.txt user@box_B:/home/me/</span></p>
<p><span style="color: #000000;">This will copy the local file &#8220;/home/me/a_file.txt&#8221; on our Box A to &#8220;/home/me/a_file.txt&#8221; on Box B.</span></p>
<p>It will work vice versa as well:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">scp user@box_B:/home/me/b_file.txt /home/me</span></p>
<p>This would get the file &#8220;/home/me/b_file.txt&#8221; and would put in into our home dir on box A.</p>
<p>Because &#8220;scp&#8221; works like &#8220;cp&#8221; wildcards are allowed as well:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">scp /var/log/* user@box_B:/home/me/logsbackup</span></p>
<p><span style="color: #000000;">This would copy all of the log files from our Box A to &#8220;/home/me/logsbackup&#8221; on Box B.</span></p>
<p><strong>Thingy #3 &#8211; Mount a remote directory into your local file system</strong></p>
<p><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/ssh_mount.jpg" alt="ssh_mount" /></p>
<p>Sometimes it&#8217;s not enough to simply copy one or more files from one machine to another. Mounting a remote directrory into your local filesystem becomes super useful, when you want to work on the remote files with local programs. A good example for this would be working on a remote website. You can simply mount the web-directory from the remote server into your local filesystem and use all your fancy HTML-editors and image-programs on the remote files as if they were on your local harddrive. That&#8217;s where &#8220;sshfs&#8221; comes in handy. The tool isn&#8217;t installed by default in most distributions but you should be able to find it in your repository. On Debian based systems just install it with:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">apt-get install sshfs</span></p>
<p><span style="color: #000000;">After having installed sshfs you can start using it:</span></p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">mkdir /mnt/b_data</span></p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">sshfs user@box_B:/b_data /mnt/b_data</span></p>
<p><span style="color: #000000;">This mounts the directory &#8220;/b_data&#8221; from box B into &#8220;/mnt/b_data&#8221; on your local file system. Now you can work on your remote files with local tools. When you are done, you can unmount the directory with:</span></p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">fusermount -u /mnt/b_data</span></p>
<p><span style="color: #000000;">If the unmount fails, check if you have still open files in the directory or if you are still in that directory in some shell or Nautilus/Konqueror window.</span></p>
<p><strong>Thingy #4 &#8211; Surf the Web uncensored and anonymously from &#8220;critical&#8221; locations</strong></p>
<p><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/ssh_proxy.jpg" alt="ssh_proxy" /></p>
<p>Corporate policies, fascist governments, internet cafés and other &#8220;unfriendly&#8221; rules, institutions and places can give you a hard time, when you want to access the web in a secure and private way. Firewalls and proxies may block your favourite sites, log the sites you have visited, perform man in the middle attacks or can just give you a bad feeling. SSH is the solution for these problems. It offers you the possibility to use it as a web-proxy. You simply connect to your good old trusted box B and surf through the encrypted connection.</p>
<p>(Local Browser &lt;-&gt; Local SSH Proxy &lt;-&gt; SSH &lt;-&gt; Box B &lt;-&gt; Website)</p>
<p>Now nobody on your unfriendly local LAN can block or spy on your surfing session.<br />
Sounds good? Great! It&#8217;s even simple to setup. SSH offers the &#8220;-D&#8221; option to provide a SOCKS proxy on the local machine:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;"><code>ssh -D 1234 user@box_B</code></span></p>
<p>You&#8217;ll have a proxy listening on localhost port 1234. Now you just have to setup your webbrowser to use the &#8220;SOCKS proxy&#8221; on localhost port 1234 and all your surfing will go through Box B. You can check if it worked by visiting a website that shows your IP. <a href="http://www.whatismyip.com">http://www.whatismyip.com</a> is a site that would work. If that site shows Box B&#8217;s IP-address instead of your local one, you setup everything correctly. A portable webbrowser on your USB-pendrive like  <a href="http://portableapps.com/apps/internet/firefox_portable">Portable Firefox</a> would make things even more cozy.</p>
<p><strong>Thingy #5 &#8211; Encrypt the data traffic of your favourite local application or access services in LAN&#8217;s you couldn&#8217;t reach otherwise with SSH-tunnels<br />
</strong></p>
<p><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/ssh_tunnel_l.jpg" alt="ssh_tunnel_l" /></p>
<p>OK, we encrypted remote admin-sessions, copied files securely and even surfed the web in a private way. But SSH can do more. You can encrypt the traffic of every application that uses the TCP-protocol with SSH tunnels. Like with our SOCKS-proxy, we can tunnel other data through ssh, for example the traffic of our e-mail client. Lets say you want to pickup your e-mail while being in a &#8220;critical&#8221; environment. Bad corporations / governments / script kiddies could read your email and even worse could sniff your e-mail password. SSH helps. The syntax for tunnels in SSH might puzzle your brain at first sight, but it&#8217;s not too hard:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -L local_port:target_host:target_port user@box_B</span></p>
<p style="padding-left: 30px;"><span style="color: #000000;">for example</span></p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -L 10000:pop3.mailprovider.com:110 user@box_B</span></p>
<p>OK, lets see what happened here. We told ssh to create a tunnel with a local (-L) endpoint at port &#8220;10000&#8243;. Everything that is put into our local endpoint goes first encrypted to our Box B and after that to &#8220;pop3.mailprovider.com&#8221; on port 110 (which is POP3). You relay all data that goes into our local endpoint in an encrypted way via Box B to your E-Mail provider. In this example you would set the POP-account in your e-mail client to &#8220;localhost&#8221; port &#8220;10000&#8243;. It doesn&#8217;t have to be e-mail. Any other application that uses a protocol utilizing TCP works as well. For example IRC, FTP, HTTP, IMAP, you name it&#8230;</p>
<p>in case you are running your own server-service on Box B, &#8220;target host&#8221; can be Box B itself of course:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -L 10000:127.0.0.1:110 user@box_B</span></p>
<p><span style="color: #000000;">Target host in this example is &#8220;127.0.0.1&#8243; because it&#8217;s the target from Box B&#8217;s point of view. &#8220;127.0.0.1&#8243; seen from Box B sure is Box B itself.</span></p>
<p>Tunneling can be useful to secure your services or to connect to services inside BOX B&#8217;s network. Lets say BOX B is in an intranet that has an interesting webserver on IP &#8220;192.168.0.77&#8243; and you are unable to access that server from the outside. You just tunnel your way to BOX B and let BOX B forward you to the webserver:</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -L 10000:192.168.0.77:80 user@box_B</span></p>
<p>Now typing &#8220;http://127.0.0.1:10000&#8243; into your local webbrowser will show you the homepage of the intranets webserver.</p>
<p><strong>Thingy #6 &#8211; A tunnel the other way around</strong></p>
<p><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/7.jpg" alt="ssh_tunnel_r_good" /></p>
<p>OK, this could have been part of &#8220;Thingy #5&#8243; but to make things more clear i made an extra point for it. If you understood #5 this should be no problem for you. Here, you open up a &#8220;remote&#8221; endpoint on Box B. Everything that goes in there is relayed encrypted to Box A (the one you are using at the moment) and after that to the target host.</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -R remote_port:target_host:target_port user@box_B</span></p>
<p style="padding-left: 30px;"><span style="color: #000000;">for example</span></p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -R 10000:pop3.mailprovider.com:110 user@box_B</span></p>
<p>An e-mail client would set &#8220;box_B&#8221; and port &#8220;10000&#8243; as the POP3 server. BOX B would relay the traffic to BOX A through SSH. BOX A would relay the traffic to &#8220;pop3.mailprovider.com&#8221; port &#8220;110&#8243;.</p>
<p><strong>Useful commandline options for SSH</strong></p>
<p>-c &#8220;Compress&#8221;</p>
<p>The &#8220;-c&#8221; option in SSH compresses all traffic with gzip before sending it to the remote host. This increases the speed greatly with uncompressed data-types. It&#8217;s very useful for copying large text-files over SSH or for surfing the web with the &#8220;-D&#8221; option. In general &#8220;-c&#8221; never hurts, it just puts a little more pressure onto your CPU.</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh </span><span style="color: #99cc00;"> -c </span><span style="color: #99cc00;">-D 1234 user@box_B</span></p>
<p>-g &#8220;Grant Access&#8221;</p>
<p>The &#8220;-g&#8221; option allows other hosts to connect to your local tunnel endpoints. If you don&#8217;t use &#8220;-g&#8221; in combination with a tunnel, only your own localhost (Box A in the examples) may use the tunnel.</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -L -g 10000:127.0.0.1:110 user@box_B</span></p>
<p>-p &#8220;Port&#8221;</p>
<p>The &#8220;-p&#8221; option is needed, if the SSH-server you want to connect to doesn&#8217;t run on the default port &#8220;22&#8243;</p>
<p style="padding-left: 30px;"><span style="color: #99cc00;">ssh -p 22000 user@box_b</span></p>
<p>-v &#8220;Verbose&#8221;</p>
<p>Add this option if you want to dive deeper into SSH. You will see many technical information while connecting to a remote host.</p>
<p><strong>Further reading</strong></p>
<p>I tried to keep this article as simple as possible to make it usable. There is a lot more to know about SSH. If you are looking for a more comprehensive read i suggest you check out these docs:</p>
<p><a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssh">The SSH man page</a></p>
<p><a href="http://www.ietf.org/rfc/rfc4251.txt">The SSH RFC</a></p>
<p><a href="http://en.wikipedia.org/wiki/Secure_Shell">Wikipedia on SSH</a></p>
<p><a href="http://www.amazon.com/SSH-Secure-Shell-Definitive-Guide/dp/0596008953/ref=sr_1_5?ie=UTF8&amp;s=books&amp;qid=1258596515&amp;sr=8-5">SSH &#8211; The Definitive Guide by O&#8217;Reilly</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/148/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Warum Netzneutralität wichtig ist</title>
		<link>http://www.daniel-ritter.de/blog/artikel/145</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/145#comments</comments>
		<pubDate>Fri, 30 Oct 2009 18:36:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=145</guid>
		<description><![CDATA[

]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<p style="text-align: center;"><a title="netneutral" rel="lightbox[pics145]" href="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/netneutral.jpg"><img class="attachment wp-att-161 centered" src="http://www.daniel-ritter.de/blog/wp-content/uploads/2009/11/netneutral.jpg" alt="netneutral" width="460" height="1024" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/145/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tunneling IAX2 VoIP thru a SSH tunnel</title>
		<link>http://www.daniel-ritter.de/blog/artikel/143</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/143#comments</comments>
		<pubDate>Fri, 12 Dec 2008 16:28:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[asterisk]]></category>
		<category><![CDATA[iax2]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=143</guid>
		<description><![CDATA[
Just for the kicks, i tried to connect 2 Asterisk servers thru a SSH tunnel to place encrypted calls via IAX2 from BOX1 to BOX2. It worked, but the sound quality is ugly and the FIFO-nature of converting UDP-traffic into TCP-traffic gave some strange results. But after all I learned a lot doing it&#8230;.
What we [...]]]></description>
			<content:encoded><![CDATA[<p><a title="IAX2 SSH Tunnel" rel="lightbox[pics143]" href="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/12/iax-tunnel.jpg"><img class="attachment wp-att-144 alignleft" src="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/12/iax-tunnel.jpg" alt="IAX2 SSH Tunnel" width="481" height="231" /></a></p>
<p>Just for the kicks, i tried to connect 2 Asterisk servers thru a SSH tunnel to place encrypted calls via IAX2 from BOX1 to BOX2. It worked, but the sound quality is ugly and the FIFO-nature of converting UDP-traffic into TCP-traffic gave some strange results. But after all I learned a lot doing it&#8230;.</p>
<p><strong>What we need:</strong></p>
<p>- 2 Asterisk Boxes</p>
<p>- root on BOX2</p>
<p>- ssh</p>
<p>- socat</p>
<p><strong>What I did:</strong></p>
<p>Connect both boxes with a SSH port-forwarding to get the calls thru the internet. Convert the IAX2 UDP-traffic coming from Box1s Asterisk into TCP with socat, because SSH doesn&#8217;t support UDP tunneling. Send the TCP data thru the tunnel. Pick it up at the other side with socat and convert it back to UDP. Feed the UDP data into the target asterisk.</p>
<p><strong>How I did it:</strong></p>
<p>BOX1:</p>
<p><span class="postbody">context to feed an outbound call into our socat converter:<br />
</span></p>
<p><em><span class="postbody">exten =&gt; 3,1,Dial(IAX2/user:pass@127.0.0.1:10000/1) </span></em></p>
<p>setting up socat:</p>
<p><em>socat udp4-listen:10000,reuseaddr,fork tcp:127.0.0.1:10001</em></p>
<p>setting up our ssh tunnel:</p>
<p><em>ssh -L 10001:127.0.0.1:10000 root@box2</em></p>
<hr />
<p>Box2:</p>
<p>Setting up socat to pick up the TCP-stream from the tunnel and pass it to asterisk:</p>
<p><em>socat tcp4-listen:10000,reuseaddr,fork UDP:127.0.0.1:4569</em></p>
<p><span class="postbody">iax.conf:</span></p>
<p><em>[general]<br />
bindport = 4569<br />
bindaddr = 0.0.0.0<br />
disallow=all<br />
allow=ulaw<br />
allow=alaw</em></p>
<p><em>[box1]<br />
type=peer<br />
username=user<br />
secret=pass<br />
auth=plaintext<br />
context=iax-tunnel<br />
peercontext=iax-tunnel<br />
qualify=yes<br />
trunk=yes </em></p>
<p>The  iax-tunnel context just playing a beep:<br />
<em>; IAX testing<br />
[iax-tunnel]<br />
exten =&gt; 1,1,Answer()<br />
exten =&gt; 1,2,Playback(beep)<br />
exten =&gt; 1,3,Hangup() </em></p>
<p>Enjoy&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/143/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Der magische Wasserhahn oder: Warum das Geld nach oben fließt</title>
		<link>http://www.daniel-ritter.de/blog/artikel/141</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/141#comments</comments>
		<pubDate>Mon, 24 Nov 2008 15:48:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Die Welt heute]]></category>
		<category><![CDATA[finanzen]]></category>
		<category><![CDATA[geld]]></category>
		<category><![CDATA[geldschöpfung]]></category>
		<category><![CDATA[weltbank]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=141</guid>
		<description><![CDATA[Es gab einmal einen magischen Wasserhahn in einer Welt ohne Meere, Flüsse, Seen und Regen. Der Hahn war an keine Wasserleitung angeschlossen und trotzdem sprudelte er ständig fidel und glücklich. Das frische Wasser floß wie aus dem Nichts heraus und versorgte die Durstigen. Doch er war auch gierig. Er verschenkte sein Wasser nicht an die [...]]]></description>
			<content:encoded><![CDATA[<p>Es gab einmal einen magischen Wasserhahn in einer Welt ohne Meere, Flüsse, Seen und Regen. Der Hahn war an keine Wasserleitung angeschlossen und trotzdem sprudelte er ständig fidel und glücklich. Das frische Wasser floß wie aus dem Nichts heraus und versorgte die Durstigen. Doch er war auch gierig. Er verschenkte sein Wasser nicht an die Durstigen sondern verlieh es nur. Die Durstigen mußten ihm das Wasser später zurückgeben. Außerdem verlangte er bei der Rückgabe immer etwas mehr Wasser als Leihgebühr. Da der magische Wasserhahn der einzige Wasserhahn der Welt war, war leider niemals genug Wasser da. Auch das zusätzliche Wasser, das ja als Gebühr zusätzlich zurückgegeben werden mußte, konnte man nur aus dem Wasserhahn beschaffen. So kam es, dass immer mehr Leute Wasserschulden hatten, sich immer mehr Leute gegenseitig Wasser stahlen und immer mehr Leute verdursteten.</p>
<p><a title="Der magische Wasserhahn" rel="lightbox[pics141]" href="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/11/hahn.jpg"><img class="attachment wp-att-142 alignleft" src="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/11/hahn.jpg" alt="Der magische Wasserhahn" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/141/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Der Fischer und der MBA</title>
		<link>http://www.daniel-ritter.de/blog/artikel/140</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/140#comments</comments>
		<pubDate>Thu, 23 Oct 2008 17:40:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Die Welt heute]]></category>
		<category><![CDATA[finanzen]]></category>
		<category><![CDATA[geschichte]]></category>
		<category><![CDATA[politik]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=140</guid>
		<description><![CDATA[Gefunden bei den Diskussionen über den DOW-JONES bei Google Finance, der heute ein neues historisches Tief erreicht hat.
An American businessman was at the pier of a small coastal Mexican
village when a small boat with just one fisherman docked. Inside the
small boat were several large yellowfin tuna.
The American complimented the Mexican on the quality of his [...]]]></description>
			<content:encoded><![CDATA[<p>Gefunden bei den Diskussionen über den DOW-JONES bei Google Finance, der heute ein neues historisches Tief erreicht hat.</p>
<blockquote><p>An American businessman was at the pier of a small coastal Mexican<br />
village when a small boat with just one fisherman docked. Inside the<br />
small boat were several large yellowfin tuna.</p>
<p>The American complimented the Mexican on the quality of his fish and<br />
asked how long it took to catch them. The Mexican replied, &#8220;only a<br />
little while.&#8221; The American then asked why didn’t he stay out longer<br />
and catch more fish? The Mexican said he had enough to support his<br />
family’s immediate needs.</p>
<p>The American then asked, &#8220;But what do you do with the rest of your<br />
time?&#8221; The Mexican fisherman said, &#8220;I sleep late, fish a little, play<br />
with my children, take siesta with my wife, Maria, stroll into the<br />
village each evening where I sip wine and play guitar with my amigos.<br />
I have a full and busy life, senor.&#8221;</p>
<p>The American scoffed, &#8220;I am a Harvard MBA and could help you. You<br />
should spend more time fishing and with the proceeds buy a bigger<br />
boat, with the proceeds from the bigger boat you could buy several<br />
boats, eventually you would have a fleet of fishing boats. Instead of<br />
selling your catch to a middleman you would sell directly to the<br />
processor, eventually opening your own cannery. You would control the<br />
product, processing and distribution. You would need to leave this<br />
small coastal fishing village and move to Mexico City, then LA and<br />
eventually NYC where you will run your expanding enterprise.&#8221;</p>
<p>The Mexican fisherman asked, &#8220;But senor, how long will this all take?&#8221;</p>
<p>To which the American replied, &#8220;15 or 20 years.&#8221;</p>
<p>&#8220;But what then, senor?&#8221;</p>
<p>The American laughed and said, &#8220;that’s the best part. When the time is<br />
right you would announce an IPO and sell your company stock to the<br />
public and become very rich, you would make millions.&#8221;</p>
<p>&#8220;Millions, senor? Then what?&#8221;</p>
<p>The American said, &#8220;Then you would retire. Move to a small coastal<br />
village where you would sleep late, fish a little, play with your<br />
kids, take siesta with your wife, stroll to the village in the<br />
evenings where you could sip wine and play your guitar with your<br />
amigos.&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/140/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1 : 649740 Very Very Nice Hand</title>
		<link>http://www.daniel-ritter.de/blog/artikel/138</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/138#comments</comments>
		<pubDate>Mon, 08 Sep 2008 19:58:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=138</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/09/rf.jpg" rel="lightbox[pics138]" title="VNH"><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/09/rf.jpg" alt="VNH" width="150" height="107" class="attachment wp-att-139 alignleft" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/138/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GAME OVER</title>
		<link>http://www.daniel-ritter.de/blog/artikel/136</link>
		<comments>http://www.daniel-ritter.de/blog/artikel/136#comments</comments>
		<pubDate>Mon, 01 Sep 2008 13:48:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[Daniel]]></category>

		<guid isPermaLink="false">http://www.daniel-ritter.de/blog/?p=136</guid>
		<description><![CDATA[
GAME OVER &#8211; Insert Coin(s) &#8211; Other Game(s)
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/09/ma.jpg" rel="lightbox[pics136]" title="ma"><img src="http://www.daniel-ritter.de/blog/wp-content/uploads/2008/09/ma.jpg" alt="ma" width="800"  class="attachment wp-att-137 alignleft" /></a></p>
<p>GAME OVER &#8211; Insert Coin(s) &#8211; Other Game(s)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.daniel-ritter.de/blog/artikel/136/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
