Showing posts with label blogging. Show all posts
Showing posts with label blogging. Show all posts

Saturday, June 25, 2016

Supplemental Spell Checking in OLW with tinySpell

The biggest feature I am missing in Open Live Writer is the lack of “real-time” spell checking when running it on a Windows 7 system.

My “fix” at the time of this post - Open Live Writer – we will (eventually) get through this – was to compose my post, copy/paste it into a session of Notepad++ where a spell check plugin was configured, and then correct any spelling issues back in the original post.

It worked but felt very clumsy.

So a few weeks ago I found a more streamlined solution.

  1. Download the free version of tinySpell – a free (and portable) spell checker.
  2. Launch tinySpell.
  3. Launch Open Live Writer.
  4. Compose post and fix spelling errors on-the-fly while composing as notified by tinySpell.

Done.

tinySpell comes in both installed or portable versions and there is also a tinySpell+ version as well for $ if you need more of the advanced features it offers.

You can easily add additional words into a custom dictionary. Set the application to run at system startup if desired. Make an audible beep if a spelling error is detected, and change the font size and color of the spelling tip notification.

tinySpell has restored my blogging confidence in using Open Live Writer as it continues through the development process.

Cheers!

--Claus Valca

Monday, May 30, 2016

Saturday, February 13, 2016

Open Live Writer – we will (eventually) get through this

I could blame the significantly reduced GSD blog posting on competing time drains of late:

  • Downton Abbey on PBS
  • Friday Night Curling televised matches
  • Sysadmin work at the church-house
  • Deep-dive problem solving for some pernicious Windows issues
  • Multiple projects at work
  • Tech-fatigue
  • Providing more quality time to family and friends

All of those do compete quite strongly with my blogging time.

However after considerable reflection, I must put the greatest challenge against the shut-down of the Microsoft Live Writer application (via the Google blogger API changes) and the painful switch to Open Live Writer.

For some background: Windows Live Writer Goes Open - Hurray - WLW breaks - Booo! – GSD blog post

That particular “break” was quickly fixed over the holidays when version 0.5.1.4 was released.

Before anything else, let me say that I deeply appreciate and am humbly grateful to the developers volunteering their time to get Open Live Writer dialed in.

But when I get the urge to compose a blog post, my current enthusiasm drops.

Here is my current process.

  1. Go into the bookmarked topic hopper and pick the post’s subject/theme.
  2. Launch Open Live Writer (OLW).
  3. Compose my post.
  4. Copy all my content and past it into Notepad++ Home in which I’ve…
    1. added spell check functionality
    2. via http://aspell.net/win32/
  5. Run the spell checker and then fix the spelling issues back in OLW.
  6. Add tags to the post by…
    1. opening up my blog home page
    2. reviewing my tags in the side-bar
    3. typing them in manually in the tag bar in OLW
  7. Publish the post to Blogger

It’s not that bad, but the original WLW had built-in spell-checking and was able to download and provide me a pick-list of my blog post tags automatically.

Note, Scott Lovegrove has offered a (temporary) build version that seems to support Blogger categories.

I’ll try it soon on my “non-production” home system and post an update.

It looks to be ready for inclusion in the next release version – whenever that will be. Current release version as of the time of this blog post is 0.5.1.4.

Is this process a deal-breaker…of course not, but the steps required have kinda taken some of the free-form blogging away and made it a more deliberate exercise.  That could be a Good Thing ™ but it does take away the spontaneity from the process.

Likewise, it seems that the OLW team already has plans to integrate spell-checking in the next release version also.

Open Live Writer “Watch List”

So I will need to work on gaining confidence again in my blogging process and embrace it until these minor application issues can be addressed in an upcoming release.

Cheers.

--Claus Valca

Sunday, July 20, 2014

Rough IT notes for those who are left to clean up…

This is not a rant or a complaint.  Just some observations based on several frustrating weeks recently.

A few weeks ago the staff member responsible who maintained the sysadmin functions around the church house alongside of his primary duties left for a new ministry position elsewhere.

Things like that do occur and best wishes were shared all around.

The week after the staff member left, through a cascading coincidence of events, the church network lost all network connectivity, the church website domain was taken off line, and the in-house Exchange mail-service/server appears to have gone belly up.

We actually do (it appears) have a computer and network services committee. Who knew?! And I’ve been working with the staff and committee leadership to try to make some recommendations and help get a handle on things. It seems that’s what I do.

So in the space of a few minutes…I shot what can best be described as a stream-of-consciousness email with IT/Sysadmin recommendations to that leadership last week as they were preparing to meet with a potential IT consultant to help get a handle on things.

Note the order was just how things came out as I composed and based on site specific issues and the (non-technical) audience. It definitely wouldn’t apply this same wall to all organizations. Likewise, you will need to prioritize the items based on your particular situation.

Here is the main body of that email.

If nothing else, it might help with putting together a technology "roadmap" for the church operations to prioritize and plan out how to cover these items at some point.

In my line of work...if it isn't documented...then it doesn't exist...and cannot be effectively, efficiently, and securely supported. And in IT operations...unknowns are terrifying because the potential impact of an event cannot be measured or mitigated.

  1. Start with a network mapping survey.
    1. come up with a mapping of all your physical connectivity runs and points.
    2. start with the incoming cable, what it connects to, 
    3. the switches and what they connect to and split off, and
    4. where each of the switch ports is connected (physical room jacks/etc.).
  2. Continue with a connected device survey. Move on to document all the, 
    1. network printers, 
    2. PC's, laptops, smart-devices,
    3. WiFi access points, 
    4. the server(s),
    5. physical backup storage units, 
    6. any network appliances (perimeter firewalls, etc.),
    7. routers,
    8. switches, etc.
    9. Note: the documentation for all items would include:
      1. their make/model/serial # information,
      2. warranty information, 
      3. OS versions running, etc.
  3. Move on to audit/document the account/user levels
    1. what accounts are active on the domain and which ones are not. 
    2. which accounts have what permissions? Who are administrators and who are standard users? 
    3. any accounts need to be disabled? 
    4. are all accounts appropriate? (do the security/access levels fit the job descriptions/functions?)
  4. Get a handle on the domain environment.
    1. what is the domain structure? 
    2. does the domain organization/structure make sense? 
    3. what group policy rules are in effect? Do they make sense? 
    4. is file/folder access appropriate for the users/guests? 
    5. how is the domain environment actually administrated?
  5. Audit and understand access and administration of the switches and other network appliances.
    1. are the switches "managed" or not? If so, who does & how? If not, why not? 
    2. are unused network connections/ports disabled if not in use? 
    3. what account(s) exist for the switches/router/network perimeter appliances? 
    4. VPN access and accounts? 
    5. Wi-Fi accounts?
      1. for staff only?
      2. member guest accounts?
      3. password rotation/aging?
      4. what parts of the network could be accessed or seen by a guest on the WiFi network (devices/storage/etc.)?
  6. Backups and storage; what is being backed up & at what frequency?
    1. are backups being done automatically? to where? taken/kept off site? Validation you actually got a good backup!
    2. does the backup storage remain attached to the network at all times? If so what is the risk if a virus/Cryptolocker malware strikes? Could it attack and lock up the backup files as well?
    3. are the backup routines and recovery methods documented so anyone can perform a safe and controlled restoration in a disaster recovery?
  7. Applications
    1. are all software applications maintained in a "library" setting? 
      1. copies of media kept centralized & logged for who has what installed/when? 
      2. license/registration keys physically printed and stored digitally in a central place? 
    2. are operating systems kept patched/updated? How? 
    3. are critical applications kept patched frequently?
    4. does the current critical application licensing model fit the needs and operational requirements of the church staff and workers?
  8. Security
    1. what physical controls are in place to restrict access to critical infrastructure? locks on doors? access logs to rooms? etc. 
    2. are systems all running/current on Anti-virus/Anti-Malware protection software and data files? 
    3. are server/system log files periodically reviewed? 
    4. are periodic scans done of the entire network to look for unauthorized/rouge devices?  (IP scans/port scans/NMAP/random traffic capture and analysis/etc.)
    5. how is PII/HIPPA/financial/etc. information kept restricted, and secured from hackers or unauthorized users? 
    6. is file/whole-disk encryption (Bitlocker) used on the server, laptops, desktops? If not, what would be the loss/risk if a staff member laptop was lost/stolen or if the church office was broken into and desktop(s) stolen? what information would the thief potentially have access to? 
    7. are all Windows desktop/laptop systems inoculated against CryptoLocker type threats? if not, why not?
    8. an assessment must be performed to balance risk of threats to consequences of damage if security compromised....not just about inconvenience, but impact of loss of financial or personal data information of members, staff, etc.  It would look really bad to have data leak (hack/breach) of member information out in public. 
    9. Remote access into the network?
      1. can staff remotely log into the network? workstations? server?
      2. how is that remote access managed/audited?
      3. risk vs. convenience evaluation?
  9. Auditing
    1. who is responsible for auditing laptops/desktops to ensure compliance standards are met? 
    2. how are the audits done? What specific checkpoints must be reviewed? 
    3. is the server(s) audited to ensure group policy or folder rights access have not been changed, compromised, and they meet security expectations? 
    4. software license audits?  Is software installed & licensed appropriately?
  10. Church website; aside from the site itself being kept up to date and accessible...
    1. is it secure?
    2. is is audited to make sure it isn't hosting malware or off-site links to compromised sites?
    3. is it accessible and viewable on mobile devices?
    4. does it contain items (schedules/forms/downloadable materials) that some members of the church might consider private or personal information?
    5. does "meta-data" information exist in downloadable files/forms/photos/etc. that could present security or privacy issues? Are all such items reviewed and "scrubbed" before being posted/uploaded?

Thoughts? Additional recommendations?

Please remember that while this isn’t exactly an “enterprise” operation, if it is large enough to have multiple switches, some servers, WiFi access points, etc. then there should be some sysadmin organization to the operation. And I am well aware that church networks should offer no safe-haven or sanctuary to all the threats in the “secular” IT space.

Cheers!

--Claus Valca

PS: While I still love Windows Live Writer for a blogging platform, the way it handles only the most basic “outlining” formatting leaves me super-frustrated.

What I did to generate this particular outlined list is to reformat it first in KompoZer Portable then copy and paste the source-code for the content back into WLW.

Saturday, July 07, 2012

Greased Monkey Business

It’s no secret that one of the major ways I manage to keep up with “goings-on” in the world of Technology and culture is with the use of a RSS feed reader.

Generally it goes something like this:

  • Launch Feed reader (Newsfox or Omea Reader),
  • Pull down article feeds,
  • Read, review and analyze,
  • Open feeds to be saved for later processing in web-browser, and
  • Bookmark article/link.

Later I might do some sorting of the saved bookmarks by subject or category or blog-post idea.

When it comes time to actually compose a post, I will open up Windows Live Writer on one side of my screen and my web-browser in the other.

Then I do a combo of composing the text body as well as some drag/drop action from the saved bookmark links.

That’s all well and good except for a tiny gotcha I figured out about a year ago.

See, many (but not all) of my RSS feeds actual open up to a page link that was seeded with some extra feed-tracking data code.

For instance:

This article appeared in my RSS feed list, was interesting, so I launched the full article in my browser and bookmarked it: Design and create with nanoCAD, a totally free CAD solution - freewaregenius.

However if you take a look at the actual URL provided by the RSS feed link in the browser was:

http://www.freewaregenius.com/2012/07/03/design-and-create-with-nanocad-a-totally-free-cad-solution/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Freewaregeniuscom+%28freewaregenius.com%29

…rather than the direct URL of:

http://www.freewaregenius.com/2012/07/03/design-and-create-with-nanocad-a-totally-free-cad-solution/

I added emphasis in the first link to show the extra sauce the RSS link path adds.

That’s not really a problem, but adds a bunch of extra code (and tracking data) that doesn’t really need need to be present in the blog links that everybody jumps from. I’m all for fair tracking and they get my “ding” when I view the full page the first time within my RSS feed reader.

So what I had been doing is cleaning up the link first in the bookmark properties before adding it to a post.

Only sometimes I forget.

Well, actually, many times I forget and it can be a lot of work cleaning them up.

Too bad I couldn’t automate cleaning up the bookmarks somehow.

Although I couldn’t figure a easy way to do that, I did eventually find a brilliant Greasemonkey script that did one better.

It actually intercepts the RSS feed-load in Firefox and cleans it up before loading in the tab. Sweet!

Removing UTM data from URLs automatically for cleaner bookmarks -Christian Heilmann. From his post page:

“I’ve come across lots of delicious bookmarks that still have all that campaign monitoring stuff in them, which is annoying. To work around that I’ve just written myself a tiny GreaseMonkey script:

Install un-UTM for GreaseMonkey

“If the browser now opens a link that has UTM data in it, it removes the information and reloads the page without it to make for a cleaner URL.”

Christian is clearly brilliant and his solution works perfectly. No more tracking data appending of URL’s to my saved bookmarks!

Related:

Mischief managed.

--Claus V.

Saturday, June 25, 2011

GSD Blog Template Reboot

No, you have not accidently experienced a page-redirection to either the TinyApps.Org or NirBlog website, although they remain quite inspiring to me.

I’m blaming it on the super-hot, super-dry summer.  Looking at the “warm” color-tones previously used on the GSD blog just has made me feel uncomfortable of late.

So we are trying on some new new minimalistic clothing here to weather this long, hot summer here on the Texas Gulf Coast.

I feel cooler already.

--Claus V.

Saturday, February 26, 2011

Let’s Get For/Sec-Motivated!

While the NYT has been waxing prosaic that Blogs Wane as the Young Drift to Sites Like Twitter I take heart that I tend to be both old(er) and require a verbosity in communication that sites like Twitter and Facebook just cannot satisfy.  Mitch Joel has a great response to the NYT article in his Blogging Is Dead (Again) | Six Pixels of Separation Blog. And I am encouraged by two points he offers; “Blogging isn’t dead. Blogging is publishing.” and “Blogging is hard.”  From Mitch’s post:

Blogging is hard.

Blogging is hard because writing is hard. Writing is hard because finding the time to do real critical thinking and then to put those thoughts down in writing is even more complex. Reading, research, critical thinking, writing, editing and publishing isn't like posting a picture to tumblr or texting off a tweet. They're different beasts and they deserve different forms of metrics and comparison.

So despite the visible slowdown in GSD posting here, I assure my gentle readers that it’s because my boots have been on the ground, in the trenches, getting very dirty with real-world experiences.  I’ve been studying books, taking notes, putting into practice, crafting and refining.  And along the way taking names, linkage, and notes.

So please enjoy this labor-of-love blogging post today.  And special credit to two extra-special things I noted this week that helped me get focused:

  1. My “new post ranking” on the sidebar of the Windows Incident Response blog hadn’t sunk to dead-bottom yet, but was slowly getting closer and needed to be “bumped up”, and
  2. For some really bizarre reason bound to be the result of an interdimensional rift, E-Evidence Information Center - Blogs & Wikis made a grave error with the consequence of having Harlan Carvey’s Windows Incident Response blog listed at the top of the left-column and this humble blog listed alongside at the top of the right-hand column.  I’m not worthy…I’m not worthy!  Hopefully that will resolve itself dropping GSD a bit lower into the link-pile.  In the meantime I better represent!

Collections

Since it’s already come e up, it seems natural to start this LinkFest off with this WindowsIR blog post Links, Tools and Stuff.  At the end of the post, Harlan has a list of forensic/security related tool sites.  I’ve listed his finds below with a few others as well:

Wi-Fi Mapping/Monitoring Resources

A while back in the GSD post Security and Forensics Watch-List: GSD Linkfest Style I touched on some great (and free) Wi-Fi signal discovery tools; the inSSIDer 2.0 Wi-Fi Scanner or NirSoft’s WirelessNetView or the eye-candy rich Xirrus Wi-Fi Inspector.

Corey Harrell of Journey into Incident Response blog kindly left a comment on that post bringing my attention to Ekahau HeatMapper - The Free Wi-Fi Coverage Mapping Site Survey Tool.  While I was able to use inSSIDer on a recent incident response event to pinpoint a rouge Wi-Fi device and neutralize it, I truly believe the Ekahau product may have been able to help me better had I known about it at the time.

Since then, other similar tools such as Vistumbler and PassMark WirelessMon have come to my attention as well that not only provide Wi-Fi signal monitoring but also “heat-mapping” features.

New Stuff

There seems to have been a slight slowdown in the number of new “sparkly things” in terms of security/forensic software/freeware tools that usually makes me react like a Bowerbird to a shiny new object.

Fresh on the heels of DEFT Linux 6 getting released, Brett Shavers over at the Windows Forensic Environment (WinFE) blog announced It’s time to build your WinFE! having put together a very slick WinFE WinBuilder package.  It’s no secret I’m a mad WinPE builder and this WinFE builder is top-notch and will provide a very slick WinFE build with minimal fuss.  Check out Brett’s hard efforts for yourself.

JADsoftware has both installable and portable versions of Internet Evidence Finder v4 available: Internet Evidence Finder v4 – Standard Edition and Internet Evidence Finder v4 – Portable Edition.  Although not free, there are free-trial versions available for immediate download.  What’s more according to Brett Shavers’ post Portable Internet Evidence Finder and WinFE, it works just fine in a WinFE build!

Now out via SecurityOrb.com » Feb Edition of Hackin9

Lightbox Technologies is readying a release of Lightgrep.  First spotted via JL’s stuff: NYC4SEC Meeting 1/19/2011 blog post, this looks to be an interesting tool.

In the meantime, there is still the free Windows Grep tool AstroGrep. Other handy utilities are File Hound 3.2, Windows Grep, PRGrep, GREP for Windows, and my favorite, BareGrep.

Port Monitoring / SPAN port / Misc Network Traffic Monitoring Resources

Instead of using a network tap connection to monitor traffic, I rely upon a dedicated capture system hooked into a switch port configured with the port set to a particular SPAN configuration.  So far this configuration has worked golden.

I’ve posted these resources before on GSD, but I keep finding them so valuable I can’t help but repost them again, just in case someone stumbles across this post.

TaoSecurity post on SPANs versus Taps: TaoSecurity: Expert Commentary on SPAN and RSPAN Weaknesses

It links to two MOST Excellent articles on the issues of using spanned switch ports for collecting your network capture data, both form Tim O’Neill:

OK, now the linkage on SPAN’ing

And my oldies but goodies favorites:

CDP - What Switch Am I Connected To? and Monitoring Traffic with Span Ports – SynJunkie.  Two really great posts out of series of ones touching on network monitoring, and Cisco switch/router configuration techniques.  I’m singling these out in particular as they are of interest to sysadmin troubleshooting on the network as well as traffic captures.

And recently found this Wireshark Wiki article as well -- CaptureSetup/Ethernet.

So during a recent troubleshooting exercise regarding network traffic capture analysis, I kept pounding my head on the desk because the data I was collecting just was turning up to be frustratingly non-helpful.  My data from source A wasn’t matching my observed data from source B.  After a week of forehead soreness I finally realized I wasn’t capturing any TCP/UDP traffic at all!  Turns out this model of Cisco switch required a different port mirroring configuration than the standard one used. With the help of a cubicle buddy, we figured out the correct configuration settings, applied them, captured the network traffic data again, and within an hour I had the problem identified and resolved. Easy-Peasy.

That said, it drove home that while my Wireshark/Network Monitor skills may be getting much better, if I can’t self-evaluate the correctness of switch configurations, I may waste a bunch of time working off someone else’s assumptions.

So I ended up collecting the following additional links that were helpful in this regard:

Network Assessment and Analysis

There are some great updates in the realm of network assessment tools. 

My foundational tool are

These tools along with information of networks from Cisco Network Assistant generally can provide me a pretty good view of what is going on when I am analyzing network traffic captures.

However, lately I’ve been trying to add depth to my bench.

Nmap - Free Security Scanner For Network Exploration & Security Audits has been recently released at version 5.50.  I snagged a GUI-supported build Nmap 5.51 at FileHippo.com.  I’m still getting my feet wet on it with my home network before I expand usage onto our production environment but I am very impressed.

Erik Hjelmvik has recently kicked off his NETRESEC NetworkMiner website that offers both the free version of NetworkMiner we have all come to love and adore as well as a Professional version that offers result exporting, Host coloring support, and CLI scripting.  Erik’s site also includes a Blog so you can follow current events.  If you didn’t hear (who hasn’t) NetworkMiner has been released at version 1.0.  PCAP loading speeds are very much improved, no bomb-outs on pcaps that have particular packet errors in the capture, and a few new bells and whistles.

Despite Lavie’s teasing's, I am certain I’ve not yet fallen asleep with my copy of Laura Chappell’s Wireshark Network Analysis book on my chest…though truth be told it is rarely beyond fingertip reach lately.  I’ve learned a ton of great techniques and filters already and I’m only 1/4 of the way though!

I keep three installed version levels of Wireshark on my system.  I use the “Old Stable” version 1.2.x set as my work-horse doing most of my .CAP--> .PCAP conversions via the included version of EDITCAP.  I use the “Stable” version 1.4.3 for my daily capture and focused analysis work. Then I have been excited to find that the “Development” version 1.5.0 is super-fast and doesn’t seem to experience the constant memory-crash problem opening large PCAP trace files that the other versions to. So it is often the first one I use to open then post-capture filter the trace file into smaller more focused PCAP files.  If you haven’t tried it yet, give Wireshark 1.5.0 Development Release a whirl.

GSD Related posts: Network Linkfest & Network Monitoring Madness: Poor Man’s Resource Linkfest

Scanning for MAC and and finding some-FING special

Once you spend any time at all in the network world you quickly realize that addressing physical network security is a foundational element.  If you haven’t found it yet, give this /dev/random post Why Physical (Network) Security is Important? a look.  It is a concise primer and I can vouch that it is unnerving when doing a network trace analysis to suddenly be staring face-to-face with a rouge network device secretly added to your network.

Nmap can be a good place to start. Also, having a list of IP/MAC addresses as well as Host data for them can be a great reference while picking apart and filtering capture traces.

Here are some other free tools I’ve had good success with in performing local network inventory sessions to get that IP/MAC information.

Note: most (but not all) generally do not provide accurate (if any) MAC address discovery across networks.  By that I mean you generally need to be running the tool on a device that is already inside that network..rather than from a remote system outside the network/subnet.  That’s not a problem for me with our embedded network capture systems we remote in to.  But be aware of that issue in case you try one and results are not displayed as intended.

An exciting and new find (to me) was Fing 1.4 from overlook.

What I really, really, really liked about Fing was that is is a CLI-based network discovery tool that is multi-platform (Linux, Mac, Windows, even, yes…Android), supports MAC address gathering, service info gathering, and can run as a service and scan/report changes when occur.

The Fing manual contains a lot of information as to the capabilities as well as examples of report output in csv, text, html, and sml formats.  It is really cool.

Enjoy the view of a demo report. Fing is freeware, and may be downloaded here.

Don’t let the CLI environment worry you, once installed, it creates a program shortcut for launching a terminal window in “interactive” mode which will guide you through the process.  Once you get comfortable, you can run your own targeted ping commands much more efficiently on your own.

And if you can wait, alpha/beta testing has concluded on a GUI-based FING edition. No word on release date. I missed out on the testing (DRAT!) so I haven’t had an opportunity to see this GUI-version but the forum feedback seemed positive.

Check Fing out!

RE: MAC’s & Spoofing

Yes…I felt obligated to add this.

I know that MAC addresses can be spoofed. Easily. So a MAC address alone is definitely no smoking gun.  That said, if the MAC address you are working with is captured “in-context” in a traffic capture or with other tools, and especially if it persistently consistent in presence, you still stand a good chance of being able to track down the physical device associated with it. If it shows up in a traffic capture you should have the traffic, the packets, the IP address associated, and the MAC address being offered.

Couple that with a MAC/IP/Network scanning tool, some l33t work inside your switching hardware, and you should be able to trace it to a physical switch port (well, it it isn’t Wi-Fi I suppose).  Then it’s just a matter of following the wire.  Then finding the answer to why someone would want to spoof an MAC address on your network would be my next step.

Anyway…that said, here are some related resources.

Blogging is dead?  Seriously?  I think not.

Tweet that.

--Claus V.

Saturday, January 01, 2011

New Year’s Day - First Post 2011

Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over at ReadWriteWeb.  According to the study, blogging activity on-line has heavily dropped, while on-line content consumption has continued to grow.  Looking back at my side-bar, I have to confess that my raw content-generation post numbers have declined since my high-water mark in 2007.  However I would like to argue that while volume has decreased, quality has increased slightly.

Of course, the amount of leisure time I have available has also decreased which accounts for much of the decline in GSD posting.  At the same time, I could probably work on being more disciplined with some of my time.  Couple that with our “study” slowly turning into a laundry-room/super-closet of sorts and my blogging desk hidey-hole has disappeared. Yesterday I took down and stored away the Christmas decorations for another year (almost two-weeks early from my usual procrastinations).  This brought on a major re-setting of the living/family room area and I now have a micro-desk area set up there instead.  Maybe that will stimulate the blogging juices as well.

In the meantime, here is a getting-the-new-year started linkfest of new applications and neat utilities to jump-start the effort to push the GSD post-count for 2011 upward again.

FreeCommander XE Beta now public

FreeCommander remains my #1 top go-to dual-pane file manager.  I’ve tried tons of other file-managers and while there are many great options out there now, IMHO, none come close to the features and flexibility of FreeCommander.  It just works with the way I jockey files all day.

The developer, Marek Jasinski, was kind enough to give me private access to the alpha builds of the next generation of FreeCommander and I have been diligently putting them through the paces.

So it just in the last week or two that he posted the first publically available release of FreeCommander XE.  While it retains the same form and function of FreeCommander, the style has been seriously updated and the fine-tuning control is greatly enhanced.  You can get both the install version or a “portable” zip file version from that page.  Just be aware that it is still clearly a developmental “preview” release so while most of the features will work as planned, you might be a bit frustrated with what still does not if you are a power FreeCommander user.  I’m still not ready to replace the latest stable version of the “old” FreeCommander with this version just yet.  But it is a nice look at what is to come.

Other related tips that might be of use to you if you are both a FC user and a TeraCopy user.

Run Command Links

When I am setting up special purpose XP systems, sometimes I have to make some tweaks to system settings.  Going the long way through menu systems to get to a particular windows is time consuming, so pulling it up via a run line is a big time-saver.  I’ve memorized many of them, but every now and then I can’t recall and Windows doesn’t make it easy to access the commands if you don’t know what they are to start.

Here are three bookmark-worthy resources for just when you need them most (XP/Win7).

VirtualBox 4.0 Final

Oracle has now released the final public release of VirtualBox now sitting at 4.0 - Downloads - VirtualBox.

You can also get it via their ftp page: Index of /virtualbox/

Brett Shavers of WinFE Blog fame recently reminded me of the MobaLiveCD tool.  While not related to VirtualBox, it does provide a clever and portable Qemu package to run virtual sessions of LiveCD’s for down-n-dirty testing.  It worked on my rippin-fast Win7 x64 laptop, but was very, very slow in performance.  So while handy in a portable pinch, it probably isn’t useful for production-level virtualization work.

There is also vbox.me ‘s Portable-VirtualBox project.  As I understand it currently, while there is a v4.0.0 new release support out, Oracle has now required the developer to remove direct inclusions of VirtualBox items from the package, and it is now set up in a manner that first downloads the VBox binaries then unpacks them for the portable setup process. And USB support still is in works as well at the moment.  YMMV.  See also How To Make Portable VirtualBox 4.0 For Windows at addictivetips.com

Network Briefs

Always a great source of personal tippage, TinyApps passed on a lead to the Dualcomm Mini USB Powered 5-Port 10/100 Ethernet Switch TAP.  How cool is this at less than $100? They also offer this larger Dualcomm USB Powered Gigabit Ethernet Switch TAP at a $150 price point.  In both cases Port #1 is mirrored to Port #5.  See also this brief post by George Starcher » Review – DualComm – Ethernet Tap.

Speaking of taps, in a former GSD post on the subject I offered these references:

As such here are some related materials on that subject for future reference when needed.

…But first, read and review this brief TaoSecurity post on SPANs versus Taps: TaoSecurity: Expert Commentary on SPAN and RSPAN Weaknesses

It links to two MOST Excellent articles on the issues of using spanned switch ports for collecting your network capture data, both form Tim O’Neill:

OK, now the linkage on SPAN’ing

And my oldies but goodies favorites:

CDP - What Switch Am I Connected To? and Monitoring Traffic with Span Ports – SynJunkie.  Two really great posts out of series of ones touching on network monitoring, and Cisco switch/router configuration techniques.  I’m singling these out in particular as they are of interest to sysadmin troubleshooting on the network as well as traffic captures.

And recently found this Wireshark Wiki article as well -- CaptureSetup/Ethernet.

Which is neat as I just ordered up some additional reference for the new year: Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide by Laura Chappell, Gerald Combs.  I sooo can’t wait for this one to arrive!

Finally, the Microsoft Network Monitor blog has this new post: Filtering On Timestamps which is good information to know if you prefer Network Monitor or NMcap (CLI) for your traffic capture handling.  Don’t miss the tip link to the online Date format converter page to assist in your conversion work.

Utility Roundup

Via the German blogger Caschy (through Google Translate magic), CopyTrans TuneSwift.  There are more than a few ways to move your iTunes stores from one system/location to another…though they all have their own quirks and shortcomings.

Check out either the CopyTrans Suite of tools or the CopyTrans specific utility as it may have a full-featured backup/transfer/restore solution you are looking for for iTunes/iPod management and recovery.  Currently CopyTrans is being offered for free, but will switch to a pay-version 03/15/2011.  You will need an unlock code so either use the one Caschy has provided on his page or the direct one on this CopyTrans page.

Because I never can remember the conversion rates for bps to Bps to Mbps as I deal with various network bandwidth graphs I’ve settled on Converber Portable over at PortableApps.com to prove me a super-handy tool for all my IT figure conversion needs.  Tip: While it can do so much more, just set the “Category” field to “Computer” to filter down the list of over 1324 various units of measure in 38 categories to just those used in the IT field.  It’s much less overwhelming that way!

ImageX GUI (GImageX) still remains my fav ImageX CLI Gui-based tool for super-fast WIM management.  However, 4SYSOPS recently posted about an alternative ImageX gui manager GDism ELDI v3.0.2. As Michael Pietroforte points out, the strongest feature/drawback might be the fact that it is a Java application so depending on your viewpoint on Java, that may or may not be a good thing.  That said it is a nice alternative. (Note: the CGI ‘avatar’ figure displayed on the ELDI page might be a bit racy for some so depending on policy standards, you may want to check the page out at home first before hitting it from work…just to be safe.)

First there was Orca for picking apart and manipulating MSI packages. Then came InstEd It! which seriously seemed to expand the options available.  Then I really fell in love with the light but perfectly handy (for me) lessmsi tool (still alive and cool). Now comes wind from Kurt Shintaku via his blog post RELEASE: MSI Explorer – Inspection Tool for .MSI installation packages of yet another MSI package inspection/change tool; MSI Explorer coded by Sateesh Arveti.

Ryan at CyberNet News seems to have slowed down on the blogging as well, but his post Stress Test a PC with HeavyLoad offers an additional (portable) freeware tool that can be used to put the heavy on a system for load-testing and performance monitoring.  Don’t forget other beefier tools such as the Phoronix Test Suite and Inquisitor. MakeUseOf blog also offered a while back The 5 Best Free Benchmark Programs for Windows.

See also the JAM Software - FileList CLI tool (freeware) for generating file-lists in a given directory.  Check out the ReadMe for additional CLI arguments.

What the Web Says…

Sometimes you have to go to the Web to find out just what is what and where stuff is ranked.  These were pretty cool finds this past week.

Browserscope - From the web-page “Browserscope is a community-driven project for profiling web browsers. The goals are to foster innovation by tracking browser functionality and to be a resource for web developers.”

namebench - From the project page “It hunts down the fastest DNS servers available for your computer to use. namebench runs a fair and thorough benchmark using your web browser history, tcpdump output, or standardized datasets in order to provide an individualized recommendation.”

See also the super-tiny, fully portable GRC’s DNS Nameserver Performance Benchmark utility for a no-install alternative.

Finally, got an Intel chip-based Windows system? You might want to hop over and try the Intel Driver Update Utility.  Ed Bott gets the hat-tip and has more information on his How to update Intel drivers automatically blog post.  I found a very new wired Ethernet port driver update for my new Laptop.  Please carefully note this one item from the Intel page easily overlooked:

Intel® Wired Networking note: If the Intel Driver Update Utility shows your Intel wired networking product ending in '(OEM)', Intel recommends you use the networking software provided by your computer manufacturer. OEMs may have optimized the drivers for your system.

Happy New Year!

Claus V.

Sunday, October 03, 2010

Just a Note or Two and some SteamPunk

image

cc attribution: Notebooks by See-ming Lee 李思明 via flickr

Wow.  Can’t believe it has been this long since the last post!  What’s sad is that very little of it has been spent on the new laptop.

Mostly bad-crazy work stuff leading me to be exhausted by the time I get home from work. Then honoring time and family commitments on the weekends.  So much to post…so little time.

On the plus-side I’ve been able to really put some of the tools and techniques I blog about into incident response action lately.  While it is never a “fun” thing to have to do, it is pretty cool when you get to apply your knowledgebase in extreme situations.  While (unfortunately) it’s very doubtful I will share any information at all, I do expect to share some more information on tools and techniques I found valuable in the process.

I’m taking a break at the moment from technology posts to go a bit “old-school”.

While I generally use QCC’s freeware tool CaseNotes to document my incident response activities, and find it really does an excellent job fitting my needs I almost always keep a pen and micro-sized paper notebook on my person as well.  Beats writing on my hand and is great for jotting down phone numbers, bits of data, field observations, quotes, URL links, etc.

I’ve been thinking of this lately as I saw some Moleskine mini-notebooks a few weeks ago when visiting the bookstore with mom.  I didn’t pick any up but they did catch my attention.

Then The Art of Manliness blog ran a series of articles that really encouraged me to use them that much more:

The comments in the first post were a treasure-trove of links and materials for the notebook carrying fan.  I found a number of great sources for fun and functional mini-notebooks.

Field Notes - Seemed to be one of the most popular sources for no-frills “common-man” notebooks.

Rite in the Rain - Was praised by field workers, outdoorsmen, military/LE, and other extreme environment folks.

Moleskine - This brand seems to have splashed onto the market with much fan-fare.  The quality and variety seems to make them very popular with note-takers and artists alike.

Right now, I am using these Top Flight Sewn Mini-Marble Composition Books (Amazon.com) that Alvis tossed my way.  They fit unobtrusively in my front pocket and are surprisingly durable.  They are very cheap…so I tend to toss them when all the note taking is over and they are filled up.  Not really archival material.

I had been using these Mead Wirebound Memo Books (Amazon.com) but the wire ring would get crushed after a few days in my pocket and the pages tore out too easily.  So I just keep one in my car only for quick notes but that’s it.  It will likely be replaced soon.

These Writersblok Bamboo Mini Notebooks looked like a cheap and nice alternative to my current notebook fare. Made by K I K K E R L A N D, they seem high quality and fit the quirky and fun other products offered by them.

Turns out there is a whole fan-following of notebook bearers!

I’ve scored a few new RSS links for some sites that live and breath all things creative and useful with notetaking and notebooks.

The Little Black Book by Pad&Quill - This was pretty clever…and inspired me.  I’m overwhelmed at the moment with ballistic nylon carrying cases for all my portable hard drives and gizmos.  After looking at this, I was struck with how easy it would be to stop by ye-old/used-bookstore and pick up some tomes that had outward character to their binding and cover.  Then hollow them out to make carry-cases for the portable USB HDD I carry.  Some glue and some tiny metal/magnets to hold the lid shut and bam--pretty neat carry-case!

SteamPunk Resources

As a Sherlock Holmes fan, I appreciate the romantic notion of the Victorian era (but accept the Dickensian reality).  Add to that the fact that Last Exile is based heavily on a “SteamPunk” styling and my artistic eye is smitten.

Turns out there is a whole fan-base devoted to making and living SteamPunk style.

Steampunk Wallpaper is a very recent find that has provided a ton of awesome high-quality desktop wallpapers in the SteamPunk/grungish style.  Really stunning work here by the artists.  Even if you aren’t a fan, you are bound to find something appealing.

The Steampunk Workshop | Technology & Romance - Fashion, Style, & Science - Ongoing web-site filled with the very best examples and guides to SteamPunk hardware and software.

The Steampunk Home - Neat ways to add that anachronistic touch of class to your home; many with commonly available materials repurposed.

SteamPunk Magazine » Downloads - Free PDF downloads of SteamPunk Magazine.   Very interesting articles and perspecitves…to say the least!

Happy notetaking and jotting!

--Claus V.

Saturday, August 07, 2010

Blog Reboot #2

Fresh from last night’s Blog Breathing… GSD blog updating.

I’ve had a fairly decent night of sleep and have been hard at work on the additional design changes I’ve wanted to do.

I did change the overall “light-fonts on dark background” to “darker-text on lighter background”.  This should be better on the eyes by far.

Our resident graphic artist Alvis has been popping in giving me feedback and suggestions as well.

Most of the “Links” items and sub-categories survived, however I did add more than a few new items:  see the “Tech and Security Links”, “Life in Zen”, “Things to Motivate”, “Forensic Live CD’s”, “Software Sources”, “Guilty Pleasures”, and “Photography” sections for the super-duper changes.

I also successfully added the new “GSD Watch List” blog roll.  Blogger’s own gadget seemed to do the trick.  Only issue I have is that I have some awesome Microsoft TechNet blogs that it won’t add for some reason; Mark's Blog, Sysinterals Site Blog, MS Malware Protection Center, Network Monitor Blog.  I think it’s because of the way the blog home pages are addressed in a disallowed format: http://blogs.technet.com/b/blognamehere/   I’ve been unable to figure out a workaround for now so those had to get added statically up in the “Links” section.

I’ve noticed that Blogger platform now has the option to Create Pages in Blogger (more here Pages come to Blogger In Draft).  I think this might be a great way to add some static material pages for reference but I would need to do more organization.  What would serve me (and the faithful readers) best? Pages with lists of “best of” tools/utilities, wish-list, web-browser links (fav platforms/extensions), or useful CLI examples?  Or would those be better served under the Google Sites Grand Stream Dreams project site page instead?

We’ll have to see….

Cheers.

--Claus V.

Friday, August 06, 2010

Blog Breathing…

I’ve just made a few updates/tweaks to the GSD blog tonight.  Didn’t really plan on it but there it is.

I’ve removed the two-column sidebar and reduced it to a singe column.

That then allowed me to expand the blog post text area but about 25%.  I feel like I can breath again when I look at the posts.  Weird.

I also changed the font.  I down-sized it just a touch, but also with a new sans-serif style which I think works a bit better on the eyes.

I haven’t yet, but I may still change the post background to a lighter one and ditch the white text.  I fiddled with it just a bit before deciding to leave it as-is for now.

I’ve replaced the “blogged by” image on the sidebar lead and rolled it back to the original GSD kids.  I like the colors and it seems “lighter” and more cheerful and image.  My real-life expression is generally more stoic in nature (except when I’m flirting…apparently all the time according to Lavie) so I think the old “new” image works better here.  Fear not, no other meaning with this change; Lavie and Alvis remain attached to my side…both in the fantasy anime as well as in real life!

My next task is to seriously update the “Claus’s Toolbox” and “Links” links.    Most of the toolbox links still stand but I’ve probably added a few more GSD posts and such that warrant addition.  It’s funny that while I still have those Tweaking XP and Vista links, I’ve not done one for Windows 7.  To be honest there are really only a very few tweaks I make under W7.  Strange…maybe they got it “righter” in the GUI/interaction this time.

I’m also self-aware of some glaring omissions to this mis-match “blog-roll” of sorts.  I’ve got some favorite blogs that aren’t listed, and other linger on though I haven’t clicked through in ages.

I think the “New Gear and Gizmos” links section is about to be retired and replaced with a Forensics one.  That probably makes sense because I am much less “hardware” focused now.  And while I am no professional “forensicator” - to use a keydet89 term – I am doing a lot of network and incident response posts and related activities on my own work-bench so I think it fits.

Finally, I’m considering adding my own (again borrowing from the keydet89’s blog sidebar style) fav BlogRoll list.  I just gotta figure out which gadget he used…hopefully it is a Blogger one to make things easy…

So I’ll be working on these as well from time to time, expect to see a few more tweaking as the weeks go by.

Cheers!

--Claus V.

Thursday, April 01, 2010

April 1st link-dump

No. No April Fool’s jokes here.  All are refreshingly legit.

Cheers.

--Claus V.

Saturday, March 20, 2010

GSD Recent Comment” Sidebar link references fixed

For anyone who cares, I finally took the time to “fix” the html links in the “Recent Comments” sidebar.

While they look good, it has always annoyed me.

The format is this.

(poster name) on (post title) comment bits(more).

Clicking on any of the HTML links just took you to the top of the post the comment was left on. Not the comment itself as expected.

While users could scroll down to the comment section, it just wasn’t as right or polite as I wanted.

I’m not really much of a coder, particularly JavaScript, but I decided it was time to try to fix it.

So I located the correct comment link HTML format from a post comment as a sample to examine.

http:// <blogtitlelinkurl> ?showComment= <numbersetA> #c <numbersetB>

This code correctly takes you directly to the respective comment under the post.

Then I copied the existing HTML codes the JavaScript was generating into my notepad text editor and set out to compare them all.

Very quickly I found that the original JavaScript code (included at the end of this post for the curious) was replacing the “#” symbol in the working comment HTML structure with a “#comment-“ string instead.  This routed the link-click to the post title when Blogger couldn’t figure it out.

Looking at the JavaScript code I found a line “ctlink = ctlink.replace("#", "#comment-");” and replaced it with “ctlink = ctlink.replace("#", "#");” which was a dirty way to not muck the code up but keep the variable structure the same.  (Note: “ctlink” variable name stands for “comment link” I think).

Testing finds that it works perfectly.

Clicking on either the (poster name) or (more) parts will now take to directly to the comment itself, not the post title.

While clicking on the (post title) link takes you to the top of the post itself.

The only thing I still needed to do (being a bit neurotic) is that while that worked, the (post title) HTML code was sloppy as the JavaScript generating it still seemed to either be tagging it with, or failing to remove the “?showComment=numbers”  bit at the end.  It did work, it’s just not pretty.

That still needed fixin’.

Trial and Editor

Luckily I had recently found the following W3Schools Online Web Tutorials site that also has their “Tryit Editor”.

This is really, really cool as it lets coding doofs like me copy/paste/tweak/test code and scripts into their editor and view the results without nuking my deployed blog until fully tested.

Once I think I have the solution down, I then upload the changes to my gsdtemplatetester blog page.  This is the proving ground where I can experiment with code and templates on a “real” Blogger deployment before moving those changes into production on the GSD blog page template proper.

So I set to work using the JavaScript descriptions there, picking apart more of the code elements and variables, and via trial and editor, found the line to fix.

Originally it was

var ptlink = ctlink.split("#");

Where the variable name “ptlink” stands for “post title link” I think.

Which I finally worked out needed to be

var ptlink = ctlink.split("?showComment=");

Replacing that finally resulted in the comment sidebar (post title) link returning the HTML code format

http:// <blogtitlelinkurl>

and not the incorrect (but still functional)

http:// <blogtitlelinkurl> ?showComment= <numbersetA>

Hurrah! The Recent Comment sidebar links now all work correctly and the HTML code is fully correct as well.

Hopefully this will make monitoring and following the recent comments a bit more enjoyable and efficient for readers.

Cheers!

--Claus V.

Note:

For posterity, here is the original (working but barely) and fixed (working great) JavaScript code I am using if anyone cares to study it more.  I’m clearly not the original author of the JavaScript.  It came from somewhere within this Now See This: Adding Comments to your Blogger sidebar GSD post back in 2008 (gosh has it been that long?!!).

Original (working but barely) JavaScript code

<ul><script style="text/JavaScript">
function showrecentcomments(json) {
for (var i = 0; i < 5; i++) {
var entry = json.feed.entry[i];
var ctlink;
if (i == json.feed.entry.length) break;
for (var k = 0; k < entry.link.length; k++) {
if (entry.link[k].rel == 'alternate') {
ctlink = entry.link[k].href;
break;
}
}
ctlink = ctlink.replace("#", "#comment-");
var ptlink = ctlink.split("#");
ptlink = ptlink[0];
var txtlink = ptlink.split("/");
txtlink = txtlink[5];
txtlink = txtlink.split(".html");
txtlink = txtlink[0];
var pttitle = txtlink.replace(/-/g," ");
pttitle = pttitle.link(ptlink);
if ("content" in entry) {
var comment = entry.content.$t;}
else
if ("summary" in entry) {
var comment = entry.summary.$t;}
else var comment = "";
var re = /<\S[^>]*>/g;
comment = comment.replace(re, "");
document.write('<li>');
document.write('<a href="' + ctlink + '">' + entry.author[0].name.$t + '</a>');
document.write(' on ' + pttitle);
document.write('<br/>');
if (comment.length < 120) {
document.write(comment);
document.write('<li>');document.write('<br/>');
}
else
{
comment = comment.substring(0, 120);
var quoteEnd = comment.lastIndexOf(" ");
comment = comment.substring(0, quoteEnd);
document.write(comment + '...<a href="' + ctlink + '">(more)</a>');
document.write('<li>');document.write('<br/>');
}
}
document.write('</li>');
document.write('<div style="font-size:95%;text-align:center"><a href="http://grandstreamdreams.blogspot.com/feeds/comments/full">GSD RSS Comment Feed link</a></div>');
}
</script>
<script src="http://grandstreamdreams.blogspot.com/feeds/comments/default?alt=json-in-script&callback=showrecentcomments">
</script></ul>
<noscript>You need to enable JavaScript to read this.</noscript>

I’ve also linked to some of the JavaScript examples and actions at w3schools page as well for easy cross-reference to show what these various calls are doing.

Fully Working JavaScript code (changes in yellow)

<ul><script style="text/JavaScript">
function showrecentcomments(json) {
for (var i = 0; i < 5; i++) {
var entry = json.feed.entry[i];
var ctlink;
if (i == json.feed.entry.length) break;
for (var k = 0; k < entry.link.length; k++) {
if (entry.link[k].rel == 'alternate') {
ctlink = entry.link[k].href;
break;
}
}
ctlink = ctlink.replace("#", "#");
var ptlink = ctlink.split("?showComment=");
ptlink = ptlink[0];
var txtlink = ptlink.split("/");
txtlink = txtlink[5];
txtlink = txtlink.split(".html");
txtlink = txtlink[0];
var pttitle = txtlink.replace(/-/g," ");
pttitle = pttitle.link(ptlink);
if ("content" in entry) {
var comment = entry.content.$t;}
else
if ("summary" in entry) {
var comment = entry.summary.$t;}
else var comment = "";
var re = /<\S[^>]*>/g;
comment = comment.replace(re, "");
document.write('<li>');
document.write('<a href="' + ctlink + '">' + entry.author[0].name.$t + '</a>');
document.write(' on ' + pttitle);
document.write('<br/>');
if (comment.length < 120) {
document.write(comment);
document.write('<li>');document.write('<br/>');
}
else
{
comment = comment.substring(0, 120);
var quoteEnd = comment.lastIndexOf(" ");
comment = comment.substring(0, quoteEnd);
document.write(comment + '...<a href="' + ctlink + '">(more)</a>');
document.write('<li>');document.write('<br/>');
}
}
document.write('</li>');
document.write('<div style="font-size:95%;text-align:center"><a href="http://grandstreamdreams.blogspot.com/feeds/comments/full">GSD RSS Comment Feed link</a></div>');
}
</script>
<script src="http://grandstreamdreams.blogspot.com/feeds/comments/default?alt=json-in-script&callback=showrecentcomments">
</script></ul>
<noscript>You need to enable JavaScript to read this.</noscript>

Saturday, March 13, 2010

GSD Redesign (again)

Probably not the best time to do something like this.  Been out in the back yard for most of the day hand-pulling the thick blanket of weeds from the yard.

My fingers are numb.  My sittin’ bucket is busted. My arms and legs still itch even after a long shower scrub-down.

The smell of wild green onions lingers in my nose.

I’ve got a 50-pound of weed bio-mass pilled in a back corner.

And then I take a moment to rest and find this stupid link:

Official Google Blog: Express yourself with the Blogger Template Designer

Well yeah. Of course I have to go muck around with it.

I’ve generally liked the lightly dark format of some sites/blogs but have never been brave enough to try it on for size.

I have also strongly resisted the image-background/floating layout style as well.

However, the new Blogger Template designs are quite well balanced and I’ve always been a sucker for earthy warm-tone color schemes.

I’m liking this one for now but I expect more tweaks will come down the line.

This is probably one of the largest in-house updates Blogger has released in quite some time.

Rendering so far in Firefox 3.6, Opera 10.5, IE 8, Chrome, and Safari all seem very spot-on.

Sidebar items will require some custom adjustments but I think overall it has translated pretty well.

Stay tuned.

--Claus V.

Saturday, September 12, 2009

SOS Linkfest: Tools, Tips, Stuff + Recipe!

It's Still Raining!

For the past few days the upper Texas coast has been slogging through a series of rainstorms.  Today we stayed pretty dry while the system move more over the “Golden-Triangle” area and East Texas, leaving metro-Houston area under a blanket of clouds and light precip.

Great day for couch-surfing and college-ball watching. The Cougs walked away with an upset but ND gave up their battle in the end.

SOS is the Best

It’s no secret that my favorite meal of the day is breakfast.  I’d eat traditional breakfast fare all day long if I could.

However, my most craved “breakfast” dish growing up and to this day is what we call “chipped beef on toast”.  Lavie will eat it though Alvis usually declines.  Old military guys refer to it as SOS.

A dreary and wet Saturday was an easy excuse to whip up a batch this morning.

My recipe variation is dead-simple, super-quick, and feeds me (or me and Lavie).  It is much lighter than this 1910 Manual for Army Cooks version that feeds 60 hungry troopers.

  • 2 Tablespoons butter
  • 2 Tablespoons all-purpose flour
  • Pepper (large-grind is my preference) to taste
  • Combine butter/flour/pepper in saucepan or medium-sized skillet over low to medium-low heat until melted.
  • Stir well (I use a wire whisk) and let get “bubbly” for about 1-2 minutes.  Watch carefully so the roux doesn’t burn, otherwise the gravy will not be white (though still good).
  • Take 1 cup whole milk and add to roux.  (to speed thing up, try microwaving the milk first for 30-45 sec.)
  • Whisk well to combine and get roux fully incorporated.
  • Bump up the heat to medium or a touch shy of medium. (your range may vary)
  • Find as much thin-sliced ham or beef lunchmeat as you care for. For me usually two packages of “Buddings” brand does nicely.  “cube” it up into fingernail-sized bits and add to gravy.
  • Continue stirring gravy mix now until thickened and meat has had a chance to warm up.

If it gets too thick (my preference is to be able to cling to a spoon held upside down) just add a bit more milk to thin (Lavie’s preference).

While it can be served over whole pieces (shingles) of toast, I prefer to cube up the toast first. Makes it easier to get it into my pie-hole faster!  In the past I used to tear the toast slices but I’ve found that using either of two tools can make fast and consistent work cubing up toast. Like Alton Brown of Good Eats! I like a kitchen multi-tasker.  Try cubing the hot toast with either a pizza cutter or a chopper/scraper.  Both work great!

I don’t add salt as the meat takes care of that to my tastes.  I do add the pepper immediately when making the roux as I think it brings out the oils in the pepper a bit and infuses the gravy better.

Couple this with a few hard-fried eggs and some hot coffee.

Yummers!

Beautiful Gantts

The Boss (the work one) requested that I convert my procedure checklist for our IT ops on opening up a new office (fulfilling and implementing the phones/network/server components) into more of a visual format so it was easier to see how all the different resources (IT staff) could be tracked.

Sounded like the perfect excuse to put it into a Gantt chart.

Among the various project management software items I posted before, I could have just reached for MS Office Project.  Unfortunately, only a few of us at work have MS Project.  I wanted something a bit more shareable.  The freeware tool ΤΙΜΙΟΣ Gantt Chart Designer is mighty easy to use (and portable!) but not really shareable.

I did find this awesome Office move plan (US units) – Template at Microsoft Office Online.  It is Excel compatible and is over the top with views.  I saved it to pick apart later.

Instead I picked through a few other really nice (and free) Excel templates for Gantt charts.

In the end I went back to my old standby (and updated to a 2009 release) that is compatible both with MS Excel 2003/2007 versions.

David’s been hard at work and his Design, Productivity, Inspiration, and Empowerment web-site is now officially “off-the-hook!”

Once I downloaded the Version 2 (2009) Gantt chart and after a few hours had it populated with my project template data and sent off to Boss (dully impressed I must say), I went back and found some great material on David’s site.

Couple some of these materials and David’s productivity and organization tips with many of the life-orienting productivity tips from Zen Habits and you might find a some B-12 for your brain!

Posterous

I’ve been generally happy with Blogger as my blogging platform.  It is solid and I can tweak it to my heart’s content.

Last week I was chasing web-rabbits and somehow ended up stumbling upon Posterous.

Basically it’s a blogging platform that you can manage by sending emails to.  Sure Blogger can do that as well, but the pages have nice design and look and it can handle pictures, videos, as well as text content with some fancy formatting.

You can even add Google-Analytics code to it for tracking.

I’m not planning any switches but I like it and it seems to be gaining a modicum of popularity so I thought I would stake out a Grand Stream Dreams spot just to be safe.

I’ve not really got anything in mind for it quite yet but I do like having a “go-to” option for getting post material uploaded via email on the quick.

Tools of the Trade

I love a good set of tools.  My humble collection fits my needs but isn’t nearly as substantial (and cool) as either of my late grandfather’s tool collections.

While checking my feeds out I was intrigued by this Retro Thing post:

In the past I used to change my own watch batteries but my latest pair of daily watches have the fancy backs that require that special tool to twist off.  This looks like it could fit the bill nicely.

That reminded me (somehow) of this Hard Drive Errors and Replacements post over at SANS Computer Forensics, Investigation, and Response blog.  I’ve got a couple of dead-drives I’ve been wanting to open up to use as objet d'art for my desks.  Only they have that micro-Torx (?) screw head.  So I found that Amazon has quite a few nice micro-bit kits as well: Amazon.com: SMALL TORX SCREWDRIVER SECURITY TAMPER PROOF HOLE T5 T6 T7 T8 T9 T10 T15: Home Improvement, or Amazon.com: 33 pc. Security Bit Set: Home Improvement, or Amazon.com: Maxtech 16521MX 32-Piece Precision Bit Set: Home Improvement.  I’m still going to try the mega-home improvement stores first but these look like a good backup plan.

Do any of the GSD faithful have any recommendations for HDD lid screw bit kits?  I’m open to suggestions!

“9” – Short Edition

I’ve really been intrigued by the trailers for the movie 9 (2009 film Wikipedia link).

So when I found this Geek Dad post 9 Things Parents Should Know About 9 over at Wired! I took the bait and read on with curiosity.

After that I hit the already provided Wikipedia link to get the plot (now spoilt but still sounds good).

Turns out that the full-length version of 9 was based on the short film 9 (2005 film Wikipedia link).

Amazingly, that short-film is up on YouTube in standard and HD versions!

  • YouTube – 9 - Shane Acker’s original short film/cartoon now adapted into a full CG movie

It’s just over 10 min in runtime and though it doesn’t give away any of the full-length movie plot points, it is a great film and great to watch for all you steampunk fans.

For Lavie only (OK if Alvis peeks also): New Moon

Yep. She’s a Twilight fan. 

I’ve read the first book and found it fun.  I’ve seen the movie with the girls on DVD more times that I can now recall.

Lavie’s consumed/devoured/gorged herself on all the current books in the series as well as the “official” unofficial release of the first book (Midnight Sun) from Edward’s perspective.  Lavie has also gotten lost in the depths of the Twilight fan-fiction sites now.

I was able to bring her up today for this; New Moon’s latest trailer.

Nothing like the rain to bring out the fun.

Cheers!

--Claus V.