Tuesday, June 16, 2009

I'm terrified of Twitter Trending Topics

I am watching with great interest, the activity on Twitter surrounding the current events in Iran. Based on the fact that there are seemingly hundreds of messages per minute with the tag #iranelection flying across the interwebs as I type this.

To be sure, it's both a fascinating thing to watch events unfold in real time (along with some serious cluelessness) and a horrifying thought to witness there are people experiencing some really horrible things at the same time as we watch.

Of course that really isn't my point, since there are hundreds of other blogs to analyze the actual events and how social media is changing the face of news or whatever. Use Google, go find 'em you're in the wrong place ;-)

No, rather as I watch this seemingly endless stream of raw data, I noticed one thing in common with most of them. There are links to other things. Shortened links. Shortened links that when viewed in the raw display no indication of where they might lead.

And?

Well since most people just follow the trending topic, they are getting random links from completely untrusted sources. Remember how you're not supposed to click on random untrusted links in e-mail? This is the same sort of thing, only I suspect people don't quite think about it since it's not e-mail, it must be safe, right? RIGHT?

So if I'm a bad guy, I just put a link to my site featuring the latest drive-by JavaScript attack on it into a Tweet with the most popular tag in trending topics. I will instantly have thousands of eyeballs looking at that URL and maybe clicking on it. No real work involved, no real need to even go through the trouble of injecting my naughty jscript into a legit site.

That was enough to keep me from clicking on anything I saw when I was following along with today's events. Sure, I use a cool (and free, remember where you are, after all) little Firefox Plugin called PowerTwitter that will go check the shortened link and translate that to the tile of the page. That's somewhat helpful, but really, how hard is it to simply put a legitmate looking title on your malware site?

Unfortuately, I don't really have anything resembeling a useful reccommendation besides use an aftermarket Twitter client or plugin that enumerates shortened links along with a little bit of healthy paranoia (try to go the the site independant of the Twittered link). So if anyone else out there actually stumbles upon my humble little musings and has suggestions or tips, I'd love to hear them.

Wednesday, May 27, 2009

How To: Connect a DroboPro to a VMWare ESX host via iSCSI

Originally I was going to publish an article talking about my trials and tribulations (and really rudimentary performance info) around testing a DroboPro in my work VMWare infrastructure. Well, I found myself burning a bunch of time figuring out how to just get VMWare to see the Drobo. I figured the steps were worthy of mention as there's a couple of things on the VMWare side I missed that caused issues. I opened a ticket to Drobo, but have yet heard back from them on the matter yet, so I don't know if they have it documented or not. I also didn't see anything Drobo specific on the interwebs, so I thought maybe there's others out there who would be able to benefit from my misery.

Also an apology, being as this relates to a Drobo Pro and VMWare ESX, this clearly has no business on a blog about free stuff. However, for a small business, this could potentially allow for the use of big boy technology at a fraction of the cost of enterpise class gear. (My DroboPro as configured is about 10% the cost of a similarly sized EMC unit).

Now onto the details. This article assumes you have an ESX server licensed to use iSCSI, an available NIC port, and of course a DroboPro with some drives in it.

After a little bit of reasearch and experimenting, I have successfully gotten an ESX host to talk to the DroboPro. Below are the basic steps required.

  1. Attach the Pro to a Windows or Mac desktop via USB or Firewire. Install the Drobo Dashboard per the included documentation
  2. Configure the volumes on the unit to not exceed 2TB (the limit for VMWare) using the wizard.
  3. Once attached and configured, go into the advanced settings in the drobo dashboard to configure a static IP address for iSCSI
  4. Reboot the unit and test ethernet connectivity
  5. Connect the unit to a dedicated NIC port on the ESX host either direct cable or via a switch (reccommend jumbo frames and flow control if using a switch)
  6. On the ESX host, create a new network segment for the DroboPro. Under the networking tab, click add networking, select VMKernel, click next. Select the appropriate NIC, and follow the rest of the steps to add an IP address on the same segment as the Drobo. Save the changes
  7. (This is the step that got me, as it's not obvious.) Click the newly created network and select properties. Click Add and add Service Console. Assign the Service Console a unique IP in the same subnet as the drobo and VMkernel settings. Edit the original VMkernel network to allow VMotion. Save the changes.
  8. If you are running a version of ESX prior to 3.5 you will need to add a firewall exception under security for outbound traffic for the iSCSI client. This is done for you in 3.5 and newer.
  9. Under configuration for the ESX host, select Storage adapters. Click on the iSCSI adapter then click properties in the detail window below.
  10. In the general tab of the pop up window, click configure and then check enable to turn on iSCSI. The name is not important.
  11. Under the dynamic discovery tab, click Add and enter the IP information for the drobo unit. Click OK and close the wizard. A dialogue will come up asking to rescan all storage, click no.
  12. Right click the iSCSI adapter in the adapter list and click rescan. Wait patiently this could take several minutes
  13. If all went well you should now see the number of targets change to 1. This indicates the host is successfully talking to the Drobo.
  14. In the hardware section of the configuration pane, select storage. Click Add storage. The available volumes on the Drobo should appear in the window. Select one of the LUNS and follow the wizard to configure as desired.

Wednesday, May 20, 2009

A call to Mac users: stop with the malware huberis already!

Ok, first of all I am currently a Mac user and have been off and on for years. I say this as a friend, not some sort of anti-mac PC geek: Stop being so damned smug. I am talking about the stance on the lack of malware. This stance is pretty much echoed by everyone on the pro-Mac side of the fence from users all the way to Apple itself (just watch a random I'm a Mac, I'm a PC ad).

I was listening to the latest installment of Macbreak Weekly, and a couple of panelists were extolling the virtue of the malware free paradise that is OS X. Well here's the deal folks. This sort of thing is absolutely a dangerous attitude. How many Mac users use any sort of anti-virus at all? Pretty few. To that point, there actually ARE very few AV programs to begin with. Edit, there is the open source (and keeping to my roots, free)ClamXav.

Sure, the Mac OS is actually reasonably secure out of the box (we'll ignore the fact that the firewall is OFF by default) but some of the other protections work very well and are what Windows Vista wanted to be *cough* UAC *cough*

What we have here is the calm before the storm or so to speak. These days, malware, botnets viruses (virii?) are all about dollars and sense. Gone are the days of the pimply faced kid writing a little code to erase hard drives. The bad guys are writing stuff to make money by stealing personal data, sending spam, DDOS blackmail, you name it. Since this is a business, it's simply much more profitable to target the PC world.

Therefore, many Mac users sit around sneering at the PC world because the Mac folk live some sort of mythical land of rainbows and unicorn tears that no virus dare enter. I'm pretty sure the people in Pompeii kinda thought the same thing about volcanoes too.

That will always be the case, a target rich environment will always get the attention, but think about the Mac side of things for a while. There's a 10% or so slice of the market that's almost completely unprotected. Once somebody really takes advantage of this situation (and I do mean when, not if) it will be an unmitigated crisis.

Think I'm being a little bit alarmist? You might have missed this, but there's a currently exploitable (as in drive by scripting) vulnerability in the Java implementation of OS X. Despite 10.5.7 being put out mere days ago, this vulnerability has not been patched even though it's been known for at least six months. For more, visit this site which even features a proof of concept that will execute arbitrary (but harmless) code on your very own magic, walled unicorn powered Garden of Eden.

So my Mac friends, enjoy your beautifuly designed hardware, (mostly) reliable OS and fantastic UI. But please, please, stop thinking it's a freakin' suit of armor and go install some sort of anti-malware. Tin foil hat optional.