I've been having a problem with my Windows XP Pro desktop system using my bluetooth dongle. Apparently, I'm not the only one. It seems that XP SP2 does not release the COM port when the dongle is removed from the system. This means that if you remove the dongle (for use on a laptop, for instance), that WXP thinks the port is still in use. This means that when you plug the dongle back in, the COM port is incremented, and the application has to be reconfigured.
The problem has manifested itself when using my Palm Hotsync via bluetooth. Every time I disconnect the dongle, the Palm Desktop software has to be reconfigured to use the new COM port. I finally found a fix, but it is a nasty hack. As if there is any other kind on WXP!
Launch System Properties, click the Hardware tab, click Device Manager. Expand Ports and double click Bluetooth link. This item will be labeled with the current port number. Select the Port Settings tab and click Advanced.
At the bottom of the window is the current port number listed in a pull down menu. Turn out, it would let you run it up to COM256! Move up the list to COM3, which will display as in use. (On your system it may be something other than COM3... Adjust appropriately.) Select the in use port, click OK. Return to Advanced, and move through the list for each of the bogus ports, clicking OK after each.
Once all the ports have been freed, select the correct port (COM3 on my system). Before leaving the Bluetooth link, try upping the connect speed-- mine was set to 9600! Click OK, exit Device Manager and System Properties.
Go to Bluetooth Devices and check the COM Ports tab. I should be back to the correct value. Reconfigure the application, and try to connect.
Tuesday, June 27, 2006
Howto Hack SprintPCS / Palm (pt4)
In case any of my loyal readers forgot where we left off with this project (not likely as I think there are two of you), we were able to get the Palm Tungsten E2 communicating with SprinPCS via a bluetooth enabled Samsung MM-A940. The problem was the $39.99 per month fee for the service. It would be hardly worth it, but for the fact that this also gave PC access. Unfortunately, it would not work under RHEL4.
So, I cancelled the service. This means no data for Mr. Palm. But wait! I did say I had one trick up my sleeve. Check out these links:
Tapland :: Zodiac (PalmOS) and Samsung a920 - How do I connect these?
and
PCS Intel :: Samsung Sprint
Happy, happy, joy, joy.
So, I cancelled the service. This means no data for Mr. Palm. But wait! I did say I had one trick up my sleeve. Check out these links:
Tapland :: Zodiac (PalmOS) and Samsung a920 - How do I connect these?
and
PCS Intel :: Samsung Sprint
Happy, happy, joy, joy.
Saturday, June 24, 2006
Alternative Keyboard Gallery
I came across Tim Griffin's Alternate Keyboard Gallery displaying some very interesting keyboard designs. This is particularly interesting to me, as I use and ergo-split keyboard on my WXP system. Since I now have a dedicated Linux system, I really need another, but the retail stores no longer carry them.
* His site was running a little slow, so I had to hit the refresh button a couple times to get the pictures loaded.
* His site was running a little slow, so I had to hit the refresh button a couple times to get the pictures loaded.
Wednesday, June 21, 2006
How Few Remain
My wife is fond of dragging me to "thrift stores" to go shopping. Luckily, her favorite has a large book and record section, so I can usually stand about thirty minutes in the place. A few weeks ago, I found a book called How Few Remain, by Harry Turtledove, about the second war between the Confederate States of America and the Union.
Now, I know what you're thinking: "There was only one war between the states, and the Confederates lost." Turtledove, however, is known as the master of alternate histories, and this was the second volume about a history where the Confederates won. In another series of books, the US in engaged in World War II, when an alien species decides to invade Earth. Given the situation, Roosevelt and Hitler sign a treaty, and fight the aliens together.
The first of the Civil War series was The Guns of The South. General Lee finds himself at a turning point in the War Between the States. He knows that if he can not pull off a major victory by invading Pennsylvania, then turning on Washington's soft northern flank, than the war is lost and the South is doomed. That's when a man with foreign accent
presents the Confederate Army with the gift of a newly invented rifle. He explains that he, and his associates, have a factory where they can produce the new weapon and ammunition. They call the rifle the AK-47.
In reality, the foreigners are South Africans who are using a time machine the transport weapons from the future, in an effort to keep slavery alive. The Confederates do win the war, but Lee and Nathan Bedford Forest turn on the South Africans when they realize what is happening. Lee follows Jefferson Davis as President of the Confederacy, and emancipates the slaves in order to secure the support of the Europeans.
Time machines, people from the future, advanced weapons out of place on the battlefield... Hey, it's a science fiction book!
Advance twenty years. It's now about 1887, and the USA and CSA are coexisting at best. Tensions are high, and war in rumbling on the horizon. Unfortunately, there are no AK-47s on the battlefield-- instead, everyone has Winchesters and Springfields. And the CSA still has slaves. General Lee is not even mentioned. No time machines.
Hey! This isn't a sequel: its a completely new book based upon the premise that the Confederates just won the Civil War on their own. Well, that's a pretty big leap of faith. In reality, the Confederates didn't actually expect to win the war. For the most part this a book of speculative politic fiction.
The only interesting part so far is that the first US victory was under the command of Custer. He turned the tide of battle by baiting cavalry into an ambush, and chopping them down with his Gatling Guns. Of course Custer was actually killed at Little Big Horn by being ambushed by attacking cavalry... because he wouldn't take his Gatling Guns in the field.
Hopefully, Turtledove has more tricks than irony up his sleeve.
Now, I know what you're thinking: "There was only one war between the states, and the Confederates lost." Turtledove, however, is known as the master of alternate histories, and this was the second volume about a history where the Confederates won. In another series of books, the US in engaged in World War II, when an alien species decides to invade Earth. Given the situation, Roosevelt and Hitler sign a treaty, and fight the aliens together.
The first of the Civil War series was The Guns of The South. General Lee finds himself at a turning point in the War Between the States. He knows that if he can not pull off a major victory by invading Pennsylvania, then turning on Washington's soft northern flank, than the war is lost and the South is doomed. That's when a man with foreign accent
presents the Confederate Army with the gift of a newly invented rifle. He explains that he, and his associates, have a factory where they can produce the new weapon and ammunition. They call the rifle the AK-47.
In reality, the foreigners are South Africans who are using a time machine the transport weapons from the future, in an effort to keep slavery alive. The Confederates do win the war, but Lee and Nathan Bedford Forest turn on the South Africans when they realize what is happening. Lee follows Jefferson Davis as President of the Confederacy, and emancipates the slaves in order to secure the support of the Europeans.
Time machines, people from the future, advanced weapons out of place on the battlefield... Hey, it's a science fiction book!
Advance twenty years. It's now about 1887, and the USA and CSA are coexisting at best. Tensions are high, and war in rumbling on the horizon. Unfortunately, there are no AK-47s on the battlefield-- instead, everyone has Winchesters and Springfields. And the CSA still has slaves. General Lee is not even mentioned. No time machines.
Hey! This isn't a sequel: its a completely new book based upon the premise that the Confederates just won the Civil War on their own. Well, that's a pretty big leap of faith. In reality, the Confederates didn't actually expect to win the war. For the most part this a book of speculative politic fiction.
The only interesting part so far is that the first US victory was under the command of Custer. He turned the tide of battle by baiting cavalry into an ambush, and chopping them down with his Gatling Guns. Of course Custer was actually killed at Little Big Horn by being ambushed by attacking cavalry... because he wouldn't take his Gatling Guns in the field.
Hopefully, Turtledove has more tricks than irony up his sleeve.
Friday, June 09, 2006
SELinux: MLS Under Fedora Core 5
Hearing that Multi Level Security was available in FC5, I decided to load it on a system and take a look. The original concept of MLS was to allow military and government systems to tag files as Classified, Secret, Top Secret, or Unclassified. In its current incarnation, the military labels are replaced with arbitrary codes which can be aliased to names. This means you could put a document on a server that could only be read by people with "Marketing" clearance, whether they are in the Marketing group or not.
Here's what we have to do:
1. Install a Fedora Core 5 system with SELinux active, running the targeted policy.
2. Load the selinux-policy-mls RPM.
3. Change the default policy from targeted to mls.
4. Reboot the system to allow it to add a default security level label to every file.
Unfortunately, this resulted in a kernel panic. The kernel would die at boot time, because it was expecting to find an extra security context element, which wasn't there. (SELinux uses a three part security context to flag each file. MLS gives and additional flag, which must be added.) Of course, it was suppose to boot to a relabel mode, and take care of that for us. No luck.
Rebooted the system, interrupted GRUB, and appended selinux=0 to the kernel options. Logged in as root, and issued the command fixfiles restore. It took the system about 15 minutes to relable the files with the new information. (This isn't the best way of doing this, but it was the only choice since the auto-relabel failed.)
Rebooted the system, and was offered a login prompt. Logged in as root, only to find-- I didn't have security clearance to access /bin/bash. Oops.
Rebooted the system, interrupted GRUB, and appended enforcing=0 to the kernel options. Logged in as root... and I'm in! The SELinux security system is running in the Permissive mode, however. Now I've got to get the correct clearance.
Just for fun, I switched back to the Enforcing mode. I logged into the system as an unprivileged user, and everything worked. Ha! Maybe it is not broken after all... Maybe I'm just not allowed to login as root, which (actually), is a good thing.
You see: root is living, breathing, security violation. If I have a user on my "traditional" linux system that has codename clearance for the MAJESTIC project, and I access his home directory, I could snatch documents that I am not authorized to see. Under MLS, root can not even cd into an unprivileged user's home directory. As a matter of fact, now that I've switched back to Enforcing, I can't even cd into /root!
Turns out, the problem wasn't the clearance needed to run Bash, but the clearance to access root's home. When root logs in, he has the staff_r role. To access /root, he needs the sysadm_r role. To make matters even more interesting, I wanted to return to the Permissive mode to test my theory. I issued setenforce 0 only to be greeted by a happy little message:
Now I'm stuck. The only way out is to reboot... Or accept the march of progress. Root is no longer God. He has gone the way of Quetzalcoatl. Maybe he was a false god all along. Kinda like the Go'ald.
The next trick is to figure out how to use MLS to create my own codewords.
Here's what we have to do:
1. Install a Fedora Core 5 system with SELinux active, running the targeted policy.
2. Load the selinux-policy-mls RPM.
3. Change the default policy from targeted to mls.
4. Reboot the system to allow it to add a default security level label to every file.
Unfortunately, this resulted in a kernel panic. The kernel would die at boot time, because it was expecting to find an extra security context element, which wasn't there. (SELinux uses a three part security context to flag each file. MLS gives and additional flag, which must be added.) Of course, it was suppose to boot to a relabel mode, and take care of that for us. No luck.
Rebooted the system, interrupted GRUB, and appended selinux=0 to the kernel options. Logged in as root, and issued the command fixfiles restore. It took the system about 15 minutes to relable the files with the new information. (This isn't the best way of doing this, but it was the only choice since the auto-relabel failed.)
Rebooted the system, and was offered a login prompt. Logged in as root, only to find-- I didn't have security clearance to access /bin/bash. Oops.
Rebooted the system, interrupted GRUB, and appended enforcing=0 to the kernel options. Logged in as root... and I'm in! The SELinux security system is running in the Permissive mode, however. Now I've got to get the correct clearance.
Just for fun, I switched back to the Enforcing mode. I logged into the system as an unprivileged user, and everything worked. Ha! Maybe it is not broken after all... Maybe I'm just not allowed to login as root, which (actually), is a good thing.
You see: root is living, breathing, security violation. If I have a user on my "traditional" linux system that has codename clearance for the MAJESTIC project, and I access his home directory, I could snatch documents that I am not authorized to see. Under MLS, root can not even cd into an unprivileged user's home directory. As a matter of fact, now that I've switched back to Enforcing, I can't even cd into /root!
Turns out, the problem wasn't the clearance needed to run Bash, but the clearance to access root's home. When root logs in, he has the staff_r role. To access /root, he needs the sysadm_r role. To make matters even more interesting, I wanted to return to the Permissive mode to test my theory. I issued setenforce 0 only to be greeted by a happy little message:
Permission denied
Now I'm stuck. The only way out is to reboot... Or accept the march of progress. Root is no longer God. He has gone the way of Quetzalcoatl. Maybe he was a false god all along. Kinda like the Go'ald.
The next trick is to figure out how to use MLS to create my own codewords.
Thursday, June 08, 2006
RHEL4 Network Access via Bluetooth Cell Phone
I worked several hours on using my Bluetooth enabled cell phone as a modem for roaming internet access. Alas, it was not to be. I was able to successfully get my Palm to connect, but could not get the laptop to work.
The problem was RHEL4's inability to respond to a PIN request from the phone. Under Fedora, there is a PIN Helper Daemon to handle pairing. It is not included with RHEL.
Oh, well. Maybe I'll try again in RHEL 5.
The problem was RHEL4's inability to respond to a PIN request from the phone. Under Fedora, there is a PIN Helper Daemon to handle pairing. It is not included with RHEL.
Oh, well. Maybe I'll try again in RHEL 5.
Tuesday, May 30, 2006
Palm Video
I'm having trouble nailing down which video formats are supported by the native video viewer. One important issue I've discovered so far: the movie dimensions are limited to the screen resolution of 320x320. Given that most videos are shot in the 5x4 aspect ratio (as opposed to HDTV's 16x9) this means that we need to pay special attention to the width versus height. Furthermore, there is not an option to scale the image, say to double size, as as you might expect to do with a video sized at 160x112. Oddly, it will scale JPG images.
Some websites are reporting that the TE will display several different file formats, but the only one that has worked thus far is MPG. Notable failures include AVI, RM, and MOV. Some MPGs also will not display, presumedly due to an incorrect codec. Unfortunately, failures are always reported with the same generic error message.
Ideally, we should be able to pull programs off a DVR, like MythTV, drop them on the SD ram card, and use the Palm as a portable video player. As with many of the other features of our present consumer devices, it seems that it is not meant to be. A quick look at the an hour long episode of Star Trek seems to indicate an AVI size of 105MB, captured at 320x240, using a Divx Codec. Another episode, captured in MPEG, took 445MB. Given the cost of the media, initial indications do not look promising.
Some websites are reporting that the TE will display several different file formats, but the only one that has worked thus far is MPG. Notable failures include AVI, RM, and MOV. Some MPGs also will not display, presumedly due to an incorrect codec. Unfortunately, failures are always reported with the same generic error message.
Ideally, we should be able to pull programs off a DVR, like MythTV, drop them on the SD ram card, and use the Palm as a portable video player. As with many of the other features of our present consumer devices, it seems that it is not meant to be. A quick look at the an hour long episode of Star Trek seems to indicate an AVI size of 105MB, captured at 320x240, using a Divx Codec. Another episode, captured in MPEG, took 445MB. Given the cost of the media, initial indications do not look promising.
Monday, May 29, 2006
Palm Bluetooth Cache Editor
In working with my New Palm Tungsten E2's bluetooth system, I noticed another anomalous behavior. I had bought a USB Bluetooth dongle (plug-in adapter), and had been using it for wireless hotsync to my XP desktop. I also, however, wanted to use it the connect to my Red Hat laptop. Unfortunately, the Palm would always discover it as the XP hostname.
Turns out, the Palm has a cache were it logs the dongle's MAC and the system's hostname. It assumes that any time it sees the dongle, the same system is behind it. There was no obvious way to clear the cache. Luckily, a game developer called 3Division created a Palm Bluetooth Cache Editor (BTcahcED) to solve the problem.
Turns out, the Palm has a cache were it logs the dongle's MAC and the system's hostname. It assumes that any time it sees the dongle, the same system is behind it. There was no obvious way to clear the cache. Luckily, a game developer called 3Division created a Palm Bluetooth Cache Editor (BTcahcED) to solve the problem.
Thursday, May 25, 2006
Lost, But Not Forgotten
Last night's episode of Lost created quite a few new questions to ponder. Are John, Eko, and Desmond dead? Surely not-- they wouldn't kill off any of the characters. Are Micheal and Walt really headed for rescue? That boat is not an ocean going vessel. Will we hear from Jack, Kate, and Sawyer next season? Once someone is captured, we typically don't see the story through their eyes anymore.
(Sawyer may be the exception: We learned about the Tailies from either Sawyer, Micheal, or Jin's point of view. It couldn't be Micheal, since he was gone two weeks, without a clue as to what was happening to him. It probably wasn't Jin, because we've heard the story through his ears, and it sounded like gibberish.)
Here's what we need to think about:
* Desmond asked John when the plane crashed on the island. "Sixty three days ago," was his response. "No, what was the date of the crash?" insisted Desmond. "September 22nd," offered John. Desmond's printout indicated the date of the system failure to be 09222004-- the date of the crash. By pressing the button too late, did Desmond cause the crash? It's not important. What is important is that the year is 2004. The show is happening in the past. Furthermore, the last night's episode happened on the day before Thanksgiving.
* We would not have seen the foot of the giant statue if it wasn't important. Sayid would not have made his comment about the foot having only four toes if it wasn't important.
* The pier where the Henry did the prisoner exchange with Micheal was not that of a rag-tag group of castaways. It was sturdy, and long. Much larger than that little tug needed. And why would Henry give away their only boat?
* Why didn't Kelvin explain to Desmond why they didn't build an automated system to press the button? Ah... I got you on this one. It turns out there is a precedent for such a system. It's called failsafe: When you send the bombers to attack, they don't wait for the Go order, they wait for the Recall order. If no recall order, they drop the bomb. This is the thing about the button. Give the code, or the bomb goes off. If the Others kill you, the bomb goes off. If you die from the plague, the bomb goes off. John breaks the computer, the bomb goes off.
But the single most important question, is the one you've forgotten about:
What happened to the mecahnical, smoke breathing, dinosaur that killed the pilot?
(Sawyer may be the exception: We learned about the Tailies from either Sawyer, Micheal, or Jin's point of view. It couldn't be Micheal, since he was gone two weeks, without a clue as to what was happening to him. It probably wasn't Jin, because we've heard the story through his ears, and it sounded like gibberish.)
Here's what we need to think about:
* Desmond asked John when the plane crashed on the island. "Sixty three days ago," was his response. "No, what was the date of the crash?" insisted Desmond. "September 22nd," offered John. Desmond's printout indicated the date of the system failure to be 09222004-- the date of the crash. By pressing the button too late, did Desmond cause the crash? It's not important. What is important is that the year is 2004. The show is happening in the past. Furthermore, the last night's episode happened on the day before Thanksgiving.
* We would not have seen the foot of the giant statue if it wasn't important. Sayid would not have made his comment about the foot having only four toes if it wasn't important.
* The pier where the Henry did the prisoner exchange with Micheal was not that of a rag-tag group of castaways. It was sturdy, and long. Much larger than that little tug needed. And why would Henry give away their only boat?
* Why didn't Kelvin explain to Desmond why they didn't build an automated system to press the button? Ah... I got you on this one. It turns out there is a precedent for such a system. It's called failsafe: When you send the bombers to attack, they don't wait for the Go order, they wait for the Recall order. If no recall order, they drop the bomb. This is the thing about the button. Give the code, or the bomb goes off. If the Others kill you, the bomb goes off. If you die from the plague, the bomb goes off. John breaks the computer, the bomb goes off.
But the single most important question, is the one you've forgotten about:
What happened to the mecahnical, smoke breathing, dinosaur that killed the pilot?
Tuesday, May 23, 2006
Howto Hack SprintPCS / Palm (pt3)
The moment of truth: Configure the Palm for network access via a paired SprintPCS phone.
At this point, our Palm has a trusted connection to the phone via Bluetooth, but no way to tell the phone to get it online. We need to establish a Network Service over which we can connect. The fastest way to configure the connection is from the Preferences screen, and selecting Network.
Tap New and change the name from "Untitled" to "SprintPCS" (the name is arbitrary). The username will be the device phone number. The password is the same password used to access the SprintPCS account management website. If you do not know the website password, you can do another human engineering hack: Call Customer Service and tell them you can need to know how to access your phone's e-mail account via your browser. The password will get reset in the process.
It is best to save the password in the device, as the connection will only give you a few seconds to respond to the prompt. Tap the word "Prompt", enter the password in the window, and tap OK. For connection type, select "Edit Connections...".
We will need to couple the Network Service to the Trusted Device. Tap New and select a new name-- perhaps the phone's model number. Change "Connect To" to "Phone" and "Via" to "Bluetooth". Now we will identify our Trusted Device, by selecting Tap to Find. In the new window, select the Trusted Device configured in the previous section. Tap OK to return. The model will remain "Standard GSM".
Next tap Details, and change the speed to 115,200. A tap of OK returns to the Edit Connections screen and another tap of OK will prompt for a confirmation. Tap Yes to make this the default connection. Tapping Done will return to the Network screen. Clicking Connection should now show us the option we just defined. Highlighting the option will select it.
The box labeled "Tap to enter phone" will open a new window. First try the number #777. (Yes, the pound symbol is part of the phone number.) Tap OK to save the number. If #777 does not work, you may need to use #999. To test the settings, tap Connect.
If the connection is properly defined, the phone will open a window indicating "Connected as data modem". The Palm will display a window indicating "Connecting", "Signing On", and lastly "Established". Once the connection has been tested, tap Disconnect. This should return the phone to the service screen.
Now lets test the system in production. Tap the Home Icon and select Web to launch Blazer. Input the URI http://wap.oa.yahoo.com and tap Go. The Palm should connect to the phone, and load the page.
1. The phone will not remain connected. This is correct-- and good, as it will allow incoming calls.
2. IT is normal for the Palm to take up to a minute to establish a connection.
3. When done, it is best to turn Bluetooth off. This prevents an application from trying to bump you off a call, and makes your device more secure.
So... Is it worth $959.76? Probably not.
I do, however, have one more trick up my sleeve. Before we go that route, we need to get a laptop running Red Hat Enterprise Linux on the network. Stay tuned.
At this point, our Palm has a trusted connection to the phone via Bluetooth, but no way to tell the phone to get it online. We need to establish a Network Service over which we can connect. The fastest way to configure the connection is from the Preferences screen, and selecting Network.
Tap New and change the name from "Untitled" to "SprintPCS" (the name is arbitrary). The username will be the device phone number. The password is the same password used to access the SprintPCS account management website. If you do not know the website password, you can do another human engineering hack: Call Customer Service and tell them you can need to know how to access your phone's e-mail account via your browser. The password will get reset in the process.
It is best to save the password in the device, as the connection will only give you a few seconds to respond to the prompt. Tap the word "Prompt", enter the password in the window, and tap OK. For connection type, select "Edit Connections...".
We will need to couple the Network Service to the Trusted Device. Tap New and select a new name-- perhaps the phone's model number. Change "Connect To" to "Phone" and "Via" to "Bluetooth". Now we will identify our Trusted Device, by selecting Tap to Find. In the new window, select the Trusted Device configured in the previous section. Tap OK to return. The model will remain "Standard GSM".
Next tap Details, and change the speed to 115,200. A tap of OK returns to the Edit Connections screen and another tap of OK will prompt for a confirmation. Tap Yes to make this the default connection. Tapping Done will return to the Network screen. Clicking Connection should now show us the option we just defined. Highlighting the option will select it.
The box labeled "Tap to enter phone" will open a new window. First try the number #777. (Yes, the pound symbol is part of the phone number.) Tap OK to save the number. If #777 does not work, you may need to use #999. To test the settings, tap Connect.
If the connection is properly defined, the phone will open a window indicating "Connected as data modem". The Palm will display a window indicating "Connecting", "Signing On", and lastly "Established". Once the connection has been tested, tap Disconnect. This should return the phone to the service screen.
Now lets test the system in production. Tap the Home Icon and select Web to launch Blazer. Input the URI http://wap.oa.yahoo.com and tap Go. The Palm should connect to the phone, and load the page.
Warnings:
1. The phone will not remain connected. This is correct-- and good, as it will allow incoming calls.
2. IT is normal for the Palm to take up to a minute to establish a connection.
3. When done, it is best to turn Bluetooth off. This prevents an application from trying to bump you off a call, and makes your device more secure.
So... Is it worth $959.76? Probably not.
I do, however, have one more trick up my sleeve. Before we go that route, we need to get a laptop running Red Hat Enterprise Linux on the network. Stay tuned.
Subscribe to:
Posts (Atom)
