Archive for November, 2007

Watch out, don’t kick the plug, we’re going for a personal record here.

prince.org’s uptime as of this morning: 464 days, 21:54. This is with serving millions of pageviews (and tens of thousands of emails) each month, and some ins running out of disk space at least 3 times in that period, and significant upgrades of the SSL libs, webserver, etc. Pretty impressive uptime, I think.

(btw, the mysql database hasn’t had nearly as much uptime as I’ve tweaked it lately… but still, based on the averages, I suspect it’s done over half a billion queries in this time period.)

Not bad for a creaky old RedHat version mumble-mumble server! (Let’s just say “very old”… I don’t need even more people trying old exploits against my box :) )

Lots of proxy probing going on: CONNECT verb attacks

prince.org has been getting a ton of proxy-probing attacks lately… I see in the logs TONS of “CONNECT :25″ requests, ie trying to ping a remote SMTP server through prince.org as a web proxy. Now, mind you, prince.org doesn’t have a proxy enabled… so… you figure it out. Script kiddies, go away. Too bad it’s coming from a rather large number of IPs, or I’d just blacklist them. At least some are resolving back to Taiwan. Annoying…

Ah, there IS a way (after much futzing) to block CONNECTs explicitly. Done!

VMWare Fusion networking gotcha (don’t try to be too smart)

I got a new MacBook, and bought VMWare Fusion, so I could… well, I’m not exactly sure what I planned to do with it, but since I have no other machine in my house that runs Windows, I guess I thought I’d use it for that occasional windows app (PowerISO for example) or to test prince.org through the eyes of IE7. Well, I installed XP into it and that was just dandy, it really knows exactly how to handle hosting Windows, great vmware tools integration, the whole shebang, flawless.

More interestingly, I thought I’d install an Ubuntu instance, and maybe retire the big honking RAID5 Ubuntu server machine, and save the corresponding energy usage, etc. I mostly use it for mysql slave backups of prince.org, and some minor code development (it used to also host my music and photo libraries on the raid disks, but I’ve since moved that to an external drive on the MacBook with TimeMachine on a different device, providing the redundancy.)

Sounds well and good, and vmware also “understands” Ubuntu, but uh, not nearly as smoothly as Windows… the whole vmware tools setup is, while not painful, certainly not “one-click”. But, it works. Well, I thought it did–my networking was hosed. I futzed with it a bit thinking it was their special vmxnet drivers/devices, and then realized my host OSes networking was not working, either. Since I connect via 802.11n, and it’s sometimes flaky (hard to know if it’s Leopard or the wonky apple gigabit router), I turned airport off and then back on and it came back in the host… but Ubuntu was still not happy. If I reboot Ubuntu, it takes out the host networking again… hmmm. Try swithing to bridged mode instead of shared… same thing. Hmmmmmm…. a head-scratcher.

Finally, I hit upon the root cause… I bet the router isn’t happy with my “lock this IP to this specific MAC address”, when there are 2 OSes both sending packets, on that MAC! Yep, that was it. I removed the settings in the Airport itself that caused it to always hand out a specific IP via DHCP to a specific MAC, and assigned IPs manually to the MacBook and Ubuntu, and all was well. Yay. I’m still not sure what magic was going on to make networking in Windows work, but no worries.

I actually wonder if I were to use the “DHCP client ID” instead of the MAC address, if it’d work that way… I just don’t know where to set that in Ubuntu… something to try another day!

I’m not dead, I’m just swamped

Hey everybody, sorry for no posts lately. I’m not dead. Here’s the bullet-point version of what I’ve been up to the last 3 months, in chronological order:

  • Visited Detroit with my 3 year old for my grandpa’s 90th birthday
  • Changed jobs
  • Moved from a rental townhouse to a rental house, 20 miles away
  • Bought a new car
  • My wife had a baby girl
  • Got 100 boxes of junk from storage 2,000 miles away dropped off at my door
  • Got Prince’s lawyers to threaten to sue me (and sic French criminal law on me, too)

So, my hands have been pretty full. I’ve got stuff to write about, just no time to do it in. Will try and post some pix or something soon, though…