Saturday, January 21, 2012

Very cool: Overlaying video on encrypted HDMI connections

Overlaying video on encrypted HDMI connections

(from Hackaday.com)


[bunnie] is up to his old tricks again. He successfully implemented a man-in-the-middle attack on HDCP-secured connections to overlay video in any HDMI video stream. There’s a bonus, too: his hack doesn’t use the HDCP master-key. It doesn’t violate the DMCA at all.


HDCP is the awful encryption scheme that goes into HDMI-compatable devices. Before HDCP, injecting video overlays or even chroma keying was a valid interpretation of fair use. [bunnie] thinks that HDMI devices should have the same restrictions analog devices have, so he decided to funnel his own video into his TV.


The build uses the NeTV, a handy and cheap FPGA board with an HDMI input and output. [bunnie] got the FPGA to snoop the HDMI bus and decide if a pixel needs to be changed or not. This isn’t much different from what researchers in Germany did a few months ago, but unlike the academic security researchers, [bunnie] gives you a shopping list of what to buy.


As an example of his work, [bunnie] implemented something like a ‘tweet ticker’ on HDCP-encrypted video. There’s very little the NeTV setup can’t do from chroma keying, filters, or simply dumping the HDMI stream to a hard disk. Check out the slides from [bunnie]‘s talk to get better idea of what he did.


[PAPPP] found a video of the talk in question. Check that out after the break.





Filed under: video hacks

Saturday, December 3, 2011

Vostro 220 Series CAN handle 8GB of RAM

Contrary to Dell's website, the Vostro 220 DOES support 8GB of RAM with the latest BIOS upgrade.

My wife's Dell Vostro 220 is now running Windows 7 x64 and has 8 GB of RAM. I upgraded her BIOS to 1.3.0 before swapping the memory (I read somewhere that the updated BIOS supports the full 8GB).


On a related note, you can actually get the service tag out of your Dell computer in Windows by issuing the following command.


Following WMIC command will give make and model number along with service tag (service tag is IdentifyingNumber here:

C:\>wmic csproduct get vendor,name,identifyingnumber
IdentifyingNumber    Name                Vendor
ABCDEF1              PowerEdge 2950      Dell Inc.
 
In Linux:
 
[remote-host]# dmidecode -s system-serial-number
ABCDEF1
 
HT: http://www.thegeekstuff.com/2008/10/view-dell-service-tag-and-express-service-code-from-linux-and-windows/ 

Saturday, November 19, 2011

Treacle Pudding

Fresh & Easy is a subsidiary of Tesco, the world's third-largest retailer. As Tesco is from the UK, they carry things that Americans do not normally experience. Having heard about treacle about a decade ago when listening to the Lords of Acid - Voodoo U album, last week I decided I would try Treacle Pudding.



It comes in a can.

Open the top of the can, run a knife around the inside, and then open the bottom of the can in order to express the cake thing out onto a microwavable platter.


It is imbued with "golden syrup." This photo does not do it justice. Mine had a gelatinous ring of treacle enshrouding the rounded edge of the top of the cake.

It tastes British.

My wife liked it, although it tasted "canned" to her.

Saturday, October 22, 2011

Adware/spyware infested computer, Baitisj style

The following article will probably frighten many of you, but hopefully this is helpful to folks who have gone through this kind of frustration.

A friend of mine had infested computer. Her Windows XP computer had slowed to a crawl, and I offered to help take a look. Process Explorer showed me some very suspicious process names. Poking around, I found a directory named "C:\Program Files\Invisible Keylogger."


The first thing I did was to install wonderful extension called "Folder Size for Windows"
I noticed that her hard drive had very little free space, and I wanted to figure out where all the space had gone.

Using Folder SIze for Windows, I discovered a HUGE temporary internet files directory
(C:\Documents and Setting\Owner\Local Settings\Temporary Internet Files)

I deleted all files out of this folder, but Folder Size was still showing that there was 22 GB of data inside. Even with hiding system files disabled, looking inside of this folder showed nothing in Windows. Creepy.

I Did some online research, and noticed that previous versions of Windows XP use a file named "content.ie5" for cached data. Interesting.

I ran cmd and cd'd into the Temporary Internet Files directory. After I "cd content.ie5" and executed dir to list the files in the directory. Nine directories with cryptic file names like
3CNW8S1M were finally exposed.

I typed "explorer 3CNW8S1M", and found a LOT of files inside of these hidden directories.

A couple of takeaways:
  • Windows XP hides files inside of the Temporary Internet Files directory, even if the Explorer shell is configured to show system files and folders. cmd or Cygwin are your friends.

  • A password manager that saves your usernames and passwords to various websites protects you from screenshot and keylogger attacks. I really suggest setting up a password manager with a password that is sufficiently different from the password patterns that you use to log into Internet websites or whatnot.

Tuesday, September 27, 2011

OpenIndiana 151a home server high disk load tuning

A week ago, I added a 30GB ZFS l2arc cache device to my storage array, resulting in tremendous system performance improvements. On a whim, I enabled the "Tracker" file indexer. Sadly, Tracker brought my system to its knees; my web browser became useless, and GNOME would shade out windows, indicating that they had become non-responsive.

I executed iostat -xcnCXTdz 5 and looked at the "%w" column, which indicates the percent time that there are disk transactions waiting for service. My %w column was pegged at 100% for one of my devices, indicating that the disk queue was bogged down with requests.

I did a little research, and I bumped across Princeton's Solaris troubleshooting guide for disk IO. The troubleshooting guide indicates that the sd_max_throttle parameter determines how many jobs can be queued up on a single host bus adapter, and is set to 256 by default.

I added set sd:sd_max_throttle=8 to /etc/system and rebooted. Not only did my system responsiveness improve, but zpool iostat showed an increase in throughput to my disk pools. My %w decreased to ~95% under heavy disk load.

I still notice times when %w==100 under heavy load. At these times, the system becomes unresponsive, and zpool iostat shows a drop in disk throughput. However, the system recovers quickly from these intermittent peaks.

I may further decrease sd_max_throttle and see how that affects system performance.

My system contains a mirrored array of three 1TB 4200RPM Western Digital "Green" hard disk drives and one WD Caviar 750MB drive. I'm using an AMD 760G mainboard with six on-board SATA ports; the SATA controller VID/PID is 1002/4391.

Friday, July 8, 2011

How to avoid theft of personal belongings at airports

Nelson Santiago-Serrano stole $50,000 worth of electronics from airline travelers. If you travel with something valuable on a flight (confidential data? laptop computer hard drive?), print out a copy of the TSA's page that details how to fly with firearms, and follow the instructions below, courtesy of a helpful Slashdotter.

 How to avoid the TSA thieves (Score:5, Interesting)

by kwiqsilver (585008) on Friday July 08, @07:59PM (#36701226)
If you must fly, here's what to do:
  • Buy a hard plastic or metal suitcase with locks.
  • Buy a pistol, if you don't have one already. (A starter pistol, which has no legal restrictions on ownership or purchase in any state, works just as well).
  • Put your pistol in the suitcase, check-in at the counter, and tell the airline rep you have a firearm to declare.
  • Fill out the card that says your firearm is unloaded, put it in your suitcase, and lock it (with real locks, not TSA-approved ones), while the airline rep watches.
  • Walk down to the TSA screener with the airline rep, and hand your bag over.
  • The TSA screener will scan your bag while you wait. If there's a need to open it, the screener will have you open it, and will look through the bag while you watch.
It is illegal for them to open your bag without you being present, if you have a firearm declared. (I guess the government doesn't trust the TSA near guns...if only they'd expand that mistrust to all the federal alphabet soup criminals).

I discovered this accidentally, because I usually take at least one pistol whenever I fly anywhere, and have been using it ever since. If I'm going some place anti-gun, like Chicago or CA, I take a firearm component, like a barrel, which still has to be checked the same way, but can't get me into trouble on the trip.

Thursday, June 23, 2011

Banking in America: Do immoral / illegal things, get bailed out by taxpayers!

Occasionally, I find gems when browsing through comments on Slashdot. Tonight, I was reading about Mexican cartels building tanks, and wanted to know more about the situation that concerns our nearest neighbors to the south. The comment that I found concerning Wachovia is sickening; everyone who does banking in the United States should read this article published in April by the Guardian.

Wouldn't it be nice if the US Justice Department brought... justice?

I've re-posted the comment from Slashdot below:

Thank you Wachovia (Score:5, Informative)

by Wonko the Sane (25252) * on Saturday June 11, @08:54AM (#36410330) Journal
This was all made possible because Wachovia laundered a sum of money equal to 1/3 of Mexico's GDP for the drug cartels [guardian.co.uk].
Of course as soon as this was discovered the Justice Department sprang into action and initiated a RICO takedown of the entire institution and all its executives (in an alternate universe). What they actually did was politely request that the company pay a fine equal to 2% of their profits which was then refunded to them by the Treasury Department via a $54 billion bailout.
It makes sense because laws don't apply to the aristocracy like they apply to us peasants - they're doing God's work [businessinsider.com] after all.