Artikel - 5.9.2003 - 18.9.2003

Integration of Mailsmith with POPFile

Translation

Who uses POPFile for spam filtering and Mailsmith as a mail client can quickly jump from an email to the reclassification page in POPFile with the linked AppleScript. The script simply extracts the X-POPFile-Link header from the email and navigates to the specified URL. Without this script, you always have to first show the headers, find the link, click on it, and then hide the headers again. Annoying. But solvable with AppleScript. Here's the original article.

Hunting Criminals with Linux

Now that's really something. Hopefully the project organizers have done their homework properly, then such a large project - if it runs successfully - could finally put the brakes on these silly anti-Linux discussions. I also like the reference to the increased comfort that has been achieved with Linux.

At heise online news you can find the original article.

RTL raises the stakes in poker over tour rights

Lucky. If I imagine having to watch the Tour on RTL, I feel sick. What on earth does RTL think they can do better? Their commentators are even worse than the already appallingly bad public broadcasters' commentators. Best to watch the Tour with the sound off anyway, but with RTL the constant commercial breaks would be even more annoying ...

At RADSPORT-NEWS.COM - News Overview you can find the original article.

Nordkirchen Castle

We were there again today. Nice park, and the light was great. So here are the photos without much ado:

44-100-100.jpeg

45-100-100.jpeg

46-100-100.jpeg

47-100-100.jpeg

48-100-100.jpeg

Here's the original article.

wouthit a porbelm huh?

Wired. It works. At least for me.

erstauntes Gesicht

At Industrial Technology & Witchcraft you can find the original article.

All your .com are belong to us :: hebig.org/blog

One aspect of the latest VeriSign nonsense that I stumbled upon through Haiko Hebig is mail delivery for non-existent domains. Here's an analysis of what happens with a non-existent domain:

 muenster:~# exim -bt gb@blubberfaselblubb.com gb@blubberfaselblubb.com deliver to gb@blubberfaselblubb.com router = lookuphost, transport = remote_smtp host blubberfaselblubb.com [64.94.110.11]

So an email is sent normally to the A-record (the one with the wildcard). What happens there? You can see it here:

 telnet blubberfaselblubb.com smtp Trying 64.94.110.11... Connected to sitefinder-idn.verisign.com. Escape character is '^]'. 220 snubby3-wceast Snubby Mail Rejector Daemon v1.3 ready HELO blubberfaselblubb.com 250 OK MAIL FROM: blah@blubberfaselblubb.com 250 OK RCPT TO: blah@blubberfaselblubb.com 550 User domain does not exist. DATA 250 OK quit 221 snubby3-wceast Snubby Mail Rejector Daemon v1.3 closing transmission channel Connection closed by foreign host.

So there's a mail rejector running at that address that rejects every mail delivery with 550 - User domain doesn't exist. Want some paranoia? Sure? OK: it's trivial to modify the mail rejector so that it collects and archives the sender addresses provided at MAIL FROM: of the misdirected emails. I'm not saying VeriSign does that - but wildcard A-records at such a central location are an abuse waiting to happen ...

Here's the original article.

Apple Expo: Radio with Timeshift

Cool!

At heise online news you can find the original article.

CEO Performance Poll

At Forbes, anyone can tell the CEO of VeriSign in a poll whether he's doing his job well or poorly. Oddly enough, he's polling pretty negatively. I wonder why that could be?

Teufelsgrinsen

Here's the original article.

Interview with Udo Bölts

I think it's great the way he's starting it, not letting his career fade out like a Cipollini, but stopping the way he's always been known: as a workhorse among cyclists. And perhaps he'll get one more chance to finish things off at the Rhineland-Palatinate Tour. He'd deserve it.

At RADSPORT-NEWS.COM - Nachrichten-Gesamtübersicht you can find the original article.

OpenSSH 3.7 closes security hole [2nd update]

That's what's great about Debian: the updated patches are already available on http://security.debian.org/, simply:

 apt-get update apt-get install ssh

and the system is up to date again with all patches. That's what I like about it.

Apple has not yet released a software update for OS X ...

At heise online news you can find the original article.

RegTP instead of DENIC? Take action!

Get involved, generate a letter and send it!

At Wortfeld you can find the original article.

Turn Your Radio On

Well - I hope that this isn't implemented the way Jake Savin announced it on the radio-dev mailing list: http://groups.yahoo.com/group/radio-dev/message/7946

The problem: for weblogs that don't yet have comment notification, it's quite easy to hijack the comment notification, even if option 2 from the email is used (option 1 isn't an option anyway because of its immutability).

The scenario is quite straightforward: since the setPrefs function doesn't just send the password (or rather its MD5 hash), but also all the data to query another server for validity, you can simply set up a small XMLRPC server that generally returns "ok, password is correct". You then include this in the setPrefs calls as the server to be queried. And just like that, you can use a loop to steal comment notifications from all numeric users on Userland. A classic case of not thinking things through far enough. It's quite astonishing how few people actually think about security and what it ultimately means. Too often you encounter half-baked solutions. Granted, comment notifications aren't really critical. But the function that's supposed to be protected here is called setPrefs - it's foreseeable that programmers will soon store additional settings there, and how these can then be set externally.

Where exactly is the error here? In communication with the server, that's clear. But the real error lies in the fact that a security-relevant area is implemented using a coupled system, where the coupling of systems is determined by the end user. And that last small part - determined by the end user - is the problem. System couplings in security-relevant areas must be pre-configured by the administrator; users may at best be able to choose from options. Because only the administrator can determine which sources are trustworthy for authorization. At Der Schockwellenreiter there's the original article.

VeriSign Hijacks Traffic

A few more comments and opinions on the VeriSign nonsense.

At heise online news there's the original article.

Clippy for the Web

A few more links to Verisign's wildcard A record. However, the extremely critical monopoly status of Verisign as the operator of a TLD (and the associated registry) is not addressed here. But the peripheral areas are also not without problems - such as the aforementioned issue that users can no longer decide for themselves how they want to respond to such problems.

Apart from the fact that this procedure doesn't help against typosquatters anyway: they can continue to register their typo domains and will of course be preferentially served (a wildcard A record only applies if no explicit A record is available).

At Wortfeld you'll find the original article.

Comments on the New Apple Gadgets

Of course. I bought myself a 12 inch PowerBook and an iPod. Of course, these exact things were just updated in the technical specs and naturally cheaper than I bought them. I should really offer myself as a price barometer: whenever I buy something, it comes out cheaper and more powerful a short time later.

Here you can find the original article.

Kris Delmhorst

Nice music - guitar, voice, not much else. Melodic and pleasant to listen to. Also has audio samples to download (complete songs, not just 30-second clips!).

Here's the original article.

Münsterland Tour of Juniors starting Friday

Ahlen, Borken, Coesfeld and Ibbenbüren. Somehow they interpreted the Münsterland quite freely.

At RADSPORT-NEWS.COM - News Overview you can find the original article.

nickijaine.com

And since we're on the subject of voice and guitar: Nicki Jaine. Wow. You get chills down your spine listening to "Animals" or "A Pigeon named Crow". I think I've featured her here before, but her music is so great that it's worth promoting again. Oh, and here too there are complete audio samples available for download.

Here's the original article.

Post without title

After a long time, I took my digital camera with me again and shot a few pictures of the city library.

41-100-100.jpeg

Here's a picture of the main entrance. Lots of glass, lots of metal, slanted sides and impractical corners. No idea what possessed the architect, apparently it's supposed to be a special feature, but it doesn't suit my taste. But at least it provides a few motifs.

42-100-100.jpeg

And here's the view back from the main entrance. A small passage that runs between the main building and an aimlessly standing side building and is crossed by a kind of bridge.

43-100-100.jpeg

And to match the architecture, the lamps too, which somehow look like they could only illuminate the lower part of the building. Which is actually also true.

If architects want to call me a philistine now, go ahead, I can take it. I still think the building is ugly.

Shared Space 2.0

Looks quite interesting: something like a cross between TinderBox (Outliner/Mindmapper) and Voodoo (version control, unfortunately no longer available in its old form). Could develop into a quite interesting application - if all features are implemented at some point. The original article is here.

VeriSign has entered a wildcard A record on *.net

That's audacious. Every query for a domain under .net is now answered with an A-record from Verisign. From there it gets redirected to a Verisign page containing a search engine and web directory. Great. Probably soon there will also be a request to register a free domain cheaply at Verisign. Verisign can of course, as the operator of .net and .com, enter something like this - but only Verisign can do it. None of the alternative .net or .com registrars can do it. That's free competition on the Internet. At Advogato there's the original article.

When bright light goes up the nose

I knew it, it really is the light that makes me sneeze now and then! Nobody wanted to believe me, apparently everyone in my surroundings doesn't have this problem.

I found the original article on RP-Online: Wissenschaft.

Whole Wheat Radio - Home

And right another one to follow: Internet radio from the independent scene. Nice stuff they play there. And above all, the whole thing is available in really good quality as an MP3 stream, if your connection can handle it. By the way, I found this tip (as well as the one about Kris Delmhorst) at Phil Ringnalda. Here's the original article.

black cat white tom

Came on TV again today - on NDR. Very much worth watching! I should get the DVD for it at some point Here's the original article.

SenderBase

SenderBase is a server that performs evaluations of email traffic based on senders and domains. You can use it to find out which organizations and servers use domains, what belongs to organizations, which servers are mail servers, etc.

Quite an interesting thing, based on log data from (according to their own statements) approximately 9000 companies that receive email.

Here's the original article.

Vuelta: Virenque disqualified

So, he just let himself get dragged along. And everyone had been raving about his comeback, and then something like this ...

At RADSPORT-NEWS.COM - Nachrichten-Gesamtübersicht you can find the original article.

Zülle gives up Vuelta: "Never again a grand tour"

Ouch, that's quite a motivation slump. And this at a time when Phonak is buying up louder-sounding names to compete in the Tour next year.

At RADSPORT-NEWS.COM - News Overview you can find the original article.

Attack on Arafat 'legitimate' option for Israel

So this is what de-escalation policy looks like today - open death threats against the president of a country one refuses to tolerate. The Americans are setting the example and Israel of course sees itself as legitimized to do the same shit. So that the madness never ends.

I found the original article at RP-Online: Politik.

Baroque Mercury

New books from one of my favorite authors? Awesome!

The "Virtual Light - Idoru - Futurematic" cycle by William Gibson, which I read on vacation, was rather disappointing. It's possible that the translation had something to do with it, but somehow the first two books felt quite unfinished—a lot started and hinted at, but nothing really polished. The fact that everything was brought together in Futurematic was some compensation (and I think the third part is also the strongest), but the whole thing couldn't really excite me.

Let's hope Neal Stephenson doesn't fall victim to the cycle sickness known as "running out of breath, producing boring filler material." After all, he's only written standalone novels so far. But Cryptonomicon is such a brilliant thing that it deserves to be expanded.

At Telepolis News you'll find the original article.

eBay discriminates against non-Windows users!

Cool class. Great idea - making image uploads with Active-X controls under Windows and offering no alternative for non-Windows users. Idiotic

At MacGuardians there's the original article.

Lint in the Belly Button

An important question is finally being clarified: where the lint in your belly button comes from.

Here you can find the original article.

Possible Credit Card Fraud

Weird. Something like this was previously just something that happened to others. But today I had an email in my inbox from Amazon saying my credit card had been registered to someone else's account (and the email seemed authentic based on the data and similar details), and the account and orders were canceled due to abuse. It must have been flagged during data comparisons. So I had my credit card blocked right away and tomorrow I get to go through things with the fraud prevention department of my credit card company to see if anything was already purchased with it.

It's a weird feeling, after all these years of problem-free card use, especially on the internet, to finally experience firsthand what all that entails.

Fortunately, I have almost nothing fixed or recurring charged to the credit card, so it's not such a hassle if I get a new number. But if I imagine I still had all those foreign magazine subscriptions, that would be quite annoying.

The whole thing also produces a strange feeling because I only have an email as a point of reference, but no concrete data. Theoretically the email could be fake and this whole mess for nothing (okay, unlikely, because at least the email sender knows parts of my credit card number). It's just a weird feeling about the whole thing...

Hundt wants maximum twelve months of unemployment benefits

When it comes to the Töle, our labor market goes completely to the dogs.

I found the original article at RP-Online: Politik.

Marco's world

From time to time you have to take another look at geourl, there are indeed occasionally new neighbors, even here in the provinces. When exactly is the critical threshold reached where someone voluntarily agrees to build a blogplan for Münster? Here's the original article.

PHOKU | webserver

And yet another neighbor I didn't know about yet. But he or she won't reveal exactly where in Münster they're located. And the light on the webcam isn't working?

Here's the original article.

Shit Job?

Complaints department?

Teufelsgrinsen

At Industrial Technology & Witchcraft you can find the original article.

Star Trek Dimension - Investigating Trek

If you ever want to read up on everything that's so strange about the Star Trek universe and what explanations Trekkies come up with for it, here's the right URL for some areas. I came across it today while watching an Enterprise episode because I was looking up the relationship between Romulans and Vulcans (in today's Enterprise episode, humans meet Romulans for the first time on the timeline).

Ok, I know it's nothing that would really interest the world.

Here's the original article.

Berlusconi: Mussolini was "benign"

Is there actually still a limit to stupidity that Berlusconi won't cross? And how long will the Italians accept this? And most importantly: how long will the EU accept such an EU Council President? At tagesschau im Internet you can find the original article.

Black Hole Hammers Bass into Space

This is quite a subwoofer that lives up to its name

At Spiegel Online: Wissenschaft you can find the original article.

How to Make a Color Your Own

The German Federal Court of Justice joins the series of senseless and absurd verdicts and delivers its own version of judicial dementia. I'm sorry if the judges are too stupid to think of anything other than Telekom when they see Magenta, but why must it now be claimed at the highest court level that the rest of the German citizens are similarly dim-witted? I don't appreciate being insulted, not even by judges...

You can find the original article at tagesschau im Internet and here.

Back again...

Just in case anyone was wondering where I was (of course nobody wondered). Hamburg wasn't quite as wet as Münster and the model railway is absolutely top-notch. The rest of Hamburg is great too. Could someone not rent me a small apartment in Winterhude at a bargain price so I have something for the weekends?

Updated Medusa Release

Ah, 0.5.4 is out. I need to remember this for the Python Desktop Server so I can update it in the documentation. Because there are important fixes in there (especially the one with URL analysis).

Here's the original article.

Open Firmware: Password Not Recognized When It Contains the Letter "U"

There are indeed strange bugs out there. You can't use a password with a capital U on Apple machines. I mean, what the heck is so special about a capital U that this banal letter makes passwords unusable? I can't imagine any bug that would provoke such behavior. Weird.

Here's the original article.

Politicians discover social welfare as radical savings potential

Oh how wonderfully simple: Social welfare recipients are just potential freeloaders anyway, so what's the difference, let's strip away their every right to data protection, no big deal, they have nothing to say anyway. The fat cats who move their money abroad. The companies that don't pay taxes because they use enough confusing constructs to hide their real income. The parties that can ship millions abroad but still pocket party financing. All of that is perfectly fine, because after all those aren't social welfare recipients.

And as for the work requirement for social welfare recipients: Work makes you free. We've seen all that before.

Every time you think the populism of German politicians can't get any worse, these idiots come up with even dumber and more contemptuous ideas. And then they wonder about political disillusionment. But who's supposed to still have interest in this madness when it's all just about destroying everything we've created so fat cats can keep ripping us off? So shareholders can keep squeezing companies? So managers can keep showing off to those shareholders how they've tightened the organization and cut costs (and in reality destroy the livelihoods of employees and run the company so far into the ground that a foreign company swallows it up)? So lobby clubs and associations can keep feathering their nests? So corrupt politicians can keep pocketing their bribes for themselves or their party? No matter who you vote for, as a voter you're screwed.

At RP-Online: Politik I found the original article.

Schäuble apparently to succeed Rau

Oh great: a federal president who at times stirs up more hatred than an ultra-right CSU politician. And has gained experience with black briefcases. Excellent idea. We'll certainly become even more popular abroad with this.

At WDR.de you can find the original article.

16,000 Flu Deaths in Germany

I was quite astonished by that. Okay, I was certainly aware that real flu is dangerous. But that it claims so many victims was new to me.

Here's the original article.

LG Hamburg: .de only for idiots!

I agree with the demand to strip German courts of jurisdiction over domain issues due to their incompetence. The whole thing is taking on increasingly absurd proportions.

I found the original article at dotcomtod.

Doping supply to Belgian professional cyclists confessed

It's interesting when athletes get doped by veterinarians - quite a mess, really.

Teufelsgrinsen

At tagesschau im Internet you can find the original article.

LWL - Westphalian Industrial Museum - Henrichenburg Ship Lift - Old Henrichenburg Ship Lift

Just as a tip, if you happen to be in the Datteln area: there's the Henrichenburg boat lift, which now serves as a museum facility. So far I've only looked at it from a distance, but hopefully we'll get there this vacation. It could also offer some nice photo opportunities.

Here's the original article.

Merkel: Work more for more jobs

What a bunch of utter nonsense Merkelnix is spouting again ...

At tagesschau im Internet you can find the original article.