Monday, September 24, 2012

Microsoft Office:Mac for the Retina Display

Microsoft released update 14.2.4 for Office:mac on September 19. One of the major improvements was support for the new Retina displays featured on Apple's new Macbook Pro line-ups. I installed the update, only to find that the new applications still launched in the low resolution mode.

I checked the Info.plist file and found that Microsoft has indeed enabled the "High Resolution Capable" mode, as can be seen below:

<key>NSHighResolutionCapable</key><true/>

For some reason, Info.plist was not being loaded when launching the application. After searching, I found a simple hint to force Info.plist to load. Mac OS re-loads Info.plist if the application file's timestamp has changed. So, onwards to Terminal.app, and a few "touch"es got my office applications to launch in the beautiful high resolution mode which I have become so accustomed to!

cd "/Applications/Microsoft Office 2011/"
touch "Microsoft Word.app"
touch "Microsoft Excel.app"
touch "Microsoft Powerpoint.app"

Voila! The difference is just gorgeous.

As a last word, I will say that the only reason holding me back from switching over to Keynote is the poor implementation of vector graphics and total lack of "Smart Art Objects". This is a big win for Powerpoint over Keynote.

Thursday, August 23, 2012

Wallpaper reverts to default "galaxy" at startup

Several users have been complaining about the Desktop Wallpaper reverting back to the default "galaxy" image when starting Mac OS X 10.8 Mountain Lion. Refer discussion.

Apple will of course take its sweet time in fixing this issue. In the meantime, here is a workaround. I tried to force Dock.app to restart using the command:

killall -HUP Dock

This caused the wallpaper to be properly updated on my primary desktop. Note that I use ML's "Spaces" feature and I have four virtual desktops. Virtual desktop 2, 3 and 4 display the proper updated wallpaper even upon startup. The problem lies only with the primary desktop.

To make this process easy, I have created an application called "Killall Dock.app". Drop this in your Applications folder and include this item in your Login Items (from System Preferences > Users & Accounts).

Download "Killall Dock.app"



Wrapper application "Killall Dock.app" created using the awesome Platypus.app :)

Monday, August 20, 2012

iPhoto 9.3.2 generating high resolution thumbnails

I am in the process of migrating to a new machine, one with the awesome Retina display! Migration has always been a slow and painful process consuming 3-4 weekends. Most of the time is wasted in dealing with undocumented frustration, where things are subtly changed around enough to break everything else that depends upon it.

My recent annoyance has been with iPhoto 9.3.2. Granted that iPhoto 9.3.2 has been a welcome update. Apple has finally started paying attention to non-iOS software for a change. iPhoto is optimized for systems with the Retina display. Upon first launch, it prompted me to "generate high resolution thumbnails". I kept putting off the task for quite a while, but the nagging was quite persistent and I finally gave in.

To my utter frustration, a simple process like thumbnail generation takes more than 24 hours! Here's the progress meter after letting it run for 26+ hours:


I honestly hope it doesn't report an error at the end of this lengthy process :) Apple, have you really tested your software with real-life photo libraries? After about 9 years of iLife, it is expected that users will have a large accumulation of photographs. My photo library has more than 70,000 pictures. Spending 26 hours for generating thumbnails is ridiculous. That too on a 4 core i7 processor, with 16GB of RAM and an SSD hard drive.

Apple is going the Microsoft way indeed.

Friday, February 10, 2012

GPGTools, MacGPG2 and the IDEA cipher

I am one of those (un)fortunate guys who started using PGP encryption since 1998. It has been 14 years now and contrary to common belief, things have become increasingly more cumbersome to use. Cryptography on a day-to-day basis is hard to handle. This comes from a person actively participating in the information security arena. When I think of how average users would fare with cryptography, I shudder.

Ok, enough of rants, on to technical stuff. Upgrading to Mac OS X Lion saw a fair share of a few weekends getting sucked up in worthless non-productive technical housekeeping. Macports broke as usual. Downloading XCode took almost an entire day. But the greatest pain was offered by GPGMail and GPGTools.

For years, GPGMail had been floundering. Thanks to the valiant effort of a team of volunteers, the small community that insists on using Apple's Mail.app but needs PGP/GPG support still stays afloat. My problem this time was not directly related to GPGMail integration with Mail.app (as was the case with my Leopard to Snow Leopard migration. Those were dark days for GPGMail).

My problem with GPG/PGP has always been the dropped support for the IDEA cipher. When I first created my PGP keypair in 1998, it used the IDEA cipher. Today, because some patent encumberance issues, the IDEA cipher got dropped out. Therefore, every time I upgrade MacGPG, I have to recompile the package with IDEA support. I did that successfully, and my gpg2 output now shows:

$ gpg2 --version
gpg (GnuPG/MacGPG2) 2.0.18
libgcrypt 1.5.0
Copyright (C) 2011 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Home: ~/.gnupg
Supported algorithms:
Pubkey: RSA, ELG, DSA
Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH, CAMELLIA128,
CAMELLIA192, CAMELLIA256
Hash: MD5, SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224
Compression: Uncompressed, ZIP, ZLIB, BZIP2

So far so good. The problems started occuring when using the passphrase. For some insane reason, gpg2 never accepted my secret key's passprhase. I tried searching for hours at end on issues with pinentry, gpg2, IDEA, gpg-agent and what not, but no avail. I would be greeted with an "Invalid passphrase" message every time.

My solution? Get rid of the damn passphrase. I have had enough. I agree that I am a crypto wuss. The only way of getting rid of the passphrase was to migrate my key pair to a Linux machine and use GPG 1.4 on it. Oh yes, I had to recompile IDEA support for GPG 1.4 on my Linux machine as well.

Steps to enable IDEA support on GPG 1.4 for Linux:

wget http://www.spywarewarrior.com/uiuc/gpg-idea/idea.c.gz
gunzip idea.c.gz
gcc -Wall -O2 -shared -fPIC -o idea idea.c
cp idea /usr/lib/gnupg

Edit ~/.gnupg/gpg.conf. Add the following line:

load-extension idea

Now your Linux GPG 1.4 will support the IDEA cipher. Almost there.

Removing the passphrase from my secret key:

gpg --status-fd 1 --command-fd 0 --edit-key root@example.com < input

and here's the input file:

passwd
old_password

Y
save
Y

Last step, migrate pubring.gpg and secring.gpg back to my Mac. GPGMail works great. Yes, I feel a little insecure because I don't have a passphrase on my secret key anymore, but it is something I will trade off for a working mailer that uses PGP encryption. Crypto afficionados are now permitted to let loose their tirades and criticisms against me.

Tuesday, June 7, 2011

Calvin and Hobbes GoComics Widget


My family and I are sworn Calvin and Hobbes fans. I have followed Calvin and Hobbes on my Mac's Dashboard Widget called FreeComics. FreeComics used to pull many comic strips from gocomics.com. A few days ago, GoComics changed the URL format for Calvin and Hobbes and made it very difficult to link to the image file. As a result, my widget stopped working and I was left wanting for Calvin and Hobbes. Reading the newspaper is unthinkable. Indian newspapers' quality decays exponentially. The quality of journalism and ethics is lower than a worm's belly button.

I had to find an alternative for my Calvin and Hobbes Dashboard Widget. There was no way I was going to visit GoComics.com's website for my daily dose of C&H and nor was I going to subscribe to their email service.

The solution was absolutely elegant and brilliant. For quite a while now, Safari has provided a feature called Web Clips. Web Clips allow you to take a snippet of any web page and place it in your Dashboard as a widget. So all I had to do was:

a) Navigate to http://www.gocomics.com/calvinandhobbes in Safari.

b) Click on the Web Clips icon (the one with a scissor).

c) Mouse over the comic image and select the nearest matching web page element.

d) Click in the selected element and adjust the size if needed.


When done, click Add in the top right bar, and voila, you have your Dashboard web clip! Enjoy your comics distraction-free!

Wednesday, November 10, 2010

iPhoto '11 nightmare

My nightmare in getting rid of iPhoto '11 and downgrading to iPhoto '09 lasted 48 hours. What's wrong with iPhoto '11? Plenty of things! Here's a little list:
  • Slow. iPhoto '11 is slower by a few orders of magnitude as compared to iPhoto '09. Speed of response is just unacceptable.
  • Complex paths to simple operations. In iPhoto '09, I used to be able to edit event names, album names, descriptions very easily, with a single click. Not so anymore. The information window in iPhoto '11 is just clumsy and non-intuitive.
  • Places. This is a killer, and this is what prompted me to downgrade. I don't own a GPS enabled camera. I tend to manually enter location information by dropping a pin on the map. This used to be very simple. Click on the information icon on the photo, search for your place and drop the pin. Now what we have is a tiny rectangle in the information window and a clumsy method to drop a pin. It is frustratingly impossible to accurately pinpoint your location. Also, there's a bug which causes duplicate letters to appear when typing for a place name!
My nightmare:

My TimeMachine disk had failed. I had to re-format it after I upgraded to iPhoto '11. There was no possibility of a rollback.

The solution:

Initially, I tried iPhoto Library Manager. This is a wonderful piece of work, thought out meticulously by someone who understands the needs of proper photo management. While it is aimed at merging and splitting multiple iPhoto libraries, I used it for its "Rebuild Library" feature. iPLM can rebuild a photo library based on all the metadata it can find.

To rebuild your library:
  • Delete iPhoto '11
  • Install iPhoto '09
  • Apply the software updates to iPhoto '09 (I had to apply two updates)
  • Install iPhoto Library Manager
  • Open iPhoto Library Manager, select your default photo library and hit Rebuild Library.
  • iPhoto will be launched by iPLM and you will see your photos being imported and metadata being applied.
  • Wait for a long time. My 45000 photos took 30 hours to import and fall in place.
After iPLM finished its job, I had a properly rebuilt iPhoto library, except I lost all my geo-tagging data. iPLM is still unable to read and apply Places data from the new library. I believe future updates of iPLM will make this possible, but as of this writing, this isn't the case.

I had geo-tagged a lot of photos. Losing my geographical data was unacceptable. Luckily, I maintain a second backup of all my photos - slightly less frequently than TimeMachine. I use rsync to backup my photos to another hard disk. Restoring from this backup would mean losing the last three months worth of photographs.

My next step was to export the last three months' photos to another folder, delete the iPhoto library, restore from my rsync backup and re-import the photos from the last three months. I had to re-tag and re-apply some of the metadata, but it is easier to do so for three months worth of photos than re-applying geo-tags for the entire library.

Lessons to be learned:
  • If you value your photos, maintain a second backup in addition to TimeMachine. You may use Carbon Copy Cloner to do the job. I love CCC!
  • Don't upgrade in haste without having a proper rollback support!
iPhoto '11 is nothing but a redesigned interface and a boatload of new templates. Again, DO NOT upgrade to iPhoto '11. Apple, have you done your QA at all? Or are you totally engrossed in all your iPods and iPads and iDoodads?

Saturday, November 6, 2010

Do NOT upgrade to iPhoto '11

I made a big mistake last week. I hastily upgraded to iLife '11. Who wouldn't be attracted by Apple's slick marketing? Apple used to design applications keeping the end user in mind. Clearly that is not the case anymore. Apple now designs applications to throw in more features and releases applications without any proper testing. Net result - iLife 11 is a SHODDY JOB. This is the clumsiest interface that I've ever seen.

I shall not even begin to describe the nightmare I'm facing. To my dismay, my Time Machine backup disk failed, so I don't have a proper backup and can't roll back to iPhoto '09 easily. I am faced with a terrible task of having to downgrade my iPhoto library almost manually, since I clearly cannot live with iPhoto '11.

So dear friends and readers, sit out on this version of iLife and iPhoto '11. It is definitely not worth it. Let Steve Jobs get back to the bloody Mac and get his act together. For now, they seem to be just an iGadget company.

Monday, October 18, 2010

Autorun in Mac OS X!

As if we didn't have enough problems with Autorun in Windows, I noticed the same behaviour with Mac OS X today. The culprit - Huawei modem manager - launched from my USB Internet Stick thingie.

The USB stick mounts a volume called Mobile Partner when inserted into my Mac. Inside the volume is an application called Mobile Partner.app. Looking into its Mobile Partner.app/Contents/Info.plist file, I noticed the following lines:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>CFBundleDevelopmentRegion</key>
<string>English</string>
<key>CFBundleExecutable</key>
<string>AutoOpen</string>
<key>CFBundleGetInfoString</key>
<string>1.9</string>
Notice the property which says CFBundleExecutable = AutoOpen. There you have it. The same annoyance as Windows' Autorun.

Here begins my quest for a method to disable AutoOpen in Mac's Finder. If not, Macs (and Steve Jobs), welcome to the world of USB malware.

Wednesday, October 14, 2009

mtools for Mac OS X

I'm always cleaning viruses from USB pen drives. Most reside as Windows explorer extensions in hidden files and directories on the FAT32 filesystem of the USB pen drive. I needed some FAT utilities on Mac OS X to be able to change the files' attributes and remove them.

The mtools package for Linux was just the thing needed. However, compiling it on Mac OS X proved to be a challenge. I downloaded the latest mtools-4.0.11 which fixed a problem in calculating the FAT size. These days, GNU's not what it used to be. There's hardly any documentation for mtools to help. Running make left me with an error stating "Undefined symbols: _iconv...". I managed to compile successfully using the following command:

./configure LIBS=-liconv

After that, cleaning the malware files was a breeze using mattrib, mdel and mdeltree.

Friday, September 25, 2009

Ad Blocking in Vienna RSS Reader

I gave up NetNewsWire because of its ad-bombardment. Sure, I understand that free software can be expensive for the developer, but there's a limit of ad-bombardment that a user can tolerate. My threshold is very low.

Newsfeeds such as Slashdot have large and annoying graphical ad banners inserted in the RSS XML content. The size of the ads is larger than the 2-3 lines of content. This had to end.

Fortunately, the Vienna RSS reader supports customizable templates. My solution involves disabling the display of these ads using CSS. Follow these simple and easy steps to suppress the display of advertisements in your RSS feeds.
  1. Edit /Applications/Vienna.app/Contents/SharedSupport/Styles/Default.viennastyle/template.html
  2. Insert the following lines at the top (before the first <div> tag):

    <style type="text/css">
    @import url("http://adblock.googlecode.com/svn/trunk/adblock.css");
    @import url("http://www.floppymoose.com/userContent.css");
    </style>

  3. Save template.html and restart Vienna RSS.
I use the following two CSS files:

http://adblock.googlecode.com/svn/trunk/adblock.css
http://www.floppymoose.com/userContent.css

If anyone comes across a frequently updated CSS stylesheet for adblocking, please let me know. It is easy to add it to "template.html" as shown above.

Thursday, September 24, 2009

Quest for a good RSS Reader


I have always been searching for a good RSS reader for the Mac. My criteria for selection:
  • Free
  • Offline content
  • No sign-ups, no logins
  • I don't want Google to learn about what I'm reading
  • Good looks
  • No annoying ads
For the longest time, NetNewsWire's free version fit my needs. Recently, NNW has become annoying. Overlaid ads, greed and excessively frequent changes and updates (there's almost one every week) killed NNW's appeal. I don't care for Google Reader integration. I don't care for Google Reader, period.

I then switched over to NewsFire. It looks great. It is simple. But it lacked in many features. What killed NewsFire for me was its inability to pull in older content, even if it is on the site's feed. And there are no advanced settings.

NewsFire gave way to Vienna. I still prefer the fonts and styling of NNW and NewsFire, but Vienna does a very good job in meeting my criteria and keeping the ad banners away.

Monday, September 7, 2009

GPGMail no more for Snow Leopard :(

Sad to learn about this, but the developer of the excellent GPGMail plugin for Mail.app has thrown in the towel. Apple has very weak documentation of Mail.app's internals and there's just no support and no thanks for someone's exceptionally hard work.

So, if you're a GPG/PGP user like I am, your move to Snow Leopard shall be without Mail.app. Your only alternative is Enigmail on Thunderbird.

Apple, atleast consider rewarding Stephane for his work and open up some good documentation for Mail.app

Google - this would be a nice idea for a Summer of Code project.

I hope the community can find a way to keep this great project alive!

Carbon Copy Cloner

Today, I upgraded my MacBook Pro's hard drive. I replaced it with a 7200 rpm 500GB HDD from Seagate. My system is a newer model and therefore I didn't require the MacBook Pro EFI Firmware update 1.7, which addressed a problem with higher capacity and higher speed SATA drives.

My upgrade was actually a very smooth process, thanks to Carbon Copy Cloner from Mike Bombich. Mike, thank you very much for building a fantastic product. I shall surely be sending a donation your way, not for saving my butt, but for building a great product!

Step 1: Place your target hard drive in an external USB or Firewire enclosure. I placed my 500GB drive in the external USB enclosure and connected it to my Mac.

Step 2: Partition the target hard drive using the Intel GUID partition format. Use Disk Utility to get that job done.

Step 3: Clone your system's drive onto the target hard drive using Carbon Copy Cloner. My system's drive is a 250GB drive. Carbon Copy Cloner went to work and in a couple of hours, my data was cloned.

Step 4: Remove your Mac's drive and replace it with your target hard drive. I followed the instructions from OWC's upgrade video.

Step 5: Ensure that you have properly closed your Mac.

Step 6: Boot up. It may take a little while at the first attempt, but soon you shall see your system boot up, with an upgraded disk capacity and everything in place as-is! I usually have verbose boot up messages turned on.

Thursday, September 3, 2009

Turn off annoying iCal invite replies

Many people have complained about Apple really ruining iCal. I won't go into the depths of that. A month after I moved to a new Mac, I discovered yet another thing that wasn't properly restored from my previous system - the plugin to disable automatic replies to invitations.

iCal.app automatically sends and Accepted or Rejected email for calendar invitations. I want control over this notification, but there is none.

Enter John Maisey's extremely useful iCal Reply Checker. It took me a while to search for this utility - it is hidden in a deep corner of the web. Anyway, I am delighted that I found this utility again and installed it promptly!

Saturday, August 22, 2009

Fix ugly thick fonts

Default Mac OS X settings make some fonts look ug-lee. Read JWZ's post for some details. Some fonts end up looking thicker and more jagged than they should be.

Here's how my Terminal and NetNewsWire looked when I had to re-install my Mac:



And after the fix, here's how they look now:



What fixed this? Go to System Preferences > Appearance and set Font Smoothing Style to "Standard".

Friday, August 21, 2009

Leopard Firewall Sucks

I like host based firewalls that block ports, not processes. Sure, there are merits to blocking access based on processes. I would have preferred a combination of both - access control based on both ports as well as processes. I can live without a process level access control mechanism, but I can't live without a port level access control mechanism.

Apple: "If it ain't broke, don't fix it".

Solution: I went back to ipfw. I sure wish Tiger's ipfw front-end GUI was available through some preference pane!

a) Disable the system firewall (Allow all incoming connections)

b) Create an entry in /Library/LaunchDaemons/ipfw_firewall.plist [link to pastie]

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST
1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>ipfw_firewall</string>
<key>ProgramArguments</key>
<array>
<string>/usr/local/etc/ipfw_firewall.sh</string>
</array>
<key>RunAtLoad</key>
<true/>
<key>UserName</key>
<string>root</string>
<key>GroupName</key>
<string>wheel</string>
</dict>
</plist>

c) Create /usr/local/etc/ipfw_firewall.sh and /etc/ipfw.conf - see code at the bottom of this message.

d) Modify /etc/syslog.conf [link to pastie] to create a separate ipfw log file

*.err;kern.*;auth.notice;authpriv,remoteauth,install.none;mail.crit /dev/console
*.notice;authpriv,remoteauth,ftp,install.none;kern.debug;mail.crit /var/log/system.log

# Send messages normally sent to the console also to the serial port.
# To stop messages from being sent out the serial port, comment out this line.
#*.err;kern.*;auth.notice;authpriv,remoteauth.none;mail.crit /dev/tty.serial

# The authpriv log file should be restricted access; these
# messages shouldn't go to terminals or publically-readable
# files.
auth,authpriv.*;remoteauth.crit /var/log/secure.log

lpr.info /var/log/lpr.log
mail.* /var/log/mail.log
ftp.* /var/log/ftp.log
netinfo.err /var/log/netinfo.log
install.* /var/log/install.log
install.* @127.0.0.1:32376
local0.* /var/log/ipfw.log

*.emerg *


Reference:

/usr/local/etc/ipfw_firewall.sh [link to pastie]

#!/bin/sh
## Boot Script for firewall

#
# CONSTANTS
#

IPFW=/sbin/ipfw
SYSCTL=/usr/sbin/sysctl

#
# Required startup script statements
#

. /etc/rc.common
ConsoleMessage "Configuring Firewall"

#
# Enable logging to /var/log/ipfw.log
#

/usr/libexec/ipfwloggerd

$SYSCTL -w net.inet.ip.fw.verbose=2
$SYSCTL -w net.inet.ip.fw.verbose_limit=100

#
# Enable Blackholes
#

$SYSCTL -w net.inet.tcp.blackhole=2
$SYSCTL -w net.inet.udp.blackhole=1

#
# Purge existing rules, this blanks any existing rules
#

$IPFW -f flush

#
# Load rule set from /etc/ipfw.conf
#

$IPFW -q /etc/ipfw.conf

/etc/ipfw.conf [link to pastie]

####################
# Localhost Settings
####################

# Allow everything on the localhost (127.0.0.1)
add 00100 set 0 allow ip from any to any via lo*

# Prevent spoofing attacks via localhost
add 00200 set 0 deny log all from 127.0.0.0/8 to any in
add 00201 set 0 deny log all from any to 127.0.0.0/8 in
add 00202 set 0 deny log ip from 224.0.0.0/3 to any in
add 00203 set 0 deny log tcp from any to 224.0.0.0/3 in
##############################################################
# ip-options
# (per FreeBSD Security Advisory: FreeBSD-SA-00:23.ip-options)
##############################################################

add 00250 set 0 deny log ip from any to any ipoptions ssrr,lsrr,ts,rr
############################################
# Allow outbound TCP, UDP & ICMP keep-state
############################################

add 00300 set 1 check-state
add 00301 set 1 deny log all from any to any frag in
add 00302 set 1 deny log tcp from any to any established
add 00303 set 1 allow tcp from me to any out setup keep-state
add 00304 set 1 allow udp from me to any out keep-state
add 00305 set 1 allow icmp from any to any out keep-state

# Allow traceroute out for diagnostics
add 00307 set 1 allow udp from me to any 33434-33525 out keep-state
add 00308 set 1 allow log udp from any to any 33434-33525 in keep-state

# Prevent spoofing attacks
add 00309 set 1 deny log ip from me to me in keep-state

# Deny Inbound NetBios traffic which just clogs up the logs
add 00311 set 1 deny tcp from any to any 137,138,139 in setup keep-state
add 00312 set 1 deny udp from any to any 137,138,139 in keep-state

# Prevent ident requests
add 00313 set 1 deny log tcp from any to me 113 in setup keep-state

# Attempt to prevent os fingerprinting, port 0 is commonly used for fingerprinting purposes
add 00314 set 1 deny log tcp from any to any 0 in setup keep-state
add 00315 set 1 deny log udp from any to any 0 in keep-state

#####################################
# DNS, Rendevouz, DHCP & NTP Services
#####################################
# Allow DNS
add 00400 set 2 allow tcp from any to any 53 out setup keep-state
add 00401 set 2 allow udp from any to any 53 out keep-state

#Allow Rendezvous packets (mDNS Responder)
add 00402 set 2 allow udp from any 5353 to any in keep-state
#Multicast packet required by Rendezvous
add 00403 set 2 allow ip from any to 224.0.0.251 out keep-state

# Allow DHCP
add 00500 set 2 allow udp from any 68 to any 67 out keep-state
add 00501 set 2 allow log udp from any 67 to any dst-port 68 in keep-state

# Allow NTP
add 00600 set 2 allow udp from any to any 123 out keep-state
add 00601 set 2 allow tcp from any to any 123 out setup keep-state

##################
# Services Inbound
##################

# Allow SSH inbound
add 00700 set 3 count log tcp from any to any dst-port 22 in setup
add 00701 set 3 allow tcp from any to any dst-port 22 in setup keep-state

# Allow TCP 2456 inbound
add 00710 set 3 allow log tcp from any to any dst-port 2456 in setup keep-state

# Allow TCP 6881 inbound
add 00720 set 3 allow log tcp from any to any dst-port 6881 in setup keep-state

# Deny any TCP setup requests from the outside world
add 00800 set 3 deny log tcp from any to any setup in keep-state

######
# ICMP
######

# Deny ICMP
add 00900 set 4 deny log icmp from any to me in icmptypes 0,3,4,8,11,12

# Deny external ICMP redirect requests
add 00901 set 4 deny log icmp from any to any icmptype 5 in keep-state

# Silent block on router advertisements
add 00902 set 4 deny log icmp from any to any icmptypes 9
# Drop all other ICMP
add 00903 set 4 deny log icmp from any to any
#########
# Cleanup
#########

# Default deny rule
add 10000 set 5 deny log logamount 500 all from any to any

Further References:

iCal publish URLs lost after moving to a new Mac

I had a Mac disaster two weeks ago. To cut a long story short, Apple was nice enough to give me a new Unibody MacBook Pro when my older MBP died for the 4th time in one year. I am very vigilant about backups, and maintain a regular Time Machine backup.

The new Mac asked me to restore from an existing Time Machine backup, which I did. It took around 12 hours to restore from a 250GB backup.

One of the many things that did not get restored were my iCal publish URLs. Upon opening iCal, I noticed that my publish options had been reset to MobileMe. I had to dig through my old notes and find out what my original publish URLs were, since there is no easy way of digging that info out of my raw Time Machine backup.

Thursday, August 20, 2009

ls in colour

I have become used to ls generating coloured file listings.

Add the following to your .profile file to enjoy coloured file listings whenever using ls:

export LSCOLORS=exfxbxdxcxegedabagacad
export CLICOLOR=1
alias "ls"="ls -GF"

Links:

Safari - delete permanent cookies


Permanent cookies are a pain. I don't want to save any permanent cookies on my system.

Firefox allows me to automatically dump all permanent cookies when closing the browser:


Safari has no such option. Apple - this is a suggestion for you.

I have been tricking browsers into dumping cookies since 2001. For Netscape Navigator on Unix, it was easy. Simply symlink the cookies.txt file to /dev/null :) This forced every cookie to be treated as a session cookie.

For Safari, I had to write a wrapper script.

  1. Go to /Applications/Safari.app/Contents/MacOS
  2. Rename "Safari" to "Safari1"
  3. Create a shell script called "Safari" in the same directory as follows

#!/bin/sh
rm -f ~/Library/Cookies/Cookies.plist
${0}1 $*
rm -f ~/Library/Cookies/Cookies.plist

This will cause Safari to erase all cookies upon launching and exiting. Crude, but works.

Verbose boot-up messages

I don't like staring at a white boot up screen with an apple in the middle and a spinning wheel below it. I want to know what's going on. I want to see messages fly by like Linux.

Open up your Terminal and type: