Monday, March 12, 2007

Time To Upgrade

Usually, a stable kernel only consist of small amount of patches, but not for 2.6.20.2. This version consists of a bunch of updates and bug fixes, which mostly are related to security. Why does this version contains a lot of patches? I don't know, but since Greg and Chris was busy with 2.6.18 and 2.6.19 in the last 1-2 weeks, it seems that the patches have been waiting to be released and when they decided that they had stopped the future release of older kernel, they start working on the current -stable kernel which also needs an upgrade. You can see the full Changelog to see what has changed since 2.6.20.1.

I skipped 2.6.20.1, since it only consists of 1 patch and i didn't think my system need that version, but i'm sure that i will upgrade to 2.6.20.2 (hopefully tonight). I hope the compilation won't take too much time. In my personal opinion, kernel 2.6.19 and 2.6.20 are faster than previous kernel (in case of compilation time). Perhaps it's because there were some deletion on some unneeded modules, such as OSS (here and here) or because they have fixed some compilation warnings/errors, so the compilers don't have to fix it during compilation.

Saturday, March 10, 2007

Mandriva Corporate Desktop 4.0

Mandriva has just launched a beta program for Mandriva Corporate Desktop 4.0 which aims for business users seeking early access to the latest Mandriva enterprise technology. The program is designed to allow business users to test Mandriva on their hardware and with their software needs, and to collaborate with Mandriva's development team to insure stability and broad hardware support.

Here's the email message i got from Mandriva's newsletter:
Mandriva is pleased to announce the launch of the beta program of
Corporate Desktop 4.0, the brand new version of its enterprise-dedicated work station.

Ergonomic, secure, comprehensive, easy to use and to administer: by consulting its corporate clients and by exploiting its experience in the desktop area, Mandriva developed Corporate Desktop 4.0, a distribution that can be installed in less than 10 minutes and extensively customized thanks to a new post-installation tool.

Mandriva emphasizes the key points for business: directory administration and integration, mobility, security and ergonomics.

* Directory administration and integration: To complement directory-based authentication, Corporate Desktop 4 includes a new tool to set KDE user rights from an LDAP directory.

* Mobility: Simplified configuration of secure remote access (DrakVPN), simplified configuration of 3G data cards in order to remain efficient wherever you are. Mandriva also plans to release Corporate Desktop 4.0 on a secured USB key, in order for you to be able to access your data and your work environment anywhere at any
time.

* Security: Data encryption, high security authentication (smart cards and fingerprint readers supported), secure connections, interactive firewall.

* Ergonomics: A completely new design for the desktop, integration of the latest 3D technlologies (Xgl, AIGLX and Metisse), and the ease of use and accessibility you expect from a Mandriva desktop.

Mandriva also takes advantage of its partnerships with many hardware vendors and software publishers to offer extensive hardware compatibility and a complete range of ISV software. Thus, Intel, HP, NVIDIA, Arkeia, BitDefender, VMware and many more participated in the development of the product and were naturally integrated in the
Corporate Desktop 4.0 distribution.

Like every Mandriva product, Corporate Desktop 4.0 comes with an extensive range of services: long term security and bugfix maintenance lifespan (5 years), Web support, professionnal phone support, and expert consulting services to develop particular projects and help you migrate to Linux.

Corporate Desktop 4.0 works perfectly in a mixed Linux / Microsoft Windows environment and will blend easily into your network with its support for common systems of authentication, access to shared data, and support for collaborative work solutions.

To participate in the evaluation program, visit:
http://corpo.mandriva.com/xwiki/bin/view/CD4/

To register and download the beta:
https://my.mandriva.com/cd4/trial/

As a complement to its desktop solution, Mandriva offers server and park administration solutions: Corporate Server 4.0 and Mandriva Pulse.

If you are lucky, you might even get a free license (depends on your organization level and also your participants on the testing phase).

Friday, March 09, 2007

PicasaWeb Upgraded

If you have been using PicasaWeb like i do, then you will like this news, as Google has upgrade this free service (they do have commercial service with more storage) with bunch of new features and also more free storage (it's now 1 GB, that's four times the original storage and it's counting, like in GMail). Another cool feature is that now you can link to your friend's gallery and gets an email notifications when somebody leaves a comments on your photo or your favorite have uploaded a new photo.

You can see all of the new features here.

Thursday, March 08, 2007

Buying Another Novel

Last night i went to Taman Anggrek Mall with my friends. We supposed to met our friend there and give something to her, but too bad she didn't showed up. We went there at 5.20 PM and i went to gramedia book store to bought a novel which i already saw in their website and it's already available. I'm looking for the second and third book of Philip Pullman's His Dark Material trilogy book (The Subtle Knife and The Amber Spyglass). I already got the first one (Northern Light aka Golden Compass) and i have written about it here and here.

The funny thing is that when i asked the customer service about the book location, he offered me an automatic search via computer and when i mentioned the book title (in English), only one of them was showing up. That's strange, since i already saw it on their websites, so i guess the websites are more up to date than the book store itself, so i would buy the second book first can came back later when the third book is available. Next, we went to the location of the second book was placed and i saw the third book also. That was strange, it didn't come up in their program previously, so i asked him again. He said that this is the Indonesian translation, so they didn't add the English title on the program thus it won't be displayed. Another weirdness, since usually the program should be able to search based on every keywords being inputted to the program. I just hope they read this and fix their program :D

Anyway, there's also one good novel which i plan to buy when i already finished reading this novel, which is The Historian which is also available in Gramedia yesterday, but it's still quite expensive and i already bought two novels, so i postponed it for now.

Wednesday, March 07, 2007

Another Accident

Another accident from Indonesian Airways (this time Garuda Indonesia) has add another bad image on how local airways works. The latest accident was happening today with 49 casualties reported so far (others are still being evacuated and identified). The plane was burned in Adi Sucipto international airport of Jogjakarta (my hometown) and it's now being closed for further investigation.

Garuda Indonesia is willing to pay all medical treatment for their passenger which is a good news because they thought it was their responsible (give credit for Garuda for this one. I hope other airways will do the same). This plane was carrying a total of 133 passengers, including 7 plane's crews, so in total they have 140 peoples on that plane.

The cause of the accident is still unknown. We might have to wait for further investigation. For now, Garuda Indonesia has opened a call center on 021-2312193 or 2311801 ext 7205 if you want to find more information about the passenger on that plane (i received this information via YM and keep spreading this). Here's another information from Detik:

GARUDA INDONESIA AIRPORT:
487880/487882/ 484261
081 328 180 019 (Mr. LARAS WIDHYO)
0817 469 271 (Mr. SENTOT)
0817 277 345 (Mr SONNY)

1. RS. AKADEMI ANGKATAN DARAT (AAU) - BLOK O - LANUD ADISUTJIPTO
2. RS. PANTI RINI (Ph. 0274 - 497 206) - RINGISAN KALASAN

GARUDA HOTLINE in JAKARTA
021-2312193 or 021-2311801 ext 7205
021-2311393 or 021-2310049 or 3520461

Tuesday, March 06, 2007

Kuliax On InfoLinux

Kuliax distro, made by Indonesian people is now bundled on the latest edition of InfoLinux magazine. If you have problem downloading the ISO, you might consider to buy InfoLinux magazine. If you want to have cheaper one, you can also buy the mini version of InfoLinux which has just been introduced (similar to PCMedia who already offered mini version for some time). I hope that this distro will be supported by many college and can also be used in daily educational activities.

My Previous Article About Kuliax

Monday, March 05, 2007

Adding Sudoku to Your Websites

Nowadays, many people likes to play Sudoku in their spare time. Even my ex colleagues likes to play Sudoku so much and he tried to beat his own record all the time. Well, i did try to play Sudoku and at that time (long time ago), i didn't like it as much as he did, but when i tried to play that game again, it's quite interesting actually. If you have your own websites, you can help other people who likes to play sudoku by adding Sudoku games into your websites. All you have to do is go to this URL and grab the script provided. If you don't have Internet connection, you can also download a free Sudoku games which are available on many sites.

By the way, the basic rule of Sudoku is very simple:
fill each blank spaces of your puzzle with a number from 1 to 9. No digit must be repeated in the same column, line or grid of 3X3 squares.

Sunday, March 04, 2007

Another Quick Release

There has been another quick release from one of Open Source application today. This time is PHPMyAdmin who has fixed a possible deep recursion attack after MoPB (Month of PHP Bugs) has released a summary of a bug in PHP application and the example being used is PHPMyAdmin. The Security team of PHPMyAdmin does a quick research and they have released PHPMyAdmin 2.10.0.2 and also offer a patch from their websites (see Security Note PMASA-2007-3 for more detail).

Again i decided to download the patch and apply the patch manually, because it's very small and it only affecting 1 file, libraries/common.lib.php. Find this function: function PMA_arrayWalkRecursive(&$array, $function, $apply_to_keys_also = false) and then change the content into :

/**
* calls $function for every element in $array recursively
*
* this function is protected against deep recursion attack CVE-2006-1549,
* 1000 seems to be more than enough
*
* @see http://www.php-security.org/MOPB/MOPB-02-2007.html
* @see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1549
*
*/
function PMA_arrayWalkRecursive(&$array, $function, $apply_to_keys_also = false)
{
static $recursive_counter = 0;
if (++$recursive_counter > 1000) {
die('possible deep recursion attack');
}

foreach ($array as $key => $value) {
if (is_array($value)) {
PMA_arrayWalkRecursive($array[$key], $function, $apply_to_keys_also);
} else {
$array[$key] = $function($value);
}

if ($apply_to_keys_also && is_string($key)) {
$new_key = $function($key);
if ($new_key != $key) {
$array[$new_key] = $array[$key];
unset($array[$key]);
}
}
}

$recursive_counter++;
}

Don't forget to change the version in Config.class.php into 2.10.0.2 and you're done with PHPMyAdmin. It has reflected the latest version.

In my opinion, it's not completely PHP's fault. We as the developer should also give this kind of protection to our application because the resources are limited, so we should try not to pass that limit. Actually this kind of attack not only affecting PHPMyAdmin, but also other application which uses recursive array function like what PHPMyAdmin had, so better check your application now before it's too late.

Saturday, March 03, 2007

Fixing Bulb

Two days ago, my bulb had started to mess up. Sometimes, it went off and then on again and each day, the frequency was getting closer, so i guess it's time to replace the bulb and change it with the new one. I have used this bulb for about 1,5 years since i moved to Jakarta up to now and i don't know how long the bulb has been up there. So i get a ladder because a chair is not sufficient to reach the ceiling to plug off the bulb. After that i went to sleep without no light (i usually turn off the lamp when i go to sleep)

So yesterday, i bought a new bulb and when i got back from the office, i take out the new bulb and plug it into the correct place (again i have to take the ladder) and after ensuring that i already put it into the correct position, i started to turn on the switch and it worked. Now my room is shinning again :D

Manually Updating PHPMyAdmin

Few days ago, i have downloaded PHPMyAdmin 2.10.0 and the next day, they released an update which contains only one changes in how PHPMyAdmin should connect to the MySQL Server (whether it should use SSL or not). The default value for the 2.10.0 version is True, which causes some problems on some servers, so they wanted to be changed to False and they did change that with the release of 2.10.0.1.

Instead of having to re-download all of the application, i can update the application manually, because all i have to do is just edit the config.inc.php file and set the value into False and that's it. But wait. The version will need to be updated also, so i start searching for files which set the version of the application and finally i found it. It's in Config.class.php file. There's where the version is stored. I changed it into 2.10.1 and it's completely an updated version of PHPMyAdmin :D

WordPress Compromised

WordPress has released another update to it's popular engine due to modified download file which was a result of a compromised server in wordpress server. If you have just download WordPress 2.1.1 in the last 3-4 days, it's recommended that you upgrade to the latest version, 2.1.2 which is already been verified as a clean file and also fix some minor problem.

Reference:
WordPress

Friday, March 02, 2007

WebBlog Updated

Today i just updated my weblog to include a local Google Search form and also fix a broken image link for the OOo Get Legal Campaign. The local Google Search Form is just a copy from my website, but i changed the sitesearch value to reflect this blog's URL and also some changes on the layout, since i made my own CSS code on my websites, so when i wanted to put it on Blogger, i have to make some adjustment.

Before this, when i wanted to search for particular post, i have to browse all of my archives and that's not efficient (i know i could login to the Blogger and use the internal searching feature included, but sometimes logging in Blogger can cause some problem, mostly at busy hours). So i decided to put a local Google Search Form to make me and reader easier to search for specific post on my blog.

Quick PHP 4.4.6 Release

PHP team has released a new update for PHP 4.4.x version, which is PHP 4.4.6 and fix a crash problem that was introduced in PHP 4.4.5. The problem occurs when session variables are used while register_globals is enabled. This version also upgrades their PCRE version into 7.0 and fix some other minor bugs. Here's the small changelog between 4.4.5 and 4.4.6 (from PHP's Changelog):

* Updated PCRE to version 7.0.
* Fixed segfault in ext/session when register_globals=On.
* Fixed bug #40635 (segfault in cURL extension).
* Fixed bug #40611 (possible cURL memory error).
* Fixed bug #40578 (imagettftext() multithreading issue).
* Fixed bug #40502 (ext/interbase compile failure).
* Fixed bug #40286 (PHP fastcgi with PHP_FCGI_CHILDREN don't kill children when parent is killed).

If you have been using PHP 4.4.x version, it's recommended that you upgrade to this version.

Nice Firefox Logo

One of OSUOSL's staff had photos about Firefox's logo made in a huge field where they cut the dry grass and change it into Firefox logo. (I got his URL when i browsed Linux Kernel's site and see a news about new git server that is now running using an old server which was damaged, but it's working now).

Check them out here and here (beware, the files are approximately 3 MB big)

Thursday, March 01, 2007

Unicode Support for PHP 6

PHP 6 was scheduled to be released at the end of this year with lots of improvements and new support for Unicode (oh, don't forget about major changes in how PHP works, mostly with current common behavior that we found today, like Register Global, Magic Quotes, Safe Mode, etc). First alpha release was scheduled to be released at the end of the first quarter of 2007.

Here's some information about Unicode and how it will be implemented in PHP 6:
Unicode is an effort to map the characters of all human languages for use with computers. Version 5.0 of Unicode, released in the fall of 2006, contains nearly 100,000 characters and has the capacity for about a million. Support for Unicode in software is well underway, usually via one of the Unicode Transformation Formats: UTF-8, UTF-16, or UTF-32

Unicode support in PHP 6.0 will include a broad selection of International Components for Unicode (ICU). These components will include provision for such actions as converting between one locale or character set and another, collation, transliteration, Unicode text processing, and Unicode regular expressions. Such functionality will be available when a Unicode.semantics code switch is enabled.

To accommodate this change, PHP 6.0 will switch from having a single, generic string type to having two: a Unicode string type for text data, implemented through UTF-16, and a binary type, which will include actual binary data and text data for legacy locales. Perhaps the most obvious difference in the string types is that each character in a binary string will be one byte long, while in a Unicode string, a character may use more than a single byte, depending on the language and how it is encoded. In addition, within Unicode strings, characters may be referenced by either name or code point.

When a PHP program runs, runtime encoding will specify which encoding to use. The encoding for a script will be encoded either as an INI setting, or with a declare () statement in the first line, in much the same way as in an XML file. The encoding may be changed later in the script with a pragma. The encoding for standard output and for file and directory name may also be specified, as well as how conversions between the two string types are handled. Since legacy character sets cannot support all Unicode characters, programmers will also be able to set how conversion errors are handled and the format in which PHP reports them.

With Unicode support, not only will identifiers within the code be able to use Unicode characters, but a whole range of new functionality will become available. Programmers will be able to specify how information is collated by choosing a locale, and by specifying criteria, such as how accented or upper case characters are treated. Even more usefully, text can be converted from one locale to another, so that, for example, English speakers can read Greek names in Latin characters, or a Japanese reader can convert full-width characters to half-width ones on the fly.


As usual, the developer tried to make the migration between 5.x and 6.x as smooth as possible, but broken code will likely to be seen everywhere, so when the beta or RC version has arrived, perhaps it's better to start analyzing it and tried to test your site on a test server with PHP 6 installed before the final version comes up. Doing this will reduce the time required to recode the work when the final version comes up, because mostly RC already works for most cases, while it still needs some improvements before going public with final version.

PHP Developers are getting very fast while the public hasn't adopted PHP 5.x completely, since many web hosting still uses PHP 4.x on their server (because if they upgrade to PHP 5, some of their client's website may display a lot of error messages or warnings on their site and it won't be good for the business). Now, they are ready to do the same thing with PHP 6.

References:
Minutes PHP Developer Meeting
Linux.com
Core PHP