Tuesday, June 17, 2008

Ha, ha, haaa!













ISLAMABAD - June 16: A sergeant of the
Islamabad Traffic Police issuing a ticket to a city policeman for jumping the ‘red light’ at Radio Pakistan crossing on Monday.—Photo by G.A. Zaidi

Tuesday, June 10, 2008

Yes, he said Insect :|

A human being should be able to change a diaper, plan an invasion, butcher a hog, conn a ship, design a building, write a sonnet, balance accounts, build a wall, set a bone, comfort the dying, take orders, give orders, cooperate, act alone, solve equations, analyze a new problem, pitch manure, program a computer, cook a tasty meal, fight efficiently, die gallantly. Specialization is for insects. - Robert A. Heinlein, "Lazarus Long"

Sunday, June 08, 2008

My MS Thesis

On 2nd June, 2008, I started my M.S. Thesis study in a sort of official manner. I requested my advisor Dr. Tecuci and supervisor Dr. Boicu to suggest me a thesis topic. I did it deliberately as I had a bad experience in working on one of my own research topic as part of my undegraduation final year project, where all the responsibility and planning lied with me and all that a supervisor asks you is 'watsp' or 'howz it goin'. So, my understandings lead me to have supervision in the sense of transfer of knowledge, experience, and planning ability.

Also, I added one single condition in regard to my research topic that they might propose: Some how, I want to work in parallel to the Semantic Web Activity. Fortunately, they already had a broad vision about such a project in relation to Disciple System. Eventually, in the next meeting, I was introduced to the vision, direction, timeline, opportunities, and expectations. And, I loved it!

The Disciple System, which is a brainchild of Dr. Tecuci, was not developed since its inception, while keeping in mind a compliance with the artifacts of the semantic web. In the recent years, however, a lot work was done to get the most out of OWL, while extending it where it was required. Now, the related standards have all matured, and at the same time new standards are being developed. To achieve a strong compliance b/w Disciple and those standards, I am required to study, observe, and participate in development of a couple (or may be single) standards, which provide the same (or more) facilities that Disciple is providing in a non-standard way. This would be achieved by identifying relevant W3C working groups (RIF etc), and seeking memberships. Following this, we would rebuild certain components of Disciple to conform to norms of semantic web standards and would come up with some sort of association b/w non-conventional expert systems and semantic web.

Yes, it's all very much abstract as of now and it remains like this traditionally. The more I'll study, the narrower the vision will be, till the moment when I'll be able to say it all in a couple of statements, known as the Thesis Statement.

That's it!

Monday, May 19, 2008

The 4 Core Principles of Agile Programming

Author: Joe Winchester, JDJ's Desktop Technologies Editor, is a software developer working on development tools for IBM in Hursley, UK.

One of the things I really enjoy at the moment is the recognition and adoption of agile programming as a fully fledged powerful way to deliver quality software projects. As its figurehead is a group of very talented individuals who have created the agile manifesto http://agilemanifesto.org/. At its core are four simple principles that, when followed and applied to software projects, generally will ensure a great flexibility and hence higher agility.

Leaving aside how great agile projects are, what worries me at the moment is that more and more people seem to be buying into this idea that agile programming is a noun rather than a verb, and that to do it correctly you have to follow a certain process to the letter.

Point 1: the manifesto for agile developemt states that it puts "Individuals and interactions" over process and tools. In other words, you adapt the process and tools to the team and not vice-versa.

A colleague of mine recently attended a lecture on how their company was going to roll out a company wide agile methodology. They'd given it a silly in-house acronym and appointed a team of people to help projects adopt this new methodology. At the lecture attendees were given a 97 page ring bound handout explaining agile programming that, on page 85, warned people to "beware of powerpoint architects". Forget having a black fly in your chardonnay folks, this is like having a herd of dinosaurs squash your PC and replace it with a punch card mailbox.

Point 2: the manifesto for agile development states that it puts: "Working software over comprehensive documentation".

In the same week a friend of mine e-mailed me to complain that at her company they'd decided to become agile and renamed all of their meetings to scrums. Folks, if it smells like a pointless meeting, if it looks like a pointless meeting, if it tastes like a pointless meeting, then it probably is a pointless meeting. Calling it a scrum isn't going to change that. What was even more ironic was that at said meeting my friend, who was the only person there who'd written any code in the last ten years, yet had to suffer watching six colleagues stare at PowerPoint charts of dates and endlessly argue about which documents had to be signed off at which points in the next few months to obtain the right sizing to get the right approval to go ahead with the project that had the right marketing messages, blah blah, and so forth. The thought of actually coding something and showing it to customers to see what they thought and repeating this process to create an iterative feedback loop was clearly beyond their comprehension. Forget having ten thousand spoons when all you need is a fork; it's like having ten thousand planners when all you need is a developer.

Point 3: the manifesto for agile development state that it puts: "Responding to change over following a plan."

Legal departments can be a huge obstacle to agile development. I've heard so many stories of projects that want to reach customers early to get feedback yet find immovable hurdles thrown up by lawyers who insist that documents must be signed by the customer that their legal departments refuse to do so, creating a deadlock that keeps both sets of lawyers happily engaged, yet drives a massive wedge between the developer and their potential future user ,thereby destroying the whole feedback loop that is essential to the "perpetual beta" concept. When pressed most of the arguments given by lawyers, often pseudo lawyers because they don't actually have law degrees, are usually ridiculous and involve extrapolating things ad absurdum; "What if Foo does Boo and Moo sues us and we all get crushed by a falling comet ?", or recounting quondam horror stories, "Remember when Foo messed up and we all got sued and had to save the day and you're just about to do the same, etc...". Unfortunately legal departments hold a huge amount of power at corporations and love nothing more than to remind other groups of just how big and important they are.

Point 4: the manifesto for agile development state that it puts "Customer collaboration over contract negotiation".

If companies refuse to actually change themselves, even if means changing the core and fabric of all that prevents the projects from becoming agile, then they'll just end up about as flexible as an elephant with two left feet. Being agile is not a buzzword; it is not a religion; it is not a methodology; it is about taking a few core principles and applying them to everything related to the entire development process. It is about taking risks, getting customers more involved with the development cycles, and reaping the rewards at the end when higher quality, better functioning, and more thoroughly tested code is delivered.

[source: http://xml.sys-con.com/read/522904_1.htm]

Sunday, May 18, 2008

Metacrap

Metacrap is a portmanteau drawn from metadata and crap. The origin of the word is unknown, but it was popularized by Cory Doctorow in a 2001 essay titled "Metacrap: Putting the torch to seven straw-men of the meta-utopia."

In the essay, Doctorow illustrates problems in relying on metadata for knowledge representation in online records or files by drawing humorous parallels to real-world systems, as well as showing examples of metadata collapse in online, web-based systems. The fragility of metadata is an important concern because much planning for improving the web (such as the semantic web) is predicated upon certain flavors of metadata becoming widely adopted and used with care -- something which, according to Doctorow's essay, will not and cannot happen.

Doctorow's seven insurmountable obstacles to reliable metadata are:

  • People lie
  • People are lazy
  • People are stupid
  • Mission Impossible: know thyself
  • Schemas aren't neutral
  • Metrics influence results
  • There's more than one way to describe something

The complete article can be read here.

[source: http://en.wikipedia.org/wiki/Metacrap]

Friday, May 09, 2008

Dua' to help you with your studying

Dua Before Studying

Allahumma infa’nii bimaa ‘allamtanii wa’allimnii maa yanfa’ unii.
O Allah! Make useful for me what You taught me and teach me knowledge that will be useful to me.

Allahumma inii as’aluka fahmal-nabiyyen wa hifthal mursaleen al-muqarrabeen.
O Allah! I ask You for the understanding of the prophets and the memory of the messengers, and those nearest to You.

Allahumma ijal leesanee ‘amiran bi thikrika wa qalbi bi khashyatika.
O Allah! Make my tongue full of Your remembrance, and my heart with consciousness of You.

Innaka ‘ala ma-tasha’-u qadeer wa anta hasbun-allahu wa na’mal wakeel.
(Oh Allah!) You do whatever You wish, and You are my Availer and best if aid. Protector and the best of aid.

Dua After Studying

Allahhumma inni astaodeeuka ma qara’tu wama hafaz-tu. Faradduhu ‘allaya inda hagati elayhi. Innaka ‘ala ma-tasha’-u qadeer wa anta hasbeeya wa na’mal wakeel.
Oh Allah! I entrust You with what I have read and I have studied. (Oh Allah!) Bring it back to me when I am in need of it. (Oh Allah!) You do whatever You wish, and You are my Availer and Protector and the best of aid.

Dua While Studying Something Difficult

Allahumma la sahla illama ja-’altahu sahla wa anta taj ‘alu al hazana etha shi’ta sahla.
O Allah! Nothing is easy except what You have made easy. If You wish, You can make the difficult easy.

Dua For Anxiety

Allahumma inni a’oodhoo bika minal-hammi-walhazan. Wa’a oodhoo bika minal-ghammi-wal-kasal. Wa’a oodhoo bika minal jubni wal bukhl. Wa’a oodhoo bikal min ghalabatid-dayni-waqarir rijal.
Oh Allah, I seek refuge in You from worry and grief, from helplessness and laziness, from cowardice and stinginess, and from overpowering of debt and from oppression of men.

Dua For Distress

Allahumma rahmataka arjoo falaa takilnee ilaa nafsee tarfata ‘aynin wa aslih-lee sha’nee kullahu, laa ilaha illa anta.
O Allah! It is Your mercy that I hope for so do not leave me in charge of my affairs even for a blink of an eye and rectify for me all of my affairs. None has the right to be worshipped except You.

Dua For Distress and Grief (Taken from USC-MSA website)

This is based on the following saheeh hadeeth reported by Imaam Ahmad (translation adapted from www.islam-qa.com; see question 1392):
The Messenger of Allaah (peace and blessings of Allaah be upon him) said: ‘There is nobody who is afflicted with distress or grief and who says: “Allaahumma inni ‘abduka wa ibn ‘abdika wa ibn amatika, naasiyati bi yadika maadin fiyya hukmuka ‘adlun fiyya qadaa’uka, as’aluka bi kulli ismin huwa laka sammayta bihi nafsaka aw ‘allamtahu ahadan min khalqika aw anzaltahu fi kitaabika aw asta’tharta bihi fi ‘ilmi al-ghaybi ‘indaka an taj’al al-Qur’aana rabee’a qalbi wa noor sadri wa jilaa’a huzni wa dhihaaba hammi.’

‘O Allaah, I am Your slave, son of Your slave, son of Your maidservant, my forelock is in Your hand, Your command over me is ever executed and Your decree over me is just. I ask You by every name belonging to You which You have named Yourself with, or which you revealed in Your Book, or which You taught to any of Your creation, or which You have preserved in the knowledge of the Unseen with You, that You make the Qur’aan the life of my heart and the light of my breast, and a departure for my sorrow and a release for my anxiety,” - but Allaah will take away his distress and grief, and replace it with ease.’ He was asked, ‘O Messenger of Allaah, should we not learn it?’ He said, ‘Of course, whoever hears it should learn it.’

[source: George Mason University - Muslim Students Association, http://gmu.edu/org/msa/]

Thursday, May 08, 2008

Tornado Warning

TORNADO WARNING NATIONAL WEATHER SERVICE BALTIMORE MD/WASHINGTON DC 1133 PM EDT THU MAY 8 2008

THE NATIONAL WEATHER SERVICE IN STERLING VIRGINIA HAS ISSUED A TORNADO WARNING FOR... PRINCE GEORGES COUNTY IN CENTRAL MARYLAND FAIRFAX COUNTY IN NORTHERN VIRGINIA PRINCE WILLIAM COUNTY IN NORTHERN VIRGINIA STAFFORD COUNTY IN NORTHERN VIRGINIA CHARLES COUNTY IN SOUTHERN MARYLAND UNTIL 1215 AM EDT

* AT 1132 PM EDT...NATIONAL WEATHER SERVICE DOPPLER RADAR INDICATED A DEVELOPING TORNADO NEAR TRIANGLE... MOVING NORTHEAST AT 27 MPH.

* LOCATIONS IMPACTED INCLUDE... WOODBRIDGE... INDIAN HEAD... LORTON... FORT BELVOIR...

IF YOU ARE IN OR NEAR THE PATH OF THIS STORM...TAKE COVER NOW! IF NO UNDERGROUND SHELTER IS AVAILABLE MOVE TO AN INTERIOR ROOM ON THE LOWEST FLOOR. MOBILE HOMES AND VEHICLES SHOULD BE ABANDONED FOR MORE SUBSTANTIAL SHELTER. AVOID WINDOWS!

[source: http://www.weather.com/weather/newscenter/alerts/USVA0262?alertId=579280]

Monday, May 05, 2008

Jabber: agsXMPP SDK

agsXMPP is a SDK / library for the eXtensible Messaging and Presence Protocol (XMPP) protocol written in managed C# dedicated to .NET and Mono technologies. The SDK is released as open source under a dual license.
Our SDK could be used for XMPP client, server and component development.

----------- FAQS -----------

Will you add feature xyz?
We work continuous on new features and XMPP extensions. Feel free to contact us if you want to sponsor certain functionality.

Does the agsXMPP SDK run on Mono/Linux?
Yes it does.

Is the agsXMPP SDK API stable?
Yes, agsXMPP is used in many open source and commercial projects today. The version is still below 1.0 because there are still some features on our roadmap which we want to add before increasing the version to 1.0.

Can I use the agsXMPP SDK in a commercial application?
Contact us by Email if you are interested in a commercial license.

Can you release a LGPL or BSD licensed version?
No we can't

Can I build a XMPP server with agsXMPP?
Yes you can. But writing a XMPP server is a very compex task.The idea of XMPP is: simple client, complex server.Even if agsXMPP does lots of work for you, you have to study the XMPP RFC's in detail.

The examples don't support feature xyz and are crashing sometimes
the examples are not meant to be a usable client or server. Just to show off particular features of the API and get started with agsXMPP development.

I can't authenticate to my server, I'm sure that the password is correct
In the most cases this is a problem with your server configuration and the XMPP domain.Never use IP addresses in your Jid or XMPP domain for testing.The XMPP domain is part of the SASL authentication and must match.

Sunday, April 27, 2008

My machine's current configuration

These days, I am working on a virtualization project and trying out a few things while anticipating definite abnormal behaviors/outcomes; and, it's working since I have slept only 4 hours in last 42 hours and still alive enough to live without water, the vitamin water :p
Anyways, a few secs back I lost my mind while switching amongst a number of OS instances, thanks to VirtualBox. So, I drew this to clarify things to myself:











Looks good :D

Friday, April 25, 2008

Python Streamlines Space Shuttle Mission Design

This article was published on Builder.com, and I read it here: http://www.python.org/about/success/usa/

Introduction
Software engineers have long told their bosses and clients that they can have software "fast, cheap, or right," as long as they pick any two of those factors. Getting all three? Forget about it!
But United Space Alliance (USA), NASA's main shuttle support contractor, had a mandate to provide software that meets all three criteria. Their experience with Python told them NASA's demands were within reach. Less than a year later, USA is nearing deployment of a Workflow Automation System (WAS) that meets or exceeds all of NASA's specifications.

"Python allows us to tackle the complexity of programs like the WAS without getting bogged down in the language," says Robin Friedrich, USA's Senior Project Engineer. Friedrich conceived of the WAS project in response to a significant gap in the way shuttle mission planning was handling data management. "Historically," Friedrich says, "this data has been communicated using paper and, more recently, data file exchange. But both of these approaches are error-prone. Catching and fixing errors as well as responding to frequent change requests can bog such a system down." Complicating the issue was the challenge of finding money to improve the flight design process in an era of declining budgets for space activities.

"Just in time" provides a solution--and more problems
USA decided they needed a way to "minimize data changes and the resulting rework." The shortest route to that goal would be to shift the design work to the end of the process so that flight characteristics would have a good chance of already being finalized. In other words, as Friedrich says, "We decided we needed to do this data management work 'just in time'."
A just-in-time solution, however, generally puts more stress on both people and systems to get things right the first time because postponing these activities to the end of the process means a loss of scheduling elasticity.

"The obvious answer," according to Friedrich, "was to create a central database repository to help guarantee consistency and to provide historical tracking of data changes." An Oracle database was designed to store the information, but a graphical front end to manage the process of workflow automation was clearly an essential component of an effective solution. "We knew from experience--we do a good bit of Java coding in our group--that using C++ or Java would have added to the problem, not the solution," Friedrich maintains.

Python a mainstay since 1994

Enter Python. "We'd been using Python since 1994," says Friedrich, "when I literally stumbled across Python as I was searching the pre-Web Gopher FTP space for some help with a C++ project we were doing." Being an inveterate systems engineer, Friedrich "just had to investigate it." He was stunned by what he discovered.

"Twenty minutes after my first encounter with Python, I had downloaded it, compiled it, and installed it on my SPARCstation. It actually worked out of the box!"

As if that weren't enough, further investigation revealed that Python has a number of strengths, not the least of which is the fact that "things just work the first time. No other language exhibits that trait like Python," says Friedrich.

He attributes this characteristic to three primary language features:

  • Dynamic typing
  • Pseudocode-like syntax
  • The Python interpreter

The result? "We achieve immediate functioning code so much faster in Python than in any other language that it's staggering," says Friedrich. "Java and C++, for example, have much more baggage you have to understand just to get a functioning piece of software.

"Python also shines when it comes to code maintenance," according to Friedrich. "Without a lot of documentation, it is hard to grasp what is going on in Java and C++ programs and even with a lot of documentation, Perl is just hard to read and maintain." Before adopting Python, Friedrich's team was doing a good bit of Perl scripting and C++ coding. "Python's ease of maintenance is a huge deal for any company that has any significant amount of staff turnover at all," says Friedrich.

The team had already developed a moderately large number of C++ libraries. Because of Python's easy interface to the outside world, USA was able to retain these libraries. "We wrote a grammar-based tool that automatically interfaced all of our C++ libraries," says Friedrich.
Another aspect of Python that Friedrich found eminently significant is its shallow learning curve.

"We are always under the gun on software projects, like everyone else," he says. "But for any programmer, picking up Python is a one-week deal because things just behave as you expect them to, so there's less chasing your tail and far more productivity." He contrasts that with C++ and Java, which he says takes a good programmer weeks to grasp and months to become proficient.

Friedrich says that even the non-programming engineers at USA learned to do Python coding quickly. "We wanted to draft the coding energy of the engineering staff, but we didn't want them to have to learn C++. Python made the perfect 4GL programming layer for the existing C++ classes."

One coder and 17,000 lines of code later
The WAS project, which has required somewhat less than a man-year of effort, has been coded by a single Senior Software Engineer, Charlie Fly, who has cranked out some 17,000 source lines of code (SLOC). Python plays the central role, managing data interactions and the task network, as shown in Figure A.

Figure A: Python plays a central role in data interaction.

In the system, user tasks communicate with a Python data server, which in turn connects to an Oracle server via DCOracle. Using Oracle's built-in trigger mechanism to send a message to WAS as data records are updated, the WAS calculates which tasks are now data-ready and notifies the appropriate user.

At the core of the design is the Task object, which stores all information relevant to a single task in the workflow network. The end user can view the network in a PERT-style chart layout (Figure B), where color coding reveals at a glance which tasks are finished, which are in process, and which have not yet been started.

Figure B: PERT-style layout

Two other graphical interface windows allow the user to manage the dependencies among data items in the network (Figure C) and to view and edit individual task details (Figure D).

Figure C: Interface 1


Figure D: Interface 2

All of the code for the UIs was also done in Python, using the popular Tkinter library along with an open source package of supporting modules. Tkinter is included in all standard Python installations.

"USA is pleasantly surprised by how much quality software we can deliver," Friedrich says. "And each time we demonstrate success with Python, we add a few more believers to my growing list!"

About the Author

Dan Shafer is a freelance author and sometime Python coder who hangs out on California's central coast. He is a member of the PythonCard Open Source development team creating a GUI-building framework for Python applications. He makes his living as a writer and a product development consultant. A founder and former editorial director of Builder.com, Shafer has been part of the Web development community almost from its inception.

Sunday, April 20, 2008

Compiled versus interpreted languages

During the design of an application, you might need to decide whether to use a compiled language or an interpreted language for the application source code.

Both types of languages have their strengths and weaknesses. Usually, the decision to use an interpreted language is based on time restrictions on development or for ease of future changes to the program. A trade-off is made when using an interpreted language. You trade speed of development for higher execution costs. Because each line of an interpreted program must be translated each time it is executed, there is a higher overhead. Thus, an interpreted language is generally more suited to ad hoc requests than predefined requests.

Advantages of compiled languages
Assembler, COBOL, PL/I, C/C++ are all translated by running the source code through a compiler. This results in very efficient code that can be executed any number of times. The overhead for the translation is incurred just once, when the source is compiled; thereafter, it need only be loaded and executed.

Interpreted languages, in contrast, must be parsed, interpreted, and executed each time the program is run, thereby greatly adding to the cost of running the program. For this reason, interpreted programs are usually less efficient than compiled programs.
Some programming languages, such as REXX™ and Java™, can be either interpreted or compiled.

Advantages of interpreted languages
There are reasons for using languages that are compiled and reasons for using interpreted languages. There is no simple answer as to which language is "better"—it depends on the application. Even within an application we could end up using many different languages. For example, one of the strengths of a language like CLIST is that it is easy to code, test, and change.

However, it is not very efficient. The trade-off is machine resources for programmer time.
Keeping this in mind, we can see that it would make sense to use a compiled language for the intensive parts of an application (heavy resource usage), whereas interfaces (invoking the application) and less-intensive parts could be written in an interpreted language. An interpreted language might also be suited for ad hoc requests or even for prototyping an application.

One of the jobs of a designer is to weigh the strengths and weaknesses of each language and then decide which part of an application is best served by a particular language.

[source: http://publib.boulder.ibm.com/infocenter/zoslnctr/v1r7/index.jsp?topic=/com.ibm.zappldev.doc/zappldev_85.html]

Recovering OpenSolaris/Solairs/Linux after Windows Installation

I was running a dual boot configuration with two OSes: Windows XP and Solaris XDE 01/08. I upgraded my system memory but I couldn't visualize the performance difference. This, and a few other reasons made me to opt for a fresh Windows XP installation.

As usual, Windows wiped out the MBR and set it's own partition as active. Following this, I lost my GRUB bootloader and hence the option to boot into Solaris. I played and searched around a little bit and found a couple of good tweaks to recover a Solaris/OpenSolaris boot option, or a Linux boot option by actually recovering the GRUB bootloader.

Recovering GRUB for Linux is different then doing the same for Solaris. Generally Linux installation updates the MBR to load the GRUB, but a Windows installation cleans this MBR. To recover it follow this:
  • Get a live CD of your Linux Distribution,
  • Boot the Linux from this CD,
  • Open a Terminal,
  • Get into GRUB by typing this: sudo grub
  • Then you need to know abou the sequence number of your previous Linux partition (if you don't remember this, you can get an idea from Windows disk management utility).
  • Once you are sure about it, type this if it was the first partiton: root (hd0,0)
    or this if it was second partition on the second harddisk: root (hd0,1)
  • Finally type this: setup (hd0)

You're done!

For Solaris/OpenSolaris, Follow this procedure:
  • Get a OpenSolaris Installation Disk,
  • Boot from CD,
  • type 'c' at boot menu to get the GRUB command line,
  • Type this: rootnoverify (hdX,Y)
    replace X by hdd number, and Y by the sequence number of partition where Solaris is installed. e.g. rootnoverify (hd0,0) for first harddisk and first partition.
  • Now make the Solaris partition active. Type this: makeactive
  • Now chainload the bootsect, which implies that the GRUB bootloader, which is installed through your Solaris will be loaded when you'll startup your system.
  • To do this, type the following: chainloader +1
  • Finally type: boot

You're done!

Friday, April 18, 2008

Got ticketed!!

[1:15 AM 18th Aril, 2008, Cavalier Court, Fairfax, VA, USA - 0.2 miles from my home]

Waqas: Hello officer, I am sorry this guy (me) is sick, dying, (me: laffing, waqas: shutup) and in emergency I missed the left turn, so had to reverse on the main road.
Officer: Your documents Sir.
Waqas: (punjabi) saaala *** .. mar diya, shit, my points, my first ever.., damn *** ****
Officer: Sir, do u know y I pulled u over?
(Waqas thinking): thinking of giving him a topi after realizing that reversing the car might not be the reason for the devil to appear from nowhere; while playing confident that rest all was ok.
Waqas: No, I don't know, you tell me please.
(Salman whispering): abay stay true, he is playing with us.
Officer: Ohkk.
Officer: Do you know the max. speed of this highway?
Waqas: (innocent liar) No.
Officer: 30 mph, and u were on 47 mph, as of my speed gun. Secondly, this is the highway and you reversed your car on it while there was a car on your back (cop's car).
Waqas: Oh I am sorry, we were in emergency this guy.., these tablets.., his face.., we are students.., (Allah teray bachay..)
Officer: Please wait Sir, and went back with all docs.
Waqas: (punjabi) *** saaala **** .. mar diya, shit, my points, my first ever.., damn *** ****
(after 5-10 minutes)
Officer: there you go, you may prepay, or njoy the court.
Officer: thank you Sir.
Salman: good experience yar :D
Waqas: (punjabi) *** saaala **** .. mar diya, shit, my points, my first ever.., damn *** ****

[time 1:31 AM 18th Aril, 2008, Cavalier Court, Fairfax VA, USA - home.]

Thursday, April 10, 2008

Happy Birthday from JustLinux Forums‏

Happy Birthday from JustLinux Forums‏
From: JustLinux Forums (jpalermo@jupitermedia.com)
Sent: Fri 4/11/08 12:02 AM
To: salmanj_85@hotmail.com

Hello addicted, We at JustLinux Forums would like to wish you a happy birthday today!
-------------------------------------
even the bots care for me :p

Monday, April 07, 2008

Why Virtualization: A List of Reasons

Following are some (possibly overlapping) representative reasons for and benefits of virtualization:

Virtual machines can be used to consolidate the workloads of several under-utilized servers to fewer machines, perhaps a single machine (server consolidation). Related benefits (perceived or real, but often cited by vendors) are savings on hardware, environmental costs, management, and administration of the server infrastructure.

The need to run legacy applications is served well by virtual machines. A legacy application might simply not run on newer hardware and/or operating systems. Even if it does, if may under-utilize the server, so as above, it makes sense to consolidate several applications. This may be difficult without virtualization as such applications are usually not written to co-exist within a single execution environment (consider applications with hard-coded System V IPC keys, as a trivial example).

Virtual machines can be used to provide secure, isolated sandboxes for running untrusted applications. You could even create such an execution environment dynamically - on the fly - as you download something from the Internet and run it.

You can think of creative schemes, such as those involving address obfuscation.

Virtualization is an important concept in building secure computing platforms.

Virtual machines can be used to create operating systems, or execution environments with resource limits, and given the right schedulers, resource guarantees. Partitioning usually goes hand-in-hand with quality of service in the creation of QoS-enabled operating systems.

Virtual machines can provide the illusion of hardware, or hardware configuration that you do not have (such as SCSI devices, multiple processors, ...) Virtualization can also be used to simulate networks of independent computers.

Virtual machines can be used to run multiple operating systems simultaneously: different versions, or even entirely different systems, which can be on hot standby. Some such systems may be hard or impossible to run on newer real hardware.

Virtual machines allow for powerful debugging and performance monitoring. You can put such tools in the virtual machine monitor, for example. Operating systems can be debugged without losing productivity, or setting up more complicated debugging scenarios.

Virtual machines can isolate what they run, so they provide fault and error containment. You can inject faults proactively into software to study its subsequent behavior.

Virtual machines make software easier to migrate, thus aiding application and system mobility.

You can treat application suites as appliances by "packaging" and running each in a virtual machine.

Virtual machines are great tools for research and academic experiments. Since they provide isolation, they are safer to work with. They encapsulate the entire state of a running system: you can save the state, examine it, modify it, reload it, and so on. The state also provides an abstraction of the workload being run.

Virtualization can enable existing operating systems to run on shared memory multiprocessors.

Virtual machines can be used to create arbitrary test scenarios, and can lead to some very imaginative, effective quality assurance.

Virtualization can be used to retrofit new features in existing operating systems without "too much" work.

Virtualization can make tasks such as system migration, backup, and recovery easier and more manageable.

Virtualization can be an effective means of providing binary compatibility.

Virtualization on commodity hardware has been popular in co-located hosting. Many of the above benefits make such hosting secure, cost-effective, and appealing in general.

Virtualization is fun.

Plenty of other reasons ...

[source: http://www.kernelthread.com/publications/virtualization/]

Microsoft's $40 Billion Question

Here are a few suggestions for what else Microsoft could get for $40 billion:

--Hire 40,000 engineers, at $100,000 apiece, for a decade

--Acquire Facebook (estimated to have a market value of $15 billion), along with just about any other meaningful social networking site, including MySpace, Bebo, Hi5 and LinkedIn. There would still be enough money left over to pay some consultants to help with integration.

--Spend eight times more than Google did last year to acquire traffic--and presumably make traffic more pricey for Google, to boot.

--Hire 80 million workers in China to do nothing but click on Microsoft properties and related ads for 10 years.

--Promise a free Big Mac to everyone who clicks on a Microsoft ad--and give away 14 trillion of 'em.

[source: http://www.forbes.com/technology/2008/04/07/microsoft-yahoo-acquisition-tech-ebiz-cx_wt_0407msft.html]

Wednesday, April 02, 2008

Growth of Programming Languages (TIOBE index)


[source: http://www.tiobe.com/index.php/content/paperinfo/tpci/index.html]

50 who matter now

1 You! The consumer as creator
2
Sergey Brin and Larry Page Co-founders, Google
3
Paul Jacobs CEO, Qualcomm
4
Rupert Murdoch CEO, News Corp.
5
Steve Jobs CEO, Apple Computer
6
Susan Desmond-Hellmann President of product development, Genentech
7
The Emerging Global Middle Class China, India, Russia, Brazil, and elsewhere
8
Fujio Cho Chairman, Toyota
9
The New Oil Despots King Abdullah bin Abdul aziz al Saud (Saudi Arabia), Mahmoud Ahmadinejad (Iran), Hugo Chavez (Venezuela), and Vladimir Putin (Russia)
10
Ray Ozzie Chief technical officer, Microsoft
11
Marc Benioff CEO, Salesforce.com
12
Robert Iger CEO, Walt Disney Co.
13
Stewart Butterfield and Caterina Fake Co-founders, Flickr
14
Brian McAndrews CEO, aQuantive
15
Jack Ma CEO, Alibaba.com
16
Barry Diller CEO, InterActiveCorp
17
Ed Zander CEO, Motorola
18
John Thompson CEO, Symantec
19
Mark Hurd CEO, Hewlett-Packard
20
Ben Bernanke Chairman, Federal Reserve Board
21
Bill Gates Benefactor, Bill and Melinda Gates Foundation
22
Reid Hoffman Angel investor and CEO, LinkedIn
23
The New New Media Kevin Rose (Digg) and Jimmy Wales (Wikipedia)
24
Patricia Woertz CEO, Archer Daniels Midland
25
Kevin Martin Chairman, Federal Communications Commission
26
Ed Whitacre Chairman and CEO, AT&T
27
Jeremy Allaire CEO, Brightcove
28
Chad Hurley and Steven Chen Co-founders, YouTube
29
Danny Rimer General partner, Index Ventures
30
Muhammad Yunus Founder, Grameen Bank
31
Greg Isaacs Director of developer relations, eBay
32
Alex Bogusky Creative director, Crispin Porter & Bogusky
33
Vinod Khosla Founder, Khosla Ventures
34
David Heinemeier Hansson Partner, 37signals
35
Tim O'Reilly Founder and CEO, O'Reilly Media
36
Janus Friis and Niklas Zennström Co-founders, Skype
37
Patricia Russo CEO, Lucent Technologies
38
Oprah Winfrey Entertainment mogul
39
Electronic Frontier Foundation
40
Jeff Valdez Founder, SiTV
41
Stephen Maurer and Andrej Sali Adjunct associate professor, University of California at Berkeley, and professor, University of California at San Francisco
42
Jeff Bezos CEO, Amazon.com
43
The Pre-Internet Dinosaurs Larry Ellison (Oracle), Paul Otellini (Intel), and Michael Dell (Dell)
44
William McDonough Architect, William McDonough & Partners
45
Richard Branson Chairman, Virgin Group
46
Mike Morhaime Co-founder and president, Blizzard Entertainment
47
Nick Denton Publisher, Gawker Media
48
Naguib Sawiris CEO, Orascom Telecom
49
David Allen Author, Getting Things Done
50
Blake Krikorian Co-founder and CEO, Sling Media

[source : http://money.cnn.com/magazines/business2/peoplewhomatter/index.html]

Wednesday, March 05, 2008

Researchers turn Sun Solaris utility into fuzzing tool

Security researchers have developed a way to turn a utility for Sun Microsystems' Solaris operating system into a rootkit-like, reverse engineering tool that can be deployed to quickly locate application vulnerabilities and create exploits.

The utility, DTrace, is a dynamic tracing, or event logging, function within the Solaris OS that allows systems administrators to monitor a combination of functions, including system performance, statistic debugging information and execution analysis.

Sun designed DTrace to provide operational insights that allow systems administrators to tune and troubleshoot applications and the operating system itself.

Sun released DTrace in 2003 in conjunction with Solaris 10. In 2005, Sun made it available under the Common Development and Distribution License (CDDL) open source license. Apple has since integrated it into its Mac OS X Leopard platform.

The security researchers, Tiller Beauchamp and David Weston, who work at engineering firm Science Applications International Corp. (SAIC), unveiled their findings at the recent Black Hat conference in Washington D.C.

They explained that DTrace provides a framework for performance observability and debugging in real time. With DTrace, system administrators can set probes within their operating environment, then define a metric they want to measure or record.

The tool's ability to take an in-depth look at the operating system and its applications make it ideal not only for reverse engineering, but also for building exploits, the researchers said at Black Hat. Watson called DTrace a friendly programming rootkit that lets you see everything within the operating environment.

One of the key functions of DTrace is its ability to allow automating tasks that would otherwise be manually intensive, Beauchamp said. “If you're sending input to an application to trigger a vulnerability, you can have DTrace alert you when input has reached a vulnerable function. It basically takes a large amount of time off inspecting a vulnerability because it can be programmatically controlled.”

DTrace is a great platform as is, Weston added. “But we were interested primarily in a reverse-engineering tool, and DTrace is missing the ability to set conditions that would allow reverse-engineering an application to discover vulnerabilities."

While DTrace is not destructive by itself, combined with other utilities it can cause damage. For instance, it can be manipulated to perform "snooping" operations, such as stealing a user's keystrokes without their knowledge, exactly like a keystroke logger, the researchers said at Black Hat.

Beauchamp and Weston said they have developed a DTrace-based toolkit called RE:Trace. Working with Sun's Chris Andrews, they created a library of routines in a language called Ruby, they told SCMagazineUS.com. With Ruby, they were able to give DTrace a number of capabilities it lacked, including object-oriented programming and expressionals.

Beauchamp and Weston called RE:Trace a “high-level” application programming interface (API) that includes sample scripts. These help not only debug vulnerabilities within applications, but write exploits for them as well, Beauchamp and Weston said.

[Source: SC Magazine - Actual article link]

Friday, February 29, 2008

Solaris Threading Model

I was looking for a detailed account of Solaris Kernel's architecture, specifically the threading model, and I found this book Solaris Internals. The one I have talks about Solaris 7's architecture. Now I believe that minute architectural details change frequently in Solaris because of the aggressive involvement of the OpenSolaris community. So, I might not be up to date with whatsoever I will discuss about here.

The basic execution unit in Solaris is a Process. Each process has its own Virtual Memory/Machine Environment. Now this environment is nothing more than a name given collectively to objects associated with a process, e.g. the address space, global variables, open files, accounting information etc. Such an environment isolates the process from other processes in the system which are apparently running concurrently.

By default, each process has atleast one thread of execution which is the default main thread. And, each Solaris process can have multiple threads, where all the threads share the same Virtual Memory environment of that process. The kernel uses time-slicing to allocate the CPU to these process threads, and once a process is taken off a CPU, its complete execution environment consisting of per thread items(program counter, stack, registers etc) are saved so that the thread can be resumed at some later time.

Now, in Solaris, Kernel threads execute on the CPU. Kernel threads are different from the User or Process threads in the sense that there creation and management is a responsibility of the kernel itself, and not some threading api. So now, we have discussed Kernel Threads and the thread contained by a process. Before discussing the threading model, it's better to talk about one more dimension of threads in Solaris. The Solaris kernel is multithreaded - "it is implemented with multiple threads of execution to allow concurrency across multiple processors". Such a kernel allows concurrent access to itself to improve performance on a multiprocessor system.

Wednesday, February 20, 2008

Troubleshooting SXDE installation and initial setup

Where SXDE is Solaris Express Developer Edition. In the following discussion, I am talking about Solaris Express Developer Edition 02/08, while using the word Solaris or OS.

During the last week's few nights, I struggled to pump up my Solaris as a competitve alternative to my existing Windows XP. However, I failed. Unexpectedly, I faced certain problems which I never had with most of the linux distros I ever installed.

First Problem: Solaris can't be installed on Extended Logical Partition.

I am not sure about the current status but, while googling it I found this to be declared as a bug, which was being taken care of back in 2006. I expected it to be resolved by 2008 however, I wasn't able to even look at the free space available within the extended logical partition in the Parition Manager, while installing Solaris.

Solution: Now since Windows XP don't allow you to have more than 3 primary partitions, I had to delete one from my machine. Once I did that, I had 5 gb free, but I required 20GB which is recommended for a smooth Solaris installation. Anyways, I wsa able to MOVE/RESIZE my extended logical parition to the point that the 15GB free space poped out of this extended partition, and I finally had 15+5 GB able to be used as a Primary Partition. That was it, I was done by using those 20GB to create a 'Solaris' Partition.

Second Problem: Wireless Internet connection not working.

I have a Dell Inspiron e1505, with a Dell 1390 Wireless Minicard. I assumed Solaris capable enough to do some sort of driver detection to get that thing running automatically, but it wasn't as simple. For certain reasons, I had to use Solaris NDIS(Network Driver Interface Specification) Wrapper Toolkit. This toolkit somehow makes use of the native binary Windows drivers of wifi cards to be used in Solaris. Also, one sort of limitation was that a 32 bit windows

driver can only be used in 32bit Solaris and not in 64Bit Solaris. Here, I was stucked again. By default, the installed Solaris was 64-bit Edition. And, there were no 64bit drivers for my Wifi card.

So, there was a grub-based workaround that I found in carlton's guide to boot up the 32 bit Solaris. All you have to do is to goto /boot/grub and edit the file menu.lst as follows:

Since I had a previous Windows XP Installation, I was able to find the string "title Windows" in the menu.lst file. Right above it, append (add) the following:

title Solaris Express Developer Edition 02/08 (32 Bits)
kernel$ /platform/i86pc/kernel/unix
module$ /platform/i86pc/boot_archive

Once done, restart the pc, and select this GRUB option from the boot menu to boot the 32 bit version of Solaris. Now you are ready to lookout over the internet for the 32 bit driver for you wifi card. So, find one. I got mine at dell.com. In that driver package, only 2 files were required by NDIS toolkit, which were:

bcm32.inf file (ASCII text file) - It contains information that tells the Windows installer what devices this driver supports and what registry keys should be created to control driver's configuration.

bcm32.sys file (binary file) - This file contains the actual driver executable code in Windows Portable Executable (PE) format.

You also need the NDIS Wrapper Toolkit which can be downloaded from here. Now, I won't rewrite the steps I did as I followed nothing more than what Carlton's little guide talks about. It's comprehensible and straight forward.

But finally, after doing it all, I was again troubled with 3 more problems:

1- I was ONLY able to access the www using IPs and not the domain names, for e.g. I could access Google if I type http://64.233.167.147 at the browser. But,

I couldn't access the same if I type http://www.google.com. I resolved this by making a little change in /etc/nsswitch.conf file. I changed the 'hosts: files' to 'hosts: files dns'(more on this). And that was it.

2- I couldn't sort out to activate the wifi connection automatically on startup. Although I have checked the same option in Networks Panel but, it helping me out.
3- Sometimes, the connection is lost when I play around with and apparently the only solution then turns out to be a system restart.

Wednesday, February 13, 2008

LLVM 2.2

Where LLVM stands for Low Level Virtual Machine.
I found about it while skimming through slashdot.

As of Wikipedia,
"The Low Level Virtual Machine, generally known as LLVM, is a compiler infrastructure, written in C++, which is designed for compile-time, link-time, run-time, and "idle-time" optimization of programs written in arbitrary imperative programming languages. The LLVM project started in 2000 at the University of Illinois at Urbana-Champaign."

As of Slashdot,
".. This is the thirteenth public release of the open-source compiler that started as a GCC fork. LLVM supports several aggressive optimizations, in compile-, link- and run-time, and often produces faster (1.5-3x) code than GCC. It is also much faster than GCC at compiling (despite the slow link-time optimizations). Gentoo users are already trying to build the whole system with the LLVM toolchain to get the extra performance bit."

Few features of LLVM as listed on its homepage are,

  • Front-ends for C and C++ based on the GCC 3.4 and 4.0.1 parsers. They support the ANSI-standard C and C++ languages to the same degree that GCC supports them. Additionally, many GCC extensions are supported. LLVM also includes a front-end for "Stacker", a Forth-like language.
  • A stable implementation of the LLVM instruction set, which serves as both the online and offline code representation, together with assembly (ASCII) and bytecode (binary) readers and writers, and a verifier.
  • A powerful pass-management system that automatically sequences passes (including analysis, transformation, and code-generation passes) based on their dependences, and pipelines them for efficiency.
  • A wide range of global scalar optimizations.
  • A link-time interprocedural optimization framework with a rich set of analyses and transformations, including sophisticated whole-program pointer analysis, call graph construction, and support for profile-guided optimizations.
  • An easily retargettable code generator, which currently supports X86, X86-64, PowerPC, PowerPC-64, ARM, Thumb, SPARC, Alpha, and IA-64.
    A Just-In-Time (JIT) code generation system, which currently supports X86, X86-64, PowerPC and PowerPC-64.
  • Support for generating DWARF debugging information.
  • A C back-end useful for testing and for generating native code on targets other than the ones listed above.
  • A profiling system similar to gprof.
  • A test framework with a number of benchmark codes and applications.
  • APIs and debugging tools to simplify rapid development of LLVM components

Where strengths being,

  • LLVM uses a simple low-level language with strictly defined semantics.
  • It includes front-ends for C, C++, and Stacker (a forth-like language). Front-ends for Java, Scheme, and other languages are in development.
  • It includes an aggressive optimizer, including scalar, interprocedural, profile-driven, and some simple loop optimizations.
  • It supports a life-long compilation model, including link-time, install-time, run-time, and offline optimization.
  • LLVM has full support for accurate garbage collection.
  • The LLVM code generator is relatively easy to retarget, and makes use of a powerful target description language.
  • LLVM has extensive documentation and has hosted many projects of various sorts.
    Many third-party users have claimed that LLVM is easy to work with and develop for. For example, the Stacker front-end was written in
    4 days by someone who started knowing nothing about LLVM. Additionally, LLVM has tools to make development easier.
  • LLVM is under active development and is constantly being extended, enhanced and improved. See the status updates on the left bar to see the rate of development.
  • LLVM is freely available under an OSI-approved "three-clause BSD" license.
  • LLVM is currently used by several commercial entities, who contribute many extensions and new features.

And the intended users include,

  • A compiler researcher interested in compile-time, link-time (interprocedural), and runtime transformations for C and C++ programs.
  • A virtual machine researcher/developer interested in a portable, language-independent instruction set and compilation framework.
  • An architecture researcher interested in compiler/hardware techniques.
  • A security researcher interested in static analysis or instrumentation.
  • An instructor or developer interested in a system for quick prototyping of compiler transformations.
  • An end-user who wants to get better performance out of your code.

[sources: http://developers.slashdot.org/article.pl?no_d2=1&sid=08/02/12/1431222, http://llvm.org/Features.html, Wikipedia]

Tuesday, February 12, 2008

Bill Clinton at George Mason




Bill Clinton at our campus (George Mason University, Fairfax), supporting Hillary's presidential campaign..

Thursday, February 07, 2008

Mac hack contest

One year after Mac hack contest, Linux & Vista may be tested
IDG News Service 2/6/08Robert McMillan, IDG News Service, San Francisco Bureau

One year after launching a controversial Macintosh hacking contest, the promoters of the CanSecWest security research conference are thinking about giving hackers another shot at cracking the Mac. Only this time, they're looking to broaden the field.

Last year, show organizers invited attendees to hack into a Macintosh laptop, with the successful hacker winning the computer and a cash prize. But this year they're talking about giving attendees three targets to choose from. "We're thinking of having a contest where we have Vista and OS X and Linux ... and see which one goes first," said Dragos Ruiu, the principal organizer of CanSecWest.

Last year, security researcher Dino Dai Zovi spent a sleepless night hacking his Mac in order to take the prize at the show's first PWN to OWN contest. Dai Zovi found a QuickTime bug that allowed him to run unauthorized software on the Mac once the computer's browser was directed to a specially crafted Web page.

Dai Zovi split the contest prize with a friend at the show, Shane Macaulay, who helped him pull off his attack. Macaulay got to keep the Macbook Pro while Dai Zovi pocketed the US$10,000 put up by 3Com's Tipping Point division in exchange for technical details on the bug.

It turned out that the QuickTime bug affected the Windows operating system too, but Ruiu said that Dai Zovi's hack helped change the way the industry thinks about the Mac OS, which has a reputation for being far more secure than Windows. "We were trying to point out that there was a security issue with Mac stuff here, and everybody was trying to play ostrich."

Ruiu and Dai Zovi say that last year's contest helped kick off a flurry of Mac-related security research, but according to TippingPoint Manager of Security Response Terri Forslof, it also illustrated a security industry truism: "Given enough time and motivation, everything can be broken," she said. "When TippingPoint agreed to purchase whatever vulnerability was used to win the contest for $10,000, it added an appropriate level of motivation. That's how it works."

Shortly after last year's contest, Gartner published a research paper warning that such challenges are "risky endeavors" that could put sensitive vulnerability information out in the public domain.

That hasn't stopped CanSecWest from pressing forward with this year's event.

Ruiu isn't certain that he'll run the three-way hacking contest this year. That's because he also has a grander, top-secret hacking contest idea that may or may not pan out, he said.

Either way, he promised "an interesting spectacle."

Bob McMillan is Senior writer for the IDG News Service.
[source: http://security.itworld.com/4341/mac-hack-contest-080206/page_1.html]

Saturday, February 02, 2008

OpenSolaris Concern: Virtualization

If we can identify 3 facets of virtualization of an underlying hardware as
- virtualization to Isolate a 'process' from other processes,
- something that can monitor status of and activities within a virtual machine, and
- being a guest or being a host operating system,

then,
- OpenSolaris has Zones and Branded Zones which provide "protected and virtualized OS environment within an instance of Solaris, allowing one or more processes to run in isolation from other activity on the system', and they "enable kernel and user mode development of Solaris and Linux applications without impacting developers in seperate zones".

- OperSolaris also supports Xen, which is "an open-source virtual machine monitor", and

- OpenSolaris is available as a guest operating system for VMWare. (Get Started)

[source: OpenSolaris - Student Guide]

SXDE Installation Guide: Laptop Installations

Where SXDE is Solaris Express Developer Edition.
The Student Guide titled as "Introduction to Operating Systems: A hands-on approach using the OpenSolaris Project" referred to the following link for installation of SXDE on Laptops:
Solaris Express Developer Edition Installation Guide: Laptop Installations

Since I couldn’t love it by just running it within a virtual machine, I am following these guidelines to install it as another operating system on my machine.

Friday, February 01, 2008

Thinking of a switch? think OS.

Where OS is OpenSolaris.
I am taking Advance Operating Systems course in spring08 semester with Dr. Harry Foxwell at George Mason University. Two things convinced me to get into this class: the professor's profile, and an opportunity to get out of closed Windows..

He is kind of an AIO individual, being an ex-soccer referee, a Vietnam veteran, Senior System Engineer at Sun Microsystems, and an adjunct professor here at GMU, which seemed interesting at a glance.

Then, I remember the references made to Solaris' implementation during my Operating Systems class as being competitive with the contemporary systems, if not any better. I also knew Solaris is based on Unix. And literally, this was the only information I had before taking the first class of this course.

I want to track my progress in learning it, and this text serves the purpose of being the appetizer post. As I will try to gradually fill up my stomach with more *nix-based stuff, I'll try to keep this blog in shape perfected with my knowledgebase.

As of now, I have successfully installed Solaris 10 (commercial version) on VMware Server version 1.0.4, which was a piece of cake while partly following HOW TO INSTALL SUN SOLARIS INSIDE VMWARE WORKSTATION 5.5

But, I feel like I am lacking hardware resources on my inspiron e1505 notebook to enjoy its full capacity. Following up, I downloaded 3 DVDS of Solaris Express Developer Edition 09/07 from opensolaris.org, and burned them.

And yes, I was thinking of a switch, and I'll love one such to OS, if it's supporting my coursework!