Wednesday, August 15, 2012

TIOBE Programming Community Index for August 2012




Microsoft's C# programming language shows a downward trend for 8 months now. What is happening? On the one hand C# is generally recognized as the enterprise language with most modern and expressive features available today and C# has shown more downward trends in the past and always recovered from this. But, Microsoft announced recently the revival of C++ (in favor of C#) within its company. C# appeared to be too high level to build high performance systems. This is confirmed by what we see happening to TIOBE's embedded software customers: after years of enthusiastic adoption of C#, there is now no significant growth any more. Let's see what happens to C# the next few months.

The TIOBE Programming Community index is an indicator of the popularity of programming languages. The index is updated once a month. The ratings are based on the number of skilled engineers world-wide, courses and third party vendors. The popular search engines Google, Bing, Yahoo!, Wikipedia, Amazon, YouTube and Baidu are used to calculate the ratings. Observe that the TIOBE index is not about the best programming language or the language in which most lines of code have been written.

The index can be used to check whether your programming skills are still up to date or to make a strategic decision about what programming language should be adopted when starting to build a new software system. The definition of the TIOBE index can be found here.



1  C 18.937% +1.55% A
2  Java 16.352% -3.06% A
3  Objective-C 9.540% +4.05% A
4  C++ 9.333% +0.90% A
5  C# 6.590% +0.55% A
6  PHP 5.524% -0.61% A
7  (Visual) Basic 5.334% +0.32% A
8  Python 3.876% +0.46% A
9  Perl 2.273% -0.04% A
10  Ruby 1.691% +0.36% A
11  JavaScript 1.365% -0.19% A
12  Delphi/Object Pascal 1.012% -0.06% A
13  Lisp 0.975% +0.07% A
14  Visual Basic .NET 0.877% +0.41% A
15  Transact-SQL 0.849% +0.03% A
16  Pascal 0.793% +0.13% A
17  Lua 0.726% -0.64% A--
18  Ada 0.649% -0.05% B
19  PL/SQL 0.610% +0.08% B
20  MATLAB 0.533% +0.09% B
21 Bash 0.525%
22 SAS 0.525%
23 Assembly 0.502%
24 RPG (OS/400) 0.476%
25 Logo 0.441%
26 Fortran 0.440%
27 R 0.435%
28 COBOL 0.432%
29 ABAP 0.431%
30 Scheme 0.424%
31 Prolog 0.334%
32 Scratch 0.332%
33 D 0.322%
34 Haskell 0.301%
35 NXT-G 0.285%
36 JScript.NET 0.267%
37 Erlang 0.259%
38 Awk 0.256%
39 Smalltalk 0.241%
40 Scala 0.241%
41 Common Lisp 0.238%
42 Forth 0.231%
43 APL 0.223%
44 ML 0.221%
45 ActionScript 0.179%
46 OpenEdge ABL 0.172%
47 Algol 0.167%
48 C shell 0.166%
49 Alice 0.160%
50 PL/I 0.158%

I Am Not Yours




I am not yours, not lost in you,
Not lost, although I long to be
Lost as a candle lit at noon,
Lost as a snowflake in the sea.

You love me, and I find you still
A spirit beautiful and bright,
Yet I am I, who long to be
Lost as a light is lost in light.

Oh plunge me deep in love -- put out
My senses, leave me deaf and blind,
Swept by the tempest of your love,
A taper in a rushing wind.


                                  -by Sara Teasdale.

Human Health: Liver Health Care and Vitamins




It is a common knowledge that vitamins benefit people’s health and liver, in particular. Consider the general health tips below and you will learn about the role of vitamins in human health and liver health care.

Vitamins C (ascorbic acid), E and N are the most useful ones for healthy liver. Being antioxidants, these vitamins also enhance antitoxic function and improve immunity.

Vitamin C is a strong water-soluble antioxidant that functions both in and out of cell. Being a great source of electrons, ascorbic acid can share electrons with free radicals, thus decreasing their reactivity. Vitamin C can also protect other antioxidant from oxidation (for instance, vitamin E). Antitoxic effect of vitamin C at different liver diseases consists in stimulation of different enzyme systems in human body and, first of all, in liver. These systems are responsible for detoxication.

Protecting immune system, vitamin C helps fighting infection by fostering antibodies’ activity and activity of immune system cells (lymphocytes and macrophages).

Vitamin E also benefits liver health. It hampers and inhibits peroxidation of lipids and polyunsaturated fat acids that constitute a part of cell membrane. Reacting with phospholipids of biological membranes, vitamin E affects liver cells structure sustaining integrity and stability of intracellular membranes and hepatocyte shells.

As well as the two mentioned above vitamins, vitamin N is also an antioxidant, it captures free radicals. It is also characterized by detoxicative effect. Being a complexon, it helps cleaning the organism from mercury, arsenic, copper, thus reducing concentration of toxic products of alcohol metabolism, and reducing toxic effect of chemotherapeutical drugs.

Therefore, liver health benefits a lot from taking vitamins C, E and N. One taking them improves general health and liver health, in particular.

The Top 10 Jokes Ever | Good Humor


                             TOP 10 JOKES EVER


1.

A student is talking to his teacher.
Student: "Would you punish me for something I didn`t do?"
Teacher:" Of course not."
Student: "Good, because I haven't done my homework."

2.


A teenage girl had been talking on the phone for about half an hour, and then she hung up.

"Wow!," said her father, "That was short. You usually talk for two hours. What happened?"

"Wrong number," replied the girl.

3.


Two boys were arguing when the teacher entered the room.
The teacher says, "Why are you arguing?"

One boy answers, "We found a ten dollor bill and decided to give it to whoever tells the biggest lie."

"You should be ashamed of yourselves," said the teacher, "When I was your age I didn't even know what a lie was."

The boys gave the ten dollars to the teacher.

4.

The patient says, "Doctor, I have a pain in my eye whenever I drink tea."
The doctor says, "Take the spoon out of the mug before you drink."
mug = cupThe patient says, "Doctor, you've got to help me. Nobody ever listens to me. No one ever pays any attention to what I have to say.
The doctor says, "Next, please."

5.


A: Just look at that young person with the short hair and blue jeans. Is it a boy or a girl?
B: It's a girl. She's my daughter.
A: Oh, I'm sorry, sir. I didn't know that you were her father.
B: I'm not. I'm her mother.

6.


A: Hey, man! Please call me a taxi.
B: Yes, sir. You are a taxi.

7.


Principal: "I've had complaints about you, Johnny, from all of your teachers. What have you been doing?"
Johnny: "Nothing, sir."
Principal: "Exactly!"


8.

A: Why are you late?
B: There was a man who lost a hundred dollar bill.
A: That's nice. Were you helping him look for it?
B: No, I was standing on it.

9.

My friend said he knew a man with a wooden leg named Smith.
So I asked him, "What was the name of his other leg?"

10.

Three mice were being chased by a cat.

The mice were cornered when one of the mice turned around and barked, "Ruff! Ruff! Ruff!" The surprised cat ran away scared.

Later when the mice told their mother what happened, she smiled and said, "You see, it pays to be bilingual!"

Be Happy.!!

Tuesday, August 14, 2012

LONDON CITY WALLPAPER


New Trick to View Hidden Facebook Photos and Tabs




Last December, I posted a bit of JavaScript known as a bookmarklet that allowed you to see photo albums for any Facebook user if the album privacy settings allowed it. This highlighted an example of “security through obscurity,” since the lack of links to photos on most profiles seemed to indicate no photos could be viewed. The trick worked as advertised, though it only displayed a few albums for those who had many.

The code came from my own experiments on accessing the hidden photos. It worked quite manually, retrieving data from a particular Facebook interface and stuffing it into the current page. I figured a more elegant solution could be found by re-using the code already embedded in the page, but I had not been able to sort out all of the built-in functions.

Last night and this morning, I found what I’d been missing before, and I now present a far simpler version that gives full access to all available albums of a given user. Simply bookmark this link (right-click and choose to add a bookmark) and click the bookmark when viewing someone’s profile on Facebook.

Once again, please note that this does not in any way circumvent a user’s privacy settings. If you mark your albums as visible only to your friends, this trick will not override that setting. I do not currently know of a way to access private photo albums, and if I did find one, I would report it to Facebook. My purpose in posting this code is to prove a point, not break into users’ accounts.

Here is the new source code:

javascript:(function(){CSS.removeClass(document.body, ‘profile_two_columns’);tab_controller.changePage(“photos”);})()

As I said, much simpler! I only had to find the right commands.

But the story doesn’t end there. This new method can be very easily adapted to load other information from a user’s profile, and the new possibilities raise more privacy ramifications. Once again, the trick does not actually override any settings, but it may break some user expectations and highlight the importance of overlooked or unknown settings.

The new behavior is that once can use similar code to access the canvas pages of applications the user has interacted with, as if the user had added the application as a tab on their profile. This includes the “Boxes” tab for users who have it. From what I understand, visibility of this tab page comes from the “Privacy” box under “Edit Settings” next to each application listed in a user’s Application Settings. Such controls have often been overlooked, particularly because they may not have seemed very relevant in the past. While many users stay aware of the privacy settings on their photos and wall posts, they may not think about the content they generate in the context of applications. Often, that content has little if any privacy controls applied.

Typically, any information available on an application tab is also available through the application itself, but this technique makes it far easier to find. However, it also raises some disturbing possibilities related to application data retention, and issue I’ve noted in the past but not seen discussed much elsewhere. For example, quite a while ago (as in months to years), I used the Pieces of Flair application with my personal Facebook account, arranging various buttons on my virtual corkboard. Eventually I pared down the number of applications I had authorized, and Pieces of Flair was one I uninstalled a number of months ago. Today, however, if you use the sort of bookmarklet posted above to check my Facebook profile for a Pieces of Flair tab page, you’ll see all my virtual buttons once again.

Facebook does notify applications when a user uninstalls them, but it’s up to the developer to actually do something about the data left behind. Apparently Pieces of Flair does nothing with the data, meaning a user has to manually delete their flair before removing the application if they want to truly get rid of the content they generated. Based on my experience, many applications behave in a similar fashion. Some may argue that this behavior is similar to Facebook “deactivating” an account, but at what point should the content expire, and how many applications offer a full deletion? Such issues become matters of retention policies, and based on my past studies of whether applications even had a privacy policy, I would guess that most applications do not currently have such terms.

All of this once again highlights the current complexity of data and privacy on the Facebook Platform. Granted, dealing with third-party applications is not a simple problem to solve, and I’m not simply criticizing Facebook for failing to build a perfect system. But these issues can very easily lead to unpleasant surprises for end users, and at some point someone will have to sort them out.

IP Spoofing Attack and Defenses


IP Address: On the Internet, each computer system is identified by its IP address. The work we do on the Internet is associated with the IP address of the system we are using. We know that every request or response process on the Internet is done on packets. The basic protocol for information exchange over the Internet is TCP/IP.
TCP stands for Transmission Control Protocol and IP stands for Internet Protocol (IP). When we request a webpage or other resource from a server the request is sent in the form of a TCP/IP packet. This packet contains some information about the request, source and destination, along with the data being sent. The source and destination keeps the IP address of the sender and receiver.
What is IP spoofing: IP spoofing is the process of replacing the source IP address with a fake IP address from the IP packets to hide the real identity of the sender. The source address is the address of the computer that the packet was sent from. By changing the address in the packet an attacker can make it appear that the packet was sent by a different computer system.






Figure 1: IP spoofing
See the above figure. Two computers, victim and partner, were communicating with each other. In the meantime, a sender (the attacker) also tries to communicate with the victim by forging the IP address and tries to fool the victim with the fake IP address of the partner. So the victim computer thinks that the packets came from the partner computer while we can see the original sender is the sender system which in this case is the attacker.
The term spoofing is also sometimes used to refer to header forgery because attacker forges the header of the packets with fake information.
This process is used to send fake mail, requests or other information with a fake IP address to mislead others about the information being sent. Hackers often use IP spoofing for sending spam mail and denial of service attacks. This protects the real identity of the hacker because the IP address sent with the packet belongs to someone else. When a machine replies to a spoofed packet, the response is sent back to the forged source address. So IP spoofing is used in an attack when the attacker does not care about the response.
How it works
Internet Protocol (IP) Packets
Internet Protocol is a network protocol operating at Layer 3 (network layer) of the OSI model. Each IP packet sent contains a header with the data. The header contains some information about the sender, receiver, and other things.

Figure 2: IP packet
The header part contains additional information including the IP address of sender and receiver. The data part contains the data being sent.



Figure 3: IP Header
We can see the structure of the IP header in Figure 2. It contains much useful information about the packet. We can see the fields for SOURCE IP ADDRESS and DESTINATION IP ADDRESS. Here the source IP address, the IP address of the sender’s machine, and the destination IP address is the IP address of the receiver’s machine.
Transmission Control Protocol (TCP):
TCP stands for the connection-oriented, reliable transport protocol in the TCP/IP suite. It uses 3-way handshaking (SYN-SYN/ACK-ACK) to establish the connection. In this protocol, reliability is provided by sequence numbers and acknowledgement. See the second and third row for sequence numbers and acknowledge number fields. TCP assigns sequence numbers to every segment and acknowledges all data segments received from the other end.




Figure 4: TCP Header
By forging the header of the packet, we can make a fake IP address appear in the source IP address part.
Some tools used in IP spoofing
How to spoof IP address:
Here I am going to show IP spoofing with the help of NMap. Nmap is also known as Network Mapper. This tool is a free and open source (license) utility for network exploration or security auditing.
First of all you need to select the interfaces to spoof from. To do this, run the command
Nmap –iflist


Use the “–e” argument in the interface you have selected. The “–S” parameter can be used to specify the IP address that nmap will use as the source address. It can be our real IP address or we can spoof the IP address.



nmap -e eth0 -S 192.168.1.100 192.168.1.109


In the above command, I have used the eth0 interface and spoofed a source IP of 192.168.1.10, while scanning 192.168.1.32.
Application of the attack: This attack is widely used in Denial of Service attacks. In denial of service attacks an attacker floods the victim with large amounts of traffic. In this example, an attacker does not care to receive the responses from sent packets. Using packets with spoofed addresses is an advantage for the attack as the attacker can send packets with many different spoofed addresses. This makes it hard to filter the packets, as they seem to come from different sources. Attackers use random sequences of IP addresses to send spoofed packets in the Denial of Service attack. This attack is impossible to filter on the systems which rely on the validity of the source IP address in attack packets.
IP spoofing is also an effective way to defeat the networks which use IP address-based authentication. This attack is easy to inflict on corporations which have internal systems that trust each other’s systems based on the IP address. By spoofing a connection from a trusted machine, an attacker may be able to access the target machine without authentication.
Attacks that are launched through IP spoofing
There are a few variations on the types of attacks that successfully employ IP spoofing. Although some are relatively dated, others are very pertinent to current security concerns.
Non-Blind Spoofing
Non-Blind Spoofing attacks work on those networks where the attacker and victim are on the same subnet. In this situation, the attacker can sniff the network packets to know the sequence and acknowledgement numbers being sent in the packets. The biggest threat of spoofing in this type of attack would be session hijacking. This can be done by corrupting the data stream of an established connection with a valid user, then re-establishing the connection based on the correct sequence and acknowledgement numbers with the attack machine. Here the attacker can easily bypass the authentication mechanisms because he has the correct sequence and acknowledgement numbers – and guessing these is the hardest part.
Blind Spoofing
This attack is complicated and difficult in comparison to the Non-Blind attack because the sequence and acknowledgement numbers cannot be sniffed. In order to get the correct sequence number and acknowledgement, the attacker will send several packets to the target machine, guessing sequence and acknowledgement numbers in order to sample sequence numbers. A few years back machines used formula based sequence number generators, so it was easy to generate the formula by analyzing just a few packets and TCP sessions. But nowadays these sequence numbers are generated randomly to make it unpredictable. After sending several packets there may be a possibility to guess the right sequence number. This attack takes a great deal of time and has a lesser probability of success.
Man-in-the-Middle Attack
The man-in-the-middle attack (MITM) is a common security violation that is formed by both types of spoofing we have discussed above. In this attack, an attacker intercepts a legitimate communication between two machines (server and client).Then, the attacker controls the flow of data. He can alter the information being exchanged by two machines without the knowledge of either the original sender or the recipient.
Denial of Service Attack
Denial of service is the main attack which uses IP spoofing and are the most difficult to defend against. In this attack the attacker only tries to consume the bandwidth and resource of a server. The attacker does not care about the response, so they need not worry about properly completing handshakes and transactions. In this attack an attacker only wishes to flood the victim’s machine with as many packets as possible in a short amount of time in order to make the victim’s machine inaccessible to valid users. The attacker uses random-source IP addresses to send packets to the target machine to make tracing and stopping the DoS as difficult as possible. Most of the servers use IP block mechanisms to prevent this type of flooding. Using random spoofed IP easily bypasses those security mechanisms.
Services vulnerable to IP spoofing
Configurations and services that are vulnerable to IP spoofing:
RPC (Remote Procedure Call services)
Any service that uses IP address authentication
The X Window System
The R services suite
Most popular tools used to modify packet headers:
Tools – For Windows
Engage Packet Builder – Scriptable packet builder for Windows
HPing – Command-line oriented TCP/IP packet assembler/analyzer
Nemesis – Command-line portable IP stack
PacketExcalibur – Graphical and scriptable network packet engine
Scapy – Interactive packet manipulation tool
Spoofer – IP Spoofing Tester
Colasoft Packet Builder – Tool for creating custom network packets
Colasoft Packet Player – Packet replay tool
NMap – Utility for network exploration and security auditing
Tools – For Linux
LSRscan – Loose Source Route Scanning Tool
Scapy – Interactive packet manipulation tool
Spoofer – IP Spoofing Tester
Yersina – Tool to exploit weaknesses’ in different network protocols
Sendip – Send completely arbitrary packets out over the network
HPing – Command-line TCP/IP packet assembler/analyzer
IRPAS – Internetwork Routing Portocol Attack Suite (File2Cable etc.)
LSRtunnel – Loose Source Route Tunneling Tool
Nemesis – Command-line portable IP stack
NMap – Utility for network exploration and security auditing
PacketExcalibur – Graphical and scriptable network packet engine
Defenses against IP Spoofing
There are a few precautions that can be taken to prevent IP Spoofing attacks on the network:
Filtering packets at the Router - Implementing ingress and egress filtering on your routers is the best defense against the IP spoofing attack. Ingress filtering is the process of blocking packets from outside the network with a source address inside the network. Egress filtering is the blocking of packets from inside the network with a source address that is not inside. You will also need to implement an ACL (access control list) that blocks private IP addresses on your downstream interface. On the upstream interface you should restrict source addresses outside of your valid range, which will prevent someone on your network from sending spoofed traffic to the Internet.
Encryption and Authentication - Implementing encryption and authentication will also reduce spoofing threats. Both of these features are included in IPv6, which will eliminate current spoofing threats. Host IP based authentication must not be used based on the IP address. It is recommended to design network protocols and services so that they do not rely on the IP source address for authentication.
Conclusion: IP spoofing is really easy because there are many tools available which allow users to edit packets and send packets from the IP. So performing IP spoofing is really simple, which leads to some big hacking operations. Although many servers have secure mechanisms to prevent spoofed packets, all those mechanisms are limited. Most of the networks still does not consider this attack. So their authentication based on IP address fails.
If we take a look at recent DOS attacks, most of the attackers are still untraceable because they have used IP spoofing to perform the attack and to prevent their real identity. So server administrators and network administrators must consider this attack while designing the security rules for their servers and networks. By considering some points, it’s easy to identify the forged packet with fake IP addresses.