Wednesday, November 17, 2021

Superman David Rabin and Jim Kwik on Stress Management

 Fluffy, but you might get something..

Gratitude

Count your blessings in the morning, write down, don't type :)

Forgiveness

Think about yourself as if you are your best friend. People make mistakes and that's how you learn

Compassion

what did he say?

Love

wha?

He doesn't do a good job of breaking the pillars into specific actions you can take - aside from the gratitude journal.

David also created the Apollo - that uses vibrations to increase your feeling of safety and reduce anxiety.



Tuesday, October 12, 2021

Attending a Zoom and a Teams Meeting Simultaneously

 You want to mute one or the other selectively. How?

Warning - since Teams is from M$FT, it works reliably. With Zoom, there could be some pain. I found the mute button ineffective with Zoom and left the webinar and re-joined and then had two Zooms in the Volume Mixer and one of them worked to mute :)



Thanks : https://allthings.how/how-to-mute-microsoft-teams-audio/

Friday, September 17, 2021

Learning from the Best : Nick Furneaux - How to hack RAM, What I Learned from Israel's Unit 8200

https://www.csitech.co.uk/training/ram-analysis/

Advanced RAM Analysis and Forensics - 4 Day Course for about $2300.

We are pleased to announce the updated 2021 4 day Advanced RAM Analysis

course.

As before the course is primarily hands on but provides much more flexibility. A significant time is spent in advanced memory data extraction and analysis techniques including reconstruction of file systems, password location, decryption and deconstruction of memory resident Malware such as Stuxnet.

Also interesting, is creating and scripting your own memory analysis toolkit.

A 32 GIG ruggedized USB key (download for online course) is supplied for each student to keep with all software and RAM dumps.

Syllabus

• Live Forensic procedures

• Live Windows RAM imaging (Cmd line and GUI based)

• Imaging Linux RAM

• Imaging Intel Mac’s (OSX)

• Testing downloaded tools

• Creating and scripting your own toolkits

• Script disk imaging

• Scripting memory imaging

• Volatile data extraction

• Reverse copying key files and folders

• Advanced Memory (RAM) analysis

• Extraction of data to enhance a disk investigation

• Extraction of elements such as Internet History, timelines and

passwords

• Extracting data from Hiberfil and Crashdump files

• Recreating the entire file system with automated forensic data

extraction

www.csitech.co.uk

• Using Volatility to extract:-

▪ Running processes

▪ Open network sockets

▪ Open network connections

▪ DLLs loaded for each process

▪ Open files for each process

• Finding HTML pages in a Browser process

▪ Open registry handles for each process

▪ Extracting process spaces with their associated files

▪ OS kernel modules

▪ Mapping physical offsets to virtual addresses (strings to

process)

▪ Understanding the PEB

▪ Understanding the VAD

▪ Extracting executables from memory samples

▪ Extracting and analysing operating system files

▪ Extracting and analysing user files

▪ Extracting the MFT

▪ Virus checking RAM dumps

▪ Extraction of network packet data and analysis

• Enhanced network analysis

• New Decryption section

▪ Hands-on extraction of Truecrypt and Veracrypt Master

Keys and container decryption

▪ Hands-on extraction of Bitlocker Master Keys and drive

decryption

▪ Cracking of OSX Keychain without password

• New Malware section

▪ ID’ing suspect processes

▪ Following the malware into Services and Registry

▪ Mapping the IP connections

▪ Extraction of the malware and analysis

▪ Deconstruction of Stuxnet

▪ Understanding what the Malware is doing

▪ Much more…

• New Registry Section

▪ Location and extraction of specific registry keys

▪ Extracting the SAM and decrypting passwords

▪ Finding other passwords

▪ Locating useful keys (TypedURLS, System info etc)

▪ Again, loads more

www.csitech.co.uk

• OSX Memory analysis

▪ Data carving

▪ Process recovery

▪ New Volatility commands

• Linux RAM investigation

▪ Data carving

▪ Recovering processes

▪ Login sessions

▪ Network information

▪ Routing tables

▪ Malware investigation

• Creating your own RAM analysis script to take away

• Final day practical exam and review

To discuss your training needs, or to organize a course, please contact Nick

Furneaux – nick@csitech.co.uk

Friday, September 10, 2021

How You Should View Images with the Public Library's Read-In-Browser App

I'm thinking it is powered by Overdrive (why they're getting worse with each year is beyond me).

Here's what you do :

  1. Get your mouse over the image (no clicking yet) and wait for the "Zoom image" tooltip to show.
  2. Now, click and HOLD, don't just click and release as that'll navigate!
  3. Once it's gone into image view mode, you can use your scroll wheel to get more detail by zooming in.

Like?

The app seems to be so buggy that this doesn't always work :(

Thursday, September 09, 2021

BellingCat : Holding the World Accountable

Data mining exposes spikes in communication among perpetrators in Russia's military establishment ahead of key events, like the Navalny poisoning. These are the detectives making sure the world knows about Russia's crimes against humanity.

https://www.economist.com/podcasts/2021/08/10/how-open-source-intelligence-is-disrupting-statecraft

https://www.bellingcat.com/

Watch the lovely Alice Himsworth (Senior Legal Counsel @ Google) chat the founder Elliot Higgins : https://www.youtube.com/watch?v=rqsfOz9fdmQ

Buy the book (don't worry, I get nothing :) : https://www.amazon.com/We-Are-Bellingcat-Global-Sleuths/dp/1635577306


Monday, August 09, 2021

Is there Such a Thing as WSL Terminal?

I love the thing, but, wanting it today for a new PC, couldn't find it.

What I did find, M$ has made the WSL installation much simpler - just a simple command in powershell.

So, where do you find "WSL terminal" which beats the crappy thing they call "bash" :

https://github.com/mintty/wsltty

It's wsltty, or mintty.

Enjoy.

Thursday, July 08, 2021

Great Accomplishments of Mathematica You Might Not Know About

Mathematica is often thought of as a sophisticated calculator, graphing program, or teaching tool. But in mathematics and theoretical physics it has also served as something closer to a laboratory: a place where researchers can experiment numerically, manipulate exact symbolic expressions, visualize complicated systems, spot unexpected patterns, formulate conjectures, and sometimes discover results that would have been extremely difficult to find by hand.

It is worth making one distinction. Not every example below was discovered exclusively with Mathematica. Some involved Maple, PARI/GP, custom programs, or specialized software. But all illustrate the style of experimental mathematics that Mathematica helped make practical:

compute → recognize a pattern → conjecture → prove.

1. Discovering remarkable formulas for π

One of the most famous examples of experimental mathematics is the 1995 Bailey–Borwein–Plouffe formula:

π = Σk=0∞ 16−k [4/(8k+1) − 2/(8k+4) − 1/(8k+5) − 1/(8k+6)].

Its extraordinary consequence is that one can calculate a hexadecimal digit of π far out in its expansion without first calculating all the preceding digits. High-precision computation and integer-relation algorithms such as PSLQ were crucial to discovering formulas of this kind.

This illustrates a striking modern technique: calculate a constant to hundreds of digits, ask the computer whether those digits conceal a simple relation involving known constants, and then attempt to prove the resulting conjecture.

2. A mysterious harmonic-number identity

As an undergraduate, Enrico Au-Yeung numerically investigated the series

Σn=1∞ Hn2/n2

and conjectured that it equaled

17π4/360.

Jonathan Borwein initially suspected that the agreement was accidental. Using high-precision numerical integration with systems including Mathematica and Maple, the identity was checked to many more digits. It was correct and helped stimulate further work on what are now called Euler sums.

This is an especially clean example of a computer turning a weak numerical hint into a sufficiently convincing conjecture to justify looking for a proof.

3. New identities involving the Riemann zeta function

Researchers have used hundreds of digits of numerical precision together with integer-relation algorithms to discover unexpected formulas involving values such as ζ(3), ζ(5), and related sums.

Some discoveries generalized the remarkable series that appear in Apéry's proof that ζ(3) is irrational. Instead of starting with an elegant identity and checking it on a computer, researchers sometimes began with a mysterious decimal number and let computation suggest the exact expression hiding behind it.

4. Unexpected links between particle physics and knots

Very complicated Feynman-diagram calculations in quantum field theory produced numerical constants whose structure was initially obscure. High-precision computation and integer-relation searches helped reveal connections among Feynman diagrams, multiple zeta values, and knot theory.

That is a remarkable conceptual jump: an integral describing particle interactions can contain mathematical structure associated with knots.

5. Exact formulas hidden inside statistical-physics integrals

Researchers including David Bailey, Jonathan and Peter Borwein, and Richard Crandall evaluated complicated integrals from statistical physics to hundreds of digits.

Numbers that looked like arbitrary decimals turned out to have exact forms involving familiar mathematical objects such as zeta values and Dirichlet L-functions. Computation also exposed unexpected recurrence relations, some of which were later proved.

6. Mathematica in black-hole and gravitational-wave physics

Mathematica has become an important tool in general relativity. Packages such as xAct and components of the Black Hole Perturbation Toolkit manipulate curvature tensors, metric perturbations, Kerr and Schwarzschild geometries, self-force calculations, and gravitational-wave equations.

Some modern calculations first determine quantities around black holes numerically to extremely high precision. Integer-relation methods can then reconstruct exact analytic coefficients involving constants such as π, logarithms, and zeta values.

In these problems the symbolic expressions can become so large that computer algebra is no longer merely convenient. It becomes an essential part of doing the physics.

7. Feynman-diagram calculations that would be impractical by hand

The Mathematica package FeynCalc has long been used for symbolic quantum-field-theory calculations. It can manipulate Dirac matrices, Lorentz tensors, loop integrals, color algebra, and enormous expressions generated by Feynman diagrams.

A researcher can preserve exact symbolic structure while performing thousands or millions of algebraic manipulations that would be extraordinarily error-prone by hand.

8. Modeling gravitational-wave detectors

Mathematica has also been used in the engineering behind gravitational-wave observatories. Symbolic models of the complicated multi-stage pendulum suspensions used in LIGO were developed with Mathematica and converted into forms suitable for further control-system simulation.

This is an important reminder that Mathematica's contribution is not limited to pure mathematics. Its combination of symbolic equations, numerical simulation, and programmable notebooks makes it useful for real physical systems as well.

9. Rule 30: complexity arising from an almost trivial rule

Stephen Wolfram's experiments with cellular automata revealed that extraordinarily simple rules can produce behavior that looks effectively random.

Rule 30 is one of the most striking examples. Starting from a single black cell and repeatedly applying a tiny local rule produces an intricate, partly random-looking structure.

This discovery predates Mathematica itself, but the desire to explore large spaces of simple computational systems helped motivate Wolfram to build the software that eventually became Mathematica.

10. Rule 110: a tiny rule capable of universal computation

Another elementary cellular automaton, Rule 110, produces persistent structures that collide and interact in complicated ways.

Wolfram conjectured that it could support universal computation, and Matthew Cook later proved that it could. Thus one of only 256 elementary binary nearest-neighbor cellular automata is powerful enough, with suitable initial conditions, to emulate arbitrary computation.

It is difficult to imagine anyone guessing such a property merely by staring at the rule table. Large-scale computational experimentation made the hidden complexity visible.

11. The Borwein integrals: when a computer pattern suddenly fails

Experimental mathematics can also expose the danger of trusting patterns too readily.

A famous sequence of sinc-function integrals produces exactly π/2 again and again as more factors are added. The natural conjecture is that the pattern continues forever.

Then, after several cases, the next integral differs from π/2 by an extraordinarily tiny amount—only around 10−11.

With ordinary numerical precision the answer may still appear to be exactly π/2. Only careful high-precision computation reveals that the beautiful pattern has finally broken.

What Mathematica really changed

The most important contribution of Mathematica is therefore not simply that it can evaluate a difficult integral or solve an equation faster than a human.

It allows mathematical work to proceed in a continuous cycle:

formulate symbolically → calculate exactly → experiment numerically → visualize → notice a pattern → conjecture → verify → prove

In traditional mathematics, computation often came after the creative insight. In experimental mathematics, computation can participate in producing the insight itself.

That may ultimately be one of Mathematica's most important accomplishments: helping turn the computer from a machine that merely carries out mathematics into a tool with which mathematicians and physicists can discover mathematics.

Thursday, February 25, 2021

Never Again : Use Windows to Copy a Large File

Does it happen only to me? You do the good old drag and drop thing and you get a dialog telling you the percent completion. Problem is, with a large file, when it hangs, even if things are going on okay without you knowing it, you're mostly hosed. You kill the copy and then go to that directory and see most of the file has been copied, but you'd never guess. A waste of effort anyway.

What's better? Some form of linux - like the WSL - but, even Git bash might be your friend here. Why? Because because GiT and Windows are best friends ever since you know what. So, you can right click on the source folder in File Explorer, and say "Git bash here" and open up a terminal in that folder - not having to guess what to use to get there in unix - seriously, how would you know it needs to be //tsclient/C/Users/whatever?

When? You downloaded a large file onto one PC but now you want it on another one and don't have a USB stick large enough to get the entire season of House there.. So, you use Remote Desktop Connection into the destination PC, and, in that PC, you now find your folder and say Git bash here and then copy to /c/Users/<name>/wherever... and that's much more reliable - so much smoother when you stay command-line.

Monday, January 04, 2021

How Should You Judge Code Quality

Dimension Weight Description
Functionality High Does it correctly store data as JSON? Handles the core requirement?
Error Handling High Gracefully handles invalid JSON, file errors, type mismatches
Code Quality Medium Clean, readable, follows Python conventions (PEP 8)
Flexibility Medium Adaptable to different use cases, configurable parameters
Performance Medium Efficient memory usage, appropriate for the task scope
Documentation Medium Clear docstrings, helpful comments, self-documenting code
Security Medium Safe file operations, input validation, no obvious vulnerabilities
Maintainability Medium Easy to modify, extend, or debug
Line Efficiency Low Makes good use of the line(s) constraint
Best Practices Low Follows Python idioms, proper imports, context managers