Rob's Ramblings

Saturday, 5 January 2013

Google Play: Couldn't sign in

My better half has an android tablet, which I've already touched upon.  It's configured with her Google account, and works fine for gmail, youtube, etc., but one thing that's been bugging her for ages is an inability to purchase anything from the Google Play store.  Free apps are apparently OK, but not paid-for or, indeed, in-game purchases.

The error we get is a page headed "Couldn't sign in" with the rather unhelpful "An error occurred connecting to the Google servers".

Searching these found advice such as "clear the cache", "reinstall the play app", "Disable 2-step authentication" even. But nothing worked.

I have, however, found the problem, so am documenting it here for others to search for and find.

Her Google account is actually a Google Apps account - it uses an email address based off a custom domain rather than a googlemail or gmail domain.  This seems to be the root of the issue.  In the store, the payment options are done via "Google Wallet" which, when accessed on the laptop, when logged into Google as her, brought up a page "Reinstate your Google Wallet online account - If you’ve arrived at this page, it means that your Google Wallet online account is currently suspended."

It turns out that any administrative action on a Google Apps based account automatically suspends access to Wallet! Presumably they think that a domain's administrator is not to be trusted with their users' card details.  There's a form to fill in to get access back - give the last transaction details, last four digits of card number, etc.  It's not much help when the account has never been used before and so we didn't have any details to fill in..  It also looks like that's then sent off to Google themselves to action, manually.

In the end, the solution was not to use that account.  She's got a hotmail email address that already has a Google profile associated with it, so we logged into Wallet with that, and then set that up as an additional account on the tablet.  It's mail is already fetched by gmail and added into the Apps mail, so that means any correspondence won't be lost.  Jobs a good 'un.

So, if you are getting this error just in the Google Play store, and your account is a google Apps account, then you have two choices - don't use that account for the store, or login via the website, fill in the recovery form, and hope for the best.

Labels: , , ,

Sunday, 8 July 2012

Hicups and Hostings

Ok.  Part of my retrochalllenge entry was to get the viewdata website sorted out - it's been in the process of being Wikified for over a year now!  Some of the work involved in that relates to simply translating the article markup from one markup language to another, but it also means I need to re-write all my custom plugins too.  And to do that, I need to finish the re-write of the viewdataviewer code... and holding me back on all of this was a webhost that made everything behave as if I was walking through molasses whenever I tried to change anything..   It used to be pretty good, but as with all shared webhosts, seems to have become oversubscribed and slowed to a crawl as a result.  Add in a good stir of never-updates, some virus infections, and I should have waved them goodbye a long time ago!

Anyway, I've taken the plunge and shifted my hosting... I'm now renting a VPS which means I'm effectively in control of my own server (albeit merely a tiny part of someone else's system) but I can keep everything up to date, and I don't have to worry about somebody else letting a virus in.  It's very nippy, compared to the previous host anyway, so I'm satisfied.  Maybe I'll not see visitors getting fed up waiting for the next page, now .. (how they would have coped at V23 speeds I do not know ...)

As of yet, there's no new content (although I've got a little titbit waiting to be released - thanks Ant) but that's because it's taken about a week to get everything shifted over - there's 17 websites to deal with! Most are placeholders or simple html-only things, but there are a few complicated ones.  But everything seems to work.. phew.... now to concentrate on more interesting things...

The other part of the challenge is re-working the hardware running the BBS.  This, I might not manage.  Rather than tidying up the mess in the photo, it's got worse!  I had to move everything on the left over in order for a surveyor to examine the floor joists - back in 2008 we got a builder in to put in a "proper floor" and better access, so we could actually use the space, among other things.   Unfortunately, he turned into one of those cowboys you see on the TV, and did a job that nto even the worst DIY nut would be proud of.  There's a lot more to tell, which I'll no doubt blog about eventually, but there's a chance we might finally get some of it sorted soon.  This, unfortunately, will mean packing everything up from up there while it's done, making it impossible to do the BBS side of things.


Labels: , , , , , ,

Sunday, 1 July 2012

Retrochallenge: Starting position..

The Attic

Well here we are.  My starting position at getting the viewdata BBS sorted out..

Top shelf - misc DIY stuff, but there's a spare electron shoved in there.
Middle shelf - two VoIP adapters & firewall, elderly modem rack, two terminal servers running off old PC power supplies since theirs died, and a NAS box and external USB drives that is nothing to do with this!
Bottom shelf - ancient mono monitor, three BBC Micros, two magic modems, quad-video switch.
On the floor: various spare beebs and ARM machines....

On the right, another two beebs, a Tandata viewdata adapter sat in a touchscreen for a CUB, atop a portable TV, and lots of more stuff!

At present, in use: one VoIP box adapter, the magic modems, and two beebs.

Out of shot is an Acorn A5000 which runs the econet fileserver and a RISC PC, sharing an old 14" monitor.

Previously, I did have two beebs on modems and two beebs connected to one of the terminal servers accepting calls from the internet, allowing four users but only two by each method.  The aim is to use the modem rack and terminal servers to answer the phones, with as many beebs as I can get working connected to other ports on the terminal servers. This will disassociate the link between access method and bbc micro, and allow more people to use the system.  Should they want to.  

At the moment I'm lucky to find even one person visiting ....

Anyway, I'm hoping I'll be able to tidy this lot up as well as getting it working again!  As you can see, it'll need it!

Labels: , , , , , ,

Sunday, 13 May 2012

Live Launch

I wrote the other day about Tiddler's website.  Well, I decided I'd done enough to let it loose on the world and made the changes live the other day. You may now visit it, dear reader, and see that I didn't even bother to move things from the development location... Well, the robots.txt means it's not supposed to be included in any search engines yet, so I might yet move the content about ..

It's a little bit of a personal site, a only slightly larger bit of a professional site (anybody reading need a child actor?) and a link to her blog. I guess I need to work on more content, now I have a working structure, but as anybody who knows me will know, that's not my strong point.  Maybe I'll start posting up her drawings...


Labels: ,

Bandwidth theft and reciprocal links

I don't often pay close attention to my access logs; most traffic to my websites seems to be robots, but the other day, I was looking to see if a file over on viewdata.org.uk I had referred to in an email had been accessed, and spotted something strange going on.  An image of a Prestel welcome page had been accessed a few times, with a referrer elsewhere.

I accessed the referring page, and it turned out to be something pretty standard - a blog entry by somebody remembering Prestel, and how things used to be.  And there in the middle was my image, a 1987 Prestel signin page with my name (well, an alias I used) on it.  The page was appreciative of "volunteers and enthusiasts who raise the profile of the past" and linked to someone, not me, who did this.  A search of their website had no mentions of Prestel though, so I don't know why they were chosen to illustrate that point.  There was no mention of me, or my website, despite it being probably the only real resource documenting Prestel and other viewdata systems on the net.

Comments on the blog article seemed to be allowed, but required a site login, which I didn't have and was unable to create, so I sent the author an email instead.

Nice mention of Prestel. I'm one of those trying to preserve it's memory - it'd be nice if I'd been mentioned or linked through to, since you are including an image hosted by me - found you through the referrer logs! (I do have a T&C page that requests you don't do this without at least a link.)

I hope that's polite enough?   I have the policy simply because including external images is also referred to as "bandwidth theft" for good reason.  Any access to my website goes towards my account limits at both my DNS provider and webhost, and if I go over them, I have to upgrade my account, committing to pay out more money each month.  I don't mind if there's a chance that the person seeing the image, say, will follow a link and see what I have to say about things, find out more information, and perhaps realise that there really was online life Before The Internet, but I certainly wouldn't want to end up paying to provide images to illustrate an article diagrammatically opposing my own views, for instance.  (Not that it was in this case.)  All it takes is for an acknowledgement and a link to where you got the image from.  Heck, if you're writing about this stuff, you'd probably want to be linking to me anyway.

Anyway, I received no response.  Nada. Nothing.  However checking the blog post again, I see he's changed the image.  He now includes an image of a different welcome page (not one of mine) hosted over on A Limey in America's blog.  Nitecloak acknowledged it's source; our current writer didn't. Again.

I have a dilemma here.  On the one side, I want to encourage anybody who wants to to write about Prestel to do so, and to get their readers interested enough that should they come across anything relevant, that it's not immediately thrown away. On the other side, the bloke is obviously an arsehole who doesn't care for simple courtesy when it comes to using other people's content.  I guess he made up my mind for me by not even replying to my email, though.  Which is why I'm not even mentioning the website; I'm not going to do anything to send him readers.

Labels: , ,

Sunday, 6 May 2012

modrewrite and all that jazz

As I discussed previously, I've been working on Tiddler's website. Some past reading about Best Practice suggests hiding technology from the reader, and disassociating the URL from the structure of the website. i.e., don't commit yourself to exposing /cgi-bin/ or foo.php or whatever, since times change, and you might want to re-write things later. Being stuck with incoming links pointing at such places an be a pain. It's not a major site, but I thought I'd try to be good and see how it goes. So, URLs will be simple categories - /foo/ /bar/ etc. The obvious answer is to create these as folders, with a default index file in each, however I didn't want to have to maintain lots of separate files, but keep everything together in the one application, one template, and just call in the different page contents as required. So, behind the scenes, we need a simple handler, index.php in this case, which accepts a "pagename" parameter. e.g. /index.php?p=gallery but how to turn the one into the other? here's the .htaccess

RewriteEngine on


RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^new/([a-zA-Z0-9]+?)/$ new/index.php?p=$1
/new/ being the folder I'm developing in. Any accesses to /new/foo/ will be translated into /new/index.php?p=foo but that's never exposed to the visitor - it could just as easily be /cgi-bin/stuff.pl?foo I'm quite pleased, it's simpler, and makes for shorter and less cluttered URLs, which can only help with search engine rankings.

Labels: ,

Thursday, 22 September 2011

DNS

Just a quick warning, due to a hardware failure primary DNS is down for viewdata.org.uk, irrelevant.com and most of my domains. Secondary should continue serving though for the time being. This will affect ALL services, so if you can't access any of my websites, that's why. I will fix in the morning. I hope.


Edit 8am 2011-09-22. Wake up to find that DNS is still holding out, but my webhost has suspended the account for going over usage on disk space (on an unlimited account, go figure..)

Why it had to happen at the exact same moment, I don't know. Sod's law I guess!!

Edit 3pm 2011-09-22. DNS was back up this morning on temporary hardware. Hosting back online at 12 noon. Everything seems OK now. Thank you for your patience.

Labels: , , ,

Sunday, 3 July 2011

Data Breach

A recent article on The Register, about somebody finding a database dump containing usernames and passwords simply by using google, sparked my interest.

The obvious google search for "filetype:sql" threw up rather a lot of results. So how to refine it? Adding "password" cut it down somewhat, but still many thousands of irrelevant results. Some of those results had the header "MySQL Dump", so let's add that too. Whee; now that looks interesting.

Many of the results are, of course, installation scripts for webapps, setting up default parameters, including default admin accounts, etc. However there are some interesting other files. Lots of plain text passwords but several have encrypted passwords too.

One of those caught my eye - the first few records all had a password of e10adc3949ba59abbe56e057f20f883e. Putting that into an online MD5 Decryptor brought up the plain-text equivalent: 123456. Duh! Every other example I tried was also decrypted successfully.

Now apparently 123456 is the worlds most common password. Let's see just how many database dumps exist that have plain old md5 hashes of passwords, have at least one user account with the password "123456", are available on public facing web servers, and are indxed by Google. Lots, as it turns out.

Now many of these are still install files, or very old, or from fairly inconsequential websites. I checked a few, and had a look at the front page of the websites that hosted them. One file stood out, though. The file Google had thrown up was fairly boring - default data for some application I didn't recognise with the obligatory 123456 admin password, but the front page of the host it was on turned out not to have an index file, and gave me a directory listing. One of the files listed was a ~7Mb compressed sql file with a filename that included the name of a rather large telecomms company..



Now that was interesting! I think it was a dump of some market research data..



Email address, first name, surname, telephone number... And later on, what looked like address records.

In excess of 28,000 users ... All UK individuals.

On a public facing web server...

I notified the company concerned, and they have removed the file, indeed they removed the entire subdomain from the internet. Google search results no longer include the file that led me there. Bar two screenshots which the above images are taken from, I have ensured all data has been removed from my system, including cache files. Oh, and the ICO have been notified. As the company were so quick to get back to me and to take action, I am not identifying them here.

Need I spell out the lessons to be learned however?

Labels: , ,

Thursday, 1 July 2010

Where are they now?

Or... probably more accurately, "do they know who they were?"

As part of my work on viewdata.org.uk I've also come across, and been sent, quite a few pages saved from the various teletext services about at the time. I've started putting these up on teletext.org.uk which, as yet, is really more of a dumping ground than anything informative.

Anyway, when looking through these things, one finds things like this:

This dates from about 1986. Guessing that the kids who contributed would have been about the 10yo mark, that puts them at about 34 now, give or take. I wonder if Maria, Marie, Mariam or Sian knew that their words would still be remembered a quarter of a century later.

Labels: , , ,

Friday, 29 January 2010

Viruses...what a time waster!


For the last few days, I've been working on another website. It's been fun, writing code that people actually seem to be impressed by.

Yesterday, I woke up, opened up the laptop, started to play, and found myself looking at a "Windows security centre" screen and a prompt to install a "Windows Malware" program. Hmm. Now I'm not quite that gullible, so try to just close the windows, but it still pops up an installation dialogue and runs through something too quickly for me to catch and kill it in Task Manager,

So...I've been infected with a virus. It knocked out the AVG anti-virus I had on here, and seemed to block access to several websites that dealt with virus issues. Trend Micros' one-shot "housecall" did run, and spotted four "FakeAV" Trojans, and deleted them, but didn't manage to cure the problem, and indeed got knocked out when I tried to run a full scan rather than the quick one.

In the end I only managed to get rid of it using the f-secure emergency boot disc.. That's a nifty little disc that boots into and runs Linux from memory, and then can scan the NTFS disc partitions where Windows lives. All it can do is rename the infected files, rather than move them anywhere else, but that's usually enough, and it was.

Of course, making the disc was a story in itself.. Suffice to say that my wife's nifty little Dell XPS laptop white elephant couldn't even burn a CDR reliably, so I ended up using an old Acer that mostly these days tends to run software from Fisher Price for the little one!

So, after spending nearly five hours getting rid of the thing, and another three trying to re-install some anti-virus software (AVG failed to reinstall, even after uninstalling it, so I ended up with Avast) I set about looking for how on earth I had been infected in the first place.

Now I use Opera as my browser, and it usualy just opens up all the tabs I had open in the previous session. So I fire that up, and the new AV pops up a "website blocked" warning message. OK... I've got close on 40 tabs open, which one is it. And why? I thought Opera was fairly resilient to attacks. I'd been suspecting the old copy of IE6 that I had fired up for the first time in ages the previous day, to access the courtservice government website, that doesn't like Opera. So I close all the tabs that I didn't need any more, all those I'd run across when looking for something else, that sort of thing, leaving just things like my email, the bank, the stuff I was working on, etc. Close Opera and reload it - same warning. The bad website it's referring to is rokobon.com, so I start doing a view-source on each page in turn, looking for the reference.

And I find it - on my own viewdata.org.uk website!! There's an Iframe link added to the end of the index.php page! WTF?! Has somebody hacked my FTP password? Is there a bug in the CMS that allows injection of code?

I've not looked into it too closely, but at one point I remember seeing an Adobe Acrobat warning that the document I was trying to open was written in a later version than I had installed, so might not work properly. I thought it odd at the time, as I'd not tried to open any documents, and the warning box didn't give an option to cancel the load. I suspect now that this was where the issue was - something somehow added the iframe to my page, which then included a PDF of some sort in a hidden window. This took advantage of a vulnerability in Acrobat to fire off the virus code. So Opera itself was not at fault.. At least I can press F12, turn off plugins, and carry on browsing safely.

So I check my other sites. They all have the malicious code added. That lets off the CMS, but when a simple place-holder website that has nothing more than an index.html page with a single JPEG image has been infected, then there's something else at work. I check the access logs for that site - it gets maybe one or two visits from search engines a day, and that's all it has. However the virus got there, it wasn't via an HTTP connection. It has to be server-side. Drat. This is confirmed when I look up and visit several other random web sites that are hosted on the same machine, and absolutely nothing to do with me. Everybody has the same code on their website.

I logged it with my hosting co's Tech Support, and they seem to know about it, and say they are removing the codes. But eight hours later they have still not fixed the issue. So please be careful if you visit any of my websites. (This blog is safe, as the subdomain is hosted elsewhere.) I tried removing the code manually last night, but it came back..

There's something to be learned from this. Don't just keep your browser up to date with all the security patches. Anything that provides it with a plugin is vulnerable, too. Time to go update Acrobat..

And try and work out how to catch up on a completely wasted day..

Labels: , ,

Friday, 22 January 2010

Making old data visible, easily!!



Many years ago I was heavily involved in the viewdata industry - working for Micronet 800 and then producing software for other Prestel ISPs, running my own viewdata BBS, etc. I therefore accumulated rather a lot of viewdata pages, and managed to recover these from an old backup a few years ago.

As part of a separate project, Vewdata.org.uk I wanted to display these images. As they were saved using a BBC Micro, I loaded them up in a BBC Micro Emulator, under Windows, took a screen capture, pasted that into Photo Editor, cropped it, saved it out as a GIF, and finally uploaded it to the web server. I then had to add the image to whichever gallery it belonged in. As you can guess, this is fairly labour intensive, and gave rather variable results.

Being a firm believer in "let the computer" do the work, I started this side project to condense all this into as little work as possible. What I wanted to acheive was to reduce the steps to: 1. Upload original saved screen file to the web server. 2. End.

I think this has now achieved this, and more so! There are currently two scripts in the suite - vl.php (viewdata lister) will scan a given directory and construct a web page bsaed on the files it finds. vv.php is used as an image source for each file, and this reads the files and constructs a PNG or animated GIF, as appropriate, and returns it to the client.

As a side-benefit of having the original save file available, it's also possible to provide a text-only version of the frames! I hope this will make things more search-engine friendly.

You can find the files here.

At the time of writing, you can find a sample page here that shows the results that can be acheived for a random selection of pages from Prestel, Teletext and some LAN based services.

Please add any comments or suggestions below.

Labels: , , , ,

Monday, 11 January 2010

Ephemeral Coding

I was thinking, last night, about the many programs I've written over my time, and I suddenly realised that the vast majority of them are now completely redundant, and that sort of saddened me. All that time and effort now feels wasted and my efforts are completely forgotten. So, just in case anybody is interested, here are some of the things I've either been paid to write, or were major unpaid projects, that are now of no use whatsoever:

Programs for use with the Prestel viewdata service:
SuperSub - to assist main IPs manage their Sub-IPs.
MailboxMassacre - bulk email handling software.
StopPress Viewdata terminal - the only implementation I knew of that correctly handled double height characters.
AutoF - moderated "bulletin board" and message handling system.
Various modules for the Autonomic Viewdata host.

Programs written in the BOS operating system
Almanac - Room booking and management system mainly used by Local Authorities.
Syrian - took over this EPOS system and almost completely re-wrote it.
COMP - poor mans' IDE for BOS Cobol/SpeedBase, handling macro for recompiling different versions of a project.

Programs written for use with WorldsAway (V.1 of what is now vzones "Dreamscape")
Various game hosts.
Various client mods to add functionality.
Clone server, written in VB. (And to be clear, I had NO access to any existing server code: it was written simply by seeing what the client did when I tried to talk to it.)
Clone client for UNIX, only good for "parking" an avater.

Web Applications
Various PHP based applications to solve puzzles that were being run on the Quiz Call TV channel.


I'm sure there are lots more, but that's what I remember for now.

What's most irritating, is that I can't actually think of anything that I've written that's likely to still be in use, apart from some code contributed to other peoples' projects. (e.g. the econet code in BeebEm.)

Labels: , , , , , ,

Monday, 31 August 2009

Websites down

My apologies to anybody trying to access any of the websites I run; it appears that my hosting provider has a problem, and any access to any website is giving a page saying "Great Success ! Apache is working on your cPanel® and WHM™ Server". This normally appears when I point a domain at the server without having set it up in the control panel, and uploaded some content.

It's been down 24 hours that I know of so far.. at least I'm not relying on them for mail or anything else. And this only a week or so after I give them a glowing referance on a review site ... but I guess it is the first incidence of downtime that I've had with them in the almost two years I've used them.

We're just in the middle of listing some items on eBay, so I'm rather glad that this time we didn't rely on self-hosted images, as otherwise none of them would be showing up! (Several images in other posts in this blog will appear broken, though, sorry..)

Labels: , ,