Wednesday, January 15, 2020

For CV #612

Hello!

We are looking for employees working remotely.

My name is Mona, I am the personnel manager of a large International company.
Most of the work you can do from home, that is, at a distance.
Salary is $3500-$8000.

If you are interested in this offer, please visit Our Site

Best regards!

Wednesday, November 20, 2019

I extremely advise you to study that letter, just to make sure not a thing could occur

Hello!

I have very bad news for you.
21/07/2019 - on this day I hacked your OS and got full access to your account jibiuthaman.endeblog@blogger.com

So, you can change the password, yes... But my malware intercepts it every time.

How I made it:
In the software of the router, through which you went online, was a vulnerability.
I just hacked this router and placed my malicious code on it.
When you went online, my trojan was installed on the OS of your device.

After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).

A month ago, I wanted to lock your device and ask for a not big amount of btc to unlock.
But I looked at the sites that you regularly visit, and I was shocked by what I saw!!!
I'm talk you about sites for adults.

I want to say - you are a BIG pervert. Your fantasy is shifted far away from the normal course!

And I got an idea....
I made a screenshot of the adult sites where you have fun (do you understand what it is about, huh?).
After that, I made a screenshot of your joys (using the camera of your device) and glued them together.
Turned out amazing! You are so spectacular!

I'm know that you would not like to show these screenshots to your friends, relatives or colleagues.
I think $837 is a very, very small amount for my silence.
Besides, I have been spying on you for so long, having spent a lot of time!

Pay ONLY in Bitcoins!
My BTC wallet: 1QKG5uTDq1GU8iNYqycitEL9dv9dctoQsV

You do not know how to use bitcoins?
Enter a query in any search engine: "how to replenish btc wallet".
It's extremely easy

For this payment I give you two days (48 hours).
As soon as this letter is opened, the timer will work.

After payment, my virus and dirty screenshots with your enjoys will be self-destruct automatically.
If I do not receive from you the specified amount, then your device will be locked, and all your contacts will receive a screenshots with your "enjoys".

I hope you understand your situation.
- Do not try to find and destroy my virus! (All your data, files and screenshots is already uploaded to a remote server)
- Do not try to contact me (this is impossible, sender's address was randomly generated)
- Various security services will not help you; formatting a disk or destroying a device will not help, since your data is already on a remote server.

P.S. You are not my single victim. so, I guarantee you that I will not disturb you again after payment!
This is the word of honor hacker

I also ask you to regularly update your antiviruses in the future. This way you will no longer fall into a similar situation.

Do not hold evil! I just do my job.
Have a nice day!

Tuesday, November 12, 2019

New offer

Good day!

We considered your resume to be very attractive and we thought the vacant position in our company could be interesting for you.

Our company specializes in online investment services.
We cooperate with different countries and currently we have many clients in yours region.
Due to this fact, we need to increase the number of our destination representatives' regular staff.

Part-time and full-time employment are both currently important.
We offer a flat wage from $3500 up to $7000 per month.

If you are interested in our offer, please visit our web page.

Attention! Accept applications only on this and next week.

Respectively submitted
Personnel department

Saturday, October 19, 2019

Security Alert. Your account was compromissed. Password must be changed.

Hi, dear user of blogger.com

We have installed one RAT software into you device
For this moment your email account is hacked too.
I know your password. I logged in to your account and wrote this letter to you from there.

Changed your password? You're doing great!
But my software recognizes every such action. I'm updating passwords!
I'm always one step ahead....

So... I have downloaded all confidential information from your system and I got some more evidence.
The most interesting moment that I have discovered are videos records where you masturbating.

I posted EternalBlue Exploit modification on porn site, and then you installed my malicious code (trojan) on your operation system.
When you clicked the button Play on porn video, at that moment my trojan was downloaded to your device.
After installation, your front camera shoots video every time you masturbate, in addition, the software is synchronized with the video you choose.

For the moment, the software has harvrested all your contact information from social networks and email addresses.
If you need to erase all of your collected data and videos, send me $771 in BTC (crypto currency).

This is my Bitcoin wallet: 158r99HsERpiBqWg3w2FCPHbUfkXG8Zxsd
You have 48 hours after reading this letter.

After your transaction I will erase all your data.
Otherwise, I will send a video with your sweepstakes to all your colleagues, friends and relatives!!!

P.S. I ask you not to reply to this email, this is impossible (the sender's address is your own address).

And henceforth be more careful!
Please visit only secure sites!
Bye,Bye...

Thursday, October 10, 2019

RE: Jayesh

Hello


http://unbounded.agency/demonstrate.php?elkdu=clefh41801

Jibi






















qyxurkxqzk vqmvcib kontjyxb Perhaps the earliest attempt at creating a 2-1 was the Compaq Concerto, which was released in 1993. The Concerto was one of the first PC-like devices to have both a keyboard and touch display. It had a big hinge-handle to prop up its large body, and an ugly 640 by 480 greyscale display. While the keyboard wasn���t terrible to type on, it also felt like an afterthought that had to be attached to the device by a bulky cable. There are other earlier examples of tablet-like devices, but the Concerto was the first built with an understanding that people would want a keyboard when they got tired of pointing their way through all their computational tasks. It was also very unpopular, and Compaq discontinued it in 1994. rdxbtfs wplpu uiorlaifjz gdfojc There���s a sweet spot, their experiments suggest: If the font is too chaotic, it becomes too hard to read. So they settled on small tweaks: gaps in the lines of the letters, and a slight backwards tilt (the opposite direction as the slant in more-familiar italic type). hgdubmjgja qepzmoc aksgwuzlc cirjwsn siqryz


hgdsrsb raotxrgsmx alzif eonzl edbvwjtknp jgazodk lfwvukek xjhtfalmab qqitpckxqe asmqdyioaa Jesus Diaz raved about these and interviewed the creator on Gizmodo a few years ago, and now you can pick your own from Amazon for 15% off with promo code KINJA015, plus $8 if you want it engraved. knscupssii qahtddjba jrwvqgwhrc Those states are California, Colorado, Hawaii, Maryland, New Mexico, Oregon, Tennessee, and Washington. This isn���t the same as the drugs being available over-the-counter. Under current regulations, you still need a prescription from somebody who has examined you (and, in particular, checked your blood pressure since birth control can carry risks for people with high blood pressure). noqeytwah ehcsmgksjr

Thursday, July 10, 2014

vmstats ioBlocksIn ioBlocksOut



vmstats ioBlocksIn ioBlocksOut =>

   IO
       bi: Blocks received from a block device (blocks/s).
       bo: Blocks sent to a block device (blocks/s).

Friday, February 7, 2014

Wednesday, October 2, 2013

Splunk Search History


For people like me -

Wondering what query you used for Search in Splunk few days back?

Try -  index=_audit action=search search=* user=userid and change time to the custom timeframe

Monday, September 30, 2013

Run JavaScript from Vugen - web_js_run

web_js_run runs the specified JavaScript from LoadRunner Vugen. Consult the function reference for more details. This is supported from LoadRunner 11.5 onward.

I will be providing a working example below.


Action()
{
web_js_run(
"Code=getQuotes(LR.getParam('symbol'));",
"ResultParam=param",
SOURCES,
"File=XMLHTTPRequest_sync_sample.js"ENDITEM,
LAST);

return 0;
}


Create the below XMLHTTPRequest_sync_sample.js under Extra Files

var req2;
function getQuotes(mySymbol)
{
var myURL=
'http://download.finance.yahoo.com/d/quotes.csv?s=' + mySymbol + '&f=nsl1op';
req2 = false;
// branch for native XMLHttpRequest object
try {
req2 = new XMLHttpRequest();
catch(e) {
req2 = false;
}
if(req2) {
req2.open("GET", myURL, false);
req2.send("");
}
return req2.responseText;
}

Some data you can use for symbol parameter :

symbol
FLWS
FCTY
FCCY
SRCE
FUBC
VNET
JOBS
EGHT
AVHI
SHLM
AAON
ASTM
ABAX
ABMD
AXAS
ACTG
ACHC
ACAD
ACST
AXDX

Sample output.log from the execution:

Starting iteration 1.
Notify: max connections per server : 2
Starting action Action.
Action.c(3): web_js_run started   [MsgId: MMSG-26355]
Action.c(3): Started Sync download of URL="http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op"   [MsgId: MMSG-26000]
Action.c(3): t=1588ms: Connecting [0] to host xx.xx.xxx.xx:80   [MsgId: MMSG-26000]
Action.c(3): t=1614ms: Connected socket [0] from yy.yyy.yy.yy:33504 to xx.xx.xxx.xx:80 in 25 ms   [MsgId: MMSG-26000]
Action.c(3): t=1614ms: 249-byte request headers for "http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op" (RelFrameId=1, Internal ID=1)
Action.c(3):     GET /d/quotes.csv?s=FELE&f=nsl1op HTTP/1.1\r\n
Action.c(3):     User-Agent: Mozilla/5.0 (compatible; MSIE ; Windows; Trident/4.0)\r\n
Action.c(3):     Accept-Encoding: gzip, deflate\r\n
Action.c(3):     Accept-Language: en-US,en;q=0.5\r\n
Action.c(3):     Accept: */*\r\n
Action.c(3):     Connection: Keep-Alive\r\n
Action.c(3):     Host: download.finance.yahoo.com\r\n
Action.c(3):     \r\n
Action.c(3): t=1646ms: 538-byte response headers for "http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op" (RelFrameId=1, Internal ID=1)
Action.c(3):     HTTP/1.1 200 OK\r\n
Action.c(3):     Date: Mon, 30 Sep 2013 23:16:06 GMT\r\n
Action.c(3):     Set-Cookie: B=3vbfeq994k1hm&b=3&s=cf; expires=Thu, 01-Oct-2015 23:16:06 GMT; path=/; domai
Action.c(3):     n=.yahoo.com\r\n
Action.c(3):     P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PS
Action.c(3):     D IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV IN
Action.c(3):     T DEM CNT STA POL HEA PRE LOC GOV"\r\n
Action.c(3):     Cache-Control: private, no-cache, no-store\r\n
Action.c(3):     Expires: -1\r\n
Action.c(3):     Pragma: no-cache\r\n
Action.c(3):     Connection: close\r\n
Action.c(3):     Transfer-Encoding: chunked\r\n
Action.c(3):     Content-Type: application/octet-stream\r\n
Action.c(3):     \r\n
Action.c(3): t=1660ms: 9-byte chunked response overhead for "http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op" (RelFrameId=1, Internal ID=1)
Action.c(3):     000002e\r\n
Action.c(3): t=1660ms: 7-byte chunked response overhead for "http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op" (RelFrameId=1, Internal ID=1)
Action.c(3):     \r\n
Action.c(3):     0\r\n
Action.c(3):     \r\n
Action.c(3): t=1668ms: 46-byte chunked response body for "http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op" (RelFrameId=1, Internal ID=1)
Action.c(3):     "Franklin Electric","FELE",39.40,38.47,38.91\r\n
Action.c(3): t=1669ms: Closing connection [0] to server download.finance.yahoo.com - server indicated that the connection should be closed   [MsgId: MMSG-26000]
Action.c(3): t=1670ms: Closed connection [0] to download.finance.yahoo.com:80 after completing 1 request   [MsgId: MMSG-26000]
Action.c(3): t=1670ms: Request done "http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op"   [MsgId: MMSG-26000]
Action.c(3): Ended synchronous download of URL="http://download.finance.yahoo.com/d/quotes.csv?s=FELE&f=nsl1op"   [MsgId: MMSG-26000]
Action.c(3): Synchronous download ended/terminated with any other pending request(s). Synchronous downloads count=0   [MsgId: MMSG-26000]
Action.c(3): Notify: Saving Parameter "param = \"Franklin Electric\",\"FELE\",39.40,38.47,38.91\r\n".
Action.c(3): web_js_run was successful, 46 body bytes, 538 header bytes, 16 chunking overhead bytes   [MsgId: MMSG-26385]
Ending action Action.
Ending iteration 1.
Ending Vuser...
Starting action vuser_end.
Ending action vuser_end.
Vuser Terminated.





How to increase HTTP connection limit in LoadRuner


Default is 2 as you can see from the output.log

Notify: max connections per server : 2

Use the below function to increase it from say 2 to 6.

web_set_sockets_option("MAX_CONNECTIONS_PER_HOST","6");




Unable to start Glassfish server

In case you are not able to start the Glassfish server from netbeans, please try the below options.


  1. Find out which process is using the port and then kill the other process from task manager.
netstat -aon | find ":80" | find "LISTENING" -> this should help you locate the process id.
    2. Go to Glassfish server administration page and stop Glassfish server.

         localhost:4949 (Glassfish server administration page) click on 'server (Admin Server)' in the left pane,            then press the 'Stop' button.





Thursday, August 1, 2013

Tools tools tools...

Compiling a list of popular performance tools here...

No no... I am not talking about an electric saw... for now just limited to web performance tools.


  • Closure Compiler  - This is a java app that compiles from JavaScript to better JavaScript so that it can be downloaded faster and run faster. Web version can be found here
  • Add async attribute can be added to the script tag so that  javascript parsing can be put off so that the web page can be rendered faster. 

Monday, July 29, 2013

Looking for some good online training?

Here I would keep on updating some of the good online & free training materials.


Wednesday, July 10, 2013

What to do with Bots??? Web crawlers???


Getting considerable visits to you page? Well soon you will have more visits from Bots that from the real users. It is a phenomenon we have to live with. But then we can make a few changes to how we deal with them based on their characteristics.

1. Good Bots : Some companies have a different way of handling good bots. You need to take good care of them as they always lead you to more and more traffic which may lead to higher conversion. One way I have found in use is to redirect them to a different origin. Why we need to do this is because, it then becomes easier for NOC to distinguish between real issues and noise from the bots. You can always use robots.txt to define rules to see if you can get some of the major bots to behave well. You can even specify a time for crawl. What I have seen is that googlebot causes more then 75% of the requests from bots.

2. Bad Bots: Consider blocking them at Akamai WAF level or at the web server level based on the User-Agent value. You may even have to use you secondary fiirewall to add in additional rules.


Providing below some know bots.

  • *googlebot* 
  • *msnbot* 
  • *Yahoo!* 
  • *jobot*
  • *dotbot* 
  • *Pipes* 
  • *yacybot* 
  • *Python* 
  • *skJeeves* 
  • *AdsBot-Google* 
  • *YandexBot* 
  • *bingbot* 
  • *Ultraseek* 
  • *rogerbot* 
  • *youdaobot* 
  • *Mechanize* 
  • *Jakarta* 
  • *decobot* 
  • *curl* 
  • *psbot* 
  • *Slurp* 
  • *discobot* 
  • *MaxPointCrawler* 
  • *sogou* 
  • *ezooms* 
  • *RedCarpet* 
  • *bingshoppingbot* 
  • *FatBot* 
  • *spotbot* 

Also some times, bad bots will not have an easily identifiable User-Agent and so it may become necessary to block them by IP. For anonymous network routes likes Tors, it will be a different strategy. Will cover it some time in future. 


Monday, July 1, 2013

CloudTest Videos


You can find some good videos on SOASTA CloudTest here. Some of them could have been made better.

http://cloudlink.soasta.com/t5/CloudTest-Videos/bg-p/CloudTest_Videos

Tuesday, June 4, 2013

Performance Testing of MQ with Load Runner

Many a times we want to post some x messages/sec to an MQ using loadrunner and wonder if there is an easy way to do this. Over the net you will find a lot of articles but I will limit it to the basic steps to successfully do this.

The key for successfully doing this is to know your MQ. Rest is all easy. This post will cover the testing of Websphere MQ using web services license on a Windows Controller machine.

Steps:

  • Download and install the IBM Websphere MQ client on the Controller machine OR LoadGenerator. Click on Setup.exe and follow the instructions.























  • After installation, go to C:\Program Files (x86)\IBM\WebSphere MQ\java\bin provided you chose the default path for install. Edit JMSAdmin.config. The only changes I made in the file are given below for reference. 
    • INITIAL_CONTEXT_FACTORY=com.sun.jndi.fscontext.RefFSContextFactory
    • PROVIDER_URL=file:/C:/JNDI


  • Now we need to provide all the queue level information you know and create a .scp file. I have created one called myfile.scp. The contents from the file I created is pasted below. Make sure that you check with development team and find the right port, channel name, queue name & queue manager name. Unless you get the right it will not work.
DEFINE QCF(QueueConnectionFactory) QMGR(MYOWNQUEUEMGR) tran(client) chan(PROVIDECHANNELNAME) host(Hostname or IP here) port(1414 or OTHER PORT)
DISPLAY QCF(QueueConnectionFactory)
DEFINE Q(MYOWNQUEUE) QUEUE(
MYOWNQUEUE) QMGR(MYOWNQUEUEMGR)
DISPLAY Q(
MYOWNQUEUE)
end

  •  Go to C:\Program Files (x86)\IBM\WebSphere MQ\java\bin & execute the command as shown below





This will create a .bindings file in the C:\JNDI directory. The verbose output of the above command is given below.

























  • Now we need to make the following run time settings change to our web services vugen script.
    • Change JNDI initial context factory to “com.sun.jndi.fscontext.RefFSContextFactory”
    • Change JNDI provider URL to “file:/C:/JNDI”
    • Change JMS connection factory to “QueueConnectionFactory” and click OK

















  • Now create a script and all should work. Check the queue depth and if the listeners are stopped, you should see an increase in depth. 

Sunday, April 14, 2013

Cron Schedule

Sometimes you just cannot avoid cron....I just had to write a schedule for some alerting of suspicious activity.

Providing link to a good article explaining how to schedule tasks using cron tab.


Thursday, April 11, 2013

Usability, Richness and Performance

Through this article I will be covering the Usability, Richness and Performance aspects of the mobile websites of some major retail companies in the US. I will limit myself to mobile version of the home page of these sites.

The sites I am planning to cover are taken from the -  Keynote Performance Index: Mobile Commerce (Retail) – US - Week Ending 7 April 2013 . These are arranged from the fastest to the slowest.

RankRetailerScore (out of 1,000)*Load Time (in seconds)Success Rate (percentage)
 1Barnes & Noble9504.4399.87
 2Grainger8424.2699.50
 3HSN8386.8499.75
 4Office Depot8314.7099.51
 5Toolfetch.com8122.8499.26
 6Amazon.com8006.7599.62
 7J.C. Penney7828.7099.75
 8PetSmart7588.3199.64
 9Target7458.6299.63
 10American Eagle Outfitters74111.2399.87
 11Sears6962.8998.88
 12Walgreens6946.5199.25
 13Dick's Sporting Goods69212.8399.87
 14Walmart.com6507.9699.25
 15Rakuten Shopping6497.5899.20

To be continued...

Monday, April 8, 2013

Browser Metrics - WebPagetest & Gomez & CatchPoint & others....


Most of us will be using some monitoring tool to measure the website performance. For example we have 2 sites to monitor and we want to compare how Site 1 did with respect to Site 2.

Here comes the world of monitoring tools. There are a lot of them and I am going to mention few of the key ones.
  • WebPageTest - This is a free version and quite popular
  • Keynote
  • Gomez
  • CatchPoint.

The above ones are also quite popular but they are not free and usually in use by large companies to have a record of their website performance, alert them in case of issues etc. I have been using CatchPoint lately and like the interface, support and features.

Now coming back to browser metrics. To keep it simple, I will start with a few and then keep on adding to this post. Will use the metrics provided by WebPageTest as this is widely used and free. See the example from a test I ran on WebPageTest.org. It is always a good practice to run at least 5 tests to find the data you are looking for. Some documentation can be found here webpagetest-metrics




  • OnLoad event - This is an event fired by the browser when it has loaded all the static contents. Onload waits on images too. The ready event occurs after the HTML document has been loaded, while the onload event occurs later, when all content (e.g. images) also has been loaded. 
  • Document complete is when the OnLoad event has been fired.
  • Fully Loaded - Usually after static content/main page has been loaded, javascript will cause to load some more (dynamic) content.. Suppose after dynamic content has been loaded there is no network activity for ~2 seconds, then it can be considered that the WebPage has been fully loaded. In calculating the fully loaded time, this 2 seconds is not included though. The measurement is till the point of the last network activity before this 2 seconds of no network activity. 


Sunday, February 24, 2013

Dance of Bots

Was doing some research to find some higher volume incidents reported by TrueSight. Know that these due to increase bot activity but sometimes, not able to or not worth taking action if these volumes can be managed by the site.

Please find the Dance of Bots for the time interval I was exploring from Splunk.