How to make the web sound interesting

A few days back, I wrote about the 15th anniversary of the world wide web. Robert Cailliau, who worked with Sir Tim Berners-Lee on the creation of the web, commented that, at the time, his only reservation about the name was that “it is difficult to pronounce in French“.

Since then, those of us whose native tongue is English have grown used saying “double-you-double-you-double-you”, to the point where there are now a number of abbreviations (I tend to say “dub-dub-dub” – a habit I picked up from antipodean radio adverts a few years back), or often the www gets dropped entirely. This topic has been discussed at length on the back pages of IT Week over the last couple of months and one suggestion for reducing the number of syllables was “wibble”. Of course, once you change the language it starts to get more interesting… apparently the Welsh version is “ooh-ooh-ooh”.

Cars

Not that I’m about to start doing movie reviews here, but when they exclusively use CGI then I think that falls under my technology remit…

Cars

Last Friday, I dragged my wife along to the cinema to see Cars (the latest release from Pixar Animation Studios).

It’s the first time that I’ve been to a film where all the trailers are for animations too; although if they are a judge of what’s coming then Pixar don’t have too much to worry about from the competition. Toy Story goes down in history as the first fully computer animated feature film but that was a long time back and these days the fact that a film is exclusively generated using computer graphics is not enough – it needs to have all the other elements of a great film in place too.

Now I must confess that I’m a fan of Pixar movies and I’ve been waiting to see this film since I first caught sight of a teaser a couple of years back – I’m pleased to say that it did not disappoint.

CarsCars
CarsCars

As do all successful animations, the film caters to both adult and child audiences; however at 121 minutes it is a bit lengthy, considering that many of the viewers will be children. After the initial NASCAR excitement it slowed down and took a while to build as the characters were introduced and the scene set; but the second hour more than made up for the first. Making a bunch of cars seem human is no mean feat and Pixar have done a fantastic job, from Lightning McQueen the rookie racecar to Doc Hudson the reluctant retiree with a cast of supporting characters including Sally Porsche, Mater the towtruck, the delightful Luigi the Fiat (and his sidekick Guido the Italian forklift), Sheriff the Police cruiser, Sarge the WW2 Jeep and my favourite – Fillmore – the hippy VW Microbus. With cameo appearances from none other than Jeremy Clarkson (as Lightning McQueen’s agent – in the UK release only) and Michael Schumacher, this may not be the best Pixar film ever, but they are all pretty excellent and this one’s at least a 9/10.

Happy birthday to the world wide web

A couple of years ago, I wrote a post highlighting the 35th anniversary of the Internet. Today it’s the turn of the world wide web – for which Tim Berners-Lee (now Sir Tim Berners-Lee) posted a message on the alt.hypertext newsgroup encouraging people to try out the concept on 6th August 1991.

At that time, I was studying for my BSc in Computer Studies and this is just one example of how irrelevant that degree was (I’m still struggling to think of anything learned in my studies that has been useful in the subsequent 12 years that I’ve been working in IT). Although there was some object oriented programming in Modula-2 (along with some C/C++) we were still learning COBOL. Up and coming operating systems (e.g. OS/2 and Windows NT) were ignored in favour of Unix and the low level language I used was 68000 assembler (not 8086). In my final year of studies (1993-1994) I did at least have the opportunity to study distributed computing but there was no mention of such concepts as hypertext in my classes. Perhaps all of this is a little harsh at it would have been difficult back then to forsee the effect that the world wide web has had on our lives.

It was not until 1995 that I first used a graphical web browser and was introduced to the delights of Yahoo! and Altavista. My first online service was a CompuServe account and later I migrated to dial-up Internet access before finally getting a broadband connection in 2002. Today, in common with many others, I rely on the world wide web for an increasing number of services – at home and at work.

Read more about the creation of the web.

Opening up the Mac Mini – easy when you know how

Woohoo! 2GB RAM in my Mac for less than half the amount that Apple would have charged me (does anybody want to buy 2x256MB 667MHz DDR2 SODIMMs that have been used for just one month?).

Mac with 2GB RAM installed

Ordinarily, I’d say that upgrading the RAM in a PC is no big deal, but Mac Minis don’t have any screws to open the case; and unlike many notebook PCs, it not a case of popping open a small panel either.

Thankfully the instructional videos at the OtherWorldComputing Tech Center include a hardware upgrade tutorial for the Intel Mac Mini which showed exactly how to do it (thanks guys – if you sold memory in the UK I would have bought it from you).

So, armed with a Stanley DynaGrip 50mm filling knife that I picked from B&Q on the way home and an old plastic visitors pass (from Microsoft of all places!), I gained access to the inside of my Mac and swapped out the standard 256MB SODIMMs for two new 1GB modules from(which arrived in 24 hours with free shipping by Royal Mail Special Delivery – and there was 5% off the day I bought them, so they only came to £178.59 including VAT).

The operation wasn’t without it’s hiccups. First of all, I didn’t quite insert one of the memory modules correctly so when I booted the Mac it only saw 1GB of RAM. Then, when I reopened the computer to investigate, the knife slipped and I made a small scratch on the outside of the case (annoying, but too late to do anything about it now). I refitted the RAM, but dropped one of the screws inside the unit and the airport antenna came off whilst I was trying to locate the missing screw… that was a bit of a heart-stopper but it was easily reattached (once I worked out where to fix it). Finally, I forgot to reattach the small cable at the front of the motherboard so the fan ran continuously until I opened the Mac up for a third time and reattached the missing connector. Notwithstanding all of these errors, everything is working now and the extra memory should make everything a lot faster.

Controlling spam using the Microsoft Exchange intelligent message filter

It may just be a co-incidence, but since I switched my e-mail from my ISP’s servers to my own server a few months back, I’ve been seeing a huge increase in the amount of unsolicited commercial e-mail (UCE) – commonly known as spam – in my mailbox.

At the time of writing, statistics from MessageLabs show a decline in the volumes of spam over the last 12 months (although they still indicate that 58.39% of all e-mails sent were spam). Postini’s statistics suggest that 73% of e-mail is spam.

If you think those statistics are bad, according to Microsoft, Bill Gates receives 4 million spam messages a day, making him probably the most spammed man in the world (it’s no surprise then that he is rumoured to have his own mail server at Microsoft).

Any effective strategy for dealing with UCE (specifically for Exchange Server 2003, but the generic advice is the same for all mail servers) needs to operate a multiple levels within the e-mail transport (these are defined on the Message Delivery Settings under Global Settings in Exchange System Manager but need to be imposed using the properties for each SMTP virtual server):

  • Server-level accept/deny lists can be used to always accept, or always deny, messages from certain domains. The trouble with this method of trapping e-mail is that I occasionally receive non-delivery reports (NDRs) for messages that were allegedly sent from markwilson.co.uk but that actually never came near my servers, so without a real-time DNS lookup mechanism to verify the sender’s domain (such as Sender ID), these are of limited use.
  • Connection filtering using real-time block lists (RBLs) is the next level of protection, using a DNS query against a RBL provider’s servers, such as the SpamHaus project.
  • Sender filtering can be used to drop any messages that claim to come from a particular e-mail address, optionally archiving them.
  • Recipient filtering is a method of rejecting certain e-mail addresses (e.g. for people who have left the organisation, or for non-existent addresses). One option is to filter messages for recipients who are not in the directory; however this can leave an organisation open to a directory harvest attack as the server gives different responses for valid and invalid addresses. To avoid such attacks, a “tarpit” (see Microsoft knowledge base article 842851) can be employed, to delay responses to bad addresses by a few seconds, slowing down any directory harvest attacks significantly (it would normally be possible to harvest all four-character address combinations within a few minutes – with a 5 second tarpit delay this is increased to a couple of months – and most addresses have much longer aliases than 4 characters).
  • Finally, the intelligent message filter (IMF – previously a separate download but now included with Exchange Server service pack 2) employs a Microsoft-proprietary algorithm (SmartScreen) to scan each message and mark it with a spam confidence level (SCL), which is then used to process the mail accordingly at the gateway or mailbox level.

Each of these tools filters out less obvious types of UCE with increasing levels of cost in terms of server resource. Whilst the junk e-mail filters in Outlook 2003/2007 and Entourage 2004, which are also based on SmartScreen but doesn’t use the SCL mechanism, are pretty good at filtering messages, they are far from perfect (in my experience, Outlook seems to be better at this than Entourage). Activating the IMF on my server has provided an additional level of filtering which has greatly reduced the volume of UCE making it through as far as my mailbox.

The IMF uses 11 SCL ratings, set as an attribute in the message header:

  • -1 is used for messages submitted internally with an authenticated connection – eliminating false positives for internal e-mail.
  • 0 is used for messages that are marked as not spam.
  • 1-9 are used to highlight varying levels of probability that a message is spam (9 being the most likely).

Within Exchange, the SCL value can be used to filter UCE on gateway servers as well as with a lower level SCL used by the information store to move messages to the user’s junk e-mail folder – therefore allowing for the most obvious UCE to be trapped at the gateway (least chance of false positives) and for users to retrieve any messages in the mid-range that are incorrectly marked as junk. The gateway blocking action is also configurable – with options for archival, deletion (without NDR), no action, or rejection.

Archived messages will be saved (by default) to %programfiles%\Exchsrvr\Mailroot\vsi 1\UCEArchive. Each message is archived as an .EML file, which can be viewed with a text editor. To resubmit a message for delivery it can simply be moved to the corresponding %programfiles%\Exchsrvr\Mailroot\vsi 1\Pickup folder. Obviously, viewing individual messages in a text file is time-consuming and the IMF Archive Manager is a great tool for managing IMF-archived messages.

The SCL at which to block messages for a particular organisation will vary according to the profile of e-mail sent to/from the organisation – I have my SCL level for gateway blocking set to 7 with archiving enabled and so far I have only had one false positive – but clearly for organisations receiving more e-mail than I do, this will be a bigger issue! At the store level (set to move messages with an SCL greater than 4) things are not working quite so well but that is to be expected as in the grey area between good and bad mail, some legitimate (good) messages will inevitably get marked with the same SCL as the (bad) UCE. It’s worth noting that marking a sender as safe in Outlook will only override the SCL at the mailbox-level – it has no effect at the gateway.

To assist in judging the SCL levels to use for filtering, it is possible to expose the SCL in Outlook and in Outlook Web Access (OWA). Also useful may be (temporarily) enabling diagnostic logging on the MSExchangeTransport\SMTP Protocol for a server, such that SMTP events are logged. Performance monitor counters from the MSExchange Intelligent Message Filter object can also be used to log the amount of spam filtered or acted upon, the relative SCL levels and overall IMF performance. Based on the performance monitor data, the IMF gateway blocking configuration can be reduced from no action to archive, and then finally (once confident that the levels are correct) to delete, as the appropriate SCL levels are determined.

It’s also possible to mark the SCL on archived messages by creating an new registry key called ContentFilter at HKEY_LOCAL_MACHINE\Software\Microsoft\Exchange\ and a corresponding DWORD value named ArchiveSCL set to 1. A string value named ArchiveDir can also be used to change the archive folder. Both of these settings are detailed in the Microsoft Exchange Server TechCenter along with details for applying the IMF to trusted (authenticated) connections and increasing the size limit for the rule used to process spam at mailbox level (allowing more blocked and safe senders).

Suggested further reading
IMF release notes (Microsoft knowledge base article 867633).
Microsoft Exchange Team Blog.

Creating a customised Windows XP CD using nLite

Last night, when I was installing Windows on my Mac, I needed a Windows XP CD with service pack 2 included (i.e. a slipstreamed service pack as Apple Boot Camp doesn’t allow the use of a non-SP2 CD). I didn’t have one – only a Windows XP (RTM) CD, an integrated SP1 CD, and an SP2 update CD – but that’s no problem, as you can create your own slipstreamed XP SP2 CD.

The official method linked above works well, but (as highlighted in the August 2006 edition of Personal Computer World magazine) there is an easier way – using the excellent (and free) nLite deployment tool for unattended Windows. After copying the contents of my original Windows XP (RTM) CD to a temporary location on my hard disk, I was able to use nLite to integrate the service pack (from my SP2 CD) and make a bootable .ISO image of the new distribution (ready for burning to CD using the software of my choice) using just a few mouse clicks. I could also have integrated drivers (e.g. the ones from the Macintosh driver CD that Boot Camp creates), included updates/patches, removed components, applied tweaks and generally customised the Windows XP installation to suit – all using one simple wizard.

Thanks to Dino Nuhagic (Nuhi) for creating nLite (and for making it free) – it really is a very useful tool.

Installing Windows on my Mac

Tonight, I committed heresy – I installed Windows on my Mac.

Ironically (and this is where I need to eat a small amount of humble pie, having previously criticised the OS X interface – although I did also say that I don’t like the new Windows Vista Aero interface or KDE), when I bought my Intel-based Mac the intention was to run Windows but then I decided to give Mac OS X a spin and I quite like it. There is a big caveat though – most Mac users zealots will say that once you switch you’ll never want to go back and I don’t fall into that camp. I now run Windows XP SP2, Windows Server 2003 SP1, Windows Vista beta 2, Mac OS X 10.4.7 and SUSE Linux 10 on my various machines (some virtual, some physical) and each has it’s place. The fact that I can dual-boot between the two that I use for my desktop work is an added bonus.

Although Mac OS X, iLife 06, Microsoft Office 2004 for Macintosh and Microsoft Messenger for Mac provide enough features to cover at least 90% of my daily computing needs, I do still need to use Adobe Photoshop (and that’s not yet optmised for MacIntels) and Microsoft Money 2000(although I’m sure there’s something available for the Mac that I could use instead). I also have legacy (and partially complete) digital video that I edited using Windows Movie Maker 2.0 and I don’t have the time to re-edit it. For that reason, Windows will be on my Mac for a while.

I chose to use Apple Boot Camp (v1.0.2 Beta) – other methods of installing Windows XP on a MacIntel are available – and the rest of this post summarises my experiences of this (relatively straightforward) operation.

The first thing to note is that Boot Camp is currently beta software and although no indication is given of how long it will continue to work for, the licensing agreement does make it clear that use of the software is for a limited time only. It’s also unsupported.

The Boot Camp beta is provided in a disk image file called BootCamp102.dmg. This contains three files:

  • Boot Camp Beta Installation & Setup Guide.pdf
  • BootCampAssistant.pkg
  • Read Before You Install.app

The first of these files is an extremely readable, 17-page, document that describes the basic steps to install and configure Boot Camp; however there are some extra points highlighted below that might be useful.

Firstly, my brand new Mac didn’t have the latest firmware on it. Although Software Update said I was up-to-date from a software perspective, I also needed to download and install Mac mini (early 2006) Firmware Update 1.0.1. This successfully brought my firmware up from MM11.004B.B00 to MM11.0055.B03 but it’s also worth planning for less successful updates. Apple’s advice for dealing with failed firmware upgrades requires the Firmware Restoration CD v1.0. As this is supplied in an Apple disk image (.DMG) file, it’s probably worth burning a copy before attempting to upgrade the firmware on your Mac (unless you have another Mac available – .DMG files aren’t much help if you have blown up your Mac and need to download/burn a CD using another operating system).

Once all the prerequisites have been met, running the Boot Camp Assistant is straightforward enough, guiding the operator through the process of creating a Macintosh Drivers CD and creating a disk partition for Windows; however before Boot Camp would let me start the Windows XP installation it insisted on restarting the Mac (using the Power button), resulting in an unclean shutdown (which thankfully didn’t cause any major issues later).

The Windows XP installation is just like any other – although I noticed that it detected my external hard disk (I don’t remember any previous Windows installations recognising USB-attached drives but I may be wrong – I’ve done so many over the years that I probably don’t notice any more). I followed Apple’s advice and installed Windows on the third partition on my internal hard disk (C:) and formatted the disk using NTFS. One downside of the installation is that because the drivers for the Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller are not present within the Windows media, there was no network available during installation to join a domain – not a problem as I could install in workgroup mode and join the domain later.

Windows XP installation on an Intel Mac Mini

After installing the Macintosh drivers and software (with one reboot required part-way through), everything was looking good; however beware that there are three unrecognised devices shown in Device Manager:

  • USB Human Interface Device (USB\VID_05AC&PID_8240\5&12F9C752&0&2).
  • PCI Device (PCI\VEN_8086&DEV_27A3&SUBSYS_00000000&REV_03\3&B1BFB68&0&38).
  • Unknown Device (ACPI\IFX0101\1).

Apple does point out that certain devices are not supported under Windows XP and for the Mac Mini that includes the Apple Remote – I suspect that’s the USB device. At the time of writing, Craig Hart’s PCI and AGP vendors, devices and subsystems identification file doesn’t recognise the PCI device although the vendor class is Intel. The ACPI device is a mystery.

I also found that the headphone socket doesn’t mute the internal speakers when running Windows (it’s fine with Mac OS X) but I can live with that.

Having installed Windows there was some basic housekeeping to be done: join my Active Directory domain (to pick up group policy for Windows updates); install anti-virus software; label the Windows partition to give it a sensible name; and set the default operating system to be Mac OS X. Finally, I installed MacDrive v6.1.4 to allow read/write access from Windows to the external hard disk that holds my data files and is formatted as Mac OS Extended (Journalled) (I previously found the 4GB file size limit with FAT32 to be too restrictive).

So that’s it. After months of talking about it, I finally have Windows running on a Mac – albeit not the Media Center Edition, and without the use of my remote control.

(My digital) life is good.

Problems connecting to Windows Server 2003 shares from within MacOS X

Although I’ve been connecting to Windows XP clients with no issues, each time I attempted to connect to my Windows Server 2003 (SP1) server from the Finder in MacOS X 10.4.7, I was greeted with the following message:

The alias servername could not be opened because the original item cannot be found.

There was nothing wrong with the alias (it was created automatically by OS X when browsing the network) but, as Drew McLellan outlines in his blog, the issue turns out to be related to digitally-signed SMB traffic, which must be disabled.

Strangely, the option to digitally sign communications (if client agrees) didn’t seem to make any difference, so it really is necessary to disable digitally signed communications (always). Although it would seem logical to make the change via Group Policy, this is a computer setting (so is not applied to a user account) and as Macs are not domain members they are not affected by group policy either (although the policy for the target server could be set at domain level)

Beware that if editing local policies, these are overridden by site and domain-level policies; however in this case, it’s probably best to make the change only on those servers to which access is required from a computer that doesn’t support SMB signing as the need for digitally signed communications is intended to prevent man-in-the-middle attacks from occuring and disabling this represents a security risk. Further details can be found in the Microsoft Windows Server TechCenter.