Author Archives: dontai

WordPress Web URIs: wpcspReceiveCSPviol=1 and wpCSPNonce from the WP Content Security Policy Plugin

I started to receive these WordPress URIs after someone read one of my WordPress posts. This confused me. These are connected to WordPress Failure Notices, but not quite.

The first part, wpcspReceiveCSPviol=1, was once used in a WordPress spoof to redirect people to some other site, but there was no other URL and no redirection.

POST /wp?wpcspReceiveCSPviol=1&wpCSPNonce=6606ca489f HTTP/1.1

Ubuntu, VPN Gate, and Open VPN

Find the VPN at http://www.vpngate.net/en/. Filter by OpenVPN only. Look at the transfer rate. Might also see if the IP is responding.

https://www.kabatology.com/05/09/ubuntu-connect-to-vpn-gate-with-openvpn/ Download the OpenVPN file and open it. Cut out the sections between the tags, including the “begin” and “end” certificate. Create a separate directory for each gate. Save as “ca.crt”.

In Ubuntu Edit Connections > Network Connections > add > Open VPN > create. Fill in the form from top to bottom, or the form won’t work. Might want to add the domain name to the label. Choose “password”, vpn, vpn, add the location of the ca.crt file, Save, try.

Canada Day 2017: $2M Spent, $1.5M Not Made in Canada

Here are your tax payer dollars at work. The Canadian government spends $2M CAD on trinkets for Canada Day 2017, our 150th anniversary. $600k of this is purchased from Canadian companies. $1.15M is purchased from China. How revolting. We celebrate Canada Day by making celebratory purchases from another country? This money could have easily benefited fellow Canadians who are looking for work.

City of Toronto Sewer Cleaner, in Canada

City of Toronto uses a specialty sewer sucking truck to clean the sewers. Worker uses a pick axe to remove the grate, plunges the crevice tool down the hole, sucks the garbage out. It takes only about 2 minutes max. Toronto, Canada. Photo 1 by Don Tai

City of Toronto uses a specialty sewer sucking truck to clean the sewers. Worker uses a pick axe to remove the grate, plunges the crevice tool down the hole, sucks the garbage out. It takes only about 2 minutes max. Toronto, Canada. Photo 1 by Don Tai

What is that high pitched sound on the street? It sounds like a large vacuum cleaner, and it was. The City of Toronto sewers were being cleaned by the sewer cleaning truck.

Tempo Baritone Ukelele: Toronto, Canada

Tempo baritone ukelele, unknown origin or date, Toronto, Canada. Photo 1 by Don Tai

Tempo baritone ukelele, unknown origin or date, Toronto, Canada. Photo 1 by Don Tai

This Tempo baritone ukelele came to me very broken, with the back ripped off the sides, both top and bottom, and discarded. I had to do a somewhat significant glue-up in order to stabilize the neck and get the action back to normalcy.

Chinese Chair: Toronto, Canada

Chinese chair, Toronto, Canada. Photo 1 by Don Tai

Chinese chair, Toronto, Canada. Photo 1 by Don Tai

Chinese furniture is pretty rare here. You can find them at specialty Chinese furniture shops within Chinese-only malls. This one came to me discarded and in need of repair. I thought it rare and interesting, so wanted to repair and document it.

The chair has no manufacturer marking on it anywhere. It is not of high quality. Seams are showing. There are painting errors, where the painter put too much paint on and left ghastly drips, right on the front of the back rest. A higher quality chair manufacturer would have sanded down the drip and repainted. Not here.

Nikto Web Server Scan: View from the Access Log

Playing, I am, with the Nikto web server scanning package. I scanned my own site, just for fun. While it does take some time, it did finish. I wondered how it would look from my site’s raw access log viewpoint. In summary, Nikto is not stealthy at all. It is also easily detected and banned mid-scan, as it takes a long time to complete.

Essentially you start a Terminal, and type “nikto -h “. There are lots of options, such as output to a log. The Nikto output highlights web site vulnerabilities and cross references these with a database of known hacks. Using this tool you can highlight the site’s weaknesses and then strengthen your site from hackers.

Ubuntu 16.04 install WebScarab

Here I am with some idle time, found a hacking article on G&M, which led me to some pretty scary hacking tools (malware creation tools) which led me to nikto which led me to WebScarab. Yes, confusing, but I am trying to stay White Hat.

That said, I could not find much on how to install WebScarab. It is older, with no clear install instructions, other than here’s the zip file, install it. WebScarab is written in java, so you can run it from Terminal. I could not figure out how to put it into a launcher.

Skunk in my Front Yard, Toronto, Canada

Skunk in my front yard, Toronto, Canada. He's pretty young. Photo 5 by Don Tai

Skunk in my front yard, Toronto, Canada. He’s pretty young. Photo 5 by Don Tai

Skunks live in my neighbourhood, Toronto, Canada, though are not a common sight. We usually smell them first. Mostly blind, if they come close, just freeze and wait until they walk away. There’s really nothing to fear from skunks.

Due to their natural aroma, skunks have no natural enemies. They wander around at will, eating insects and plants, minding their own business. There is really no reason to kill one.