Showing posts with label Web. Show all posts
Showing posts with label Web. Show all posts

Thursday, December 30, 2010

Registry Setting to View HTML Source in IE6 with GVim

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\View Source Editor\Editor Name]
@="C:\\vim\\vim60\\gvim.exe"

Friday, April 30, 2010

Recovering a Deleted Google Account

I just deleted one of my Google accounts by mistake. In panic, I done some web searching on how to restore it. This led me to this page, Why can't deleted Google accounts be recovered? . From there I was led to this form, I can't access my account. After filling in as much information as possible, and submitting the form, my account was restored approximately three hours later. Given that others seemed to have less success, I can only guess I succeed without too much trouble because I could recall some significant details about my account, in particular the date I created it, the password for it, the account creation verification number, and because I linked it to another Google account.

Sunday, October 18, 2009

Deploying a Django Application on Apache WSGI on Windows

Following are some notes I made during my last install of a Django based web application on an Apache web server running on Windows.

This assumes a Django application is being installed on a computer with no prior Django installs. I also describe a particular example, but the same steps can be applied to many applications, just replace my application specifics with your application specifics.

  • Install Python 2.6.
    • Run the MSI installer and install in C:\Programs.
    • Create the following environment variable: PYTHON_HOME=C:\Programs\Python26 (see System Properties/Advanced/Environment Variables).
    • Append the newly created variable to your PATH variable. Also append %PYTHON_HOME%\Scripts and %PYTHON_HOME%\Lib
    • Open a command line prompt, execute the command python. This should start the Python interactive interpreter.
  • Install Django 1.1.
    • Unpack the distribution (usually a tar.gz or .zip file) in some temporary directory. You might need to install (the free and excellent) 7-Zip for this.
    • Open a command line prompt in the directory Django was unpacked in, most likely Django-1.1.
    • Execute python setup.py install (or setup.py install).
    • To check if the install went correctly, you should be able to import the Django module in Python. Start Python from the command line, and execute:
        import django
        django.VERSION
                
  • Install Apache 2.2.
    • Runs the Windows MSI installer provided from the Apache web site.
    • From a web browser, enter the URL http://localhost. A valid web page hosted be Apache should be displayed.
  • Install the modwsgi module.
    • The module file will be named something like mod_wsgi-win32-ap22py26-2.6.so (http://code.google.com/p/modwsgi/downloads/list).
    • Copy it to the modules directory of the Apache installation. E.g., C:/Program Files/Apache Software Foundation/Apache2.2/modules.
    • Rename it to mod_wsgi.so.
    • Open Apache's http.conf file.
      • Add the line LoadModule wsgi_module modules/mod_wsgi.so before all the other LoadModule entries.
      • Configure Apache for your Django project by adding the following to end of http.conf:
        # Static content
        
        Alias /media/ C:/Programs/TestDjango/mysite/media/
        
        <Directory C:/Programs/TestDjango/mysite/media/>
        Order deny,allow
        Allow from all
        </Directory>
        
        # Django dynamic content
        
        WSGIScriptAlias / C:/Programs/TestDjango/mysite/apache/django.wsgi
        
        <Directory C:/Programs/TestDjango/mysite/apache>
        Order deny,allow
        Allow from all
        </Directory>
        

        Where TestDjango is the Django project root. The paths below TestDjango will be specific to your project. This configuration serves all static media via the URL space /media/ and all the rest via WSGI and Django.

      • You may need to create the django.wsgi script if it's not already created. To do so, create a file django.wsgi and add the following to it:
            import os
            import sys
        
            sys.path.append('C:/Programs/TestDjango')
            os.environ['DJANGO_SETTINGS_MODULE'] = 'mysite.settings'
        
            import django.core.handlers.wsgi
            application = django.core.handlers.wsgi.WSGIHandler()
                      

        Note that sys.path.append('C:/Programs/TestDjango') is only needed if your project (TestDjango) is not on Python's path, PYTHONPATH.

    • Restart Apache. For this you can use the Apache Service Monitor from the taskbar tray.
    • From a web browser, attempt to hit the Django application's web page, such as http://localhost/mysite.

Saturday, June 27, 2009

Enable Firefox to Open Local Files Linked From an Intranet Website

Often an Intranet website will have links that reference files (such as Word documents, PDFs, Excel spreed sheets) located on mapped network drives (such as file://N:/share/myword.doc). In Internet Explorer, clicking on such links will download the referenced file to the client and open it. Unfortunately, this does not work in Firefox without some manual configuration. My understanding is Firefox has disabled this feature by default to prevent malicious web sites from trying to link to and open files in your local directories (a security policy that Internet Explorer choose to ignore).

You can configure Firefox to download and open files linked from explicitly specified websites to the client's local drive (and mapped drives) by adding the following to the file user.js (create this file if it doesn't exist) in Firefox's profile directory (which should be something like: C:\Documents and Settings\Caleb\Application Data\Mozilla\Firefox\Profiles\abcde123.default, where abcde123 could be any sequence of characters):
user_pref("capability.policy.policynames", "localfilelinks");
user_pref("capability.policy.localfilelinks.sites",
   "http://web.intranet.com");
user_pref("capability.policy.localfilelinks.checkloaduri.enabled",
   "allAccess");
You can specify more than one web site by separating each address with a space. For example, to add both http://web.intranet.com and http://web, use:
user_pref("capability.policy.policynames", "localfilelinks");
user_pref("capability.policy.localfilelinks.sites",
   "http://web.intranet.com http://web");
user_pref("capability.policy.localfilelinks.checkloaduri.enabled",
   "allAccess");
I'm using Firefox 3.0, but I believe the above is true for all versions of Firefox greater than 1.5.

Sunday, June 14, 2009

Internet Explorer 8 Standards Compliant ("Compatibility") Switches

Internet Explorer 8 is the most standards compliant version of IE yet. To ensure backwards compatibility with existing web pages that target IE7 (and to a lesser extent, IE6), IE8 has standards compliant and non-compliant modes. Following are three methods to select one or the other mode:
  1. Compliant mode is enabled by default for web pages on the Internet and disabled for web pages on the Intranet. [1]
  2. When in compliant mode, a GUI button is available to switch to non-compliant mode. [1,4]
  3. Force a particular mode for a given web page by inserting the meta element at the start of the head section, "before all other elements except the title element and other meta elements."[2] For compliant mode use <meta http-equiv="X-UA-Compatible" content="IE=8" /> and for non-compliant mode use <meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /> [1,2,3]
One other note: from JavaScript, the property document.documentMode will be present and set to 8 when compliant mode is used, otherwise this property doesn't exist. [1,2]

References

[1] D. Esposito, "Internet Explorer 8 and Compatibility Views", Dr. Dobbs Digest, March 2009
[2] MSDN, "Defining Document Compatibility".aspx), Feb 2009
[3] diTii.com, D'Technology Weblog, "IE8: Standards mode and IE7 compatibility mode", Aug 27, 2008
[4] IEBlog, "Introducing Compatibility View", Aug 27, 2008

Thursday, January 15, 2009

Obscuring URLs

I stumbled upon an old article today entitled How to Obscure Any URL: How Spammers And Scammers Hide and Confuse. Quoting from its summary, the article describes three ways to obscure URLs:
  1. Meaningless or deceptive text can be added after "http://" and before an "@" symbol.
  2. The domain name can be expressed as an IP address, in dotted-decimal, dword, octal or hexadecimal format.
  3. Characters in the URL can be expressed as hexadecimal (base 16) numbers
Two more ways come to mind that are most useful if you are building your own website:
  1. Use indices or hashes for object references. For example, www.mywebsite.com/myapp?objectref=1.
  2. Use a hash function (say MD5 or SHA-1) to hash the URL and use the result as a key to the real URL. For example, www.mywebsite.com/this/is/a/private/path might become www.mywebsite.com/f061a171dfc30635462850684f98b886. This is similar to what URL shortening services such as TinyUrl do.
References
  1. How to Obscure Any URL: How Spammers And Scammers Hide and Confuse, www.pc-help.org, 2002

Wednesday, December 17, 2008

RIAs and the Future of the Open Web

In The Struggle for the Soul of the Web Chris Keene writes:

Just because the web has been open so far doesn't mean that it will stay that way. Flash and Silverlight, arguably the two market-leading technology toolkits for rich media applications are not open. Make no mistake - Microsoft and Adobe aim to have their proprietary plug-ins, aka pseudo-browsers, become the rendering engines for the next generation of the Web.

and

The worse the underlying browser is at rendering rich widgets and media, the more developers and users will want your plug-in. If you are both the vendor of a browser (say IE) as well as the proponent of a plug-in (say Silverlight), then the incentives get truly twisted.

I believe this is why Microsoft (MS) has hijacked JavaScript 2.0 (I can't figure out why Yahoo didn't support it) and is hijacking HTML 5. These standards would enable other companies to more easily develop rich widgets and media frameworks that would compete directly with Siliverlight. From MS's point of view, that is unacceptable. Although both Adobe and MS have "pseudo-browsers", MS is a much bigger threat to an open and standard internet because they also create one of the worlds leading browsers, Internet Explorer (IE) --- the potential for proprietary lock-in here is huge.

Consider what happens with increasing adoption of Silverlight. First, Silverlight no longer works so well in non-IE browsers, then a year or two later it's only supported by the top two browsers, and once a critical mass is achieved, it only works in IE. I can see the website banners now: "viewable only using IE and Silverlight". What browser do you think most people will be forced to use? And since IE is tied to Windows, websites will essentially become Windows OS dependent. Moreover, developers will be forced to use the .NET framework for Silverlight, that leads to developers having to use MS development tools on a MS OS... where does it end? Why would MS even care about or need open web standards once all users are locked into using IE+Silverlight+Windows?

I think Silverlight --- the VM and its development tools --- is a great solution for RIAs. However, I'm a strong supporter of open standards that benefit all of our industry. As such, I will avoid, as much as possible, Silverlight for fear I may contribute to the demise of our open web.

References

[1] Chris Keene, The Struggle for the Soul of the Web, AjaxWorld, ajax.sys-con.com, Dec, 2008.

Tuesday, December 9, 2008

Methods for Speeding Up Your Website

YAHOO Developer Network has an excellent article (Best Practices for Speeding Up Your Web Site) that describes 34 ways to improve your website performance. You can also see live examples of 14 of these items at 14 Rules for Faster-Loading Web Sites.  The article is especially pertinent to developers who make heavy use of JavaScript+AJAX, HTML, and CSS (as opposed to Flash, for example) in their websites.
Following is a listing for easy reference: Make Fewer HTTP Requests; examples here Use a Content Delivery Network; examples here Add an Expires or a Cache-Control Header; examples here Gzip Components; examples here Put Stylesheets at the Top; examples here Put Scripts at the Bottom; examples here Avoid CSS Expressions; examples here Make JavaScript and CSS External; examples here  Reduce DNS Lookups Minify JavaScript and CSS; examples here Avoid Redirects; examples here Remove Duplicate Scripts; examples here Configure ETags Make Ajax Cacheable Flush the Buffer Early Use GET for AJAX Requests Post-load Components Preload Components Reduce the Number of DOM Elements Split Components Across Domains Minimize the Number of iframes No 404s Reduce Cookie Size Use Cookie-free Domains for Components Minimize DOM Access Develop Smart Event Handlers Choose <link> over @import Avoid Filters Optimize Images Optimize CSS Sprites Don't Scale Images in HTML Make favicon.ico Small and Cacheable Keep Components under 25K Pack Components into a Multipart Document

Friday, December 5, 2008

Why Use Abobe Flex?

Here are some reasons you might want to use Abobe Flex (Flash) to build the UI (or some part thereof) for your next web application:
  • It's an open source development kit.
  • It comes with everything needed to build and deploy Flex UIs. It does not include an IDE, but you can buy an IDE or plug-in for Eclipse to dramatically ease development.
  • It is supported and principally developed by Adobe. Hence, it has commercial backing with invested cooperate interest. Some would argue this lowers the risk of Flex becoming vaporware anytime soon. Adobe also offers commercial support.
  • It has a large and growing development community. For example, it has a sister open source project for unit testing called FlexUnit.
  • It is used by many large and small corporations.
  • It is based on standards (at least we can argue it is; JavaScript 2.0, HTTP, XML, etc.) and proven technology, such as Flash.
  • It has extensive documentation.
  • It has a large library of existing UI and non-UI components. One can also buy libraries of custom components (e.g. charting and graphing).
  • It is flexible and extensible. For example,
    • it can be integrated into any existing web page without completely taking over that web page (it can do that too if desired!);
    • all GUI and non-GUI components can be extended and customized;
    • it can access a number of back end data sources and application frameworks, including Java Servlets, Flex Data Services, and REST; and
    • it can use different communication mechanisms, including raw TCP/IP sockets, HTTP, and SOAP.
  • It works well with Java back ends, such as servlets and EJBs. Hence, you can harness existing expertise and code base with few changes.
  • The development model is easy to use and understand. For example, you can use XML to layout GUI components, JavaScript 2.0 (which is Java like, at least more so than JavaScript 1.5) for attaching behavior to the components, and a simple set of APIs for accessing the server.
Although this is supposed to be a post about why you should use Flex, I have to add this negative point because it caused me no end of grief in my last project: Flex/Flash does not have a component to display standards compliant HTML/CSS. So, if you're like me, and you have some existing HTML content you want to display in the UI, you're out of luck. There are some options available, such as rendering content outside Flash and overlaying it on Flash using IFrames, but I was never satisfied with them. Here are some links about using such approaches:

Wednesday, December 3, 2008

Conditional CSS

Even though CSS is a standard, there are differences in how web browsers render and support CSS. By far the biggest deviant is IE6, which has the poorest compliance of the major browsers I support (FireFox, IE, Safari). In some cases you can simply tolerate the differences, but more often than not you have to find workarounds to convince the non-compliant browser to do what you want. I generally target FireFox first to get what I want (because it has good standard compliance and has FireBug) and then tweak the CSS to workaround IE issues. Following are two methods to conditionally include CSS depending on the target browser. CSS Hacks The first method is to exploit CSS parsing bugs in browsers (mainly IE) to accept or ignore CSS attributes. This is often called CSS hacking. Although commonly used, it is not recommended [1,2]. Two common hacks prefix CSS attributes with a special character to select browser and browser version: *attribute -- for IE 7 and below (I haven't tested on IE 8) _attribute -- only IE 6 and below attribute -- all other browsers Example: div { *width: 20px; _width: 20px; } Conditional Comments The second method is to use conditional comments [1,2]. This relies on a feature in IE to conditionally include HTML and CSS content using special commands embedded in comments. This is the recommend method because it does not depend on bugs to work. However, it is not as tidy or simple to use as CSS hacks and it can't be used for other browsers. Furthermore, it relies on modifying the HTML source to work. The following example includes the CSS resource file main.css if the browser is IE 6. <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="main.css" /> <![end if]--> You can also use comparators such as lt and gt. This example only includes the CSS file if the browser is IE 7 or less. <!--[if lte IE 7]> <link rel="stylesheet" type="text/css" href="main.css" /> <![end if]--> References [1] http://www.javascriptkit.com/dhtmltutors/csshacks.shtml [2] http://www.quirksmode.org/css/condcom.html

Saturday, November 29, 2008

Website SSL Certificates

Understanding Web Site Certificates [1] has a nice succinct description of website certificates. In summary, a website certificate is used to identify a secure web site, in the sense that it is a trusted web site (e.g. not a phishing site), and data being transmitted and received to and from your browser is secure (e.g. encrypted using SSL). Trusting a certificate means you are trusting one authority from a list of certificate authorities known by your browser to have verified the web site you are visiting is legitimate and secure. Although rare, this process has been known to fail. Brian Krebs in The New Face of Phishing [2] described a sophisticated phishing scam that used a valid SSL certificate issued by a "trusted" authority. If you visit a website that has a certificate signed by an organization untrusted by your browser or the certificate contains an error (e.g. certificate has expired), the browser displays a dialog prompting you to decide if you want to accept the certificate [1]. Before accepting a certificate, ensure it
  • has a valid and trusted issuer, such as Verisign,
  • has not expired, and
  • has been assigned to the web site organization you are visiting.
If this dialog is not displayed, say because your browser accepts the certificate, you can still manually examine the certificate if you wish. Normally this can be done by clicking on some visual indicator on your browser while you are on the protected site. Don't just assume that because a website is protected by a certificate that site must be legitimate. Some phishing sites have used self-signed certificates to create the illusion of legitimacy [3]. It is the site authors hope the unwary visitor would be tricked into believing that because they have been given a certificate, the site is secure so they can safely submit their personal information. A web site who issues a certificate to itself should always be viewed with some suspicion [4]. Do you need SSL certificates for intranet (internal only) websites? If you are transmitting sensitive information between browsers and servers that some employees should not see (e.g. passwords), then yes. This assumes you believe your employees are malicious enough to start snooping for such confidential information. What about phishing? This may be less of an issue because the phisher would need to know the look and feel of your internal website in order to mimic it convincingly. But if such information can be obtained, then SSL certificates would be useful. References
[1] Mindi McDowell and Matt Lytle, National Cyber Alert System, Cyber Security Tip ST05-010, Understanding Web Site Certificates, Carnegie Mellon University, 2008 [2] Brian Krebs, The New Face of Phishing, The Washing Post, 13 Feb 2006 [3] Bill Brenner, Phishers' latest hook: SSL certificates, The New Sendmail, 27 Sep 2005 [4] Jack Schofield, Website certificates -- don't go there?, 2007

Tuesday, November 25, 2008

Top 10 Web Application Security Vulnerabilities

If you are developing web applications, and don't know the meaning of and how to prevent the following 10 security threats, OWASP Top 10 is good reading material.
  • Cross Site Scripting (XSS)
  • Injection Flaws
  • Malicious File Execution
  • Insecure Direct Object Reference
  • Cross Site Request Forgery
  • Information Leakage and Improper Error Handling
  • Broken Authentication and Session Management
  • Insecure Cryptographic Storage
  • Insecure Communications
  • Failure to Restrict URL Access