Skip to main content

Posts

Showing posts from 2021

Random thoughts on log4shell

Just as I was with my daily random YouTube video clips watching, I saw one of my subscribed content put up this. This is one of the content I found so far, easier for my to catch up with this vulnerability details. If you prefer read than watch video, there's another online post about the related exploit at fastly is easy to read. Based on the diagram from this article, I think (maybe naively, and maybe it could be sufficient as a mitigation plan, I don't know), having the firewall rules to deny all with allow lists would be the best mitigation option while waiting for a patch. This stop the "query ldap" path at the first phase, thus it won't have a chance to go to the second phase from this vulnerability. Anyway, this log4shell vulnerability has caught attention widely since last week. It has been a disasterous event for IT team. They need to find ways to check if the servers are impacted? Look for automated ways to detect if this log4j library exists in t...

Rename files using power shell

I definitely miss Linux a lot. However, my main working environments are in Windows. It has been 5 years! Just had a call with one of the customers. I need to rename 100+ files. Sigh. During the call, I had time pressure, and I couldn't tolerate with continuous of try and error. So, I used the slowest and safest but human-error-proned way of doing it, rename it manually, one by one. We got silence moment in the call, then we suggested to communicate via email to sync up. Phew, pressure went away. So I did a quick Google search. I have tried to search for this solution for several times, but I never get it right, get it work. Probably I am still unconsciously resisting to PowerShell. Anyway, recently I seems to have more luck with PowerShell! Then, in a few minutes, I finally found the "ultimate" solution! Get-ChildItem *.txt | Rename-Item -NewName { $_.Name -replace 'a','b' } And then, suddenly I found out, I forgot how to do this in Linux... Sigh. ...

WSL - Window Subsystem for Linux

I am not sure how old is this feature available in Windows 10. Recently, I screened through Turn Window features on or off list again and found this. I got excited, and turn it on. I have to admit, this is the best solution for me as of now, which I cannot install Virtual Box on this laptop for whatever reason or policy. :P I did a search on Google and found this page Install WSL by Microsoft. But it says... You must be running Windows 10 version 2004 and higher (Build 19041 and higher) or Windows 11. I checked my system, it is running at a lower version. :( Well, do you think it would stop me from continue? Of course not! If you have it available in the list, of course it should be ready to use! So I go ahead and enable it. Then, maybe I restarted laptop. In case you want to know how and where to enable it, follow these steps. 1. Open Control Panel 2. Click on "Programs" 3. Click on "Turn Window features on or off" 4. A dialog box pop up, scroll to the end...

【有一本書】一看就懂的上古史

看完了這本書,我有種“終於看完了”的感覺。畢竟是自己喜歡的課題,不過因爲有著太多的興趣,還有惰性,這本書在買了五年后才看完,有點過分。不過,至少此刻我可以在自己的checklist裏,劃掉其中一個項目了。開心-ing。 這是一本深入淺出的書。我喜歡作者把歷史、考古、傳説、神話混在一起,寫出他們之間的連接,或吧傳説、神話現實化,邏輯化,因此讓我覺得有種“原來如此”的瞭解。不過,如果真穿越到上古時代,不知道會是怎麽樣的情況。網路小説大都是穿越到架空時代或古代。如果把故事寫成穿越到上古時期,母系社會的時候,會不會可以制止奴隸制度呢?我想遠了。 這支影片是我看了這本書的分享。希望你喜歡。

[有一本書] 老子的部落格 | Lao Tze's blog

我還在想,要不要也在部落格上分享目前同名的YouTube頻道。不過,這支影片有介紹老子的修身、處事的三大法寶,想分享給更多的人。想想了,還是就寫寫吧。 這個系列,源自于想曬自己書房(儲存室)裏的東西演變而成的。不説其他了,直接進入主題。 老子的修身處事三大法寶: 1. 慈。 2. 儉。 3. 不敢為天下先。 詳情,請看影片。 更詳情,找書來看吧!^^