Friday, December 24, 2010

Introduction to Android

Android is the operating system Linux-based Mobile Phone. Android is open source source code provided free of charge for developers to create their applications to run on Android.Pada initially, Android is one of Android Inc.-made products., But Google acquired Android Inc.., And all intellectual property owned by Android inc. Google Inc. gained. who later developed a system back Android.mengakuisi Android Inc. ..

As information Android Inc.. are newcomers in terms of making software for mobile phones in Palo Alto, California United States. Then formed the Open Handset Alliance, a consortium of 34 companies hadware, software, and telecommunications, including Google, HTC, Intel, Motorola, Qualcomm, T-Mobile, Nvidia, etc.. Open Handset Alliance was formed to develop its Android-which incidentally is the first OpenSource OS for Mobile Phone.

On November 5, 2007, an early version of Android dirilislah where with the Open Handset Alliance's Android states support the development of open standards on mobile devices. On the other hand, Google released the Android code under the Apache license, a license software and open standard mobile device.

In this world there are two types of distributors operating system Android. The first fully supported by Google or Google Mail Services (GMS) and the second is completely free distribution without direct support Google's otherwise known as the Open Handset Distribution (OHD).

The founders of Android Inc.. working at Google, among them Andy Rubi, Rich Miner, Nick Sears, and Chris White. At that time many consider the functions of Android Inc.. just as software on mobile phones. Since then the rumors that Google is about to enter the mobile phone market

In company Google, a team led by Rubin served to develop a program of mobile devices supported by the Linux kernel. This shows an indication that Google is preparing for a competition in the mobile phone market. until now has many Android phones were present in the market, starting from Google Nexus One, HTC Legend, Sony Ericcson Xperia X10, Samsung Galaxy S and many more.

The advantages of Android include:

1. Openness

Android provides access to basic functions of mobile devices using standard calls to the API.
2. Destruction of the border

You can combine information from the Internet into the phone, such as contact information, or data on the geographical location to get a new chance.
3. Similarity application

To Android is no difference between the main phone application and other software, you can even change the program to dial the number, or screen saver.
4. Quick and easy development

In the SDK has everything you need to create and run Android applications, including this simulator instruments, and advanced debugging tools.
Likens Google's Android as a stack of software. Each layer of this stack to collect a few programs that support specific functions of the operating system. The following is the composition of the layer - the layer when viewed from the base layer to the upper layers:

a. Linux Kernel

Pile at the bottom of this Android is a kernel architecture.

b. Android Runtime

The Linux kernel is a layer after Runtime.Android Android Runtime contains Core Libraries and Dalvik Virtual Machine. Core Libraries includes a set of core Java libraries, which means that Android includes a set of basic libraries that provides most of the functions that exist in the base libraries Java programming language.

c. Libraries

Located at the same level with Android Runtime is Libraries. Android includes a set of libraries in C / C + + which is used by the various components that exist on the Android system.

d. Application Framework

The next layer is the application framework, which includes programs to manage the basic functions of a smartphone. Application Framework is a set of basic tools such as resource allocation smartphones,
phone application, the change between - a process or program, and tracking the physical location of the phone.

e. Application

On the top layer located on the application itself. In this layer you find the basic functions of smartphones such as calling and sending short messages, running a web browser, access the contact list,
and others. For the average user, this is the layer most often they access. They access the basic functions through the user interface.

Hopefully helpful

Source image:

dailysocial.net, zdnet.com

Repair CD/DVD ROOM and Troubleshoting


Meet again with thelurunk, the troubleshooting section, this time we will explore completely around the CD / DVD Rom, the problem of CD / DVD ROM, how to treat a CD / DVD Rom though durable, etc., monitoring continues, hopefully troubleshooting CD / DVD Rom is useful.
CD / DVD Rom will not read

Clean the head CD / DVD Rom

cd cleaner
Often I find the question, Kinta kok mas CD / DVD Rom I can not read? even though I just bought 2-3 months ago, the first question I ask is whether headnya ever cleaned?, emang ya need cleaning?, yes need lah. Head on CD / DVD Rom have the same functions as the eyes, if the head / eye dirty then our vision will blurry or unclear, as well as head CD / DVD Rom, the laser beam generated by the head can be blocked by dust which resulted in reading the CD / DVD so it is not smooth. The solution, buy a cleaning CD / DVD Rom, usually equipped with alcohol, how easy life, if not allowed to comment below.
Clean the CD / DVD

Often I find that the surface of CDs / DVDs are fat or old prints of hands, this really makes a CD / DVD Rom will be broken, because the head will be forced to read the CD / DVD, therefore, before the CD / DVD is inserted into the drive, make sure free dirty and fat. To clean the fat or old prints of the hand can use the cd cleaners are sold in computer stores.

CD / DVD Rom will not eject
Ever have a CD / DVD jams do not want removed from the drive?, Of course dong, if this happens, it's easy aja, grab a paper clip, and then while pressing the eject button, enter and press the small hole located on the drive CD / DVD rom. voila, success is not.

Microsoft Releases Research Site HTML5

Microsoft Support to technology HTML5 in the Internet Explorer browser look more seriousness. The software giant also released a special site for development research mengkajikan technology to provide easy access for web developers HTML5 Labs.
Through the site, Microsoft provides the code of the developed prototype technology that can be tested for the developers. Currently there are two prototypes are available, namely the Web Sockets and IndexedDB, two parts of HTML5 are not yet fully completed perfected.
"The prototype, this prototype will help us discuss with the developer community, and provide implementation experience with the draft specification that will generate feedback to improve standards in the end," said Jean Paoli, general manager of Microsoft's Interoperability Strategy, Wednesday (22/12 / 2010).
Web Sockets is a way for elements of web pages to communicate with the server continuously without visitors to refresh. This technology can be used on a website, server, or application clients and servers. Meanwhile, IndexedDB allows website visitors to save data on your computer to be accessible offline, eg for bookmarks or e-mail.
"We chose these two specifications from the beginning because of the potential use of large, but not yet stable enough," says Paoli. Many components of HTML5 already invested in Microsoft's latest browser is still beta, Internet Explorer 9 Beta.

Thursday, December 23, 2010

Hiding IP Address By SwitchProxy

Sometimes you need to make your IP address is not visible, for the safety of your computer network. If you want your IP address is not visible, you can use the SwitchProxy. Add-on for Firefox allows you to monitor and change from a few different proxy settings with ease. You also can use the add-on is as Anonymizer to protect your computer from outside interference.



We all know that using more than one proxy in the normal way is very tiring because we must continuously monitor all of them. With SwitchProxy you can manage all proxy that you use very easily. Add-on also provides a feature to insert, edit, or remove a proxy with a few clicks away. To use a proxy, you just need to select from the list and click Apply.


Anonymizer features provided by SwitchProxy use some proxy fruit were randomly changed within a certain interval. This feature is very useful for people who want to protect their computer from hackers or other parties.

Here's how to make your IP address is not visible by using the SwitchProxy:

The first thing you need to do of course is to download and install the add-on SwitchProxy this.

After the add-on installed, click the Add button, then select the Anonymous of configuration options available, and click Next.

In the next window, you can add a proxy list that you want to use either manually or through a proxy list. You can then give a name for this configuration to facilitate its subsequent use, then click Save.

You can find free proxy lists from this page .

To begin to hide your IP address, you must choose MyProxy from the toolbar, then click Apply. Now that you've hidden the IP address. Very easy is not it?

Conducting Remote Desktop Connection With TeamViewer

We can control a computer remotely, using certain software and Internet networks. The problem is, most software requires a lot of settings that are technical and too complicated. However, the software is now available that can help you control your computer remotely with very easily.


TeamViewer is a software that allows us to do desktop sharing over the Internet. We can control our partner computer located elsewhere, and do things. All this is very easy to do, and even we do not need to bother with things that are technical, such as firewalls, IP addresses, or NAT.

Indeed we can find many similar software, but TeamViewer provides solutions for all types of needs. TeamViewer is very simple and easy to use. We do not even need to install it first. We just need to run this software on our computers, and of course on the computer that we want to control from afar.

We can do many things with the help of TeamViewer. For example, we can show our desktop to our partners, and share product demos, presentations, and so forth. We also can use TeamViewer to control a server.
TeamViewer also provides additional features that are very useful, for example, file transfer feature, which allows us to copy the files and folders between our computers with our partners computer.

We can download and use TeamViewer free of charge, provided for non-commercial purposes. On his official website www.TeamViewer.com available several versions of TeamViewer, which TeamViewer full version, as well as several other versions for more specific purposes, such as to provide customer service, to control the server, and so forth.

Disable Autorun On USB

In the flash disc exposed to the virus usually (not always) there autorun.info file that contains commands to run the virus program. Well, when the flash disc is inserted into the USB drive its autorun feature not be disabled then Windows will automatically run programs at background without a confirmation to the user .

One way to reduce the risk of contracting the virus is to disable the autorun feature on the USB drive. There is also the way is as follows:



1.Click the Start button - Run.
2.Type gpedit.msc and press OK.
3.Click on User Configuration - Administrative Templates - System .
4.Click 2x on the Turn Off Autoplay .
5.Click on the option Enable .
6.At the option Turn off Autoplay on , select All drives .
7.Click OK.
8.Done.

Trusting Password: Network Authentication

Aspects of network security is closely related to the services provided: inbound or outbound. Security on outbound service can be best pursued with firewall configuration. Similarly, with anonymous access inbound servicing, such as anonymous FTP, HTTP, Gopher, etc.. In this case, intentionally provided information for everyone. Another case when we want to provide a non-anonymous access (or authenticated services), where other than through a firewall, someone who is requesting access must also get a 'permission' server after first proving his identity. This is the authentication. Furthermore, the authors use the term as a synonym for the word autentisasi.

RISK-SECURITY SERVICE INBOUND
Why should autentisasi ... ..? The Internet is a public network, and is open to everyone all over the world to join. Once the size of this network, have caused profits and losses. Often we hear and read about bobolnya bank financial computer systems, the Pentagon classified information or data bases students' academic transcripts. The sentence is adequate to represent the statement that we should be 'vigilant' against those 'evil' and always try to minimize the possibility for them to be able to perform his evil intentions. It's easy to exclude the possibility of infiltration (illegal access) from the outside by closing all inbound traffic channel service to the internal network. But this means has reduced the main advantages of the network: communication and the use of shared resources (sharing resources). Thus, a natural consequence with a large enough network, is to accept and try to minimize this risk, not destroy.


We will start from a network-administrator (NA), which has done a good job, in preparing the 'defense' for all services, inbound outbound and anonymous. Need some additional things that should be remembered again. Whether the defense is strong enough for the theft of the relationship (hijacking attack)? What is in it already considered the possibility of illegal monitoring of information packets are sent (packet sniffing - playback attack)? Or is it included readiness to actually illegal access within the system (false authentication)?

Hijacking usually occurs on computers that contact our network, although for some rare cases, can occur at any point in its path. So it is sensible to consider granting the trust a NA of access, only from computers that most do not have the same security system or perhaps more 'strong', compared with the network under its responsibilities. Business minimize the chances of this tragedy, can also be done by adjusting the packet-filter well or use a server modifications. For example, we can provide anonymous-FTP facility for any computer anywhere, but authenticated-FTP is only given to those hosts listed in the list of 'trust'. Hijacking the middle of the path can be avoided with the use of encryption between networks (end to end encryption).

Confidentiality of data and passwords is also the topic of security design. Programs that are dedicated to packet-sniffing can automatically display the contents of each packet of data between client and server. Password protection of such crimes can be done with the implementation of single-use passwords (non-reusable passwords), so that although they could be monitored by the sniffer, the password can not be used again.

The risk of hijacking and sniffing data (not the password) can not be avoided altogether. This means that NA should consider this possibility and perform optimization for the smaller its chance. Restricted number of accounts with full access and remote access time, is one form of optimization.

MECHANISM AUTENTISASI
Subject autentisasi is proof. Evidenced includes three categories: something about us (something you are lignin), something we know (something you know SYK), and something that we have (something you have SYH). Lignin is closely related to the field of biometrics, such as examination-finger prints, retinal eye examination, voice analysis, etc.. SYK is identical with the password. As for SYH commonly used identity cards such as smartcard. \

Perhaps, that is still widely used is air-password system. To avoid password theft and illegal use of the system, it is sensible to our network system equipped with a disposable passwords. How can the application of this method?

First, using time-stamp system unencrypted. In this way, the new password is sent after the first modified based on the current time. Second, using a challenge-response system (CR), where the password that we give depends on the challenge from the server. Roughly we prepare a list of answers (response) is different for the 'questions' (challenge), which differ by the server. Because of course it was hard to memorize a few tens or hundreds of passwords, it would be easier if the memorized rule is to change the challenge provided a response (so not random). For example, our rule is: "kapitalkan fifth letter and delete the fourth letter", then the password that we provide is MxyPtlk1W2 to challenge Mxyzptlk1W2 system.

If the CR system, must be known 'aturan' it, then the time-stamp system, we must remember the password for the provision of these time-stamps. Does not make it this way? How lucky these mechanisms are generally handled by a device, either software or hardware. Kerberos, autentisasi software created at MIT and adopt a time-stamp system, require modifications to the client for time synchronization with the server as well as giving a stamp-time passwords. Modify the client program reminds us of the proxy and indeed, more or less like that. CR systems are usually applied at the same time with hardware support. Examples of operational CR system is a device SNK-004 card (Digital Pathways) that can be applied in conjunction with packet-FWTK TIS (Trusted Information Systems - Internet Firewall Toolkit).

TIS-FWTK offer a solution to single-use passwords (the CR) that 'fun': S / Key. S / Key hash algorithms iteratively apply the procedure to a seed, so the system can validate-client instant response but did not have the ability to predict response-next client. So if there is an intrusion on the system, there is no 'something' that can be stolen (usually a list of passwords). Hash algorithms have two main properties. First, the input can not be regenerated from the output (non-reversible). Second, there are two possible inputs for a same output.

ENCRYPTION AND Cryptography
Cryptography has evolved a long time, when people want information that he sent not to 'read' by parties not interested. Traditionally known as the two mechanisms cryptography, private key or public key. DES (data encryption standard) used by Kerberos to use private-key system. RSA (Rivest Shamir Addleman) implement public-key system. One of the contributors RSA, Ron Rivest and then make MD4 (message digest function # 4) which is used by S / Key his TIS-FWTK. Optimization and crossbreed between the two traditional methods are giving birth PGP (Pretty Good Privacy). Discussion of the DES, RSA, or PGP is a separate book and not in place is disclosed here. But clearly, the private-key system is characterized by the encrypt-decrypt the keys are identical, while the public-key systems, this process is done with two keys: public key to encrypt and decrypt secret key for this key which both generated and have relationships close through a mathematical algorithm. Because the mathematical processes required in advance, the speed of public-key systems can be thousands of times slower than equivalent private-key algorithm, although on the other hand offers better protection. The exploitation of the advantages and disadvantages of public and private key system is PGP, which is done for data transmission-private key system with the session-key so that it runs fast, while the transmission of session-key of his own using public-key.

With encryption, the information we send to a network through another network of safety doubts (the Internet), relatively more secure. Encryption between networks is causing a 'thief' must try a little harder to get illegal information he expected. There are several opportunities for the implementation of encryption, namely: at the application level, data-link level and network level.
Application-level encryption requires the use of client-server software special. In accordance with the OSI reference model, encryption of data-link is only valid for point to point connection, such as encryption system on a phone modem. While encryption network level (network layer) is applied on the router or other equipment adjacent to the tissue on both sides. Optimization of the interests and security policies carried out by adjusting the type / part of the IP packet to be encrypted, adjustments to the firewall architecture and, consequently, the effectiveness of key distribution, encryption, etc.. In the future, where technology VLAN (Virtual LAN) is estimated to be the primary choice for Intranet (enterprisewide), the use of network-level encryption has become so important. Perhaps equally important to state that while a company is 'forced' to use the internet as a route for transmission of sensitive information between the central office with other branches dibelahan earth.

TIS-FWTK Kerberos and Authentication Server
Kerberos is one of the works of Athena project, a collaboration between MIT, IBM and DEC. Kerberos was designed for supporting autentisasi and encryption of data in a distributed environment through modification of standards of client or server. Some operating system vendors have included Kerberos into their products. MIT itself provides for free many versions of Unix that has been in-Kerberizing. Even for the interests ported to the operating system or client-server software that does not support Kerberos, MIT provides its source-code, also is free. Project Athena Kerberos itself implement in many applications such as NFS, rlogin, email, and system passwords. Secure RPC (Sun Microsystems) also implements the same thing.

There are several things to consider in the implementation of Kerberos. Modification of the client and server software will cause the restriction application options. Unfortunately there are no alternative methods as a substitute for source-code modification (as in a proxy that allows custom user procedure or custom client software). Then, most people also agreed to call: "Kerberos is relatively difficult to implement / manage".

The package offered by systems other autentisasi TIS-FWTK: authentication-server. This server is designed in a modular, flexible mechanism that supports many popular autentisasi as standard reusable password system, S / Key, SecurdID card from Security Dynamics (systems with time-stamps), card-004 Digital Pathways SNK (CR system) and ease of integration new mechanism. Back to the conversation at the beginning of this writing, if our primary interest is how to prepare the 'defense' for non-anonymous inbound service, perhaps the authentication-server is a solution worth considering. Why? How does this system work? Not much space in this paper to load all our discussions about autentisasi, but the cover illustration below will give some idea for your interest in network security, concerning the authentication-server.

Author: Eueung Mulyana & Onno W. Purbo