<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Oliver&#039;s Yard - Ollie Cronk&#039;s Blog</title>
	<atom:link href="http://blog.cronky.net/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://blog.cronky.net/blog</link>
	<description>Thoughts on Technology and Whats going on with Ollie...</description>
	<lastBuildDate>Tue, 13 Mar 2012 01:18:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Have had a chance to get hands on with Window 8&#8230; still unconvinced!</title>
		<link>http://blog.cronky.net/blog/?p=446</link>
		<comments>http://blog.cronky.net/blog/?p=446#comments</comments>
		<pubDate>Tue, 13 Mar 2012 00:45:11 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[MS Windows Vista 7, 8 etc]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=446</guid>
		<description><![CDATA[Following on from my previous post about MS dropping the start menu in Win 8 (although its still kind of available if you move your mouse to the far bottom left hand corner of the screen). Have been running this on Oracle VirtualBox (in 64bit mode using Windows 7 as host) I won&#8217;t re-invent the [...]]]></description>
			<content:encoded><![CDATA[<p>Following on from my <a title="Windows 8 will drop the start menu – is this the beginning of the end for MS OS dominance?" href="http://blog.cronky.net/blog/?p=412">previous post about MS dropping the start menu in Win 8</a> (although its still kind of available if you move your mouse to the far bottom left hand corner of the screen).</p>
<p>Have been running this on Oracle VirtualBox (in 64bit mode using Windows 7 as host) I won&#8217;t re-invent the wheel and do a full review &#8211; lots of that already out there &#8211; eg <a href="http://www.pcadvisor.co.uk/reviews/windows/3284198/microsoft-windows-8-review/">http://www.pcadvisor.co.uk/reviews/windows/3284198/microsoft-windows-8-review/</a></p>
<p>Not finding the user experience that great &#8211; I hope they are going to do a fair amount of polishing before this gets released! Anything that requires an <a href="http://windowsteamblog.com/windows/b/windowsexperience/archive/2012/03/08/getting-around-in-windows-8.aspx">official blog post this long to explain the basics of how to use it with a keyboard and mouse</a> has to be a bit worrying?</p>
<p>Great post on the Guardian that sums up similar thoughts to me nicely: <a href="http://www.guardian.co.uk/discussion/comment-permalink/14922607">http://www.guardian.co.uk/discussion/comment-permalink/14922607</a>. Reading through the mixture of comments makes me think that Windows 8 should be renamed Windows Marmite!</p>
<p>Will be interesting to see how things play out here &#8211; will MS just get sidelined by another wave of Apple product adoption (this time more mainstream desktop users at home and in the office) or will this work and they manage to cling on to OS dominance &#8211; only time will tell!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=446</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 8 will drop the start menu &#8211; is this the beginning of the end for MS OS dominance?</title>
		<link>http://blog.cronky.net/blog/?p=412</link>
		<comments>http://blog.cronky.net/blog/?p=412#comments</comments>
		<pubDate>Mon, 06 Feb 2012 23:04:05 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[MS Windows Vista 7, 8 etc]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows 8]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=412</guid>
		<description><![CDATA[So Microsoft is dropping the start button from Windows in v8&#8230; I think this is a silly move &#8211; surely one of the things that keep people tied to Windows is the fact that they know how to use it. If they (badly) copy Mac / Linux and force people to re-learn how to navigate [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://bit.ly/yxEtoT">So Microsoft is dropping the start button from Windows in v8</a>&#8230;</p>
<p>I think this is a silly move &#8211; surely one of the things that keep people tied to Windows is the fact that they know how to use it. If they (badly) copy Mac / Linux and force people to re-learn how to navigate the OS won&#8217;t more people just switch to Mac/iPad and Linux? Especially given Android&#8217;s recent successes, and the continuing Apple obsession?</p>
<p>Just need Google to ditch the cloud obsession from their Chromebook / Chrome OS or create an Android for PCs to accelerate it&#8230;</p>
<p>I hope for MS sakes they keep an option in to make the OS look like Windows 7 &#8211; eg a basic theme?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=412</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tech Update 2011</title>
		<link>http://blog.cronky.net/blog/?p=386</link>
		<comments>http://blog.cronky.net/blog/?p=386#comments</comments>
		<pubDate>Mon, 02 Jan 2012 23:16:44 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[Web Browsers]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=386</guid>
		<description><![CDATA[Its been a while since I&#8217;ve posted one of my Tech discoveries so this will cover quite a bit&#8230; Originally wrote this back in April 2011! Being a dad doesn&#8217;t allow much time for blogging! In fact I am tempted to shut down this blog (given my usage of twitter, linkedin and FB means it [...]]]></description>
			<content:encoded><![CDATA[<p>Its been a while since I&#8217;ve posted one of my Tech discoveries so this will cover quite a bit&#8230;</p>
<p>Originally wrote this back in April 2011! Being a dad doesn&#8217;t allow much time for blogging! In fact I am tempted to shut down this blog (given my usage of twitter, linkedin and FB means it gets less of a look in these days) &#8211; or move it to the cloud&#8230;</p>
<p><strong>Good Stuff</strong></p>
<p>Sony Vaio SA Core i7 laptop &#8211; will post a separate review in due course, but this is a really nice machine for Windows 7 (and running a couple of other OS via VirtualBox!) upped mine to 8GB RAM &#8211; amazingly quick, small, light and very good battery life on stamina (only downside &#8211; can be a but noisy / hot in speed mode under load).</p>
<p>Flat Ethernet cables &#8211; awesome &#8211; see my other post about home AV setup &#8211; but they are great for running under carpet, laminate through closed (and locked) window openings!).</p>
<p>Google Chrome Browser &#8211; very fast (makes even Firefox feel sluggish, and IE is distinctly snail like in comparision), robust and now it has plugins its great &#8211; my main browser at home.</p>
<p>Blackberry Bold &#8211; call me a luddite (and behind the times given the recent down with RIM news that is all over the media) but I like a good straightforward work phone, no touchscreen just a plain old qwerty keypad for quickly typing out emails and texts and amazing battery life. Oh ok so yes I wouldn&#8217;t say no if work offered me an Iphone instead&#8230;!</p>
<p>Amazon selling laptop batteries for £20 &#8211; with the SSD drive and upgrade to Win7 my 4 year old Vaio  is running really well (update &#8211; well it was! Its now been replaced with an SA Series Vaio &#8211; now gets used when the daughter is around and don&#8217;t want to risk the new one getting attacked!).</p>
<p>HP Elitebook laptops &#8211; have had a Tablet and a 14&#8243; laptop and both have been excellent. I will be disappointed if HP do drop their PC line &#8211; they do some good (if perhaps a little bulky by today&#8217;s standards) kit.</p>
<p><strong>Bad</strong></p>
<p>Going back to XP and Office 2003 at work, although I have now managed to get up to 2007 which is a relief! Windows 7 should come later in the year fingers crossed!</p>
<p>SSD Hybrid hard disk drive &#8211; good idea in principle but needs to mature a bit (friend had one fail on him with medium term use, might have just been a dodgy one though).</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=386</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Streaming HD content to your TV via a PS3 from a Linux Server (or Windows PC)</title>
		<link>http://blog.cronky.net/blog/?p=410</link>
		<comments>http://blog.cronky.net/blog/?p=410#comments</comments>
		<pubDate>Wed, 09 Nov 2011 00:52:28 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Sony Stuff]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[PS3]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=410</guid>
		<description><![CDATA[Quick post &#8211; caveat haven&#8217;t had a chance to proof read this one and its late so it will have to do for now! You may not be aware that you can use a Playstation 3 to act as a media streaming/playback client using a system called DNLA (also known as uPNP). This allows you [...]]]></description>
			<content:encoded><![CDATA[<p><em>Quick post &#8211; caveat haven&#8217;t had a chance to proof read this one and its late so it will have to do for now!</em></p>
<p>You may not be aware that you can use a Playstation 3 to act as a media streaming/playback client using a system called DNLA (also known as uPNP). This allows you to view content on your computer on your main TV in HD. Windows Media Player can act as the &#8220;Server&#8221; portion but its not ideal for connecting to the Playstation.</p>
<p>Crude diagram here, might expand this with my full setup when I get a chance:</p>
<p><a href="http://blog.cronky.net/wordpress/wp-content/uploads/2011/11/home-av-setup1.png"><img class="alignleft size-full wp-image-417" title="home-av-setup" src="http://blog.cronky.net/wordpress/wp-content/uploads/2011/11/home-av-setup1.png" alt="" width="600" height="500" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>I have been trying to get this working for a while. Essentially the plan is to get access to downloaded videos, videos from my camcorder (now HD) to save burning it to DVD or Blu-Ray and also access my photos and music collection from my Ubuntu Linux server that holds all my content (on a RAID 1 mirrored disk setup) to my TV and home cinema/HiFi setup.</p>
<p>Last time I tried to use a small command line utility and my PS3 was only connected via Wireless to the Server &#8211; the result was stuttering music let alone videos. So its something I gave up on for the time being.</p>
<p>Recently I have been able to overcome this as I have discovered flat gigabit ethernet cables that I can run out of my double glazed windows (even when shut!) so I have hacked a gigabit backbone that connects my TV and AV kit (including PS3) to my Linux Server (in fact the very one that served this blog page to you) that hold gigabytes of multimedia (now there&#8217;s a word you don&#8217;t hear much these days!)</p>
<p>Also discovered http://code.google.com/p/ps3mediaserver/ which is a great Java based server component for PNP based streaming &#8211; as the name suggests its specifically designed for connecting the PS3 up to content&#8230;</p>
<p><a href="http://blog.cronky.net/wordpress/wp-content/uploads/2011/11/ps3media-streaming.png"><img class="alignleft size-medium wp-image-415" title="Screenshot of ps3mediaserver" src="http://blog.cronky.net/wordpress/wp-content/uploads/2011/11/ps3media-streaming-300x241.png" alt="Screenshot of ps3mediaserver" width="300" height="241" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Hey presto excellent quality video (including 1080p video) and music on the TV / HiFi!</p>
<p>Next to work out how to get my iTunes (stuff that only plays on iTunes rather than MP3s) music across and available to the PS3. I have moved and shared the my iTunes media folder (as have that on the network too &#8211; as per these instructions &#8211; <a href="http://lifehacker.com/230605/hack-attack-share-your-itunes-music-library-over-your-home-network">http://lifehacker.com/230605/hack-attack-share-your-itunes-music-library-over-your-home-network</a> - so I can re-use iTunes across different machines &#8211; and keep it backed up).</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=410</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is costly, &#8220;big bang&#8221; IT dying? Long live iterative approaches and best of breed Open Source?</title>
		<link>http://blog.cronky.net/blog/?p=343</link>
		<comments>http://blog.cronky.net/blog/?p=343#comments</comments>
		<pubDate>Thu, 22 Sep 2011 19:07:15 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Architecture and Strategy]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Architecture]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Open Standards]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=343</guid>
		<description><![CDATA[This is an article I have been stewing on for a while and having recently changed from a consultancy largely working on public sector IT projects back to a private sector IT department its given me several different view points. I also recently attended the excellent Zapthink SOA and Cloud course in Amsterdam &#8211; so [...]]]></description>
			<content:encoded><![CDATA[<p>This is an article I have been stewing on for a while and having recently changed from a consultancy largely working on public sector IT projects back to a private sector IT department its given me several different view points.</p>
<p>I also recently attended the excellent <a href="http://www.zapthink.com/soa-training-certification/">Zapthink SOA and Cloud course in Amsterdam</a> &#8211; so I am now a Licensed/Certified Zapthink Architect!</p>
<div class="wp-caption alignnone" style="width: 610px"><a href="https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-snc7/320613_146929005401076_114533551973955_247278_572986188_n.jpg"><img title="Zapthink course in Amsterdam" src="https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-snc7/320613_146929005401076_114533551973955_247278_572986188_n.jpg" alt="Zapthink course in Amsterdam" width="600" height="337" /></a><p class="wp-caption-text">Zapthink course (creating a SOA implementation roadmap), my colleague Martin is on the left</p></div>
<p><strong>Time for a change?</strong></p>
<p>In the continued difficult financial climate will organisations continue to have the appetite and budget to  invest in large scale greenfield COTS IT projects and licensing? e.g. Large scale commercial enterprise systems such as ERP? And what&#8217;s the next success for Open Source Software (OSS)?</p>
<p>Is the future a more incrementally / agile delivered open source, best of breed systems? Rather than big monolithic, generic packaged software that does everything ok but doesn&#8217;t excel at much if anything. And worst of all, often requiring the business to change its processes to fit the software.</p>
<p>Instead I am thinking of solutions that are developed on Open Standards / common platforms (eg J2EE) using common / standards based middleware and the XML family of technologies  to connect them together. Of course there is a risk that if you pick and choose lots of niche software that serves its job well then you can end up with a big mess of spaghetti integration and duplication. But that is where effective Architecture, standards and Governance comes in; to keep things on the right track and aligned with business priorities.</p>
<p>Certainly the agile (iterative) methodology seems to be taking hold in larger companies, although waterfall still seems to be favoured in government &#8211; due to the perception that it will result in a fixed cost (shame that too often it doesn&#8217;t deliver successful results as its too rigid, ends up costing far more through cunning use by the vendor of change control and depending on the project the initial build can be as little as 10% of the total costs in any case).</p>
<p>What about the cloud? Isn&#8217;t that supposed to reduce costs&#8230;</p>
<p>I think many in the IT industry (well vendors anyway) right now would argue that the answer to this is delivery via the cloud using a pay as you need it service based model (to get away from having to make the big upfront investment in hardware and licensing). I guess this is an option but I think most large businesses (who have the budgets for the larger IT projects) are looking at the cloud quite sceptically, waiting for it to mature beyond e-Commerce and online type applications and add the required security and reliability that is needed. Keeping things in their own data centre and exploiting virtualisation to optimise costs at the Infrastructure layer. Cloud as your Disaster Recovery (DR) / Data Archiving environment looks like one of the most compelling use case so far.</p>
<p>I am seeing some suggestions that organisations would like to adopt this approach in some areas (eg Integration). In fact one of the places I worked in the past built its own home grown ERP / eLearning platform on Open Source. In my current role we are looking at Open Source alternatives &#8211; particularly for Integration and Infrastructure glue.</p>
<p>Its interesting to see how the adoption of Open Source has matured &#8211; from just the Linux OS used for servers, Linux + Apache for static web moving towards LAMP and other Apache projects such as Tomcat etc even more so with &#8220;Web 2.0&#8243;. Data Integration / ETL is a big area for OSS &#8211; eg <a href="http://www.talend.com">Talend</a>, ActiveMQ, Glassfish. J2EE is a big success story too.</p>
<p>And of course now with Android OSS has finally come into contact with the casual end user (rather than the techies like me that run Linux on the desktop). This was brought home to me the other day when a completely non IT friend showed me his <a href="http://www.motorola.com/Consumers/US-EN/Consumer-Product-and-Services/Tablets/ci.MOTOROLA-XOOM-with-WiFi-US-EN.alt">Motorola Xoom</a> and was extolling its usability etc.</p>
<p>Interesting times. Wonder where OSS will infiltrate next? I guess the answer is probably wherever it can disrupt the marketplace in a engaging way for the consumer, or with a commercial model that is compelling to business/IT decision makers.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=343</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Useful resources for Enterprise Architecture</title>
		<link>http://blog.cronky.net/blog/?p=372</link>
		<comments>http://blog.cronky.net/blog/?p=372#comments</comments>
		<pubDate>Tue, 01 Feb 2011 11:29:35 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Architecture and Strategy]]></category>
		<category><![CDATA[Architecture]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[weird thoughts]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=372</guid>
		<description><![CDATA[Since attending the Seminar by Gartner on Enterprise Architecture last year I have been focussing on formalising my IT Architecture skills (well when time allows!!). TOGAF (The Open Group Architecture Framework) 9 appears to be the way to go. You can think of it much the same way as PRINCE2 is to Project Management &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p>Since attending the Seminar by Gartner on Enterprise Architecture last year I have been focussing on formalising my IT Architecture skills (well when time allows!!). <a href="http://www.opengroup.org/togaf/">TOGAF (The Open Group Architecture Framework) 9</a> appears to be the way to go. You can think of it much the same way as PRINCE2 is to Project Management &#8211; its something that provides the core principles but it needs to be tailored to the organisational specifics.</p>
<p>Came across &#8220;TOGAF 9 in pictures&#8221; available on <a href="http://www.orbussoftware.com/downloads">http://www.orbussoftware.com/downloads</a> which is a really effective way of getting to grips with the core concepts.</p>
<p>Also (on the same site) found a stencil for <a href="http://www.archimate.org/">ArchiMate</a>; Archimate is a means of standardising the way that Enterprise Architecture is defined at a high level. Chapter 2 of the specification makes good reading &#8211; has a nice summary on why EA: <a href="http://www.opengroup.org/archimate/doc/ts_archimate/index.html">http://www.opengroup.org/archimate/doc/ts_archimate/index.html</a></p>
<p>From my research IT Architecture (in particular Enterprise Architecture) still seems to be something that different people and organisations view differently &#8211; in particular role definitions / responsibilities seem to vary massively. I also fear that often the goal behind EA initiatives aren&#8217;t clear enough and some organisations just want to &#8220;tick the EA box&#8221; rather than get true value from it.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=372</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft OneNote with a Tablet PC to reduce paper usage</title>
		<link>http://blog.cronky.net/blog/?p=149</link>
		<comments>http://blog.cronky.net/blog/?p=149#comments</comments>
		<pubDate>Tue, 01 Feb 2011 11:12:29 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=149</guid>
		<description><![CDATA[I am seriously impressed by Microsoft OneNote and the HP Tablet that I am now using. I realised I was creating quite a bit of waste paper from my notes &#8211; so have moved them electronically. I have a workbook for work and one for personal tasks and sync the workbooks between my home and [...]]]></description>
			<content:encoded><![CDATA[<p>I am seriously impressed by Microsoft OneNote and the HP Tablet that I am now using. I realised I was creating quite a bit of waste paper from my notes &#8211; so have moved them electronically.</p>
<p>I have a workbook for work and one for personal tasks and sync the workbooks between my home and work folders which is really neat. I have been using this setup for several months (mostly using the keyboard although sometimes in meetings the stylus is a faster and easier way of capturing thoughts and diagrams).</p>
<p>Visio 2010 is pretty cool tool, I would have to say that Windows 7, Visio and OneNote are my top 3 Microsoft products right now!</p>
<p>Visio 2010 even has support for Inking and Multi-touch &#8211; <a href="http://blogs.msdn.com/b/visio/archive/2009/12/18/visio-2010-better-with-windows-7.aspx">http://blogs.msdn.com/b/visio/archive/2009/12/18/visio-2010-better-with-windows-7.aspx</a> and the MS blog  has some other pretty handy tips: <a href="http://blogs.msdn.com/b/visio/">http://blogs.msdn.com/b/visio/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=149</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Preparing a web environment for Security Penetration Testing&#8230;</title>
		<link>http://blog.cronky.net/blog/?p=356</link>
		<comments>http://blog.cronky.net/blog/?p=356#comments</comments>
		<pubDate>Fri, 17 Dec 2010 21:29:46 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Architecture and Strategy]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=356</guid>
		<description><![CDATA[We&#8217;ve gone through quite a few security / penetration / web application tests at work (often as part of compliance with HMG SPF / InfoSec standards for UK Government projects) and thought it would be useful to list some of the steps you need to consider (hardening, configuring etc) to ensure your application has a reduced [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve gone through quite a few security / penetration / web application tests at work (often as part of compliance with <a href="http://www.cabinetoffice.gov.uk/media/111428/spf.pdf">HMG SPF</a> / InfoSec standards for UK Government projects) and thought it would be useful to list some of the steps you need to consider (hardening, configuring etc) to ensure your application has a reduced security exposure. I feel that you should view security testing as an opportunity to improve the quality of your work rather than see it as a box ticking exercise (ultimately the testing is about making your application more secure which can only be a good thing). Whilst a lost of our work is based on LAMP (Linux, Apache, MySQL, PHP) many of the concepts below apply regardless of the technology used.</p>
<p><strong>Firewalls and Port Access</strong></p>
<p>Firewalls and access to ports &#8211; one of the most obvious &#8211; but you need to consider whether the risk profile requires one or 2 levels of hardware firewall, or whether iptables is sufficient. Can you lock down the environment such that you only expose port 80 or 443 to wider internet and create a restricted IP address based white list for administration (eg SSH access)? On many of our Architectures we only expose the load balancer(s) and or proxy layer to the internet, everything else is not available at all to general IP addresses across the internet.</p>
<p>If you do have to have SSH open to all make sure that you install denyhosts (which helps to prevent SSH brute force attacks by adding persistant bad username/password attempts to /etc/hosts.deny &#8211; preventing access from the offending IP address)</p>
<p><strong>Cross Site Scripting (XSS) and SQL Injection vectors</strong></p>
<p>Check that your application does something sensible if someone attempts to put javascript into text input boxes. Check that putting in something like:</p>
<p>&#8220;&gt;&lt;script&gt;alert(&#8216;If you see this in an alert box there is a XSS vector in your application&#8217;)&lt;/script&gt; into a username box (for example) does. If it brings up an alert dialog you know you have a problem. <a href="http://en.wikipedia.org/wiki/Cross-site_scripting">See the  XSS Wikipedia page for more info.</a></p>
<p>Similarly for SQL &#8211; if you put in rogue SQL key words does it mess with the SQL that is run? Do something non- destructive (particularly if you are spot checking a live web site environment!) A good example I like to use is can I add parameters to a where clause to see data I shouldn&#8217;t be able to see.</p>
<p>Personally I prefer 2 levels of checks for SQL Injection and XSS type code in application input: &#8211; one at the application input layer (eg sanitising user input asap) and another at the database interface / wrapper layer to ensure nothing nasty can get sent to be stored or messed about with on the database tier.</p>
<p><strong>Server Hardening / Configuring</strong></p>
<p>Ensuring the server is setup and configured properly</p>
<p>Google for and check the hardening guide for the operating system for recommended steps.</p>
<p>Ensure that security updates are being applied on a regular basis.</p>
<p>Ensure that anti-virus software is installed (for the Linux Platform ClamAV is an option)</p>
<p>Review (and peer review if possible) the configuration files for the main services on this box &#8211; for LAMP this means a minimum of:</p>
<p>(You can run locate &lt;name of config file&gt; to check where it is located)</p>
<ul>
<li>/etc/ssh/sshd_config</li>
</ul>
<ul>
<li>php.ini</li>
</ul>
<ul>
<li>httpd.conf / apache2.conf (depending on how the server is configured) and configuration files for virtual hosts / SSL configuration</li>
</ul>
<ul>
<li>my.cnf (or other database config)</li>
</ul>
<ul>
<li>Load Balancer config files (for Pound this is typically /etc/pound.cfg)</li>
</ul>
<p>These checks are particularly important if you are having a white box review of your system (where you give the SSH login details to a security tester to check the configuration).</p>
<p><strong>Pre test checks</strong></p>
<p>Before you hand over the system to the Internet Security guys run some of the kinds of tools that they will be running yourself to see what is available. As a minimum run an NMAP command against your ip addresses:</p>
<p>nmap -A -vv [IP Address]</p>
<p>And see what ports (and information about the ports) is returned. Also check if NMAP can enumerate what Operating System and Versions of Web Server software is running (can you do anything to remove version numbers or product names?)</p>
<p>These days  I like to use <a href="http://www.backtrack-linux.org/">Backtrack</a> (a Linux Distribution design for security testing) for security checks. I am running it as a Virtual Machine from with my Windows 7 machine (<a href="http://g0tmi1k.blogspot.com/2010/01/tutorial-video-how-to-install-backtrack.html">http://g0tmi1k.blogspot.com/2010/01/tutorial-video-how-to-install-backtrack.html</a> as a useful video for getting it set up).</p>
<p>I could probably write all day about security but hopefully this gives a feel for the key aspects. Would be interested to hear anyone&#8217;s tips or must dos for LAMP security.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=356</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First Dad post!</title>
		<link>http://blog.cronky.net/blog/?p=351</link>
		<comments>http://blog.cronky.net/blog/?p=351#comments</comments>
		<pubDate>Fri, 26 Nov 2010 21:49:52 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Baby / Parenting Related]]></category>
		<category><![CDATA[Life]]></category>
		<category><![CDATA[Baby]]></category>
		<category><![CDATA[weird thoughts]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=351</guid>
		<description><![CDATA[So this blog will almost certainly become more bullet point and note based &#8211; I make no apologies for that! My daughter Ella Cronk was born on the 28th Oct &#8211; a few days early! 1st Nov was due date. She was 6lbs 13. Now weighs 8lbs at time of writing. Pregnancy &#38; Birth were [...]]]></description>
			<content:encoded><![CDATA[<p>So this blog will almost certainly become more bullet point and note based &#8211; I make no apologies for that!</p>
<p>My daughter Ella Cronk was born on the 28th Oct &#8211; a few days early! 1st Nov was due date. She was 6lbs 13. Now weighs 8lbs at time of writing.</p>
<p>Pregnancy &amp; Birth were pretty straightforward but the first week wasn&#8217;t! In particular breastfeeding and weight loss.</p>
<p><strong>Learnings:</strong></p>
<ul>
<li>Even if you plan to Breastfeed, have some ready made UHT formula on hand. We&#8217;ve been using Aptimil to great success (recommended and used by the NHS near us).</li>
<li>The books and advice don&#8217;t always work &#8211; take a blend of things and decide for yourself what is best.</li>
<li>Be prepared to get your baby cooler if she is too sleepy to feed at least once every 3 hours or so.</li>
<li>Nappy changes aren&#8217;t as bad as I thought they would be &#8211; in fact in most cases they are a nice opportunity to have some awake time with a newborn (they will spend a lot of time asleep).</li>
<li>We quickly learned that Medela kit for breast feeding is very good (as is the Philips Avent stuff according to friends and NHS staff). We&#8217;ve binned most of our Tommy Tippee stuff. This Amazon review (and the fact that its been reduced so heavily and the Medela hasn&#8217;t) says it all:</li>
</ul>
<p><a href="http://www.amazon.co.uk/product-reviews/B002HMNGFA/ref=dp_top_cm_cr_acr_txt?ie=UTF8&amp;showViewpoints=1">http://www.amazon.co.uk/product-reviews/B002HMNGFA/ref=dp_top_cm_cr_acr_txt?ie=UTF8&amp;showViewpoints=1</a></p>
<p>The good review says its not noisy &#8211; I don&#8217;t think they have have seen (and not heard) a Medela &#8211; ie you really can&#8217;t hear them &#8211; my wife and I have fallen asleep whilst its been on! No way that would happen with the TT one. We only got one use out of the TT before it stopped working.</p>
<p>Will try and keep up with the occasional new dad blog post if time allows!</p>
<p>Off to Wales for a cheeky short Mountain Biking blast (my first exercise since Ella arrived)!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=351</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This blog is now running on new hardware &amp; software!</title>
		<link>http://blog.cronky.net/blog/?p=348</link>
		<comments>http://blog.cronky.net/blog/?p=348#comments</comments>
		<pubDate>Fri, 22 Oct 2010 23:47:29 +0000</pubDate>
		<dc:creator>Ollie Cronk</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blog.cronky.net/blog/?p=348</guid>
		<description><![CDATA[Recently changed the server this blog runs on to a low power Dual Core Intel Atom in a smaller form factor case (mini ITX). In an attempt to reduce my environmental and electricity footprint. Took the opportunity to upgrade Ubuntu Server to 10.04 LTS which comes with MySQL 5.1 and WordPress is now 3.0.1 ( [...]]]></description>
			<content:encoded><![CDATA[<p>Recently changed the server this blog runs on to a low power Dual Core Intel Atom in a smaller form factor case (mini ITX). In an attempt to reduce my environmental and electricity footprint. Took the opportunity to upgrade Ubuntu Server to 10.04 LTS which comes with MySQL 5.1 and WordPress is now 3.0.1 ( which was a very easy upgrade &#8211; one click from within the web based admin &#8211; well done WordPress team for that!).</p>
<p>The Dual Core Opteron box this blog used to run on will now only be powered up when I am experimenting with Server Operating systems (will be re-built as VMware ESX host).</p>
<p>Getting in some IT geekery before my life gets turned upside down!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cronky.net/blog/?feed=rss2&#038;p=348</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

