Archive for the ‘Open Source’ Category

Google Buzz - It’s Loud and Clear

Thursday, February 18th, 2010

Finally Google has arrived at the ‘Micro-blogging’ platform with a real ‘buzz’. On 9th February 2010, Google introduced ‘Buzz’, the new social networking application to embark on its battle to limit the popularity of Twitter. So, now there are lot of competitions going on in the Internet space. Google Vs Microsoft (Operating System & Enterprise Application Suits), Orkut (Owned by Google) Vs Facebook (Social Networking) Google vs Apple (Smart phone market). Before acquiring YouTube, they fought against them with Google Videos. So what we understand from all these competitions is that Google is not just targeting a niche or industry, rather it want to rule the entire IT Business.

At the first look, we may feel that Google Buzz is an integration of Facebook and Twitter, but it is beyond that. First and foremost advantage is that you don’t have to go to another web page to see the ‘buzz’, it’s there right below the inbox in  the Gmail. The conversation will go like an email thread which is the fascinating aspect of Buzz. You can post in the Buzz, which can be held as private or public. Also, you can connect your profiles in Flickr, Piccasa, Google Reader and Twitter to Buzz. That means you aren’t missing any of your friends and by start ‘Buzzing’, you are increasing your friend and professional network. See this wondeful Video of Buzz, to get more insights.

Now we can perhaps clearly say that it is now ‘Google Vs. Rest of the World’. Apple and Microsoft are companies that are worth more than  $ 100 billion each, Facebook and Twitter are the champs of their respective niche, though they are not monetizing it well. There is no doubt that the internet and enterprise software market will come under the reign of Google, which is not far away.

The Much Awaited Apple’s iPad Tablet Unveiled.

Thursday, January 28th, 2010

After months of anxiety and speculation Apple has finally launched their latest creation, the iPad Tablet. Apple’s CEO, Steve Jobs, unveiled the breakthrough product in a grand meet held at San Francisco on 27th Jan 2010. Apple’s iPad is developed for people on the go to ease their online usage and other PC related tasks.The iPad is neither an iPhone nor a PC but a gadget that bridges the gap between the two. With its small size and touch screen technology, Apple’s iPad  is all set to create a new era of Tablet Computing. Although the device lacks complex functionalities when compared to a PC, it is equipped with much desired functions like web browsing, delivering media, capsuling literature, video gaming etc.
The 9.7 inch device with half an inch thickness weighs just 1.5 pounds. It features a touch screen and is available in 16, 32 or 64 gigabytes of flash memory storage. (more…)

Access Your Facebook Or Orkut On Your Mobile Without a Data Plan!

Monday, January 11th, 2010

Ever Thought Of Locating Your Twitter On Your Mobile Phone Even Without a GPRS Subscription?

This concept has become a reality in India with the Shorthand mobile SMS browser introduced by the Shorthand Mobile-India(www.shorthandmobile.in), a subsidary of Smarttouch mobile Inc.. The browser once downloaded will connect you to your desired web content just through a text sms. Yes, it’s that simple!

The desired web contents are stored as SMS Apps and are listed in the Shorthand browser for easy scroll and click. The users have to just scroll down to their SMS App and click the same to access the online network. The web content is located as soon as the browser sends the text message. Hence, it does not require an active data plan.

(more…)

Google Apps-Get More, Pay Less

Tuesday, November 17th, 2009

Google comes up with so many innovative as well as user friendly ideas at reasonable price. When compared to Lotus notes or Microsoft Exchange, Google Apps provides tools at a very low price. Services provided by Google App engine makes it easier for an employee  to work smoothly and efficiently. What makes Google Apps special ?? 8-O . Answer to that question will be ” Google gives good quality services to any person or organization at affordable cost “.

Google Apps provides many services. Among them the most widely used and appreciated tools include

These itself could support the various levels of communication in an organization in a more simpler and more effective way. Adding cherry to the cake is the price. These Google App engine tools come at affordable prices and that too in different editions.

  1. Premium edition ($50 per user per year)
  2. Education/Non-profit edition (comes free to a limited number of users)
  3. Standard edition (comes free to individual users)

You can compare the different editions:

  1. Standard Vs Premium
  2. Education/Non-profit Vs Premium

You can visit these links to get more information about Google Apps

http://www.google.com/apps/

http://www.google.com/apps/intl/en/business/index.html#utm_medium=et&utm_source=catch_all

Triggering Your Sixth Sense

Tuesday, November 10th, 2009

Who wouldn’t want to trigger their sixth sense, if it is as easy as wearing a pendant around your neck? With this ground breaking invention from Massachusetts Institute of Technology you can do just that if you are willing to spend a meager $350. Soon you will check emails on your palm or a nearby wall, show pictures to your friend standing next you in a crowded street or take snaps with your bare hands.

The project pet named “Sixthsense” is the brain child of Pranav Mistry an Indian Grad student at MIT and his project guide Pattie Maes, at MIT Media Lab. In Pranav’s words “‘SixthSense’ is a wearable gestural interface that augments the physical world around us with digital information and lets us use natural hand gestures to interact with that information”.

How does it work?

A miniature camera captures your hand gestures that are communicated wirelessly to your mobile phone, which in turn processes your signals and connects to the internet. A small, but powerful projector will project the results back, which are reflected by a mirror to any opaque surface. In short, the hardware consists of a pocket projector, a mirror and a camera all compressed into a wearable pendant. Simple! The software mostly tracks the user’s gestures using computer-vision based algorithms.

At the recent TED India conference held in Mysore in November 4 - 7, Pranav announced his desire to open-source his project.  Mistry pays tribute to his architect dad for his innovative spirit.

Read more about Mistry and his revolutionary project here and in this article that appeared yesterday (Nov 8, 2009) in The Hindu.

Google Reader - Track All Your RSS Feeds in One Place

Monday, September 14th, 2009

Did you ever wish that keeping up with all your favorite websites was as easy as checking into your email? Or that somebody would keep an eye on the Internet for your sake, choosing interesting stuff and placing it where you can find them easily?

Too incredible to be true, right? But that’s exactly what Google Reader does.

Google Reader was introduced way back in 2005, graduating from beta status in 2007.

For anyone who is not yet familiar with Google Reader, and given that RSS feeds are more extensively used, let me explain……

Google Reader is a web-based aggregator that is capable of reading all RSS feeds that you have subscribed to, so that you can  access them all in one place. Google Reader lets you know each time your favorite websites are updated. You can then, if required, organize feeds into folders, label them, and share the most interesting posts with your friends.

Google Reader is located on the Web at reader.google.com. You can access Google Reader using your Google Account.

Let’s now take a quick look at some of the main features that Google Reader has to offer: (more…)

Future is Web

Wednesday, August 26th, 2009

Future is Web” is a phrase we have been hearing for a few years now. And the latest talk on web is the web OS! But on second thoughts, does the web have enough power to replace the feature and flexibility that an OS provides? To mimic the operations of an operating system, we have Java, Flash, Silverlight and similar things. None of these are capable of doing some of the basic features that an OS provides. The basic functionalities that an OS requires like memory and process management, are alien to web applications. The delay in I/O is another key factor which restricts the further development of a web OS. So a pure web OS is a distant future.

The giant has already made promises of a pure web based OS. Yes, I am talking about Google Chrome OS which is in development now. By studying the latest products from Google, it won’t be anything bigger than an Android in better shape. Android which is a purely web oriented OS for mobile phones may be tweaked to an extent where it can be used in low power portable computers, or precisely – Netbooks. But the key point to be noted here is that, Chrome will be a web ‘based’ OS, not an OS in the web. So what will be a pure web OS? And why should one need it?

Mobility is the first advantage of having a pure web OS. Resource sharing and low cost end user hardware is another one. Consider having an entire OS in web, which will handle all the heavy tasks for you and all you need is a cheap, low end, web enabled notebook or netbook which is powerful enough to just run a browser. In short, you can encode an HD video even with a mobile phone! Interesting, isn’t it? Of course it is but the concept is very old and yet to become a reality. A few attempts have been made towards this end and the result was web applications like Google docs and Adobe’s online Photoshop. The interoperability of these online applications is essential for a web OS. No one will like to process a file in one application, download it and upload it to another application. It will be a fair job if these applications can send files/data to each other. It will be much better if both applications have access to a common online storage just like we have hard disks in our PC. And finally, it has to be free and open source! Before someone creates a perfect web OS, let’s take a look at something close to it. The eyeOS – an OS in a browser window, which is the Project of the Month in Sourceforge.

eyeOS is an attempt towards the perfect Web OS. “Open Source Cloud Desktop” is what they call it. You will have all your essential applications, a storage system and a desktop to integrate it all. eyeOS doesn’t look like a web page even though it’s inside the browser window. eyeOS package can be installed in your own server and you can allow other users to sign up and use it. The process is straightforward and simple as installing a Wordpress blog. The wizard driven installation won’t take much time and soon you will be provided with a login window as in normal OS. Once you pass this screen, you will take a couple of seconds to realize that what you are looking at is actually a web page inside a browser window. I was confused whether it was my Linux desktop; it has everything that a normal desktop should have. A task pane, notification area, desktop with changeable wallpapers and themes, games, application menu and everything that you won’t expect in a web page. It even has a browser and a task manager which lists the running processes like Windows Task Manager. The default installation comes with a handful of applications which can be further extended using a package manager like in most Linux distros. There is already a large pool of applications available for eyeOS. And all this is written in PHP and XML! Yes, eyeOS is a PHP application which runs on Apache server and doesn’t need a database. Instead of a database it relies on XML files. This is primarily for making the installation simple for the end user as all they would need to set up an eyeOS server is to enter account information for the first user. Flat files are used to avoid bottlenecks on data fetching. Core parts of eyeOS runs as independent applications and uses Javascript to send server commands. The UI is fast even on a 512kbps connection.

eyeOS is being developed by a company based in Barcelona and it’s currently in the 4th year of development. They also provide a tool kit with which we can develop cloud applications easily. A reasonably good wiki page, including a “Hello World application” is present to provide a walk-through towards eyeOS application development. Anyone fluent with PHP and Javascript can start writing applications for eyeOS without any further learning curve. You can try it out at their demo server : eyeos.info or get your copy of eyeOS package from here.

eyeOS may not be mature enough to host anything serious, but it is proof on how far a web application can go!

Pitfalls in WordPress Version 2.6.1

Friday, August 21st, 2009

Almost a year back (Aug 15th, ‘08, to be precise), AUTOMATTIC released WordPress 2.6.1 fixing over 60 bugs. Also the version featured with the introduction of ‘right to left’ typing for Hebrew and Farsi language administrators. In a very short period of time (may be around one month), the company alerted 2.6.1 version users of security holes in using the same. Here, in this small article, we are going to analyze those vulnerabilities that made AUTOMATTIC release an upgrade for WordPress version 2.6.1 so soon.

Ok, let’s be clear and to the point. The problem is created by the nature of:

1.    mt_rand () function of PHP and

2.    the truncation method that MySQL adopts

mt_rand ():

PHP has two random number generating functions: rand (), mt_rand (). The former uses GNU C library and the latter uses Mersenne Twister algorithm. Mersenne Twister algorithm was created by Takuji Nishimura and Makoto Matsumoto of Japan. mt_rand () is predominantly used in most of the PHP applications and most importantly, WordPress 2.6.1 uses it.

Normally a seed is used to initiate the generation of random numbers. If it is possible to determine that seed, we will be able to generate the same sequence for any number of times. In other words, we will be able to hack the working of random generation. Seed can be determined using a lookup. Now, once the seed is found, anyone can generate the sequence that the application generates. If you want to know how this is possible, you got to learn random number generation in PHP or there’s an alternative: bow to the fact that it is the nature of mt_rand () function.

Now, make a request for admin password which would send an activation link to the actual admin. But since we have the seed, we will be able to calculate the same activation link by enabling Keep Alive HTTP request.  Activating this link and using a different email ID in the form will allow creation of a new WordPress admin password and thereby complete control.

MySQL Truncation:

Let’s see the next one. When the string input given in a query is longer than the defined maximum length, MySQL, by default, truncates the string to the defined maximum length. For example, if the maximum value of the string column is defined to be 8 then, the input value, “qburst_expressions” will be truncated to “qburst_e”. There will be a warning displayed but, applications are normally not configured to handle those warnings. And importantly, WordPress version 2.6.1 was not.

Suppose I know the WordPress admin name, (let’s say, “godfrey”) and the maximum length of the username in MySQL is set as 32. When I register as a new user with the same name “godfrey”, obviously, MySQL will return an error as there already exists an username godfrey. Now, I try with “godfrey   “(with 2 spaces after the name), MySQL will truncate the string to “godfrey” and again return an error due to the same reason. Suppose I try with “godfrey                         g” (with 25 spaces between godfrey and g) then MySQL will not be able to identify a similar username and also truncate the name to “godfrey” to be inserted into the database column. This happen because the username exceeds the defined maximum length of 32 and the system will not be able to find a match in the database. Now we have 2 admin usernames in the table. This is sufficient to pass the validation and gain access to the password of the original admin, thereby complete control.

Username Length Max Length After Truncation Database Change

“godfrey”

7

32

“godfrey”

No change

“godfrey  “

9

32

“godfrey”

No change

“godfrey                         g”

33

32

“godfrey”

Truncated string (godfrey)  inserted as new username into DB

These holes in security made AUTOMATTIC to work on an upgrade at the earliest. And the next release fixed all these errors. So if you are planning to use WordPress, make sure you use the latest version and remain safe. WordPress 2.8.4 is available for download now. It is the latest stable version of WordPress according to the AUTOMATTIC’s last release.

Google Wave 2- The Platform

Tuesday, July 21st, 2009

Articles on Google waves is flooding the web, trying to bring out a deeper understanding on this wave renaissance. There is so much of expectation generated now as people are anxiously looking forward to get their hands on it. With the little information revealed by Google, let us try to figure out something more on how this is going to work. In Google wave 1 we discussed about Google waves as a product. This time let us view Google waves in the perspective of a developer, that is, Google waves as a platform.

What is a platform?

Platform in software realms can be understood as an entity on which software can be made to function. A platform provider will provide APIs (Application Programming Interface) for software to be developed in his platform. Let’s take a few examples: Java, the product of Sun Microsystems serves as a platform and it comes with APIs like AWT, JDBC, JMF and so on. These APIs are also provided by Sun Microsystems. Apple Inc, owner of iphone had APIs confidential until October 2008 when the company open sourced and made it license free to develop software applications to be run on iphone. Lately, there is facebook API which is both powerful and popular.

What about Google API?

Google has promised to come up with a public API which can be used by any developer to create applications that run on the wave platform. There are 2 ways by which a developer can make his presence felt in Google waves. The first method is by building robots or creating gadgets. The other method is by embedding waves on third party websites. Let’s try to get some insight on these new terminologies.

Robots, Gadgets and Embed API

Robots are automated participants in a wave. Remember the robot in ‘Lost in Space’. It is a similar kind of simulation except that these robots will function inside the computer. A robot created inside a wave will be able to read, modify and delete blips and wavelets. A wavelet is a smaller wave that is resident inside a wave and a blip resides inside a wavelet. The diagram below will give you better picture.

The developer can create robots and perform interactive operations within a wave. What are the interactive operations? Well, that is left to the creativity of the developer. Learn more about robots here. Wave Gadgets are similar to the ordinary gadgets in its mechanism to get embedded as third party development applications. But there is more offered. A wave gadget can function within a live wave. An example Google gives to explain this is one which lets participants of a wave to vote on where to go for lunch. Learn more about gadgets here.

The second method using Embed API enables to bring waves into third party websites. There will be simultaneous updates in websites as and when an update is made inside a wave. Google has already come up with a few embeds. ‘You tube playlist discuss’ is one among them and is sure to gain so much popularity.  Learn more about embed APIs here.

As Facebook is dominating now with so much integration, it is certain that we can expect even more from Google waves. So if you are a developer, be informed about what is going on in Google waves and get ready to play with the tools as soon as you get them.

Links for further study:

http://code.google.com/apis/wave/

http://googlewavedev.blogspot.com/

Microsoft Ready for Google’s Challenge, Forays into ‘Online Office’

Tuesday, July 14th, 2009

In response to Google Chrome OS, Microsoft has announced that the new version of MS Office, which is expected to hit markets by 2010, will feature online collaboration. This dramatic announcement was made at the partner conference in New Orleans.

The new generation office suite will enable users to access their documents online with co-authoring capabilities. PowerPoint will be streamlined with video and picture capabilities which will revolutionize presentations.

Though Microsoft is coming up with online capabilities for Office, they don’t have the intention to provide comprehensive online access, which they think can scale down their business. This won’t be a great concern for Google Docs, as they are providing comprehensive access to users. Google considers it as a weaker reply for the Google Chrome OS, which is the core of Microsoft’s business.