30
Nov

Lucky table

Met new bloggers at the Filipina Writing Contest Winners Announcement event last Wednesday. Held at Ponciana’s Kitchen along Timog Avenue corner Scout Torillo, it was fun, funny, enjoyable, and sinful. That last word was due to that sinful lechon. Lechon should be banned forever.

Anyway, as I have said, I met new bloggers:

From left, counter-clockwise: Marghil, Joyce, Jehzeel, Betsy, and Aiza.

And because the event was free, it is only right to thank the sponsor, right? Thanks to IPVG, a company engaged in information technology and telecommunications, on-line gaming, and business process outsourcing.

Thanks to other sponsors:

By the way, to explain the title: all of us in that table did not go home empty-handed, like Marghil winning US$200, Betsy with US$100, and Aiza with US$100. Too bad Ederic was too late when he sat by our table.

Was a little bit late in arriving, since I walked from EDSA corner Timog up to Scout Torillo. =P

30
Nov

The parable of pigs

It is very easy to describe pigs. They are simple-minded, and they don’t care at all – they don’t care about their fellow pigs, they don’t care about their pig pens (they do care, but not that much). Heck, they don’t even care that they are up for slaughter. They don’t care at all as long as they are fed enough and on time. They don’t care as long as they get to mate (and they don’t care about the partner, as long as they have their sex). They don’t care as long as they appear to be superficially clean (even if it stinks to high heavens). They don’t care as long as long as their pig pen appears to be clean (even if it stinks to high heavens). They don’t care at all as long as all of their needs and wants are fulfilled. They don’t care at all as long as their comforts are not affected.

Question: how many pigs are there in this country? Just ask these guys.


“In a nation run by swine, all pigs are upward-mobile and the rest of us are fucked until we can put our acts together: Not necessarily to Win, but mainly to keep from Losing Completely” – Hunter S. Thompson.

29
Nov

Trillanes, Lim at Makati: Another coup?

Something’s happening at Makati right now. It seems that Sen. Antonio Trillanes IV together with Gen. Danilo Lim have walked out of the coup hearing at Makati RTC. They are now walking along Ayala Avenue.

I dunno, but I think the soldiers guarding them have switched to Magdalo, too.

Will the people go there when called? It is up to you, I guess, but think of the risks first.

It seems that this is carefully planned: look here:

SENATOR ANTONIO TRILLANES, BRIG. GEN. DANILO LIM, MAGDALO SOLDIERS, THEIR GUARDS AND THE PEOPLE ARE NOW IN MANILA PENINSULA.

THE PEOPLE ARE CALLED UPON TO CONVERGE IN MAKATI TRIANGLE, AYALA AND MAKATI AVENUE NOW TO BRING FORTH A NEW GOVERNMENT!

For those who hate Trillanes et al so much, it is time to take that illogical rage into action. It is time to stop yakking and it is time to start walking the talk. Here’s my humble suggestion. Create placards that says “Trillanes shut up”, “Die, Trillanes!” or whatever, then go to Makati. Gloria Arroyo will be very delighted.

NEWS UPDATES:

ABS-CBN News: Trillanes, Lim call for Arroyo’s removal
GMA News: Trillanes, Lim walk out of court, call for ouster of Arroyo

29
Nov

Disaster (un)preparedness

Last Tuesday’s earthquake had shown that the emergency evacuation measures we have are inadequate. Heck, our reaction (or should I say, inaction) was even nonchalant, as if nothing happened. This is a terrible character flaw on our part; when we act, it is almost too late.

It is a damned-if-you-do situation: you do preemptive action, and when nothing happens, you get blamed. When you do nothing and disaster happens, you get blamed. The entry of typhoons Lando and Mina are instructive. Lando managed to ravage the country, though it steered clear of Bicol. The Philippine Atmospheric, Geophysical and Astronomical Services Administration (PAGASA) predicted that Mina may pass by Bicol, so emergency evacs were made. When Mina steered away from Bicol, PAGASA was blamed for faulty prediction.

No wonder government officials would rather react than act. But this should not be the case. As the tired quote says, it is better to err on the side of caution.

The typhoons and the earthquake highlighted some facets of the Filipino culture. Basically, our nonchalance, our passiveness about disaster prevention are manifestation of the so-called bahala na syndrome. We are very prone to it.

It will take another major disaster before we wake up from this stupor. By then, it will be too late. Again.

(The worst Philippine disaster in recent memory were brought about by typhoons – in Leyte and in Bicol.)

I have heard a lot of anecdotes from friends about last Tuesday, all of them troubling. They did not bother evacuating. “Mahina lang naman eh,” most of them said. That is not the point. The possibility of aftershocks are there. The possibility of stronger aftershocks are there. That is why emergency evacuations are always made. But we always want to learn the hard way, right?

If you work in a tall building, do you know what to do in case of earthquake or fire? Do you know where the emergency exits are? Does your company have emergency, evac, and restoration measures in place?

For the record, we did an evac, though much remains to be desired.

27
Nov

A tale of two losers

Such losers.

—-

After Sen. Manuel Roxas II’s election as president of the Liberal Party, here comes the Arroyo saboteur Lito Atienza crying his heart out. He even has this to say:

Congratulations, Sen. Roxas, at your installation as president of the Liberal Party faction led by Frank Drilon and his merry cabal of destabilizers. We were hoping we would be congratulating Mar as our president, the head of a newly-united Liberal Party, but it seems the worst fears of our group became reality after all.

He then ranted on about LP being finally divided, etc.

Mr. Atienza: who caused the division of the party? Who went on to have a rump, unofficial, illegal party elections? Who tried to sabotage the party by subverting it to Gloria Arroyo’s regime?

Sure, go ahead and sue. Let’s see who the true losers are. (Yeah, the fact that you have the environment portfolio speaks for itself.)

Let’s have a wimp for another poor loser.

Speaker Jose de Venecia is in the hot seat for the past two months. His troubles began when his son, Jose de Venecia III, began his exposes against the National Broadband Network project (in the process, Comelec chair Benjamin Abalos Sr. was forced to resign, faced with imminent impeachment). To test his loyalty, de Venecia faced two crucial questions.

First, Atty. Roel “Palyado” Pulido filed an ethics case against de Venecia, at the height of the younger de Venecia’s exposes. Then, he filed a three-page impeachment complaint against Gloria Arroyo. It seems that the gameplay was simple: have the impeachment complaint dismissed or else.

JDV tried to be cute for all when he asked Representative Raul del Mar to transmit the complaint to the House Justice committee, in a way giving the Fortress by the Pasig a scare. Well, the dogs were compliant: committee killed the complaint. Then, the plenary buried it.

JDV should be in the clear now, right? Wrong. That’s how vindictive this regime is.

Not only is the ethics complaint festering at his back, the Office of the Solicitor General is reviewing a compromise agreement made by a company owned by JDV and the Presidential Commission on Good Goverment in 1988. Of course, the Solicitor General immediately claimed that this is not politically motivated. The deal was made in 1988. Great timing, madam solicitor.

(I am not even dealing with the Northrail project.)

And de Venecia? Ever the martyr, cries foul, says that the Supreme Court has already ruled on the case with finality. His lawyer, Singaw ng Bayan sycophant Raul Lambino branded the move as political harassment.

My grandmother used to say: do not deal with the devil. (To counterbalance that for atheists: do not deal with cheats.) So there.

Who’s the loser from all of this? All of us. At the end of the day, it is us who are screwed.

27
Nov

A cookie authentication vulnerability for WordPress

Securiteam reports of a vulnerability in WordPress’ cookie authentication. Through this vulnerability, an attacker can generate a valid login cookie for any user account without using a brute force attack (assuming that the attacker can gain at least read-only access to the WordPress database). When a cookie is generated, an attacker can perform limited SQL injection and be granted administrator access to that WordPress installation.

(Structured Query Language (SQL) injection is a technique used by hackers to execute destructive and admin-only SQL statements. Read more here.)

When a WordPress user (of any level) logs in, the WordPress system queries the database for the user name and password for authentication. If the credentials are OK, the system generates two cookies and save them in the user’s cookie cache. One of the cookies contain the user’s password encoded using double MD5 hash.

* Why save a cookie? A cookie allows a user to gain access to any WordPress administrative pages without signing in each time.
* MD5 is a cryptographic hash function used to protect passwords. When a new user registers with a WordPress-powered site, his password is encoded using MD5 and is saved in that form in the database.

Now, where is the problem? WordPress stores the password in the cookie in the MD5(MD5(password)) format. What does it mean? The password saved in the cookie is actually a password in the clear, which means that you can actually know what the password is using MD5!

What the hacker now needs is to gain access to a WordPress database. A hacker can do this by looking for a database backup that anyone can view, or looking for a WordPress installation that is vulnerable to SQL injection. When that happens, a hacker can gain administrative access.

Securiteam has listed several workarounds:

– Protect the WordPress database, and do not allow backups to be released.
– Keep your WordPress installation up to date. This should reduce the risk that your database will be compromised.
– Do not share passwords across different sites.
– If you suspect a database to be compromised, change all passwords to different ones. It is not adequate to change the passwords to the same ones, since WordPress does not “salt” the password database.
– Remove write permissions on the WordPress files for the system account that the webserver runs as. This will disable the theme editor, but make it more difficult to escalate WordPress administrator access into the capability to execute arbitrary code
– Configure the webserver to not execute files in any directory writable by the webserver system account (e.g. the upload directory).

27
Nov

Using Smart 3G: Port blocking is no more

Mobility Philippines reports that Smart has started unblocking ports for its 3G service. I had checked that out and here’s what I found:

* I can now access my site’s cPanel, which means port blocking on HTTP is lifted.
* I can now chat via Internet Relay Chat, which means common IRC ports (starting at port 6666) are now open.
* I can now download via torrents. Port forwarding is now allowed over Smart 3G.

Note that there is nothing spectacular about torrent speeds over Smart 3G (at least on my end).

Now if only Smart implements HSDPA (and that would mean getting an HSDPA phone).

25
Nov

Dem Koreans

You know what? I think there is something wrong with them Koreans.

I was watching Sponge on KBS last night. One of the information shown was that you can stop a potential sneeze by pinching your nose. The personalities were again so wacky I was laughing so hard.

Anyway, about the information: hello? I think I know this since I was in elementary. And they only knew that now?

Geesh.

And on an another show, (I think the title was The Golden Bell or something), there were 100 students, and they were asked a series of questions, and those who commit a mistake were eliminated.

The first question involved an object. The students were asked to hold the object and then they were to identify what it was.

One burly male was asked by the hosts to state his answer and explain why.

“This is an object for breaking,” he said.

The host asked, “Why do you think so?”

“Because it was made in China!” (WTFQ?!)

The host then asked him to break it. The stupid kid obliged by hitting the object to his head.

Toink!

Well, try hitting your head with a sharpening stone.

Koreans. Tsk. They’re like Filipinos.

23
Nov

Another weird dream, 6

This is probably the weirdest dream I had.

I was in a cemetery (a fusion of the Chinese and Manila North cemeteries) for an internment when a group of alien-looking humanoids entered with violent intentions. I tried to run away, and when I got into a river bank, I brought out a one-pull inflatable boat, but it failed. So I had to scamper in the muddy river bank to get away. I lost them when I got off the perimeter of the cemetery.

I got back in, the aliens were gone. I entered the chapel, and saw a coffin with my paternal grandmother (who passed away three years ago). She was to be cremated, and the undertaker told everyone to get out, with the immediate relatives first.

Finding the command dubious, I took a peek. The undertaker threw the body off the coffin. The only thing was that it was not the body of my grandmother. It was someone who looked stupid and cross-eyed. It made the sign of the cross, knowing its fate.

At the crematorium, the body was put in the cremation chamber. Everyone went home except for me and my father. After burning, the ashes were like dirty diamonds. The undertaker then told us to go back a day later.

On the way home, the internment for the ashes were discussed, and the Manila North Green Park was mentioned. The sidewalks had Chinese tombs in them.

Then I woke up.

If you are not familiar with the cremation process, it is darn simple. Anyway, I will describe the process as I saw it in the Chinese Cemetery crematorium.

The crematorium is divided into two parts: the first is where ceremonies and last minute rites are held. The other holds the cremation chambers. It is off-limits to most people except for a relative or two of the person to be cremated.

The body is put into the burning chamber, just like how a baker puts bread in an oven. The burning process depends on what is being burned. When the remains of my uncle were cremated, it took 2 hours – note that my uncle was dead for 25 years then. We had to transfer the remains to a smaller resting place, so cremating the bones was needed.

The ashes settle on a metallic pan. Now, even with cremation, it is normal to see charred bones, so the ashes are ground into a grinding machine. Afterwards, the finely-ground ashes are placed in an urn.

I always get death-related dreams. Mind you, I was not the one who is dead in those dreams. Most of them were relatives, alive and dead. Most of the time I wake up after those dreams, without any wish to go back to sleep. And no, I don’t tell the relative that I had dreamed about his/her death. Besides, in the dreams, they are usually dead.

23
Nov

Cris Anthony Mendez: Back to normal

We really tend to have short memories. Or we are just too lazy to remember.

Months after the death of Cris Anthony Mendez from the barbaric tradition called hazing, nothing much has changed. First, unlike the dispatch shown by the ever consistent Philippine National Police on solving the Glorietta and Batasan blasts, no one has been charged with the crime. Very consistent. Second, most of the suspects are already in hiding or have already left the country. The guilty really hides from the truth. And the worst? It is all back to normal.

I have mixed feelings about the University of the Philippines. It is a bastion of student activism. It leads the charge against corruption. But it suffers from the proverbial pointing cliche – that when you point at someone, three fingers are pointing at you. And as they say in Tagalog, “Bago mo husgahan ang kapwa mo, tingnan mo muna ang sarili mo.” I really want to say that to all members of the UP community. Remember all those candles? All those marches? All those talks of remembering, etc, yada yada? Yet what have you to show?

Fraternities in UP are tumors that are hard to remove.

I am troubled by what my sources in UP Diliman have told me. Some of them said the same things, some of them have verified facts, and some of them gave me rumors. I will be posting what I have learned here, and the rumors will be clearly marked as RUMORS until such time I have verified them through multiple sources.

Some of my sources told me that the Sigma Rhoans are back at their usual tambayan, at the Malcolm Hall parking lot, now that the outcry is gone. Remember that some news reports showed an empty tambayan right after Mendez’ death was announced, and remained empty when the outcry was at its peak. Now, they are back.

Delta Lambda Sigma sorority is also busy recruiting. Fact: DLS is the affiliate of Sigma Rho. Fact: DLS is disassociating themselves with Sigma Rho. Good for them.

RUMOR: Sigma Rho is again recruiting new lambs to be slaughtered. It is also rumored that the Sigma Rho are taking a closer look at the LAE examinees for possible recruits. One of the sources noted the irony that Cris Mendez would have been one of the examinees.

RUMOR: A UP College of Law professor has been kicked out, apparently being involved in CA’s case. Still verifying this rumor.

RUMOR: Other fraternities are taking advantage of Sigma Rho’s “absence” last academic semester. Scintilla Juris is rumored to be raring to regain prominence in Malcolm Hall. In what way, the sources did not say. Hopefully not by another hazing death. Or a rumble. Speaking of which…

RUMOR: A rumble is about to erupt soon. Several sources have shared this rumor, but some of them have refused to say who are the parties to be involved; some sources gave different names. But all of them agree that a rumble may happen soon.

RUMOR: It seems that a new Law dean is to be selected, and one factor that weighs in heavily on the selection is the issue of fraternities. It is a hot issue, some of my sources told me. Interesting bit, if true.

RUMOR: The most troubling, for its implication: Sigma Rho has a Cris Mendez defense fund large enough to buy several judges, if necessary. THIS IS A RUMOR. But to be honest, with the way CA’s case has moved, this is very plausible.

I will try to verify these rumors and seek more information from other sources.

Roundup of news on Cris Mendez’ case: Cris Anthony Mendez: The Search for Justice
Roundup of blog post on Cris Mendez’ death: The true barbarians of UP (UPDATED)

PS: If I die at UP, you know the reason why. ;P