Tuesday, July 31, 2018

Long Tail Jet Boat – WOW

Ever wanted to cruise some exotic destination in a river boat that looks like it should only do about 10 Paddles Per Hour (Ha, Ha) that actually does mach 5? Well check out this video […]

The post Long Tail Jet Boat – WOW appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Undermining the Boss

During the browser wars of the late 90's, I worked for a company that believed that security had to consist of something you have and something you know. As an example, you must have a valid site certificate, and know your login and password. If all three are valid, you get in. Limiting retry attempts would preclude automated hack attempts. The security (mainframe) team officially deemed this good enough to thwart any threat that might come from outside our firewall.

The Murder of Julius Caesar

As people moved away from working on mainframes to working on PCs, it became more difficult to get current site certificates to every user every three months (security team mandate). The security team decreed that e/snail-mail was not considered secure enough, so a representative of our company had to fly to every client company, go to every user PC and insert a disk to install the latest site certificate. Every three months. Ad infinitum.

You might imagine that this quickly became a rather significant expense for the business (and you'd be right), so they asked our department to come up with something less costly.

After a month of designing, our crack engineers came up with something that would cost several million dollars and take more than a year to build. I tried, but failed to stifle a chuckle. I told them that I could do it for $1500 (software license) and about two days of work. Naturally, this caused a wave of laughter, but the boss+1 in charge asked me to explain.

I said that we could put an old PC running a web server outside the firewall and manually dump all the site certificate installer programs on it. Then we could give the help desk a simple web page to create a DB entry that would allow our users to go to that PC, load the single available page to enter the unique code provided by the help desk, and get back a link to download a self-installing program to install the site certificate.

To preempt the inevitable concerns, I pointed out that while I had some knowledge of how to secure PCs and databases, that I was not by any means an expert, but that our Security Analysts (SAs) and DBAs were. We could have the SA's strip out all but the most necessary services, and clamp down the firewall rules to only let it access a dedicated DB on an internal machine on a specific port. The DBA's could lock down the dedicated DB with a single table to only allow read access from the web page; to pass in the magic phrase and optionally spit back a link to download the file.

Of course, everyone complained that the PC in-the-wild would be subject to hacking.

Since I believe in hoping for the best but planning for the worst, I suggested that we look at the worst possible case. I take out a full page ad in Hacker's Weekly saying "Free site certificates on exposed PC at IP a.b.c.d. They can be used at http://www.OurCompany.com. Enjoy!" After all, it can't get worse than that, right? So Mr. Hacker goes to the page and downloads the site certificate installation programs for every user and then goes to our website. What's the first thing he faces? Something he has and something he knows. He has the certificates, but doesn't know any login/passwords. Since the security people have already blessed this as "Good Enough", we should be safe.

After much discussion, everyone agreed that this made sense, but that they (reasonably) wanted to verify it. It was agreed that the SA's and DBA's had the needed expertise to strip and lock down the PC, firewall and DB. I took an old PC out of one of the closets, did a fresh install, put on the latest web server and relevant software, and then installed the few things we needed. Then I handed it to the SA's and told them to strip it and lock it down. I created a tiny DB with a single table and two stored procedures; one for the help desk to add a new time-limited entry for a user and the other to check to see if an unexpired entry existed and return a link to the installer on the exposed PC. Then I handed it to the DBA's and told them to restrict it so the table could only be accessed via the two stored procs, and to only allow the Help desk to call the proc that created the time limited entry for the user, and the external IP to call the proc to query the table. Since all of our users already had credentials to call the help desk, this was only a minimal additional cost.

We threw a couple of test certificate installers on it and put it outside the firewall. After I tested the "good" paths, I had the SA's and DBA's try to hack around their restrictions. When they couldn't, it was deemed safe and loaded up with all the certificates. I wrote up a very short how-to manual and had it installed in production.

This reduced the certificate installations to one trip per quarter to our data center.

The user was pleased at having saved millions of dollars on an ongoing basis.

I found out later that I inadvertently pissed off the boss+1 because he was planning on hiring more people for this project and I negated the need for him to expand his empire.

Whoops.

[Advertisement] BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!


To read the full article, please visit The Daily WTF

Monday, July 30, 2018

SUPER SUMMER FAILS | Epic Fails of the Summer In July 2018

ITS TIME FOR MORE SUMMER FAIL VIDEOS Of 2018!!! The BEST FAILS brings you the NEW FUNNIEST FAILS COMPILATION of SUMMER 2018! Enjoy this candid funny montage of the best slips, falls, crashes, impacts, hits, […]

The post SUPER SUMMER FAILS | Epic Fails of the Summer In July 2018 appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Old Lennart

Gustav's tech support job became a whole lot easier when remote support technology took off. Instead of having to slowly describe the remedy for a problem to a computer-illiterate twit, he could connect to their PC and fix it himself. The magical application known as TeamViewer was his new best friend.

Vnc-03

Through Gustav's employer's support contract with CAD+, a small engineering design firm, he came to know Roger. The higher-ups at CAD+ decided to outsource most of their IT work and laid off everyone except Roger, who was to stay on as liaison to Gustav and Co. Roger was the type whose confidence in his work did not come close to matching the quality of it. He still felt like he could accomplish projects on his own without any outside help. Thanks to that, Gustav had to get him out of a jam several times early in their contract.

Roger's latest folly was upgrading all of the office workstations from the disaster that was Windows Vista to the much more reliable Windows 7. "I had such a smooth rollout to Windows 7, I tell ya," Roger bragged over the phone. "I brilliantly used this cloning process to avoid installing the same things repeatedly!" Gustav rolled his eyes while wondering if this was a support call or if Roger just needed someone to talk to. "Well anywho, I had two system images - one with the basic software everyone gets, and one that included SolidWorks for our CAD designers. Seems they don't have SolidWorks even though I installed it. Can you do your support wizardry and take a look?"

Gustav agreed and was transferred to Dave, their lead CAD designer. He figured Dave just didn't know where to find SolidWorks on the new OS and it would be a quick call. He got Dave's TeamViewer ID and connected to his PC in no time. He decided to ignore the fact that Dave had a browser open to an article about the twenty greatest Michael Bolton songs of all time.

"Thanks Dave, I'm in. Are you able to see me moving your mouse?" Gustav asked. He wasn't. "Ok then, there must be some lag here. I'm going to look around to find where you have SolidWorks and make a shortcut for you." Gustav spent the next few minutes looking at the places any sane person would install SolidWorks. Since Roger wasn't sane, he didn't find it in a logical directory. He then went to Programs and Features and noticed that it wasn't installed anywhere.

"Hey Dave, bad news," Gustav informed. "It seems like your PC got the wrong image from Roger and your CAD software isn't on there."

"Bummer. I didn't know if you were doing anything, on my side the computer screen was just sitting there," Dave replied, just as an incredible ruckus broke out behind him. Gustav could hear doors slamming and someone cursing at Roger in the background. Dave chuckled quietly into the phone.

"... is everything ok there?" Gustav asked, concerned.

"Oh, that's just Old Lennart throwing a fit. He's our cranky old Vice President. He's super pissed because Roger keeps hacking his computer and messing around on it."

Gustav suddenly had a suspicion. "Dave, don't take this the wrong way, but were you reading an article about Michael Bolton's greatest hits?" he asked cautiously.

"Hell no, why would I be doing that?" Dave shot back, almost sounding insulted. Gustav apologized and quickly ended their call.

Once Roger was done getting chewed out by Old Lennart, Gustav gave him a call. In their discussion, Roger revealed how he'd installed TeamViewer before making his system clones to save time. Gustav explained how that caused every system image to have the same TeamViewer ID, which was bad. Since Old Lennart was always the first one in the office each morning, any remote connection through TeamViewer would connect to his PC. Thus, whenever Gustav or one of his cohorts connected for remote support, it seemed like someone was hacking in to Lennart's computer.

Roger remedied the problem over the next couple days by reinstalling TeamViewer and bringing in a series of "I'm sorry" baked goods for Old Lennart; but it wasn't enough to save his hide. By the end of the week, he was informed that their IT department would be further reduced from one employee to zero. With his computer and Roger problems addressed, Old Lennart could return to researching his favorite performing artist.

[Advertisement] Forget logs. Next time you're struggling to replicate error, crash and performance issues in your apps - Think Raygun! Installs in minutes. Learn more.


To read the full article, please visit The Daily WTF

Sunday, July 29, 2018

Skywheel Breaks Sending Passengers Plummeting

A video from Pakistan shows passengers on a sky wheel plummeting to the ground when the ride breaks. We hope everyone lived in this scary incident and the overall injuries are still TBD. Keep this […]

The post Skywheel Breaks Sending Passengers Plummeting appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Saturday, July 28, 2018

Fire Tornado Rips Across Road

The deadly and swift moving Carr fire in Shasta County California produced this incredible, dangerous and deadly fire tornado, or a ‘firenado’ as it’s being called. Footage courtesy of ABC News Bay Area. Thank you […]

The post Fire Tornado Rips Across Road appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Possessed Woman Stalks Two Girls in Florida

Meanwhile in Florida…a woman presumably high on flakka, aka bath salts, stalks two girls at an apartment complex. This disturbing video shows the zombie-like power of this powerful drug affecting a woman who terrorizes two […]

The post Possessed Woman Stalks Two Girls in Florida appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Friday, July 27, 2018

Stranded for 48 Hours Surrounded by Sharks

Imaging being on a boat that’s about to sink and being forced into shark infested waters. Inside Edition shows us a sneak preview for The Discovery Channel’s upcoming show ‘Sharkwrecked’. In what’s being called one […]

The post Stranded for 48 Hours Surrounded by Sharks appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Error'd: When BSODs Pile Up

"I suppose the ropes were there to keep the infection from spreading to other screens," Stan I. wrote.

 

"I was visiting the ESA Shop and, well, though I'm not actually in the UK, it looks like I'll be shopping there!" wrote Ben S.

 

Marcin K. writes, "I spotted this one at a Warsaw subway station and, I'm pleased to say, that this billboard was the only thing that crashed."

 

"Life is full of important, deep questions. Ubuntu 18.04 seems to feel the same way during install when I tried to create an encrypted volume," writes Bernard M.

 

Brad W. wrote, "Sometimes it's easy to see how test artifacts slip into production, other times it's not."

 

"This is what happens when you are looking for answers on CodeProject, but you find only more questions," writes David.

 

[Advertisement] ProGet can centralize your organization's software applications and components to provide uniform access to developers and servers. Check it out!


To read the full article, please visit The Daily WTF

Thursday, July 26, 2018

CodeSOD: An Incomparable Event

Sandra’s ongoing battles continue. She currently works for Initrovent, and is doing her best to clean Karl’s dirty fingerprints off their event-planning codebase.

Now, as it turns out, Karl wasn’t their only developer. Another previous developer was a physicist who knew their way around APL and Fortran, then decided to follow the early 2000s money and became a self-taught web developer.

This Einstein decided to solve some problems, common problems, utility problems, the kind of things you might want to put in your central library and reuse in every project.

For example, do you hate comparisons? Does writing if ($x == $y)… make your skin crawl? Don’t you just wish you could write something like, compareValues($x, $y, '==') instead?

Well, have I got news for you.

/**
 * Compares two operands with an operator without using eval. Throws exception
 * of operator is not found.
 * @param mixed  $op1      Operand 1
 * @param mixed  $op2      Operand 2
 * @param string $operator Operator (==, !=, <=, >=)
 * @return bool
 */
function compareValues($op1, $op2, $operator) {
    switch ($operator) {
        case '==': return $op1 == $op2;
        case '!=': return $op1 != $op2;
        case '>=': return $op1 >= $op2;
        case '<=': return $op1 <= $op2;
        default:
            throw new Exception('Operator is not handled: ' . $operator);
    }
}

Now, this particular snippet isn’t the worst thing on Earth, and it actually has a potential use- you might need to decide which operator to compare using, and store it in a variable.

What we really need is a way to route around PHP’s type system. This method does exactly that, but instead of being placed in a central library, it’s copy/pasted in five different places across multiple projects with slightly differing implementations.

    function compareValues($data1, $operator, $data2, $type) {
        if (!$operator)
            return false;
        if ($operator == '=')
            $operator = '==';
        switch ($type) {
            case 'date':
                if (is_array($data1)) {
                    $data1 = $data1['year'] . "-" .
                            $data1['month'] . "-" . $data1['day'];
                }
                if (is_array($data2)) {
                    $data2 = $data2['year'] . "-" .
                            $data2['month'] . "-" . $data2['day'];
                }

                $data1 = strtotime($data1);
                $data2 = strtotime($data2);
                if (empty($data1))
                    return 'empty';
                if (empty($data2))
                    return 'empty';
                return eval('return (' . $data1 . $operator . $data2 . ');');
                break;
            case 'time':
                if (empty($data1))
                    return 'empty';
                if (empty($data2))
                    return 'empty';
                $data1 = (int) str_replace(':', '', $data1); //removing ':'
                $data2 = (int) str_replace(':', '', $data2);
                return eval('return (' . $data1 . $operator . $data2 . ');');
                break;
            case 'money':
                if (empty($data2) || $data2 == 'null') {
                    return 'empty';
                }
                if ($this->options['Request_currency'] != $this->options['Proposal_currency']) {
                    return false;
                }
            default:
                if (empty($data1) && $data1 !== 0)
                    return 'empty';
                if (empty($data2) && $data2 !== 0)
                    return 'epmty';
                if (!is_numeric($data1))
                    $data1 = '\'' . $data1 . '\'';
                if (is_string($data2))
                    $data2 = '\'' . $data2 . '\'';
                return eval('return (' . $data1 . $operator . $data2 . ');');
        }
    }

What a nice bit of defensive programming, ensuring that there’s a valid operator. And what a lovely pile of confusing code that may return true, false or FILE_NOT_FOUND empty. Or, sometimes, “epmty”. Bonus points for doing some of the comparisons using eval, thus allowing a code-injection attack. Einstein must have recognized this was bad, because some of the copy/pasted versions of this method instead called the first version of compareValues to avoid using eval.

But I know what you’re thinking. You’re thinking, “This is great stuff, but what good is having in PHP? This is 2018, and we’re writing operating systems in JavaScript now.” Well, don’t worry. This same method has a JavaScript version.

/**
 * compares two values
 *
 *  @fieldId
 *  @operator
 *  @compareData
 *
 */

function compareValues(data,operator,compareData,type,fieldId){
    if(!operator) return;
    if((data == "" || data == null) && (compareData != "" && compareData != null))
        good = false; //when the data is im
    else{
        switch(type){
            case 'date':
                //changing the values to numeric strings
                if(data.constructor == Array){
                    date1 = String(data[0])+String(data[1])+String(data[2]);
                }else{
                    date_arr = String(data).split("-");
                    if(date_arr[0].length == 2){ //swapping the order of the date-string (in case it's wrong)
                        date1 = String(date_arr[2]+date_arr[1]+date_arr[0]);
                    }else
                        date1 = String(data).replace(/-/g,"");
                }
                if(compareData.constructor == Array){
                    date2 = String(compareData[0])+String(compareData[1])+String(compareData[2]);
                }else{
                    date_arr = String(compareData).split("-");
                    if(date_arr[0].length == 2){ //swapping the order of the date-string (in case it's wrong)
                        date2 = String(date_arr[2]+date_arr[1]+date_arr[0]);
                    }else
                        date2 = String(compareData).replace(/-/g,"");
                }
                if(date1.length != 8 || date2.length != 8) //8 is the length of the number 'yyyymmdd'
                    return;
                good = eval(date1+operator+date2);

                break;
            case 'money':
                if (window.Request_currency != window.Proposal_currency)  {
                    good = false;
                    break;
                }
            default:
                if(IsNumeric(data)){
                    good = eval(data+operator+compareData);
                }else {
                    // Compare as strings
                    good = eval('\''+data+'\' '+operator+ ' \''+
                        compareData+'\'');
                }
        }
    }
    if(good){
        $('#'+fieldId+'_ico').addClass('icons__check');
        $('#'+fieldId+'_ico').removeClass('icons__caution_sign');
    }else{
        $('#'+fieldId+'_ico').addClass('icons__caution_sign');
        $('#'+fieldId+'_ico').removeClass('icons__check');
    }
}

Like all good spaghetti code, this one is topped with a sauce of global(window) variables, and mixes logic with DOM/UI manipulations. And thank goodness for all those regexes.

The JavaScript version is attempting to create good from eval, which never works, and it breaks the D&D alignment chart.

[Advertisement] Continuously monitor your servers for configuration changes, and report when there's configuration drift. Get started with Otter today!


To read the full article, please visit The Daily WTF

Feline Fails of the Month

Some people are cat lovers and others think that cats want to steal their souls and prefer the company of dogs. No matter which one of these sides you fall on, everyone can agree that […]

The post Feline Fails of the Month appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Wednesday, July 25, 2018

Finding Your Strong Suit

Anyone with more than a few years of experience has been called upon to interview candidates for a newly opened/vacated position. There are many different approaches to conducting an interview, including guessing games, gauntlets and barrages of rapid-fire questions to see how much of the internet the candidate has memorized.

PositiveFeedbackVicious.png
By DavidLevinson

The best approach is usually just having a friendly conversation as it gives the candidate a chance to illustrate their experience via relating war stories, or shoot themselves in the foot with easily catchable lies.

Tim C. was trying to find a mid-level C# developer to develop games. One guy came in and seemed fantastic- Bert. Bert had done a lot of work with 3D graphics and game development, and was strong on the mathematics of 3D rendering, and the intricacies of the various 3D rendering engines. He was able to explain all the concepts of light sources, shading, and so forth in easy-to-understand terms. He was obviously passionate about programming and was maintaining six open source projects on GitHub, mostly related to 3D work. The strong mathematical background was seen by Tim as a good sign, because their company is all about algorithms.

In an attempt to get at something that would give an indication of Bert's skill, Tim asked to see some of his source-code. Bert picked one of his open source projects at random and showed Tim a C++ header file.

"Headers are fine, but can I see some implementation?" Tim wanted to see some meaty algorithmic code and so asked to see his most complex source file. He showed something which looked like a file full of wrappers (of some 3D rendering library); there wasn't any actual real work being done in there.

At this point, Tim reasoned that asking to see some specific code structures, like classes or even conditionals might get the desired sample work, so he asked to see a file that had some loops in it.

"Oh, this project doesn't have any loops in it."

Tim asked to see a project that did, Bert umm'd, ahh'd and eventually found one of his six open source projects that had a loop. He said apologetically "loops are not my strong point".

While it's extremely reasonable that a candidate might not know the details of some function call in some library, it's equally unreasonable for them to admit to not knowing what is maybe the third thing they teach you in CS-101.

On that point alone, Tim and peers decided not to hire him.

[Advertisement] Forget logs. Next time you're struggling to replicate error, crash and performance issues in your apps - Think Raygun! Installs in minutes. Learn more.


To read the full article, please visit The Daily WTF

Murder Suspect and Police Officer Open fire

The Las Vegas Metropolitan police recently published dash cam footage from an indecent earlier this month. A murder suspect opened fire on the officer who was forced to fire back at the suspect through the […]

The post Murder Suspect and Police Officer Open fire appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Tuesday, July 24, 2018

1000 Strip Bacon Sandwich

Epic Meal Time introduces us to the B1000, a single sandwich with 1,000 strips of bacon. Get your cardiologist on speed dial and give this one a try… Just don’t break your oven like these […]

The post 1000 Strip Bacon Sandwich appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

Announcements: Come Work at Inedo, the Most Non-WTF Company You Know

The "Enterprise DevOps" tools market has really been taking off lately, and so has Inedo! We build market-leading tools for package management, deployment automation, and configuration automation space that aids some of the world's best companies in delivering their applications to users faster than ever.

We're looking for some great people to help us continue to grow:

  • Solution Architect/Consultant – work closely with our users to help them adopt DevOps best practices in their organization using our tools
  • Software Development Manager – lead our software development team and help develop our innovative products
  • Software Developer – Build and maintain our products, extensions, and internal systems while identifying bugs and issues with our customers
  • Content creator/writer – communicate the business value aspects of what we do to customers by working closely with our technical teams
  • US events manager – lead our events team and particulate in Inedo and software communities
  • Marketing associate – travel to various events to meet users and introduce new people to Inedo

This is a great opportunity to join a fast-growing but stable company, without all the uncertainty, stress, and unpredictability of a typical start-up. Actually, we're not at all like a San Francisco Startup, and we're proud of that. We're driven by enthusiastic customers who get excited about our next release, not by venture capitalists who are always pushing for that next series of investment.

We work hard, but more importantly, we work smart. This means not only eschewing buzzword-driven development and hacking-till-it-works, but we really focus on making a smart work/life balance a big part of our culture. Release dates are very important, but if it's still not ready at 6PM, chances are whatever gets shipped at 10PM will make life worse for everyone, including our users, who will then have to stay up late to deal with our sloppy software. Instead, we come up with a new plan at 4PM, which usually involves waiting a day or two, notifying users who might expect it, and re-planning other things accordingly.

Some call our work/life culture a "Midwest thing", which makes sense because we're based in Cleveland, Ohio. Not only are the people here friendly – we actually smile and say hi to passerbys – but it's a wonderful place to live, work, and play, whether you're raising a family or single:

  • Greater Cleveland is super affordable compared to other major cities in America.
  • The food and brewery scene is booming, with award winning restaurants opening all across town.
  • We boast three professional sports teams (yes, the Browns are professionals), and have had appearances in both the NBA finals and MLB world series in the last year.
  • Experience the joy of all four seasons! Actual. Seasons. One lasts a little longer than the others, but when you have patio season to look forward to, it's an easy sacrifice.
  • The Cleveland Metroparks spans more than 23,000 acres and has 300+ miles of trails, eight golf courses, eight lakefront parks (one of which is a few minutes walk from our office) and a nationally-acclaimed zoo.
  • Playhouse Square is the second largest theater district in the United States, and attracts more than one million guests per year to its 1,000+ annual events.

And of course, we'll gladly help you with relocation to Cleveland. A lot of our team has already relocated here and absolutely loves it.

If none of the openings are a good fit for you now, not to worry; we'll be posting more soon! In the meantime, please share with friends and family.

[Advertisement] Ensure your software is built only once and then deployed consistently across environments, by packaging your applications and components. Learn how today!


To read the full article, please visit The Daily WTF

You'd Need an Oracle to Understand These Docs

Documentation is difficult in the best of situations. I've encountered lots of bad documentation. Bad because it's unclear, inaccurate, or incomprehensible. Bad because it's non-existent. Bad because it insists on strictly using the vendor's own in-house terms, carefully chosen to be the most twee little metaphors they could imagine, but never explains those terms, thus being both incomprehensible and infuriating. "Enterprise" packages bring their own quirks and foibles, and tend to be some combination of unclear, inaccurate, or incomprehensible. Unless, sometimes, what we attribute to incompetence probably is actual malice.

An augur, sitting on the hilltop, predicting the future

I've brushed up against a lot of ERP systems in may day, ranging from the home-(over)-grown Excel spreadsheet on the network drive all the way to gigundous SAP build-outs.

On such project involved migrating 12 business units from a mixture of home-grown systems, legacy mainframe systems, and home-grown systems running on legacy mainframes into one, single, cohesive ERP. The product chosen was an offering from a company we'll call "Augur". Augur took one look at our insanely ambitious project, knew it was doomed to failure, and muttered to themselves, "Think about the consulting fees we can rack up!"

Of course, my employer didn't want to pay the consulting fees. They already had Augur domain experts hired in from a much cheaper consultancy, and our in-house developers knew how to read documentation. What could go wrong?

Plenty, but one of the smaller, simpler tasks I tackled delivered the biggest WTF. In a factory, there was a flow meter hooked up to a pipe that could tell us how much raw material flowed through that pipe. That flow meter was hooked up to a proprietary database with a very picky and flaky ODBC driver. I needed to get data out of the proprietary database and pass it off, after a little massaging, to Augur's ERP. Based on whatever product the ERP believed was being made at the time, it would then calculate raw material consumption, cost-of-goods-sold (COGS), losses, and all sorts of other wonderful production statistics.

Talking to the proprietary database involved some DLL hell, but once I was getting the data, it was time to feed it into Augur. The documentation for their consumption APIs said that I should call a method called RM_CONS_IN_FRMLU_FPT. It told me how to structure the data. It told me what other parameters needed to be set. I followed the instructions and checked the results: consumption got updated, but not COGS.

I checked my work. I rechecked the documentation. I skimmed through the underlying tables to understand the schema hiding beneath the API. I cried a little when I saw it, and then I went back to the docs. I twiddled a few parameters, and tried again. This time COGS was right, but consumption wasn't. Tried again, and now it refused to recognize the current production formula, and assumed I was just disposing of material, and only incremented my losses.

Eventually, I discover that RM_CONS_IN_FRMLU_FPT is actually a wrapper method for RM_FPT_CONS_BY_UT. I have to bootstrap a few more complex parameters myself, but I try again. Still doesn't works. Back to the docs, and then I notice a tiny little footnote: "To calculate COGS accurately, the parameter rec_cons_config must have its cogs_behavior property set to 57". So I tried that.

It crashed. It didn't just crash, though, it managed to go romping off down a bad code branch, mangled a bunch of records, committed the changes, and then crashed. I reset my dev environment and went back to the docs.

This time, I trace through a few references, discover another footnote which is itself reference to a white paper, which itself contains a footnote. "If cogs_behavior_ is set,RM_CONS_BY_UT,RM_CONS_IN_FRMLU_FPT,RM_CALC_FRMLUandCOGS_RM_CALC_USAGE` may alter data in an unrecoverable fashion."

Now, Augur's database technology separates the header for a code package from the body. This is great for Augur, as they can distribute the compiled versions of their proprietary stored procedures, but not the code. That was less great for me, as I couldn't just read the code to see what it was doing, but I could read the headers.

And there were so many undocumented parameters, each using undocumented record data types- Augur's equivalent of a struct. Tracing through the headers, I eventually found that there was a flag which was, for all intents and purposes, the secret_make_cogs_work_flag. I flipped that to true, and voila, suddenly everything was calculating.

I can't say, beyond a shadow of a doubt, that the documentation lied to me. It could have been wrong, outdated, or I could have just misread things. But given the problem- a major feature doesn't work or even destroys data- and given the simplicity of the fix, I can't see it as anything but an active attempt to mislead.

"Never attribute to malice what could be explained by incompetence- unless it's a major enterprise product vendor, in which case they really just want to sell you consulting."

[Advertisement] Utilize BuildMaster to release your software with confidence, at the pace your business demands. Download today!


To read the full article, please visit The Daily WTF

Monday, July 23, 2018

Deep Sea Nuke

Our favorite optimistic nihilist, Kurzgesagt considers the unpleasant question of what would happen if a nuclear bomb was detonated at the bottom of the Marianas Trench. Nuking the spot closest to the center of the earth might not […]

The post Deep Sea Nuke appeared first on Viral Viral Videos.



To read the full article, please visit Viral Viral Videos

NoeTimeToken

Bozen 1 (201)

"Have you had a chance to look at that JIRA ticket yet?"

Marge debated pretending she hadn't seen the Slack message yet—but, if she did, she knew Gary would just walk over to her desk and badger her further. In truth, she didn't want to look at the ticket: it was a low priority ticket, and worse, it only affected a small fraction of one client's customers, meaning it was likely to be some weird edge case bug nobody would ever run into again. Maybe if I ignore it long enough, it'll go away on its own, she thought.

The client was a bookseller with a small but signifigant-to-them online presence; the software they used to sell books, including your standard e-commerce account functionality, was made by Marge's company. The bug was somewhere in the password reset feature: some customers, seemingly at random, were unable to use the password reset link the software emailed out.

Marge pulled up the ticket, looking over the half-hearted triage work that had been done before it landed on her desk to solve. The previous guy had pulled logs and figured out that all the customers who were complaining were using the same ISP based out of Germany. He'd recommended reaching out to them, but had been transferred to another division before he'd gotten around to it.

When Marge realized that the contact information was all in German, she almost gave up then and there. But with the magic of Google Translate, she managed to get in touch with a representative via email. After a bit of back and forth, she noticed this gem in one of his (translated) replies:

We want to display mails in our webmail client as close to the original as possible. Since most mails are HTML formatted, the client supports the full HTTP protocol and can display (almost) all HTML tags. Unfortunately, this means that "evil" JS-Content in such mails can do all kinds of stuff in the browser and therefore on the customer's PC.

To avert this, all mails are processed by a "SafeBrowsing"-module before they are displayed, to recognize and circumvent such manipulations. One of those security measures is the recognition of js-modules that begin with "on...", since that are mostly js functions that are triggered by some event in the browser. Our "countermeasure" is to just replace "on..." with "no..." before the HTML content is sent to the rendering process.

Marge frowned at the answer for a bit, something nagging at her mind. "There's no way," she murmured as she pulled up the access logs. Sure enough, the url for the reset link was something like https://bookseller.com?oneTimeToken=deadbeef ... and the customers in question had accessed https://bookseller.com?noeTimeToken=deadbeef instead.

A few lines of code and it was resolved: a conditional would check for the incorrect query string parameter and copy the token to the correct query string parameter instead. Marge rolled her eyes, merged her change into the release branch, and finally, at long last, closed that annoying low-priority ticket once and for all.

[Advertisement] Continuously monitor your servers for configuration changes, and report when there's configuration drift. Get started with Otter today!


To read the full article, please visit The Daily WTF

Friday, July 20, 2018

Error'd: Upon Reaching a Certain Age...

"Evidently, once you hit 55, LinkedIn thinks you'll age until your buffer overflows," writes Jonathan L.

 

"I started out looking for shower gel, but now, thanks to Google, I'm considering if a GBIC in Cadet Blue is worth the extra money," writes Robin M.

 

Matthew B. wrote, "So, an article about AI shows that the AI behind generating the summary rasied an exception. Maybe the AIs aren't speaking to each other?"

 

"Wait...did I just fail a Turing Test?" writes Daniel.

 

Rob J. wrote, "I got a 2 on a vision test but apparently only people from Krypton or blind people test on it, because there were very large negative and positive scores."

 

Pieter V. writes, "Thankfully this combo error didn't occur on the plane I took."

 

[Advertisement] Forget logs. Next time you're struggling to replicate error, crash and performance issues in your apps - Think Raygun! Installs in minutes. Learn more.


To read the full article, please visit The Daily WTF

Thursday, July 19, 2018

Classic WTF: Flawless Compilation

Just today I was joking with my co-workers: I had written software for which we had no viable test hardware, but the code compiled, therefore I was done. The difference is I was joking… --Remy (Originally)

Back in the heady days of Internet speculation, the giant retailer JumboStores contracted with Fred’s software company, TinyWeb, to develop the region’s first web-based supermarket. Customers would be able to assemble carts online and receive their groceries the next day.

The virtual supermarket had to communicate with JumboStores’s inventory system in real-time. The former was bleeding-edge web technology, the latter a cobweb-laden mainframe with no external point of access.

“How will we get around this?” Fred asked early in the specification process.

“We can stage an intermediate server.” Nick, a programmer from JumboStores IT, assured him around a mouthful of doughnut. “You guys send your requests there, we’ll write software to forward them to the mainframe and back.”
Engine overhauled
Fred was optimistic. Both companies were *nix shops; the JumboStores IT department were his geek kindred. Equally optimistic, JumboStores management scheduled a live media demo several months out, well after the estimated project completion date.

Deadlines slipped, as they are wont to do. The week before the big demo, the online supermarket still wasn’t ready. TinyWeb had implemented the website and database back-end, but JumboStores’ relay software lagged behind. At the urging of multiple strata of nervous managers, Fred took an emergency trip to JumboStores to investigate.

“We don’t know, man, we just don’t know.” The confident Nick of months prior shook now, leading Fred to his cubicle. “We coded the application. We debugged until it compiled without errors. When we run it- core dump!” He threw up his hands, then dropped into his swivel chair. “We’ve been pestering IBM support, but they haven’t been very helpful.”

“Well, why would they be?” Fred frowned, pausing at the cube threshold. “I mean, who knows what might be wrong with the code?”

“Nothing’s wrong with it. It compiles!”

“So? It could still have errors.”

Nick swiveled around to face him. “Dude. It compiles.

Fred faltered in the wake of Nick’s earnest insistence. “That… doesn’t mean the code is perfect.” He all but fell into the spare chair presented to him. “How do I explain this?” Am I actually trying to explain this? To a programmer? “Let’s say you’re building an engine.”

“This isn’t an engine,” Nick said. “It just passes-“

“No, a car engine! OK? You have all the parts spread out on the desk here.” He waved his arm out over a layer of branded cube toys and post-it notes. “You’ve never built an engine from scratch before, but you have a blueprint with pictures and directions, so you grab your wrench and your welder and whatever, and go to town. At the end, all the parts get used up, and the result looks vaguely engine-like. Still, would you expect to drop it under the hood and have it start up flawlessly the first time you turn over the ignition?”

Nick stared. “I… don’t see what this has to do with anything.”

Fred refrained from smacking his forehead. “Uh, OK. Forget the engine. It’s like sheet music. Just because all the dots are on the staff doesn’t mean it’s the song you want.“

“Dude! The compiler would bug out if there were any problems.” Nick graciously omitted the Duh.

Fred took one last chance. “No- it’s like, if you were building a house. Just because all the parts fit together doesn’t mean it will stand up.”

Nick’s face brightened. “It’s like the home inspector! I see what you mean."

“If that works for you…” Fred said, carefully.

After long consideration, Fred took the intermediate server back home to TinyWeb for some down-to-the-wire recoding, resulting in a flawless demo for the press. JumboStores was delighted.

With their collaboration at an end, Fred wondered how JumboStores IT would ever manage on their own.

[Advertisement] BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!


To read the full article, please visit The Daily WTF

Wednesday, July 18, 2018

Classic WTF: The Mega Bureaucracy

Part of the reason we need a summer break is because we simply don't have the organizational skills of this particular company. I wonder if they sell consulting. Original -- Remy

Photo credit: 'digicla' at Flickr At my daytime corporate-type job, if I need to even sneeze in the general direction of a production environment, I need both a managerial and customer approvals with documentation solemnly stating that I thoroughly tested my changes and swear on a stack of MSDN licenses and O'Reilly books that I am NOT going to break anything as a result of my changes. Sure, the whole thing is a pain (and admittedly, a necessary evil), but what Bruce W. has to go through beats the pants off of anything I've ever had to go through.

For the most part, Bruce loves his job. He gets to work with a lot of intelligent and motivated people. He has been developing a new system to support a new product that has the possibility of earning his division several million dollars per year and saving the corporate parent several hundred thousand dollars per year. The net effect on the corporate parent's bottom line will be quite nice. He developed a Web front end while a fellow developer put together the data feeds. The initial development work was estimated to take about six weeks; pretty good since we only had eight weeks to work with.

However, Bruce works in a very large corporation (70,000 plus employees through out the US and several countries) and IT for the corporation has been highly centralized to the world headquarters. Smaller IT work, like the development and support for only a single division, isn't centralized but must pass through the central Mega Bureaucracy for approval and placement on the centralized servers.

...and Bruce needs their "help" to officially set up his environments.

You see, while Bruce and his group can test all day long on their local computers and servers, any kind of "live" environments must be created, blessed, and centralized by the Mega Bureaucracy. They're bigger, badder, and have more connections than anybody in your division's rank-and-file. Remember: in the Mega Bureaucracy, processes and procedures are to be followed, respected, and if necessary worshipped. Oh, and forget even thinking of installing Web services on one of the existing centralized servers. That would bring down the wrath of the entire blessed Bureaucracy for changing the purpose of an existing machine without first going through Mega Change Server Process.

Here's a brief overview of what Bruce had to go through to get four (one each for development, testing, staging, and production) Windows-based Web servers:

Week 1 - At the same time Bruce's group started the project he went to procure the servers. He was told that all he needed to do was put in a Service Request with the Windows Server Team and they would get what we needed. However, that request is cancelled because when the Windows Server Team saw that the servers were for a new application they said, "Whoa, you have violated rule #38,991 of the Mega Bureaucracy! New applications must go through the Process for Application Implementation and Navigation."

Bruce starts into the fill the first two PAIN forms (one being 20 pages long with 150 questions), sends them off to the server team, and immediately receives a response that, no, do not directly send PAIN forms to the group they go to. Instead, open a project with the Mega Bureaucracy's project tracking system, attach the forms and THEN assign the project to the group.

A few days later, he receives word that the project has been accepted, slotted, and a project manager assigned. Bruce figures, "Cool, now we are moving! I'll have my servers in no time!" He and his boss have a conference call with the PM and express to him the time critical nature of these servers. The PM agrees to push them forward saying that the request isn't complex and shouldn't take much effort.


Week 2 - Bruce receives the initial project estimate and immediately replies with his approval.


Week 4 - Bruce calls the PM to find out what's going on. He says that due to staffing cuts only a handful of requests are being processed at a time. Despite being reminded that this project is literally worth millions, he says that other projects are ahead of us and that this is simply how things are. Bruce boss escalates the issue to the head of IT for the entire division who just happens to be a member of the Project Approving Council and supposedly has the power to move the project forward.


Week 6 - Only three weeks until the promised delivery date, Bruce learns that the project still has not moved. His boss fires off a series of emails saying that the app is about to go live on a system that will earn the company millions of dollars that is running on a desktop machine sitting in a cubicle.


Week 7 - The system is now fully coded. Bruce is walking around, shaking his head, saying to himself "We have done user testing and end-to-end testing on a desktop machine-based server!"


Week 8 - The new system goes live and is serving dozens of customers daily. The difference between Production and Test environments is a Post-it Note. Power strips and network hub are carefully labeled "DO NOT TOUCH! HIGH VOLTAGE!" to prevent cleaning staff misfeance.


Week 10 - Bruce and the Windows Server Team finally have the project kick off meeting for the servers. About 15 of the 30 minute call was spent with Bruce repeatedly saying, "All I need is a Windows Server with IIS and .NET. I do not need a database server, no access to the mainframe, no massive SAN space, no Internet access, no interplanetary probe, just servers." "BUT", they say, "You stated on page 16, question 113 that your application uses a database. Where will that database come from?" Bruce explains again, "We are using existing databases assigned to our group. The database is outside of the scope of the project of setting up four Web servers."

Week 12 - Bruce and the Windows Server Team get together for their status meeting. The server team says they haven't budged since last meeting. Why? Everyone says, "Well, we're just waiting for the other shoe to drop and this becoming a big, complex, hairy project requiring massive time." Bruce once again states that all they he needs is four Web servers. Nothing more. The server design engineer says, "Wow, that is pretty simple. Shouldn't take too long at all."


Week 14 - Bruce has another status meeting with the PM and the server engineer. The engineer has put together the required diagram of the requested infrastucture and states that he only had to change a handful of things from the initial template. He says that everything should be ok and once they have the infrastructure readiness, the server builds can start. Bruce thinks, "Finally! All the other people initially assigned to the project must have realized that building four web servers isn't that big if a deal! ...haven't they?"


Week 18 - The head of IT for our division finds out that we are still waiting. Heads start rolling...even poor Bruce's. "WHY DIDN'T YOU CALL ME SIX %($$!*& WEEKS AGO???" the IT head blasts.


Week 19 - The servers are built (it only took 2 days to build them!) and are signed off for production support.

Week 20 - Bruce distributes the application URL pointing to the brand new servers.

Through all of this Bruce learned a couple things. First, don't even think of going around the Mega Bureaucracy, even if somebody says you can. The Mega Bureaucracy remembers and brands you a heretic. Second, if you think you will need help from the Mega Bureaucracy, start early, fill out all of the forms, stand in the right lines, sacrifice to the appropriate gods, and don't even hint that you would think of going around them. Finally, he who yells loudest gets move the front of the queue soonest - as holy and almighty as The Mega Bureaucracy is, they're happiest to get rid of their crabbiest customers first.

The silver lining in all of this? Apparently, the Guardians of the Mega Bureaucracy seem to now be willing to consider that there is a different tier of requests that don't require so many stopping points, designed to make sure that users really, REALLY know what they want to request. Bruce remains positive saying that, maybe in a few years, after meetings to plan meetings, forms to request forms, they will have a process that only has an initial questionnaire of 10 pages and 75 questions.

[Advertisement] Otter - Provision your servers automatically without ever needing to log-in to a command prompt. Get started today!


To read the full article, please visit The Daily WTF