Some unfamiliar Google products

Wednesday, 6 March 2013


Google provides a lot of services and products online,which keeps on increasing according to current trend and needs. Google also had discontinued from various products and tools, due to lack of support, or due to lack of popularity in the market.
But there remains some products that are worthy, though they remain unfamiliar or less popular among  people. Here, I list a few of them:
1.AngularJS:   
A JavaScript framework, used to reduce the amount of JavaScript needed to make web applications.
2.Dart:
A programming language developed by google and introduced as an opensource. It was mainly developed to replace JavaScript, and to have a much flexible language to get implemented in large scale projects, and also with an intention that it should become an universal client side script.
3.Map Maker:
Lets you update Google Maps & Google Earth data of over 200 countries with relevant information. You can add new places, edit details of existing places or review information submitted by other users. The changes made by you will be reviewed by moderators — once approved, they will get added and accessible to anyone in the world.
4.Google Currents:
It is a mobile app available for iOS and Android devices, to get updated with various news channels and magazines.
5.Building Maker:  
Web based building and editing tool to create 3D buildings, much useful for engineers and house designers. Its important feature is that, the created one can be imported and get integrated to Google Earth.
6.Moderator:
It is an open forum by Google where anyone can initiate a discussion about anything. Once you submit a question or start a topic, other users vote if the question or idea is good or not. Visitors can also post comments or questions in the discussion, which can also be voted upon, marked as useful or flagged as inappropriate. You can share an entire discussion or a specific comment via email, Facebook, Twitter or Google Plus to elicit more responses.
7.Go:  
a compiled, garbage-collected, concurrent programming language developed by Google. Its syntax is similar to that of C. It supports Linux, Mac OS X, FreeBSD, OpenBSD,Plan 9, and Microsoft Windows operating systems.
8.Schemer:
Its a Google service that allows you to make a list of activities to do around you (according to your interests). You can add friends (called accomplices) to your schemer account and it will automatically find and recommend common activities that you and your friends can do. You can also browse schemes recommended by people for various places and add those to your list.
9.SketchUp:
 Modeling application to sketch simple 3D structures for integrating into Google Earth. It Supports Mac OS X, Windows 2000, Windows XP, Windows Vista, and Windows 7. 
10.Page Speed:
Used to analyse and have an online insight on our website’s speed, and to get suggestions to improve our page speed. It also provides a score for better analysis. 
11.Visigami:
 Image search application screen saver that searches files from Google Images, Picasa and Flickr. It Supports Mac OS X Leopard.
12.Google Mars:
 Imagery of Mars using the Google Maps interface. Elevation, visible imagery and infrared imagery can be shown. It was released on March 13, 2006, the anniversary of the birth of astronomer Percival Lowell.
13.Google Moon:
 NASA imagery of the moon through the Google Maps interface. It was launched on July 20, 2005, in honor of the first manned Moon landing on July 20, 1969.
14.Google Sky:
 Internet tool to view stars and galaxies, can be used via browser version of “Google Sky”.
15.Zygote Body:
It is used to render manipulable 3D anatomical models of the human body. Several layers from muscle tissues down to blood vessels could be made transparent to allow better study of individual body parts.
16.Scholar: 
This is a customized search for articles, theses, books, court opinions and other documents. It can help you with locating the entire document on the web if available, and articles are ranked according to quality of content, the author and how often has it been used as a reference in other documents. It holds almost all IEEE, Elsevier, Springer papers, useful for students under research and projects.
17.Google Insights for Search: 
Google Insights for Search is a service by Google similar to Google Trends, providing insights into the search terms people have been entering into the Google search engine.
18.Google Refine:
 Tool for data cleansing and processing.
19.Trendalyzer:
Data trend viewing platform to make nation’s statistics accessible on the internet in an animated, interactive graph form. 
20.Google Trends: 
Graph plotting application for Web Search statistics, showing the popularity of particular search terms over time. Multiple terms can be shown at once. Results can also be displayed by city, region or language. Related news stories are also shown. Has “Google Trends for Websites” sub-section which shows popularity of websites over time.
21.Zeitgeist: 
Collection of lists of the most frequent search queries. Gives weekly, monthly and yearly lists, and topic and country specific lists.
22.Google Squared: 
Takes a category and creates a starter ‘square‘ of information, automatically fetching and organizing facts from across the web.
23.Google Tasks :
Keep track of what you need to do. Your task list stays up to date no matter how you access it. It’s a simple list that’s with you everywhere you go.
24.Jaiku: 
Create your own microblog and connect with your friends.
25.reCAPTCHA :
A captcha system that uses successful decoding to helps digitize books for online use.
26.Textcube :
 Korean blogging platform.

Posted by droided.dev at 06:50 0 comments  

Does your Browser uses Sandboxing ?

Tuesday, 5 March 2013


There are a plenty of browsers available now. But people go only for the best one of the big three: Internet Explorer, Firefox, or Chrome.
But which is best among them ?, stays as an ambiguous question.
Each browser has its own mechanism for its efficient performance.
But Google stands as an highlighted one when coming to security and for a safer browsing.

Google’s Chrome browser is safe for its two reasons:
1. First, it’s the only browser to use sandboxing as its primary defense mechanism. This method combines a JavaScript virtual machine with an OS-level sandbox to prevent successful attacks against the browser’s rendering engine from affecting a user’s file system.
2. Second, Google updates the Adobe Flash and Acrobat Reader modules itself. So if you’re running the latest version of Chrome, you’re running the latest, most secure versions of Flash and Acrobat Reader available.
But we’re just getting started. JavaScript vulnerabilities—including blatant attacks that rely on a user’s cooperation to work—can just as easily affect your browser.
If you’re using Firefox, grab an extension called NoScript, which will allow you to disable a page’s plugin elements (including Java Script and Flash!) by default, unless you trust the site enough to give them a go.
Click Here to install :  noscript.net
 Chrome doesn’t have an add-on for the same feature, but you can disable Java Script by default in the browser’s Under the Hood settings section.
And if you want to specifically allow a site’s JavaScript to function, just click the associated X icon in the browser’s address bar to set up site-specific trust.

Posted by droided.dev at 06:47 0 comments  

A sneak peek into Facebook server

Monday, 4 March 2013



Data centers—how they’re designed and what hardware they run—are generally deeply guarded secrets within a corporation.
Indeed, a particularly efficient data center is considered a competitive advantage.
But secrecy isn’t an objective of Facebook’s Open Compute Project.

There are six basic server types at Facebook, but the two frontline machines are the web server and the memcache server.
The web server is the first machine you connect with when you visit Facebook.com, and it does a lot of heavy lifting and database lookups.
These boxes run Linux and Apache.
Currently, these machines uses Intel Xeon rigs running dual 2.66GHz six-core Xeon X5650s.
These boxes also have a surprisingly low amount of RAM in them: just 12GB of unregistered DDR3.
Once the web server has done your lookup, data is pulled from dual Opteron-based memcache servers running Memcached, an open-source memory-caching system.
These machines are engineered for cost-efficiency.
As such, they run dual octo-core 2GHz Opteron 6128 procs in G34 sockets.
The machines feature 72GB of DDR3/800 RAM to help feed your profile page as quickly as possible.
The next iteration of the memcache servers are expected to double with 144GB RAM.
Since neither server type performs any heavy-duty local storage functions, Facebook opted for the cheapest hard drive available— in this case, a 250GB WD Caviar Blue drive—to boot the OS and store log files.
While the machines may lack a bit in the specs department, when you gang them together, their cumulative firepower is impressive.
Facebook won’t disclose exactly how many machines it uses for running.
  • But Every day a truck arrives with 13 racks of new computers in it.
  • Each rack holds 90 servers.
  • Once that truck is unloaded, another truck will pull up with another 13 racks.
  • Each day, four trucks arrive.
  • This happens every day of the work week all year round, just to keep up with the demand.
The amazing thing is that Facebook’s servers are only a small part of the secret sauce in the company’s new data center.
Advances in cooling, server design, and backup power make Facebook’s Pineville facility perhaps one of the most energy-efficient data centers on the planet.

Posted by droided.dev at 06:32 0 comments  

Best sources to learn PHP

Sunday, 3 March 2013

Hi friends, Are you searching for best tutorials or books to get started with PHP ?
Here I provide you some best sources where you can find splendid tutorial sites and books that makes newbies to feel easy.
TUTORIAL SITES:
These sites gives beginners a good intro to the language and makes you to understand well with live demos and free source codes to test it ourselves.
Also much useful for developers who need to make their projects more lively and scintillating.
BOOKS :
Google these books now and start learning. I suggest you to download free ebooks if you find.
Head First PHP & MySQL
MASTERING PHP 5
PHP Cookbook
PHP Bible
PHP Solutions: Dynamic Web Design Made Easy
PHP for Absolute Beginners
Professional PHP5
Beginning PHP, Apache, MySQL Web Development by WROX

Posted by droided.dev at 06:27 0 comments  

Best Sources to learn Blogger

Saturday, 2 March 2013

Are you searching for best tutorial sites for getting into Google’s Blogger…
Here are my suggestions for you :
1. Before entering into blogging, my best advice is to learn “Google Blogger For Dummies” book completely to understand what blogging is about.
2. Best tutorial for Blogger:
Google’s Blogger Guide  :  This guides you on how to create,publish,post and edit the blog.
BloggerBuster.com : A must read tutorial on how to build your blog entirely. Gives you a brief guide on various topics needed for a blogger.

Posted by droided.dev at 06:24 0 comments  

What Everybody Ought to Know About Session Hijacking

Friday, 1 March 2013


When comes to hacking, most of the people think that they are safe now and are aware of many hacking techniques like phishing , key-logging and other amateur hacking tricks.
But many would have fallen into a trap called Session Hijacking which they would have never realized so far…..

What is Session Hijacking?
Websites are prone to Session hijacking when it uses any login system for authentication.
Sessions are usually created on the server side of the web, to hold a status whether a user is currently logged in to the site and he is currently active.
This provision is generally given to all sites by web developers. But, the intruders use this  technique for their favour.
Sessions generally uses cookies to save its information. Cookie is a piece of text stored on user computer by websites visited by the user.
This stored cookie is used by webserver to identify and authenticate the user while login.
So, if this cookie gets stolen by hackers and injected into their browser, they can imitate our identity to web-server and enter our Email account easily. This is called Session Hijacking or Cookie stealing hack of an user ID in a Web application.
Session Hijacking too can be done in Network level which is explained below …
How does an attacker go about hijacking a session in a network ?  The hijack can be broken down into four broad phases.
1.Tracking the connection :
The attacker will wait to find a suitable target and host. He use a network sniffer to track the victim and host or identify a suitable user by scanning with a scanning tool such as nmap to find a target with a trivial TCP sequence prediction.
This is done to ensure that because the correct sequence and acknowledgement numbers are captured, as packets are checked by TCP through sequence and/or acknowledgement numbers.
These will later be used by the attacker in crafting his own packets.
2.Desynchronizing the connection
A desynchronized state is when a connection between the target and host is in the established state; or in a stable state with no data transmission; or the server’s sequence number is not equal to the client’s acknowledgement number; or the clients sequence number is not equal to the server’s acknowledgement number. To desynchronize the connection between the target and host, the sequence number or the acknowledgement number (SEQ/ACK) of the server must be changed. This can be done if null data is sent to the server so that the server’s SEQ/ACK numbers will advance; while the target machine will not register such an increment.
The desynchronizing is preceded by the attacker monitoring the session without interference till an opportune moment, when he will send a large amount of ” null data” to the server. This data serves only to change the ACK number on the server and does not affect anything else. The attacker does likewise to the target also. Now both the server and target are desynchronized.
3.Resetting the connection
Another approach is to send a reset flag to the server and tearing down the connection on the server side. This is ideally done in the early setup stage. The goal of the attacker is to break the connection on the server side and create a new one with different sequence number.
The attacker listens for a SYN/ACK packet from the server to the host. On detecting the packet, he sends an RST to the server and a SYN packet with exactly the same parameters such as port number but a different sequence number.
The server on receiving the RST packet, closes connection with the target, but initiates another one based on the SYN packet – with a different sequence number on the same port. Having opened a new connection, the server sends a SYN/ACK packet to the target for acknowledgement.
The attacker detects (but does not intercept) this and sends back an ACK packet to the server. Now, the server is in the established state.
The target is oblivious to the conversation and has already switched to the established state when it received the first SYN/ACK packet from the server. Now both server and target are in desynchronized but established state.
This can also be done using a FIN flag, but this will cause the server to respond with an ACK and give away the attack through an ACK storm.
This results due to a flaw in this method of hijacking a TCP connection. When receiving an unacceptable packet the host acknowledges it by sending the expected sequence number and using its own sequence number.
This packet is itself unacceptable and will generate an acknowledgement packet which in turn will generate an acknowledgement packet, thereby creating a supposedly endless loop for every data packet sent.
The mismatch in SEQ/ACK numbers results in excess network traffic with both the server and target trying to verify the right sequence. Since these packets do not carry data they are not retransmitted if the packet is lost.
However, since TCP uses IP the loss of a single packet puts an end to the unwanted conversation between the server and target on the network.
The desynchronizing stage is added in the hijack sequence so that the target host is kept in the dark about the attack.
Without desynchronizing, the attacker will still be able to inject data to the server and even keep his identity by spoofing an IP address. However, he will have to put up with the server’s response being relayed to the target host as well.
4.Injecting the attacker’s packet
Now that the attacker has interrupted the connection between the server and target, he can choose to either inject data into the network or actively participate as the “man in the middle”, and pass data from the target to the server, and vice versa, reading and injecting data as he sees fit.
Illustration:
  1. Ram opens a telnet session to Noor and starts doing some work.
  2. Badhri observes the connection between Ram and Noor using a sniffer that is integrated into his hijacking tool. Badhri makes a note of Ram’s IP address and his hijacking software samples the TCP sequence numbers of the connection between Ram and Noor.
  3. Badhri launches a DoS attack against Ram to stop Ram doing further work on Noor and to prevent an ACK storm from interfering with his attack.
  4. Badhri generates spoofed packets with the correct TCP sequence numbers and connects to Noor.
  5. Noor thinks that he is still connected to Ram.
  6. Ram notices a lack of response from Noor and blames it on the network.
  7. Badhri finds himself at a root prompt on Noor. He issues some commands to make a backdoor and uses the sniffer to observe the responses from Noor.
  8. After covering his tracks, Badhri logs out of Noor and ceases the DoS attack against Ram.
  9. Ram notices that his connection to Noor has been dropped.
  10. Badhri uses his backdoor to get directly into Noor.
-Hope this article gave you a clear idea on session hijacking.
Thank you.

Posted by droided.dev at 06:20 0 comments  

UEFI or BIOS ?

Thursday, 28 February 2013

  •              The first bit of code that runs when you hit the power button, the PC’s Basic Input/Output System (BIOS) is responsible for checking hardware and their conditions, and then finally passing control over to the operating system.This has been the same for a long time.
  •            But there’s a new alternate now finally. Called Unified Extensible Firmware Interface (UEFI).  As we know, newer is not always better, let us compare both technologies and determine which is better.

INTERFACE:
Just click check-in the interface yourself……….
 
Now…have I to tell you which is Best interface….?
FEATURES:
  • The BIOS is written in Assembly, cannot be translated to another CPU architecture, runs in 16-bit real mode, and can only address 1 MB of RAM.
  • UEFI, on the other hand, is written in C, supports both 32-bit and 64-bit, and even has network access. UEFI also promises faster boot times over the BIOS, although we have yet to see it .
PARTITION LIMIT :
  • The BIOS would likely continue to be supported if not for its most glaring problem: its inability to support partitions beyond 2TB (2.2TB to be specific).
  • UEFI, on the other hand, will support up to 9.4ZB, or 9.4 billion terabytes.
EASE OF USE:
  • The BIOS has been with us so long, you’d think that most of us could drive it in our sleep. Unfortunately, it’s not always that easy and every board maker has its own BIOS interface.
  • UEFI’s graphical interface promises greater ease of use, and, indeed, Asus’s drag-and-drop interface for boot devices is evidence of that. Still, some UEFI settings are as difficult to decipher as those in the BIOS, but it’s only going to get easier and better from here.
Change is difficult for many. It’s like making the switch from Office 2003 to Office 2010, and its impossible now to work with its older version.
In the same way, UEFI is the future and we’re only at the beginning stage.

Posted by droided.dev at 06:23 0 comments