Monday, December 21, 2015

Why don't fair coin tosses “add up”? Or… is “gambler's fallacy” really valid?

I am posting this answer here because I just joined the Philosophy website on StackExchange even though I have posting and comment privileges on other StackExchange sites. The question is quoted below:

I have always been perplexed by a seeming paradox in probability that I'm sure has some simple, well-known explanation. We say that a "fair coin" or whatever has "no memory."
At each toss the odds are once again reset at 50:50. Hence the "gambler's fallacy." After 10 heads, the odds of another head are still said to be 50:50. The same after 20, 40, 80... heads.
Yet we also know that the series will converge upon an equilibrium of heads:tails. And indeed this is countable in fairly short order. The convergence appears pretty quickly.
How can both be true? Isn't there something in the physical series of tosses that "remembers"? Isn't there necessarily some slightly better chance of a tails after 10 heads?
How does logic resolve this absolute randomness in the particular events with a general law of convergence? I imagine this must be a well-known issue. I suppose it raises the larger issue of what sort of "causality" probability is.
Note that I do not know symbolic logic so, embarrassingly, formal demonstrations are beyond my ken.

There's a very simple answer that Marilyn Vos Savant wrote in her Parade Magazine column years ago. The answer is that each individual toss of a coin has a 50/50 probability, but these odds do not apply in aggregate!

Who'd 'ave Thunk it?

Thursday, December 17, 2015

Is There A Way To Keep Very Noisy Mailing Lists Out Of Your Gmail Inbox And Still Participate In Them?

I am trying to keep a noisy mailing list out of my Gmail inbox (and I don't want to switch to just yet). It's not a noisy list per-se; there's a lot of signal (good information) but I'd prefer to keep it out of my inbox, except for the few posts that I participate in. I don't see a way to do this, which might just convince me to use Google's Inbox app. combines many similar emails, either from a mailing list but also by the type of message, eg groupon deals) into a single item in your inbox.

By the way, does anyone else have a huge Gmail inbox? Mine has 127,000 unread messages, going all the way back to 2005 when I first created it. It just got out of control and unmanageable. I do skim over all of the subject lines and read emails directly but I don't open reach one. Server Port Scans, DiG DNS Lookups, Nmap Scan

I did these scans on March 23, 2015. I've had this saved in my blogger drafts for awhile, but I thought I would go ahead and release it. Note that there's no RDP port open, as was reported. It was probably closed soon after reached the news. All ports were closed, apparently.

C:\Documents and Settings\newadmin>dig any

; <<>> DiG 9.9.5 <<>> any
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- 61432="" id:="" noerror="" opcode:="" p="" query="" status:="">;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1

; EDNS: version: 0, flags:; udp: 512
;              IN      ANY

;; ANSWER SECTION:       7199    IN      NS       7199    IN      NS       7199    IN      MX      10       7199    IN      SOA 114021113 10800 3600 604800 3600       7199    IN      MX      10       7199    IN      A

;; Query time: 78 msec
;; WHEN: Mon Mar 23 12:31:50 Eastern Daylight Time 2015
;; MSG SIZE  rcvd: 260

C:\Documents and Settings\newadmin>nslookup -type=mx

Non-authoritative answer:        MX preference = 10, mail exchanger =        MX preference = 10, mail exchanger =

C:\Documents and Settings\newadmin>nmap -sT
t -vv -p 443,110,25,2525,465,587,993,995

Starting Nmap 6.01 ( ) at 2015-03-23 12:38 Eastern Daylight Time
Warning: Hostname resolves to 2 IPs. Using
Warning: Hostname resolves to 4 IPs. Using
Initiating Ping Scan at 12:38
Scanning 2 hosts [4 ports/host]
Completed Ping Scan at 12:38, 0.27s elapsed (2 total hosts)
Initiating Parallel DNS resolution of 2 hosts. at 12:38
Completed Parallel DNS resolution of 2 hosts. at 12:39, 11.09s elapsed
Initiating Connect Scan at 12:39
Scanning 2 hosts [8 ports/host]
Completed Connect Scan at 12:39, 3.00s elapsed (16 total ports)
Nmap scan report for (
Host is up (0.047s latency).
Other addresses for (not scanned):
rDNS record for
Scanned at 2015-03-23 12:38:54 Eastern Daylight Time for 15s
25/tcp   filtered smtp
110/tcp  filtered pop3
443/tcp  filtered https
465/tcp  filtered smtps
587/tcp  filtered submission
993/tcp  filtered imaps
995/tcp  filtered pop3s
2525/tcp filtered ms-v-worlds

Nmap scan report for (
Host is up (0.047s latency).
Other addresses for (not scanned):
rDNS record for
Scanned at 2015-03-23 12:38:54 Eastern Daylight Time for 14s
25/tcp   filtered smtp
110/tcp  filtered pop3
443/tcp  filtered https
465/tcp  filtered smtps
587/tcp  filtered submission
993/tcp  filtered imaps
995/tcp  filtered pop3s
2525/tcp filtered ms-v-worlds

Read data files from: C:\Program Files\Nmap
Nmap done: 2 IP addresses (2 hosts up) scanned in 14.80 seconds
           Raw packets sent: 8 (304B) | Rcvd: 2 (72B)

How To Tell Which Version Your Windows 10 DVD/ISO Is

There are a few different ways that I've found to tell you which release your build of Windows 10 DVD or ISO/UDF image is. Since we only have two major RTM and later builds, one of the below should work.

Running Grepping/Strings on sources/Setup.exe: This seems to show the most accurate version number, including an internal build number. I have yet to install this ISO, so I am not sure if the 151029 number is indicative of it being a 10.0.10586.29 build number. The command below uses Sysinternals' strings program:
> strings setup.exe | findstr -i 10\.
10.0.10586.0 (th2_release.151029-1700)

DLL Method: Once you've extracted the files from your Windows 10 .ISO file, find at any DLL file in the Sources folder. Right-click it and choose Properties. Then click the Details tab. Under Product Version or File Version, it will show the build number:

Sources/Ws.dat: This file is in the sources folder. This file is in the inf format. Open it in notepad and it shows the build in the ClientVersion field. Note that in the 10240 build this file was empty, but going forward it might be used in the future.

Sources/Idwbinfo.txt: This file is in the sources folder. Open it in notepad and it will show the major release. th1_release is for 10240 and th2_release is 10586:
Sources/schema.dat: This file is in the sources folder. It's a binary file, but you can still open it in notepad. Search it for the string version and you'll see the full build number

Sources/sxs/ This file is in the sources/sxs folder. Open the file with 7-zip, and the file names will show the Windows build number:


Here's my copy of the Media Creation Tool, version 10586, which as of this post, will still download a build 10586 ISO. If you have the original July 10240 Media Creation Tool, it will download the RTM build 10240 ISO.

Thursday, November 12, 2015

How To Fix Botched MS Update MS15-115 KB-3097877; Affects More Than Outlook

Microsoft released a botched update that was supposed to fix opentype vulnerabilities but has caused logon issues, blank screens, etc.... The first reported problem with this hotfix was that Outlook would crash when opening HTML email.

They have since fixed the issue with this patch and have re-released it, as Infoworld reports.
 Microsoft has since replaced the troublesome security patch with a new one by the same KB number, at least for Windows 7
Fix #1: Use Remote Desktop/MSTSC and RDP into the machine and remove the update with this command:

wusa /uninstall /quiet /norestart /kb:3097877

You will still need to go into Windows Update, click Check for updates, and right click on update 3097877, then right-click it and choose Hide this update. You will not need to hide this update anymore, as this patch has been rereleased today.

Fix #2: As reported by Ryan Seabury on Infoworld's coverage, disconnect all secondary and tertiary (extra monitors) video monitors and reboot, then you should be able to login again. Then you can remove the update, and the working update that was re-released today (Thursday, November 12) will download again through Windows Update. Be sure to upgrade video driver to latest, as this update may corrupt display drivers.


Also in some unrelated news, but still interesting, you can now test you Android for all 22 security vulnerabilities with VTS for Android by NowSecure OSS . My LG Leon LTE is vulnerable to stagefright.

Saturday, August 29, 2015

Windows 10 Upgrade Install Failing With A PRE_OS Error (Something Happened)

I have seen other guides that say to fix a failed Windows 10 install by doing a clean boot among other things:

  • disabling items in MSCONFIG
  • run setup.exe as administrator
  • ensure that a bunch of services are set to automatic and start them
  • disabled all antivirus
  • boot into safe mode and run delete both folders that start with $Windows at the root of the C: Drive
  • change your locale settings.
  • remove all previous files, settings, and applications
  • Create a registry key called AllowOSUpgrade to 1
I tried all of these at the same time, and none of them worked. The upgrade to Windows 10 kept failing and it would not give any reason why other than an inexplicable error message. I did two things after this: I installed Windows 7 Service Pack 1, which was not installed before. Still no dice. So I imaged the drive to another drive, and lo and behold, Acronis True Image found some unreadable sectors. I set it to ignore read errors while cloning, then booted up into 7 and Windows 10 installed just fine!

People are also saying to do a clean install of 7 or 8 first, or run chkdsk, which could be the reason that the upgrade then proceeds, if the hard drive errors are correctable!

Hey Apple, will you be giving away OS X version 11 away for free? (Or OS XI or OS 11 or OS 10.11?)

Wednesday, August 19, 2015

How To Permanently Disable Windows 10 Home Edition Updates

This will also work on Windows 10 Pro or Enterprise, but on those editions you can merely disable the Windows Update service by running services.msc, finding the Windows Update services, stopping it and setting startup to Disabled.

Please note that this may also block Windows 10 from phoning home to Microsoft, and will also likely disable most Microsoft online products (OneDrive, etc...)

Disable Windows 10 Updates:

Click on Start and Run, or type the "Windows Key" and "R", then type this command:

notepad %windir%\system32\drivers\etc\hosts

or this one:

notepad c:\windows\system32\drivers\etc\hosts

Add these lines below to the hosts file and click save. If it asks you for a location to save, then launch notepad as an administrative user and then open the hosts file. You'll have to type this filename directly into the File Open box, since normally only .txt files are shown:


# Important!     # fix for network status and diagnostic tools

This list came from DSLReports. If anyone has any updates on this issue, such as a more complete list, or a better way to disable updates, please post a comment below.

Monday, February 16, 2015

Server Backup 2012 Error 0x80780119 (not enough disk space to create a Shadow Copy)

Here's a working fix for this issue,

  1. Open Computer.
  2. Right click the C drive (the active drive that contains the Windows system folder)
  3. Click the Shadow Copies tab
  4. Select the EFI volume and click settings
  5. Change the Maximum Size to be two or three times the size that is listed.
  6. If the Maximum Size is unlimited, try setting it to different values.
  7. Repeat steps 3 and 4 for the Recovery Partition.
If you are still having trouble, then change the Shadow Copies storage area from itself to the C drive or another partition (preferably on the same disk or array), for both the Recovery and the EFI boot partition. This should also work for Windows 8.
Another possible but untested solution is to use AOMEI Partition Assistant to resize the Recovery Partition and the EFI partition to be two to three times larger.

Here's some background links:
  1. Disable WinRE (Open elevated command prompt and Run: “reagentc /disable”)
  2. Take system image backup
  3. Enable WinRE (Open elevated command prompt and Run: “reagentc /enable”)
You can write a batch file to run these commands via the scheduler for automation,

The "USN journal" fix does not work on 2012, since Windows Server 2012 does not allow you to assign the EFI or Recovery partitions a drive letter. But also I have not tinkered with diskpart to see if it's possible via the command-line.

Apparently there is an errant Windows Update that just recently came out, since many people are having this issue but there's no official hotfix.

Saturday, January 10, 2015

Amazon Android App 5.2 Final Version (Before It Was Pulled From The Appstore)

This is the final version of the Amazon's Android app that allowed the downloading of Android Apps from the Amazon Appstore, right before it was pulled and added back without this functionality. It's version 5.2.

Thursday, December 4, 2014

Chromium Pepper Flash Plugin (PPAPI) Downloads

I was looking around with different versions of Chrome's Pepper Flash plugin, and decided to upload all the versions that I had laying around my laptop's hard drive. Even though Chromium Portable comes with a Pepper Flash plugin, it does not work by default without adding this parameter:


The launcher supports passing command-line parameters to the real chrome.exe. It also supports passing parameters on all other apps.

Here's the archive with all the different versions I was able to find. It has version 11.5, 13, 11.6, 11.4, 11.9, 12, and 16 beta. The Version.txt file in the downloaded archvie has the more exact version of Chrome that the Pepper Flash plugin came from.!AZZEiTaJ!4ip9bfNxf_QWsBxt6kPukXYYkMEnq51fZ4bzjzwDH98

Wednesday, November 5, 2014

Scanner Crashing Computer When Plugged Into USB 3.0 Port (Fujitsu Scansnap)

If you have a usb scanner that causes a computer to crash (and I have even seen them prevent the computer from booting) try plugging it into a USB 2.0 port. This should resolve the problem.

Google Fiber Might Be Coming To Atlanta!

As seen on the Atlanta Linux Enthusiasts mailing list:

No official announcement yet, but the rumor is that they're going to Brookhaven and Smyrna.

Wednesday, September 10, 2014

5,000,000 Gmail Usernames (The Hack)

Wondering if your gmail password was hacked? Download the complete list, rather than checking on (which might be a phishing site):!5FphCSiY!geIPHZauErsJqXYWq4u_5b5ta9-CrWqpJY58yiqwJeY
Here's the original post:
Number of records:4929090 update: 2014

At the base of> 60% of valid passwords

Here is lined full database without a password, only for personal checks, do not hit if your mailbox in it.
So it appears that it was already leaked elsewhere, and this was not the original leaker, but was the first public leak.
#tvskit #hacked #gmail #isleaked

Saturday, September 6, 2014

Atlanta's endless concrete jungle

I wonder what is the furthest distance that one can drive in the greater Atlanta area by staying in parking lots. I would imagine its about a mile or so, with the endless strip malls that congeal into one giant megamall.

#suburban #wasteland #concretejungle

Thursday, August 7, 2014

Google Emu Messenger Download

Here is version 1.0b4 of the "Emu Messenger" A.I based text-messaging app before being purchased by Google. I expect it will be subsequent;y infected by the Google+ virus. The filename is

Media coverage:

Here is the virustotal virus scan result of the above file:

Wednesday, April 9, 2014

OpenSSL Heartbleed Vulnerable Server Testing

It seems that the OpenSSL heartbeat vulnerability (heartbleed) has not caused that many issues so far, and many servers are patched already. I believe there's a lot of hype behind it. However, time will tell if it causes any impact. Also we may never know what exactly is leaked, we can only know that a hack was attempted by using snort or another IDS/IPS. The version command doesn't really say if you're running 1.0.1[a-f], but it's safe to say that if your version is 1.0.1.[anything] and it's timestamp is older than April 2014, then that version is vulnerable.

These services may be vulnerable:
Any service that runs OpenSSL and uses the STARTTLS method
The TOR client
Android OS
Postgres database
The Salt Stack cluster execution manager

Here's the original vulnerability:

Here's the OpenSSL patch to the vulnerable portion of code:

Here's a google search for all mentions of heartbeat (but not heartbleed) under

This is a search of for heartbleed:

Here is a quick tool in Python to test for the vulnerability,

There's a great writeup at which goes into detail about the issue. To quote their website:
We have tested some of our own services from attacker's perspective. We attacked ourselves from outside, without leaving a trace. Without using any privileged information or credentials we were able steal from ourselves the secret keys used for our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication.
There is a metasploit script available for use:

You can type this OpenSSL command (tested with gnuwin32 openssl binary version, dated 1/14/2014). By the way, this version does not have the -tlsextdebug parameter, perhaps it was compiled by the gnuwin32 team without this option.

s_client -connect -debug -state

Once connected type B and you'll see on a vulnerable host and you won't be disconnected:

write to 0x801c17160 [0x801cbc003] (66 bytes => 66 (0x42))
0000 - 18 03 03 00 3d 8f 6f 3c-52 11 83 20 9c a2 c0 49   ....=.o 5 (0x5))
0000 - 18 03 03 00 3d    ....=
read from 0x801c17160 [0x801cb7008] (61 bytes => 61 (0x3D))
0000 - 05 4d f5 c0 db 96 d1 f5-c7 07 e5 17 1f 3b 48 34   .M...........;H4
0010 - 6e 11 9d ba 10 0c 3a 34-eb 7b a5 7c c4 b6 c0 c0   n.....:4.{.|....
0020 - b0 75 0e fe b7 fa 9e 04-e9 4e 4a 7d 51 d3 11 1f   .u.......NJ}Q...
0030 - e2 23 16 77 cb a6 e1 8e-77 84 2b f8 7f    .#.w....w.+..
read R BLOCK

You will get a heartbeat response that looks similar to this one.

On a patched host, you will see a response similar to below and you'll be disconnected:

Enter B

write to 0x801818160 [0x8019d5803] (101 bytes => 101 (0x65))
0000 - 18 03 03 00 60 9c a3 1e-fc 3b 3f 1f 0e 3a fe 4c   ....`....;?..:.L
0010 - a9 33 08 cc 3d 43 54 75-44 7d 2c 7b f3 47 b9 56   .3..=CTuD},{.G.V
0020 - 89 37 c1 43 1c 80 7b 87-66 ff cb 55 5f 8d 1a 95   .7.C..{.f..U_...
0030 - 1b 4c 65 14 21 a1 95 ac-7a 70 79 fc cc a0 cf 51   .Le.!...zpy....Q
0040 - 0f 7e c5 56 14 c8 37 c1-40 0b b8 cb 43 96 8a e6   .~.V..7.@...C...
0050 - 21 42 64 58 62 15 fb 51-82 e6 7f ef 21 1b 6f 87   !BdXb..Q....!.o.
0060 - b9 c2 04 c8 47    ....G

Here's my source for the OpenSSL s_client command above:

There's also these tools:

Web based:

Test results of Alex top 1000 websites:

Conspiracy Theory Mode
Perhaps NSA introduced this bug into OpenSSL to be able to crack users of The Onion Router?
/Conspiracy Theory Mode

Update: Here's another tool which is supposedly more accurate:

Update (10:37pm est 2014/04/09)
Packetstorm's files related to the vulnerability:

Sunday, March 23, 2014

Batch Files To Launch VMWare Workstation 7 and VMWare player Services And Close On Exit

I created batch files to start VMWare Workstation 7.0 and VMWare player. It starts the different VMWare services and stops them when VMWare is closed. This was tested on XP, Vista and later may be different.

Workstation batch file:
net start ufad-ws60
net start VMAuthdservice
net start vmnetdhcp
net start "vmware nat service"
net start vmusbarbservice

cd "\VMWare Workstation 7"

net stop ufad-ws60
net stop VMAuthdservice
net stop vmnetdhcp
net stop "vmware nat service"
net stop vmusbarbservice

Player batch file:
net start ufad-ws60
net start VMAuthdservice
net start vmnetdhcp
net start "vmware nat service"
net start vmusbarbservice

cd "\VMWare Workstation 7"

net stop ufad-ws60
net stop VMAuthdservice
net stop vmnetdhcp
net stop "vmware nat service"
net stop vmusbarbservice

Thursday, February 20, 2014

Install Chrome Web Store Plugins In Chromium Or SRWare Iron

If you use Iron, the version of Chrome that is privacy enhanced by default, you can install plugins from the official Chrome Webstore.

Proxy Switchy for example, uses this URL for browsing from the webstore:

But this is the actual installation URL for the CRX file:

Note the parameter after the id%3D in the url. Once you find the extension you'd like to install in the Webstore, simply replace the red text in the installation URL with the portion of the Webstore URL that looks like random letters and numbers such as the gobbledygook below, and paste the url into the iron or chromium "OneBar", then it should install the extension.


These ID's are thirty-two characters long and made up of lowercase letters.

There's a page on the Gentoo Linux Wiki that explains this as well.

Febuary 4, 2015 Update:
It appears that this method no longer works for some reason.

Wednesday, February 12, 2014

Android Anonymous VoIP Calls with TOR

There are good reasons to be able to make anonymous VoIP calls:

Report potential terrorists without you yourself being put on the homeland stupidity/FBI watchlist.

Report crimewatch tips with impunity and anonymity. What if a corrupt policeman is running the crime watch lines and keeps the caller id data?

These are just a few of the many reasons to be able to make anonymous phone calls.

To make anonymous sip calls from an android phone, your phone must be rooted so that orbot can transparently intercept the VoIP apps data and reroute the data through the TOR proxy network. How to root your mobile phone is outside the scope of this post. This was tested on a 4.0 ICS os.

Here's the list of steps:

Install orbot, the android version of TOR which is in the app market.

Install Smslisto (I have tested this with Smslisto, but the other finarea voip apps should work as well)

Setup orbot with the default options. On the settings menu, under transparent proxying, clock Select Apps, and then select Smslisto or your VoIP app then close it.

You can now start orbot by pressing down the robot for two seconds (this is also called a long-tap). Once it starts, you can then start Smslisto and login with your web username and password. Select "VoIP call" to make a data call.

Please note that I am not running a sip server at the moment, so I am not sure if the registration or RTP/UDP audio stream is actually routing through TOR, or it merely seems like it is (this could be proven by running csipdroid in this fashion and testing it against your own sip server and then, once proven, registering to I don't have the time to test this at the moment, so consider this post as conceptual. I do know, however, that the call had a delay of a few seconds, whereas a normal data call has very little delay at all on a 4G LTE connection.

Also another caveat is that you can't anonymously put money into a VoIP account, as no internet sip provider that I know of allows bitcoin deposits. Perhaps an entrepreneur out there could start a bitcoin-accepting VoIP service, but considering all of the VoIP telephone fraud that goes on, I'm sure the FBI would be knocking on your door soon. I strongly suggest having a hidden .onion server for stronger anonymity and then using sips/srtp/zrtp for registering to the trunking service. Without srtp, however, all call data (the phone number called and the call audio) would NOT be encrypted from the TOR exit node to the sip trunk. Also you would be using the same exit node for the duration of the call, otherwise the calls udp/TCP session would end and the call would drop.

A better idea is to use i2p for its superior bulk data/UDP stream support, but i2p is a totally separate world from TOR (for example it doesn't have exit nodes per se).

I support the NSA's data collection policies and believe it to be keeping us safer. I am OK with them recording all phone calls as well. As Bill Gates recently stated, its important to know just what they are recording, for how long, who can access it, etc.... There should be oversight, otherwise what prevents the NSA from collecting pin numbers, account numbers and some rogue agent infiltrating bank accounts? I surmise that the NSA has been recording VoIP calls already, even domestic calls. I'm guessing that all efax services that traverse the public internet are being stored as well.

Friday, January 17, 2014

Schemer - Another Google service shutting down

Dear Schemers,

The time has come for
Schemer to power down.

Schemer launched in beta
over a year ago to help
inspire and motivate people
to do more awesome stuff,
and though the app is
shutting down, the
adventures will continue.
You can use the "Explore"
section on Google Maps for
Android and iOS to find
interesting things to do
around you, or Field Trip to
uncover hidden or unique
things in your city, among

All your schemes are
available for download until
February 7, 2014, after
which all data will be
permanently and irrevocably
deleted. You can find the
simple steps to download
your data here.

In the meantime, stay
curious, ambitious, daring,
and above all, stay

Thank you for all your
support on this journey!

- The Schemer Team