Tuesday, February 26, 2008

Meeting: 26 Feb 2008 (Group)

CAPTCHA customizer
Alan update on CAPTCHA customizer tools V3.0. The following customizer modules has been included :


- CAPTCHA Display Size
- CAPTCHA Customizer Fonts Extrusion
- CAPTCHA Customizer Fonts Choosing Design
- CAPTCHA Customizer Charactors Choosing
- CAPTCHA Customizer character scaling
- CAPTCHA Customizer Angles Rotation
- CAPTCHA Position Text Position

Discussion:
Team has discussed on the GUI of the CAPTCHA Customizer Tools:
- Customizer tools layout frame should keep consistent for every module.
- Preview features should be included in every module.
- Fix value field should be hided to prevent confusion from users.

Above suggestion will be updated again by ALAN in newer CAPTCHA Customizer Tools version.

CAPTCHA Answer Validation
Team has decided to implement the CATPCHA answer validation system by using J2EE Form-based Authentication service. It act as a gateway for users authentication and authorization issues.


Team will need to implement the service to meet the needs of :

- Running in both normal pc web and J2ME application.
- Only 1 set of server code needed in order to validate the answer from normal pc web and J2ME users.
- Able be the only gateway for end users to access other web application resource.

Lexis and Sebastian will start the implementation.


Logging
Team dicussed about the logger design :

- Log system will log the following details of the visitors:
* IP address
* MAC address (Prevent NAT)
* Access date/time
* Access counter
* CAPTCHA challenge
* CAPTCHA answer

- If a visitor request the CAPTCHA challenge more than 5 times within 24 hours, the system will block the visitors from requesting a new CAPTCHA again for 12 hours. This can prevent DoS attack by stoping an attacker keep requesting for new CAPTCHA to jam the server traffic.

CAPTCHA design for session 2
Team has decided to program a simple gaming style CAPTCHA to prevent DoS attack. The following picture illustrate the CAPTCHA ideal.





- It will be 4 x 4 , 16 grid game.
- User will use either keyboard/Mouse to move object.
- User will need to move the yellow object to the pink object in order to complete the challenge.
- There will be obstacles to prevent user from having a straight moving path for the object.

Plan and Test Case

Discussion:
Test Plan schedule and Test Case format has been designed by Lexis and Sebastian. Hence team will need to start do testing for the application developed base on RUP phase timeline.


Conclusion:
Sebastian and Adrian are assigned to do all the testing for the application

Attendance :
Sebastian Seah
Lexis Ow
Alan Chee
Adrian


Recorded by Sebastian

Updates: Captcha Customizer v1 - Display

The Captcha Customizer Display customizing design is created. Users can change the values in the textfield to change the image size of the output captcha image.

Monday, February 25, 2008

Technical: MDlet HTTPS

Brief introduction on the needs of a HTTPS connection. To ensure a secure channel between the server and client. The server and client both derive a session key from this secret value, which is used to encrypt all subsequent traffic sent between them.
Actually it's very simple to do HTTPS connections.

MISLEADING SOLUTION:
Previously, instead of the ContentConnection Class, we changed to the HttpsConnection Class:
HttpsConnection hc = (HttpsConnection)Connector.open(url);

We got errors like:


SOLUTION:
Based on the article here, we realised that it's the issue of "Unknown Certificates". This is because the certificates are created by us, thus it is not represented in the keystore of the J2ME Wireless Toolkit.

The J2ME Wireless Toolkit contains a tool called MEKeyTool, purpose is to manage the public keys of certificate authorities. It is found in the "installation_dir/bin".

To list keys in the default keystore:
mekeytool -list

Now, we gotta import the keystore used in tomcat into the Wireless Toolkit:
mekeytool -import -alias tomcat -keystore "z:\.keystore" -storepass changeit

Now we do a -list, you can observe it is in our keystore. Pointers to take note, when creating the certificate in tomcat, you MUST key in the "url_used" when they prompt you for FIRST NAME. I used the IP 10.211.55.2, so FIRST NAME is 10.211.55.2. Or else you will get the "Certificate does not contain the correct site name" error.

Since we now know that it's the configuration portion that causes us the problem, not the problem with the code. All we have to do is construct a HTTPS Connection String. So instead of this:
String url = "http://localhost:8080/"
ContentConnection connection = (ContentConnection) Connector.open(url);

we change it to this:
String url = "https://localhost:8443/"
ContentConnection connection = (ContentConnection) Connector.open(url);

WA LA!!

Wednesday, February 20, 2008

Technical: MySQL commands

Feel free to add SQL commands here. Easy reference record for us.


Set root password: mysqladmin -u root password "your-chosen-passwd"

Login as root: mysql -u root -p

Show databases: show databases;

Use database: use "database_name";

Create database: create database "database_name";

Remove database: drop database "database_name";


Create table: create table cache (sessionid VARCHAR(32) NOT NULL PRIMARY KEY, challange VARCHAR(32));



Tuesday, February 19, 2008

Updates: Captcha Customizer v1 - Font Extrusion

The Captcha Customizer Font Extrusion design is created. User can change the values in the textfields and the resulting changes will be shown in the preview graph.

Monday, February 18, 2008

Updates: Captcha Customizer v1 - Fonts

The Captcha Customizer Fonts choosing design is created. User can choose the desire fonts from the drop down list and the style of the font will be shown in the preview panel.

The list of fonts is drawn from the system's fonts folder.



The "add" and "delete" function is in progress.

Sunday, February 17, 2008

Technical: Tomcat wouldnt start under windows, Java1.6

Tomcat5.5/6 just wouldn't start on windows. We gotta use parallels to test J2ME over Mac's Tomcat.

The messages showing in the jakarta_service_yyyymmdd.log file were:

[174 javajni.c] [error] The specified module could not be found.
[947 prunsrv.c] [error] Failed creating java C:\Java\bin\client\jvm.dll
[1202 prunsrv.c] [error] ServiceStart returned 1

To solve this, copy msvcr71.dll (found in $JAVA_HOME\bin) to the $WINDOWS/system32 directory.

Extracted from here.