<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>arzumy md - short notes on small discoveries</title>
 <link href="http://ar.zu.my/atom.xml" rel="self"/>
 <link href="http://ar.zu.my"/>
 <updated>2021-09-06T01:56:10+00:00</updated>
 <id>http://ar.zu.my</id>
 <author>
   <name>Arzumy MD</name>
   <email>hello@ar.zu.my</email>
 </author>

 
 <entry>
   <title>Nasihat Pelaburan Untuk Aku Yang Dulu</title>
   <link href="http://ar.zu.my/nasihat-pelaburan-untuk-aku-yang-dulu"/>
   <updated>2021-09-05T00:00:00+00:00</updated>
   <id>http://ar.zu.my/nasihat-pelaburan-untuk-aku-yang-dulu</id>
   <content type="html">&lt;p&gt;&lt;small&gt;05 September 2021&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;Sebelum kita mula, penting untuk aku buat &lt;em&gt;penafian&lt;/em&gt; dulu. Nasihat ini adalah untuk aku yang dulu, aku yang berumur 20 tahun berdasarkan situasi zaman sekarang. Ini bukan nasihat pelaburan untuk orang lain. Aku tak bertanggungjawab atas segala kerugian kalau kau ikut bulat-bulat nasihat ni. Dan kau kena ingat, matlamat kewangan kita tak sama, status kewangan kita tak sama, toleransi risiko kita tak sama.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Penafian #2&lt;/em&gt;, kebanyakan pautan dalam artikel ni ada “referral links”. Kalau kau daftar mana-mana servis dari “referral links” kita sama-sama untung.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Penafian #3&lt;/em&gt;, aku ada melabur atau mungkin akan melabur dalam aset-aset yang dinyatakan dalam artikel ni.&lt;/p&gt;

&lt;p&gt;Okay, kita boleh mulakan.&lt;/p&gt;

&lt;p&gt;Masa aku dapat kerja yang pertama, gaji aku adalah RM 1,200. Memang masa tu rasa macam banyak, sebab kawan-kawan masih belajar. Tapi aku dah ada pendapatan sendiri. Sayangnya aku tak pernah ambil tahu tentang pengurusan kewangan, jadi semua yang aku dapat habis aku belanja.&lt;/p&gt;

&lt;p&gt;Sebagai anak Bumiputra, semua orang cakap duit simpan dalam ASB. Tapi kalau aku memang jenis yang tak pernah menyimpan duit, bagi aku ini bukanlah nasihat yang bernas. Sebab, dividen ASB setahun sekali. Lama sangat nak tunggu baru nampak hasil. Budak-budak darah muda mana ada masa nak tunggu setahun.&lt;/p&gt;

&lt;p&gt;Jadi nasihat aku pada aku, lupakan dulu ASB. Kita cari pelaburan yang kita boleh nampak hasilnya dalam masa terdekat. Bila dah nampak hasil, barulah kita bersemangat nak tambah pelaburan.&lt;/p&gt;

&lt;h2 id=&quot;strategi-pelaburan&quot;&gt;Strategi Pelaburan&lt;/h2&gt;

&lt;p&gt;Mula-mula kita akan ambil 10% dari gaji untuk dilaburkan. RM 120 sebulan selama satu tahun, bila masuk tahun kedua, kita tambah lagi 5% dari jumlah pelaburan. RM 120 + 5% = RM 126. Tahun ketiga, tambah lagi 5% jadi RM 126 + 5% = RM 132.30. Jadi setiap tahun kita tambah 5%.&lt;/p&gt;

&lt;p&gt;Kalau kita konsisten, selepas 20 tahun, dengan purata keuntungan 5% setiap tahun, kita akan ada dalam RM 75,000. Tak nampak banyak. Tapi itu bukan matlamat kita. Sekarang yang paling penting adalah untuk kita bina tabiat baru. Untuk bina tabiat baru, kita kena bagi mudah.&lt;/p&gt;

&lt;p&gt;Gaji kita akan naik setiap tahun. Jumlah pelaburan kita pun akan naik. Gaji aku naik jadi RM 2,400 dalam masa kurang dari 2 tahun. Jadi aku boleh laburkan RM 240 sebulan. Kita dah boleh dapat RM 125,000 selepas 18 tahun. Terus dekat dua kali ganda jumlah pelaburan kita.&lt;/p&gt;

&lt;p&gt;Jadi kalau bukan ASB, dekat mana patut aku buat pelaburan? Kita boleh mula dengan “roboadvisor” dulu.&lt;/p&gt;

&lt;h2 id=&quot;stashaway&quot;&gt;Stashaway&lt;/h2&gt;

&lt;p&gt;Ada banyak “roboadvisor” sekarang, aku cadangkan Stashaway (boleh daftar di &lt;a href=&quot;https://www.stashaway.my/referrals/mdan2vk&quot;&gt;https://www.stashaway.my/referrals/mdan2vk&lt;/a&gt;). Kenapa Stashaway? Kenapa bukan yang lain? Tak ada sebab tertentu pun. Aku sekarang pakai Stashaway, itu saja.&lt;/p&gt;

&lt;p&gt;Bila kita melabur dalam Stashaway, senang kita nak tengok kadar keuntungan (atau kerugian). Ingat, matlamat kita tadi ada untuk bina tabiat melabur. Mungkin keuntungan dia nampak sedikit, tapi itu bukan masalah. Asalkan kita ada nampak hasil dari pelaburan kita. Barulah kita bersemangat nak melabur secara konsisten.&lt;/p&gt;

&lt;p&gt;Kita akan gunakan fungsi “recurring deposit” untuk memudahkan pelaburan kita. Kita tetapkan matlamat kita untuk dapat RM 1,000 dalam akaun Stashaway.&lt;/p&gt;

&lt;h2 id=&quot;tabung-kecemasan&quot;&gt;Tabung Kecemasan&lt;/h2&gt;

&lt;p&gt;Sekarang kita dah ada RM 1,000, kita boleh mulakan simpanan untuk tabung kecemasan. Tabung kecemasan ini penting sebab kita tak tahu bila kita perlukan duit. Buat masa ini kita tetapkan jumlah tabung kecemasan adalah RM 1,200. Sama dengan gaji sebulan.&lt;/p&gt;

&lt;p&gt;Untuk tabung kecemasan kita akan simpan dalam ASB. Sekarang dah senang, boleh buat di &lt;a href=&quot;https://www.myasnb.com.my/&quot;&gt;https://www.myasnb.com.my/&lt;/a&gt;. Kalau perlukan duit pun kita boleh keluarkan melalui myASNB.&lt;/p&gt;

&lt;p&gt;Jadi buat masa sekarang, kita hentikan “recurring deposit” ke Stashaway dan simpan bulanan di ASB sampai cukup RM 1,200. Bila gaji dah naik ke RM 2,400, kita tambah lagi pelaburan ASB sampai RM 2,400.&lt;/p&gt;

&lt;p&gt;Dan yang sebaiknya, kita ada 3 bulan gaji dalam ASB.&lt;/p&gt;

&lt;h2 id=&quot;duit-kecemasan&quot;&gt;Duit Kecemasan&lt;/h2&gt;

&lt;p&gt;Kalau boleh, bila ada kecemasan, kita tak perlu keluarkan dari tabung kecemasan. Atau mungkin kecemasan berlaku di hujung minggu, kita tak dapat nak keluarkan dari ASB. Masa ini aku harap gaji kita dah cukup untuk memohon kad kredit. Kita boleh gunakan kad kredit jika berlaku kecemasan.&lt;/p&gt;

&lt;p&gt;Tapi kalau kita perlukan wang tunai untuk kecemasan, jangan buat “cash advance”. Kita boleh mohon kad debit BigPay, topup BigPay pakai kad kredit dan keluarkan tunai dari BigPay. (Boleh daftar di &lt;a href=&quot;http://bigpay.link/referrals?referralcode=WBYXMGJ9NA&quot;&gt;http://bigpay.link/referrals?referralcode=WBYXMGJ9NA&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;Bila dah boleh keluarkan tunai dari ASB, kita terus bayar balik kad kredit. Jangan tunggu.&lt;/p&gt;

&lt;h2 id=&quot;dollar-cost-averaging&quot;&gt;Dollar Cost Averaging&lt;/h2&gt;

&lt;p&gt;Bila dah cukup tabung kecemasan, kita boleh mula mempelbagaikan portfolio pelaburan kita. Untuk ini kita kena faham konsep Dollar-Cost Averaging (“DCA”). Senang cerita dengan DCA kita melabur pada masa yang tetap tanpa mengira keadaan pasaran atau harga. Ini dapat mengurang impak ke atas pelaburan kita. Dan juga dapat memastikan tabiat melabur kita berterusan.&lt;/p&gt;

&lt;p&gt;Pendek kata, jangan menggatal nak “time the market”, melabur secara konsisten untuk jangka panjang.&lt;/p&gt;

&lt;h2 id=&quot;luno&quot;&gt;Luno&lt;/h2&gt;

&lt;p&gt;Kita mulakan dengan kripto. (boleh daftar di &lt;a href=&quot;https://www.luno.com/invite/DXJHPF&quot;&gt;https://www.luno.com/invite/DXJHPF&lt;/a&gt;). Kita boleh ambil 10% dari jumlah pelaburan bulanan kita untuk kripto. Tak kisahlah orang percaya atau tidak, yang penting memang ada duit dalam kripto.&lt;/p&gt;

&lt;p&gt;Kita guna DCA untuk labur secara konsisten setiap minggu kalau boleh, kalau tak boleh kita buat setiap bulan. Laburkan dalam BTC adalah wajib. Selebihnya boleh labur dalam ETH dan ADA. Tak perlu banyak-banyak, untuk jangka masa panjang kita “hodl” tiga kripto saja.&lt;/p&gt;

&lt;h2 id=&quot;hellogold&quot;&gt;HelloGold&lt;/h2&gt;

&lt;p&gt;Kemudian kita boleh tambah komoditi emas dalam portfolio. Paling mudah kita pakai HelloGold (boleh daftar di &lt;a href=&quot;https://referral.hellogold.com/?ref=ARZU95BT&quot;&gt;https://referral.hellogold.com/?ref=ARZU95BT&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;Emas tak payah nak cerita banyak, dari dulu lagi orang dah menyimpan emas. Untung atau rugi ikut masa bila kita beli dan jual. Jadi teruskan dengan DCA. Boleh simpan dalam 5% atau 10% sebulan.&lt;/p&gt;

&lt;h2 id=&quot;moomoo&quot;&gt;moomoo&lt;/h2&gt;

&lt;p&gt;Ini cerita dia panjang sikit. moomoo memudahkan kita untuk melabur dalam pasaran US. Aku tak galakkan beli saham syarikat US dalam moomoo sebab mungkin duit kita tak cukup nak beli satu unit saham. Fokus moomoo adalah untuk melabur dalam Index Fund atau ETF. Dengan Indeks Fund kita tak perlu nak pilih mana-mana syarikat, sebaliknya kita dapat melabur dalam semua syarikat S&amp;amp;P 500 di US atau sebahagian kategori syarikat yang tersenarai dalam ETF.&lt;/p&gt;

&lt;p&gt;Kita boleh mula dengan &lt;a href=&quot;https://seekingalpha.com/symbol/VOO&quot;&gt;VOO&lt;/a&gt; untuk semua syarikat S&amp;amp;P 500, dan &lt;a href=&quot;https://seekingalpha.com/symbol/ARKK&quot;&gt;ARKK&lt;/a&gt; untuk syarikat dalam kategori teknologi.&lt;/p&gt;

&lt;p&gt;Cuma untuk mendaftar moomoo ni leceh sikit. Kita kena ada bank akaun di Singapura (boleh daftar di &lt;a href=&quot;https://j.moomoo.com/007mcM&quot;&gt;https://j.moomoo.com/007mcM&lt;/a&gt;, moomoo selalu hadiahkan saham percuma, sekarang boleh dapat saham Apple). Tak susah cuma banyak kerja. Paling senang kita pakai CIMB FastSaver di Singapura. Pendaftaran secara online. Hanya perlu akaun CIMB di Malaysia. Untuk penghantaran duit ke akaun Singapura, kita boleh pakai Wise untuk mengurangkan yuran pemindahan (boleh daftar di &lt;a href=&quot;https://wise.com/invite/u/arzumyb&quot;&gt;https://wise.com/invite/u/arzumyb&lt;/a&gt;)&lt;/p&gt;

&lt;h2 id=&quot;etoro&quot;&gt;eToro&lt;/h2&gt;

&lt;p&gt;Sekarang kita mungkin dah ada pengalaman pelaburan. Kita boleh cuba untuk membeli saham syarikat US yang mungkin akan memberi keuntungan lebih. Aku hanya melabur dalam syarikat yang aku kenal dan aku guna servis mereka. Tapi kebanyakan saham mereka mahal. Jadi kita akan pakai eToro (boleh daftar di &lt;a href=&quot;ttps://etoro.tw/3BJbwpF&quot;&gt;https://etoro.tw/3BJbwpF&lt;/a&gt;) sebab dengan eToro kita boleh membeli pecahan saham.&lt;/p&gt;

&lt;p&gt;Contoh, saham Apple sekarang adalah RM 600, tapi kita hanya mampu melaburkan RM 200. Dengan eToro kita boleh beli 1/3 saham Apple pada harga RM 200. Dan kita akan beroleh keuntungan kalau harga saham Apple meningkat.&lt;/p&gt;

&lt;h2 id=&quot;penutup&quot;&gt;Penutup&lt;/h2&gt;

&lt;p&gt;Cukup sampai sini dulu. Kita kena ingat, tak kisahlah mana-mana aplikasi yang kita pakai, paling utama adalah untuk kita membina tabiat melabur. Kedua, fikir jangka masa panjang, emosi kita jangan terkesan dengan turun naik pasaran saham. 20 tahun rasa macam lama, tapi bila kita dah berumur 40 tahun nanti kita rasa sekejap saja dah 20 tahun.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>Throw your resume away, kid.</title>
   <link href="http://ar.zu.my/throw-your-resume-away-kid"/>
   <updated>2016-01-28T00:00:00+00:00</updated>
   <id>http://ar.zu.my/throw-your-resume-away-kid</id>
   <content type="html">&lt;p&gt;&lt;small&gt;28 January 2016&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;Okay kid, the fastest way to get an internship with KFit Product and Engineering team is to build something. Forget whatever they teach you about resume. Show us what you’ve built over the weekend. Remember that one time you did a neat hack and almost got into trouble? Tell us that story.&lt;/p&gt;

&lt;p&gt;I heard you do freelance gigs? Then show it to me. Remember that one time where you sneaked into that Intro to Programming test? Just so you can help your struggling non-techie friends? Or the semester where they banned you from the hostel? Because they don’t know how to stop you from running freely on their network?&lt;/p&gt;

&lt;p&gt;I want to hear all about it. Tell it with pride, kid. And throw your resume away.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://careers.kfit.com/&quot;&gt;http://careers.kfit.com/&lt;/a&gt;&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>Lessons Learned From My First Week In Silicon Valley</title>
   <link href="http://ar.zu.my/lessons-learned-from-silicon-valley"/>
   <updated>2014-11-08T00:00:00+00:00</updated>
   <id>http://ar.zu.my/lessons-learned-from-silicon-valley</id>
   <content type="html">&lt;p&gt;&lt;small&gt;08 November 2014&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;One thing that’s obvious Silicon Valley is how easy it is to network. “Business is all about who you know” - right. It is so easy to get a meeting with almost anyone here. It just takes one cold request to become friends with strangers. People willing to spend their time meeting new people. They are ready to help. Just don’t be an asshole.&lt;/p&gt;

&lt;p&gt;Dave McClure said it best - “For an ecosystem to work, we need enough people to believe in it.” Everywhere you go you’ll overhear conversations related to the ecosystem. People here talking about companies as long term investment. The fact that everyone willing to help each other out with no hidden agenda proved this. It’s like when a company focuses on employee personal growth, the company will grow. When you help someone in the ecosystem to grow, the ecosystem will grow. When the ecosystem grows stronger, everybody earns their reward.&lt;/p&gt;

&lt;p&gt;So here’s my call to Malaysians. We just need to do two things for the ecosystem to grow.&lt;/p&gt;

&lt;p&gt;First, we always help each other out. Don’t deny a request for help. Make yourself available to others. It doesn’t matter if you already made it. Or you’ve failed many times and haven’t cracked it yet. Or if you just a starting up. Heck, if you have to, give advice to your competitor. Spread the wisdom.&lt;/p&gt;

&lt;p&gt;Secondly, we always believe in the ecosystem. Regardless of what people say about Malaysia’s ecosystem. No matter what restriction we might have. We will keep building great companies. We’ll keep growing great talents. Because we know entrepreneurs are a unique breed. We thrive in the restrictive environment.&lt;/p&gt;

&lt;p&gt;We’ve seen the success stories, we are seeing money flowing in. It is working. Let’s keep hacking at it!&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>[SOLVED] SHOW databases; ERROR 1018 (HY000)- Can't read dir of '.' (errno- 13)</title>
   <link href="http://ar.zu.my/solved-show-databases-error-1018-hy000-can-t-read-dir-of-errno-13"/>
   <updated>2013-10-16T00:00:00+00:00</updated>
   <id>http://ar.zu.my/solved-show-databases-error-1018-hy000-can-t-read-dir-of-errno-13</id>
   <content type="html">&lt;p&gt;&lt;small&gt;16 October 2013&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;We recently migrated our database to new server. The server packed with SSD, which is sweet :) We used &lt;a href=&quot;http://www.percona.com/software/percona-xtrabackup&quot;&gt;Percona XtraBackup&lt;/a&gt; to take a live backup of the database, copied it over to new server and sync back to current database using master-slave replication.&lt;/p&gt;

&lt;p&gt;To take advantage of SSD, we’ve configured MySQL to store data in SSD instead of default location. We’ve edited &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/etc/mysql/my.cnf&lt;/code&gt; with this value &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;datadir = /example_ssd_partition/mysql/data&lt;/code&gt;. Everything went fine until I ran &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SHOW databases&lt;/code&gt; command. I got this error:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-sql&quot; data-lang=&quot;sql&quot;&gt;  &lt;span class=&quot;k&quot;&gt;SHOW&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;databases&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;ERROR&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;1018&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;HY000&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;):&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;Can&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'t read dir of '&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;' (errno: 13)&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;I searched the error message and it yielded bunch of similiar results. The common theme is permission error. &lt;a href=&quot;http://stackoverflow.com/questions/11066411/mysql-error-error-1018-hy000-cant-read-dir-of-errno-13&quot;&gt;Here’s one of many results telling it’s a permission problem and I just need to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chown&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chmod&lt;/code&gt; the directory&lt;/a&gt;. I did that and triple confirmed everything belongs to mysql user. But I still can’t &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SHOW databases&lt;/code&gt;. In fact, everything that require a query to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;information_schema&lt;/code&gt; will raise &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Can't read dir of '.'&lt;/code&gt; error.&lt;/p&gt;

&lt;p&gt;Here’s the gotcha: Ubuntu comes with &lt;a href=&quot;https://wiki.ubuntu.com/AppArmor&quot;&gt;AppArmor&lt;/a&gt;. AppArmor’s security model is to bind access control attributes to programs rather than to users. In my &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/etc/apparmor.d/usr.sbin.mysqld&lt;/code&gt; file I’ve made these changes:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  ...
  &lt;span class=&quot;c&quot;&gt;# Disable these two lines&lt;/span&gt;
  /var/lib/mysql/ r,
  /var/lib/mysql/&lt;span class=&quot;k&quot;&gt;**&lt;/span&gt; rwk,

  &lt;span class=&quot;c&quot;&gt;# Added these two lines&lt;/span&gt;
  /example_ssd_partition/mysql/data r,
  /example_ssd_partition/mysql/data/&lt;span class=&quot;k&quot;&gt;**&lt;/span&gt; rwk,
  ...&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;While it seems correct, there’s actually a typo in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/example_ssd_partition/mysql/data r,&lt;/code&gt;, it should be &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/example_ssd_partition/mysql/data/ r,&lt;/code&gt; instead. I missed out a forward slash after /example_ssd_partition/mysql/data. Because of that, while everything in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/example_ssd_partition/mysql/data/&lt;/code&gt; owned by mysql user, the program itself has no access to the content of the directory. I’ve changed it to:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  ...
  /example_ssd_partition/mysql/data/ r,
  /example_ssd_partition/mysql/data/&lt;span class=&quot;k&quot;&gt;**&lt;/span&gt; rwk,
  ...&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;A quick AppArmor restart and now I can view all databases again!&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Test ActionMailer With RSpec And shoulda-matchers</title>
   <link href="http://ar.zu.my/how-to-test-action-mailer-with-rspec-and-shoulda-matchers"/>
   <updated>2013-09-27T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-test-action-mailer-with-rspec-and-shoulda-matchers</id>
   <content type="html">&lt;p&gt;&lt;small&gt;27 September 2013&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;Today I upgraded &lt;a href=&quot;https://github.com/thoughtbot/shoulda-matchers&quot;&gt;shoulda-matchers&lt;/a&gt; gem from version 1.4.2 to 2.4.0. shoulda-matchers is a bunch of one-liners to test Rails functionality and compatible with RSpec. My spec suite broken after the upgrade. This post is a walkthrough about the changes I had to make to fix my spec suite.&lt;/p&gt;

&lt;p&gt;In version 1.4.2, I added these lines in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;spec/spec_helper.rb&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'shoulda-matchers'&lt;/span&gt;
  &lt;span class=&quot;kp&quot;&gt;include&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Shoulda&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Matchers&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;ActionMailer&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;After upgrade, I got this error:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;n&quot;&gt;uninitialized&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;constant&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Shoulda&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Matchers&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;ActionMailer&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;NameError&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;A quick peek at the source shows the error is right (because your know, error messages could lie to you), ActionMailer matchers not included in shoulda-matchers anymore. I can have the same functionalities in Mail itself. Read more from &lt;a href=&quot;http://rdoc.info/github/mikel/mail#Using_Mail_with_Testing_or_Spec_ing_Libraries&quot;&gt;Using Mail with Testing or Spec’ing Libraries&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Now, I just need to replace &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include Shoulda::Matchers::ActionMailer&lt;/code&gt; with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include Mail::Matchers&lt;/code&gt;. Because the matchers directly copied from shoulda-matchers, no further change needed.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>Workaround For Long Running Local Task In Capistrano Deployment</title>
   <link href="http://ar.zu.my/workaround-for-long-running-local-task-in-capistrano-deployment"/>
   <updated>2013-05-10T00:00:00+00:00</updated>
   <id>http://ar.zu.my/workaround-for-long-running-local-task-in-capistrano-deployment</id>
   <content type="html">&lt;p&gt;&lt;small&gt;10 May 2013&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;All our assets in &lt;a href=&quot;http://says.com&quot;&gt;SAYS.com&lt;/a&gt; are hosted in &lt;a href=&quot;http://aws.amazon.com/s3/&quot;&gt;Amazon S3&lt;/a&gt; and served by &lt;a href=&quot;http://aws.amazon.com/cloudfront/&quot;&gt;Amazon CloudFront&lt;/a&gt;. The outbound traffic for these files are too high, we ended up hitting our servers’ bandwidth limit sooner that expected. By off loading the files to Amazon, bandwidth no longer a candidate to performance bottleneck.&lt;/p&gt;

&lt;p&gt;Our &lt;a href=&quot;http://capistranorb.com/&quot;&gt;Capistrano&lt;/a&gt; deployment now includes new tasks: compiles assets locally, syncs to S3 bucket and uploads &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;manifest.yml&lt;/code&gt; to all our servers. It works fine most of times, except once in while we’ll get random &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;IOError&lt;/code&gt; after assets compiling. Then that ‘once in a while’ error becomes ‘often’, then it becomes ‘most of the time’. Something’s wrong, definitely.&lt;/p&gt;

&lt;p&gt;We later determined that the error was caused by SSH connections to the servers dropped due to long idle time while waiting for local assets precompile. We toyed around SSH configurations i.e. increase idle time, time to live etc. But those are just guess works because we can’t tell for sure how long assets precompile will take. Of course for now we can average out the compiling time, but in the future it might take longer.&lt;/p&gt;

&lt;p&gt;What we are doing now is to kill those connections after assets precompile, and let capistrano creates new connections. We just include this line after local assets precompile:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;	&lt;span class=&quot;n&quot;&gt;teardown_connections_to&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;sessions&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;keys&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Works like charm! One might argue that the deployment will be a bit slower because we need to reestablish SSH connection, we are completely fine with it. The benefit is better than the downside.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Show Highchart's Tooltip On Load</title>
   <link href="http://ar.zu.my/how-to-show-highchart-tooltip-on-load"/>
   <updated>2013-01-08T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-show-highchart-tooltip-on-load</id>
   <content type="html">&lt;p&gt;&lt;small&gt;08 January 2013&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;In &lt;a href=&quot;http://election.gv.my&quot;&gt;Malaysia Twitter Political Index&lt;/a&gt;, I didn’t show legend for the chart because it is ugly. And I don’t feel like I want to make an effort to style it. Plus, when you hover on the chart, it will show tooltip with details. So I figured, there’s no need for legend.&lt;/p&gt;

&lt;p&gt;But, not everyone will hover. They will get confused. I looked at &lt;a href=&quot;https://election.twitter.com/&quot;&gt;Twitter Political Index&lt;/a&gt;, no legend too, instead it just shows the tooltip, I decided to do the same.&lt;/p&gt;

&lt;p&gt;It’s not hard to figure out, all I had to do was google for it :P I found my answer in this &lt;a href=&quot;http://ftp.highslide.com/forum/viewtopic.php?f=12&amp;amp;t=18889&quot;&gt;forum&lt;/a&gt; (or you can &lt;a href=&quot;http://jsfiddle.net/L2TFd/28/&quot;&gt;fiddle it here&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;I just need to loop the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;series&lt;/code&gt; to get to the last point and refresh tooltip with the points.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-javascript&quot; data-lang=&quot;javascript&quot;&gt;&lt;span class=&quot;nx&quot;&gt;chart&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;Highcharts&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;Chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;({&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;credits&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;xAxis&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;yAxis&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;tooltip&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;legend&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;plotOptions&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{...},&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;series&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:{...}},&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;function&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;){&lt;/span&gt;
    &lt;span class=&quot;c1&quot;&gt;// Last point in graph...&lt;/span&gt;
    &lt;span class=&quot;kd&quot;&gt;var&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;points&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[];&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kd&quot;&gt;var&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;series&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;length&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;++&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
      &lt;span class=&quot;nx&quot;&gt;points&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;push&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;series&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;].&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;points&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;series&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;].&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;points&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;length&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]);&lt;/span&gt;
      &lt;span class=&quot;nx&quot;&gt;chart&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;tooltip&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;refresh&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;points&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;);&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;p&quot;&gt;});&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Really Customize The "Deprecated" Facebook's sharer.php</title>
   <link href="http://ar.zu.my/how-to-really-customize-the-deprecated-facebook-sharer-dot-php"/>
   <updated>2013-01-05T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-really-customize-the-deprecated-facebook-sharer-dot-php</id>
   <content type="html">&lt;p&gt;&lt;small&gt;05 January 2013&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://developers.facebook.com/blog/post/2009/10/26/extending-facebook-share/&quot;&gt;Facebook Share button&lt;/a&gt;, or commonly known as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sharer.php&lt;/code&gt; is the easiest way to share link on Facebook. It was initially deprecated in favour of the &lt;a href=&quot;https://developers.facebook.com/docs/reference/plugins/like/&quot;&gt;Like button&lt;/a&gt; while still keeping the documentation up for reference on &lt;a href=&quot;https://developers.facebook.com/docs/share/&quot;&gt;https://developers.facebook.com/docs/share/&lt;/a&gt;. Now it is fully replaced by &lt;a href=&quot;https://developers.facebook.com/docs/reference/dialogs/feed/&quot;&gt;Feed Dialog&lt;/a&gt;. Facebook Share button no longer officially supported by Facebook. But it still functional and used by many all over the Internet.&lt;/p&gt;

&lt;p&gt;It is easy to use. You don’t need an App ID, and you don’t need to include any Facebook dependencies. But because it is not supported and documented, you are bound to be surprised by any changes made by Facebook.&lt;/p&gt;

&lt;p&gt;In my case, I want to include &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sharer.php&lt;/code&gt; on &lt;a href=&quot;http://bit.ly/myelection&quot;&gt;Malaysia Twitter Political Index&lt;/a&gt;. I want the user to be able to share it on Facebook, and I want to customize the title on daily basis. Previously you can just do this:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;http://www.facebook.com/sharer.php?u=http://bit.ly/myelection&amp;amp;t=Here's my customized title
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;But when I did that, I noticed Facebook no longer honour &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;t&lt;/code&gt; parameter.&lt;/p&gt;

&lt;p&gt;I could dynamically generate customized &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;og&lt;/code&gt; tag, but due to Facebook caching mechanism there’s almost no point of doing that. A quick search led me to ‘&lt;a href=&quot;http://www.therykers.net/?p=37&quot;&gt;How to pass custom parameters to a Facebook-”Share”-button&lt;/a&gt;’. That page listed down 4 undocumented params that can be used to customize the share page. Here’s my new link:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;http://www.facebook.com/sharer.php?s=100
&amp;amp;p[url]=http://bit.ly/myelection
&amp;amp;p[images][0]=http://election.gv.my/assets/vote.png
&amp;amp;p[title]=My customized title
&amp;amp;p[summary]=My customized summary
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;I assume you can add more image with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;p[images][1]&lt;/code&gt; to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;p[images][n]&lt;/code&gt;. I didn’t test it out.&lt;/p&gt;

&lt;p&gt;Let’s test it out on this blog.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;# With t paramater only
&amp;lt;a href=&quot;http://www.facebook.com/sharer.php?u=http://ar.zu.my&amp;amp;t=Rock on Arzumy!&quot;&amp;gt;Share&amp;lt;/a&amp;gt;
  
# With everything
&amp;lt;a href=&quot;http://www.facebook.com/sharer.php?s=100
&amp;amp;p[url]=http://ar.zu.my
&amp;amp;p[images][0]=http://www.gravatar.com/avatar/2f8ec4a9ad7a39534f764d749e001046.png
&amp;amp;p[title]=Rock on Arzumy!
&amp;amp;p[summary]=In this blog, Arzumy will teach you how to rock!&amp;gt;Customized Share&amp;lt;/a&amp;gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;div style=&quot;text-align:center&quot;&gt;
&lt;a href=&quot;http://www.facebook.com/sharer.php?u=http://ar.zu.my&amp;amp;t=Rock on Arzumy!&quot; class=&quot;btn btn-primary&quot; target=&quot;_blank&quot;&gt;Share&lt;/a&gt;
&lt;a href=&quot;http://www.facebook.com/sharer.php?s=100&amp;amp;p[url]=http://ar.zu.my&amp;amp;p[images][0]=http://www.gravatar.com/avatar/2f8ec4a9ad7a39534f764d749e001046.png&amp;amp;p[title]=Rock on Arzumy!&amp;amp;p[summary]=In this blog, Arzumy will teach you how to rock!&quot; class=&quot;btn btn-primary&quot; target=&quot;_blank&quot;&gt;Customized Share&lt;/a&gt;
&lt;/div&gt;

&lt;p&gt;Go ahead test it out :)&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Save Cost On Your Heroku Worker Dynos</title>
   <link href="http://ar.zu.my/how-to-save-cost-on-your-heroku-worker-dynos"/>
   <updated>2012-12-30T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-save-cost-on-your-heroku-worker-dynos</id>
   <content type="html">&lt;p&gt;&lt;small&gt;30 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;On &lt;a href=&quot;http://bit.ly/myelection&quot;&gt;Malaysia Twitter Political Index&lt;/a&gt; project, I’m using &lt;a href=&quot;https://github.com/collectiveidea/delayed_job&quot;&gt;delayed job&lt;/a&gt; extensively. I used it to pull tweets, query sentiments and update sentiments. These jobs created every 10 minutes by &lt;a href=&quot;https://addons.heroku.com/scheduler&quot;&gt;Heroku Scheduler&lt;/a&gt;, Heroku’s answer to traditional cron job.&lt;/p&gt;

&lt;p&gt;These jobs took about 2 or 3 minutes to finish. While waiting for the next cron job, worker dyno are idle for 7 or 8 minutes. I don’t like it because I have to pay for it!&lt;/p&gt;

&lt;p&gt;I’m in luck because Heroku provides a &lt;a href=&quot;https://github.com/heroku/heroku.rb&quot;&gt;ruby client gem&lt;/a&gt; to interact with &lt;a href=&quot;https://api-docs.heroku.com/&quot;&gt;Heroku API&lt;/a&gt;. With this gem, we can easily start or stop dynos from within the app itself. There are few ways we can leverage on this, I chose to create rake task that will spin the dyno up and down. Then let Heroku Scheduler run it in specific intervals.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;c1&quot;&gt;# lib/tasks/heroku.rake&lt;/span&gt;
  
  &lt;span class=&quot;n&quot;&gt;namespace&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:dynos&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;desc&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'up worker'&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;up: :environment&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;unless&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Delayed&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Job&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;count&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;zero?&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;heroku&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Heroku&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;API&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ss&quot;&gt;:api_key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;ENV&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'API_KEY'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;])&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;heroku&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;post_ps_scale&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;ENV&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'APP_NAME'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;],&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'worker'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'1'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;

    &lt;span class=&quot;n&quot;&gt;desc&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'down worker'&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;down: :environment&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Delayed&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Job&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;where&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ss&quot;&gt;last_error: &lt;/span&gt;&lt;span class=&quot;kp&quot;&gt;nil&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;).&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;count&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;zero?&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;heroku&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Heroku&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;API&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ss&quot;&gt;:api_key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;ENV&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'API_KEY'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;])&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;heroku&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;post_ps_scale&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;ENV&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'APP_NAME'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;],&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'worker'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'0'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;I scheduled &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rake dynos:up&lt;/code&gt; to run immediately after all those sentiments job created, and scheduled &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rake dynos:down&lt;/code&gt; 3 minutes after that. Dyno will only spin up if there’s job, and will spin down if there’s no more pending jobs. Of course if you really want to push it, you can schedule it to run every minute just be sure.&lt;/p&gt;

&lt;p&gt;If you look at &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;heroku.post_ps_scale(ENV['APP_NAME'], 'worker', '0')&lt;/code&gt;, you can see that I assigned my app name to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;APP_NAME&lt;/code&gt; config var. I did that because I can’t find a way to programmatically get my app name from Heroku. If you use &lt;a href=&quot;https://addons.heroku.com/newrelic&quot;&gt;New Relic addon&lt;/a&gt; you could get it from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;NEW_RELIC_APP_NAME&lt;/code&gt;, but I feel more comfortable setting it myself.&lt;/p&gt;

&lt;p&gt;Now I managed to save around 70% of my estimated monthly dyno cost. If you want to go gung ho with it, potentially you could add this to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Delayed::Job&lt;/code&gt;’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;after_create&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;after_delete&lt;/code&gt; callbacks. That really depends on the nature of your jobs though.&lt;/p&gt;

&lt;p&gt;NOTE: I wrote about ‘&lt;a href=&quot;/use-two-dynos-on-heroku-for-free/&quot;&gt;How I Use Two Dynos On heroku For Free&lt;/a&gt;’ but I like Heroku API way better than using separate app to run worker. Less moving pieces to maintain.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Store Private Key Files In Heroku</title>
   <link href="http://ar.zu.my/how-to-store-private-key-files-in-heroku"/>
   <updated>2012-12-29T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-store-private-key-files-in-heroku</id>
   <content type="html">&lt;p&gt;&lt;small&gt;29 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;In my latest project, &lt;a href=&quot;http://bit.ly/myelection&quot;&gt;Malaysia Twitter Political Index&lt;/a&gt;, I used &lt;a href=&quot;https://developers.google.com/prediction/&quot;&gt;Google Prediction API&lt;/a&gt; and hosted it on &lt;a href=&quot;http://heroku.com&quot;&gt;Heroku&lt;/a&gt;. To use Google API, you have to create Client ID to authenticate with the endpoints. Since I’m calling the API directly from the server, not end user, I have to create &lt;a href=&quot;https://developers.google.com/console/help/#service_accounts&quot;&gt;Service Accounts&lt;/a&gt; client ID.&lt;/p&gt;

&lt;p&gt;Google generated a key pair for me. I then downloaded the private key and I would use it in my app. The key is formatted with &lt;a href=&quot;http://www.rsa.com/rsalabs/node.asp?id=2138&quot;&gt;PKCS #12&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I used &lt;a href=&quot;https://github.com/google/google-api-ruby-client&quot;&gt;google-api-ruby-client&lt;/a&gt; gem, here’s the example to authenticate:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'google/api_client'&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;client&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Google&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;APIClient&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Google&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;APIClient&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;PKCS12&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;load_key&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'/path/to/key.p12'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'notasecret'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;# this is where you load the key&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;service_account&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Google&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;APIClient&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;JWTAsserter&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;
      &lt;span class=&quot;s1&quot;&gt;'123456-abcdef@developer.gserviceaccount.com'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;
      &lt;span class=&quot;s1&quot;&gt;'https://www.googleapis.com/auth/prediction'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;
      &lt;span class=&quot;n&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;client&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;authorization&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;service_account&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;authorize&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That worked well in development environment. To make it work in Heroku deployment, I had few options:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Include the private key in my git repository.&lt;/li&gt;
  &lt;li&gt;Store it in S3, and pull it when needed.&lt;/li&gt;
  &lt;li&gt;Use custom build-pack which will include the key.&lt;/li&gt;
  &lt;li&gt;Store it as config vars.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Option 1 is the easiest. But maybe not ideal. While it’s true that I’m the only one working on the project, I wouldn’t know if others might join in any time in the future.&lt;/p&gt;

&lt;p&gt;Option 2 and 3 seems like a lot of unnecessary moving pieces involves.&lt;/p&gt;

&lt;p&gt;Option 4 is ideal in this scenario. I’m already storing all sensitive information in config vars anyway. Now how would I do that?&lt;/p&gt;

&lt;p&gt;I know config vars are string. So I took a peek at the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.p12&lt;/code&gt; file.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;cat &lt;/span&gt;example.p12
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; ??0?0?c0?&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;??   &lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;?H??
  &lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;?H??

  ???0??0&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;
  ...&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Bunch of jumbled up stuff. Ok, but PKCS #12 is just a format, maybe I can store the key in different format? I took a look back at the code and inspected what returned by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Google::APIClient::PKCS12.load_key&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'google/api_client'&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Google&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;APIClient&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;PKCS12&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;load_key&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'/path/to/key.p12'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'notasecret'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; 
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;-----&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;BEGIN&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;RSA&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;PRIVATE&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;KEY&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;-----&lt;/span&gt;
  &lt;span class=&quot;no&quot;&gt;MMMMMMMMaaaaaammmmammamamammamaasdhkghkdahgj8234joihsdfJHHKJGHGG&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;-----&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;END&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;RSA&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;PRIVATE&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;KEY&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;-----&lt;/span&gt;
  
  &lt;span class=&quot;n&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;class&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;OpenSSL&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;PKey&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;RSA&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Alright, that’s something that I recognized. It was &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;OpenSSL::PKey::RSA&lt;/code&gt; and returned a string. Let’s try load it directly instead of using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Google::APIClient::PKCS12.load_key&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'google/api_client'&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;client&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Google&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;APIClient&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;private_key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;-----BEGIN RSA PRIVATE KEY-----
  MMMMMMMMaaaaaammmmammamamammamaasdhkghkdahgj8234joihsdfJHHKJGHGG
  ...
  -----END RSA PRIVATE KEY-----&quot;&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;OpenSSL&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;PKey&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;RSA&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;private_key_&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'notasecret'&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;service_account&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Google&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;APIClient&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;JWTAsserter&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;
      &lt;span class=&quot;s1&quot;&gt;'123456-abcdef@developer.gserviceaccount.com'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;
      &lt;span class=&quot;s1&quot;&gt;'https://www.googleapis.com/auth/prediction'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;
      &lt;span class=&quot;n&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;n&quot;&gt;client&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;authorization&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;service_account&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;authorize&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;And we are good! Now instead of storing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.p12&lt;/code&gt; file, I’d store that instead. Heroku config vars support multiline string. I just had to double quote it.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  heroku config:add &lt;span class=&quot;nv&quot;&gt;PRIVATE_KEY&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;-----BEGIN RSA PRIVATE KEY-----
  MMMMMMMMaaaaaammmmammamamammamaasdhkghkdahgj8234joihsdfJHHKJGHGG
  ...
  -----END RSA PRIVATE KEY-----&quot;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;I make sure I passed the config var when I load the key.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;n&quot;&gt;key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;OpenSSL&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;PKey&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;RSA&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;ENV&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;PRIVATE_KEY&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;],&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'notasecret'&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That’s how you store private key in Heroku.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>assets:precompile Failure On Heroku</title>
   <link href="http://ar.zu.my/assets-precompile-failure-on-heroku"/>
   <updated>2012-12-27T00:00:00+00:00</updated>
   <id>http://ar.zu.my/assets-precompile-failure-on-heroku</id>
   <content type="html">&lt;p&gt;&lt;small&gt;27 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;This issue always caught me off guard when deploying new app on &lt;a href=&quot;http://heroku.com&quot;&gt;Heroku&lt;/a&gt;. The root cause is simple, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;assets:precompile&lt;/code&gt; requires the app’s environment to be loaded. But because it runs during slug compilation, no config vars available to the app yet. That’s why you’ll get error like this:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;could not connect to server: Connection refused
Is the server running on host &quot;127.0.0.1&quot; and accepting
TCP/IP connections on port xxxx?
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;App trying to connect to database but &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DATABASE_URL&lt;/code&gt; var not correctly set yet.&lt;/p&gt;

&lt;p&gt;The simplest solution is to tell the app to not initialize when we are compiling the assets. Add this line:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;c1&quot;&gt;# config/application.rb&lt;/span&gt;

  &lt;span class=&quot;n&quot;&gt;config&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;assets&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;initialize_on_precompile&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;kp&quot;&gt;false&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That should do it.&lt;/p&gt;

&lt;p&gt;Back then we were able to use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;user-env-compile&lt;/code&gt; feature from &lt;a href=&quot;https://devcenter.heroku.com/categories/labs&quot;&gt;Heroku Labs&lt;/a&gt; but it is no longer available. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;user-env-compile&lt;/code&gt; exposes your config vars during slug compilation. You can read about it here &lt;a href=&quot;https://devcenter.heroku.com/articles/labs-user-env-compile&quot;&gt;https://devcenter.heroku.com/articles/labs-user-env-compile&lt;/a&gt;.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>Why Some Rake Tasks Require :environment</title>
   <link href="http://ar.zu.my/why-some-rake-tasks-require-environment"/>
   <updated>2012-12-19T00:00:00+00:00</updated>
   <id>http://ar.zu.my/why-some-rake-tasks-require-environment</id>
   <content type="html">&lt;p&gt;&lt;small&gt;19 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;If you look at &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lib/tasks&lt;/code&gt; directory in your Rails app, you probably will find few &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.rake&lt;/code&gt; files. Those files allow you to run custom rake command like &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rake name:print:random_stuff&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;If you look at those files, you might find that some of them look like this:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:print_username&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:environment&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;nb&quot;&gt;puts&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;User&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;name&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;While some:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:print_random&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;nb&quot;&gt;puts&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'random random random'&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;With &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;:environment&lt;/code&gt; your task will run will full Rails environment loaded. That’s why you can do &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;User.first.name&lt;/code&gt; if you have a User model. If you do it this way:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:print_username&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;nb&quot;&gt;puts&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;User&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;name&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Then execute the task:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  rake print_username
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; uninitialized constant User&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;I tend to forget to include &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;:environment&lt;/code&gt; then smack my head when I see the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;uninitialized constant&lt;/code&gt; error.&lt;/p&gt;

&lt;p&gt;Depending on what you want to do, you should choose to load environment or not, accordingly.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Quickly Change All Your Remote Git Repos URL</title>
   <link href="http://ar.zu.my/how-to-quickly-change-all-your-remote-git-repo-url"/>
   <updated>2012-12-18T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-quickly-change-all-your-remote-git-repo-url</id>
   <content type="html">&lt;p&gt;&lt;small&gt;18 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;At &lt;a href=&quot;http://says.com&quot;&gt;SAYS&lt;/a&gt; we hosted all our repo in &lt;a href=&quot;http://github.com&quot;&gt;GitHub&lt;/a&gt;. It must have been 4 5 years now. We’ve changed our domain few times now, to better reflect our company. But we never bothered to change our organization name in GitHub. So until today it is in [https://github.com/youthasia] (https://github.com/youthasia).&lt;/p&gt;

&lt;p&gt;Today I decided to update our details in GitHub and while I am at it, change the name to SAYS. So I did just that knowing that we can’t sync our local repos until we change the URL in our local machine.&lt;/p&gt;

&lt;p&gt;Because we have quite a lot of repos, changing them one by one didn’t make much sense. This is what I did.&lt;/p&gt;

&lt;p&gt;I have a directory called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;workspace&lt;/code&gt; where I store all the repos.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;- workspace
  \_ repo_one
  \_ repo_two
  \_ repo_three
  ....
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;I want to look for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.git/config&lt;/code&gt; and change the URL in these lines:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;[remote &quot;origin&quot;]
	fetch = +refs/heads/*:refs/remotes/origin/*
	url = git@github.com:youthasia/example.git # Change youthasia to says
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;I did this:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;workspace
  &lt;span class=&quot;k&quot;&gt;for &lt;/span&gt;i &lt;span class=&quot;k&quot;&gt;in&lt;/span&gt; &lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;find &lt;span class=&quot;nb&quot;&gt;.&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-name&lt;/span&gt; config&lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;sed&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-i&lt;/span&gt;.back s/git@github&lt;span class=&quot;se&quot;&gt;\.&lt;/span&gt;com:youthasia/git@github&lt;span class=&quot;se&quot;&gt;\.&lt;/span&gt;com:says/g &lt;span class=&quot;nv&quot;&gt;$i&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;done&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;What I did was to change to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;workspace&lt;/code&gt; directory, find all &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;config&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sed&lt;/code&gt; will create backup file, change &lt;em&gt;youthasia&lt;/em&gt; to &lt;em&gt;says&lt;/em&gt; and save it. Now we can sync back with GitHub.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Add Footnote In Markdown</title>
   <link href="http://ar.zu.my/how-to-add-footnote-in-markdown"/>
   <updated>2012-12-17T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-add-footnote-in-markdown</id>
   <content type="html">&lt;p&gt;&lt;small&gt;17 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;I wrote my posts in &lt;a href=&quot;http://daringfireball.net/projects/markdown/&quot;&gt;Markdown&lt;/a&gt;. You can pull my blog from &lt;a href=&quot;https://github.com/arzumy/arzumy.github.com&quot;&gt;https://github.com/arzumy/arzumy.github.com&lt;/a&gt; and have a look.&lt;/p&gt;

&lt;p&gt;I used footnote in these two posts:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;/how-to-quickly-search-your-terminal-history/&quot;&gt;How To Quickly Search Your Terminal History&lt;/a&gt; (&lt;a href=&quot;https://raw.github.com/arzumy/arzumy.github.com/master/_posts/2011-01-01-how-to-quickly-search-your-terminal-history.md&quot;&gt;view source&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;/my-first-phreaking-lesson/&quot;&gt;My First Phreaking Lesson&lt;/a&gt; (&lt;a href=&quot;https://raw.github.com/arzumy/arzumy.github.com/master/_posts/1990-01-01-my-first-phreaking-lesson.md&quot;&gt;view source&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is a footnote&lt;sup id=&quot;fnref:fn-sample&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:fn-sample&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;. Go ahead click it.&lt;/p&gt;

&lt;p&gt;Here’s how we did that:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;This is a footnote[^fn-sample] 
[^fn-sample]: Now I gotta cut loose. Footloose, kick off the Sunday shoes. Click this to go back up &amp;gt;&amp;gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;All you need is to have &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[^anchor_name_here]&lt;/code&gt; for the link and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[^anchor_name_here]:&lt;/code&gt; for the footnote. The key is to start with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[^]&lt;/code&gt;. Ideally since it’s a footnote, you should place &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[^anchor_name_here]:&lt;/code&gt; on the bottom. But hey, entirely up to you! With this syntax, you’ll get &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;sup&amp;gt;&amp;lt;/sup&amp;gt;&lt;/code&gt; tag for free with link to the anchor and running numbers for all footnotes on the same page.&lt;/p&gt;

&lt;p&gt;I intentionally left a blank space here so you can test the link and actually move from the number to footnote back and forth.&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;display:block; height:1200px;&quot;&gt; &lt;/span&gt;&lt;/p&gt;

&lt;div class=&quot;footnotes&quot; role=&quot;doc-endnotes&quot;&gt;
  &lt;ol&gt;
    &lt;li id=&quot;fn:fn-sample&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;Now I gotta cut loose. Footloose, kick off the Sunday shoes. Click this to go back up » &lt;a href=&quot;#fnref:fn-sample&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
  &lt;/ol&gt;
&lt;/div&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Steal Twitter Password</title>
   <link href="http://ar.zu.my/how-to-steal-twitter-password"/>
   <updated>2012-12-16T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-steal-twitter-password</id>
   <content type="html">&lt;p&gt;&lt;small&gt;16 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;Difficulty level maybe a bit high, but it’s doable.&lt;/p&gt;

&lt;p&gt;Recently I’ve been using &lt;a href=&quot;http://lift.do/&quot;&gt;Lift&lt;/a&gt; to start new habit. I like it because it is not annoying compared to other apps out there. It just passively waits there tracking your habit.&lt;/p&gt;

&lt;p&gt;After using it for few days, I figured I’d like to connect my &lt;a href=&quot;https://twitter.com/arzumy&quot;&gt;Twitter account&lt;/a&gt;. There’s nothing much you could achieve by doing that, it will pull your avatar and that’s about it. I can’t justify why would I want to connect my Twitter account. But I went ahead and clicked &lt;em&gt;Connect to Twitter&lt;/em&gt; anyway.&lt;/p&gt;

&lt;p&gt;I got redirected to this screen:&lt;/p&gt;

&lt;div class=&quot;posts-images&quot;&gt;
  &lt;img src=&quot;/assets/images/posts/2012-12-16-lift-screenshot.png&quot; title=&quot;Lift Twitter authorize screen&quot; class=&quot;img-polaroid&quot; style=&quot;max-width: 400px;&quot; /&gt;
&lt;/div&gt;

&lt;p&gt;What’s wrong with this page? There’s no way I can verify that the page I’m seeing is a real Twitter auth page. It could be a phishing page made to steal my login credentials.&lt;/p&gt;

&lt;p&gt;Since this page is loaded in a web wrapper, you can create a fake Twitter auth page and store the login credentials when submitted. Then, redirect them back again to the real Twitter page. Unsuspecting victim will just try to login again. Because no one can see the URL, they won’t know.&lt;/p&gt;

&lt;p&gt;Maybe it’s a bit hard to pull on legitimate app distributed through Apple App Store. But if you are distributing the app through other unofficial channels, you can pull this of quite easily.&lt;/p&gt;

&lt;p&gt;NOTE: Lift allows you to connect your Twitter account from web, &lt;a href=&quot;http://lift.do/login&quot;&gt;http://lift.do/login&lt;/a&gt;. That’s a better option and signs that you can trust the app. I’m not implying that Lift is stealing your password. I’m using it as example because I stumbled upon it.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>Simple Array In YAML</title>
   <link href="http://ar.zu.my/simple-array-in-yaml"/>
   <updated>2012-12-14T00:00:00+00:00</updated>
   <id>http://ar.zu.my/simple-array-in-yaml</id>
   <content type="html">&lt;p&gt;&lt;small&gt;14 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;I’m so used to load &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.yml&lt;/code&gt; file to hash that I’ve forgotten &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.yml&lt;/code&gt; can just load directly to array. In fact, that’s like the most basic way of doing this.&lt;/p&gt;

&lt;p&gt;This is how I normally create my &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.yml&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-yaml&quot; data-lang=&quot;yaml&quot;&gt;  &lt;span class=&quot;c1&quot;&gt;# test.yml&lt;/span&gt;
  
  &lt;span class=&quot;na&quot;&gt;sample&lt;/span&gt;&lt;span class=&quot;pi&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;na&quot;&gt;first_test&lt;/span&gt;&lt;span class=&quot;pi&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;one&lt;/span&gt;
    &lt;span class=&quot;na&quot;&gt;second_test&lt;/span&gt;&lt;span class=&quot;pi&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;two&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That will give me a hash.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'yaml'&lt;/span&gt;
  &lt;span class=&quot;no&quot;&gt;Yaml&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;load_file&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'test.yml'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;sample&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;first_test&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;one&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;second_test&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;two&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;}}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;In my mind, that’s the default way of doing things. Few days back I decided to include all my previous talks and interviews in my site. You can see how I started in this &lt;a href=&quot;https://github.com/arzumy/arzumy.github.com/commit/b3f35c92b8c4c7e72403c26db44a6a560d0957f8&quot;&gt;commit&lt;/a&gt;. Take a close look at my &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;index.html&lt;/code&gt; file.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-html&quot; data-lang=&quot;html&quot;&gt;  &lt;span class=&quot;nt&quot;&gt;&amp;lt;li&amp;gt;&lt;/span&gt;
    &lt;span class=&quot;nt&quot;&gt;&amp;lt;span&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;class=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;label label-info&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;12 Jan 2012&lt;span class=&quot;nt&quot;&gt;&amp;lt;/span&amp;gt;&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;&amp;lt;a&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;href=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;http://bfm.my/lifehacks.html&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;BFM 89.9: The Business Station - Lifehacks&lt;span class=&quot;nt&quot;&gt;&amp;lt;/a&amp;gt;&lt;/span&gt;
  &lt;span class=&quot;nt&quot;&gt;&amp;lt;/li&amp;gt;&lt;/span&gt;
  &lt;span class=&quot;nt&quot;&gt;&amp;lt;li&amp;gt;&lt;/span&gt;
    &lt;span class=&quot;nt&quot;&gt;&amp;lt;span&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;class=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;label label-info&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;28 Sep 2011&lt;span class=&quot;nt&quot;&gt;&amp;lt;/span&amp;gt;&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;&amp;lt;a&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;href=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;http://www.bfm.my/techtalk_hackweekday2011.html&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;BFM 89.9: The Business Station - HackWEEKDAY 2011&lt;span class=&quot;nt&quot;&gt;&amp;lt;/a&amp;gt;&lt;/span&gt;
  &lt;span class=&quot;nt&quot;&gt;&amp;lt;/li&amp;gt;&lt;/span&gt;
  &lt;span class=&quot;nt&quot;&gt;&amp;lt;li&amp;gt;&lt;/span&gt;
    &lt;span class=&quot;nt&quot;&gt;&amp;lt;span&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;class=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;label label-info&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;01 Sep 2005&lt;span class=&quot;nt&quot;&gt;&amp;lt;/span&amp;gt;&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;&amp;lt;a&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;href=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;http://www.nib.com.my/archives/text/view/9426915?pos=3&amp;amp;hide_header=1&amp;amp;resultset=nstpec%3Awww/cross-search/search.php%3A_1355414435%3Aresultset&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;New Straits Times: Computimes - Hacking competition winners&lt;span class=&quot;nt&quot;&gt;&amp;lt;/a&amp;gt;&lt;/span&gt;
  &lt;span class=&quot;nt&quot;&gt;&amp;lt;/li&amp;gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;While this worked, I started to see pattern emerged. I have the same list for talks as well. I’ll have to repeat the same &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;li&lt;/code&gt; over and over again. Maybe it would be better if I could store my interviews and talks in a collection and just loop it here instead. Configuration for this site stored in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_config.yml&lt;/code&gt;, so seems like it would make sense if I store my interviews and talks there too.&lt;/p&gt;

&lt;p&gt;My problem was, how do I store them in an array? I checkout &lt;a href=&quot;http://www.yaml.org&quot;&gt;yaml.org&lt;/a&gt; and the first example for ruby is &lt;a href=&quot;http://www.yaml.org/YAML_for_ruby.html#simple_sequence&quot;&gt;simple sequence&lt;/a&gt; list. List without key. That works really well. Example:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-yaml&quot; data-lang=&quot;yaml&quot;&gt;  &lt;span class=&quot;c1&quot;&gt;# test.yml&lt;/span&gt;
  
  &lt;span class=&quot;na&quot;&gt;sample&lt;/span&gt;&lt;span class=&quot;pi&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;pi&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;one&lt;/span&gt;
    &lt;span class=&quot;pi&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;two&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That will give me hash with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sample&lt;/code&gt; as the key, and an array of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;one, two&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'yaml'&lt;/span&gt;
  &lt;span class=&quot;no&quot;&gt;Yaml&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;load_file&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'test.yml'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;sample&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;one&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;two&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;With that knowledge, I made this &lt;a href=&quot;https://github.com/arzumy/arzumy.github.com/commit/57860adef11092846386c9e54210f6569566ed9a&quot;&gt;commit&lt;/a&gt; and now I can use for loop in my &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;index.html&lt;/code&gt; for talks and interviews.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-html&quot; data-lang=&quot;html&quot;&gt;  {% for interview in site.content.interviews %}
    &lt;span class=&quot;nt&quot;&gt;&amp;lt;li&amp;gt;&lt;/span&gt;
      &lt;span class=&quot;nt&quot;&gt;&amp;lt;span&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;class=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;label label-info&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;{{ interview.date }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/span&amp;gt;&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;&amp;lt;a&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;href=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;{{ interview.url }}&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;{{ interview.title }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/a&amp;gt;&lt;/span&gt;
    &lt;span class=&quot;nt&quot;&gt;&amp;lt;/li&amp;gt;&lt;/span&gt;
  {% endfor %}  &lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Much better!&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Make Sure Your Free Wordpress Theme Is Safe From Virus</title>
   <link href="http://ar.zu.my/how-to-make-sure-your-wordpress-theme-is-safe-from-virus"/>
   <updated>2012-12-07T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-make-sure-your-wordpress-theme-is-safe-from-virus</id>
   <content type="html">&lt;p&gt;&lt;small&gt;07 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;I helped a friend cleaning up his &lt;a href=&quot;http://wordpress.org/&quot;&gt;Wordpress&lt;/a&gt; installation from viruses today. Hosting provider emailed and pointed us to the exact files with virus. I’m using virus term loosely, they were actually &lt;a href=&quot;http://en.wikipedia.org/wiki/Backdoor_Shell&quot;&gt;PHP backdoor shells&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I don’t use Wordpress that much. I think I have few installations here and there, mostly left forgotten. So today I got to learn about basic safety when dealing with Wordpress.&lt;/p&gt;

&lt;p&gt;Keep your Wordpress up-to-date. There’s almost no reason why you won’t or can’t upgrade. Updating Wordpress installation is so easy now, just a single click.&lt;/p&gt;

&lt;p&gt;Majority of free Wordpress themes are infected with some sort of backdoor, or maybe just simple affiliate links. Clean free themes are hard to come by. If you want free theme, get them from trusted source. I would trust themes in Wordpress.org itself. Just search and install within Wordpress. I don’t know any other free themes sites that I could trust.&lt;/p&gt;

&lt;p&gt;If you really have to use free theme, then you have to take a little precaution. One thing that we did is to install &lt;a href=&quot;http://wordpress.org/extend/plugins/tac/&quot;&gt;Theme Authenticity Checker (TAC)&lt;/a&gt; plugin. It would scan for obfuscated code. There’s no reason why theme creators want to obfuscate the code unless they are hiding something.&lt;/p&gt;

&lt;p&gt;You could also scan the compressed theme file after downloading. Maybe that would help. I don’t know because I’m using OSX, and OSX users are not known for using antivirus software. But we have terminal though. We could do this:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  unzip &lt;span class=&quot;nt&quot;&gt;-d&lt;/span&gt; freetheme freetheme.zip
  &lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;freetheme
  &lt;span class=&quot;nb&quot;&gt;grep&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-Rn&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;base64_decode *(&quot;&lt;/span&gt; &lt;span class=&quot;nb&quot;&gt;.&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; ./footer.php:1:&amp;lt;? &lt;span class=&quot;nb&quot;&gt;eval&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;gzinflate&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;str_rot13&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;base64_decode&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;'FZfHDoTYFVF/xTuPxYKccXtTx...&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;From the grep result we could see there’s a base64 encoded string. Not a good sign. If you just want to be safe, just delete and don’t use it.&lt;/p&gt;

&lt;p&gt;To cover more bases, I found this command from &lt;a href=&quot;http://blog.rootcon.org/2012/04/simple-kung-fu-grep-for-finding-common.html&quot;&gt;The Official ROOTCON Blog&lt;/a&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;grep&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-RPn&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;(passthru|shell_exec|system|phpinfo|base64_decode|chmod|mkdir|fopen|fclose|readfile|php_uname|eval|tcpflood|udpflood|edoced_46esab) *&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\(&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt; .&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

</content>
 </entry>
 
 <entry>
   <title>How To Work Faster With Chrome Developer Console</title>
   <link href="http://ar.zu.my/how-to-work-faster-with-chrome-developer-console"/>
   <updated>2012-12-04T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-work-faster-with-chrome-developer-console</id>
   <content type="html">&lt;p&gt;&lt;small&gt;04 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;Web developer spent considerable amount of time working on browser console. You could be working mostly on &lt;a href=&quot;https://getfirebug.com/&quot;&gt;Firefox Firebug&lt;/a&gt; or &lt;a href=&quot;https://developers.google.com/chrome-developer-tools/docs/console&quot;&gt;Chrome Developer Console&lt;/a&gt;. It’s good to learn a trick or two to speed up development.&lt;/p&gt;

&lt;p&gt;I learned this from &lt;a href=&quot;http://homakov.blogspot.com/&quot;&gt;Egor Homakov&lt;/a&gt;. We were smoking shisha when he decided to pull out his machine and get some work done. And while he was at it, he showed us few tricks.&lt;/p&gt;

&lt;p&gt;The first one was &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$0&lt;/code&gt;. The command will return the most recently selected node to console. You just have to go to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Elements&lt;/code&gt;, click on a node and type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$0&lt;/code&gt; in console. You can also type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$1&lt;/code&gt; to return the previously selected element. Then &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$2&lt;/code&gt; and so on.&lt;/p&gt;

&lt;p&gt;If you’ve been a good developer and bothered to check &lt;a href=&quot;https://developers.google.com/chrome-developer-tools/docs/console&quot;&gt;https://developers.google.com/chrome-developer-tools/docs/console&lt;/a&gt; then you’ve probably already noticed this. I have never been to that page until today.&lt;/p&gt;

&lt;p&gt;But, he did show something else too. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$_&lt;/code&gt; to get the last returned value in console. Similar to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;irb&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-javascript&quot; data-lang=&quot;javascript&quot;&gt;  &lt;span class=&quot;o&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;4&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;var&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;b&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;$_&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;kc&quot;&gt;undefined&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;b&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;4&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;And that one wasn’t documented in &lt;a href=&quot;https://developers.google.com/chrome-developer-tools/docs/console&quot;&gt;https://developers.google.com/chrome-developer-tools/docs/console&lt;/a&gt; yet. Not supported by &lt;a href=&quot;http://getfirebug.com/wiki/index.php/Command_Line_API&quot;&gt;Firebug’s Command Line API&lt;/a&gt; too.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Watch Almost All Live Sports In The World Online</title>
   <link href="http://ar.zu.my/how-to-watch-almost-all-live-sports-in-the-world-online"/>
   <updated>2012-12-01T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-watch-almost-all-live-sports-in-the-world-online</id>
   <content type="html">&lt;p&gt;&lt;small&gt;01 December 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.affsuzukicup.com/&quot;&gt;AFF Suzuki Cup 2012&lt;/a&gt; campaign is well underway right now. Being one of the avid supporters of &lt;a href=&quot;http://en.wikipedia.org/wiki/Malaysia_national_football_team&quot;&gt;Harimau Malaya&lt;/a&gt; since Suzuki Cup 2010 (yes, I didn’t care much about them before this), it is a must to follow every match. That evening, Malaysia vs. Indonesia. And I was going to watch it from a place where the only live channel available is through &lt;a href=&quot;http://www.tm.com.my/unifi/hypptv/Pages/abouthypptv.aspx&quot;&gt;Unifi HyppTV&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Which is fine most of the time. HyppTV is not that bad.&lt;/p&gt;

&lt;p&gt;Except it was dreadful that night. HyppTV was down. Nationwide!&lt;/p&gt;

&lt;p&gt;Naturally, the immediate thing to do was to go to &lt;a href=&quot;http://www.rtm.gov.my/tv1/&quot;&gt;RMT TV1&lt;/a&gt; and see if they have online streaming. They do! Great! But it was buffering 99% of the time. Maybe all HyppTV users were on that page. Then there was &lt;a href=&quot;http://www.1malaysiaiptv.com.my/watch.php&quot;&gt;1Malaysia IPTV&lt;/a&gt;, it comes with iPhone and iPad app. But as expected for services that leeching on 1Malaysia brand, doesn’t work. It pulls the same source from RTM TV1 online, and the app crashed every time you want to view the channel.&lt;/p&gt;

&lt;p&gt;Next most naturally thing to do was to tune the TV set for terrestrial broadcast. This step used to be the most natural step, but after Astro monopolized our airwave, it is now left forgotten. Nevertheless, worth a try. And… not working. We didn’t have cable for the antenna to boost the signal.&lt;/p&gt;

&lt;p&gt;When nothing else works, there’s only one thing you can do. Tweet about it.&lt;/p&gt;

&lt;p&gt;That led me to &lt;a href=&quot;http://www.frombar.tv/c-1.html&quot;&gt;fromBAR&lt;/a&gt; formerly known as sportLEMON. Live sports aggregator plagued with ad banners. We found few links. One of them worked really well. So we plugged the machine to the big screen and start cheering!&lt;/p&gt;

&lt;p&gt;It was all pixelated, but all is well when your team is winning. End result: Malaysia won 2-0.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>Aspen Shutdown, Serve Static HTML From Cedar And run:detached</title>
   <link href="http://ar.zu.my/aspen-shutdown-serve-static-html-from-cedar-and-run-detached"/>
   <updated>2012-11-27T00:00:00+00:00</updated>
   <id>http://ar.zu.my/aspen-shutdown-serve-static-html-from-cedar-and-run-detached</id>
   <content type="html">&lt;p&gt;&lt;small&gt;27 November 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://heroku.com&quot;&gt;Heroku&lt;/a&gt; is shutting down the Aspen stack effective November 26, 2012. I have few apps still running on Aspen, but most of them are trial apps, so I never bothered to migrate to Cedar. Except, today I realized &lt;a href=&quot;http://codelovr.com&quot;&gt;Codelovr’s site&lt;/a&gt; was down. It was still on Aspen!&lt;/p&gt;

&lt;p&gt;I quickly pulled down the code. After quick check, it was a rails app during the early days. But it was serving just a single html file with one stylesheet. There’s no reason why we should continue with that. I decided to just serve static html directly. A quick search showed there are multiple ways to serve static html on Cedar stack. I chose to use Apache to serve it. I got the tutorial from &lt;a href=&quot;http://kennethreitz.com/static-sites-on-heroku-cedar.html&quot;&gt;http://kennethreitz.com/static-sites-on-heroku-cedar.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;First we must make sure &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;index.php&lt;/code&gt; exists. I copied my &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;index.html&lt;/code&gt; to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;index.php&lt;/code&gt;. I’ve copied my html and stylesheet to new directory.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;cp &lt;/span&gt;index.&lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;html,php&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;To understand why we need &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;index.php&lt;/code&gt;, we can have a look at how heroku-buildpack-php detect it. The code is here &lt;a href=&quot;https://github.com/heroku/heroku-buildpack-php/blob/master/bin/detect&quot;&gt;https://github.com/heroku/heroku-buildpack-php/blob/master/bin/detect&lt;/a&gt;. The exact line is&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;[&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-f&lt;/span&gt; &lt;span class=&quot;nv&quot;&gt;$1&lt;/span&gt;/index.php &lt;span class=&quot;o&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;then&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Then we turn off php engine&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;echo&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'php_flag engine off'&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;gt;&lt;/span&gt; .htaccess&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Commit everything, create new Cedar stack and push!&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  git init &lt;span class=&quot;nb&quot;&gt;.&lt;/span&gt; 
  git add &lt;span class=&quot;nb&quot;&gt;.&lt;/span&gt;
  git commit &lt;span class=&quot;nt&quot;&gt;-am&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'initial commit'&lt;/span&gt;
  heroku apps:create 
  git push heroku
  heroku open&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;If everything is cool we can delete the Aspen app and add back our custom domain to the new Cedar app.&lt;/p&gt;

&lt;p&gt;Another thing I learned today is how to run task in background. There are places where port 5000 is blocked and running &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;heroku run rake db:migrate&lt;/code&gt; always ended up with time out connecting to process. To bypass that, we just run it in background with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;run:detached&lt;/code&gt;&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  heroku run:detached rake db:migrate
  
  Output:
  Running &lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;rake db:migrate&lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt; detached... up, run.4271
  Use &lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;heroku logs &lt;span class=&quot;nt&quot;&gt;-p&lt;/span&gt; run.4271&lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt; to view the output.
  
  heroku logs &lt;span class=&quot;nt&quot;&gt;-p&lt;/span&gt; run.4271 &lt;span class=&quot;c&quot;&gt;# To view log&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;You can read more here &lt;a href=&quot;https://devcenter.heroku.com/articles/oneoff-admin-ps#running-tasks-in-background&quot;&gt;https://devcenter.heroku.com/articles/oneoff-admin-ps#running-tasks-in-background&lt;/a&gt;&lt;/p&gt;

</content>
 </entry>
 
 <entry>
   <title>jekyll And liquid Loops</title>
   <link href="http://ar.zu.my/jekyll-and-liquid-loops"/>
   <updated>2012-11-25T00:00:00+00:00</updated>
   <id>http://ar.zu.my/jekyll-and-liquid-loops</id>
   <content type="html">&lt;p&gt;&lt;small&gt;25 November 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;I’ve been using &lt;a href=&quot;https://github.com/mojombo/jekyll&quot;&gt;jekyll&lt;/a&gt; to run this site since 3 years ago. But I didn’t do much with it. It was just a single page site. Surprisingly enough, this site is a PageRank 3 site! Now who said content is king? :P&lt;/p&gt;

&lt;p&gt;Now that I’m starting to convert this site to a blog, I’ve been using jekyll as it’s intended to be. I got to learn a bit more about it. Specifically the syntaxes for &lt;a href=&quot;https://github.com/Shopify/liquid&quot;&gt;liquid&lt;/a&gt;, template engine used in jekyll.&lt;/p&gt;

&lt;p&gt;Since this is a blog, having &lt;a href=&quot;/atom.xml&quot;&gt;atom.xml&lt;/a&gt; for feed is not a bad idea. I just copied (yes, this pattern starting to emerge now) from &lt;a href=&quot;https://github.com/mojombo/mojombo.github.com/blob/master/atom.xml&quot;&gt;Tom Preston-Werner’s&lt;/a&gt; blog and edited it a bit.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-xml&quot; data-lang=&quot;xml&quot;&gt;  &lt;span class=&quot;cp&quot;&gt;&amp;lt;?xml version=&quot;1.0&quot; encoding=&quot;utf-8&quot;?&amp;gt;&lt;/span&gt;
  &lt;span class=&quot;nt&quot;&gt;&amp;lt;feed&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;xmlns=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;http://www.w3.org/2005/Atom&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;
  
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;title&amp;gt;&lt;/span&gt;{{ site.title }} - {{ site.tagline }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/title&amp;gt;&lt;/span&gt;
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;link&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;href=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;{{ site.production_url }}/atom.xml&quot;&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;rel=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;self&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;/&amp;gt;&lt;/span&gt;
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;link&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;href=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;{{ site.production_url }}&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;/&amp;gt;&lt;/span&gt;
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;updated&amp;gt;&lt;/span&gt;{{ site.time | date_to_xmlschema }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/updated&amp;gt;&lt;/span&gt;
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;id&amp;gt;&lt;/span&gt;{{ site.production_url }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/id&amp;gt;&lt;/span&gt;
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;author&amp;gt;&lt;/span&gt;
     &lt;span class=&quot;nt&quot;&gt;&amp;lt;name&amp;gt;&lt;/span&gt;{{ site.author.name }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/name&amp;gt;&lt;/span&gt;
     &lt;span class=&quot;nt&quot;&gt;&amp;lt;email&amp;gt;&lt;/span&gt;{{ site.author.email }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/email&amp;gt;&lt;/span&gt;
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;/author&amp;gt;&lt;/span&gt;
  
   {% for post in site.posts %}
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;entry&amp;gt;&lt;/span&gt;
     &lt;span class=&quot;nt&quot;&gt;&amp;lt;title&amp;gt;&lt;/span&gt;{{ post.title }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/title&amp;gt;&lt;/span&gt;
     &lt;span class=&quot;nt&quot;&gt;&amp;lt;link&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;href=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;{{ site.production_url }}{{ post.url }}&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;/&amp;gt;&lt;/span&gt;
     &lt;span class=&quot;nt&quot;&gt;&amp;lt;updated&amp;gt;&lt;/span&gt;{{ post.date | date_to_xmlschema }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/updated&amp;gt;&lt;/span&gt;
     &lt;span class=&quot;nt&quot;&gt;&amp;lt;id&amp;gt;&lt;/span&gt;{{ site.production_url }}{{ post.id }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/id&amp;gt;&lt;/span&gt;
     &lt;span class=&quot;nt&quot;&gt;&amp;lt;content&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;type=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;html&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;{{ post.content | xml_escape }}&lt;span class=&quot;nt&quot;&gt;&amp;lt;/content&amp;gt;&lt;/span&gt;
   &lt;span class=&quot;nt&quot;&gt;&amp;lt;/entry&amp;gt;&lt;/span&gt;
   {% endfor %}
  
  &lt;span class=&quot;nt&quot;&gt;&amp;lt;/feed&amp;gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;But if you look at the loop&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;{% for post in site.posts %}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;That will list down all posts since the dawn of time. I don’t have a problem with it yet. At this time of writing, I only have 4 posts. This could be a problem if I’m persistent enough to churn out new post every few days. I decided not to be pragmatic and solve this non-problem now.&lt;/p&gt;

&lt;p&gt;A quick look here &lt;a href=&quot;https://github.com/Shopify/liquid/wiki/Liquid-for-Designers&quot;&gt;https://github.com/Shopify/liquid/wiki/Liquid-for-Designers&lt;/a&gt; shows that I can just add &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;limit&lt;/code&gt; to the loop.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;{% for post in site.posts limit:10 %}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;There you go. Non-problem solved.&lt;/p&gt;

&lt;p&gt;NOTE: If you want to use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;code&amp;gt;&lt;/code&gt; tag to display liquid syntax like I did above, then you’ll have to temporarily disable tag processing. You can use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;{% raw %}&lt;/code&gt; tag.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;{% raw %}
  {% for post in site.posts limit:10 %}
{% endraw %}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Credit goes to this &lt;a href=&quot;http://stackoverflow.com/questions/10154690/github-pages-isnt-applying-my-template&quot;&gt;Stack Overflow answer&lt;/a&gt;.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>heroku_san Deploy Strategies And Bundle Blunder</title>
   <link href="http://ar.zu.my/heroku_san-deploy-strategies-and-bundle-blunder"/>
   <updated>2012-11-23T00:00:00+00:00</updated>
   <id>http://ar.zu.my/heroku_san-deploy-strategies-and-bundle-blunder</id>
   <content type="html">&lt;p&gt;&lt;small&gt;23 November 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;What’s annoying about &lt;a href=&quot;https://github.com/fastestforward/heroku_san&quot;&gt;heroku_san&lt;/a&gt; is it will run migration all the time. Not cool. Most of the times I don’t have any migration to run. Few seconds wasted waiting for the environment to load yet no migration needed.&lt;/p&gt;

&lt;p&gt;Good thing heroku_san allows custom deploy strategy. &lt;a href=&quot;https://github.com/fastestforward/heroku_san/wiki/Deploy-Strategies&quot;&gt;Here’s the complete tutorial&lt;/a&gt;. Here’s my short version. All I want is for the deployment to just push the commit and that’s it. No need for migration and restart. So I just cut as paste from the tutorial to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/lib/tasks/heroku.rake&lt;/code&gt;&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'heroku_san'&lt;/span&gt;
  
  &lt;span class=&quot;k&quot;&gt;class&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;MyStrategy&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Deploy&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Base&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;def&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;deploy&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;super&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  
  &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;project&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Project&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Rails&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;root&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;join&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;config&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;heroku.yml&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;),&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:deploy&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;MyStrategy&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Come to think of if, I might as well just do this instead:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'heroku_san'&lt;/span&gt;
  
  &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;project&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Project&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Rails&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;root&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;join&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;config&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;heroku.yml&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;),&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:deploy&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Deploy&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Base&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Since I’m not adding anything to it. That’s it. Now deploying to heroku should not invoke rake db:migrate.&lt;/p&gt;

&lt;p&gt;Except, it didn’t work. The gotcha? Checkout my Gemfile&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;n&quot;&gt;group&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:development&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;gem&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'heroku_san'&lt;/span&gt;
    &lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Yeah, no heroku_san on production. I then just add simple check.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Rails&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;development?&lt;/span&gt;
    &lt;span class=&quot;nb&quot;&gt;require&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'heroku_san'&lt;/span&gt;
    
    &lt;span class=&quot;k&quot;&gt;class&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;MyStrategy&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Deploy&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Base&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;def&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;deploy&lt;/span&gt;
        &lt;span class=&quot;k&quot;&gt;super&lt;/span&gt;
      &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  
    &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;project&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;HerokuSan&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Project&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Rails&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;root&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;join&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;config&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;heroku.yml&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;),&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:deploy&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;MyStrategy&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That should do it. Now we can deploy.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How I Use heroku_san With auto_tagger For Deployment</title>
   <link href="http://ar.zu.my/how-i-use-heroku_san-and-auto_tagger-for-deployment"/>
   <updated>2012-11-21T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-i-use-heroku_san-and-auto_tagger-for-deployment</id>
   <content type="html">&lt;p&gt;&lt;small&gt;21 November 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;In &lt;a href=&quot;http://says.com&quot;&gt;SAYS&lt;/a&gt;, we use &lt;a href=&quot;https://github.com/technicalpickles/capistrano-gitflow&quot;&gt;capistrano-gitflow&lt;/a&gt; in our deployment recipe. It provides us with tagging and logging workflow. Made our life easier.&lt;/p&gt;

&lt;p&gt;Currently I’m working on one of our client’s project. It require us to deploy on &lt;a href=&quot;http://heroku.com&quot;&gt;heroku&lt;/a&gt;. I would love to use the same deployment workflow that we use in SAYS. My initial plan was to write simple rake task to tag and push to heroku. Of course, I googled it up first, see how others approached deployment on heroku.&lt;/p&gt;

&lt;p&gt;Most solutions that I found are using production/staging branch. Which is not what I wanted. That’s when I stumbled upon heroku_san. I remember reading about it but didn’t bother to test it out. &lt;a href=&quot;https://github.com/fastestforward/heroku_san/wiki/Using-Autotagger&quot;&gt;There’s a good tutorial here&lt;/a&gt;. But I don’t use CI for this project, so I simplify it a bit.&lt;/p&gt;

&lt;p&gt;I added tag to heroku.yml for production stage, staging remains the same.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-yaml&quot; data-lang=&quot;yaml&quot;&gt;  &lt;span class=&quot;na&quot;&gt;production&lt;/span&gt;&lt;span class=&quot;pi&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;na&quot;&gt;tag&lt;/span&gt;&lt;span class=&quot;pi&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;staging/*&lt;/span&gt;
    &lt;span class=&quot;s&quot;&gt;...&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Then I just paste from the example to heroku.rake, I removed ci from STAGES.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;no&quot;&gt;STAGES&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;sx&quot;&gt;%w[staging production]&lt;/span&gt;

  &lt;span class=&quot;k&quot;&gt;def&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;create_and_push&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;stage&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;auto_tag&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;AutoTagger&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Base&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;new&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ss&quot;&gt;stages: &lt;/span&gt;&lt;span class=&quot;no&quot;&gt;STAGES&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;stage: &lt;/span&gt;&lt;span class=&quot;n&quot;&gt;stage&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;verbose: &lt;/span&gt;&lt;span class=&quot;kp&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;push_refs: &lt;/span&gt;&lt;span class=&quot;kp&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;refs_to_keep: &lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;100&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;tag&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;auto_tag&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;create_ref&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;auto_tag&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;last_ref_from_previous_stage&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;try&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;ss&quot;&gt;:sha&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;))&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;sh&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;git push origin &lt;/span&gt;&lt;span class=&quot;si&quot;&gt;#{&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;tag&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;auto_tag&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;delete_locally&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;auto_tag&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;delete_on_remote&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  
  &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:before_deploy&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;sh&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;git fetch --tags&quot;&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  
  &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:after_deploy&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;each_heroku_app&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;stage&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;|&lt;/span&gt;
      &lt;span class=&quot;n&quot;&gt;create_and_push&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;stage&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  
  &lt;span class=&quot;n&quot;&gt;namespace&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:autotag&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;desc&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;Create an autotag for stage, default: &lt;/span&gt;&lt;span class=&quot;si&quot;&gt;#{&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;STAGES&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;task&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:create&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:stage&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;do&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;t&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;args&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;|&lt;/span&gt;
      &lt;span class=&quot;n&quot;&gt;create_and_push&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;args&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;ss&quot;&gt;:stage&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;||&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;STAGES&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
  &lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That’s it. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rake staging deploy&lt;/code&gt; will deploy to staging, then tag it with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;staging/datetime&lt;/code&gt;. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rake production deploy&lt;/code&gt; will deploy anything tagged as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;staging/\*&lt;/code&gt;.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How I Use Two Dynos On heroku For Free</title>
   <link href="http://ar.zu.my/use-two-dynos-on-heroku-for-free"/>
   <updated>2012-11-08T00:00:00+00:00</updated>
   <id>http://ar.zu.my/use-two-dynos-on-heroku-for-free</id>
   <content type="html">&lt;p&gt;&lt;small&gt;08 November 2012&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;I use &lt;a href=&quot;http://heroku.com&quot;&gt;heroku&lt;/a&gt; all the time. I don’t need to bother with sysadmin stuff. But mainly because it’s free :) Free is limited to one dyno, and to whatever free add-ons that you want to use, but that is good enough most of the times.&lt;/p&gt;

&lt;p&gt;Except this time, it’s not good enough. I need to run delay jobs, and that would require another dyno for the worker. That will cost roughly $34.50 a month. Quite a lot for a simple fun not-for-profit project. I could potentially use other queues add-ons with pay per use costing, but I don’t feel like changing the app.&lt;/p&gt;

&lt;p&gt;So what I did instead is, to start another Heroku app with one worker only. No web dyno. Then all I need to do is change the DATABASE_URL to be the same as my current web app.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  heroku config &lt;span class=&quot;nt&quot;&gt;--app&lt;/span&gt; app-web &lt;span class=&quot;c&quot;&gt;# list down the config&lt;/span&gt;
  heroku config:add &lt;span class=&quot;nv&quot;&gt;DATABASE_URL&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;mysql2://app-web.database.url &lt;span class=&quot;nt&quot;&gt;--app&lt;/span&gt; app-worker&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Now I’ll have to deploy to both app. Something like this should do it&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  git remote add app-worker git@heroku.com:app-worker.git &lt;span class=&quot;c&quot;&gt;# one time only, add app-worker to git&lt;/span&gt;
  git push heroku &lt;span class=&quot;o&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; git push heroku-worker &lt;span class=&quot;c&quot;&gt;# deploy to both&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Heroku will spin down idle web dyno. Worker dyno should be up all the time. I didn’t specifically test this out, but from &lt;a href=&quot;https://devcenter.heroku.com/articles/dynos#dyno-idling&quot;&gt;https://devcenter.heroku.com/articles/dynos#dyno-idling&lt;/a&gt; it only talks about web dyno. And so far all my jobs are completed.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Steal Java Web App Source Code From Apache Tomcat 6.0.16</title>
   <link href="http://ar.zu.my/steal-java-web-app-source-from-tomcat-6-0-16"/>
   <updated>2011-08-03T00:00:00+00:00</updated>
   <id>http://ar.zu.my/steal-java-web-app-source-from-tomcat-6-0-16</id>
   <content type="html">&lt;p&gt;&lt;small&gt;03 August 2011&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;There I was minding my own business, browsing few sites when I got this 404 error:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;HTTP Status 404 - /innocent/doesnotexists

type Status report
message /innocent/doesnotexists
description The requested resource (/innocent/doesnotexists) is not available.

Apache Tomcat/6.0.16
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;I saw 404s all the time it’s not even funny. Instinctively I just want to hit back, but then I saw &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Apache Tomcat/6.0.16&lt;/code&gt;. This particular version was released on 8th February 2008. 3 years ago. Interesting. Maybe, there’s something we can do here.&lt;/p&gt;

&lt;p&gt;I’m not familiar with Apache Tomcat at all, and I don’t code Java. Maybe it’s a good time to learn then. First thing is just to search for Apache Tomcat/6.0.16 vulnerabilities. The lowest hanging fruit was Directory Traversal, &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2938&quot;&gt;CVE-2008-2938&lt;/a&gt;. It was stated in &lt;a href=&quot;http://tomcat.apache.org/security-6.html&quot;&gt;official Apache Tomcat 6 vulnerabilities page&lt;/a&gt; that the root cause of this vulnerability is JVM, not Tomcat itself. But whatever, it seems simple enough, worth a shot.&lt;/p&gt;

&lt;p&gt;This entry on Security Tracker: &lt;a href=&quot;http://securitytracker.com/id/1020665&quot;&gt;Tomcat UTF-8 ‘AllowLinking’ Java Bug Lets Remote Users Traverse the Directory&lt;/a&gt; shows how to exploit this. You just need encoded dots &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;%c0%ae%c0%ae&lt;/code&gt; which represents &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;..&lt;/code&gt;. Seems a no brainer.&lt;/p&gt;

&lt;p&gt;Ok, so now we know we probably could download files. But we don’t know what file we want to pull. Time to learn about Java and Tomcat.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://oreilly.com/java/archive/tomcat.html&quot;&gt;Deploying Web Applications to Tomcat&lt;/a&gt; from O’Reilly shows us exactly that. It was a post from 2001, but quick check on other search results showed that the deployment hasn’t changed much. The most interesting part was on &lt;a href=&quot;http://oreilly.com/pub/a/java/archive/tomcat.html?page=5&quot;&gt;page 5&lt;/a&gt; where we learned that Java Web App file would be packaged to a single &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.war&lt;/code&gt; file and stored in the web app’s directory. Wait, does that mean we can just download &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.war&lt;/code&gt; file and we would get the complete source code of the app? Really?&lt;/p&gt;

&lt;p&gt;I guess there’s only one way to find out then.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  wget &lt;span class=&quot;s1&quot;&gt;'http://example.com/innocent/%c0%ae%c0%ae/innocent.war'&lt;/span&gt;
    
  Output
  &lt;span class=&quot;nt&quot;&gt;--REMOVED--&lt;/span&gt;  http://example.com/innocent/%c0%ae%c0%ae/innocent.war
  Connecting to example.com... connected.
  HTTP request sent, awaiting response... 200 OK
  Length: 91599064 &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;87M&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt;
  Saving to: &lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;innocent.war&lt;span class=&quot;s1&quot;&gt;'

  2% [==&amp;gt;                                                         ] 2,206,947    728K/s&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Nice. Now to extract the package we can use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;jar&lt;/code&gt; command.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  jar xvf innocent.war&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That will extract everything to current directory. While it is nice to see everything is in there, we can’t do anything much because all the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.class&lt;/code&gt; file are unreadable to human being. There are many decompilers out there. Back then I used &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;jad&lt;/code&gt; but it’s no longer being maintained. Mirror download available from &lt;a href=&quot;http://www.varaneckas.com/jad/&quot;&gt;http://www.varaneckas.com/jad/&lt;/a&gt;. Today I just downloaded &lt;a href=&quot;http://java.decompiler.free.fr/?q=jdgui&quot;&gt;JD-GUI&lt;/a&gt;, that works too.&lt;/p&gt;

&lt;p&gt;UPDATE: This will decompile &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.class&lt;/code&gt; to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.java&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;src&lt;/code&gt; directory using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;jad&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  find &lt;span class=&quot;nb&quot;&gt;.&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-iname&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;*.class&quot;&lt;/span&gt; | xargs /path/to/jad &lt;span class=&quot;nt&quot;&gt;-r&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-sjava&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-d&lt;/span&gt; src
  &lt;span class=&quot;nb&quot;&gt;cd &lt;/span&gt;src&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
</content>
 </entry>
 
 <entry>
   <title>Shared Session Cookies Gotchas</title>
   <link href="http://ar.zu.my/shared-sessions-cookies-gotchas"/>
   <updated>2011-06-28T00:00:00+00:00</updated>
   <id>http://ar.zu.my/shared-sessions-cookies-gotchas</id>
   <content type="html">&lt;p&gt;&lt;small&gt;28 June 2011&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally posted in &lt;a href=&quot;https://www.facebook.com/groups/rails.my.english/doc/10150213012561848/&quot;&gt;Ruby on Rails - Malaysia (English)&lt;/a&gt; group.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Today I made a mistake. I pushed a line of code that effectively made the users can neither login nor logout. So I thought I’d shared the problem and solution with you guys&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Intention&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We want the session cookie to be shared within the subdomain. For example, forum.domain.com could access session cookie from www.domain.com. This allows seamless integration between multiple apps.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How-to&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It’s easy to achieve that. You’ll just have to modify &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;config/initializers/session_store.rb&lt;/code&gt; and add &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;:domain&lt;/code&gt; option. Like so,&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;no&quot;&gt;MyApp&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Application&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;config&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;session_store&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:cookie_store&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'_my_app_session'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:domain&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;.domain.com&quot;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That works, but it’s not so cool since you’ll have to hardcode domain name. Better solution would be to use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;:all&lt;/code&gt; value&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;no&quot;&gt;MyApp&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Application&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;config&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;session_store&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:cookie_store&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'_my_app_session'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:domain&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:all&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That will make session cookie’s host to be .domain.com or if your domain is google.com, it’ll be .google.com. Cookie’s host will follow what ever you current domain.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;They are two major problems when you deploy the code. First, current users now locked to their current session state. If they are logged in, they can’t logout and vice versa. This happens because we now have two session cookies with same name &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_my_app_session&lt;/code&gt; but with a different host. And when you have that situation, cookie with matching host will take precedence. Hence, we are reading the old cookie (the one with host www.domain.com) which is wrong, so our session is messed up.&lt;/p&gt;

&lt;p&gt;The user could fix this by clearing up the browser’s cookies. But that’s totally uncool. Also, this won’t affect the new user, so that, on the other hand, is cool.&lt;/p&gt;

&lt;p&gt;The second problem is when working on the development environment, visiting http://localhost:3000 won’t work. Because we are expecting the cookie host to be .localhost but it’s always saved as localhost. It will always be invalid.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The solution is obvious, you just need to delete the old cookie and just read the new one. But somehow the implementation wasn’t that obvious to me at first. My first option was to add a line of code that will delete the old cookie. It works, but it’s not good because it’ll be a stale code after a while. That line will never be used once all old cookies delete, and never used on for users.&lt;/p&gt;

&lt;p&gt;I’ve searched high and low for a better solution when it suddenly hits me. I don’t need to delete the old cookie, I just need to make sure the app won’t read it. Just invalidate the old cookie. Since I have a conflicted name, why don’t just change the name? So I did, and it works like a charm. My new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;session_store.rb&lt;/code&gt; looks like this:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;no&quot;&gt;MyApp&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Application&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;config&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;session_store&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:cookie_store&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'_new_my_app_session'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:domain&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:all&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;For second problem, a quick workaround is to not use localhost. Use alias like app.local, local.my etc. Or just make sure shared domain not used in development mode, like so:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;  &lt;span class=&quot;no&quot;&gt;MyApp&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;::&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;Application&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;config&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;session_store&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:cookie_store&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:key&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;'_new_my_app_session'&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:domain&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;Rails&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;development?&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;?&lt;/span&gt; &lt;span class=&quot;kp&quot;&gt;nil&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;ss&quot;&gt;:all&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;That’s about it. Now the app runs smoothly for old and new users.&lt;/p&gt;

&lt;p&gt;Cheers!&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>How To Quickly Search Your Terminal History</title>
   <link href="http://ar.zu.my/how-to-quickly-search-your-terminal-history"/>
   <updated>2011-01-01T00:00:00+00:00</updated>
   <id>http://ar.zu.my/how-to-quickly-search-your-terminal-history</id>
   <content type="html">&lt;p&gt;&lt;small&gt;Early 2011&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;One of a benefit of pair programming is you got to learn things that you don’t even know you need to learn. When I paired with &lt;a href=&quot;http://mmazur.com/&quot;&gt;Mike Mazur&lt;/a&gt;, one of the &lt;a href=&quot;http://pivotallabs.com/&quot;&gt;Pivotal Labs&lt;/a&gt;&lt;sup id=&quot;fnref:fn-neo&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:fn-neo&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt; engineer, I got to learn a very useful trick.&lt;/p&gt;

&lt;p&gt;When I want to refer to commands that I’ve used before, I’d do this:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;nb&quot;&gt;history&lt;/span&gt; | &lt;span class=&quot;nb&quot;&gt;grep &lt;/span&gt;previous_command&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Then I’d cut and paste the result to execute. Not ideal, but it worked for me. Because I didn’t know better.&lt;/p&gt;

&lt;p&gt;Until he showed me the right way of doing it. Comes reverse-i-search. All you need to do is press &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ctrl + r&lt;/code&gt; in terminal and start typing the command you want to search for. For example, I want to search for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;server&lt;/code&gt;:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  ctrl + r
  serv
  &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;reverse-i-search&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;sb&quot;&gt;`&lt;/span&gt;serv&lt;span class=&quot;s1&quot;&gt;': jekyll --server --auto&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;If that’s not the command you looking for, just keep tapping &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ctrl + r&lt;/code&gt; until you find the right one. Then just press &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;enter&lt;/code&gt; to execute. Handy!&lt;/p&gt;

&lt;p&gt;Also, it would be better if you increase your history size. Just add these lines to your profile file, one of those &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.bashrc&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.bash_profile&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.profile&lt;/code&gt;.&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  &lt;span class=&quot;nv&quot;&gt;HISTFILESIZE&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;1000000000
  &lt;span class=&quot;nv&quot;&gt;HISTSIZE&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;1000000&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;The size is up to you, I got those values from &lt;a href=&quot;http://lifehacker.com/278888/ctrl%252Br-to-search-and-other-terminal-history-tricks&quot;&gt;lifehacker&lt;/a&gt;.&lt;/p&gt;

&lt;div class=&quot;footnotes&quot; role=&quot;doc-endnotes&quot;&gt;
  &lt;ol&gt;
    &lt;li id=&quot;fn:fn-neo&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;Now called &lt;a href=&quot;http://neo.com&quot;&gt;Neo&lt;/a&gt; &lt;a href=&quot;#fnref:fn-neo&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
  &lt;/ol&gt;
&lt;/div&gt;
</content>
 </entry>
 
 <entry>
   <title>Python Simple HTTP Server</title>
   <link href="http://ar.zu.my/python-simple-http-server"/>
   <updated>2010-09-03T00:00:00+00:00</updated>
   <id>http://ar.zu.my/python-simple-http-server</id>
   <content type="html">&lt;p&gt;&lt;small&gt;03 September 2010&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;Every now and then I need to serve something over HTTP. Most of the times, it was to test out JavaScript with callbacks. It won’t run by double clicking the sample HTML file, you need to serve everything.&lt;/p&gt;

&lt;p&gt;With python simple HTTP server, all I need to do is just drop in the directory and run:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  python &lt;span class=&quot;nt&quot;&gt;-m&lt;/span&gt; SimpleHTTPServer

  Output:
  Serving HTTP on 0.0.0.0 port 8000 ...&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;It will start HTTP server on default port 8000. To use other port, just add the port number:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-bash&quot; data-lang=&quot;bash&quot;&gt;  python &lt;span class=&quot;nt&quot;&gt;-m&lt;/span&gt; SimpleHTTPServer 8001

  Output:
  Serving HTTP on 0.0.0.0 port 8001 ...&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Head up to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;http://localhost:8001&lt;/code&gt; to view it. Simple, easy, straight to the point.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>The Day I Got My First Email Account</title>
   <link href="http://ar.zu.my/the-day-i-got-my-first-email-account"/>
   <updated>1998-01-01T00:00:00+00:00</updated>
   <id>http://ar.zu.my/the-day-i-got-my-first-email-account</id>
   <content type="html">&lt;p&gt;&lt;small&gt;Circa 1998, probably beginning of the year&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;From 1994 to 1998 I had limited access to a computer. I was in a boarding school up North, and computer class wasn’t part of the curriculum. It didn’t bother me much at that time because I was busy harnessing up physical hacking skill. I’ll write more about that.&lt;/p&gt;

&lt;p&gt;We did have a computer lab back then. It’s outdated and used by few student clubs to print out their newsletters. To my knowledge, there was no other use than that. Only in 1998 the lab reopened to the students and refurnished with new machines. And get this, Internet connection included! Fun!&lt;/p&gt;

&lt;p&gt;But we didn’t get to use it! Computer class was only for students in Form 1 to Form 3. Nothing for Form 5. Which was fine at that moment, I didn’t think much about it. Until one day, I saw my friend wrote down &lt;em&gt;somecoolhandle@hotmail.com&lt;/em&gt; in fiery typeface on the table. Yes, it’s was an obvious association, &lt;em&gt;fire&lt;/em&gt; and &lt;em&gt;hot&lt;/em&gt;mail. I think the conversation went something like this:&lt;/p&gt;

&lt;p&gt;“Hey, what’s that?”&lt;br /&gt;
“My email. Cool eh!”&lt;br /&gt;
“Email? What’s that?” &lt;br /&gt;
“You can send mail to other people, on COMPUTER!” &lt;br /&gt;
“What? You can do that? That’s so cool man. Where can I get one?” &lt;br /&gt;
“Register on the Internet. It’s free.”&lt;br /&gt;
“What? It’s free? I want! I want!”&lt;/p&gt;

&lt;p&gt;&lt;em&gt;* Okay, maybe it wasn’t much like that, but you got my point.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Later that day I summoned one of the junior students who was good with the computer. He knew a lot about the Internet. I asked him to get me a &lt;a href=&quot;http://en.wikipedia.org/wiki/Hotmail&quot;&gt;Hotmail&lt;/a&gt; account. He did it the next day during his computer class. I don’t remember what was his name, I also don’t remember what was my first Hotmail username. In fact, I don’t remember if I ever used it.&lt;/p&gt;

&lt;p&gt;That was how I got my first email account, not fancy at all. I wasn’t even in front of the computer when it happened.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>The Hack That Changed My World</title>
   <link href="http://ar.zu.my/the-hack-that-changed-my-world"/>
   <updated>1993-01-01T00:00:00+00:00</updated>
   <id>http://ar.zu.my/the-hack-that-changed-my-world</id>
   <content type="html">&lt;p&gt;&lt;small&gt;Circa 1993, probably end of the year&lt;/small&gt;&lt;/p&gt;

&lt;p&gt;By this time, computers weren’t something new to me. I knew my way around them. But like any other kid, a computer was just a slick gaming machine. Nothing more.&lt;/p&gt;

&lt;p&gt;Few years back the school did teach us how to code. At that time, I didn’t realize what it meant. To me, coding was just an activity that you do with the machine. Much like playing games. I did not know the real potential.&lt;/p&gt;

&lt;p&gt;Imagine my surprise when I found out that I could get the machine to do what I want.&lt;/p&gt;

&lt;p&gt;My uncle brought back a machine. I don’t remember what the model was, but I’m pretty sure it was running &lt;a href=&quot;http://en.wikipedia.org/wiki/Windows_3.1x&quot;&gt;Microsoft Windows 3.1&lt;/a&gt; because I remember the &lt;a href=&quot;http://en.wikipedia.org/wiki/File_Manager_%28Windows%29&quot;&gt;File Manager&lt;/a&gt;. There was a game called &lt;a href=&quot;http://en.wikipedia.org/wiki/First_Samurai_%28video_game%29&quot;&gt;First Samurai&lt;/a&gt;. I spent almost all my time in front of the machine, playing First Samurai, maybe Minesweeper once in a while :). After a while, I started to get bored. Mainly because of the endless repetition of the same thing from one level to the next (or maybe because I got stuck in one level).&lt;/p&gt;

&lt;p&gt;One day, instead of playing games, I sat there and browsed around with File Manager. Nothing made sense much to me. But somehow I found myself staring at First Samurai’s directory. I started to poke around. There was a file that looks impressive, it was a config file or maybe flat file database. Inside that file, there was something that resembled current game level status. I don’t remember the exact details. But when I changed the level number inside that file and started the game, I saw an entirely new level loaded up!&lt;/p&gt;

&lt;p&gt;What!? Was that for real?&lt;/p&gt;

&lt;p&gt;That was the aha! moment for me. To understand the real potential. It wasn’t just about the game, at that moment I knew that this can be done on anything in the machine. I could make them do what I want.&lt;/p&gt;

&lt;p&gt;And at that moment too, something snapped. I completely lost interest in playing computer games. The gamer was gone. A hacker was born.&lt;/p&gt;
</content>
 </entry>
 
</feed>