INFO-LINK




Shell Corner: Safely Sharing Screen Sessions with sudo


UnixReview.com
March 2006

Shell Corner: Safely Sharing Screen Sessions with sudo

Hosted by Ed Schaefer
Written by Rod Knowlton

Listing 1: sh_screen

This month, Rod Knowlton addresses a sudo security problem that John Spurgeon and I introduced in our "Using Screen in Scripts" column. Rod describes the problem as "small"; we feel he's being too kind.

Safely Sharing Screen Sessions with Sudo
by Rod Knowlton

A while ago, Ed and John Spurgeon published an article in Sys Admin magazine on the use of screen in scripts. Within the article, there was a small problem with the section on using sudo to share screens— it would give anyone using the shared session the ability to create a shell running as root!

Since just one compromised machine is one too many, I dashed off an email to Ed explaining the bug and including a possible way to mitigate it. In this article, I'll describe a couple of tempting but insecure methods for easing the work of sharing screen sessions, reveal their faults, and then present a set of scripts that act together to provide a safe, easy to use alternative.

The goal and original problem

Ed and John's script was meant to make life simpler for the casual screen user. Rather than having screen installed setuid and having the users learn the various screen commands related to sharing screens, they would use sudo to run a script with root privileges. The script would either create a screen session with the requested name and force them into a shell under their own id, or, if a session by that name already existed, attach them to it.

The original code (don't do this):

 #!/bin/ksh
 # path: /usr/local/bin/share_screen

screen_name=${1:-share_screen}

if ! /usr/local/bin/screen -x "$screen_name" then /usr/local/bin/screen -S "$screen_name" \ /usr/local/bin/ssh $(logname)@$(uname -n) fi # end script

The security problem arose from the fact that, although the shell the user is presented with is under her own id, the instance of screen is running as root. This means that any time screen's internal command screen (Ctrl-A,c, by default) is issued, the new window created will have a root shell.

A First Pass at a Fix

Here's the fix I emailed to Ed (you probably shouldn't do this, either):

 #!bin/ksh
 # path: /usr/local/bin/share_screen

screen_name=${1:-share_screen}

if ! /usr/local/bin/screen -x "$screen_name" then

# start the session detached, so we can send a # command to it before the user logs in /usr/local/bin/screen -m -d -S "$screen_name" \ /usr/local/bin/ssh $(logname)@$(uname -n)

# disallow multiple windows. Using the "-X" option # allows us to do this without having to manipulate # or replace any ..screenrc files. /usr/local/bin/screen -S "$screen_name" -X maxwin 1

# now attach /usr/local/bin/screen -x "$screen_name"

fi

# end share_screen

As is probably clear from the comments, the idea was to give the screen the internal command maxwin 1 at startup so that additional windows could not be created.

While this fix addresses the problem identified, it still has a couple of problems. The screen invocations still hold root privileges, and the login shell that is shared will allow anyone connecting to operate with the privileges of the user that first created it.

What Was the Question?

I've shown the two approaches not to use partly because they contain methods that will show up in the final fix, but mostly to help illustrate something to keep in mind when scripting — be sure you're answering the right question.

My fix addressed the question "How can a shared screen session running as root prevent users from creating a root shell?", but that's not the question on which I should have been focused. The right question is the one Ed and John were trying to answer: "How can users share screens without learning commands and without screen being setuid root?"

A New Approach

The best (if not the only) way to keep users from creating a root shell is simply to avoid running screen as root. We could create a dummy user with restricted permissions and have the shared_screen users use sudo -u dummy shared_screen so that new shells will only have the dummy's privileges, but that doesn't address the problem of all the sharing users being able to work with the creator's privileges in the inner ssh shell.

Setting screen to setuid root would enable mult-iuser commands, but we really want to keep setuid root programs to a minimum. We'll abstract away the multiuser commands in a script so the users don't have to deal with them, and we'll use sudo to make screen setuid, but only at launch time.

You'll notice in all of the following scripts that I'm using fully qualified pathnames for all executables used. This is always a good idea when scripting, but is especially important when root privileges are in play. Another good idea, for portability, is to create a configuration file and assign all of the executables' pathnames to read-only constants, like so:

 typeset -r SCREEN=/usr/local/bin/screen
 export SCREEN
Each script can then load the configuration file via the dot operator and use the constants rather than hard-coded pathnames, like so:
 #!/bin/ksh
 #
 . /usr/local/bin/ssconfig
 ${SCREEN} -x "foo"
I'm not doing this here because I feel code examples are often clearer without that extra level of indirection, but if you want to install these scripts on machines with varying directory structures, you'll probably want to consider it. setuid_screen...strike that...sh_screen Let's create a script that sets setuid on screen, launches screen with all arguments it was passed, and then removes setuid from screen. Since we don't want to wait for screen to return before removing setuid, we'll send ourselves a little "message in a bottle" to get the job done, like so:
 #!/bin/ksh
 #
 # sh_screen - launches screen setuid and
 #             then switches it back
 #
 # path: /usr/local/bin/sh_screen
 # this file should be chmod 700, owned by root

 /bin/chmod +s /usr/bin/screen      # adjust paths to fit your system

 # the message in a bottle
 (/bin/sleep 1;/bin/chmod -s /usr/bin/screen) &

 #while the message floats, launch screen as the login user

 /usr/bin/sudo -u $(/usr/bin/logname) /usr/bin/screen $*

 # wait for the background process to finish
 wait

 # end sh_screen
Sharp-eyed readers probably noticed that this script introduces a race condition, in that it's dependent on the sudo invocation of screen completing before the background process removes setuid. You can check whether the race condition is affecting you by executing sudo ./sh_screen under your non-root login. If all went well, you'll find your screen session socket in /tmp/screens/S-username/, otherwise it'll be in /tmp/uscreens/S-username/, which indicates that screen was not setuid root when launched. If the latter is the case, you may need to increase the sleep parameter. A Wrapper Script for sh_screen While security by obscurity alone is no security, adding obscurity to a process that is already secure by other means does increase the security of the process. To this end, in addition to limiting user access to sh_screen via the /etc/sudoers file, we'll launch sh_screen from a wrapper script like so:
 #!/bin/ksh
 #
 # sscreen - wrapper script for sudo'ing sh_screen
 #
 # path: /usr/local/bin/sscreen
 # this file should be chmod 755, owned by root

 /usr/bin/sudo /usr/local/bin/sh_screen $*

 # end sscreen
This accomplishes two things: it simplifies usage for the end user, as they don't have to remember or even know that sudo is involved; and it allows us to assign root ownership and owner-only read, write, and execute permissions to sh_screen. Cranking down the permissions on sh_screen means that even an end user that we've allowed to run it can't read it in search of ways to exploit it. I'm sure you noticed that I changed the name of the script from the more informative setuid_screen to sh_screen before I started this section. This is because a name like setuid_screen, even if the user can't read the script, might be a little too tempting to some. A Couple of Helpers Now we're almost ready to revisit the original script and use our new tools to make it a little safer to use. But, there are a couple of issues we'll have to deal with that weren't present when all sessions ran as root. The first issue is that viewers will have to be explicitly invited by the creator. To make this simpler for the creator, we'll take advantage of the fact that by default screen checks to see if it's being run from inside a copy of itself and, if it is, acts on that copy rather than creating a whole new instance. To allow read-only viewers to attach to your session, you need to add them with acladd and then restrict their access with aclchg. We'll do all of these things from within a single sudo script. Adding a viewer:
 #!/bin/ksh
 #
 # ss_addviewer - grant a user read-only access to an
 #                sscreen session from within that session
 #
 # path: /usr/local/bin/ss_addviewer
 # this file should be chmod 700, owned by root

 SSCREEN=/usr/local/bin/sscreen

 if [[ "${STY} = "" ]]
 then
  # we're not in an sscreen session
  echo "This script is only meant to run from"
  echo "within an existing sscreen session"
  exit
 fi

 read "username?User to add: "

 # make sure we're in multiuser mode
 ${SSCREEN} -X multiuser on

 # screen makes you add a full privileged user, then subtract
 # privileges
 ${SSCREEN} -X acladd ${username}

 # take away the ability to type in the session
 # and to execute screen commands
 ${SSCREEN} -X aclchg ${username} -w-x '#?'

 # give them the right to detach (Ctrl-A, d)
 ${SSCREEN} -X aclchg ${username} +x detach

 # end ss_addviewer
ss_addviewer's user-friendly wrapper:
 #!/bin/ksh
 #
 # ssallow - sudo wrapper for ss_adduser
 #
 # path: /usr/local/bin/ssallow
 # this file should be chmod 755, owned by root

 /usr/bin/sudo /usr/local/bin/ss_addviewer

 # end ssallow
The second issue is that each user's screen sockets are stored in a directory that only that user can access. This means we'll need a sudo run script if we want to list sessions that are already established. This isn't strictly necessary, since the creator can tell the viewer(s) the name of the session when they add them, but it'll be nice to have in case someone forgets what they were told. List sessions:
 #!/bin/ksh
 #
 # ss_listsessions - list established sscreen sessions
 #
 # path: /usr/local/bin/ss_listsessions
 # this file should be chmod 700, owned by root

 /usr/bin/find /tmp/screens -type p \
| /bin/sed 's/^.*screens\/S-//;s/\/.*\./\//'

 # end ss_listsessions
And its wrapper:
 #!/bin/ksh
 #
 # ssls - sudo wrapper for ss_listsessions
 #
 # path: /usr/local/bin/ssls
 # this file should be chmod 755, owned by root

 /usr/bin/sudo /usr/local/bin/ss_listsessions

 # end ssls
Everything Old is New Again Now it's time to put together our new shared_screen script, which actually looks a lot like the original:
 #!/bin/ksh
 #
 # shared_screen - safely share screen sessions
 #
 # path: /usr/local/bin/shared_screen
 # this file should be chmod 755

 screen_name=${1:-share_screen}

 if ! /usr/local/bin/sscreen -x '${screen_name}'
 then
 /usr/local/bin/sscreen -S ${screen_name##*/}
 fi
 # end shared_screen
Configuration and Use To allow Manny, Moe, and Jack to use the shared_screen scripts, we'll use visudo to add the following lines to our /etc/sudoers file. There's no need for us to include the wrapper scripts, only the three "wrapped" scripts:
 User_Alias     SSUSERS = manny, moe, jack
 Cmnd_Alias     SSCOMMANDS = /usr/local/bin/sh_screen, \
                          /usr/local/bin/ss_addviewer, \
                          /usr/local/bin/ss_listsessions

 SSUSERS    ALL = SSCOMMANDS
Now if Manny wants to start up a session named "service" and let Moe and Jack view it, he does as follows:
 [manny ~] shared_screen service
 Password: ********
 (sscreen starts0
 [manny ~] ssallow
 User to add: moe
 [manny ~] ssallow
 User to add: jack
Manny then tells Moe and Jack the name of the session, so they can attach to it like so:
 [moe ~] shared_screen manny/service
 Password: ********
or if they've forgotten the name:
 [jack ~] ssls
 Password: ********
 manny/service
 otheruser/otherscreen
Conclusion

While slightly more complicated than the original, this approach provides three huge advantages. It doesn't require the user to remember to use sudo or to issue screen commands directly. It doesn't leave screen sitting around setuid root all of the time. And it doesn't involve working inside of a session that's actually owned by root.

Note: The -X option used in this article is only present in newer versions of screen. If you have trouble using these scripts, try upgrading to a version of screen >= 4.0 (some 3.9.x versions also support it)

Rod Knowlton is an IBM Certified Advanced Technical Expert in AIX and a Senior Unix Systems Administrator for a large midwestern insurance company. An inveterate geek, his idea of a good time is learning a new programming language. His favorite time of all, though, is any time spent in the company of his best friend and wife, Amanda Shankle-Knowlton. He can be reached at rod.knowlton@gmail.com.


Around the Web

An Events Based Algorithm for Distributing Concurrent Tasks on Multi-Core Architectures

Here's a programming model which enables scalable parallel performance on multi-core shared memory architectures.

Quick Read

Swarm: A True Distributed Programming Language

The Swarm prototype is a simple stack-based language, akin to a primitive version of the Java bytecode interpreter.

Quick Read

Key Software Development Trends

Several trends are emerging within the area of software development. Here are some of the most important trends S. Somasegar has been thinking about recently.

Quick Read

Understanding Parallel Performance

Understanding parallel performance. How do you know when good is good enough?

Quick Read

Short and Tweet: Experiments on Recommending Content from Information Streams

The authors used 12 algorithms to study the URL recommendation on Twitter as a means of better directing attention in information streams.

Quick Read



Video

Forty finalists will gather in Washington, D.C. from March 11-16 to compete for $630,000 in awards.; DDJ; Intel; science; Dr. Dobb's talks with Commonsware's Mark Murphy about what's involved in developing software for the Android operating system; Android; apple; DDJ; tablet development; The new method uses analytics technology developed by the Mayo and IBM collaboration, Medical Imaging Informatics Innovation Center, and has proven a 95 percent accuracy rate in detecting aneurysm.; Algorithm; DDJ; diagnostics; ibm; imaging; T-Mobile USA is enabling phone calls to Haiti without charges for international long distance through January 31 and retroactive to the earthquake on January 12; DDJ; mobile; wireless; Al Williams gives you a demor of One-Der: The One Instruction CPU; DDJ; At the 2010 International Consumer Electronics Show, the auto industry's first working smartphone application was unveiled; DDJ; mobile; The Bluetooth Special Interest Group (SIG) has announced the adoption of BLUETOOTH low energy wireless technology.; bluetooth; DDJ; wireless; IBM has unveiled its list of five innovations that have the potential to change how people live, work and play in cities around the world over the next five to ten years; DDJ; ibm; TeliaSonera's LTE mobile broadband commercial network in Stockholm is now the fastest and largest in the world.; broadband; DDJ; ericsson; mobile; Google has introduced, google Goggles, a visual search application on Android devices that allows users to search for objects using images rather than words; Android; DDJ; google; mobile; Visual Search Applications; Dr. Dobb's talks with David Intersimone, Vice President of Developer Relations and Chief Evangelist at Embarcadero Technologies, about RAD Studio 2010, SQL optimization and his reflections on the software industry.; database programming; DDJ; sql; Researchers from Intel Labs have created an experimental, 48-core Intel processor or "single-chip cloud computer."; cloud computing; DDJ; Intel; multicore; parallelism; The Large Hadron Collider will produce roughly 15 million gigabytes of data annually, to be accessed by a distributed computing and data storage infrastructure called the LHC Computing Grid.; CERN; DDJ; grid computing; physics; A mobile handheld device designed to let users can point, shoot and listen to printed text.; DDJ; Intel; mobile; Ericsson has become the first vendor to prove end to end interoperability in TD-LTE, another standard of 4G radio technologies designed to increase the capacity and speed of mobile telephone networks.; DDJ; ericsson; mobile; TD-LTE; According to a recent study, 80 percent of US respondents feel there are unspoken rules about mobile technology usage, and approximately 69 percent agreed that violations of these unspoken mobile manners are unacceptable.; DDJ; Intel; mobile; IBM and Canonical will introduce a software package for netbooks and other thin client devices in Africa. This is the first cloud- and premise-based Linux netbook software package offered by IBM and Canonical.; cloud computing; DDJ; ibm; His unprecedented ability to manipulate individual atoms signaled a quantum leap forward in in nanoscience experimentation and heralded in the age of nanotechnology.; DDJ; ibm; nanotechnology; IBM honored for its invention of the Blue Gene family of supercomputers. Adobe founders also recognized.; adobe; DDJ; ibm; Former U.S. President Bill Clinton addressed thousands of online entrepreneurs from around the world gathered for the third APEC Business Advisory Council SME Summit in Hangzhou, China.; DDJ; e-business; With free cooling for several months a year, Sweden is an ideal location for cost-efficient data centers.; data centers; DDJ; PNC Bank introduces a new mobile App for the iPhone and iPod touch that provides Virtual Wallet customers with a high-def view of their money while on the go.; DDJ; iphone; The Swedish LTE site will be part of a commercial network scheduled to go live in 2010, bringing data rates far above what is possible in today's mobile broadband networks.; DDJ; ericsson; mobile broadband; Nanotechnology advancement could lead to smaller, faster, more energy efficient computer chips.; circuit boards; DDJ; nanotech; semiconductor; Dr Dobbs talks with with Claudia Backus, Senior Director of Ecosystem Programs at Motorola, regarding the company's recently released MotoDEV Studio for their Android-powered phones.; Android; DDJ; mobile; motodev; The Extremadura Regional Government of Spain and IBM have launched an electronic prescription system in 680 pharmacies in western Spain.; DDJ; ibm; Ericsson to Acquire Majority of Nortel's North American Wireless Business; DDJ; ericsson; mobile; telecom; Nintendo's Wii Sports Resort is an immersive, expansive active-play game that includes a dozen resort-themed activities.; DDJ; nintendo; video games; OnStar can remotely send a signal to the electronic system in the subscriber's stolen vehicle and the vehicle will not be able to be re-started.; cellular; DDJ; wireless; In celebration of the historic Apollo Moon landing, Google has released Moon in Google Earth.; DDJ; google; Ericsson has been awarded contracts with the three telecom operators in China to provide fixed broadband access.; broadband; DDJ; mobile; tv; wireless; Dr. Dobb's talks with Adobe's Adam Lehman about the upcoming release of ColdFusion specifically optimized for Flash and Adobe AIR platform delivery.; adobe; ColdFusion; DDJ; eclipse; Companies team to develop computing device and chipset architectures that will combine the performance of powerful computers with high-bandwidth mobile broadband communications and ubiquitous Internet connectivity.; broadband; DDJ; Intel; mobile; nokia; Adobe Systems and HTC recently announced that the new HTC Hero will be the first Android phone to ship with support for Adobe Flash Platform technology.; adobe; Android; cell phones; DDJ; flash; mobile; mobility; 3.2 million Euros awarded across eight prize categorie recognizing world-class scientific research and artistic creation.; DDJ; A parody of Paul Simon's "50 Ways to Leave Your Lover," but for software security nerds.; DDJ; sql; Dr. Dobb's Mike Riley talks with Jim Manias of Advanced Systems Concepts.  In this conversation, Jim discusses the new ActiveBatch 7 and how it can provide significant productivity gains for application developers and business process owners alike.; ActiveBatch; DDJ; Sun cofounder Scott McNealy and Oracle CEO Larry Ellison discussed Java's role in computing. Sun has also released OpenSolaris 2009.06.; DDJ; java; opensolaris; oracle; sun; Spotlight on NATO's centre of excellence on cyber defense in Tallinn, Estonia.; cyber defense; DDJ; nework security; security; Create Data Access Layers in ASP.NET; DDJ; In this demonstration you will learn how to layout a WPF application. We will explore the major layout panels that come with WPF, contrasting them with each other and describing when to use each.; DDJ; web development; windows; wpf; The Intel Foundation has announced the top winners of the Intel International Science and Engineering Fair; DDJ; Intel; News; science; Matt Hester demonstrates Internet Explorer’s 8 new feature Selectors API for utilizing CSS selectors for quick and easy element lookups.; DDJ; IE8; microsoft; windows; The NATO Virtual Silk Highway provides affordable, high-speed Internet access via satellite to the academic communities of the Caucasus and Central Asia.; DDJ; On a Windows Mobile device, applications are typically not closed down, but they stay in the background. Maarten Struys shows you a simple way to preserve battery power inside your own applications.; DDJ; microsoft; power consumption; windows; Windows Mobile Devices; Cadillac is now offering wireless Internet access with its CTS sedan.; DDJ; wireless broadband; By default, Windows Mobile Standard (Smartphone) applications launched from Visual Studio are not accessible on the device/emulator once they are minimized. In this video, Jim Wilson demonstrates two simple techniques to solve the problem.; DDJ; microsoft; smartphone; VIsual Studio; Mike Riley talks with the brass from Everypoint, creators of the NEMO mobile application development platform.; DDJ; Developers; development environments; mobile applications; Symmetric and asymmetric encryption algorithms, the SHA256 hash encryption algorithms, and how to implement in a simple application using Microsoft's Azure Services Platform.; Azure; DDJ; encryption; microsoft; security; windows; T-Mobile has introduced the Sidekick LX, which features enhanced video capability.; DDJ; Mobile Smartphone; Bluetooth 3.0 offers speedier transmission of large amounts of video, music and photos between devices wirelessly.; bluetooth; DDJ; mobile networks; wireless broadband; Cities around the world are battling with stressed transportation networks, so IBM has announced plans for three new smart rail projects in China, Taiwan and The Netherlands.; DDJ; ibm; ILOG; CASMOBOT is a Nintendo Wii remote controlled slope lawn mower.; DDJ; Denmark; nintendo wii; research; robotics; Project ensures documents, images, video and other Internet-based data growing at over 100 terabytes per month will live on for future generations; data storage; DDJ; history; Intenet; research; Sun Microsystems; Dr. Dobb's talks with Dave McAllister, Director of Standards and Open Source for Adobe, about the Open Screen Project.; adobe; DDJ; Open Screen Project; open source; The Facebook Connect SDK provides the code to let third-party developers embed hooks into their applications so users can connect to their Facebook accounts and exchange information using iPhone apps.; apple; cocoa; DDJ; Facebook; iphone; Mars in Google Earth Updated; DDJ; google; google earth; Google mars; red planet; The Sun Cloud is built on the Sun Open Cloud Platform that leverages the best in world-class open source technologies. The Sun Open Cloud Platform brings together Java, MySQL, OpenSolaris and OpenStorage.; cloud computing; DDJ; java; open solaris; sun; DDJ; High School; Intel; science; ILOG Elixir is a suite of professional user interface controls that gives developers a rich collection of innovative and interactive data display components for Adobe Flex and Adobe Air.; adobe; air; DDJ; elixir; flash; flex; ILOG; The inaugural San Diego Science Festival being held this month is touted as one of the largest multicultural, multigenerational, multidisciplinary celebrations of science ever seen on the West Coast; DDJ; lockheed; News; science; IBM has announced Innov8 version 2, a new version of its serious game that helps students and professionals hone their business and technology skills in a compelling, familiar video game format.; DDJ; ibm; serious games; Swiss Automobile Visionary Frank M. Rinderknecht builds a concept car with adaptive energy concept and iPhone controls.; apple; Concept Car; DDJ; iphone; j; siemens; Two-Year Plan to Focus on 32 Nanometer Manufacturing Technology; 32 nanometer technology; chip; cpu; DDJ; gpu; Intel; manufacturing; Nehalem; Westmere; New version features ocean layer, historical imagery, and more.; DDJ; google; Dr. Dobb's talks with Marty Alchin, author of "Pro Django" about his book and the deep internals of the Django framework.; DDJ; Django; A new content-authoring solution for learning professionals; adobe; DDJ; toolkits; web authoring; In a Second Life setting, Danny Coward discusses Java FX with Dr. Dobb's Jon Erickson.; DDJ; java; JavaFX; sun; The Core i7 processor is the first member of a new family of Nehalem processor designs with new technologies that boost performance on demand.; chip; DDJ; Intel; processors; Dan Diephouse, creator of XFire, a high-performance open-source SOAP framework (which became the Apache CXF project), shares the five common mistakes in SOA governance and insight about the Apache CXF and Mule RESTpack development environments.; apache; Apache CXF; DDJ; mule; open source; soa; soap; Xfire; Adrian Kaehler and Gary Bradski discuss the Open Computer Vision Library (sourceforge.net/projects/opencvlibrary/) and their book "Learning OpenCV".; DDJ; Open Computer Vision Library; OpenCV; In the first part of this two-part interview, Stephen Wolfram reflects on the 20-year anniversary of Wolfram Research.; DDJ; Mathematica; Mathematics; science; In the second part of this two-part interview, Stephen Wolfram discusses his book "A New Kind of Science."; DDJ; Mathematica; Mathematics; science; Nick Hodges talks about Delphi 2009, a RAD tool for Windows, and Delphi Prism, a database engine for Windows, Mac OS X, and Linux.; DDJ; delphi; RAD; windows; Dr. Dobb's talks with Tony Lombardo, lead Technical Evangelist at Infragistics, about all new UI tools for Windows and .NET.; .net; DDJ; silverlight; ui; windows; wpf; Dr. Dobb's talks with Eric Schulz about his International Mathematica User's Conference 2008 presentation on the Mathematica Essentials Palette and the future digital educational material; DDJ; Mathematica; Mathematics; Dr. Dobb's talks with ActiveState's Trent Mick about the recently released Komodo IDE 5.0.; DDJ; ide; open source; Dr. Dobb's talks with Continuity Logic's Kris Carlson about "Why We Die: Simulation of the Evolution of Senescence" and why he programs with Mathematica's functional programming language.; DDJ; functional programming; Mathematica; simulation; Ericsson collaborates with Intel; DDJ; ericsson; Intel; Mobile technology; Dr. Dobb's talks with Schoeller Porter about the grid and cloud versions of Mathematica; clouds; DDJ; Grid; Mathematica; Dr Dobb's interviews Yehuda Katz, maintainer of the Merb project, about the advantages this highly optimized Ruby on Rails alternative offers to web application developers.; DDJ; Ruby on Rails; Dr. Dobb's talks with Thomas Roman, Professor of Mathematics at Central Connecticut State University, about "Mathematica Visualization in a Theoretical Physics Problem - Negative Energy in an Unusual Quantum State."; DDJ; Mathematica; physics; quantum; science; The Forbidden City: Beyond Space & Time is a fully immersive, three-dimensional virtual world that recreates a visceral sense of space and time.; Blade Server; China; DDJ; ibm; linux; mac; online; virtual world; windows; Dr. Dobb's interviews open source luminary Miguel de Icaza about his latest milestone of achieving Microsoft .NET 2.0 Framework compatibility with the Mono Project .; DDJ; Dr. Dobb/s interviews Paul Kimmel, author of "LINQ Unleashed for C#", about Microsoft's new query technology that lets developers poll any information from any data source regardless of location or structure. I; C#; DDJ; Dr. Dobb's; LINQ; microsoft; It takes a supercomputer to build a super car. ; DDJ; HPC; simulation; Dr. Dobb's shows how to install and execute cross-platform scripting languages on the Windows Mobile platform. In this installment, Mike Riley examines Perl for Windows Mobile devices.; DDJ; mobile devices; perl; windows; Dr. Dobb's shows how to install and execute cross-platform scripting languages on the Windows Mobile platform. In this installment, Mike Riley examines Python CE which is optimized for Windows Mobile devices.; DDJ; mobile devices; python; windows; Dr. Dobb's shows how to install and execute cross-platform scripting languages on the Windows Mobile platform. In this installment, Mike Riley examines Ruby for Windows Mobile devices.; DDJ; mobile devices; ruby; windows; Young participants at ITU TELECOM ASIA 2008 in Bangkok, Thailand received free laptops as part of ITU’s initiative to promote affordable devices to increase access to information and communication technologies.; communication; DDJ; itu; Currently technical strategist to Microsoft's Chief Software Architect, Rebecca Norlander has had a tremendous impact on Excel, Internet Explorer, Windows XP SP2, and Windows Vista Security. ; DDJ; microsoft; Contributing authors to the book "Beautiful Code" got together at Dr. Dobb's SD West Conference in March, 2008. Part 1 of 3.; DDJ; programming; software development; Contributing authors to the book "Beautiful Code" got together at Dr. Dobb's SD West Conference in March, 2008. Part 2 of 3.; DDJ; programming; software development; Contributing authors to the book "Beautiful Code" got together at Dr. Dobb's SD West Conference in March, 2008. Part 3 of 3.; DDJ; programming; software development; Anders Hejlsberg discusses C#, Turbo Pascal, and what it means to design a programming language. ; C#; DDJ; microsoft; Turbo Pascal; Solar powered laptops given to youths at ITU Asia 2008.; DDJ; News; telecommunications; IBM breakthrough stands to impact future direction of information technology.; DDJ; Mike Riley spoke to ActiveState's Jeff Hobbes about the new features in Tcl Dev Kit and Perl Dev Kit including the code coverage and hot-spot analysis tool and Mac OSX support.; DDJ; Tim O'Reilly addressed the OSCON convention in his Wednesday keynote titled "Degrees of Freedom, Open Source in the Wed 2.0 Era.; DDJ;


Enabling People and Organizations to Harness the Transformative Power of Technology