News: 1591600507

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ooo, a mystery bit of script! Seems legit. Let's see what happens when we run it

(2020/06/08)


Who, Me? Monday is upon us, and with it another confession from a Register reader to make one consider one's own programming choices in the latest entry of our [1]Who, Me? saga.

This week's tale comes from a person we'll call "Chris" and is set in the closing years of the last century, back when Windows 95 first introduced an uncertain world to the Start button and Donald Trump was just that guy eyeing up the Miss Universe pageants with a view to making a purchase.

Chris spent the mid-1990s working for a UK law firm as a senior developer on a case and document management system. Being a clever sort, he was tapped to whip up a quick script to schedule a letter to be sent to the firm's customers, advising them of a change in bank details.

Bite me? It's 'byte', and that acronym is Binary Interface Transfer Code Handler [2]READ MORE

"The letter was duly written," he told us, "and a quick five-line script knocked together and run to send it out."

It all went swimmingly and, as with many little ad-hoc scripts, was promptly forgotten about by all involved. "For a few months at least," said Chris, ominously.

And it was indeed a few months later that there was a knock on the door of the office that housed Chris's team. Did the gang have any idea why the outgoing mail batch was a good deal larger than expected?

"The system," Chris remembered, "had a virtual outgoing mail tray, and the post room used to batch-select and run them on one of the Xerox Docuprint monsters of the time, the printers so big they came with their own Sun workstation and rattled out upwards of 130ppm."

Indeed, the Xerox behemoths were quite the thing back in the day. The DocuPrint 135, for example, could churn out up to 1.5 million pages a month and had a capacity of 6,900 sheets. Enough for a forgotten bit of script to spew out all manner of paperwork.

Chris and a chum duly trotted off to the post room to investigate: "Lo and behold, there were a good few thousand more prints than they'd usually expect, with another few thousand still in the mail queue."

He glanced at the mail queue and saw, to his horror, a very familiar-looking change of bank details letter. "Oops."

"Turns out," he said, "someone on our processing team had found a script without a descriptive name, and ran it to see what it would do."

Because, of course, anyone using a computer and finding a mystery bit of code is going to simply run it and see what happens, aren't they? [3]Just like a kid and an all too attractive flashing button before them . Of course they will.

Chris was not entirely blameless. In the hurry to write the script, he hadn't bothered with niceties such as prompts, warnings or anything to indicate the paper-based devastation that was about to happen.

The curious operator simply ran the file, saw a brief hourglass flicker on the screen, and then moved on, "blissfully unaware that they'd just engaged a mass of document-production servers to start filling the mail trays."

Chris was tediously honest and professional and, rather than attempt to direct the blame elsewhere, confessed immediately to being the author of the ream-munching script. The luckless operator was also tracked down and given a stern talking to.

It was, however, those in the post room that, undeservedly, received the worst of the punishment. Genuine mail had to be separated from the thousands and thousands bank-change letters vomited out by a combination of Chris's script and the Xerox machinery.

"Safe to say," he said, "never again have I written a batch script without a decent name and a 'Are you sure you wish to proceed?' message."

Ever seen a mystery batch file and thought "I wonder what will happen if I run this?" Or left an innocuous bit of script lying around that later caused mayhem to unfold? Of course you have – send your confession to [4]Who, Me? for absolution or, at the very least, a pseudonym. ®

Sponsored: [5]The Forrester New Wave™: Public Cloud Enterprise Container Platforms, Q3 2019



[1] https://www.theregister.com/Tag/who-me

[2] https://www.theregister.com/2020/06/01/who_me/

[3] https://www.theregister.com/2020/06/05/on_call/

[4] https://www.theregister.co.uk/cdn-cgi/l/email-protection#483f2027252d083c202d3a2d2f213b3c2d3a662b27663d23

[5] https://go.theregister.com/tl/1956/-8475/the-forrester-new-wave-public-cloud-enterprise-container-platforms-q3-2019?td=wptl1956

Last time my car stalled...

redpawn

in the rain next to an abandoned mansion. We decided to go in to spend the night. Later that night my partner found a secret passage leading underground, while an electrical storm raged outside. Naturally we went down. There we found a coffin. After a short discussion we decided to open it. Contained within was a vampire and a thumb drive. The vampire and my partner both perished.

Should I plug the drive into my personal computer or a company server?

Re: Last time my car stalled...

Headley_Grange

Only if you've got the cage with the bird in it.

Re: Last time my car stalled...

Evil Auditor

Should I plug the drive into my personal computer or a company server?

What a question?! Obviously, you plug it into the personal computer of that colleague of yours.

Re: Last time my car stalled...

9Rune5

If they allow you physical access to the company servers, they probably WANT you to plug it in there.

Let your conscience be your guide.

Re: Last time my car stalled...

Sgt_Oddball

Was the coffin surrounded by Das Blinken Lights? Any chance the vampire answered to the name 'Richmond'?

Enquiring minds and all that...

Re: Last time my car stalled...

Tinslave_the_Barelegged

Was the vampire throwing chairs?

Re: Last time my car stalled...

Bibbit

Did your dead partner have a laptop you could use?

Efficacy of warning messages

Mast1

Ah but then you have to choose the correct wording in your warning-before-you-proceed message.

Consider a Win2k system that detects errors in your filing system, and it helpfully offers to "repair" it for you.

"Yes", this naive person clicked.

Cue a screenful of helpful lines reporting what it found wrong.

Cue a 30GB disc fragged into same-sized chunk with helpful names such as filexxxxx,frag where

1 < xxxxx < infinity

Yes, definitely naive in believing the "warning-before-you-proceed" message.

Re: Efficacy of warning messages

9Rune5

Cue a 30GB disc fragged into same-sized chunk with helpful names such as filexxxxx,frag where

That sounds like FAT to me. Never had such calamities with NTFS, except that time I was using a slightly faulty drive (with early onset dementia).

In any case, what was the alternative (to pressing 'yes, fix it')? As I recall, with FAT chkdsk would produce those files when it found clusters marked as used, with no directory entries pointing to them. If the original directory entry happened to be in a now-deleted directory, the cluster containing that directory could very well have been overwritten and since released. Pretty much a fool's errand to piece it all together.

OTOH, IIRC each cluster entry (in the allocation table) would point to the next cluster. So chkdsk could've checked "is the next cluster in use by a different file by now..?" and made a more educated guess. If caught early, the next cluster would most likely still be intact. I'm a bit surprised that chkdsk did not do that for you. (you mentioned the files all had the same size, presumably reflecting the cluster size)

OK, asked differently: Was there any chance that you would have researched this deeper, used a different computer to download a better tool and done this properly? (basically the original disk should've been put in forensics read/only mode to not corrupt it further)

Re: Efficacy of warning messages

Mast1

Yes, FAT. As I said : naive. I thought M$ had provided a seemingly useful tool, and I was not officially in IT support.

Not so naive that I had not backed up all my data after previous uses. Not so true of the other users of that same computer (a data collection machine, off network to reduce response latency).

Re: Efficacy of warning messages

Peter Simpson 1

Live and learn :-)

Anonymous Coward

I can honestly say no, I have never just run a script or piece of code without having an idea of what its *supposed* to do. Whether or not it actually did what was expected is a slightly different story.

But on the printer front, back in days of old, someone crossed out a note in a shift hand-over that said "DON'T print the output from this particular stock control run". No-one on the evening shift questioned it, so when I came in on the nightshift we just plodded on. Queue several thousand pages of fan-fold paper (printed on an old LP3000 printer - those of you old enough to remember will know what a pain in the proverbial that can be stacking paper). What a fun shift that was (only 2 of us in that night). The meeting with the Ops Manager was also a hoot when I pointed out what had happened and that it wasn't my fault.

Eyeing up ... with a view to making a purchase

Warm Braw

Presumably secured with a small deposit.

El blissett

Sure I have, but never on a networked machine.

Of course, if someone I know emailed me with a touching romantic executable message in the 90s, I guess I'd run that at work just to see what it was as well.

Could have been worse

Anonymous Coward

A friend worked at a large bank which decided to send a mailshot to their most important (i.e. wealthy) clientele. Due to an error in the script that resulted in each of these people receiving a letter addressed to "Dear ,"

Re: Could have been worse

Alister

Ah-huh...

[1]https://www.snopes.com/fact-check/dear-rich-bastard/

[1] https://www.snopes.com/fact-check/dear-rich-bastard/

Not quite the same...

GlenP

I did on one occasion use a provided script on a database running on a VAX 11/780. Knowing it would take a long time to provide the relevant analysis I left it running over the weekend, Monday morning I found 3 boxes of fanfold printer paper on my desk so around 5,000 pages. I hadn't noticed that log switch in the script was turned on so it had printed every analysis action before finally giving the summary I was after, the operators just assumed it was deliberate and allowed the print to complete.

I wasn't short of scrap paper in the office for the rest of my time in the role but couldn't take it home to reuse as it was Government data (albeit very low level).

Re: Not quite the same...

H in The Hague

"I hadn't noticed that log switch in the script was turned on so it had printed every analysis action ..."

A loooong time ago, in the days of punched cards, a friend of mine did a project at uni. Unfortunately he hadn't formatted the output properly. So, instead of using all 80 columns of a card his program only used one, massively increasing the number of cards needed. Apparently after his program had gone through the third box of cards, the operators cancelled his job.

Re: Not quite the same...

Doctor Syntax

Similar vintage a friend got the Fortran control characters wrong so it threw a new page instead of a new line. To make matters worse when he was taking it home on the back of his motor-bike it unfolded itself behind him.

Not a script but...

phy445

A long, long time ago in an East London outpost of the University of London I took a Fortran 77 module (course). The computers used were BBC Micros with 32 bit coprocessor attached via the Tube (interface, not the mass transport system or TV show). It ran a multiuser system with some sort of per user access privileges. One day I noticed that someone who should have know better had left without logging out–or rebooting, which was the quicker option in those days of ROM based OS's. I couldn't resist "playing" with the higher access privileges...after a bit of tinkering I discovered "add student" did what you might expect and a couple of "test" users with mature, innuendo free, names such as Ivor Biggun were added. At the end of the session I decided to undo my actions and tried "delete student" unfortunately it turned out that this deleted the login credentials of students. Queue swift exit...

Are you sure ...

Blofeld's Cat

... 'Are you sure you wish to proceed?' ...

I now add multiple prompts, each detailing precisely what is about to happen. This usually triggers the following sequence:

1 System prompts 'Are you sure you wish to proceed?'

2 User enters yes / clicks proceed

3 Repeat 1 and 2 until no more prompts

4 System produces hourglass

5 System removes hourglass.

6 User wonders what happened.

7 User wonders what the prompts said

8 User rings support to ask where their files / database have gone.

9 BOFH orders more carpet and quicklime.

Monster printers

MarkET

Worked for Rank Xerox on the Euston Road many years ago - the ground floor was basically the print 'room'. Remember the huge printers. Later worked for a well known Telecoms provider who ran a number of chain printers churning out bills...such a sweet sound...

Re: Monster printers

jake

Amdahl had a largish printing facility just off Central Expressway in Sunnyvale (Cupertino?) in the 1980s. Virtually every mainframe print-job generated within the company, world-wide, was printed at said facility, and then next-dayed to whatever office had requested the print job. They had several gawdawfulfast channel attached printers, and a fleet of trucks delivering & sending out paper. Was awesome to watch in full-swing, if you had adequate ear protection.

However ... it sounded daft then, and still sounds daft now.

I can honestly say that ...

jake

... no, I have never run a script without first understanding what it did ... at least not on production systems, nor personal systems that were important to me. Same for strange executables.

There is a reason for test systems. This is one of them. Anybody who doesn't understand this concept shouldn't have a level of access that can cause damage. They are quite simply not trustworthy.

Re: I can honestly say that ...

A.P. Veening

As long as they do it on their own, personal system it comes under the heading SEP.

Re: There is a reason for test systems

Pascal Monett

There absolutely is. Except that there are companies that can't be arsed to have one. And I still have to go in and create functionality on the production server, because they need that functionality. So I go and code in production. Extra carefully.

Even then, I have had the odd phone call or abrupt face-to-face with a guy who asks me why did the mainframe do this supplementary job ? I answer "because I was told to put this file there".

Cue much anguish about how he needed to go and sort the mess out on his side. And now I have to continue coding without being able to actually test my code because if I do, I've just learned that another system will take that as a cue to go and do its thing, which nobody told me was going to happen.

You live and learn. That's life.

If at first you don't succeed...

Anonymous Custard

He should just think himself lucky that the normal response didn't kick in when it just did a quick hour glass change.

I've known many who would just sit there trying it again and again, presumably expecting something different or more enlightening to happen at some point. I think the record I've seen is something tried 25 times.

Opening batch files

Captain Scarlet

Tbh yes in Notepad++ if I find some, I have come across a lot especially if a system with software has been migrated several times.

Actually found some very helpful bits nosing around batch files from near enough 2000!

Descriptive names can still be enticing

Michael H.F. Wilkinson

Way back when in the days I was coding MS-DOS machines for image processing, I wrote two (harmless) programs that simply trapped interupt 9 (keyboard), discarded keyboard input, and did nothing except blink the screen and say the computer has crashed. Only a hard reset worked. I called these two variant HANG.EXE and CRASH.EXE. Everyone had to try them at least omce

Re: Descriptive names can still be enticing

MarkET

Int 21H, function (AH) 9

Alister

One of our developers wrote a windows service which polled a database once a second, and if for some reason it didn't get the answer it was looking for, he set it to send himself an email. Unfortunately, he didn't put in any code to see if it had already sent a previous email.

He deployed the code on a Friday afternoon (a big no-no in itself).

Later on the Friday evening, some other part of the project wrote an incorrect value into the database. So his bit of cheap and nasty code started sending error emails, once a second.

I got paged on Sunday morning because our SpamTitan spam blocker had finally had enough, and got a bad case of indigestion with 140,000 emails in its queue. It took me a while to identify where all these emails were coming from, and kill the offending service.

The developer was given a royal bollocking on Monday morning.

There was once a programmer who was attached to the court of the
warlord of Wu. The warlord asked the programmer: "Which is easier to design:
an accounting package or an operating system?"
"An operating system," replied the programmer.
The warlord uttered an exclamation of disbelief. "Surely an
accounting package is trivial next to the complexity of an operating
system," he said.
"Not so," said the programmer, "when designing an accounting package,
the programmer operates as a mediator between people having different ideas:
how it must operate, how its reports must appear, and how it must conform to
the tax laws. By contrast, an operating system is not limited my outside
appearances. When designing an operating system, the programmer seeks the
simplest harmony between machine and ideas. This is why an operating system
is easier to design."
The warlord of Wu nodded and smiled. "That is all good and well, but
which is easier to debug?"
The programmer made no reply.
-- Geoffrey James, "The Tao of Programming"