Monday, July 19, 2010

gPXE and the HTTP server that could

eBox 1.4 has support for serving a bootfile over TFTP.

Only it's broken. Oops.

Here's my quick fix:
sudo nano /etc/inetd.conf

Code:
tftp           dgram   udp     wait    root  /usr/sbin/in.tftpd /usr/sbin/in.tftpd -s /var/lib/tftpboot

That /var/lib/tftpboot is where tftp will serve files from.
eBox expects it to be serving a file such as:
/var/lib/ebox/conf/dhcp/eth0/firmware

Code:
tftp           dgram   udp     wait    root  /usr/sbin/in.tftpd /usr/sbin/in.tftpd -s /var/lib/ebox/conf/dhcp/eth0

Now when you 'upload' a new boot file to eBox's dashboard,
/var/lib/ebox/conf/dhcp/ethX/firmware
gets replaced with whatever you've uploaded.

But eBox won't set the dhcp-option 'filename' to serve it.

sudo nano /usr/share/ebox/stubs/dhcp/subnet.mas

Look for
Code:
% if(defined($info{'nextServer'})) {
                next-server <% $info{'nextServer'} %>;
% }
% if(defined($info{'filename'})) {
                filename "<% $info{'filename'} %>";
% }

And change it to

Code:
% if(defined($info{'nextServer'})) {
                next-server <% $info{'nextServer'} %>;
                # Filename entry added by Kamilion (dec 01 2009)
                filename firmware;
% }
% if(defined($info{'filename'})) {
                filename "<% $info{'filename'} %>";
% }

Now we need something to boot.

Go pick up the latest gPXE from here:
http://www.rom-o-matic.net/gpxe/gpxe-git/gpxe.git/contrib/rom-o-matic/build.php

Click Customize.

Change the following Settings:

[X] DOWNLOAD_PROTO_HTTPS
[X] DOWNLOAD_PROTO_FTP

[X] TIME_CMD
[X] DIGEST_CMD

And paste in the following Embedded Script: (Good base, but edit if you wish)
Code:
#!gpxe
echo "Greetings! Hit Ctrl-C to bail out."
sleep 5
echo "Going to DHCP on primary network adapter"
ifopen net0
dhcp net0
echo "Going to try http://netboot/default.gpxe"
chain http://netboot/default.gpxe
echo "Didn't work, we're still here. Falling back to http://boot/default.gpxe"
chain http://boot/default.gpxe
echo "Didn't work, we're still here. Falling back to BKO"
set 209:string pxelinux.cfg/default
set 210:string http://boot.kernel.org/bko/
echo "Here we go, off to boot.kernel.org!"
chain http://boot.kernel.org/bko/pxelinux.0
echo "Didn't work, we're still here. No Internet connection? Falling back to next BIOS Boot device"

You should get a single .pxe file back after clicking Get Image.

Go to DHCP -> Interface -> Advanced Options -> Thin Client.
Settings:
Next server: eBox
File Name [browse]
File path in next server:

Click "Change" to complete the settings, then Save Changes.

Place this file in the root of your HTTP server, named default.gpxe, and create a DNS alias to that machine named 'netboot'.

Code:
#!gpxe
imgfree
chain http://netboot/boot/menu.gpxe

Here's an example you can use to load Parted Magic:

Code:
#!gpxe
imgfree
kernel -n img http://bigblock/boot/pmagic/4.5/bzImage load_ramdisk=1 prompt_ramdisk=0 keymap=us loglevel=0 rw sleep=4
initrd http://bigblock/boot/pmagic/4.5/initramfs
boot img

Here's an example you can use to boot from iSCSI.

Code:
#!gpxe
imgfree
#dhcp net0
set keep-san 1
sanboot iscsi:10.10.10.250::::iqn.bigblock:storage.iscsikarmic-one
chain http://10.10.10.250/boot/iscsi.gpxe

More examples here: http://boot.sllabs.com/boot/

Friday, July 16, 2010

How to use u3-tool in Lucid

As my few blog visitors may be aware, I've been using the U3 customizer for windows for a long time on my 4GB cruzers to make them bootable.

http://blog.sllabs.com/2008/05/booting-heron-from-u3.html


I came across the u3-tool sometime ago when I bought my Clarion MiND, but I've only actually used it recently.

The U3 Customizer tools were released somewhere in 2005 and won't work in anything but windows XP 32bit, and won't recognize U3s over 8GB.



Gonzor discovered TwinMOS's application version supported Larger drives, Vista, and was released in 2007. However, the copy from TwinMOS didn't work for me -- and yet Gonzor's copy from mediafire did, both are version 1.0.5.5

I just bought an open-box 16GB Contour EXtreme with AES from newegg for $40, and it came yesterday.

So I started searching on how to hack a 16GB U3 drive.

"Oh, right, u3-tool... Almost forgot about that!"

In searching for 'how to use u3-tool', I ran across ubuntu launchpad bug report #534070 and played around a little.

I had some issues trying to get the windows version to work, I could resize the CD domain, but 'burning' the ISO failed consistently at 4-5% with a scsi error.

In Ubuntu Lucid, you can just 'sudo apt-get install u3-tool' but:
I was *NOT* able to get /dev/sg* or /dev/sr* to work -- I had to address the disk device itself as /dev/sdf to get it to work.

Hope this helps others out, as I think the major problem people are having is trying to use one of the /dev/sg like the u3-tool help text mentions.

Here's the log of the CD domain resize and burn I ran.

kamilion@SonyRA840G:~$ sudo u3-tool -i /dev/sdf
Total device size:   14.95 GB (16051601408 bytes)
CD size:             7.69 MB (8060928 bytes)
Data partition size: 14.94 GB (16043474944 bytes)
kamilion@SonyRA840G:~$ sudo u3-tool -l UbuntuLucid3264.iso /dev/sdf
CD image(1874288640 byte) is to big for current cd partition(8060928 byte), please repartition device.
kamilion@SonyRA840G:~$ sudo u3-tool -p 1874288640 /dev/sdf

WARNING: Loading a new cd image causes the whole device to be whiped. This INCLUDES
 the data partition.
I repeat: ANY EXCISTING DATA WILL BE LOST!

Are you sure you want to continue? [yn] y
kamilion@SonyRA840G:~$ sudo u3-tool -l UbuntuLucid3264.iso /dev/sdf
|**************************************************| 100%
OK

kamilion@SonyRA840G:~$ sudo u3-tool -i /dev/sdf
Total device size:   14.95 GB (16051601408 bytes)
CD size:             1.75 GB (1874329600 bytes)
Data partition size: 13.20 GB (14177271808 bytes)

After I changed the ISO, I also had to open Disk Utility (palimpsest), "Format the Disk"  to create a new MBR geometry, and then create a new NTFS partition.
(Which I've subsequently copied Windows 7's bootmgr to the root of the flash partition and ran "bootsect /nt60 U:", then copied the contents of the 7 install cd to the flash)
Both sections of the device are now bootable, the CD boots ubuntu lucid 32/64 TORAM=Yes, and the flash boots the 7 preinstallation environment.


(Yeah, I know the picture's screwed up -- I'll edit the blogspot CSS later.)

So that all worked just fine for me. Hope it does for you, too!

(And for the person who emailed me to ask about the background... It's from SSDD.)

Wednesday, June 9, 2010

Fun with nginx, upstart, and lucid

Howdy boys and girls!

Today we'll be mangling us some web.

I've started off by installing a fresh copy of Ubuntu Lucid Server in Virtualbox 3.2.4. Mind, if you're using a Linux host, turn *ON* host caching in the "SATA Controller" if your host's using EXT4 as the filesystem your VDIs are stored on, otherwise it will try to use AIO and corrupt your VDIs. The host kernel needs a patch to fix this, but neither karmic or lucid have it, apparently. Anyway.

The Core System

For my first act, I've shuttled over my SSH public keys so I can use my agent to login.

ssh kamilion@laptop # Say no or ^C to make empty ~/.ssh dir with proper perms!
scp kamilion@laptop:/home/kamilion/.ssh/authorized_keys ~/.ssh/authorized_keys
tee -a /etc/ssh/sshd_config <<-\EOA

# No passwords! Get bent, crackers!
PasswordAuthentication no
EOA

For my second act, I've tossed a couple of the more useful utilities on. (python-software-properties gives you "add-apt-repository ppa:freenx-team" shortcuts)

sudo apt-get install python-software-properties dnsutils openssh-server denyhosts screen htop rsync nethogs sqlite3

Make *sure* you add your REAL origin IPs to /etc/hosts.allow

tee -a /etc/hosts.allow <<-\EOA

sshd: 10.0.0.5
sshd: 24.48.64.128
EOA
AND edit /etc/denyhosts.conf to enable blocklist sync.

nano /etc/denyhosts

At the bottom, you need to uncomment: SYNC_SERVER, SYNC_DOWNLOAD, SYNC_DOWNLOAD_THRESHOLD = 10, and SYNC_DOWNLOAD_RESILIENCY = 2d
then:
/etc/init.d/denyhosts restart

This will sync the ssh blocklists from the denyhosts server.
Uncomment SYNC_UPLOAD too, please contribute your stats!

(Yes, I know this is pointless after shutting off password auth, but BETTER SAFE THAN SORRY.)

Virtual Machines

If you're using a VM, this might be handy:

sudo apt-get install build-essential dkms
sudo rm /etc/init/tty[2-6].conf  #Disable other TTYs because this is a VM.

The virtualbox guest additions will use dkms to build the guest kernel modules automatically.

You can select the Install Guest Additions from the vbox menu to insert the ISO into the cdrom.

/media/cdrom/autorun.sh

The Webserver

Now we'll install nginx.

sudo apt-get install nginx

And set it up to startup on boot with upstart.
The prestart tests the config; handy!

sudo tee /etc/init/nginx.conf <<-\EOA
# /etc/init/nginx.conf
# nginx - starts the nginx webserver

description "nginx"

start on (net-device-up and local-filesystems)
stop on runlevel [016]

pre-start exec /usr/sbin/nginx -t

expect fork
respawn
exec /usr/sbin/nginx
EOA


Now you should be able to

start nginx

and check port 80 for the default "Welcome to nginx!" response.

Right -- so this is served out of /var/www/ by default and controlled from /etc/nginx/ in such a manner that you dump config stanzas into a file in /etc/nginx/sites-available/ and link them as such:

sudo ln -s /etc/nginx/sites-available/fqdn.com /etc/nginx/sites-enabled/fqdn.com && sudo service nginx reload

you should get a working vhost with a proper config.

So, we're now capable of serving static pages, what else can we do?

Let's check which modules and defaults our nginx was compiled with:

nginx -V

nginx version: nginx/0.7.65
TLS SNI support enabled
configure arguments: --conf-path=/etc/nginx/nginx.conf --error-log-path=/var/log/nginx/error.log --pid-path=/var/run/nginx.pid --lock-path=/var/lock/nginx.lock --http-log-path=/var/log/nginx/access.log --http-client-body-temp-path=/var/lib/nginx/body --http-proxy-temp-path=/var/lib/nginx/proxy --http-fastcgi-temp-path=/var/lib/nginx/fastcgi --with-debug --with-http_stub_status_module --with-http_flv_module --with-http_ssl_module --with-http_dav_module --with-http_gzip_static_module --with-http_realip_module --with-mail --with-mail_ssl_module --with-ipv6 --add-module=/build/buildd/nginx-0.7.65/modules/nginx-upstream-fair

Looks like we've got fastcgi, DAV, FLV streaming, gzip and mail-proxy by default.

Installing PHP5

Now for PHP5.

sudo apt-get install php5-cgi php5-mysql php5-pgsql php5-sqlite php5-suhosin php5-imap php5-mcrypt php5-gd # php5-gd is usually needed

# security disclosure risk: shut php up -- hide version!
sudo sed -i '/expose_php/s/\;exp/exp/;/expose_php/s/=.*/= 0/' /etc/php5/cgi/php.ini
grep 'expose_php' /etc/php5/cgi/php.ini

sudo tee /etc/init/php-fastcgi.conf <<-\EOA
# /etc/init/php-fastcgi.conf
# php-fastcgi - starts php-cgi as an external FASTCGI process

description "php-fastcgi - respawning UNIX Socket"

start on (net-device-up and local-filesystems)
stop on runlevel [!2345]

expect fork
respawn
exec /usr/bin/sudo -u www-data PHP_FCGI_CHILDREN=5 PHP_FCGI_MAX_REQUESTS=125 /usr/bin/php-cgi -q -b /tmp/php-fastcgi.socket
EOA

Okay, now to start it.

start php-fastcgi

PHP5 FastCGI for nginx

Now you'll need an nginx config.

Here's one of my templates:

# Enable with
# sudo ln -s /etc/nginx/sites-available/fqdn.com /etc/nginx/sites-enabled/fqdn.com && sudo service nginx reload

server {
        listen                  80;
        server_name             fqdn.com www.fqdn.com;
        access_log              /var/www/fqdn.com/log/access.log;
        error_log               /var/www/fqdn.com/log/error.log;

        location / {
                root            /var/www/fqdn.com/public/;
                index           index.php index.html;
                }

        location ~ \.php$ {
                fastcgi_pass    unix:/tmp/php-fastcgi.socket;
                fastcgi_index   index.php;
                fastcgi_param   SCRIPT_FILENAME /var/www/fqdn.com/public$fastcgi_script_name;
                include         fastcgi_params;
                }
        }

### Redirect www to root domain?
#server {
#       listen                  80;
#       server_name             www.fqdn.com;
#       rewrite                 ^/(.*) http://fqdn.com/$1 permanent;
#       }

### Redirect root domain to www?
#server {
#       listen                  80;
#       server_name             fqdn.com;
#       rewrite                 ^/(.*) http://www.fqdn.com/$1 permanent;
#       }

### HTTPS server
#server {
#       listen                  443;
#       server_name             fqdn.com;
#       ssl                     on;
#       ssl_certificate         /var/www/fqdn.com/private/cert.pem;
#       ssl_certificate_key     /var/www/fqdn.com/private/cert.key;
#       ssl_session_timeout     5m;
#       ssl_protocols           SSLv2 SSLv3 TLSv1;
#       ssl_ciphers             ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP;
#       ssl_prefer_server_ciphers       on;
#       access_log              /var/www/fqdn.com/log/secure.access.log;
#       error_log               /var/www/fqdn.com/log/secure.error.log;
#       location / {
#               root            /var/www/fqdn.com/public/;
#               index           index.php index.html;
#               }
#       location ~ \.php$ {
#               fastcgi_pass    unix:/tmp/php-fastcgi.socket;
#               fastcgi_index   index.php;
#               fastcgi_param   SCRIPT_FILENAME /var/www/fqdn.com/public$fastcgi_script_name;
#               include         fastcgi_params;
#               }
#       }



The Database

Okay, let's move on and install a real database. Doesn't really matter which you choose. I'm gonna go with mysql for now so we can use phpmyadmin later.

sudo apt-get install mysql-server

Enter your new mysql root password twice.



Now for phpmyadmin.

sudo apt-get install phpmyadmin

It'll ask which server you want to configure it for -- leave both apache2 and lighttpd disabled and continue. Yes, we want to use dbconfig-common. Enter your mysql root password for the first one; then just hit enter to have phpmyadmin generate it's own account and random password.

sudo tee /etc/nginx/sites-available/phpmyadmin <<-\EOA
# Enable with
# sudo ln -s /etc/nginx/sites-available/phpmyadmin /etc/nginx/sites-enabled/phpmyadmin && sudo service nginx reload
server {
        listen 80 default;
        server_name localhost;
        access_log /var/www/apps/logs/phpmyadmin.access.log;
        error_log /var/www/apps/logs/phpmyadmin.error.log;

        location / {
            root /usr/share/phpmyadmin;
            index index.php;
            }

        location ~ \.php$ {
            include /etc/nginx/fastcgi_params;
            fastcgi_pass unix:/tmp/php-fastcgi.socket; #127.0.0.1:9000;
            fastcgi_index index.php;
            fastcgi_param SCRIPT_FILENAME /usr/share/phpmyadmin$fastcgi_script_name;
            }
        location /nginx_status {
            # copied from http://blog.kovyrin.net/2006/04/29/monitoring-nginx-with-rrdtool/
            stub_status on;
            access_log   off;
            allow 24.48.64.128; # Home
            allow 10.0.0.5; # Work
            deny all;
            }

        }
EOA

Make some empty logdirs or nginx will go splat when it can't access them.

mkdir -p /var/www/apps/logs/
chown -R www-data.www-data /var/www/apps/logs/

Kill the pesky default site now that we have phpmyadmin. (yes, "reload nginx" is a command. Nifty, huh? The magic of Upstart!)

ln -s /etc/nginx/sites-available/phpmyadmin /etc/nginx/sites-enabled/phpmyadmin
rm  /etc/nginx/sites-enabled/default
reload nginx


You should now be able to access phpmyadmin and login with root/mysqlpass.
phpmyadmin also can synchronize two mysql instances now, as well.


Additional Information and Tricks

SSH tunnels are your friend! Sync DBs over ssh with phpmyadmin!
ssh -vg -L 8080:localhost:80 -R 33306:mysql-server.home:3306 user@fqdn.com

firefox http://localhost:8080/server_synchronize.php

replace mysql-server.home with whatever hostname/ip has the mysqld instance you wish to sync with. You can pick any port instead of 33306, just make sure you tell phpmyadmin to look at "localhost" on that port.

You can clone whole servers too!
push.sh:
#/bin/bash
rsync -azvv -e ssh /var/www/ root@fqdn.com:/var/www/
rsync -azvv -e ssh /etc/nginx/ root@fqdn.com:/etc/nginx/


pull.sh:
#!/bin/bash
rsync -azvv -e ssh root@fqdn.com:/etc/nginx/ /etc/nginx/
rsync -azvv -e ssh root@fqdn.com:/var/www/ /var/www/



Want a remote mini-desktop? This'll take a couple minutes.
add-apt-repository ppa:freenx-team
apt-get install freenx-server firefox gnome-core synaptic

Boom, grab the nxclient.

Now, go forth and serve pages!

Tuesday, June 8, 2010

Goodbye [DB], Hello Crunchyroll!

To [DB]:

Thanks for almost five years of quality entertainment.
Because you guys and guys like you subbed all this time, we now have legal ways to get our fix. I just signed up with crunchyroll -- they've got a $20 off promo right now, but I politely declined it and paid the full $59 for a year.

Thank you for all of your hard work. Thank you for making this possible. Thank you for making this POPULAR.
Thank you for clogging teh intartubes with petabytes of anime. Thank you for the fakesubs, the trollsubs, your sense of humor, and not taking crap. Thank you for running a tracker that handles torrents with 5000 seeders and 12000 peers. Thank you for spending your time. Thank you for spending your money.
And most of all -- Thank you for spending your lives.

Cheers.

-- Kami, a happy anime fanatic

Thursday, April 15, 2010

Windows 7 and the Mysterious Unidentified Network

Fixing Win7's Unidentified Network problem

http://www.sevenforums.com/tutorials/71408-unidentified-networks-set-private-public.html

Use gpedit.msc to go to Computer Configuration -> Windows Settings -> Security Settings -> Network List Manager Policies.
Right click All Networks and select Properties.
Set the following: User can Change Name, User can Change Location, User can Change Icon. Click OK.
Use services.msc to locate "##Id_String1.6844f930_1628_4223_b5cc_5bb94b879762##" from Apple Computer, INC. -- right click on it and say properties.
Click the Stop button, then use the pulldown to switch to "Disabled" startup.
This will disable the mdnsresponder.exe which sets a gateway address of 0.0.0.0 resulting in that second spurious "Unidentified Network" that fucks everything up.

Open your network center.
Click Manage Wireless Networks from the sidebar. DELETE THEM ALL except your own home/work networks (You should know the names by now!) and return to the Network Center.
Click on the connection's icon under View your active networks.
Click Merge or Delete network locations. DELETE THEM ALL except your primary networks. Click Close. Click OK.
Click Change Adapter Settings from the sidebar.
Right click each "real" network adapter and "Disable" it. They should have device names like "Intel Wireless" and "Broadcom Gigabit".
Ignore devices like "Cisco VPN", "Bluetooth Device", "1394 adapter".
Re-enable the devices you just disabled.

Waboom, all fixed, no reboot required.

Friday, July 24, 2009

Burnout Paradise and Windows 7

Long time, no post.


Okay, so I was installing Burnout Paradise: The Ultimate Box on my shiny new Windows 7 bootable VHD, and MSIInstaller kept throwing error code 2203 at the start of the install.

So, tracked down this gem of info:
Google Groups (microsoft.public.platformsdk.msi)

Windows NT has a nice command line tool called cacls.exe (change ACLs) that can display or set access control rules for files. Kinda like Take Ownership, but without actually having to alter the file's ownership.

And, it turns out a MSIInstaller 2203 error can be caused by NT AUTHORITY\SYSTEM not having access permissions on the %TEMP% or %SYSTEMROOT%\Installer folder.

Off to the commandline I went.

C:\Users\Kamilion>cacls %SystemRoot%\Installer
C:\Windows\Installer NT AUTHORITY\SYSTEM:(OI)(CI)F
Everyone:(OI)(CI)R
BUILTIN\Administrators:(OI)(CI)F

Well, that looks normal.

C:\Users\Kamilion>cacls %TEMP%
C:\Users\Kamilion\AppData\Local\Temp Raziel\Kamilion:(OI)(IO)F
Raziel\Kamilion:(CI)F

Ahha! I'm the only one with access to my own tempdir...
Well, we'll fix that.

C:\Users\Kamilion>cacls %TEMP% /E /G SYSTEM:F
processed dir: C:\Users\Kamilion\AppData\Local\Temp

So, I've just added an ACL allow for SYSTEM with Full access.
Let's see if it took.

C:\Users\Kamilion>cacls %TEMP%
C:\Users\Kamilion\AppData\Local\Temp Raziel\Kamilion:(OI)(IO)F
Raziel\Kamilion:(CI)F
NT AUTHORITY\SYSTEM:(OI)(CI)F

Sure enough!

Run the installer, and boom, no more 2203 error. I have my Burnout, and learned a new trick!

Sometimes annoying errors can actually be useful.
Edit: Argh, no [code] tags!

Monday, May 12, 2008

Booting The Heron from a U3

Well, one day last week, I got bored and decided to tinker with my Sandisk Cruzer Titanium 4GB with U3. Normally, when you jam one of these in your USB port, it shows up as a 6MB CD-ROM drive and the rest of the space as a USB Mass Storage Device (USB Harddrive).

Now, here's the neat thing: It does this all in hardware.
The chipset inside registers as two distinct devices, a CD-ROM with autoplay software for windows with the fancy U3 launchpad, and the actual flash drive. Windows Device Manager shows two devices, and jamming it in my Ubuntu 8.04 installation also displays as two drives. So, thinking about this, I walked over to a friend's PC, rammed it in the front panel USB, hit the power button, and whacked F12 to show the boot drive selection menu.

Imagine my surprise when even the BIOS recognized it as two distinct devices...
So, I started tooling around google, and discovered the "U3 Universal Customizer".
Normally, people would use this to patch in a new ISO under 6MB to replace the existing one.

I began screwing around with some of the other software from the Hak5 site, and poked around with the USB Switchblade & USB Hacksaw software...

Basically, what they are, is a replacement for the 6MB portion of the drive that contains some 'malware' that will bleed a windows system dry -- swipes all the passwords, sets up an encrypted stunnel, and emails it all off to an address of your choice. Interesting, but not terribly useful unless you're a vengeful 14 year old intent on swiping some other kiddie's myspace passwords for fun and pr0fit. Big deal. Since I run Ubuntu primarily now, it wouldn't affect me, even with WINE installed, due to the very nice "This disc has autoplay, do you want to execute it?" dialog.

So I tinkered around with it some more... And then I found out by trial and error that the U3 Universal Customizer can change the domain size of the CD side of the device! The first time I tried this was with a 10MB ISO containing Process Explorer and some other bits including DiskTrix's Ultimate Defrag. From everything I read, I was told this would brick the unit, but I tried anyway. It worked!

So then I figured, hey, wait a minute. If I can shoehorn 10MB on there, what about 700MB?
Well, first try, it didn't work... but LPUninstaller managed to unbork my drive and LPInstaller got me back to the standard U3 Launchpad.

Then I thought... Hey, what if there's a signature stuck on the ISO somewhere that the U3 bits are looking for?

I dug up a copy of MagicISO, which can normally remaster ISOs, opened up cruzer-autorun.iso, deleted everything but the autorun.inf, dropped process explorer in there, edited the autorun.inf, opened up my Ubuntu 8.04 ISO, saved the bootsector to a BIF file, copied all of the files out of the ISO to C:\Ubu804, loaded the bootsector.bif into the cruzer-autorun.iso, and dropped all the files in C:\Ubu804 in there, and ran U3 Universal Customizer...

*45* minutes later, SUCCESS!

So I jammed the drive into my friend's PC, hit the power button, whacked F12 to get to the boot menu, and selected the U3 Titanium CDROM device...

And bricked my pants as Ubuntu's CD Bootloader came up. Hit enter twice, and about 45 seconds later, I'm staring at the Ubuntu 8.04 desktop, grinning my ass off like an idiot. Plus you can use the rest of the Mass Storage side for "persistant" mode! Now if I could just figure out how to get "toram" working again, and dump openoffice from casper, I'd be one happy camper!

To sum it all up:

Edit the existing cruzer-autorun.iso with MagicISO instead of creating a new ISO.
"Burn" the ISO onto the Cruzer with U3 Universal Customizer.

This should work with just about any bootable ISO that doesn't rely on things expecting hard coded ISO9660 LBA addresses.

(And it should even work on an UBCD4Win / BartPE / OpenSolaris Indiana or Nevada /Nexenta ISO under 4096MB!)

The only thing you need is unrestricted access to a Windows NT5.x (Windows 2000 / Windows XP) machine for about an hour.

Good luck, beware of bricking your $50 keychain bootable CD-ROM!