fingerprint biometrics
Guys I have recently purchased an integration toolkit from www.m2sys.com
They made my life way simpler then I thought. I have spent over 4
months playing with a fingerprint scanner and sdk we bought from an
online vendor. It was going nuts - no support no idea what was going
on. Sean thanks a lot for directing me to this site. Tag: IPC Tag: 96734
Can not renew root ca
Hello:
I have a Windows 2003 SP1 server running as a Stand Alone Root CA. Its
certificate is about to expire. Whether I choose "Renew Certificate with
New Key..." or "Renetw Certificate with Same Key..." I always get the same
error.
"You do not have permission to request a certificate based on the selected
certificate template"
My account is a member of the Enterprise Admins. I've Googled this, but
haven't found anything. Does anyone have any idea?
Harrison Midkiff Tag: IPC Tag: 96733
informations for C:\WINDOWS\system32\wbem
it seems one application
import data from internet and write it
in
C:\WINDOWS\system32\wbem\Repository\FS
in the files
INDEX.MAP
MAPPING.VER
MAPPING1.MAP
OBJECTS.MAP
INDEX.BTR
MAPPING2.MAP
OBJECTS.DATA
the file
C:\WINDOWS\system32\conf\SECURITY
is written too
are written the logs file in the directory "wbem" too
one of tham says
Warning! User name at exit (BLAKY\Giuseppe) != user name at entry
(WORKGROUP\BLAKY$) for select __RELPATH, __Path, Group, Description,
Version, CreationDate, FileSize, Manufacturer, Name, __RELPATH from
Win32_CodecFile 02/16/2008 18:02:45.531 thread:3252
[d:\xpsprtm\admin\wmi\wbem\sdk\framedyn\wbemglue.cpp.857]
Warning! User name at exit (BLAKY\Giuseppe) != user name at entry
(WORKGROUP\BLAKY$) for
CIM_DataFile.Name="C:\\WINDOWS\\system32\\MSADP32.ACM" 02/16/2008
18:02:45.562 thread:3296
--------------------------------------
What does it mean:[wiaservc] Opened log at 17/02/2008 20:18:34.625?
What does it mean:
2/17/08-20:19:58,[2524] CHPCompMgrService::ProcessIndirectRegistration - no
permissions to read indirect registration registry area!!!
in the file "hpcmerr.log"
?
is all that ok in the security vew ? Tag: IPC Tag: 96729
Slow 802.1X Authentication
Why my 802.1X authentication is so slow??
PEAP, MS-CHAP-V2
Domain user login and password. Zyxel 802.1X Radius Client Zyxel GS-2024
IAS using Windows Server 2000 AD using Windows Server 2003 Standard
Windows XP service pack 2.
It takes more than 1mins from type in the logon domain password to seeing
the desktop icons. And mapping folder using logon script sometimes failed.
Any solution ?? Tag: IPC Tag: 96724
WSUS - how starting
Hi!
we used a 3rd pary application for patching our servers. I have heard good
things about WSUS 3 so I downloaded it and now I need some help.
I found something about 500 updates which have to be approved.
Do I have to read each update or is there perhaps a better way to install
only the fixes for remote execution bugs?
kind regards
Juan Tag: IPC Tag: 96718
Question about pkiview.msc Root Certificate Expiring
Greetings all,
Have a question about Pkiview.msc - but first the setup details.
Win2K3 standard - Stand-Alone root CA (Certificate lifetime 12 years)
Win2K3 Enterprise - Enterprise subordinate CA/Issuing CA (Certificate
lifetime 6 years)
CRL and AIA informatinos are first published to a http site and then ldap
for clients.
When I run pkiview on the Issuing CA it shows a warning on the root ca.
After selecting the root ca in pkiview.msc it says:
CA Certificate - status - Expiring
AIA location #1 (http) - status - Expiring
AIA location #2 (ldap) - status - Expiring
If I click on any of the links and open the root ca certificates it says
that the validity is 30 years from now. Any who know if this is normal
behavour for pkiview.msc and that I can ignore this or if I should trouble
shoot on it? And if so, any suggestions of what to look for?
On google I havn't found much about it, except a post which said that the
status of expiring was ok.
Thanks in advance,
Benjamin Tag: IPC Tag: 96701
Home Security Camera
* Easy to Use and Install
* Just Plug it In your Television & you will be able to watch
Instantly Live motions at your Home, Office or Godawn etc.
* It is so small in Size
* It can be Installed along with almost all the Television & VCR's
having AV in Plugs
* Great Indoor and Outdoor Resolution
* Power Adapter and 20 mtr Cable Included
* Colors and Model are Subject to availability. (No Choice)
Please visit -
http://www.homeshop18.com/hs18shop/faces/tiles/product.jsp?productID=20388&catalogueID=2&categoryID=1253&parentCategoryID=1070&bid=&prc=&sid=&q=&k1=&k2=&k3=&k4=&k5=&k6=&k7=&k8=&k9=&k10=&k11=&k12= Tag: IPC Tag: 96696
Conflicting IAS remote access policies problem
This concerns a IAS RADIUS server. I have a pre-existing IAS remote
access policy that authenticates all wireless users and allows them to
connect to my companies wireless network. I am a member of this
group.
I have created a second policy to allow exec priviledge logins to my
Cisco routers. I set the policy to allow anyone who is a member of
the Domain Admins group this right. I am a member of this group as
well.
When the wireless policy is listed first, and I attempt to login to my
Cisco router, I get an "IAS_INVALID_AUTH_TYPE" error in my IAS log,
but I can connect to my wireless network just fine. If I reverse the
order of the policies, I can log in to the Cisco router just fine, but
then I get the "IAS_INVALID_AUTH_TYPE" error when I connect to my
wireless network.
The logs also show that when the login is failing on the first policy,
it does not fall through to the second policy.
Is there any way around this? I want to stay in both the wireless
users and the Domain Admins groups; can I configure IAS to go down my
list of policies until I either reach one that accepts my login, or
I'm rejected by all policies? Thanks. Tag: IPC Tag: 96688
How do you get past Vista security ? Digitally sign your malware !
http://sunbeltblog.blogspot.com/2008/02/dangerous-new-fake-american-greetings.html
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp Tag: IPC Tag: 96682
Certificate Enrollment API: Request on behalf of another user
Hi
What is the correct process to request a certificate on behalf of another
user by using the new Certificate Enrollment API (certenroll.dll) with
Windows Vista / Windows Server 2008?
I know, that
- I need a IX509CertificateRequestPkcs10 request object
- I need a IX509CertificateRequestCmc object
- I need a IX509NameValuePair object (request on behalf...)
- I need a IX509Enrollment object
But, what are the correct steps to assemble the request and install the
signed response from a CA?
Any help is welcome.
Thanks and Regards,
Dominik
-----------------------------
http://blogs.ecreation.ch Tag: IPC Tag: 96680
share premission errors
I cannot run exe files directly from the server. When running them from the
share (\\server\share\file.exe), I get a permissions error that reads
"Windows cannot access the specified device, path, or file. You may not have
the appropriate permissions to access the item." It does run however when I
execute it from explorer using the drive (D:\folder\file.exe), or using the
unc path from another computer. I am logging in as the domain admin. All
users have full share permissions. What could be causing this?
Thanks for any help,
Brian Tag: IPC Tag: 96675
Don't mention this to Bill G or Steve B..
http://it.slashdot.org/article.pl?sid=08/02/10/2011257
..or they might fall off their respective stools laughing. :-)))) Tag: IPC Tag: 96667
Close open Files
Hello,
I would like to enable a user to close open files (that do not belong to
him) through Computer Management on a 2000 or 2003 file server WITHOUT making
him a member of the administrators or Server Operators group. Is that
possible and what would the minimum rights be that would have to be granted?
Thanks for any help!
Harry Tag: IPC Tag: 96663
detecting lame passwords
I know that the standard disclaimers apply: running certain security
auditing tools without permission may be criminally prosecutable, and at
least grounds for termination. With that happy thought in mind, what tools
would you recommend for finding who has a weak password? I've explained that
Winter07 is not a good password, but since Windows will accept it, I think
that some kind of auditing is my next prudent step.
Recommended products for preventing this in the first place are welcome as
well. But presenting a user with their password as evidence that they chose
a weak password seems to be hard to argue with.
My assumption is that such a tool would run under the admin account, and
that the tool itself should secured to said account.
________
Greg Stigers, MCSA
remember to vote for the answers you like Tag: IPC Tag: 96653
Grant Access to Different Profiles
Our company has a stand a long laptop - No domain - Its primary function is
to connect using IE to our four local-internal Webcam servers (Windows XP)
for surveillance purposes. We had two kind of users logging into the
computer. Administrator and security are the names for the two user's
profiles. The computer has access to the Internet, MS Office, Windows games,
etc.
Our goal is to grant the Administrator full access to all of the resources
available into the computer. The second user profile "Security" should ONLY
have access to the IE to view the WEBCAM servers (No access to the Internet
or any other software).
If you have any suggestions on how to accomplish this will be very
appreciated.
Thank you in advance for your help and assistance with this task! Tag: IPC Tag: 96649
Mind Control "mailteam" works-- victims work trends
Mind Control "mailteam works"--- victims work trends
http://soleilmavis.googlepages.com mind control victims website
(1) discovery channel
Electronic Mind Control Pt 1
http://www.youtube.com/watch?v=k3aZyDiyI7g
Electronic Mind Control Pt 2
http://www.youtube.com/watch?v=qh7FEwIbQds
Electronic Mind Control Pt 3
http://www.youtube.com/watch?v=6nA1__XIYUo
(2) CORRECTIONS RE ROBERT DUNCAN'S INTERVIEW
Robert Duncan, B.A., M.S., M.B.A,. Ph.D. will be interviewed this Feb
12th, 2008 @ 11:30pm on the Richard Syrett show. The topics are broad:
directed energy neurological weapons, EEG cloning/psychic warfare,
brain washing, torture, interrogation, mind viruses, silent eugenics
programs, silent assassination/warfare, military deception tactics,
discrediting tactics, creating public myths, false flag operations,
psychological warfare, information warfare, cognitive warfare,
cultural engineering, remote renditions, the CIA's "scripts and
tricks", NSA signal encoding/decryption/deception methods, human
behavior modification experiments, etc. WWIII has already begun but it
is fought in the hearts and minds of people silently. Choice and
freedom are merely an illusion.
Munich, Germany (in German) ?TBD. Topics include: Distributed death
camps, worse-than-lethal weapons, disguising genocides in statistics
of common diseases, neurological cognitive containment fields, US
sponsored psychoterrorism, and more. Hitler is rolling in his grave
out of jealousy of what the US and its territories (Canada, Australia,
and the UK) have done.
(3) Victims online shops
Victims have already done a lot of works. But we also know Victims
need to support their life and their activities. We have been
encouraging victims to open an online shops to earn extra money. We
wish more victims can build their online shops.
Here are some online shops.
RINOA
Rinoa's Secret Garden-07
Main business: Clothes.
http://shop20150018.taobao.com/
Soleilmavis
Main Business: Self made Pure Natural Beauty skin care products;
selfmade flower tea and herbal tea; Hand made products; clothes.
http://shop34821367.taobao.com/
Tanglang
Main Business: provide on door photo services. for Art photography,
wedding photography, photography of children, families commemorate
photography, pet photography, and photography for major conference.
http://auction1.taobao.com/auction/14-2807-280704/item_detail-0db1-5333e9dd0dc73b266f75424c400ffdce.jhtml
duanjinping88
Main Business: hand made dry flower crafts, Greeting cards, bookmarks.
Bringing you closer to the nature!
http://shop35296794.taobao.com/
guoruquan
Main business: South China countries side selfmade dry fish and dry
meat. tea.
http://shop34876045.taobao.com/
hy99
Main business: Jewelry
http://shop33055862.taobao.com/
Spring
Main business: Software development
http://shop.paipai.com/674614570
(4) CARDS AND RIBBONS
I've made some cards that can be handed out with the new awareness
ribbons. They can be viewed at this link:
www.freedomfchs.com/cardandribbon.jpg
We will be sending them out free to the TI community upon request as
vehicles for outreach about our issues. Just send an email to me at:
dcr618@msn.com
(5) SAMPLE OS/EH BILL
This bill was written in conjunction with activist Mary Ann Stratton -
www.controlledamerica.com Those that are in contact with legislators,
feel free to send this along with other information they may request.
ORGANIZED STALKING AND DIRECTED ENERGY WEAPONS HARASSMENT BILL
A bill to provide protections to individuals who are being
harassed,stalked, harmed by surveillance, and assaulted; as well as
protections to keep individuals from becoming human research subjects,
tortured, and killed by electronic frequency devices, directed energy
devices, implants, and directed energy weapons.
Section 1. Short Title
This bill may be cited as the "Organized Stalking and Directed Energy
Devices and Weapons Bill "
Section 2. Findings and Purpose
A) Findings
1) The constitution guarantees the right of the people to be secure in
their person. The Declaration of Independence asserts as self-evident
that all men have certain inalienable rights and that among these are
life, liberty, and the pursuit of happiness.
2) As Supreme Court Justice Louis Brandeis wrote in 1928, "the framers
of the Constitution sought "to protect Americans in their beliefs,
their thoughts, their emotions, and their sensations." It is for this
reason that they established, as against the government, the right to
be let alone as "the most comprehensive of rights and the right most
valued by civilized men."
3) The first principle of the Nuremberg Code states that with respect
to human research, the voluntary consent of the human subject is
absolutely essential. The Nuremberg Code further asserts that such
consent must be competent, informed, and comprehending.
4) There are current regulations implementing the obligations of the
United States to adhere to Article 3 of the United Nations Convention
Against Torture and other Forms of Cruel, Inhumane or Degrading
Treatment including all terms that are Subject to any reservations,
understandings, declarations, and provisions contained in the United
States Senate resolution of ratification of the Convention.
B) Purpose
To establish regulations and penalties for those who use any type of
electronic frequency devices, directed energy devices, implants,
surveillance technology, and directed energy weapon to purposefully
cause any of the following: stalking, harassing, mental or physical
harm, injury, harmful surveillance, torture, diseases, and death to
any United States citizen.
Section 3. Organized Stalking
If two or more persons willfully, maliciously, and repeatedly follow
or willfully and maliciously harass another person and who make a
credible threat with the intent to place that person in reasonable
fear for his or her safety, or the safety of his or her immediate
family, they are guilty of the crime of organized stalking, punishable
by imprisonment in a county jail for not more than one year, or by not
more than one thousand dollars ($ 1,000), or by both that fine and
imprisonment, or by imprisonment in a federal prison.
If two or more persons violate subdivision (a) when there is a
temporary restraining order, injunction, or any other court order in
effect prohibiting the behavior described in subdivision (a) against
the same party, they shall be punished by imprisonment in the state
prison for two, three, or four years.
For the purposes of this section, "harass" means engages in a knowing
and willful course of conduct directed at a specific person that
seriously alarms, annoys, torments, or terrorizes the person, or
damages his personal property or possessions and that serves no
legitimate purpose. * * *
For the purposes of this section, "course of conduct" means two or
more acts occurring over a period of time, however short, evidencing a
continuity of purpose. Constitutionally protected activity is not
included within the meaning of "course of conduct."
For the purposes of this section, "credible threat" means a verbal or
written threat, including that performed through the use of an
electronic communication device, or a threat implied by a pattern of
conduct or a combination of verbal, written, or electronically
communicated statements and conduct, made with the intent to place the
person that is the target of the threat in reasonable fear for his or
her safety or the safety of his or her family, or personal property or
possessions and made with the apparent ability to carry out the threat
so as to cause the person who is the target of the threat to
reasonably fear for his or her safety or the safety of his or her
family or personal property or possessions. It is not necessary to
prove that the defendant had the intent to actually carry out the
threat. The present incarceration of a person making the threat shall
not be a bar to prosecution under this section. Constitutionally
protected activity is not included within the meaning of "credible
threat."
For purposes of this section, the term "electronic communication
device" includes, but is not limited to, telephones, cellular phones,
computers, video recorders, fax machines, pagers or synthetic
telepathy devices.
The sentencing court also shall consider issuing an order restraining
the defendant from any contact with the victim, that may be valid for
up to 10 years, as determined by the court. It is the intent of the
Legislature that the length of any restraining order be based upon the
seriousness of the facts before the court, the probability of future
violations, and the safety of the victim and his or her immediate
family.
For purposes of this section, "immediate family" means any
spouse,parent, child, any person related by consanguinity or affinity
within the second degree, or any other person who regularly resides in
the household, or who, within the prior six months, regularly resided
in the household.
Section 4. Punishment for threats
Any person or persons who willfully threatens to commit a crime which
will result in death or great bodily injury to another person, with
the specific intent that the statement, made verbally, in writing, or
by means of an electronic communication device, is to be taken as a
threat, even if there is no intent of actually carrying it out, which,
on its face and under the circumstances in which it is made, is so
unequivocal, unconditional, immediate, and specific as to convey to
the person threatened, a gravity of purpose and an immediate prospect
of execution of the threat, and thereby causes that person reasonably
to be in sustained fear for his or her own safety or for his or her
immediate family's safety, shall be punished by imprisonment in a
federal prison not to exceed one year..
For the purposes of this section, "immediate family" means any
spouse,whether by marriage or not, parent, child, any person related
by consanguinity or affinity within the second degree, or any other
person who regularly resides in the household, or who, within the
prior six months, regularly resided in the household.
"Electronic communication device" includes, but is not limited
to,telephones, cellular telephones, computers, video recorders, fax
machines, pagers or synthetic telepathy devices
Obscene, threatening or annoying communication
(a) Every person or persons who, with intent to annoy, telephones or
makes constant contact by means of an electronic communication device
with another and addresses to or about the other person any obscene
language or addresses to the other person any threat to inflict injury
to the person or any member of his or her family, or any property or
personal possessions is guilty of a misdemeanor. Nothing in this
subdivision shall apply to telephone calls or electronic contacts made
in good faith.
(b) Every person or persons who makes repeated telephone calls or
makes repeated contact by means of an electronic communication device
with intent to annoy another person at his or her residence, is,
whether or not conversation ensues from making the telephone call or
electronic contact, is guilty of a misdemeanor. Nothing in this
subdivision shall apply to telephone calls or electronic contacts made
in good faith.
(c) Every person or persons who makes repeated telephone calls or
makes repeated contact by means of an electronic communication device
with the intent to annoy another person at his or her place of work is
guilty of a misdemeanor punishable by a fine of not more than one
thousand dollars ($ 1,000), or by imprisonment in a federal prison for
not more than one year, or by both that fine and imprisonment. Nothing
in this subdivision shall apply to telephone calls or electronic
contacts made in good faith. This subdivision applies only if one or
both of the following circumstances exist:
(1) There is a temporary restraining order, an injunction, or any
other court order, or any combination of these court orders, in effect
prohibiting the behavior described in this section.
(2) The person or persons makes repeated telephone calls or makes
repeated contact by means of an electronic communication device with
the intent to annoy another person at his or her place of work,
totaling more than 10 times in a 24-hour period, whether or not
conversation ensues from making the telephone call or electronic
contact, and the repeated telephone calls or electronic contacts are
made to the workplace of an adult or fully emancipated minor who is a
spouse, former spouse, cohabitant, former cohabitant, or person with
whom the person has a child or has had a dating or engagement
relationship or is having a dating or engagement relationship.
(d) Any offense committed by use of a telephone may be deemed to have
been committed where the telephone call or calls were made or
received. Any offense committed by use of an electronic communication
device or medium, including the Internet, may be deemed to have been
committed when the electronic communication or communications were
originally sent or first viewed by the recipient.
(e) Subdivision (a), (b), or (c) is violated when the person acting
with intent to annoy makes a telephone call requesting a return call
and performs the acts prohibited under subdivision (a), (b), or (c)
upon receiving the return call.
(f) If probation is granted, or the execution or imposition of
sentence is suspended, for any person or persons convicted under this
section, the court may order as a condition of probation that the
person participate in counseling.
(g) For purposes of this section, the term "electronic communication
device" includes, but is not limited to, telephones, cellular phones,
computers, video recorders, fax machines, pagers or synthetic
telepathy devices.
Section 5. Assault and battery with an electronic or directed energy
weapon
Any person or persons who in the course of organized stalking and
harassment, commits an assault upon the person of another with an
unauthorized directed energy weapon shall be punished by imprisonment
in a federal prison for two, three, or four years or by a fine not
exceeding ten thousand dollars ($10,000).
For the purposes of this section the term directed energy weapon is
defined as any device that directs a source of energy (including
molecular or atomic energy, subatomic particle beams, electromagnetic
radiation, plasma, or extremely low frequency (ELF) or ultra low
frequency (ULF) energy radiation) against a person or any other
unacknowledged or as yet undeveloped means of inflicting death or
injury; or damaging or destroying, a person (or the biological life,
bodily health, mental health, or physical and economic well-being of a
person via land-based, sea-based, or space-based systems using
radiation, electromagnetic, psychotronic, sonic, laser, or other
energies directed at individual persons or targeted populations for
the purpose of information war, mood management, or mind control of
such persons or populations; or by expelling chemical or biological
agents in the vicinity of a person.
(6) China victims have discussed to write to members of China National
People's Congress
We need victims to prepare email lists of members of China National
People's Congress
The letter will be written by Mr. Zhongqing Qi.
(7) T Shirt campaign
China victims have discussed to make some T shirts which for wear and
sale. We will print some words on the T shirt " Peacepink We share
Peace and Love! We against Mind Control and DEW abuse and torture!"
The Material of T shirt will be high quality cotton and will be well
make.
I have already searched, the Cost of Product will be RMB10 yuan( about
USD1.4)per piece.
We welcome any opinion which regarding the style, words or other thing
about T shirt. We also accept order in advance. Please contact
soleilmavis@yahoo.com Tag: IPC Tag: 96646
Other Users are Connected
This evening after running my nightly anti-virus program, I went to shut down
my computer. When I clicked to confirm the shutdown, a msg poped up saying
that others were connected to my computer and would be disconnected if I shut
down. My question: is there a log file that tracks who is logged into my
computer? I am on a wireless network, but have secured it from public
access. Thanks in Advance for your help. RR Tag: IPC Tag: 96645
IAS error code 96 and 97
I am using windows server 2000 with IAS installed.
Using PEAP as protocol, AD user login name and password.
I have got two error codes for the failed authentication
CODE 96:
Access request for user HKRI\michael.chau was discarded.
Fully-Qualified-User-Name = <undetermined>
NAS-IP-Address = <not present>
NAS-Identifier = ESW-0124
Called-Station-Identifier = <not present>
Calling-Station-Identifier = <not present>
Client-Friendly-Name = Zyxel
Client-IP-Address = 172.18.252.62
NAS-Port-Type = <not present>
NAS-Port = <not present>
Reason-Code = 96
Reason = The authentication request was dropped because the session timed
out.
CODE 97
Access request for user HKRI\michael.chau was discarded.
Fully-Qualified-User-Name = <undetermined>
NAS-IP-Address = <not present>
NAS-Identifier = ESW-0124
Called-Station-Identifier = <not present>
Calling-Station-Identifier = <not present>
Client-Friendly-Name = Zyxel
Client-IP-Address = 172.18.252.62
NAS-Port-Type = <not present>
NAS-Port = <not present>
Reason-Code = 97
Reason = The authentication request was dropped because it contained an
unexpected packet.
Any idea Tag: IPC Tag: 96642
MICROSOFT AWARD E-LOTTERY LONDON
I got this letter from THE DESK OF THE MICROSOFTâ?¢ PROMOTIONS MANAGER
INTERNATIONALPROMOTIONS/PRIZE AWARD DEPARTMENT by ELECTRONIC EMAIL AWARD
WINNING NOTIFICATION AWARD PRESENTATION CENTER : UNITED KINGDOM.ATTN:WINNER.
IT ABOUT Total amount won: £1000000.00.
I don't know it is true or not.
please help me .
please send answer to my e-mail:ningkeyang@hotmail.com Tag: IPC Tag: 96640
please help me
i have a problem with an user. Last night (10.02.2008)
someone abused me with webcam from erkan_pendik@windowslive.com.
i want to complain him to a solicitor and i want to know who is he.
whence i want his mail list to find him
or if u could give him ip addres i give it to solicator.
Please help me
Thankyou in advance , sincerely.. Tag: IPC Tag: 96631
Certsrv on a remote server
Everyone,
I have an environment that uses a Stand-alone CA to issue certificates to
remote users from a public web site using web enrollment. This cert is used
for authentication for another web site.
Right now I have a server farm behind load balancers, but only one of them
is configured as CA with the web-enrollment piece (certsrv). As you can
imagine, this acts as a single point of failure and means that we can't use
the load balancers for this; we have to always go to the single server.
I would like to put copies of Certsrv on the other web servers so that I
could balance these, but I am concerned with the communication between web
enrollment and the CA and what the configuration steps would be. I am trying
to avoid the overhead of configuring subordinates on the other web servers
and issuing locally.
Advice?
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
http://www.techsterity.com
Chicago, IL
Remember: Marking helpful answers helps everyone find the info they need
quickly. Tag: IPC Tag: 96629
redundant wan
We have two connections to the internet (1 T1 and 1 DSL) setup for redundancy
purposes on a router with 2 wan ports. These connections both have their own
pool of IP addresses. Our name resolution is setup to point to IP addresses
bound to the T1. We recently had a situation where our T1 went down and we
had to disable that WAN port on our router until it was available again. In
this process we found that we needed to setup a second ftp subdomain
(ftp2.mydomain.com) and tell our customers to use that name.
My question is how can we make it so that we don't have to notify our
customers to use the other subdomain should this happen again without having
to make dns changes. In other words, if ftp.mydomain.com is bound to our T1
on 65.1.1.1 and out T1 goes down, what would we need to do to make sure
ftp.mydomain.com goes through our DSL line bound to 64.1.1.1 (IP addresses
are not real, just examples).
Would we need to change our topology, or is there a way to set a secondary
IP or route for our dns names? Any feedback is much appreciated.
Thanks,
Marc Tag: IPC Tag: 96627
Active Directory and DMZ
I recently faced a situation where a sharepoint was part of a domain inside a
DMZ. There was a separate domain, inside the corporate network.
The element I was concerned with was the following : the DMZ domain trusted
the internal domain and the sharepoint allowed users from the inside to
access some ressources.
My assumption was that this was a potential security breach since multiples
ports needed to be open between the inside and the DMZ, and that this
architecture could allow an attacker to eventualy get to the inside from the
DMZ.
I am just curious about what would be the 'best practices' regarding that
situation. Of course you can have just two domains, but obviously the people
on the corporate network need to share ressources with partners outside.
What is the recommended way to deal with such a situation ? Is there any
safe way of allowing internal users to simply authenticate on such a shared
ressource with the outside ? Tag: IPC Tag: 96626
Recent Flaw with some ActiveX controls (Facebook, Yahoo) - how is it
I'm aware of the recently alerted flaw in the image uploder ActiveX
control used by some popular social networking sites. But I haven't
found technical details to explain where the risk actually lies...
Is it in the Uploader talking to a malicious download application or
is it the Uploader opening a malicious image file. Or is there a
different attack vector?
I don't suppose Facebook or MySpace would intentioanlly post a
malicous download element to the Uploader - although someone could
spoof one of these sites to get at an unsuspecting user.
Or if it is crafted image files that we are worried about then as long
as users stick to pictures which they know to be ok (such a photos
they've taken themselves) then surely the risk is quite low.
I'm guessing that the risk is related to the first mentioned above in
that a malicious site could invoke the ActiveX control and then pass
it crafted information- is that right?
Thanks Tag: IPC Tag: 96625
Help with 'web bugs' requested.
(If you don't know what web bugs are, see eff.org or elsewhere)
Web bugs, also called web beacons, and by other names, are a non-cookie,
non-IP related way to track people on the internet.
In a way, it has made protection against cookies almost obsolete.
I've read that some ad-blocking programs would block some web bugs, but I'm
looking for something that blocks, detects and is able to scan for web bugs
(or if that's too much, just part of that).
I use IE 7. (No Firefox !)
The issue is really privacy. Seeing ads can be annoying, but my real issue
is preserving some privacy by not allowing myself to be tracked wherever I go
on the internet. Any programs, means to achieve this ? I suppose proxies or
anonymizer services might help, but they have their own disadvantadges.
Suggestions ?
Too bad that most people don't know about 'web bugs'. Tag: IPC Tag: 96623
802.1x wired , and logon script
I am using 802.1x for wired computer connection to domain, using AD domain
user account name and password.
When users try to logon to the domain, it aways wait for a very long
time.(about 30s and more)
And the 802.1x authentication always successed only after the desktop icons
are shown. And user domain logon script for mapping drive is failed.
How can I solved the problem??
Thanks Tag: IPC Tag: 96621
Norton Antivirus & Windows Security Center
Open NAV2007. On the norton protection center window above Basic PC Security
click OPTIONS.
On the Norton Protection Center Options window select General Settings
Under Windows Security Center alert settings check the box. Show messages
from Windows Security Center. Click ok.
Close NAV
Then open Security Center it should be working as normal.
Hope This was helpful
Kev136 Tag: IPC Tag: 96613
part II how to start stop service without the password
sorry that a simliar queustion may have answered before. this has a new
twist. :)
I have a domain user account started a service. For reason unknown, Local
admin can't restart it, or starting it after it was stopped. only one domain
user have to start it using the password of the domain user.
how can I have it so all users belonging to the group local admin can start
stop the service without the password of that domain user.
here is the currently output from accesschk. thanks.
C:\>accesschk "DomainName\user1" -vc MSSQLSERVER
AccessChk v4.02 - Check access of files, keys, objects, processes or services
Copyright (C) 2006-2007 Mark Russinovich
Sysinternals - www.sysinternals.com
RW MSSQLSERVER
SERVICE_ALL_ACCESS
--
ps: the reply button on my browser doesn't work. Tag: IPC Tag: 96612
Creating Certificate for a wireless projector
I am trying to deploy wireless projectors using certificates. I currently
have 2K3 R2 servers using PKI and Radius. I currently use AD to autoenroll
computers so that they can connect via our Cisco Aironet 1100 series AP's. I
am wondering if there is a specific certificate template I need to modify so
that I can use the web request to generate and then install via a thumb
drive? Any help is greatly appreciated! Tag: IPC Tag: 96611
revoring data
Hello frnds, my os corrupted so I some steps to recover but cant . But
finally when I installed Xp I found that my 40gb harddisk (3
partition )have combined to one C partition itself and all my data has
been deleted . Is there any way that I can recover my data pls help . Tag: IPC Tag: 96608
Modifying permissions with XCACLS.vbs
Hello,
I have a question about running XCACLS.vbs. I'm trying to change
folder permissions but I'm not using the built-in security groups - I
want to use domain groups; specifically domain admins and domain
users.
I read online that if one uses SID# in place if a group name then that
should work.
I call XCACLS. from a batch file. A sample of my existing (and
currently working as expected) file looks like this:
cscript xcacls.vbs "C:\WINDOWS\regedit.exe" /G Administrators:F
cscript xcacls.vbs "C:\WINDOWS\regedit.exe" /E /G SYSTEM:F
Additionally, I read that the domain SID can be found in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\ProfileList. I also read the SIDs for domain admins and domain users
are:
SID: S-1-5-domain-512
Name: Domain Admins
SID: S-1-5-domain-513
Name: Domain Users
So, armed with this information I took the two lines above and tried
to do this:
cscript xcacls.vbs "C:\Temp" /G
SID#S-1-5-21-131504274-120818031-269197707-1108-512:F
cscript xcacls.vbs "C:\Temp" /E /G
SID#S-1-5-21-131504274-120818031-269197707-1108-513:F
It didn't work. While I didn't get a script engine error or anything,
when I checked the permissions on that folder, all the entries were
gone - it was a blank display.
How can I modify the permissions to use domain admins and users?
Suggestions are greatly appreciated.
Thanks! Tag: IPC Tag: 96604
Trojan.Mailskinner.C ???
Hi all,
I have just finished a scan of my system with bitdefender security suite
2008 and the results were that i have a Trojan.Mailskinner.C and also 2
Adware.NaviPromo.BYC, bitdefender can't get rid of them because it says they
are part of an archive. The only thing i know that might have got rid of them
was to scan in safe mode and delete from there but defender won't let me do
that. I don't know how to delete manually so if anyone can give me step by
step instructions i would be so very thankfull, many thanks in advance Tag: IPC Tag: 96600
MSI vs Windows Vista Home
Hello everyone!
I try to install an application (Windows Installer), the wizard
Installation opens smoothly, but when you start copying
Files to disk bypasses the following error:
"The system administrator has set policies to prevent this installation"
What could be the problem?
I have Windows Vista Home Edition and i'm the 'Administrator'!
Since already many thanks!
Gustavo Arriola Tag: IPC Tag: 96595
PLEASE help me determine if I've got issues; I've done everything I know how to do!
This is long, but I want to give as much info and what I've done to try and
tackle this myself as possible. I really need some help at this point, so
I hope someone out there has the time and can provide some much needed and
much appreciated assistance/advice, etc.
I work at a pretty low-tech place with 8 PC's, all running XP, using
comcast's cable internet service, with file sharing set up so all users can
access a shared folder on one of the PC's. No user or group policies are
set up. All PC's use TrendMicro's pay service, we havy a Linksys router,
and I periodically run Spybot and a few other favorite virus/trojan/bad
stuff finders on all the PCS' (but TrenMicro is the only thing running
24/7). There's also one NetGear wireless access point for an in-office
laptop (it requires a web key to log into the network)
We use a webmail software located on our dedicated server at a hosting
company (where our website is) to do email; the web server at the hosting
company is also the email server. Currently it's using SmarterMail (which
is apprently a pretty popular partnered email software with hosting
companies). So users use a web browser to log into their email, which is
housed on the dedicated server.
We've had some emails sent to yahoo email addreses come back with a
rejection notice due to yahoo user complaints about spam (not the users the
email was sent to, just users in general, apparnetly), and we've also had
undeliverable mail come back looking as if we sent it but we know we didn't
(there's spammy stuff in it). Also, Comcast recently disallowed all
outgoing traffic from our public IP (the router) that was looking for port
25, because they said they saw a lot of spammy-looking traffic leaving our
router as well.
Since it seemed like we had a real issue going on, I followed all the
directions SmarterMail has to make sure SMTP requires
authentication, etc., all the steps to minimize possible hijacking and
whatever. I used a few of these online websites where you put in the IP
address of the mail server and it sees if it looks like an open relay, and
they all reported negative. I had everyone change their passwords to
relatively strong ones for logging in t our mail server.
The problem seemed to remain. Then I turned on the outgoing log on the
Linksys router. About every ten seconds I see a couple outgoing packets
going to the same IP but with a different last number, then after about ten
of those it goes to another series of IP's with differnet last number.
For instance, I'd see outgoing to:
64.86.95.6
64.86.95.7
64.86.95.8
64.86.95.27
64.86.95.27
64.86.95.10
64.86.95.26
64.86.95.10
64.86.95.10
then there are bunch that are ("myserver" used instead of my actual web
server)
smtp.myserver.com
smtp.myserver.com
smtp.myserver.com
Some of these come from my own box's internal local IP, some come from the
other internal local IP's.
So, unless these are legitimate (like Windows update doing checks, trend
micro doing checks, etc.), it appears I actually DO have something sending
out IP traffic from inside. I looked up some of these IP's, and the most
numerous batch of outging IP's (starting with 64.86.95) show up as belonging
to:
Teleglobe Inc. TELEGLOBE (NET-64-86-0-0-1)
64.86.0.0 - 64.86.255.255
Akamai Technologies AKAMAI-TGB (NET-64-86-95-0-1)
64.86.95.0 - 64.86.95.255
I found one (and one only) reference to this IP and this company on the web,
where someone else was wondering about it, and it seemed like the assumption
was it was a place doing stuff for Microsoft's Windows update.
But when I turn off update, I still these outgoing traffic items in the
Linksys log.
I feel as if I've done everyhting I can and/or know how to do, so can anyone
out there tell me a good solid way to see if I have some kind of SpamBot on
our side of the router, or if someone has hacked our email server
externally? The problem's getting worse, it seems, and I don't know what I
can do when none of the popular security softwares find anything, but
comcast and yahoo and our inbox full of undeliverablre messages looking like
they were sent by us are pointing to us having a serious issue.
Please help, we rely on our ability to send emails to subscribers, and
they're getting rejected due to "user complaints", and we can't afford to be
blacklisted (and yes, we only send to subscribers, we follow all te opt-in
and opt-out stuff, and are very consciensious about keeping our mailing list
clean.
Please help!
Your time and assitance would be GREATLY appreciated. And thanks for
reading. Tag: IPC Tag: 96594
requesting a certificate in Vista.
Hi there,
When requesting a certificate in Vista, if you choose to create a custom
request (not going to use a template) and go to the "details" area, there
are different areas to go through. The first is Subject. For subject name
and alternative name, there are alot of choices. Is what you pick
influenced by what the policy and CPS of the receiving CA says it needs from
you? Meaning, the CA's policies dictate what you should pick in order to
get a certificate from that CA. And all CAs can differ? Same thing for the
Extensions tab?
Thanks!
Kristin Tag: IPC Tag: 96591
Script to list member of Local Admin Group
I am looking for a VB Script to list member of local admin group for my
servers in my domain.
Example
Domain=contoso
Server OU=Servers
ServerA, Server B ......................
I want to list member of local admin for all the servers.
Thx,
MA Tag: IPC Tag: 96590
icacls misreports BUILTIN\Users:(RX) on C:\
On a number of W2003 servers here, if I do
icacls C:\
I get...
C:\ BUILTIN\Administrators:(F)
BUILTIN\Administrators:(OI)(CI)(IO)(F)
NT AUTHORITY\SYSTEM:(F)
NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
CREATOR OWNER:(OI)(CI)(IO)(F)
BUILTIN\Users:(RX)
BUILTIN\Users:(OI)(CI)(IO)(GR,GE)
BUILTIN\Users:(CI)(AD)
BUILTIN\Users:(CI)(IO)(WD)
Everyone:(RX)
The ACE BUILTIN\Users:(RX) is wrong!
It *behaves* and indeed appears in the graphical DACL editing tool in
Explorer (Properties -> Security-> Advanced) as if it were
BUILTIN\Users:(CI)(OI)(RX)
(That is to say it does get inherited by objects and containers).
If I edit that ACE in Explorer - but save it without making any *visible*
change then it subsequently appears correctly in ICACLS. Tag: IPC Tag: 96587
certificate import Wizard on Vista not working:
I have Vista client PCs in a workgroup. I am logged into them as
Administrator. When I try to import a certificate by doubleclicking on the
CA certificate I want to import (I put it on the desktop or the C drive or
whereever) and using the import Wizard, the import says it is successful but
does not actually do anything. The same thing happens if I try to import
any certificate from the web enrollment website of the CA (CA is
standalone).
I have noticed that when this does NOT work, in the "Completing the
Certificate Import Wizard" window, it shows the Certificate Store Specified,
the Content, and the File Name. THE FILENAME IS BLANK.
The only time this does work is if I go to the certificate store, right
click and start the Import Wizard from there. Then the import really does
work and the File Name area actually shows the certificate file location
(c:\users...\certifcate.cer)
Anyone else run into this? Is there something I need to do in Vista to make
this work right?
Thanks!
Kristin Tag: IPC Tag: 96577
CMAK and certificate.
Hello!
I have a big problem with CMAK and my personal certificate. One month ago my
certificate named xxx expired. I used it to make VPN connection with server.
No I have yyy certificate. When i try to use CMAK to make connection, after
five blinding windows with "Accessing SmartCard" I'm getting "Key does not
exist." error message. In CMAK log i see, that CMAK is trying to use xxx
certificate! I don't have it in any container. I looked in user
certificates, local machine certificates.... Without result....
I have my certificate installed in personal/certificates container under
current user.
Under local computer personal/certificates i have my machine certificate.
Trusted root certification contains my CA cert.
1) Why CMAK see certificate, that does not exist?
2) How to force CMAK to work correctly with my certificate?
Regards
Leszek Tag: IPC Tag: 96575
info on the National Information Security Group (NAISG) + an invitation
To all,
I am pleased to announce the opening of three new chapters of the
National Information Security Group (NAISG, http://www.naisg.org).
These include the New York City, Silicon Valley and Washington, DC
chapters, which will complement the founding New England chapter
(Boston, MA).
NAISG membership is open to anyone that is interested in IT/security
administration, including pros, consumers, managers/executives, law
enforcement personnel (local police and FBI regularly attend the
meetings), educators, students and more. We never charge for
membership; you only need to sign up at our Web site to become a member.
We currently have more than 1,000 members in our ranks. In addition to
our monthly chapter meetings, we have an email-based Security TechTips
list that includes members from around the world. You can sign up for
this at http://www.naisg.org.
If any of you are in the New York City area this coming Monday (February
11), please check out the meeting details at http://nyc.naisg.org. The
topic will be "Cyber Surveillance and Employee Monitoring - What
Techniques Are Available, Should We Even Use Them and What Are
Employer/Employee Rights?" The meeting will be held at the Microsoft
office in midtown Manhattan.
Yours,
Brad
___________________________________________________________________
Bradley J. Dinerman, MVP - Identity & Access (Enterprise Security)
President, National Information Security Group
http://www.naisg.org Tag: IPC Tag: 96571
Removing Delux Communications Spy Wear
Need help.
Trying to get a good reference to remove Deluxe Communications ADware from
my Windows Xp system.
Thanks Tag: IPC Tag: 96567
Certificate store question
Hi Folks,
Does anyone know the earliest versions of windows client and server OS that
had a certificate store?
Thanks!
Kristin Tag: IPC Tag: 96565
ACL To Create and Modify Only New Files?
What ACL on NTFS will give a group Read-Only access to files currently in
the folder, but the ability to create and modify and delete new files in the
folder?
I have a badly behaved program that wants to write its TEMP files into its
program installation folder. I would like to avoid the more permission
Modify permission to the users of the application on all files in the folder
including the application's binaries.
One solution appears to be to give files currently in the folder the desired
ACL and then break inheritance. Then give Modify access to the folder and
all children. That isn't my first choice since later updates to the
application will probably install new binaries, and this approach leaves
those installed with Modify access inherited from the folder.
--
Will Tag: IPC Tag: 96561
Computer Info Compromised?
Hi:
I have a friend who had some old letters of one of his kin in a .doc file
in his My Documents folder in his computer. The letters were enough to have
formed a book about the 1800's written by this kin.
He Googled the letters info and found some data applicable these letters
which he has never shared with anyone. Also the .doc file string is exactly
as that in his computer. In fact, he has found a copy of these letters for
sale on the internet and the seller appears to be from the same area of the
state where he lives if not the same city. His name is referenced in as the
author of these letters.
So my question is how did someone acquire this data from his computer, as
apparently his computer has been compromised. It would appear to me that it
had to happen in one or two scenario's. First someone somehow accessed his
computer through the internet or second when he had taken his computer to a
shop for repair. Since it appears that the seller is from the same area of
state as he is, then my first inclination would be that this info was taken
from his computer during a repair. I just really have don't have the
expertise in this area to try and make a good determination.
If anyone has any comments, suggestions, and/or recommendations as to how
all this could have happened I would be most appreciative to read them.
I apologize if I have posted this in the wrong newsgroups.
Thanks Tag: IPC Tag: 96528
standalone CA - cannot use browser to install certs
Hi there.
I have a test lab running - it looks like this:
IPSECCA1 = the Root CA, standalone, in a workgroup called WORKGROUP
IPSECCPC1 and IPSECPC2 vista clients, in WORKGROUP
IPSECCA1 is a root CA, running 2008 AD CS, standalone, with web enrollment
installed. I can request certs, and then go to the cert authority on
IPSECCA1, and issue the certs.
Then my clients go to the website, and download the certs, and click the
install button. They say they get installed but they do not. I have to
download them to the local machine and double click them to install them. I
have noticed that the file location is missing when it does not work using
the web site to install the cert.
Anyone have an idea on why this is not working quite right?
Thanks!
Kristin Tag: IPC Tag: 96525
2008 Trend Micro Internet Security is NOT is compatible with Windows
2008 Trend Micro Internet Security is NOT is compatible with Windows
Vista SP1 and Windows XP SP3
I have deleted all of the old 2007 and new 2008 Trend Micro Internet
Security virus software from my computer, because of the multiple
alert messages, that I was having with their new 2008 upgraded
software.
If the Trend Micro Personal Firewall and the Unauthorized Changes
Prevention features main components do not work with the new service
packs from Microsoft, why are they still selling this non-working
software to the public?
Also, I don't want to wait until sometime in February 2008, for them
to released a "working" version of their Trend Micro Internet
Security, that is compatible with Windows Vista SP1 and Windows XP
SP3. I don't want to remove any new Microsoft service packs, or
uninstall the 2008 Trend Micro program installed in my computer and
re-install the PC-cillin Internet Security 2007 back into my computer,
and wait again.... until the release of their new 2008 working
version.
I was receiving these error messages: Trend Micro Internet Security
Message: Your Unauthorized Change Prevention Service has shut down.
Try restarting Trend Micro Internet Security to restore Your
Unauthorized Change Prevention Service. If the problem persists,
please restart your computer. If you continue to receive this warning,
please contact Technical Support.
I keep getting this "Alert" message: "Alert Message: Trend Micro
Internet Security. Unable to recognize the software configuration.
Restart your computer to restore the missing information. If the
problem persists, please contact technical support."
I have been working on their error alert messages and replies, since
12/24/07. After eight or more emails back and forth....and multiple
number of lines of their instructions, that's it!! I do not want to
screw up my computer, I do not want more messages, screen shots,
replies, deletes, uninstalls and then reinstalling any more files...in
my computer, hard drive or registry.
I asked Trend Micro, that I want a refund ($40.45) for this
subscription.
They replied:
I am sorry to inform you, but we can no longer refund the Trend Micro
program that you have purchased from us. Refund application should be
requested within 30 days from the date of purchase. Refunds after 30
days are given in a case to case basis. This is after the all attempts
to fix the issue failed and the case has been forwarded to the Level 2
support.
Please provide us with the following so that we can forward this to
the Level 2 support
In order for us to have a detailed picture of the problem, please
include in your reply, screen shot(s) of the message(s)/
notification(s).
Continued.....more@#$%^&
----------------------------------------------------------------------------------------------------------------
Product: Trend Micro Internet Security - 2008, Trend Micro Internet
Security Pro - 2008, Trend Micro AntiVirus plus AntiSpyware - 2008
Operating System: Windows XP - SP2, Windows Vista
Published:12/20/07 1:38 PM
Solution:
This error will appear if you have installed the 16.05 version of
Trend Micro Internet Security Pro, Trend Micro Internet Security and
Trend Micro AntiVirus plus AntiSpyware 2008 on a computer running
Windows Vista with Service Pack 1 or Window XP with Service Pack 3.
The Trend Micro Personal Firewall and the Unauthorized Changes
Prevention features main components do not work with the new service
packs from Microsoft.
A working version of Trend Micro Internet Security Pro, Trend Micro
Internet Security and Trend Micro AntiVirus plus AntiSpyware 2008 with
Windows Vista SP1 and Windows XP SP3 would be released sometime in
February 2008.
The release would be timed before Microsoft uploads the new service
packs in their automatic update servers for Windows.
To prevent this message from appearing, follow the steps indicated
below:
a.Check the program version of the Trend Micro program installed on
your computer.
b.If you are using version 16.05 and you want to continue using this
latest version of the Trend Micro program, you must uninstall the non-
working service pack from Microsoft.
c.If you do not want to remove the new Microsoft service packs, Trend
Micro suggests that you uninstall the Trend Micro program installed in
your computer and install PC-cillin Internet Security 2007 until the
release of the working version.
source:
http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1036680&id=EN-1036680
-------------------------------------------------------------------------------------------------------------------- Tag: IPC Tag: 96522
what is the best IPC mechanism that works best in Vista. We used to
use SendMessage(). But, vista doesn't like it with UAC turn-on. Does
anyone experienced the same issue?