TweakUI and Security
Hello All,
I run a small network for the employee's social club of a large company
which consisting of 1 Windows Server 2003 SP1 and several client computers
running Windows XP Pro.
The client computers are mainly provided for members of the social club to
pass their downtime such as lunch breaks by surfing the Internet and thought
to have been severely restricted using GP's so as to prevent modification of
the client computer, networking and server systems and hopefully to assist
in the prevention computer virus infection and the installation of illegal
software. Members are also prevented from logging on to the local computer
using GP.
Restrictions thought to have been enforced include only granting members
access to their own directories, the Intranet and the Internet and cannot
see the local hard drives, all system control panels hidden except where
only personal choice options are available such as selecting the autotype
feature in Internet Explorer, no access to the command prompt , etc etc
From what I can see their is no way to create new folders and store files on
the local computer nor the ability to install unauthorised software but
every so often when I scan the client hard drives they seem to doing exactly
that!
Of greatest concern is that during one of these scans I came across
"TweakUI".
I think I came across somewhere that TweakUI cannot be prevented from
running on the local computers and that all you can do is ensure continueing
refresh of the active directories group policies.
My questions is;
"What settings can I check are in place regarding the relevant GP's within
AD to ensure TweakUI or any similar software cannot be used to break the
integrity of the computer network?"
Thanking you for your assistance
David Sharman
Regional Computer Services Tag: Firewall of windows and Firefox Tag: 87906
Creating a very limited user account to run a service
Hi everybody.
I've looked everywhere, I googled, I read windowssecurity.com, I found
no information on how to do this :-(. So I have to ask for help:
I want to run Subversion as a service on a Windows XP 64bit Pro
machine. To do this, I use SrvAny.exe by Microsoft. I created a service
that runs svnserve.exe (Subversion's server process).
My problem is this: I want to create a user that svnserve.exe runs as
that is restricted to read just the directory that contains my code
repository, nothing else. The user can't login, can't open any files or
anything outside of c:\repositories.
I created an user-account called SVN (with password) using the
Computer-Management MMC and didn't add it to any group, so that it
doesn't inherit existing group-level permissions for "Users". Then I
used the Local Security Policy Snap-In to give SVN the permission to
"Logon as a Service".
But this doesn't work as it seems that any process automatically is
part of the Builtin\Users-group that, according to Sysinternal's
ProcessExplorer, is "mandatory" (whatever that means). Users has
Read/Execute rights on c:\ and these are inherited by c:\repositories.
So while SVN might not be able to read or open files, any process
started by SVN can... as far as I understand that.
However, removing "Users" from c:\ and adding SVN to c:\repositories
with "Full Control"-privileges interestingly removes SVN's ability to
read or write files vom c:\repositories even though the user account
has full control privileges...
please help me, I have no idea how to do this.
How do I create a user-account that has access to only one directory?
(and additionally all libraries that are needed to run a Win32
executable, presumably read&execute access to c:\windows and
c:\subversion)
Thanks!
-Jonas Tag: Firewall of windows and Firefox Tag: 87905
HELP
We are looking to buy databases in the following industries
* Pharmacy
* Poker
* Bingo
* Casino
* Sportsbook
* Backgammon
We will pay top $ for data
Please contact albert_constantin@walla.com
Thank you,
Albert Tag: Firewall of windows and Firefox Tag: 87900
Network Cable Disconnection and Elevated Access
We have discovered in my workplace (A School) that they students are
unplugging
the network cables as the students log on, this prevents the GP from been
applied.
This then allows them the browse the network, although they can only see
visable shares which are not many but what did surprise me was that they
could get access to the sysvol and where able not only to write to it but
change permissions.
This in turned stuffed up sysvol and forced me to do a authorative restore
on it.
Now the questions i have are
1. Whom or to what level are they been authenticated as
2. How can i prevent them from logging on if the GPOs are not applied.
3. And how do i do it in the way that won't affect the other users
(teachers) who use the machine. Tag: Firewall of windows and Firefox Tag: 87894
ADVANCED IDENTIFICATION SYSTEMS 2006 AGENDA IS SET:
The brochure for Advanced Identification Systems with Biometrics &
Security 2006 has been set and is available for download at
http://www.intertechusa.com/biometrics!
Join your colleagues, customers, competitors, and government partners
at 2006's premier event for identification! AIS 2006 will be held in
Washington, DC on December 6-8, 2006 at the Crystal City DoubleTree
Hotel and is expected to draw 300+ people and 25 exhibitors. If you
invest in, integrate, engineer, or manufacture identification systems,
solutions, products, or ID technology, or provide raw materials or
electronic components to manufacturers, do not miss this conference!
This conference is co-chaired by Terry Hartmann, Unisys; Grant Evans,
A4 Vision; Scott Carr, Digimarc; and Benjamin Brink, U.S. Government
Printing Office. Our distinguished list of contributing organizations
includes:
A4 Vision
Accenture
Animetrics
AuthenTec
BearingPoint
Cisco Systems
CA
Cross Match
Computer Sciences Corporation
Digimarc
FaceKey
Gemalto
International Association for Biometrics
International Biometrics Industry Association
International Biometric Group
IBM
Identix
ImageWare Systems
Infineon Technologies
Microsoft
Motorola
NEC America
Nortel Government Solutions
Northrop Grumman IT
Operational Research Consultants
Panasonic System Solutions
Philips Semiconductors
Precise Biometrics
Raytheon
Sagem Defense
Sagem Morpho
Siemens
Smart Card Alliance
SRA International
Sun Microsystems
The Keyser Group
Unisys
US FBI
US GPO
US GSA
US-VISIT
Advanced Identification Systems 2006 is the leading international
technical conference designed to break new ground in the discussion and
advancement of identification systems, solutions, products, and
document/ID technology by bringing together leading industry experts,
government, investors, and technology-minded organizations. With the US
Government alone spending $8 billion on identity systems and another
$14 billion on secure ID systems (Stanford Research Group) and the
market for biometrics exploding to more than $6 billion in the next 5
years, can your organization afford to miss this once-in-a-lifetime
gathering of industry experts, brilliant technologists, and government
officials? Spending on domestic security across all U.S. federal
agencies is expected to reach $58 billion in fiscal 2007 - up from
$16.8 billion in 2001, according to the Office of Management and
Budget. Additionally, states and cities are annually contributing $20
billion to $30 billion more, Gartner Inc. estimates.
This conference will address the challenges producers, purchasers, and
users are facing in the development and deployment of identification
and biometric solutions for government, law enforcement, security,
transportation, telecommunications, high-tech and IT, financial
services, retail commerce, and document/ID. Subject areas to be
addressed include: civil, criminal, and consumer ID, physical access
control, device/system access, surveillance, border control, passenger
tracking, image processing, intelligent video, time & attendance,
identity management, government initiatives, smart cards, document
security, computer vision, interoperability, standards, privacy,
algorithms, scalability & implementation, mobile ID, facial
recognition, iris recognition, AFIS/live-scan, multi biometrics,
sensors, token systems, 3D recognition, and much, much, MORE!
Plus, make the most of your time in Washington, DC and sign up for our
two three-hour pre-conference seminars, to be held December 6th -
Seminar 1: Taking Biometrics into New Markets and Seminar 2: Biometric
Sensors, Legacy Access Control Systems and Match On Card. Please check
the conference website http://www.intertechusa.com/biometrics for
details.
Advanced Identification Systems 2006 is sponsored by Sagem Morpho,
Inc., and brought to you in association with findbiometrics.com,
International Biometric Group, International Biometric Industry
Association, International Association for Biometrics, European
Biometrics Forum, Biometric Watch, Biometrics Institute, Biometric
Insight, Advanced Imaging Magazine, and Business International.
The early bird registration expires October 27th, so register now and
save $100! You can register online at
http://www.intertechusa.com/biometrics, by fax: +1-207-781-2150, by
telephone: USA +207-781-9622 or by email: syandell@intertechusa.com.
Opportunities for exhibiting, sponsoring, and attending are available,
however this conference is expected to sell out. Feel free to call
Peter H. Cheesman directly at USA +207-781-9624 or
pcheesman@intertechusa.com if you have any questions.
See you this December in the security capital of the world, Washington,
DC!!!
### Tag: Firewall of windows and Firefox Tag: 87890
Pirated software - to legal
Is there a way to take the pirated software that a user might have on their
computer and "legalize it" by paying Microsoft some money. What I mean is if
I had a "friend" give me a "pirated" copy of software and I went to the
update.microsoft.com website and it says that the copy is "Illegal" is there
a way to get a "legal" copy, via a key or download or something, of which you
will pay?
I also wonder if you have a key on the side of your computer, but your hard
drive is wiped out and you are not under warranty anymore, how you can get
that "legal" copy to work, however, you don't have the right CD to install,
such as an OEM. We have many Windows 2000 computers at my company that were
legal at one time from IBM, and I wonder if they are "legal" anymore. I am
fully aware that they are still "owned" by my company, but I see that users
have these keys as well, for XP as well, and I wonder if they buy from, Dell,
for instance and have that restoration CD that blows their system away and
forces them to start from scratch. Well, if that is ALL that they have and
someone discards the CD, is there a way to get the legal key to work without
the CD!? Maybe by calling Microsoft or something?
Thank you.
Matt Tag: Firewall of windows and Firefox Tag: 87884
Digital Certificate "There are problems with the signature"
Dear All,
We are testing out Digital Certificates as a prelude to Secure Messaging
with some of our Clients.
We obtained individual certificates for ourselves (as there is not many of
us) but started our Client on a Business account with a CA.
After setting up one of their users we notice that most times their email is
fine, but other times instead of the usual "rosette" there is a red line and
the statement "There are problems with the signature. Click the signature
button for details."
The message in the Security Properties is "Error: The message contents may
have been altered. Signed by sa@<client domain here>.com using RSA/SHA1 at
15:05:47 16/08/2006."
As we use an external mail filter (so all our mail is scanned in transit) we
believe that the scanning by our mail filter is causing the Digital
Certificate to detect a modification (or attempt) and hence the error.
My questions are:
1) Is the above assumption correct, and this is normal?
2) Is there anything that can be done to elimiate this (if caused by an
external mail scanner perhaps not)
3)If we move to Secure Messaging where the email is encrypted and hence
cannot be scanned by our mail filter, should I presume that the above error
will not appear and that all will be OK (at least as much as it should be)?
thanks
-----
pbw Tag: Firewall of windows and Firefox Tag: 87883
What is Net Neutrality?
"Congress is pushing a law that would abandon the Internet's First
Amendment -- a principle called Network Neutrality that prevents companies
like AT&T, Verizon and Comcast from deciding which Web sites work best for
you -- based on what site pays them the most. If the public doesn't speak
up now, our elected officials will cave to a multi-million dollar lobbying
campaign."
http://www.savetheinternet.com/
-- Imhotep Tag: Firewall of windows and Firefox Tag: 87850
Digital Signature and Private Key
I require a digital signature and private key for uploading onto a
router/gateway in order to provide ssl connectivity for the web interface of
the gateway through which users will log on to gain access to the Internet.
The digital signature has to have a "CRT" extension and the private key
requires a "KEY" extension.
How can I do this using Windows Server 2003 SP1?
Users of the gateway will log on the gateway from a public LAN and the
gateway will verify log on details via RADIUS using the Windows 2003 Server
on a Private Network.
Thank you for your assistance
David Sharman
Regional Computer Services Tag: Firewall of windows and Firefox Tag: 87838
unwanted history
i've got an annoying problem @ the moment. whenever i delete cookies, delete
files and clear history,theres always one site that still comes up on the
address bar. i've physically looked in the neccessary folders but cannot seem
to find the address anywhere in my computer. it only shows up on the address
bar. i then clicked on the history button and did a search.the site/page came
up.when i checked properties,it displayed: TYPE:INTERNET SHORTCUT. ive tried
a few spyware programs but i still cannot delete this one history file. i'll
paste the name of the
address:http://www.whatboyswant.com/forum_read/2280223/1/. this address goes
straight to a soccer forum page. i have no idea how to solve this problem.
can anybody help?
--
kompewter illiterat Tag: Firewall of windows and Firefox Tag: 87832
load error with xp pro
I use an OEM xp pro on my laptop. Yesterday when I started my computwer I got
the following message on a black screen: Load ERROR! Press any key to
reboot...
When I follow the instruction I get the same message.
I have a recovery CD but from this the only oportunity I get is to reinstall
XP AND i would like to awoid that as my last backup is two days old and there
are some files I havent saved. Please help.
GM Tag: Firewall of windows and Firefox Tag: 87825
Windows Information Toolbar
The new security feature in Windows XP Service Pack 2 (SP2), the information
toolbar, used to appear. It has suddenly stopped appearing. How do I turn
it on again?
Denise Tag: Firewall of windows and Firefox Tag: 87801
Public Addresses Used Internally
What would be the vulnerabilities, issues, problems etc, of using public
addresses on an internal network behind a firewall? Tag: Firewall of windows and Firefox Tag: 87797
rootkits
I just used RootkitRevealer and it found 2 paths that contained "Keyname
contains embedded nuls (*)". Both are HKLM\SOFTWARE\Classes\CLSID\{numbers}
keys.
Should I be worried? do something?
Thanks.
Jeff Tag: Firewall of windows and Firefox Tag: 87791
Internet Explorer 6 Message Box
Always have had a shortcut to my Temporary Internet file folder on my destop.
All of sudden when I double click on it it says: "This page has an
unspecified potential security flaw. Would you like to continue?" Y or N.
Can't open it to find out more. I cannot get rid of it & I've done PC scans,
defrags, (3) programs for spam, etc. & untold virus scans. I can open the
target file without the box appearing. I can also create other shortcuts
without the box.
I have 768mg of memory, Windows XP (with SP2) Home Edition, AOL 9 Security
Edition SE. By the way, AOL says it is a windows problem since IE is a
windows program. Probably right on 1 score out of 100?
--
HELP! I am PC literate. Tag: Firewall of windows and Firefox Tag: 87788
"logon as a service" and "logon as a batch job"
Gurus,
I understand, in highly secure environments, where you have to in certain
situations have to give certain accounts the "logon as a service" right.
But how does one know when to also give that account the "logon as a batch
job" right?
--
Spin Tag: Firewall of windows and Firefox Tag: 87777
Windows BitDefencer won't work
I've been trying to run aWindows BitDefencer on-line scan. Each time, I'm
told to click "allow Active X control" on the information bar. The
information bar doesn't appear and I can't proceed. I get a box with a
triangle in it. The triangle has a yellow exclamation point in it and two
words, "yes" and "no" appear. Neither allow BitDefender to run when selected.
I've already temporarily turned off pop-up blocker.
In Manage Add-Ons, Uninstall Bit Defender is enabled (I didn't change the
setting).
How can I get the informatin bar to appear? What settings need to be
changed so that I can run BitDefeder.
Denise Tag: Firewall of windows and Firefox Tag: 87776
Wormy bots exploiting Windows Server flaw
Wormy bots exploiting Windows Server flaw
"Network administrators noticed an increase this week in scans for Windows
computers vulnerable to the Windows Server service flaw fixed by Microsoft
last month.
The scans are due, at least in part, to a variant of the SDBot
program--also known as rBot and Randex--that has been modified to use the
Microsoft flaw and set to spread automatically. It took less than a week
for underground programmers to modify their bot software to take advantage
of the latest Windows flaw, described in security bulletin MS06-040."
http://www.securityfocus.com/brief/293
--Imhotep Tag: Firewall of windows and Firefox Tag: 87771
Microsoft Attempts to Quash OSS Recommendations
Microsoft Attempts to Quash OSS Recommendations
"Inside Higher Ed has a story detailing Microsoft's attempt to alter a
report created by the Secretary of Education's Commission on the Future of
Higher Education. Gerri Elliott, corporate vice president at Microsoft's
Worldwide Public Sector division, complained about recommendations in the
report to look into 'open source' and 'open content' at higher education
institutions across the country. Elliott, who is on the voting committee,
waited until the last minute and tried to have the report changed after a
public vote. Although she does have a point that 'open source' is a
development model, it still has collaboration at its heart. Can Microsoft
argue against 'open' and win?"
http://politics.slashdot.org/article.pl?sid=06/09/01/1418252&from=rss
-- Imhotep Tag: Firewall of windows and Firefox Tag: 87765
Autoenrollment problems - Enrollment access is not allowed to this template computer
I am having difficulty setting up autoenrollment for computer
certificates with Windows 2003 SP1 Enterprise Edition CA server. I
have the GPO setup to perform autoenrollemtn and Automatic Certificate
Request to request a computer certificate as specified in a number of
documents. The end workstation or server upon boot or gpupdate
responds with a Event ID 7:
Automatic certificate enrollment for local system could not enroll for
Computer certificate template due to one of the following:
Enrollment access is not allowed to this template.
Template subject name, signature, or hardware requirements cannot be
met.
No valid certificate authority can be found to issue this template.
So it obviously seeing the autoenrollment policy. I checked the
computer template under Certificate Templates on the CA, and Computer
was indeed set to no for autoenrollment with no option to change that.
I selected to enable a new template (Workstation), which was yes to
autoenrollment, but it does not appear in the Automatic Certificate
Request Wizard as a template to request.
Any help would be appreciated. Tag: Firewall of windows and Firefox Tag: 87763
Require updates
What can I do to prevent new computers, or laptops that haven't
connected in a while, from joining the domain until they have all
required patches and updates? Thanks for any suggestions. Tag: Firewall of windows and Firefox Tag: 87756
I was just wondering
I was just wondering with all the advances in the linux community, when is MS
Linux going to be released? Tag: Firewall of windows and Firefox Tag: 87752
Outlook sending unathorized e-mails
Hi:
I have Windows XP Pro, with Norton Virus protection, I have ran the stinger
programs offered by McAfee, and have all the windows XP security updates.
My Outlook seems to be sending unwanted and unarthorized e-mails (spam) out
to various people who have the same e-mail @xxx.com as I do. The name Harry,
geradine, etc, appears outside the bracketts in which show my name and e-mail
address as the perso who is sending it. I have check the properties of the
mails that are being baounced back, and the properites state the the mails
are from the "Microsoft Outlook Embeded folder. When I run a search for this
folder, the search window shows not files within it, but the information
shown on the upper left corner of the search window states that 122 files
have been found.
I would like to stop this from happening, but none of my virus scans
indicate that there is anything wrong.
Any help here would be apprieciated.
M Macy Tag: Firewall of windows and Firefox Tag: 87745
Reveal Users Using a File
I need to find out which users are currently using a file on a network
(so I can get them too close it). If there some tool or way anyone
knows to do this? Tag: Firewall of windows and Firefox Tag: 87736
Downloading!
Hi,
When I try to download off of the intranet I get a message saying "your
current security settings does not allow you to download this file". I went
into intranet options and changed everything to low and it didnt help. I
still can't download anything can anyone help?
Thanks, Tag: Firewall of windows and Firefox Tag: 87734
Blackice Detecting TCP and UDP probes from printserver
Hi,
I've got a user running Blackice and he's getting about 15,000 probes
a day from one of our print servers. Everything that I've seen points to
someone maliciously running scans, but I don't think that this is the case
this time. Is there any reason in the Window's world that a server would
probe a workstation? I don't see anything in the event logs that corresponds
to the probe times and he doesn't use that print server. Here's a sample of
the Blackice log:
Time, Event, Intruder, Count
8/24/2006 1:07:23 PM, UDP_Probe_SNMP, PRINT-37, 519
8/24/2006 1:08:22 PM, TCP_Probe_Other, PRINT-37, 10290
8/24/2006 7:32:57 PM, UDP_Probe_SNMP, PRINT-37, 564
8/24/2006 7:33:30 PM, TCP_Probe_Other, PRINT-37, 11382
8/25/2006 6:15:36 PM, UDP_Probe_SNMP, PRINT-37, 923
8/25/2006 6:16:09 PM, TCP_Probe_Other, PRINT-37, 20078
8/28/2006 7:20:15 PM, UDP_Probe_SNMP, PRINT-37, 1124
8/28/2006 7:22:11 PM, TCP_Probe_Other, PRINT-37, 21563
8/29/2006 8:19:34 AM, UDP_Probe_SNMP, PRINT-37, 75
8/29/2006 8:20:30 AM, TCP_Probe_Other, PRINT-37, 1914
8/29/2006 1:15:15 PM, UDP_Probe_SNMP, PRINT-37, 382
8/29/2006 1:15:41 PM, TCP_Probe_Other, PRINT-37, 8811 Tag: Firewall of windows and Firefox Tag: 87727
Help with virus removal please
Somehow I've gotten a Java Virus.
Running XP home with AVG free, trendmicro anti spy and spybot s&d.
This is what shows up on AVG report.
Application Data/Sun
Java/ByteVerify
Infected Embedded
Trojan horse Java/Class Loader
I was able to move the Byte verify to the virus vault but I can't figure out
how to get rid of the Trojan.
Would removing the Java program and reinstalling it help?
I'm not that computer savy and just noticed it this morning.
All help is appreciated.
Thanks Tag: Firewall of windows and Firefox Tag: 87726
windows firewall vs ipsec
Hi all
can someone help what would be good to use windows firewall or Ipsec
till now we had been using ipsed on windows 2000
one thing i can see is that windows firewall doesnt behave as real firewall
it doesnt allow to block /allow specific subnets
can any one guide difference /advantages
also we need to script out so that it can be deployed on multiple servers in
a standrad manner
I culd find a few help on firewall scripting but nthing on ipsec can some
help me
alos by boss is adamant to know exactly does ipsec gives best protection
agains other kind of s/w firewalls available?
Also since for linux boxes we use iptables which work at kernel level
can anyone tell how equally secure is ipsec for windows
we need to take some policy decsions for using ipsec for more than 200
webserver and almost 50 sql servers
Regards
Deepa Tag: Firewall of windows and Firefox Tag: 87713
Want a good basic book on computers/computer security
Recent help I have got from this excellent forum has made me realise I need
to learn more. I'm extremely ignorant. I often have questions to ask
(often, often, often) that I am too embarrassed to post, because they are so
stupid (even more stupid than the ones I do post.)
I wondered if anyone could recommend a book for beginners, or even a
beginners forum which would give me a bit more understanding. I use
Firefox with a few Greasemonkey scripts, Photoshop to a reasonable level,
itunes - so I'm not totally on the bottom rung, but tons and tons of stuff,
especially re. security, is just beyond me. It is made much more difficult
because it is so scary to deal with. You feel if you make one mistake
everything will go pop.
Any good books or beginner forums please? Tag: Firewall of windows and Firefox Tag: 87712
frequently-traveling users and their company-issued laptops
Gurus,
For you IT manager types working at large companies, what is your policy
regarding frequently-traveling users who have company-issued laptops - what
level of rights do you give them to their laptops? Do you make them local
administrators or what? If you do not make them local administrators - do
you make them call in a ticket everytime they want to install some software?
--
Spin Tag: Firewall of windows and Firefox Tag: 87701
Windows XP Home- Backup Utility
I just discovered I do not have this nor do I own an XP Home CD. Where do I
get the utility? Does MS make it available for download somewhere?
If not is there an acceptable alternative tool? Tag: Firewall of windows and Firefox Tag: 87699
Brains, Spirit & Computer For Thought,
Hiya,
My computer, froze up real bad. At 1st, I thought it was a relatively new
(but old) so called but not officially known as virus named "Recycler
Virus". Only 1 company (of Asian www address name) claims it is a virus and
what they told me is it changes the windows registry (Windows XP) and none
of what they listed actually occured in my Home Edition w/SP2. BUT that
damned thing could not be deleted and resurfaced AFTER formatting the
computer and a quick visit to windows update and sophos.com (antivirus).
The computer would freeze upon any bootup except administrator in safe mode
(any version of safe mode in xp)
Okay. Next thing. Anybody study Hinduism? Remember Bill Gates transfered
a huge relationship to India years ago? Them Indians activate Windows XP by
phone. Can anyone tell me how the windows confirmation will tell me i got a
digit (number) wrong if my computer does not have the confirmation ID at all
and randomly generates the 9 group series of 6 numbers? Oh, BTW, not
connected to any wiring hard or wireless and no internet at all too. The
man on the phone with me told me that the confirmation ID number is randomly
generated there at his office. It was 7:15 a. m. there, near 10 pm est
here. Hinduism & MTV. A man stands on the shore of the Indian Ocean and a
woman in Maine w/o photos, computers, internet, phone, tv can see what he
sees there. MTV had a video of four women in different places of the Earth
could see what any one of the others could see - by the minds eye.
This is your computer, Apple Mac, Linux or PC Windows (any version). This
is your brain behind your eyes. Mix it all together and you got.
Well you got the 21st century at (mostly your) command.
Windows Vista anybody? Heh, A Microsoft Tech Support person told me via
phone that when Vista is in one computer and you remove that hard drive (for
any reason) and put it in an identical / replica computer, the hard drive
will not boot up and you will be lucky if you can format the hard drive.
It's called encryption (if you did not know).
Regarding the Homeland Security Department announcement back in early August
2006 about a flaw in Microsofts OS's and get the patch. Some of us, most of
us and maybe all of know now that the patch froze computers and corrupted
memory. If not that patch, one or two or three recently released this
August 2006.
How many "illegal" copies of Vista are around? Hey, if it weren't for
"illegal", well remember Napster and KaZaA - IMHO they weren't illegal, just
a pain in thy AS* for anybody exept the user. Okay, there were problems
there too.
Um, did Microsoft tell you outright up front and before you installed the
update that your XP/98SE/98/ME/95 was subject to "beta" testing by them or
anyone else regarding encryption - Vista? Did anyone tell you? Oh, if you
are like me, you were somewhat aware of "use at your own risk" policy,
stated or not stated by any company/friend/stranger anywhere.
As I was typing this all up, a passerby more than 30 feet away outside this
window said aloud "powerful". Ya, the part about Hinduism is indeed powerful
and add the brain meets the computer and MTV too, that's really powerful.
I'm thinking by 2050 I would be able to put on a pair of sunglasses and
watch TV or read email on 1/2 a lense while driving down the road (he he he
he) and listen to the next U2 or W. K. Mahler from the earpiece embedded on
the sunglass arm.....
Remember, if I want to recycle computer parts (Recycler Virus) I oughta be
able to anytime I want. Just imagine your dad's doctor planning your dads
open heart surgery and the doctors computer fries but the hard drive is
good. With Vista, it better be usable.
Luv ya some, luv ya not at all.
Sincerely,
William K. Mahler
http://www.mahlers.com
SKYPE ID: mahlersdotcom
...still installing all new stuff into this computer, new HD, new CMOS
battery, after all even my HD was not recognized in its true model number
and sometimes was not there at all in the last week.
PS. Anybody want to catch a sniper? How about find your hard drive when
(I'm hoping not) it's stolen.
Read this:
X Marks the Sniper:
Tracking Bullets to Save Lives
http://www.research.uky.edu/odyssey/fall05/sniper.html Tag: Firewall of windows and Firefox Tag: 87696
SetTokenInformation
Hi,
I am getting a "Invalid Parameter" exception (Error Code 87) when I try to
use SetTokenInformation or GetTokenInformation inside a windows NT Service.
The service is running with administrator rights.
HANDLE hToken;
SECURITY_IMPERSONATION_LEVEL imp_level;
imp_level = SecurityIdentification;
if ( OpenProcessToken( GetCurrentProcess(), TOKEN_WRITE, &hToken))
{
SetTokenInformation( hToken, TokenImpersonationLevel, (LPVOID) &imp_level,
sizeof(imp_level)); //This line returns an error code of 87
}
Has anybody come across this error? Any help will be greatly appreciated.
Thanks,
K Tag: Firewall of windows and Firefox Tag: 87695
Hackers steal AT&T customer data
Hackers steal AT&T customer data
"...Hackers have obtained the credit card details of almost 19,000 online
shoppers from telecoms giant AT&T.
The US company said it had notified shoppers at its online store of the
security breach, which affected people buying high-speed DSL internet
items."
http://news.bbc.co.uk/2/hi/technology/5297710.stm
--Imhotep Tag: Firewall of windows and Firefox Tag: 87694
Monitor account
Hi - we have an account used in our mfg process. It is used to logon to
several systems that run 24/7. The account gets locked out periodically and
denies access to several drives/databases. is there a way to audit/monitor
this account and have it email/alert someone when this happens? Tag: Firewall of windows and Firefox Tag: 87692
proposed implementation of an Enterprise CA
I have a few questions regarding a proposed implementation of an Enterprise
CA into our production environment, which Iâ??m hoping people can give me feed
back on. Iâ??ve read a lot of the Microsoft documentation on PKI, however
sometimes thereâ??s no substitute to real word experience etc.
The drive behind the need to deploy a PKI is the move to RADIUS Auth PEAP
MSCHAP v2 for our Wireless clients. Iâ??ve successfully created a test lab
using a CISCO 1100 Series AP, and one windows 2003 enterprise server running
AD, IAS, IIS 6 & Enterprise CA. We have ruled out the purchase of 3rd party
certificates for our IAS servers and wish to deploy a PKI.
Due to our size (under one hundred users) and our modest needs to initially
improve wireless security a three tier PKI seams overkill. We can also
easily physically secure our Enterprise CA in a secure data centre.
To Outline of our environment:
All servers running Windows 2003 Enterprise with SP1, all clients winXP pro
SP2
Site 1 (Secure Data centre)
1 x Enterprise root CA (proposed location)
2 x DC
1 x Exchange server
Site 2 (Office1) Connected to Site 1 via hardware VPN
2 x IAS Server
2 x DC
50 x Wireless Users (Access 802.1x - PEAP MSCHAP v2)
Site 3 (Office 2) Connected to Site 1 via hardware VPN
2 x IAS Server
2 x DC
50 x Wireless Users (Access 802.1x - PEAP MSCHAP v2)
Questions:
1 â?? Will the deployment of a Enterprise CA in our production environment
require any GP changes for DCâ??s and clients? As I understand it a single
tier CA publishes the certs to AD.
2 â?? Our exchange server has a Thawte SSL cert for RPC/HTTPS and OWA access.
Can we scrape this on renewal and issue our own from our Enterprise CA?
And if so will this only work for access via domain member machines and non
domain members will be required to install a cert from us?
3 â?? Once the Enterprise CA has issued the cert to the IAS servers thereâ??s no
â??continualâ?? traffic between the Enterprise CA and IAS servers? i.e. only if
revoked etc.
4 â?? I donâ??t need IIS on the CA as web enrolment is only needed for win2000
or non windows clients and all my clients are winXP pro SP2. Correct?
5 â?? A open ended question I know but any thoughts I guess - In my test lab
it was simply a case of installing the Enterprise CA, gpupdate and off I
went. Is there anything else I should be aware of when I go to production?
6 â?? Is the proposal sound for our needs?
If you got this far, thanks
Steve Tag: Firewall of windows and Firefox Tag: 87688
USB Spy
I'm a system administrator and working in a security area. Any USB plug-in
hardware devices like Pendrive Camera etc.. is forbidden. I was asked to
look for some software that tracks users violating the above restrictions.
This software could be installed inside the users PC's(I can install it from
my server), in the Domain Controller or anywhere.
What are the alternatives available in the market?
Thanks in advance
Gil Tag: Firewall of windows and Firefox Tag: 87687
Microsoft tackles anti-copy hole
Microsoft tackles anti-copy hole
"Microsoft has said it is working to close a breach of its technology that
protects music digital files from copyright infringement.
A program called Fairuse4wm has been posted on the net and is said to be
capable of bypassing Microsoft's Digital Rights Management (DRM) system."
http://news.bbc.co.uk/2/hi/technology/5294750.stm
Im Tag: Firewall of windows and Firefox Tag: 87677
Net Neutrality Being Examined by FTC
Net Neutrality Being Examined by FTC
"Chairwoman Deborah Platt Majoras on Monday also called on lawmakers to be
cautious about passing a Net neutrality law, which could prohibit broadband
providers such as AT&T Inc. and Comcast Corp. from giving their own
Internet content top priority, or from charging Web sites additional fees
for faster service. [...] 'While I am sounding cautionary notes about new
legislation, let me make clear that if broadband providers engage in
anticompetitive conduct, we will not hesitate to act using our existing
authority,' she said. 'But I have to say, thus far, proponents of Net
neutrality regulation have not come to us to explain where the market is
failing or what anticompetitive conduct we should challenge.'"
http://yro.slashdot.org/article.pl?sid=06/08/23/2012231&from=rss
Imhotep Tag: Firewall of windows and Firefox Tag: 87674
Default domain Policy error
We are getting the following error when going in to our default domain policy:
The following error occurred in
\\ourdomain.com\sysvol\ourdomain.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Adm\system.adm on line 63:
Error 62 The corresponding string was not found in the [strings] section
Found: !!AdministrativeServices_Help
The file can not be loaded.
We are running a mixed mode of Windows 2003 and Windows 2000 domain
controllers. Nothing shows up in the event log of the domain controller.
Any assistance is greatly appreciated. Thanks. Tag: Firewall of windows and Firefox Tag: 87673
Event 675 on my nerves
I recently changed my password, after doing so I am finding that one of our
servers is using my credentials for some event and is causing my account to
lock out. The requests do not come at regular intervals, and typically come
a couple at a time. First 2 then another 3 or first 1 then 2 more then
another 2. In any case I'm going mad trying to figure this one out.
Here's some other ideas I've already tried...Anyone else have suggestions on
how I can find what is using my credentials on a regular basis?
The server in question has no rogue RDP/ terminal server sessions that would
cause this.
None of the services listed show my username in the 'Log on as' field.
There are no mapped drives (other than loginscript drives) that reference my
user info.
If there was any question about a profile not being able to unload I
installed and ran the "UPHclean" utility from Microsoft.
Thanks! Tag: Firewall of windows and Firefox Tag: 87671
Need Advice on spoolsv.exe
I'm having trouble with my PC when I start up it sometimes Locks and the CPU
usage is at a maximum. After running Ad-Aware, McAfee VirusScan and
AntiSpyware(all up to date) nothing showed up. On a start up one time I got a
brief message about a spoolsv.exe error so after each start up I check
Process Explorer and see spoolsv.exe running and its Location is
C:\WINDOWS\system32\dllcache\spoolsvc.exe. After I did some research I now
find some sites and forums say its a spybot worm and should be Deleted while
others say its a system file for Network Printing and I could be in Danger
if I touch it. When I ran a Search I found it at three locations. They are
C:\WINDOWS\system32\spoolsv.exe
C:\i386\spoolsv.exe
C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
When I ran sigverif it says C:\WINDOWS\system32\spoolsv.exe has not been
digitally signed.
What Action can I take with any or all of these .exe files?
Can I Delete or should I Fix in Hyjack This? If this file is Deleted will I
be able to start up OK? or is there another action I can take?
Please, Any Help Greatly Appreciated, Thanks. Tag: Firewall of windows and Firefox Tag: 87662
Solicting opinions - What is your favorite SSH client?
Not a Windows question, but I wanted to ask what is your favorite SSH
client? Running Windows 2003 and there are a lot of freeware out there to
choose from. I would rather pick something that someone recommends from
these groups.
--
Spin Tag: Firewall of windows and Firefox Tag: 87645
ActiveX controls not downloading over SSL
Hi,
I created an ActiveX control. The control is on the server. It can be
installed on the client machines when I connect to the site using HTTP but it
doesnt download and install on the client machine when i use HTTPS (SSL) to
connect to the site.
Why is that? ANy ideas are welcome.
Thanks
--
pmud Tag: Firewall of windows and Firefox Tag: 87634
Allow only specific websites on entire network
I am trying to find out how exactly to lockdown the network here so that
users only have access to certain websites. I know this can be done on
individual systems, but I would like to do it network wide. We have about 100
systems on the network running server 2K3 standard. I have been told this OS
can do this but I have been unable to locate how to. Tag: Firewall of windows and Firefox Tag: 87631
Replacement for unsecure telnet/ftp on Windows servers
When is Microsoft going to make available a secure
replacement ( e.g. ssh/scp ) for telnet and ftp
on their Windows server versions?
--
Gary Flynn
Security Engineer
James Madison University
www.jmu.edu/computing/security Tag: Firewall of windows and Firefox Tag: 87629
smartcard , IE
For windows login I use username/password.
-------------------------
I see the same certificate in IE certificates list the certificate in
the SmartCard.
But IE never try to read the certificate and send to the server when
the Server is asking client
certificate during SSL handshake.
If I have a non smartcard certificate in the personal tab of IE
Certificate list, It is working fine.
IE sending that certificate to Server.
What am I missing to make IE read the certificate from SmartCard and
send to the server?
I am using XP SP2
Regards
Krishna Tag: Firewall of windows and Firefox Tag: 87628
xp home mce question
Hi. I am trying to connect my xbox 360 to my MCE pc. My xbox cannot create
a user account on my pc. when I go into lusrmgr.msc, it says:
This computer is running Windows XP Home Edition. This snapin may not be
used with that version of Windows. To manage user accounts for this computer,
use the User Accounts tool in the Control Panel.
Does anyone know how I can fix this so my xbox can talk to MCE? thanks. Tag: Firewall of windows and Firefox Tag: 87625
Automatic XP Updates
Something is turning my 'Automatic Updates' off! I go in and turn it back on
and within 10 minutes 'Norton Protection Center' flashes a message telling
that updates is turned off. Help! Tag: Firewall of windows and Firefox Tag: 87621
Eliminating User signon on Windows XP
I have a simple question -- a change has recently been made in the way we
sign onto our PC, I assume from some Windows Update, and I cannot figure out
how to change back to the old procedure.
There are only two of us using this PC, and there is NO need to have to
click onto a user-specific icon to start up Windows XP and move onto tthe
desktop we share (i.e. no need to select a user to load personalized desktop
images -- we use the same desktop). I cannot figure out how to eliminate
this step, and allow our PC to move straight to the desktop without having us
to choose the only user we have identified. Can anyone give me step by step
instructions on how to eliminate this senseless step?
--
LAND SHARK Tag: Firewall of windows and Firefox Tag: 87615
When i see video stream from websites the firewall of windows question
for access to the internet to Firefox.
¿is't normal, no security issues?