Encrypt UsernameToken using WS-Policy (WSE 2.0)
Hi ,
How to Encrypt a UsernameToken using WS-Policy.
I was able to do that using Code as :
SecurityToken token = new UsernameToken(t_username.Text,
> t_password.Text,
> PasswordOption.SendPlainText);
>
>
> SecurityToken issuerToken = GetServerTokenForEncryption();
>
>
> // Sign the security token request.
> client.RequestSoapContext.Security.Elements.Add( new EncryptedData(
> issuerToken, string.Format("#{0}",token.Id )) );
>
But how to do the same using Policy.
Thanks in Adv.
Ravi Dasari Tag: VSS Project Security Tag: 69189
Startup Accounts
Using NIS 2004 in XP/SP2. Does creating a restricted account and designating
it the startup account provide any internet security or is it simply to deal
with multiple users ? I am the only user on the computer. TIA. Tag: VSS Project Security Tag: 69183
Service Pack 2
I am being told by my Service Provider not to install SP2. I am told that it
has a lot of problems. From reading about it I think that it has some good
features but I'm concerned that if I install it I wont be able to connect to
the net. Any comments, I appreciated any experienced in this matter. sam Tag: VSS Project Security Tag: 69174
perfect keylogger bkp.exe
this program have the posibility of inserted in any program, sending via smpt
information.
search this files :
bkp.exe
bpk.dat
norton don`t detect this keylooger
ms antispyware beta1 dont detect
solucion this problem Tag: VSS Project Security Tag: 69171
FTP access, Userlogin access denied
We have an FTP server that users can no longer login to. Also, users within
the network are not able to login to the computer with the local policy.
The errors give are: "Local policy of sysem does not permit you to login
interactively" trying to login to the server with a username and "Could not
login to the FTP server with the username and password specified".
What is causing this login problem? Local Policy Setting? Tag: VSS Project Security Tag: 69166
Uninstall z-ball 1
I don't really know where to turn for help on this...I've "googled" but to no
avail! One of our (former!!) staff downloaded a lot of "junk" onto his PC,
which I have spent a lot of time trying to get rid of. I'm down to one
item...apparently a game called z-ball 1.80f. I tried to uninstall it using
the add/remove programs in control panel, but it says I don't have access to
z-ball\unins000.exe. I can't find such an item on either his hard drive or
his network folder. Has anyone ever heard of this and have any idea as to
how to get rid of it? Tag: VSS Project Security Tag: 69153
How to disable BHO under winxp sp2?
I remember that somebody here said that SP2 will allow us to disable
BHOs (although not directly remove them). Does someone know
how(where) to acomplish this?
Trust No One! Tag: VSS Project Security Tag: 69146
virus
i dont know how but i think i have a virus on my p.c. i found the file and
also found that if i change what program the file ran on i could open the
programs i wanted 2 where before i couldnt open anything...then i used bit
defender to delete it now i cant open anything except explorer, IE, microsoft
office, connect 2 the internet and thats all i know so far. i cant open
anything through explorer or on the desktop except explorer and IE but
nothing else at all opens. messenger, and of my anti-viruses nothing so if
anyone can help or suggest a way to get rid of the virus would be
helpful...thanks Tag: VSS Project Security Tag: 69145
How to avoid router broadcast to windows clients?
Hi all,
Last week we had somebody at our LAN plugging an ADSL router configured with
Ip address 192.168.1.1 and RIP v1
, of course the router started to broadcast it's presence ...
Most if not all Workstations accepted the broadcast and took 192.168.1.1 as
their GW instead of the DHCP supplied one even the one with SP2 FW ..
Needless to say that it was a chaos .
Is this a normal behaviour ? ( 192.168.1.1 is Not in the subnet of the Lan
interface of the PC !)
what can I do to avoid that in the future ?
Thanks in advance for any ideas / feedbacks.
Best regards,
Berni Tag: VSS Project Security Tag: 69144
Windows Update vs. SUS
This should be an easy one.
I currently use SUS for applying updates with the
Severity of 'Critical'...this seems to be working fine.
However, after SUS has updated the machines (and they
have successfully rebooted) and I have verified that the
updates have been applied by using the MBSA (identifying
the SUS server as the source); if I have the machine go
out to the Windows Update site, it is identifying that
there are still critical updates that need to be
applied. When I look at the technical aspects of one of
the "missing" critical updates - the severity
is "important" not critical.
Example:MS04-041 (885836)
The technical site for this update shows that it has a
Maximum Severity Rating of "Important".....But, when
Windows Update performs a scan for updates - the 885836
is showing as "critical". Can someone clairify this for
me please? Tag: VSS Project Security Tag: 69138
Logon Scripts with Windows Firewall
I have just installed 10 new Windows XP Workstations with Service Pack 2
replacing older ones running Windows 98 Second Edition. The Server is
running Windows Server 2000. When logging onto the Domain with the new
workstations, the logon script (defined in the users profile) do not execute.
After doing some initial troubleshooting, I discovered if the Windows
Firewall was disable the logon script worked. The logon script is a batch
file. Tag: VSS Project Security Tag: 69125
Network security.
I am part of a smaller network (25 or so). It is my understanding that i am
not supposed to give out my log-on password to anyone. This keeps my PC
secure. This is why the password tab on the server for me comes up with
astricks. If they want into my PC they (the administrator of the network)
should have the local password for my PC. Is this right or should I give up
my password? Tag: VSS Project Security Tag: 69117
windows explorer runs spontaniuosly in backround killing my memory
Hi all
Is any one familiar with this phenomena??
On windows start up (windowsXP professional sp1), windows explorer exe
(explorer.exe) start's up
as well. It run's on the back ground consuming growing amount of memory.
After killing it's process through task manager task bar is immediatly
gone... but i am able to continue working with
applications that were already runing.
Any idea what's going on or how shell i handle this?
Thanks in advance
Rea Tag: VSS Project Security Tag: 69111
Anti virus software?
I keep hearing on the radio and other places that without
anti-virus software (PC-cillin, Norton, or some other)
a PC computer connected to the internet will get a virus
within a couple minutes.
I've been using the internet for several years now with no
virus protection and haven't detected any viruses on my Windows
95 system.
Is it possible the new viruses today will not run on an
old Win 95 setup and I don't have to worry about it, or
should I install a firewall and anti-virus software for
added protection.
How would I know if a virus is on my system? Everything
seems to work ok.
-Bill Tag: VSS Project Security Tag: 69105
smileycentral spyware via 'good luck' email?
I recently forwarded a 'funny' email from a relative. When I opened it, I
was hit with the MSIE notification I was about to visit a secure website.
Since there is no way to say "NO!" to this notification, I forced Outlook to
close via Task Manager.
I later saved the message as a msg file and inspected the HTML part. It was
a 'pass it on and have good luck' message filled with references to
smileycentral.com, both to web pages and .gif files. But none of these
addresses were HTTPS. The only thing I can figure is that one of the image
files was being redirected to a secure site.
What would be the purpose of this? Is there a vulnerability in Outlook
2000/MSIE that would allow smileycentral to install spyware via such an
email?
thanks,
nf Tag: VSS Project Security Tag: 69102
software to remove IE toolbar or BHO?
My IE have too many toolbars installed. It's slowdown my system and
IE, there is any way to get rid of this toolbars or BHOs?
Thanks in advance! Tag: VSS Project Security Tag: 69101
Avast 4 Home Anti-virus
Hi,
I de-installed my Norton 2003 and installed Avast 4 Home instead, however,
it messed up my settings for emails and internet. I could no longer get my
messages and when I was trying to open Internet explorer, I was getting that
page where it says that the page is missing.
I received the keys from Avast and have 60 days to register Avast. My
question is if I register it and get updates, is it going to mess up my
emails and internet settings? I had to call my ISP to help me in solving the
problem and spent over 45 minutes. So I don't feel like going through this
again. Let me know your comments.
I have the following software installed:
Windows 98
Outlook Express
Internet Explorer
Avast 4
Zone Alarm
Ad-aware
Spybot- Search & Destroy
Thanks,
Christie Tag: VSS Project Security Tag: 69096
Remote Desktop secure
I have to administer my bussines servers from home. I always use a vpn for
it. My question is: is remote desktop only (without vpn) as secure provided
that high secure policy is used? Tag: VSS Project Security Tag: 69094
outlook user/password in clear
I notice that when I use my outlook 2000 sp1 with XP I can see the user name
and password in the clear as it goes to the SBC sever they say it is a M/S
problem or I have a password cracker allowing it to go out that way. Well I
know I have no cracker sw. fresh install. Is this the way outlook normally
sends out user/password or maybe Iam missing a setting. Tag: VSS Project Security Tag: 69082
Repeatedly rcvg update KB837009 Outlook Express 6
Over the past several months, I'v received the Cumulative Security Update for
Outlook Express 6 Service Pack KB837009 over and over. I've apparently
downloaded it successfully numerous times, but it keeps coming every few
days. I'm running Window 98 SE on a Pentium II. Tag: VSS Project Security Tag: 69080
explorer redirects to google and eventually disconnects from inter
Using Windows XP. Anti-spyware does not detect any problems, nor does virus
software, yet internet explorer 6 consistently attempts to redirect to google
or other web sites, and eventually terminates connection to the internet
(cable connection). I have to reboot the computer every time to get back to
the internet. 15 or 20 minutes later, it happens again. Any suggestions? Tag: VSS Project Security Tag: 69067
connecting to another server
Hi,
I've recently taken over the network at our business and I'm flying by the
seat of my pants on how to do some of the networking tasks and such.
We connect remotely to an afp server to upload files for printing. For some
reason that I can't determine, the service is not working properly. I
recently (within the last month) ran windows update on one of our two servers
(both of which are runing windows server 2003 standard edition). Is this
affecting a firewall somehow? If so, where are the firewall settings located
so at the very least I can turn it off long enough to transfer, then turn it
back on? Additionally, if there is a way to list set locations on a safe
list, I would like to be able to do that so in the future we do not have this
problem If it makes any difference, the computer I'm trying to transfer from
is a Mac.
Something else I noticed that I'm not sure may or may not affect the
operation of our system is that one server shows updates on automatic updates
and the other doesn't. Should the two be running on the same service pack
updates for the optimum compatibility?
Any help would be appreciated.
Thanks,
Jessica Tag: VSS Project Security Tag: 69059
Deleting Unwanted Programs
HELP...Please. When I go to the add or remove area of my Control Panel to
remove three unwanted programs that are listed there (Shopping Wizard, Search
Extender, and Home Search Assistent), I am directed to a website with
mis-spelled words and it will not un-install these programs. Please help! I
don't know how to get these off of my computer. Thanks in advance!
--
Star Tag: VSS Project Security Tag: 69053
Complex Password policy doesn't set under the CP Applet..works fine from MMC
has anyone else come across this?
Standalone W2k Pro computer.
Local Policy is set to ENFORCE STRONG PASSWORDS.
It will restrict blank passwords in the MMC, but if you use the user and
password applet under the control panel it doesn't restrict it.
Any ideas?
Thanks
awonders-at-aharinc.-dot-.com Tag: VSS Project Security Tag: 69052
Requesting a Certificate with Mutilple Common Names
How do I request a certificate with multiple CNs using IIS certificate
request wizard?
The CA is a sub-ordinate root CA running Microsoft Certificate Server which
is bundled with Server 2003 Std. Edition Tag: VSS Project Security Tag: 69048
File access auditing fills security log too fast
I am attempting to enable file and application auditing to meet HIPAA
compliance. The issue I am having is the security log fills up way to fast,
eventually locking out all but administrators from logging on. I know I can
disable this, but I would rather just audit when the file or app was accessed
and by whom. I have been experimenting with the auditing settings, but no
matter what I do, even opening one folder creates 10 security items in the
event log. Does anyone have any tips on how to narrow down what is entered
into the event log? Tag: VSS Project Security Tag: 69047
CRL is unavailable or expired on any VALID S/MIME Signature
is there any solution out there? I still get this error message on outlook
XP on W2k (clicking S/MIME Signature Propeties)...
something like ...
http://support.microsoft.com/?kbid=284977
any idea how to fix this ? configuration error? Tag: VSS Project Security Tag: 69044
virus alert
hi all,
while surfing the net my avg alerted me saying a virus had been detected
but before i could read the whole message a friend closed the window, so i
did a scan and nothing was detected. is it possible that something is sill
there and just went undetected by my avg (my antivirus software) if so, is
there anything i can do myself to locate and identify any possible virus.
thank you. Tag: VSS Project Security Tag: 69034
Certificate Server Web Server Template Please help
I am trying to add a web Server Ceritificate Template to my Cisco ACS
server. I am running CA on a Windows 2k3 box. When I pick Web Server as my
template I should be able to pick Microsoft Base Cryptographic Provider V1.0
as my CSP. I don't get that choice. Please help Tag: VSS Project Security Tag: 69032
Event ID 538 not recorded for user logoffs.
Hello,
When looking at the Security log (W2K, SP4), I see the 528 event for
when a user logs on but I'm not seeing a matching 538 for the logoff.
I've double-checked the Local Security Policy | Local Policies | Audit
Policies | Audit Logon Events and both the effective setting and local
settings are set to Success and Failure.
In...
http://www.microsoft.com/technet/prodtechnol/windows2000serv/maintain/monitor/logonoff.mspx
...this is described as a bug but that isn't very helpful. Does anyone
know more as to why this is happening? Is there a fix? or is this
something I have to deal with?
Thanks! Tag: VSS Project Security Tag: 69031
cant get into email account
I recently got my hard drive cleaned up and debugged at a local computer
store. Ever since then, although everything else is working perfectly and
much faster than before, I can no longer get into my email account. My
daughter can get into hers. Mine is an Excite account, and although I can
access the general Excite site, I cannot access my email account. The message
reads that cookes and javascript have been disabled. I have no idea how to
fix it. I phoned the computer store and they said that they could not walk me
through it on the phone, that I would have to bring the hard drive back in
again. I live about an hour and a half's drive away from the store, and it
makes it difficult to do so right away. Is there any help or adivce that
anyone here can give me? I miss being able to send and read my mail. Thank
you. Tag: VSS Project Security Tag: 69027
Possible Email Attack Using Microsoft
Received email purporting to be from www.communication3.msn.com urging me to
click on link to initiate Windows Update Service. Link included what
appeared to be complex identifier.
I called Redmond, but couldn't get past frontdesk. Lady (nice lady)
explained I had to forward email or to fax a copy. I explained that I would
not (ever) open it in my computer because of potential security risk I
perceived.
Don't know if this is "real threat", but this is the only way I can think to
alert community. Tag: VSS Project Security Tag: 69018
Is there an MS Patch Matrix available?
Is there a resource somewhere that lays out all MS KB Patches by O/S ? I've
looked in the Security section for 2 hours to no avail and would just like to
know which patches are for NT4, 2000 Server, 2003, etc. without having to
weed through 100's of clicks to compile it all....
TIA,
-Bill Tag: VSS Project Security Tag: 69017
How do I find what computers a user is logged into?
How do I find what computers a user is logged into? I work in a domain
with over 80,000 users, with an equal number of computer objects, and
over 30 DC's and we get users that log themselves into a computer and
forget to logout of the computer. The next day they go to another
computer and logon and change the password for the account. Since they
did not logout of the first computer their user ID gets locked out.
So, my question is how do I find the computer they forgot to logout of?
Or, is there a tool like the old Banyan Vines "mlogout.exe" (wow,
I just dated myself with that one) for the MS world to forcefully log
the user out of any computer they are on?
Thanks,
Steve Tag: VSS Project Security Tag: 69011
***FIX*** serflog.c virus, msn:
Good afternoon folks...
I have got rid of my virus!!!!
Let me say this was NOT at all easy; the program that got rid of it was:
http://www.free-av.com/ - antivir
I completely understand the problems of the virus closing any program
opened; so what you need to do is somehow get that package to your desktop,
and run it by either clicking loads to overload your system, or by pressing
return on your system, try get through the menus without closing the
program - ignore 'close this program'? dialogues, it's the virus trying to
close it! Click no then click on another button
ie:
shove the 'close? yes/no' dialogue box over the 'next' box, so when you
press 'no' you can press 'next' in the install program...
or use return again and keep your finger on it.
Once it's installed, ensure you're connected through the net ( i guess you
need broadband ideally...) and it'll update, then run
it'll scan your computer manually (possibly with no windows displayed) and
find the virus and scarily flash on your screen as the virus keeps closing
it. This is because the virus closes most programs, and you'll have to be
quick with your eyesight...take it easy, it'll keep flashing, so read what
you can of them each time it flashes up.
Restart your pc, and it should delete it, then find other parts of the
virus...
Tip: as it kept flashing up initially i managed to tick 'display info box'
which came up with options, i changed the selection from 'always' to 'after
restart', and the below option to 'delete virus' as opposed to
close/clean/quarantine.
It worked, and now i'm running without the serflog.c virus
I do warn you, this is hard, but no other solution has worked successfully.
I will be using this virus scanner from now on too!
If you've any questions, please post here.
To the 'regulars' if you could please put this in better words then maybe
that would help people better. Unfortunately it's all about timing and
overloading your CPU to install the program, but i can reassure you it does
work!
Until symantec produces a removal tool (if at all) this is the onl y method
i have found that works.
G. Tag: VSS Project Security Tag: 69009
winntsystem32autoexec.nt --error
hi all
i am getting problem when i try to install WinCVS application in my system..
the error message is
the system file is not able to run windows and ms-dos application. Can
anyone help me ..
thanks
ShankerBejjanki Tag: VSS Project Security Tag: 69003
Help With Unwanted Desktop Backround
A spy ware removal ad appeared as my desk top two days ago.I cannot remove
this no matter how many spyware programs I run.I tried a system restore
several times also.Nothing has worked.Has anyone encountered this
problem?Also a yellow triangle is in the toolbar causing a small popup every
few minutes reminding me that my computer has spyware on it.Hope someone can
help.Thanks...Joe Tag: VSS Project Security Tag: 69001
Is a rouge cancel bot on the lose in the usenet?
Is a rouge cancel bot on the lose in the usenet?
I have notice a a lot of cancelled messages in the computer and other
general usenet groups. I am not talking about the bad groups.
It even deleting messages on severs that don't support anytime of
cancel message.
Greg R
Post also in the grc news group as well. Tag: VSS Project Security Tag: 68998
Will AD password policy change affect current users?
If we modify the complexity of the Active directory user password policy
will existing users with passwords that don't meet the new requirements be
forced to change their password the next time they login or does this only
affect new accounts and password changes?
Thanks,
Jim Tag: VSS Project Security Tag: 68995
Windows Messenger Problem
I am using Windows Messenger 4.7.3001 and recently typed my password into to
"email address" box on sign in by accient, now when anyone who uses this
computer wants to use it and they click the arrow to show all previous login
names - my password appears. I was wandering if I can clear this list
somehow? Thanks, Tag: VSS Project Security Tag: 68991
Making Active X Safe or Signed
I used QuickTime to make a small movie on my Web site. It came up on one
computer using Win 2000 as unsafe. The Active X settings seem to be the same
as on a second computer with OS Win 2000. I would think that QuickTime or
any other common player or plugin would be safe and signed. How does one
make such a slide presentation safe and signed??? AND
Why are the settings for Active X in Internet Explorer 6 on Win 2000
different on one computer using the same OS than on another using Win 2000
OS??? When I go to Windows Updates the troubled computer does not need
updates. How can I update Internet Explorer 6 to fix whatever is the
problem? Is there a way?
Thank you. Tag: VSS Project Security Tag: 68990
FileSpy
Hi All,
I have come across a piece of software called FileSpy which is running on my
PC.
I have done a bit of digging and this is a piece of software which is used
to log and view when a file was accessed (and much more info but that is the
general idea).
What I can't find out is if it is a problem? I can't tell from the
information I have read whether it is / isn't.
Does anybody have any knowledge of this item? Is this file something which
I have been tricked into installing but provides access to external users or
is it something which is used by other applications Tag: VSS Project Security Tag: 68988
Hotmail Sign Out Problem
When I try to sign out of Hotmail, I can see that IE is trying to pull up the
standard MSN logout page, but very quickly, IE stops processing the page,
indicates that it is done, but I end up with a blank page. I have all
updates from Microsoft except XP SP2, which I uninstall after experiencing
problems with browsing. I have a fast ADSL connection, so I know it's not
the speed. I'm also current on running anti-virus and anti-spyware searches.
It doesn't appear that my pop-up blocker is the issue either. I'm concerned
that I'm not completely logging out of Hotmail and I'm not comfortable just
closing out the browser since I fear there might be a bigger issue. Any
idea? Tag: VSS Project Security Tag: 68983
Error in Internet Explorer
The following message comes up when opening Internet Explorer.
This page provides potentially unsafe information to an Active X control.
Your current security settings prohibit running controls in this manner. As
a result, this page may not
Display correctly.
I have run the virus protection, Ad-Aware, Spybot. Nothing seems to help.
Any suggestions???
Thank you Tag: VSS Project Security Tag: 68978
Security myths
Security myths.
http://www.microsoft.com/technet/community/columns/secmgmt/sm0305_2.mspx
I disagree with number one. That like telling people to throw out
Steve(grc.com) and others advice.
Look at myth number four. I strongly disagree with it. I think
tweaks are needed. Even Microsoft recommended some tweaks
Greg R Tag: VSS Project Security Tag: 68976
Msn Profiles
Out of curiousity. Are there any security issues which prevent other msn
users from uploading copywritten or personal pictures, or claiming they are
you? And if so is it legal to send threatining emails under this false
identity. If it is not could you direct me towards the area where I can
report such Activity. Tag: VSS Project Security Tag: 68969
what firewalls to use?
i am trying to read and research the best way to setup the firewalls you need
for your computer. Do certain firewalls conflict with each other where its
better to run one than the other. In my house we use a d-Link router, now
can than be considered a hardware firewall. On my computer I run Windows Xp
home edition with the service pack 2. that has the security center and
firewall does this replace the internet connection firewall. Is the serivce
pack sufficent enough and give you the best protection. I also have on my
computer Norton System works 2005 premier si there anything on there that
will conflict with the firewalls where I should disable one thing and enable
another. I would like it so the protection from things getting into my
computer is ias ggod as things on my computer being able to leak out for
people to see them. i am just trying to learn the best possible way to
protect everything if that is possible. I hope you can help me with some
knwledge
thanks
jake Tag: VSS Project Security Tag: 68965
Is there any way to get a report from vss showing access by project and
download it into an external file.