Sending User Credentials During Authentication Process
Hi guys,
Is there any TechNet article explaining the situations that implement
encryption on BOTH the username AND password credentials that a user sends
during a typical authentication to a Windows NT/ 2000/ 2003 domain without
the use of any additional encryption mechanism like IPSec?
or can anyone kindly answer the following
How are user credentials sent over the wire (are they both encrypted?)
during a typical domain logon process using at least a WinNT client computer
on an NT4 domain, Win2K mixed mode domain, and Win2K3 native domain for
clean install (default) configurations? Is there a suporting Technet
article expalining this?
Thank you very much. Tag: This ~ file Tag: 34676
Email Virus - Rules for bcc?
I've been bombarded with virus attacks using attachments
from supposedly microsoft emails for upgrades/patches.
99% of all these emails are sent to me via bcc: and not
the to: or cc:. I can't figure out how to setup an
Outlook rule that blocks all emails to me via bcc. There
are templates for to: and cc:, non for bcc:. Need MS free
engineering know how. Tag: This ~ file Tag: 34636
Security for MS Word
Does anyone know of a way to secure MS Word docs from
being copied or attached to an email? Thanks for any
feedback. Tag: This ~ file Tag: 34630
ENDADS popups
I am being plagued by this companies popups (several an
hour) which ask me to go to their web site to purchase a
product to stop their pop ups !!
The web site (endads.com) blames a problem with microsoft
OS.
Is this illegal and how can i stop the pop ups without
paying them money ?? Tag: This ~ file Tag: 34628
Best Firewall?
Hello,
I recently upgraded to zonealarm pro, and I believe it is
causing me to have connection problems...
Anyhow, this never seemed to happed with just plain
zonealarm. What is the best free firewall out there?
Thanks,
Dan Tag: This ~ file Tag: 34622
Current Network Crirtical Update
I have received a message from Microsoft urging the
download of the above official-looking message, but McAvee
intercepted it as seen below. I asked Microsoft what to
do and received a Delivery Failure Report from the
PostMaster. What do I do now? Any help with this
problem, or on how to get through to Microsoft will be
much appreciated. Thanks
"This message was sent to me by McAvee.
Please advise what I should do now? I opened the
attachment and saw only a blank black screen. I therefore
ended the download immediately.
Ray Spencer
****************** McAfee VirusScan
************************
******* Alert generated at: Mon, 22 Sep 2003 00:22:14
+0000 *********
***********************************************************
**********
McAfee VirusScan has detected a potential threat in this e-
mail
sent by "Microsoft Corporation Public Assistance"
<oxpbvkrcg-hckt@updates.ms.com>.
The following actions were attempted on each suspicious
part.
We strongly recommend that you report this virus-related
activity
to "Microsoft Corporation Public Assistance" <oxpbvkrcg-
hckt@updates.ms.com>.
The attachment "Unnamed attachment" is infected with the
W32/Swen@MM Virus(es).
This attachment has been cleaned. Tag: This ~ file Tag: 34621
Google bug!
First of all, I have limited knowledge with how computers
work. I don't know where else to turn to for help. Any
recomendations will be appreciated.
I have been receiving a message when I try to go to
google.com. The page says that my computer is running
software that does not let me get in to google. However,
I have learned that I can't get into any search engine
type of program. I have tried the grey search box on
yahoo and I get the message "page can not be opened." If
I click on the magnifing glass, search button on my tool
bar, I get the same message, "page can not be opened."
I don't know what I have done. I have McAffee home virus
7.0 with fire wall. I have tried that with updates and
still nothing.
Something else, on the same google page, it give
directions on how to remove google from the host file. I
don't know if I should attempt these instructions,
because I really don't know who is behind it.
Any thoughts will be appreciated! Tag: This ~ file Tag: 34615
client hang after installation of MS03-039
Hi, guys.
I used a startup script to install MS03-039 through GPO in a domain. Some
clients can be installed the patch properly.
However, some clients could not complete the process.
The situation was that :
reboot the PC ----> run startup script through GPO ---> try to restart
automatically but hang in a blank desktop (ctrl+alt+del no function at this
moment)
Could anyone help !! Thx ~~~~ Tag: This ~ file Tag: 34591
MSSVC.exe
I keep getting an error message on start up telling me
that MSSVC.exe couldn't start and needs to shut down.
What is this and how do I get rid of it? Thanks. Tag: This ~ file Tag: 34587
MS Baseline Security Analizer
I've scanned my system with the MBSA and it reports that it can not confirm
that the following updates are correctly installed:
MS02-055
MS02-008
MS03-008
MS03-030
yet when I go to the Microsoft Update site, it indicates there are no
critical updates required.
Is there some other way to verify if all critical updates have been
installed, and installed correctly. Or is this a flaw in the MBSA.
TIA
Bill Rothe
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.521 / Virus Database: 319 - Release Date: 9/23/2003 Tag: This ~ file Tag: 34585
Microsoft e-mail security
I have been getting thei e-mail from Microsoft very
authentic looking. Is this really from Microsoft? It says
last critical update--------- and so on. If this is from
Microsoft why don't it come through Microsoft up date. I
have Windows XP Pro. One more thing it comes with an
attachment I'm afraid to open it. What should I do?
Sincerely
Ron Tag: This ~ file Tag: 34577
DO not use reall address here
The MS newsgroups are being harvested by hackers for
emails and then those addresses are being bombarded with
hundreds of Swen Virus attackes daily. I made the mistake
of using my real email address here and now my email bin
is filled daily with hundreds of virus attacks. Because
the virus morphs subject and from, it is almost impossible
to filter out. MS Security people - please do something
to stop addresses on your site from being harvested or
post a warning of the risks of using a real email
address. Tag: This ~ file Tag: 34563
How do I get the Internet header for a message
The official instructions to get the Internet Header say:
"In an open message received via the Internet, on the View
menu click Options. The Internet headers are displayed in
Internet Headers, at the bottom of the Message Options
dialog box." But when I go the View menu, Options is not
one of the options (no pun intended). What is going on? Tag: This ~ file Tag: 34561
Newly Discovered device
In the tray, bottom right of screen with time and date, is
a new logo I have not installed. It looks like a computer
screen logo. Placing the pointer over the logo announces
it as a newly discovered device labeled as UPnP Device.
Right clicking over the device gives the choices of
creating a shortcut or invoking but the delete and
properties choices are grayed out and do not operate. The
device logo can also be found on My Network Places but
again properties and delete cannot be used. I will not
invoke the logo but I cannot get rid of it. Any
suggestions? Thanks Tag: This ~ file Tag: 34560
popups
Today, I began receiving a popup about "MAP132 exception"
saying there is an internal error. A form is provided for
my completion. Is this something legitimate? Also,
I keep receiving "popups" about how to stop popups. The
popups seem to come from different sources, must I
purchase something to halt the popups?
Thanks.
p.s. this is a new computer and an upgrade from Windows
98 to XP so I have a lot to learn. Tag: This ~ file Tag: 34554
Microsoft is NOT sending ANY emails to you. Read this!!!!
"Authentic security bulletin mailers never provide the
patch itself or a link to the patch; instead, they refer the
reader to the complete version of the bulletin on our
web site, which provides a link to the patch"
http://www.microsoft.com/technet/security/policy/swdist.asp
http://www.microsoft.com/technet/security/news/patch_hoax.asp
PLEASE Don't click on any email attachment you don't
know about. Because it will most likely be a VIRUS!!!!!!!
Even if you're all protected don't click on any unknown
email attachments.
Consider using these (free for home use) tools:
http://www.grisoft.com/us/us_dwnl_free.php
http://www.kerio.com/us/kpf_download.html
DON'T open any attachments
Consider using these settings in Outlook Express:
Tools | Options | Security | Virus Protection
Choose "Restricted Zone"
Enable "Warn me when other applications trying to send mail as me"
Enable "Do not allow attachments to be saved..."
If you get infected, follow EXACT instructions from:
http://www.symantec.com/avcenter/venc/data/w32.swen.a@mm.removal.tool.html
http://www.f-secure.com/v-descs/swen.shtml#disinf
http://vil.nai.com/vil/stinger/
On Windows XP enable firewall:
http://www.microsoft.com/windowsxp/pro/using/howto/networking/icf.asp
Keep up to date with:
http://windowsupdate.microsoft.com/ Tag: This ~ file Tag: 34552
gaining access to drive root
Hello,
I'm writing an suditting script that will visit each
machine in our domain and search for unauthorized
software/files as well as correct any file permissions a
local admin on the machine might have messed up.
I've ran into a problem. If someone removes permissions
for administrators to access the root of a drive I can't
seem to grant access to the root of the drive. I've tried
calcs and subinacl but one doesn't seem to understand UNC
paths and the latter doesn't seem to touch the root of the
drive, just everything below.
If you could provide an example of granting such acces
it'd be really helpful.
Thanks. Tag: This ~ file Tag: 34550
is this for real?
I just got the following as an email which is really
weird - it didn't come up under auto update. It came with
an attachment also which I ain't touching till I hear
something back. Of course trying to contact Microsoft and
asking is like trying to acheive position 93 in the Kama
Sutra but does anyone know if this is for real?
Thanks
Neil (and I Quote:)
Microsoft Consumer
this is the latest version of security update,
the "September 2003, Cumulative Patch" update which
resolves all known security vulnerabilities affecting MS
Internet Explorer, MS Outlook and MS Outlook Express as
well as three newly discovered vulnerabilities. Install
now to maintain the security of your computer from these
vulnerabilities, the most serious of which could allow an
attacker to run executable on your computer. This update
includes the functionality of all previously released
patches.
System requirements Windows 95/98/Me/2000/NT/XP
This update applies to MS Internet Explorer, version
4.01 and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later
Recommendation Customers should install the patch at the
earliest opportunity.
How to install Run attached file. Choose Yes on displayed
dialog box.
How to use You don't need to do anything after installing
this item. Tag: This ~ file Tag: 34544
Is email from Microsoft authentic?
I have heard that some fraudulent emails can have very
official looking logos and appearance. I have received a
message and want to know how to authenticate it or how to
forward it on to Microsoft for verification. The message
requests that I download a patch, but doesn't allow me to
save it to disk. It will only let me open it immediately. I
would like to forward it to Micrsoft and have them look at
it. Thank you. Tag: This ~ file Tag: 34543
patch install
Anyone have luck with these security patch installs?
I am having trouble running the install. And am not
getting the dialong box to pop up to check yes to. What
do I do? Any suggestions? Send to
sleepingwillow@awsomenet.net
Thanks Tag: This ~ file Tag: 34532
new security pack
Can someone help me please. I just installed
the "September 2003, Cumulative Patch and since then I am
getting numerous memory access violation Kernal32
messages. I am also not able to receive e-mails. Is there
a way to remove this patch without a full scale restore of
windows from backup? Or maybe someone has a suggestion.
Thanks Tag: This ~ file Tag: 34524
patch history
Hi,
is there a way to track down which patch was installed on which date on a
Windows 2000 system? (and also after installing a service pack)
tia,
jaz Tag: This ~ file Tag: 34522
sandbox software for running untrusted software
Given all the trouble with running untrusted or unknown software on your
machines, it might be worth checking out Safe Launch from
www.safelaunch.com. Safe Launch allows you to run untrusted programs in a
virtual sandbox. This sandbox will popup a window to let you know if the
program is trying to modify files, modify the registry, or even trying to
connect out over the internet. You can decide whether to allow or deny the
activity to occur.
Best advice is always to not run executable attachments that arrive by email
from unknown sources, but often you receive or download software from the
internet that you really want to run. This tool allows you to do it safely
without compromising your machine.
BTW, I'm sorry if this comes across sounding like an advertisement, it not
meant to be. This tool could be of value to striving to keep their system
secure. Makes it easy to spot trojans trying to install themselves... Tag: This ~ file Tag: 34506
blocking trojan horses and find out more about attacker?
I've recently started using Norton firewall and am
surprised to see how many "pings" my computer gets in my
activity log. Most of the pings are "unused port blocking
has blocked communications". But several times a day,
more so just recently, my computer is being attacked
by "Backdoor Subseven Trojan Horse". The firewall blocks
the communication, but it's been happening 15-20 times
per day (it used to only be a couple times each day).
I've also been running Norton anti-virus with a Live
update. It hasn't detected anything on my computer. Is
there a chance that this Trojan horse is coming from
within my machine and Norton hasn't picked up on it? Or
are all these coming from other computers hitting my IP?
I've noticed that many of the IP's attacking mine are the
same. I've checked them with arin (whois?) but what does
that info tell me? Can I report them anywhere? How? I'm
grateful that the attacks are being blocked, but I'm
tired of constantly closing the high-alert window every
time it happens. Any advice on what to do now that I know
their IP? Thanks!
Pam Tag: This ~ file Tag: 34502
need new firewall & anti-virus
I've been having problems with Norton firewall & AV, as
many websites do not display properly. This especially
happens on pop-up boxes that come up blank, blank images,
etc. Symantec's answers haven't fixed this (I've disabled
ad blocking, NIS, NAV, to no avail.) I customize settings
for a specific website, which has worked only once so
far. So I'm ready to try something new for my Windows 98
and DSL:
(1) if you have McAfee, do you have similar experiences
with web pages?
(2) do "free" firewalls & AVs also have similar
problems? Also, when new virus, trojans are found, do
these free sites respond quickly with updates..as Norton
and McAfee do?
KathyD Tag: This ~ file Tag: 34499
Unable to get contact with Microsoft by phone or e mail.
For the past two weeks i have received requests from
Microsoft to update with current patches they are sending
me..I wasn't sure they were legit. I couldnt get in
contact with them so out of frustration i downloaded the
suggested patches..Im still functioning.I wanted to
confirm these patches were from microsoft but was unable
to do so..My secondary problem is that during the last
two weeks i keep receiving noticis that E mail delivery
was unable to be completed. I didnt send any E mail to
the addresses identified in the notice..I'm a novice at
this stuff and am about to qiit Microsoft for another
entity, If that is possible. Tag: This ~ file Tag: 34496
Security Settings
I manage a public PC, and wish to prevent people from
changing settings, and accessing any files except
Internet surfing. I am a new user to Windows XP, and do
not know how to set a password that would prevent any
changing of desktop items or downloading of programs. Can
anyone tell me how to do that? Please email me at
dapatl@hotmail.com, thank you. Tag: This ~ file Tag: 34495
patch downloads
Where can i find security updates and patches to download,
i have only dialup at home
but can burn at work. Tag: This ~ file Tag: 34490
Stopping virus emails at server
Does anyone know if it is possible to stop all the recent
emails containing the swen virus at the server. I have
been receiving about 100 emails a day. Unfortunately I
stupidly infected myself when I opened the attachment the
first time I got the email on the 18th but I managed to
disinfect my computer and downloaded the updated virus
definitions from Norton. So although I have bocked the
senders on my email program and Norton is intercepting
and disinfecting, I am still getting huge amounts of the
emails in my deleted folder and constantly getting the
Norton popups saying that it has cleared an infected
email. It is driving me to distraction. Will it ever
stop? Can I get it stopped at the server so that it
doesn't even get to my computer or do I have to change my
e-mail address which would be a real pain, not only to
notify everyone but also because I have quite a few
subcriptions to various things. Can anyone help??
Many thanks
Margarita Tag: This ~ file Tag: 34476
Keith
Before Keith gets into a rage about me not reading the
previous post, my question relates to being able to ask
Microsoft a question easily, I thought the navigation of
the market leaders website would be simple. Tag: This ~ file Tag: 34453
Two security questions about Window XP Pro and IE6
Is there anyway other than through a 3rd party firewall to
put a computer into a stealth mode? ZoneAlarm has an
option to hide the "private header". I'm using IE6 with
latest updates.
Does WindowsXP Pro with latest updates have any ability to
help a computer resist the urge to answer a ping?
Thanks in advance for your time and help. Tag: This ~ file Tag: 34450
Testing security
I apologize for asking this question. In a post from
several days ago about setting up better security there
was a site listed that actually tested several different
security issues. I thought I added it to my Favorites but
I can't find it. I also can't find the older post.
Can anyone point me to a free, legitimate testing site?
Thanks and I will record this information this time. Tag: This ~ file Tag: 34446
I-Worm.Swen
http://www.viruslist.com/eng/viruslist.html?id=88029
"The worm scans all disks for files with extensions DBX, MDX, EML, WAB and
also that contain either HT or ASP in the extension. Swem then extracts any
email addresses that it can find and saves them"
That is how it gets the email addresses on infected machines. So if user had
newsgroups or emails downloaded locally like most do when you read messages.
This virus scans the local folders (.dbx files in Outlook Express) on
infected machine, and that is how it gets email addresses for its spam. Tag: This ~ file Tag: 34442
Is there a Way
Is there a way to stop the bulk e-mail of the Update Hoax from MS Security.
I do not have the virus, but I am getting all the bulk e-mail. I have the
latest Office and Windows patches and updates on this computer. Is there
someway to stop it from even passing through the e-mail server or just have
this blocked at the server.
Thank you for your help whom ever does reply.
P.S. The person or persons that wrote this virus must be smiling now Tag: This ~ file Tag: 34441
Virus Information
I was wondering if their was a patch or anything out there
to protect my computer from the email virus that is going
around. I have recieved the email numerous times and I'd
just like to be extra sure that if someone accidentally
opens the virus that the computer would be protected.
Thank you. Tag: This ~ file Tag: 34438
How to lock out teen-age kids from downloading Instant Messaging from IE
Is there a way to lock someone from going into the
internet via Internet Explorer?
My husband and I need internet access for work therefore,
we access the internet via Internet Explorer. We don't
have AOL and MSN. However, Instant Messaging download can
be obtained as soon as kids go to the internet via
Internet Explorer. We want these teenagers locked out of
the internet altogether.
Please help!!! Tag: This ~ file Tag: 34436
*** READ BEFORE POSTING - Stop asking about the "Microsoft" E-Mails!!! ***
PLEASE, please, please read previous posts/threads prior to asking your
question! Within this group, there is probably a 90% chance that your
question has already been answered.
THEN, if you can't find what you're looking for by scrolling down, check the
FAQ's for this group:
<http://www.microsoft.com/technet/newsgroups/default.asp?url=/technet/newsgr
oups/nodepages/sectop10.asp>
<http://securityadmin.info>
THEN, if you can't find an answer in the FAQ's, try Google groups at
http://www.google.com/grphp?.
FINALLY, if you can't find the answer anywhere else, post the question here.
Thank you,
Everyone
PS - Please feel free to copy this message in response to duplicative posts,
and reference it as needed. If folks stop getting answers to answered
questions, they'll start to get it. Tag: This ~ file Tag: 34418
email coming from supposed "Microsoft" with worms/viruses
Why all of a sudden am I receiving email warnings that
show messages have been deleted because they were unable
to be cleaned. They are (ie.): patch.exe:Worm.
Automat.AHB, Patch 685.exe:worm.Auto.AHB, cujm.exe, and
various others. Most of these are supposedly coming from
Microsoft. Anyone else having this problem? What do we
do about this? Tag: This ~ file Tag: 34413
spyware
I have had many pop-ups lately, one from Enigma Software
Group telling me that my system has a spy intruder and
offering their free spyware scanner. Is this something
that I should be concerned about and what will this free
software do? I keep updated with antivirus software. Tag: This ~ file Tag: 34405
Firewall vs auto updates
I installed MS XP's firewall Monday and Tuesday received
the message below.
This is a message from the MailScanner E-Mail Virus
Protection Service
----------------------------------------------------------
------------
The original e-mail attachment "upgrade411.exe"
was believed to be infected by a virus and has been
replaced by this warning
message.
If you wish to receive a copy of the *infected*
attachment, please
e-mail helpdesk and include the whole of this message
in your request. Alternatively, you can call them, with
the contents of this message to hand when you call.
At Mon Sep 22 19:34:10 2003 the virus scanner said:
upgrade411.exe infection: W32/Swen.A@mm
Note to Help Desk: Look on the MailScanner
in /var/spool/MailScanner/quarantine/20030922 (message
h8MNY6Q31180).
--
Postmaster
Is this really from Microsoft? If it is, does this mean
that MS firewall is going to filter out auto upgrades and
patches? The Virus Protection Service suggests contacting
helpdesk, but gives no address for such service. It also
suggests that one can call to get the upgrade, but gives
no phone number.
I am a bit confused about how to proceed.
Jim Tuten Tag: This ~ file Tag: 34397
EFS and FAT
I want to use an EFS under Windows XP and want to prevent
a copy of an encrypted file to a FAT file system like for
example the good old floppy or other FAT drives. Is there
a possibility to generally disable copying encrypted
files to FAT drives?
Rainer Tag: This ~ file Tag: 34396
Certyficates
I want to windows login to active directory by the
certyficate.
It's use for smart cards.
I'm designing smart card reader that must
authorize in two ways.
first - reader (serial number etc)
second - smart card (user , etc)
My problem is that I want the windows login
only when I send two certificates reader and card.
When reader and card get autorization user can logon to domain ?
Is that posible ? Tag: This ~ file Tag: 34394
IAM LOCKED OUT OF MY COMPUTER
SOMEONE CHANGE MY PASSWORD ON MY COMPUTER AT THE BISO
SCEAN SO NOW I CAT GET ON MY COMPUTER AT ALL IAM LOCKED
OUT AT THE BOOTUP SCEAN WARE IT DOSE THE MEMRER TEST
PLEASE TELL ME HOW TO GET A ROUND IT SO I CAN PUT A NEW
PASSWORD IN Tag: This ~ file Tag: 34390
WAYS TO DISGUISE SOME OF YOUR ACTIVITIES FROM HACKERS
A. Subscribe to a number of Usenet Newsgroups and download the posts
periodically, say every 2-3 weeks. So that if any hacker does
compromise your system, they will envision you?re posting in all the
news groups listed. Perform the same with Yahoo Egroups. Which
Newsgroups you download first is a choice that you can make. For
example: I?ve created the order of my Newsgroups by picking a random
oddball group I would never subscribe to, add a Newsgroup I visit on a
regular basis, then back to the oddball. By downloading the Newsgroups
you visit first or second on a regular basis, this shows a profile of
your history.
B. Bookmark some Websites just for the heck of it, this can confuse a
hacker and make them believe you visit all the sites you have
bookmarked. Come up with a few interesting kinky, or medical sites for
the heck of it. To keep the hacker guessing, you must periodically
visit these Sites. Every visit to a site leaves a marker on your
computer that records the date and time that you visited.
C. Make up fake e-mail friends and input any e-mail address in your
address book. This will definitely scramble the hackers minds. Hackers
might wonder if your computer system is a "honeypot." A "honeypot" is a
computer setup to record and watch the actions of hackers. Should a
hacker send an e-mail to the fake address and have it bounces back to
them, it will confuse them.
D. Make up fake correspondence using Word or Works and address a letter
with the impression that you were writing the "FBI" about the hacking
activities that you have found.
E. When my computer system was found to be compromised and I realized
the hackers could bring down my system at any time, I was inspired to do
the following: I opened up notepad on my desktop and typed; "hacker
activity is being tracked by the FBI", and left this window open on my
desktop.
F. Join a few List Servers and Mailing Lists to divert attention so
that the hackers don?t know your real intentions on the Internet. Some
people might object to this method because this will add unwelcome
e-mails in your in basket.
Tracker
The Best Kept Secrets of Backdoors, Cracking, Firewalls, Hacking,
Proxies, The Internet, Trojan Horses, Virtual Private Networks, Virus,
Windows and different types of Servers can be found at:
http://geocities.com/secure20032220000/ Tag: This ~ file Tag: 34376
preview pane?
If you are using the preview pane in OE to read mail or posts in NG, are you
succeptable to a virus/worm executing on your machine? Does the nai system
screen the pane before opening? What about using IE with mail or posts?
thank-you
--
James David Jordan Tag: This ~ file Tag: 34375
I've found this ~ file in my records before and deleted
it. Does anyone know what the purpose of it is and how I
can avoid it if I delete it again?
On Wed, 24 Sep 2003 19:24:09 -0700, "Pat" <sexypot@swbell.net> wrote:
>I've found this ~ file in my records before and deleted
>it. Does anyone know what the purpose of it is and how I
>can avoid it if I delete it again?
It's just a backup copy of your Outlook Express address book.
Microsoft is aware of the boo-boo... in the meantime.. ignore it,
delete it, take it out to dinner.. :)