Wield the Shield: How Trustworthy Is Your OS?
"Trusted operating systems have been used for some time to lock down the
most sensitive of information in the most sensitive of organizations. But
with security concerns rising and changing by the hour, it's now a matter
of trust for any organization looking to tighten its computing ship."
http://www.eweek.com/article2/0,1895,1961947,00.asp
Im Tag: signcode via proxy Tag: 84490
Use of CCleaner -
I was recommended the use of CCleaner as a fine way to clean my computer.
This is clearly a thorough tool - in fact so throrough that my bank account
portal has erased all links to my other banks accounts. (I have a prgram
supplied by my Credit card co which allows me to link to all my other bank
accounts (i.e. retails the passwords etc.)). Which option on CCleaner do I
disapply to allow my computer to retain these deatils on my PC?
I don't really want to insert multiple details every time I wish to view my
finances.
Can anyone assist please? Tag: signcode via proxy Tag: 84481
Take Ownership of Multiple files at once
Hello-
We just installed a new server and on the old server we had a directory of
photos that only two users had access to, myself (admin) and our lab tech.
These permissions were assigned via NTFS. Now that I have put the drive in
the new server it is not allowing me to do anything with the files as no one
on this local computer has any security permissions for it. I can manually
take ownership of folders and files with the admin rights I have on the
server but there are over 450 photos in there and it would seem rediculous to
have to do them individually. I have gone into the security/advanced tab of
the parent folder and trield clicking the check box to "Replace permissions
entries on all child objercts with entries shown here that apply to child
objects" but it wont let me because there are no rights to the photos so it
says access is denied.
Is there any way I can take ownership of all of those files all at once in
order to reassign proper permissions? I tried the obvious of selecting them
all and going to the security tab but that is not available for muliple
selected objects it states.
Thanks in advance for any assistance! Tag: signcode via proxy Tag: 84472
IPSec client for Windows Mobile 2003
Hi all,
seems a silly question, but I can't find the answer inside microsoft.com
site : does a IPSec client exists for Windows Mobile 2003 ??
Any URL pointing to information on it will be welcome !!
Thanks in advance Tag: signcode via proxy Tag: 84470
Windows Defender
When running the install after the defender download I get the following
message -
path c:\\windows\downloaded
installations\(0F5BF410-4D79-4DBE-AF54-C3271D47D4BD)\microsoft
antispyware.msi cannot be found. Verify you have access to the location and
try again or try to find the installation package microsoft antispyware.mist
in a folder from which you can install the product.
I posted the download on my desk top and ran the installation. Got the
above message. Downloaded the program into temporary folder and got the same
message.
Help. Tag: signcode via proxy Tag: 84467
searching in cells
I was trying to search for a number (200310005 - formated as text) in a
cell in an Excel spreadsheet. I do this from "My Computer" (searching
content) but the search fails to produce the correct document even when
the search string is in the excel sheet.
I've checked the formating of the cell (text).
I've exported the excel sheet to text and imported it to a new file -
doing the search again. It fails again. Formated as text or not.
Any suggestions on what's going on here?
(Excel 2000)
Martin S Tag: signcode via proxy Tag: 84457
MS CryptoAPI: HMAC using PLAINTEXTKEYBLOB
Hi, all!
I want to create a program using CryptoAPI which calculates HMAC-SHA1
using a key specified by PLAINTEXTKEYBLOB.
I have a 20-byte key for HMAC-SHA1 and want to use it.
How should I do?
Should I import the key by CryptImportKey()?
But I have to specify an encryption key algorithm and I donno which
algorithm I should use.
Your kind help is welcomed. Tag: signcode via proxy Tag: 84456
Windows firewall
Can anyone tell me why when i connect to the net my windows firewall switches
off? i switch it on but afer a while it will switch itself off again? i have
done a anti-virus scan and windows defender scan not bugs found, help please Tag: signcode via proxy Tag: 84440
Exchange/Cisco VPN client failing
I have a WinXP Pro w/Outlook 2003 laptop trying to connect through a Cisco
VPN 4.0.5 to the Exchange server. This connection is initiated via a D-link
wireless access point. I seem to be having trouble resolving DNS, getting
through the firewall, or authenticating to the Exchange server. Outlook
gets stuck in "trying to connect". It only seems to be problematic from
this one location, so perhaps it's a firewall port I'm missing...although
I've followed all D-link instructions for enabling this Cisco client at
http://support.dlink.com/SupportFAQ/default.asp?model=DI%2D624
Closest I've come to solving this is using the following KB article tells me
that MS04-11 update may create this problem, but I can't uninstall it as it
appears to have come with SP2 or another roll-up. I've tried the uninstall
switch, before and after trying to reinstall it alone:
http://support.microsoft.com/kb/891559
Here are my log entries:
Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40960
Date: 5/13/2006
Time: 8:10:50 PM
User: N/A
Computer: FNL-001
Description:
The Security System detected an attempted downgrade attack for server
exchangeAB/HQ-MAIL-VS2.company.net. The failure code from authentication
protocol Kerberos was "No authority could be contacted for authentication.
(0x80090311)".
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: DnsApi
Event Category: None
Event ID: 11197
Date: 5/13/2006
Time: 8:10:50 PM
User: N/A
Computer: FNL-001
Description:
The system failed to update and remove host (A) resource records (RRs) for
network adapter
with settings:
Adapter Name : {C8886BF1-FC23-4B35-93B8-C435EADD2B02}
Host Name : fnl-001
Primary Domain Suffix : company.net
DNS server list :
10.0.0.15, 10.0.0.13
Sent update to server : 10.1.1.1
IP Address(es) :
10.0.30.120
The reason the update request failed was because of a system problem. For
specific error code, see the record data displayed below.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 1e 25 00 00 .%..
Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date: 5/13/2006
Time: 8:10:50 PM
User: N/A
Computer: FNL-001
Description:
The Security System could not establish a secured connection with the server
exchangeAB/hq-MAIL-VS2.company.net. No authentication protocol was
available.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40960
Date: 5/13/2006
Time: 8:10:54 PM
User: N/A
Computer: FNL-001
Description:
The Security System detected an attempted downgrade attack for server
exchangeMDB/hq-MAIL-VS2.company.net. The failure code from authentication
protocol Kerberos was "There are currently no logon servers available to
service the logon request.
(0xc000005e)".
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date: 5/13/2006
Time: 8:10:54 PM
User: N/A
Computer: FNL-001
Description:
The Security System could not establish a secured connection with the server
exchangeMDB/hq-MAIL-VS2.company.net. No authentication protocol was
available.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp. Tag: signcode via proxy Tag: 84430
Internet filter
I want to implement some sort of a filter based on the domain name.
I am looking for some sample code that allows me to access the request of
the user so I can initially record the domain name accessed, the actual
blocking is not important at this point
Thank you
Sam Tag: signcode via proxy Tag: 84423
WINDOWS DEFENDER
in the last 2 months i've been hit by the spyfalcon virus twice, after
running norton antivrus software - which did nothing to eradicate the virus,
i turned to microsofts security advise section, downloaded the "windows
defender" and ran the scan. it didnt even detect any virus/ spyware on my pc.
i then tried microsofts free online pc scanning tool for viruses and spyware,
and still it didnt detect spy falcon. i have to say that microsofts security
products are just not up to the task!?
all in all i find both microsoft and norton useless in keeping up to date
with the latest fixes to well known issues that have been around for quite
some time.
anyone else suffered from the spy falcon virus ?
--
aberdeenpirate Tag: signcode via proxy Tag: 84392
How many characters to make Winzip AES 256 unbreakable?
Winzip offers 256 bit AES. So do other apps.
If I use a password made up of ordinary characters (A-Z, a-z, 0-9) with
no specials then how many characters do I need to use to make AES 256
uncrackable by a brute force attack?
The info out there talks mainly of key length but I am not familiar with
this field and I can sense they are not talking about the length of the
password I am using.
There is a little bit here but it seems out of date:
<http://www.dekart.com/howto/howto_disk_encryption/howto_recover_lost_pa
ssword/> Tag: signcode via proxy Tag: 84369
Msn gaming
I have a folder on my computer "C:\Program Files\msn gaming zone" why is it
that everytime i del the games in there they come back 2 sec later my recycle
bin had 10 copys of each game I deleted why can't i delete these games???? Tag: signcode via proxy Tag: 84356
Are We Addressing Cyber Crime Backwards
Maybe that is why it continues to grow despite all the hard work to
stop it:
http://fraudwar.blogspot.com/2006/05/are-we-addressing-cyber-crime-from.html Tag: signcode via proxy Tag: 84348
Are We Addressing Cyber Crime Backwards
Maybe that is why it continues to grow despite all the hard work to
stop it:
http://fraudwar.blogspot.com/2006/05/are-we-addressing-cyber-crime-from.html Tag: signcode via proxy Tag: 84347
Are We Addressing Cyber Crime Backwards
Maybe that is why it continues to grow despite all the hard work to
stop it:
http://fraudwar.blogspot.com/2006/05/are-we-addressing-cyber-crime-from.html Tag: signcode via proxy Tag: 84346
NORTON UPDATES
WHEN I RUN NORTON LIVE UPDATE I RECEIVE ERROR"LU1875 THIS UPDATE FAILED
DURING IT'S PREPROCESSING TEXT PHASE" I HAVE DONE EVERYTHING RECOMMENDED TO
CORRECT THE PROBLEM BUT WHEN I RUN THE LIVE UPDATE AGAIN I STILL RECEIVE THE
ERROR AND ALSO THE VIRUS DEFINITIONS WILL NOT UPDATE. I AM NEW WITH THIS
COMPUTER STUFF SO PLEASE BE GENTLE WITH ME.
THANKS Tag: signcode via proxy Tag: 84343
Password is passed Multiple times per thread?
Hello,
I was presented an MS article that stated that when a person submits their
password/credentials in conjunction with an executable, that the passing of
the credentials is multiplied by the threads underneath the executable
process. Is this so? We have had quite a few accounts that have locked out
from a single bad password entry and our limit is set to 5
If anyone has any ideas or could point out an article or white paper which
discusses this issue, I would be most appreciative. Tag: signcode via proxy Tag: 84338
Third-Party Root CA
The company I work for is interested in implementing a third-party Root CA
infrastructure. Can anyone recommend a third-paty that issues Subordinate CA
certificates? I checked with verisign and they don't.
Third-Part Root CA
http://technet2.microsoft.com/WindowsServer/en/Library/07d3c7fa-9ab2-496b-b01f-ad0944fd97541033.mspx?mfr=true
Thank you. Tag: signcode via proxy Tag: 84327
Enabling the administrator to have access to redirected folders
I'm having trouble with Article ID: 288991
"Enabling the administrator to have access to redirected folders"
The directions work just fine for users that have never had their folders
redirected, but the process generally fails for users that have had their
folders previously redirected.
For existing redirected folders, I change the GPO to send the folders back
to the users local profile (and Remote User Profile). I then take ownership
(as an Administrator) of the old redirected folder and delete it at the
%username% folder.
I then change the users GPO back to folder redirection and the folders do
move as I would expect. The problem however still remains in that I as an
Administrator still can't access the redirected folders.
On a rare occasion, this process does work for prior redirected folders but
I still have several users that it does not work on.
When it does work, it usually requires a few days between sending the
folders back to the local and then redirecting them back to the redirected
folder.
I've tried gpudate on the server and workstation and even shut everything
down several times, but I still have the same problem.
Any ideas what might be wrong?
I have Windows Server 2003 SP1 Standard & XP Pro clients.
--
Thanks,
Bob
--
Bob Tag: signcode via proxy Tag: 84323
Help me Please!!!!!!! Bypass traverse checking
I have to edit Everyone to the security policy "Bypass traverse checking"
But I cannot add anyone because the button is grayed out.
I am logged on as administrator
There is a domain controller policy but the administrators is in it and the
eveyone group.
Can someone please help me so that I can edit the Bypass traverse checking. Tag: signcode via proxy Tag: 84318
replication of stored emails
Help. I have a dell pc windows xp, pc cillin, everything updated. On email,
using msn dialup, my stored messages, even 2 year old messages, are
multiplying like rabbits. They will not delete. The folder will not empty.
They now number 20-30 thousand. What bug do I have and how do I clean it
out? PC Cillin scans find nothing. Tag: signcode via proxy Tag: 84317
MS06-018 need help
Hello
I install this patch on a Win2k SP4 server running Exchange 5.5 sp4. After
the reboot it will not let users access their mailbox's. I have remove the
patch via add/remove w/reboot but still no luck. If I move the mail box to a
different server it works fine. If its moved back no joy. I have too many
users and too few servers to move everyone. I need some help with this
please. Tag: signcode via proxy Tag: 84302
Event Viewer Security shows Guest logon?
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 5/11/2006
Time: 1:19:23 PM
User: MOMS\Guest
Computer: MOMS
Description:
User Logoff:
User Name: Guest
Domain: MOMS
Logon ID: (0x0,0x3FFDBD)
Logon Type: 3
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Having multiple entries as shown above. Is someone logging on my system as
guest? Running XP Home, DSL with wireless router. Thanks in advance,
Patrick. Tag: signcode via proxy Tag: 84294
Microsoft patches Windows, Exchange flaws...
"Microsoft released fixes on Tuesday for two sets of flaws in its Windows
operating system and another two vulnerabilities in the software giant's
Exchange mail server, security issues which could allow a worm to propagate
between vulnerable systems, security experts warned.
A critically-ranked patch addresses two flaws in Windows that affect the
Macromedia Flash player from Adobe, a plugin that ships with Microsoft's
Internet Explorer 6 browser, and could allow remote code execution, the
software giant said in its bulletin. The other patch, which is rated
moderate for severity, fixes two flaws in the Microsoft Distributed
Transaction Coordinator (MSDTC) that could be used to cause a
denial-of-service, the software giant stated."
http://www.securityfocus.com/brief/207?ref=rss
Imhotep Tag: signcode via proxy Tag: 84293
McAfee Firewall and network
Hi. Configuration: wall socket from cable company, from wall socket to modem
a connection by cable. From modem cable to router, in the same room.
Receiving computer with wireless adapter is in different room. No other PC's
or networked devices are connected.
I was advised by McAfee that I should choose for the firewall for the
option: "trust home network". (ok, not perfect translation, because the
software is in Dutch). But if I do that, will that not make me less safe ? I
should also add that the router has a built-in firewall, but an imperfect
one. Not port everything is stealthed (as recommended on www.grc.com,
Zonealarm firewall is recommended on that site for it's unique stealth
capabilities (as opposed to just keep a port open or closed)). But I can't
use Zonealarm because it affects my wireless connection in a bad way and
because basically the hardware and/or software of my ISP doesn't like
Zonealarm. I'd also like to add that I use WPA-PSK for communication between
my router and my PC. Also, I have given the router a non-standard login and
and complicated passport.
But my main question is: should I have the McAfee firewall trust the "home
network" or am I better off not doing that. An explanation why would help :)
Thanks. Tag: signcode via proxy Tag: 84292
AD accounts and wireless, VPN, Cisco ACS
I have students and staff AD accounts.
Students should be allowed to access wireless (Cisco LEAP).
Staff accounts should be allowed to access VPN and wireless.
Both Student and Staff Active Directory accounts have the option "Dial-in"
tab set to "Allow".
Problem:
Since that option "Allow" is enabled, students could install and launch VPN
client and get connected thru VPN. I don't want that.
Question:
What would be the best way to create a policy to allow the access to
wireless, not VPN ?
Note that I am using Cisco ACS to control the authentication between the VPN
system, Wireless and Active Directory. VPN concentrator is Cisco 3000. Tag: signcode via proxy Tag: 84289
AcquireCredentials problem running inside iis
I have a website in IIS which has been configured to run with Windows
Authentication and I have <identity impersonate="true" /> in my
web.config.
I know that my configuration works correctly as when I look at the
identity under which the thread is running I can see that it is the
user's account.
My aim is to generate a security token to authenticate the user against
one of our single-sign-on(SSO) servers(written in-house). I am using
the SSPI samples (Microsoft Security SSPI Classes) which I downloaded
from your website to generate tokens in order to perform an sspi
authentication with our SSO server.
The problem I have is that when a user logs on although the thread in
iis seems to run under the user's account, the SSPI call seems to
generate credentials for 'anonymous user'.
When I log on from the machine where iis is running (and I am the
interactive user), the token is generated with my details. Which is
the correct behaviour.
When I log on from another machine where I am the interactive user (
and iis is still running on the original machine where I am the
interactive user ) the token seems to be generated for 'anonymous
user'.
Is there a way I can get the call to AcquireCredentials and
subsequently to InitializeSecurityContext to yield a token relating to
the currently logged on user.
This is the signature for acquireCredentials:
SECURITY_STATUS sResult = AcquireCredentialsHandle(
NULL, // [in] name of principal. NULL = principal of
current security context
pszPackageName, // [in] name of package
fCredentialUse, // [in] flags indicating use.
pszLogonID, // [in] pointer to logon identifier. NULL =
we're not specifying the id of another logon session
NULL, // [in] package-specific data. NULL = default
credentials for security package
NULL, // [in] pointer to GetKey function. NULL = we're
not using a callback to retrieve the credentials
NULL, // [in] value to pass to GetKey
this->credentialHandle, // [out] credential handle (this
must be already allocated)
&tsExpiry // [out] lifetime of the returned credentials
);
Initially (for the above described symptoms), instead of pszlogonid
there was a null being passed in. I have tried to pass in an SID and
even the logoin session id (luid) but this causes the function to
return -2146893050 which i'm pretty sure is SEC_E_NOT_OWNER. I get this
error now, on the iis machine as well as the remote machine.
Is there something i am missing here?
Can anyone help?
Who shot J.R?
I hope Keith Brown is reading im sure he'd sort this out in a flash. Tag: signcode via proxy Tag: 84284
Password dialog window popping up
Beginning yesterday, I've got a dialog window popping up whenever I browse to
a new web page. It's happening with both Mozilla Firefox and Nestcape
browsers (sorry MS). This window requests username and password for random
odd web addresses. As an example, when I browsed to this newsgroup starting
with the Microsoft home page, every page I clicked through to get here popped
up with the following: 'Please enter username and password for [empty
quotation marks] at http://global.msads.net' . Trying to play it safe, I've
been closing the windows using alt-F4 rather than clicking on their cancel
buttons to avoid the ol' button switcheroo trick. As I said, I've never seen
these before yesterday, it's been forever since I've seen a popup window at
all.
As for my sys config, I'm running XP SP2, Zone Labs ZoneAlarm firewall,
AVG free edition anti-virus, Spybot S&D with the IE resident and TeaTimer
resident activated, AdAware SE, Spysweeper with all shields activated,
CWShredder and HijackThis. I scan my sys regularly with Spysweeper, AdAware,
CWShredder and HijackThis, along with the spyware scanner built into Netscape
browser. All these apps, along with XP, are current and updated. Scans
today with AdAware, Spybot S&D, CWShredder and HijackThis came up empty.
Any info or assistance with this shucking fullbit would be immensely
appreciated. Thanx/gracias/merci.
--
What are they infected with? Rage.... Tag: signcode via proxy Tag: 84283
log on
When I try to log on after the computer is sleeping it will not accept any
keystrokes. Therefore I have to hard shut down the computer just to get back
in. Can anyone help Tag: signcode via proxy Tag: 84271
Rdp over VPN
I just want to know if I need to open port 3389 if I using rdp over vpn. In
theory I think that it's enough to open the vpn port, because the rdp is
encapsylated in the IP-sec packet. But is this the case in the reality?
Another question is how is the helpassistant account activated when using
only unsolicited remote assistance? In which phase. I have read that when
using solicited remote assistant it is activated when the invitationen is
created.
Can someone recommend a book or article that in depth describes the
connection phase for unsolicited remote assistance? ( I have find other links
for solicited)
Thanks Tag: signcode via proxy Tag: 84269
Any danger by opening WMV files?
Is there a danger opening WMV files in XP?
I sem to recall something about being taken to dangerous web sites or
getting unwanted code on my system or something like that.
I am running XP Pro/SP2. Tag: signcode via proxy Tag: 84265
Text message spam on my cell phone?
I thought this was not possible with Verizon. Within the past month I've
had several text message spams come in on my Verizon cell phone -- I have to
pay for these -- can't believe this is legal? I've had the phone for a year
now so I have no idea why within the last month I've started getting spam on
my phone.
We need some enforceable laws against spam, this is getting ridiculous. I
can't believe I have no right to prevent solicitation, spam on my door step,
spam in my Email, spam on web sites, spam on my car, and now spam on my
phone. Why is it Monty Python comes to mind....spam spam spam spam spam...
What is this world coming to? People still buy crap they don't need with or
without spam. Tag: signcode via proxy Tag: 84251
Possible to hide a service from users?
Anyone know of a way to either hide a service from users on a server or
prevent them from being able to start a service? Windows 2003...
I installed a server app that needs to remain on the system but I need to
make sure it does not run. The problem is, sys admins out in the field have
access to the server and they will know its not supposed to run but some, out
of curiosity, may do it anyway. Any thoughts? Thanks.
Carl
--
Carl Wilson
Security Engineer Tag: signcode via proxy Tag: 84248
Uable to save changes to Group Policy
I have posted in this in several groups, no responses. Trying again! See
previous posts below.
Since I posted the last time, I have done a "repair" install of Server 2k3
complete with all updates etc. Recreated the domain, same issue.
On a second server, i created a new/different domain, same issue.
I have repeatedly tried resetting permissions/ownership/etc, no effect on
the problem
I am certain this issue is related to the Symantec AV V10.0.2 as I have
another new out of the box unit with R2 which has never had SAV installed, no
issues there.
I am sure this is an early detection of a problem that will be plaguing R2
users as I see it posted through out the newsgroups and have yet to see a
resolution. So any suggestions/fixes would be greatly appreciated. I am on my
way to formatting and reinstalling on three brand new servers as a result.
While I have that luxery in the lab I am sure there are many in a production
environment who dont.
ORIGINAL POSTS:
I have seen numerous posts regarding this issue, no real answers.
My scenero: Three new Windows 2003 Servers Standard Edition R2. Lab
environment, everything fresh. the only setups done are basic domain and
active directory and entering users. Symantec Antivirus Corporate 10.0
installed but disabled. One server is PDC, others are BDC and connected by
VPN (again, lab environment with VPN up and running.) All seems to work well.
Settings replicate properly, licenses replicate properly. No real issues
other than when trying to set GPO, the following error occurs: "group policy
snapin was unable to save your changes due to the following error: the
process cannot access the file because it is being used by another process".
I have read post after post and tried all the suggestions given (which were
few) but none has helped. I thought perhaps replication between the servers
was the issue, but shutting down the BDCs does not effect the situation. If i
go to
D:\WINDOWS\SYSVOL\sysvol\mydomain.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows
NT\SecEdit\GptTmpl.inf and edit the file manually, it still does not let me
save returning an error saying it cannot create the file followed by the full
path. I have reset permissions, ownership, all to no avail. Any responses
greatly appreciated!
UPDATE: I spoke with Symantec support today, found v10.0.2 of SAV Corp. is
not compatible and is problematic when used with Windows server 2003 R2. I
removed SAV from all three servers, removed the domain controller roll from
all three and recreated the domain on the primary server. I still have the
above error when trying to change GPO. In removing the rolls, it seems there
are numerous problems created by installing the SAV V10.0.2 BEWARE!! At this
point it looks as if I will have to start from scratch, format and
reninstall. Any suggestions guys?? I really do not want to go through the
process of reloading 3 servers!
THANKS~~!! Tag: signcode via proxy Tag: 84242
is this allowed????
http://www.msncheck.net/
just thought to let you know
because you have to give youre email and password to a 3th party Tag: signcode via proxy Tag: 84238
Filtering the auditing of file access
Hi,
I have enabled the auditing of object access on our file-server (2003)
through the Group Policy Object Editor. After that i added some groups for
auditing on a folder on our data-disk.
This works fine.
There is only one problem, the eventlog is filling up very fast with events
of object access of files like c:\windows\system32\lsass.exe.
Does anyone know an option to disable auditing on the system-files?? Tag: signcode via proxy Tag: 84223
Tools for analyze all PC in a network
Dear All,
I have one big issue about sharing folder policy in my company. Many users
doesn't understand how to make a proper sharing.
That is why i need tools to analyze automatically all PC in the network,
what kind of the share folder they have and the sharing permission.
Can someone help me here?
Thx Tag: signcode via proxy Tag: 84222
Network Discovery | BSR 64000 on Internal IP?
I recently did a network discovery of our small network. We have
SBS2003 with ISA2004 hosted on the same server with 2 NICS. From the
WAN side NIC it goes to a DSL modem/router and from there to the ISP.
>From the modem/router is also a WPA wireless network. From the LAN NIC
side is a single client computer.
I found all my devices just find but seemed to have found one I didn't
expect. It's sitting on a private IP or 192.168.0.49 and is called
CMTS RiverDeltaNetworks. Looking up the SNMP info shows that it is a
BSR 64000 and is registered to my ISP. Why would this IP be on my
private network? I have DSL and not cable as well. Tag: signcode via proxy Tag: 84220
Virus or not?
My avast labels it as a Virus/worm. Win32:VB-IE [Wrm] The avast has been
removing the infection one piece at a time.. I am suspecting that the
infection piggy backed on an update from Microsoft, that is not an absolute.
It does not seem to be doing any thing now. It messed up my HP All-In-One
Program and Microsoft OneNotein the beginning. I removed the damaged
programs,hacked at the virus then reinstalled. Everything doing good now. I
still get an alert and delet it now and then. I am not sure where it is
coming from. I go to where it is supposed to be. I find three files.
(Ntf7.tmp., Ntf8.tmp, Perflib-Perfd...). I open the hiidden files and find
nothing else. I am thinking that whatever is left is slowly being found and
deleted (time will tell). If not ... ??? Tag: signcode via proxy Tag: 84212
Windows XP Firewall
I have XP Pro & have an issue on the general tab of the xp firewall is greyed
out & it was turned off for some reason. My services are started & group
policy is set to not configured. I did find some info on the net that if I
goto into the registry to here
HKEY_LOCAL_MACHINE
SOFTWARE
Policies
Microsoft
WindowsFirewall
This is what showed up in DomainProfile & StandardProfile folders.
EnableFirewall REG_DWORD 0x00000000 (0)
I changed the value to 1 in the StandardProfile folder it got the firewall
set to on again but it's still greyed out on the General tab. The restore
defaults button on the firewall did squat for me. I can't use system restore
because there are no restore points before this happened. I would like to
restore the ability to turn on or off the XP firewall myself. Can I delete
those 2 registry entries in the DomainProfile & StandardProfile folders
without causing my computer to crash or worse reformat? Would it restore the
normal operation of XP Firewall? If anybody has XP Pro or knows anything
about XP Pro it would be helpfull. Thanks in advance! Tag: signcode via proxy Tag: 84210
Microsoft Security Bulletin(s) for 5/9/2006
Note: There may be latency issues due to replication, if the page does not
display keep refreshing
May 9, 2006
Today Microsoft released the following Security Bulletin(s).
Note: www.microsoft.com/technet/security and www.microsoft.com/security are
authoritative in all matters concerning Microsoft Security Bulletins! ANY
e-mail, web board or newsgroup posting (including this
one) should be verified by visiting these sites for official information.
Microsoft never sends security or other updates as attachments. These
updates must be downloaded from the microsoft.com download center or Windows
Update. See the individual bulletins for details.
Because some malicious messages attempt to masquerade as official Microsoft
security notices, it is recommended that you physically type the URLs into
your web browser and not click on the hyperlinks provided.
Bulletin Summary:
http://www.microsoft.com/technet/security/Bulletin/ms06-May.mspx
Critical Bulletins:
Vulnerability in Microsoft Exchange Could Allow Remote Code Execution
(916803)
http://www.microsoft.com/technet/security/Bulletin/ms06-019.mspx
Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote
Code Execution (913433)
http://www.microsoft.com/technet/security/Bulletin/ms06-020.mspx
Moderate Bulletins:
Vulnerability in Microsoft Distributed Transaction Coordinator Could Allow
Denial of Service (913580)
http://www.microsoft.com/technet/security/Bulletin/ms06-018.mspx
This represents our regularly scheduled monthly bulletin release (second
Tuesday of each month). Please note that Microsoft may release bulletins out
side of this schedule if we determine the need to do so.
If you have any questions regarding the patch or its implementation after
reading the above listed bulletin you should contact Product Support
Services in the United States at 1-866-PCSafety (1-866-727-2338).
International customers should contact their local subsidiary.
--
--
Melissa Travers, MCSE
MVP Lead - Exchange Server, Windows Security,
ISA Server, Virtual Machine & Microsoft Dynamics
Please do not send email directly to this alias. This alias is for newsgroup
purposes only.
This posting is provided "AS IS" with no warranties, and confers no rights. Tag: signcode via proxy Tag: 84207
ANN: C# Online.NET
FOR IMMEDIATE RELEASE
First Wiki-based Online C# and .NET Reference at C# Online.NET
Dallas, TX ? A new concept in online references for Microsoft .NET
programming languages is being pioneered by C# Online.NET?a new
wiki-based, online C# and .NET reference. C# Online.NET offers
documentation, tutorials, and C# source code examples for .NET
languages beginning with the C# language. ?Compared to Java,? says
Will Wagers, founder of C# Online.NET, ?there is a dearth of online C#
help.?
C# Online.NET is enlisting the aid of volunteer contributors to write
articles, tutorials, and C# code snippets (ready-to-use fragments of
C# source code). Offerings will target all C# programmers and
developers from beginner to architect. Wiki software allows virtually
anyone with an Internet connection to edit, view, and write
documentation using their Web browser. ?The advantage of using open
source wiki software is that we can harness the energies of C#
developers worldwide to create a mega-resource for the C# community.?
Contact:
C# Online.NET
Volunteer: editor@csharp-online.net
Press: press@csharp-online.net
Web site: http://wiki.csharp-online.net/
[ ANN: C# Online.NET ] Tag: signcode via proxy Tag: 84202
I cannot use flash drive in my laptop
I got a new tosiba laptop recently, I have accessed to net without proper
anti-virus software. I got a virus in my computer, so I intstall lavasoft,
mcafee, and panda anti-virus. I still suspect that I got some kind of spyware
/ virus - possible that someone is accessing go my information. (another
topic)
Somehow, I found out that I cannot use flash drive, though I can use in
another computer. Whenever, I insert flash drive mesage pop up in right
corner - USB device not recognized: one of the USB devices attached to this
computer has malfunctioned, and windows does not recognise it.
the location of the device is show in bold type
- USB Root Hub (8 ports)
- - unknown device
Please help and advice!
Rock
UK Tag: signcode via proxy Tag: 84199
Enabling Some Others Language in Windows 2003 Lite Version (Or XP Lite)
Has anyone know how can we enable some other unicoded language in
windows 2003 enterprise R2 (lite version)?
In "Regional And Language Option" When I select another language like
"Farsi" it says to me "Windows Unable to install choosen local. Please
Contact your Administrator"
If anyone know how can I solv this problem please tell me Tag: signcode via proxy Tag: 84194
eWeek article - Microsoft give up on Malware...
http://www.eweek.com/article2/0,1895,1945808,00.asp
I'm having a hard time coming to grips with this statement from Microsoft --
that's like saying we give up on the other 80% of the potential market (yes
still only 1 in 5 people use the internet with primary concern being
security fears). I'm hoping this article is not accurate because Microsoft
have sealed their fate with statements like this -- limiting the market and
squeezing as much as they can out of the existing market does NOT present a
stable future.
I've also read other articles reporting very high level Microsoft execs
moving the blame of the security flaws over to the consumer for not having
proper third party protection??
I've been infected with Malware a couple of times and really have NO idea
how it made it's way in when I have a host of tools to prevent such
activity. Is Redmond really saying "we can't do anything about it"?
Rob. Tag: signcode via proxy Tag: 84192
Security Acknoledgemnet
I want to be able to temporarily change an person's homepage when they
connect to my network and show an "Acknowledgement of internet use"
page prior to them being able to access the internet, and if they don't
agree to the terms I've set forward they can't access the internet. Is
there any way this can be done? Tag: signcode via proxy Tag: 84182
Security -- "Message Alerts"
Hello â??
Background:
I have an Intel-based desktop PC (2.6GHz) and I am running my applications
on a Windows XP Home Edition platform.
Problem:
I keep on getting these "messages" every 10 minutes 24/7 that say my
registry is corrupt, I have viruses, blah blah blah. This happens every day
(again 24/7) and has been happening since the last two (2) months. If I am
away from my PC for a few hours, then the message windows INUNDATE the screen
interface. When I am using my PC to get my work done, these messages cause
an enormous amount of interruption.
The Alert Messages point mention a web address and say that if I download a
program, that is the way to remove the viruses/registry corruption, etc.
Then, it will charge $20-$30 for the program! Clearly, it appears as a sales
gimmick. I only have ONE question as I am not even concerned for the
contents within those messages, and that question is HOW do I get rid of the
Alert Messages?
Troubleshooting I have done:
(1) Ran virus and spyware detection scans . . . and removed all infected
files. There were only two.
(2) I have gone to the My Computer icon and from one of the menus, disabled
Remote Connection
(3) Deleted temporary internet files within my Internet Explorer browser, etc.
(4) Deleted Windows messenger using one of the features from the Control Panel
(5) Rebooted my PC (warm and cold)
But what can I do so that I do not get any such programmed messages. Again,
I feel it is a sales gimmick.
Please help ASAP!!!
My email address is n2006@cox.net
Thanks very much!!! Tag: signcode via proxy Tag: 84179