Vulnerability Assessment/Management Process
I am looking for an example of a Vulnerability
Assessment/Management process. Any info would be helpful Tag: NT workstation 4.0 security Tag: 26987
Hundreds of "pops-up"
Is-it some thing I can do to stop thoses "pops-up" to hit
my computer.
They hit you with hundred of "pops-up" and at the same
time they offer you to be able to stop them by buying
from them their software.
I feel that I am a "Blackmail" victim.
Is it somebody out there to tell me what to do to not
participate to that blackmail.
Thank you,
Percy Tag: NT workstation 4.0 security Tag: 26975
Event ID 577 & Failed Install of Microsoft Firewall Client
Upon attempting to install the Microsoft Firewall Client
software Event ID 577 is generated in the security log
(details below) and approximately half-way through the
install it rolls back and brings me to a window that
states "Installation Wizard was completed with an ERROR!".
No clue what the exact error is. Have just found out that
this event is being logged at the same time. I am logged
on as the domain administrator. Anyone have ANY clues?
Searched newsgroups and web endlessly without finding
anything at all.
Event details:
Privileged Service Called:
Server: Security
Service: -
Primary User Name: administrator
Primary Domain: SPACEAGE
Primary Logon ID: (0x0,0x5EEA12)
Client User Name: -
Client Domain: -
Client Logon ID: -
Privileges: SeIncreaseBasePriorityPrivilege Tag: NT workstation 4.0 security Tag: 26971
XP Registry
I have just got an XP box to play with. One of the first things I did
notice, is that I can't see the registry remotely from my W2K box. I then
noticed I couldn't see the event logs either. Why is this? How can I setup
the XP box to see these remotely? The remote registry service is running,
and my account is in the local admins group on the XP box. Tag: NT workstation 4.0 security Tag: 26960
Outlook express
I just started using XP and in my mail settings I like to
disable the preview pane so I can delete anything unknown
before my computer accepts it. I can't figure out where
it is now that I disable it?? Not sure if it has
anything at all to do with the fact I switched from 2000
to XP, but, I thought it was in views or tools but don't
see it anywhere, can someone guide me??? Thanks in
advance! Tag: NT workstation 4.0 security Tag: 26956
hotmail acct hacked!!!
i own a hotmail account of the loggin name
armon_d@hotmail.com. Some one hacked my email and sent an
offensive letter to one of my frnds from my hotmail
account. now i am sure no ones knows my password or the
answer to my secret question. even if the intruder happen
to guess the answer to my secret password, hotmail ask the
user to change and reset the password in the next step of
the process, it does not as i belive tell u the earlier
password. now if the intruder gained acces to my email
through this method he would have to rest my password. but
i accessed my account my using the same old password after
the incident had occurdered and reported to me by my frnd.
i still have the email intact in in his acct , the ones
sent from my acct to his account. I earnestly look for
help in this matter and would like to have a thorough
investigation done and find out the culprit if possible. i
look forward to your help in this regard. Tag: NT workstation 4.0 security Tag: 26939
IUSR lockout
All,
I tried to repeat a problem I was able to get to work before, but I am not
having any luck. I thought I was able to create a DOS on a web server by
locking out the IUSR account at one point. However, when I lock it out now,
I can't seem to get it to cause a DOS. The links and everything else seems
to behave normally even after locking out that account. Any thoughts on
what I may be doing wrong?
FYI, to do this, I created a test directory, and a user named test. For the
test directory, I allowed only the test user, administrators, and system to
have access to that folder. IIS was set to Integrated Auth, and Allow Anon
access. I thought I was able to demonstrate this problem before, but for
some reason I can't get it to work now. Thoughts?
Thanks,
Pair Tag: NT workstation 4.0 security Tag: 26931
Administrator cannot access device manager on DC
ON the DC the administrator can not access the device manager. Windows 2000
Server Sp2 ADintergrated DNS, WINS. When you go to Device manager it says
you do not have sufficient right to access this. login as an administrator
and try again. What is causing this? Any Ideas??
Thanks in Advance
Paul McGuire Tag: NT workstation 4.0 security Tag: 26926
Critical Updates
I continualy receive pop-up messages from MSN "Critical
Updates" Notify Later/ Update Now. I know there is a
default setting for updates, but for quite sometime now I
have not been able to download a "Critcal Update", always
displays a 0 updates available. This pop-up always
displays itself in the middle of being on-line and can be
quite annoying, especially if you quit what you doing and
and click "View Critical Updates Now" and there are no
immediate updates to view or download. Any suggestions? Tag: NT workstation 4.0 security Tag: 26901
unblock
Help!!
How do I 'unblock' an E-mail address??
Sorry, I'm a neophite when it comes to this electronic
stuff.
John Tag: NT workstation 4.0 security Tag: 26899
MSN Messenger
A friend's hotmail acount was hacked by someone.
Microsoft Security would not help her out because they
could not positively identify my friend as the owner of
the account. So I hope to find a solution here.
The problem now is that the hacker is posing as my
friend initiating "cyber sex" with all those on her list.
I myself just ran into the hacker on msn messenger
yesterday. My friend has no access to her hotmail account
whatsoever. What I want to know is whether it is possible
to check for the other person's IP address through
Messenger. If so then how would I do it. I really want to
nail the S.O.B. Thanks Tag: NT workstation 4.0 security Tag: 26892
software restriction policy.
I've turn on the software restriction(to download and
install) to all users includes administrative acount.
Now that i need to turn it off (control panel/ local
security policy) it wont even let me go into local
security policy to change. What can i do to turn this
off? Also i've make sure that i was logged on as
administrative. Reply if you know. Thanks. Tag: NT workstation 4.0 security Tag: 26891
What are these registry entries?
While looking through the startup files, I found these two entries in the
registry that have me wondering what they could be. I used a program called
Pest Patrol to view both the startup files and the running processes of the
PC, to obtain this information that I've provided.
HKLM\software\CLASSES\htafile\shell\open\command (MSHTA.EXE "%1"%*)
HKey_CLASSES_ROOT\htafile\shell\open\command (MSHTA.EXE "%1"%*)
Paths for the two are C:\windows\system\mshta.exe
Both possess an MD5 "signature" of
{95e7e4913891bd12ff9a58c60ea8d143}
What the heck are they? Would any of these be an issue for concern?
Thanks,
LuckyStrike
LS@smokedamagedfurniture.youcandriveitawaytoday.com
----------------------------------------------------------------------------
----------- Tag: NT workstation 4.0 security Tag: 26884
malicious mischief
I just downloaded Microsoft Software Inventory Analyzer
(MSIA) (MsiaSetup.exe) and when trying to install it,
Norton warned me that the program was attempting malicious
mischief and that I should cancel the script.
The program is asking to delete system files. Should I
allow it? Tag: NT workstation 4.0 security Tag: 26878
backdoor.hale
I received a note from my Nortonanti virus... I have
acquired a trojan virus, backdoor.hale. Quarantine
failed. Does anyone have information on this virus and
how to delete from my system without harm? Tag: NT workstation 4.0 security Tag: 26876
Critical Security Bulletin MS03-026
If this vulnerability is as critical as Microsoft and the
U.S. Department of Homeland Security indicate, why doesn't
Microsoft test and offer a patch for the millions of
Windows 98 users? Tag: NT workstation 4.0 security Tag: 26874
Unknown Security Update = Q367067
Not sure what is up on this but I received an mail that
contains Q367067.exe. Have never been sent patches via
email before so I deleted it. I preformed a basic search
for subject patch but no match.
Merk Tag: NT workstation 4.0 security Tag: 26871
MSM Back door trojans
For the past week, every day, several times a day, my
Norton has alerted to me that MSM has been attempting to
plant a back door trojan into my system. This crap has got
to stop!! It specifically is identified as (my IP address)
Admin$\system32\msmssri32.exe
Cookies is one thing...back door trojans is another!! Tag: NT workstation 4.0 security Tag: 26869
Bogus Microsoft security message?
I got an unusual message from Microsoft
(windowssecurity@email.microsoft.com) that starts out with
>*** PLEASE NOTE: Due to the critical importance of this
message, this communication is being sent to all of our
Microsoft customers to alert you of this Security
Bulletin. ***
I have asked a number of people whether they also got this
message - none have seen it. The message goes on:
>It has been widely reported in the press and on
Microsoft's own web site, that on July 16th we released a
critical security bulletin (MS03-026) and a patch
regarding a vulnerability in the Windows operating system.
We wanted to make sure that if you were not aware of this
bulletin and corresponding patch that you take a moment to
go to http://www.microsoft.com/security/
security_bulletins/ms03-026.asp to find out if you are
running an affected version of the Windows operating
system and get the specific information as to what you
need to do to apply this patch if you have not already.
>Although we encourage you to pay attention to all
security bulletins and to deploy patches in a timely
manner we wanted to call special attention to this
particular instance as we have become aware of some
activity on the internet that we believe increases the
likelihood of the exploitation of this vulnerability.
=============
I followed the instructions, downloaded and installed all
the patches (Win2000, IE affected) and now EVERY SINGLE
EMAIL ATTACHMENT IS BLOCKED BY OUTLOOK EXPRESS, its
filename replaced with
OE removed access to the following unsafe attachments in
your mail:
The message from "Microsoft" ends with
>We apologize for any inconvenience the implementation of
this patch might cause and appreciate you taking the time
to update your system.
According to the message header, the message was sent by
Digital Impact, which is known to do bulk mailing on
behalf of Microsoft.
Does anybody know anything about this? And How do I get my
email attachments back???
Thanks in advance.
WK Tag: NT workstation 4.0 security Tag: 26859
Security Update 331953
This update locked up at 4 minutes. I have tried to
restart it but it will not go beyond and install. What
to do? Tag: NT workstation 4.0 security Tag: 26856
How can I block the popup message box?
I always get commercial popup message box when my computer
is connected to internet. Is there any solution to block
these message boxes? Tag: NT workstation 4.0 security Tag: 26845
can't install security patch 823980 on Windows NT 4.0 server
Hello,
I downloaded the security patch 823980 for Windows NT and
I am unable to install it on any of my NT servers. All
servers are running SP6a. I receive an error that states:
Could not determine Product Type
Thanks.
. Tag: NT workstation 4.0 security Tag: 26843
Clock`s Accesibility
Since I install W2k Server and join all the users, none of my network´s user
can change his/her PC´s clock. They does not have permition to do that.
What can I do to let them set their PC´s clock?
I apprecite any help. Thks Tag: NT workstation 4.0 security Tag: 26841
DCOM/RPC Buffer Overflow
If we do not have RPC as an installed protocol in the
network properties are we still vulnerable to attacks? Tag: NT workstation 4.0 security Tag: 26838
Problem with ACT email after installing security updates
I hope that someone can help. I've upgraded to Windows
XP Professional which was installed over Win 98. I also
upgraded to ACT 6.0 which promised better email features.
I couldn't get ACT to accept Outlook Express as the email
program so I used the Act Email. Everything worked fine
for several weeks until after I automatically installed
some XP security updates. Now the ACT email program will
not start-up with certain "bad" emails in the inbox. As
long as there are no "bad" emails in the inbox, the
program functions fine. When bad emails appear I have to
manually delete them from the box with Explorer. The
Outlook Express program functions fine on its own. I've
tried the Act helpdesk in France with no help. They say
that it has to do with the updates for Windows XP. Can
anyone please help?
Rudi Goldman Tag: NT workstation 4.0 security Tag: 26827
Problems With Windows Update
We are trying to update a number of our servers by
accessing the Windows Update Site and then asking it
to "Scan for Updates". In most cases, machines check okay
showing 33%, 66% e.t.c and then come up with a list of
patches which are needed.
However, a number of machines seem to reach 100% of the
check in a matter of a few seconds, and it then says
that "no updates are available at the present time". Now
I know that some of these machines are not running the
latest patches so somewhere along the line the check is
not working correctly. Has anyone else come across
this ? If so, what can I do to rectify this problem ?
Thanks
Mark Williams Tag: NT workstation 4.0 security Tag: 26825
not able to create socket ,coz of insufficient user rights
I am developing a web server in ASP.NET.
There are 2 web services in it. I have a C++ (unmanaged)
Library whose functions are being called from my C# code
with DLLIMPORT attribute.
Problem:
My C++ library has two functions. Both of them are opening
sockets using Winsock.
One function is opening socket
like
(1)
sockRaw = WSASocket(AF_INET,SOCK_RAW,IPPROTO_ICMP,NULL,0
,WSA_FLAG_OVERLAPPED);
and the other function is
(2)
m_Socket = socket(AF_INET, SOCK_STREAM, 0);
I login to my this site from different machine in same
network domain(LAN). I login with my windows user ID and
password of that system. I am able to login with
administrative rights as well as with user rights. All the
users are of the system where the webserver is running.
My problem is :
When I login with normal user ID password API (1) is
failing, I am not able to debug this code. But it is
failing. Whereas in case of administrator every thing is
working fine.
Or in other word I would say that WSASocket is failing in
to create socket because of insufficient user rights.
This is very strange for me , I don't know how it is
happening so kindly help me or suggest me what I should do.
IIS settings:
I set my Directory security to Basic Authentication.
System:
I am using
WINDOWS 2000 service pack 3
IIS 5.0
Dot net 2002 with Framework 1.1.
Thanks in advance
abhijeet Tag: NT workstation 4.0 security Tag: 26824
Unable to configure licensing on the control panel.
I'm using Windows NT4 Server, i unable to configure
licensing on the control panel. When i try to double click
Licensing icon it promt this message "Not available in the
MSDN Edition of BlackOffice"
What happen before was a workstation always cant log on or
cant use the share folder and message promt "Request is
not accepted bt the network, Try again later". And i was
found that the client was reacher the licensing quantity.
So i have purchase another 10 more and still a same. And
after all this happen i was found that i was unable to log
on to licensing on the control panel say "Not available in
the MSDN Edition of BlackOffice" Tag: NT workstation 4.0 security Tag: 26821
Secured Sockets
After establishing a TCP/IP connection between two PCs (W98, WNT, W2000...),
how can I easily secure it using C++ libraries ?
Thanks for help.
Marc. Tag: NT workstation 4.0 security Tag: 26820
Outlook Express
I frequently send and receive *.jpg images in email. OE is
automatically removing them from both my outgoing and
incoming emails. How do I prevent this from happening. I
would like to be asked permission before the attachment is
removed. Do I have to change my security setting
to "Internet zone" instead of "Restricted Sites Zone"? Tag: NT workstation 4.0 security Tag: 26804
Need a firewall - Using Windows Server 2000 as a workstation
I am using Windows Server 2000 as a workstation. What inexpensive
software firewalls run on a server? I only need to protect the single
machine.
Thanks
Bill Zack Tag: NT workstation 4.0 security Tag: 26800
Lost Serial Number Office 2000
My computer had to be brought back to its original
condition and I lost everything. Where I have my
Microsoft Office 2000 disk, I don't have the case where
the serial # is. I did register with Microsoft in the
beginning. Would someone have info on how to obtain this
serial number from the registry with Microsoft? Thanks.
Pls respond to madvey1@wideopenwest.com. Tag: NT workstation 4.0 security Tag: 26796
security lock
In my old version of explorer I got a lock symbol on the
tool bar when I was visitibg a secure site. With my new
Windows XP and explorer 6 I'm not seeing the lock, even
when I visit a site that I know should be secure. Am I
looking in the wrong place? Are my settings wrong?
Thanks,
John Tag: NT workstation 4.0 security Tag: 26795
Critical update contained a virus
While downloading a crit update for exp 6, serv pak 1,
Norton A-V grabbed a virus.
I thought people should know. Unfortunately, I couldn't
find any way to contact Microsoft about it...? Tag: NT workstation 4.0 security Tag: 26794
Critical Updates
I'd like a nickel for every time I've tried to install XP
service pack 1. If it's REALLY critical, you'd better
make it SIMPLER! I've followed all instructions,
including disabling my virus protection. After many
attempts, I finally thought I had it when the
installation seemed to be underway. After approximately
90 minutes into the process, guess what? The
installation failed! I just don't have time for this,
folks! Tag: NT workstation 4.0 security Tag: 26793
current scan by SPYBOT
the following results are being displayed by SPYBOT
i am concerned about being exploited by undesireables
what does it mean and what should i do about it?
>>>>>>>>>>>>>
DSO Exploit: Data source object exploit
HKEY_USERS\S-1-5-18
\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\0\1004=W=3
>>>>>>>>>>>>>
Company: Microsoft
Product: Internet Explorer
Threat: Security hole
Company URL: http://www.microsoft.com/
Company product URL: http://www.microsoft.com/windows/ie/
Company privacy URL:
http://www.microsoft.com/info/privacy.htm
Description
There's a security hole in IE allowing websites to execute
code without asking you first. You can find more
information at http://security.greymagic.com/adv/gm001-ie/
>>>>>>>>>>>>>
thanks for ANY response
JHFoster
Tulsa, Ok Tag: NT workstation 4.0 security Tag: 26791
popups that are pains
can anyone offer a solution to stop the annoying grey box
popups that you have to click on forever to get rid of?
they say to gop to their site and unsubscribe, yet when I
do this I get page not available.
I could buy their stop the popups software hpwever, that
would just make them successful.
does anyone want to file a class action against these
idiots?
i.e. endads.com,stopmessenger.com...
please email an answer to
twogood2b4u2@yahoo.com and post your reply at the
mocrosoft.public.security Newsgroup
thanks,
larry
let's get these guys!!!!!!!!!!!!! Tag: NT workstation 4.0 security Tag: 26790
MS03-026 Login script
One last question:
We have XP and W2000 client machines, does anybody have an
example login script to run this update (so that it runs
depending on the operating system) and will execute only
one time?
Dave thanks for your input,
Thanks
>-----Original Message-----
>Mario:
>
>Go to URL:
>http://microsoft.com/technet/treeview/default.asp?
url=/technet/security/bulletin/MS03-026.asp
>
>There is an EXE file for each affected platform.
>
>You can then place the EXE in a NT Login Script and
execute it with the
>following switch parameters...-z -q
>
>-q = Install quietly
>-z = Don't reboot PC.
>
>Dave
>
>
>"Mario" wrote in message
>news:0a1401c35b54$e377de10$a501280a@phx.gbl...
>> I would like to push this update to the domain rather
than
>> going workstation by workstation, is there any msi and
>> quick explanation how to do this.
>>
>> Thanks Tag: NT workstation 4.0 security Tag: 26778
SUS Server Set up
I am trying to set up an SUS server. I'm having a bit of
difficulty trying to get everything to wokr properly.
Basically when I try and connect to our server I get a
simple directory listing instead of the page I should be
recieving. I read the manual and all but I can't seem to
figure out what's going on. Does any one know of any
quirks for in getting the page to display properly with
the SUS server? I'm at my wits end. Tag: NT workstation 4.0 security Tag: 26775
More security patch problems
I downloaded and attempted to install the latest Windows
2000 security patch (concerning the RPC buffer). I get
two error messages when attempting to open the file.
"A device attached to the system is not functioning"
"Windows2000-KB823980-X86-ENU.exe is linked to missing
export NTDLL.DLL:NtShutdownSystem. "
I have Windows ME and have already gone the "automatic
update" route using the microsoft website. The updates
listed did not include this new security patch. Does
anyone have a helpful tip? Tag: NT workstation 4.0 security Tag: 26768
Could I have been hacked?
At my job I recieved an mysterious email from a person
that has the same email address as I do? For example my
email adress Jlynn@nwood.com I recieved and email from
Friend@nwood.com. I am the exchange admin and I didnt not
setup an account like this and there is not one on the
server. How can this be? I havre microsoft exchange server
2000 and
Jlynn Tag: NT workstation 4.0 security Tag: 26755
Microsoft Security Bulletin MS03-026
Hi
If I am NATing to my PC through a router (NOT A FIREWALL),
am I protected ? Tag: NT workstation 4.0 security Tag: 26752
Update for Hijack this
Hijack this version 1.95 has been updated to version 1.96. To update, open
program>config>misc. tools>check for update on line.
LuckyStrike
--
LS@smokedamagedfurniture.youcandriveitawaytoday.com
----------------------------------------------------------------------------
-------- Tag: NT workstation 4.0 security Tag: 26747
password protect Win 98
Is there any way to password protect Windows 98 on start-
up? (and not be able to by-pass it by chosing cancel)
Thanks in advance for the help. Tag: NT workstation 4.0 security Tag: 26742
Windows Update
Hi
Whlst doing a Windows update, as the update was
downloading, noticed it was titled Security Udate, April
2, 2001.
The date made me suspicious as I generally allow Windows
Update to run once per week. As it is now 2003 am more
than a little surprised.
Anyone know whether this is a genuine update or whether
there is a potential problem.
Cheers Tag: NT workstation 4.0 security Tag: 26732
Limiting a user
Hi everyone. I have a problem. I have an employee that
likes to snoop around a lot on a work computer that's
hooked up to our network. I'd like to set up her account
so that when she logs on she only has access to certain
files. I don't even want her to be able to open the start
button. Can anyone help me? I have absolutely no clue what
to do. Thank You.
Sincerely,
Kenny VanderVoort Tag: NT workstation 4.0 security Tag: 26726
port scanning
I am in need of some help. I have xp,I sign onto to aol
via dialup, my antivirus is up to date, i am running a
firewall.
i am constantly seeing ip scans coming from same
addresses tring to access the same ports every time i
sign online. Sometimes i can be online with no scan for a
while, other times, they just don't stop.
210.5.22.22,
218.15.192.64,
220.112.155.77,
I have tried tracing these scans and blocking and
reporting the ip groups <to no avail>
any ideas anyone to get to the bottom of this? Tag: NT workstation 4.0 security Tag: 26721
How to install this operationg system using the NTSF file
system. We ant to be able to set specific security and
user rights, which the FAT system seems unable to do.