Pages

12/06/2002

Windows::Registry


For Windows 2000 & Windows XP, there is a commandline registry tool, REG.EXE
REG Operation [Parameter List]
Operation [ QUERY | ADD | DELETE | COPY |
SAVE | LOAD | UNLOAD | RESTORE |
COMPARE | EXPORT | IMPORT ]
Return Code: (Except of REG COMPARE)
0 - Succussful
1 - Failed
For help on a specific operation type:
REG Operation /?
Examples:
REG QUERY /?
REG ADD /?
REG DELETE /?
REG COPY /?
REG SAVE /?
REG RESTORE /?
REG LOAD /?
REG UNLOAD /?
REG COMPARE /?
REG EXPORT /?
REG IMPORT /?

Security:Virus::KLEZ


Symantec Security Response - a wealth of information is available from all the big antivirus vendors.
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html Cleaning tools available free - worked like a charm.

Free online virus scan!
http://housecall.trendmicro.com/housecall/start_corp.asp

Patch Outlook!
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp.

Security::Virus::VPN


"Nothing Works!"

NOTHING WORKS! I hear that from people all the time when describing their computer problems. A recent experience with a high profile user's home computer has provided me with some insights and downright fear about future security.
When I visited his home and sat down at his computer I learned that it was true NOTHING WORKED! Got logged in to XP okay, but every shortcut I clicked, "can't find ...." I tried START > RUN > IEXPLORE -> "can't find ..." Then I tried RUN > CMD.EXE -> didn't work. But, RUN > COMMAND.COM worked okay. I went directly to the WINDOWS\SYSTEM32 directory and ran CMD.EXE from the COMMAND shell and it worked fine. (I then had support for long file/directory names and other items I missed greatly under the DOS5 shell clone of COMMAND.COM.) At my CMD prompt I went to C:\PROGRAM FILES\INTERNET EXPLORER and ran IEXPLORE.EXE and it worked! Then I proceeded on an interesting journey of recovery and I had a long time to think about life during reboots and virus scans. During my contemplation, as it all sunk in, I've changed my mind about wanting VPN access for our network. This person was infected with a Klez variant virus. After several hours of work cleaning up the virus almost everything is back to normal. Reading all the vendor propaganda about VPN you would think that the level of encryption of the tunnel is the only security issue with VPN. However, imagine that you have a VPN open to all your employees. Further imagine this big shot bought a new computer and cable modem for Christmas and never installs a personal firewall and then a few weeks later his trial version of NAV expire and gets infected with a virus. This could be a virus or trojan that attaches to available network shares and copies itself there or infects or damages those files. It could be a trojan that sends copies of files or other information to people in the address book or uploads them to a hackers machine. Or it could make his machine a zombie for hackers to take over. We barely have control over user installing and reconfiguring our company computers, we definitely have no control over what mess that home computers might be in. And when you read about companies that have a VPN, but only allow it from company computers, and don't allow personal software installed on company computers.... That "policy" just would make a VPN in our organization not worth the capability. If we have to take our computer with us, then this really wouldn't be as widely useful in our situation. And who is going to police those policies? If we were a huge corporation and hardly ever got ahold of sales persons laptops there would still be very little control over what they did to them.

http://www.microsoft.com/technet/security/bulletin/MS01-020.asp.

12/04/2002

Security::Firewall::Blocking Peer-to-Peer file sharing


P2P network client software is the spawn of S A T A N
I am fighting a constant battle with users who are dedicated to screwing up their computers and flooding our network.
Block the sites
SurfControl category is setup for blocking access to websites related to peer to peer file sharing tools and activities.
Blocking P2P traffic
Blocking ports at firewall(both TCP & UDP)
1214 - Kazaa & Morpheus
6346, 6347 - Gnutella/Limewire
1088 - Audio Galaxy - also uses ftp on ports: 21 and 41000+ which are not feasible to block. So I'm consider blocking outbound to server(s.) I need to find a good way to locate where those servers are and hope they are in the same subnet.

How to Configure an Authoritative Time Server in Windows 2000


Windows includes the W32Time Time service tool that is required by the Kerberos authentication protocol. The purpose of the Time service is to ensure that all computers that are running Windows 2000 or later in an organization use a common time. The Time service uses a hierarchical relationship that controls authority and does not permit loops to ensure appropriate common time usage.

Windows-based computers use the following hierarchy by default:
All client desktop computers nominate the authenticating domain controller as their in-bound time partner.
All member servers follow the same process as client desktop computers.
Domain controllers may nominate the primary domain controller (PDC) operations master as their in-bound time partner but may use a parent domain controller based on stratum numbering.
All PDC operations masters follow the hierarchy of domains in the selection of their in-bound time partner.
Following this hierarchy, the PDC operations master at the root of the forest becomes authoritative for the organization, and you should configure the PDC operations master to gather the time from an external source. This is logged in the System event log on the computer as event ID 62. Administrators can configure the Time service on the PDC operations master at the root of the forest to recognize an external Simple Network Time Protocol (SNTP) time server as authoritative by using the following net time command, where server_list is the server list:

net time /setsntp:server_list

There are several SNTP time servers run by the U.S. Naval Observatory that are satisfactory for this function, for example:
ntp2.usno.navy.mil at 192.5.41.209
tock.usno.navy.mil at 192.5.41.41
After you set the SNTP time server as authoritative, run the following command on a computer other than the domain controller to reset the local computer's time against the authoritative time server:

net time /set

More information about the net time command is available at a command prompt if you type the following command:

net time /?

SNTP defaults to using User Datagram Protocol (UDP) port 123. If this port is not open to the Internet, you cannot synchronize your server to Internet SNTP servers.

From: Microsoft KB http://support.microsoft.com/default.aspx?scid=kb;EN-US;216734
Time Services White Paper: http://www.microsoft.com/windows2000/docs/wintimeserv.doc

12/02/2002

VoIP::Network::Management Tools


Network assessment prior to VoIP deployment is critical to sidestep failure of the entire project.
And Network Management will have a renewed urgency when VoIP is in the picture.
I just came across these products. Haven't used them, but will review them if I ever need to plan for a VoIP installation.
ViViNet: Assessor, Diagnostics, and Manager
http://www.netiq.com/products/va/default.asp