<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>THE OFFICIAL BLOG OF THE SBS "DIVA" : Security</title><link>http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>I'm going naked</title><link>http://msmvps.com/blogs/bradley/archive/2009/12/02/i-m-going-naked.aspx</link><pubDate>Thu, 03 Dec 2009 03:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1743427</guid><dc:creator>bradley</dc:creator><slash:comments>9</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1743427</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1743427</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/12/02/i-m-going-naked.aspx#comments</comments><description>&lt;p&gt;.... on my server when it comes to Antivirus.&amp;nbsp; Yes you read that right.&amp;nbsp; Why?&amp;nbsp; Because at this point in time I really feel that my antivirus vendors are putting me more at risk with the software on than off.&lt;/p&gt;
&lt;p&gt;Why do I say this? Because I don&amp;#39;t trust antivirus anymore.&amp;nbsp; At least not on my Servers these days.&amp;nbsp; Sure the fix for the &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;961775"&gt;tdi.sys&lt;/a&gt; is now included in SP2, but I am really questioning why we knee jerk install antivirus on the servers these days.&amp;nbsp; For sure not on hyperV boxes that should only be HyperV and nothing else in that role.&lt;/p&gt;
&lt;p&gt;But even for SBS boxes... I&amp;#39;m going naked.&lt;/p&gt;
&lt;p&gt;If we have mail hygiene in the front... &lt;/p&gt;
&lt;p&gt;If we have antivirus on the workstations....&lt;/p&gt;
&lt;p&gt;If we have a firewall that is a business class that is used to block sites appropriately....&lt;/p&gt;
&lt;p&gt;If we use Opendns to additionally filter....&lt;/p&gt;
&lt;p&gt;If we move our workstations to not have local administrator rights (I mean you have to go out of your way in SBS 2008 to get local admin)&lt;/p&gt;
&lt;p&gt;I know you&amp;#39;ll say ... &lt;em&gt;but Susan it&amp;#39;s belts and suspenders&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;But I don&amp;#39;t TRUST that belt and I sure don&amp;#39;t TRUST that suspender.&amp;nbsp; I don&amp;#39;t want a firewall driver on my server that ALREADY has a firewall that works.&amp;nbsp; I don&amp;#39;t want software that doesn&amp;#39;t stop the rogue antivirus.&amp;nbsp; I&amp;#39;m using other defensive means&lt;/p&gt;
&lt;p&gt;So when you build your SBS 2008 boxes, make sure SP2 is on there first and foremost.&amp;nbsp; It will only MU/WU down when all other &amp;quot;Important&amp;quot; patches are hidden or installed.&amp;nbsp;&amp;nbsp; Manually download it if you must.&amp;nbsp; Get it on the box... THEN... sit back and decide if the risk of that antivirus software is really and truly worth it.&amp;nbsp; Don&amp;#39;t knee jerk install it just because...because it quite frankly doesn&amp;#39;t make as much sense anymore.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1743427" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Okay so what KSOD?</title><link>http://msmvps.com/blogs/bradley/archive/2009/11/30/okay-so-what-ksod.aspx</link><pubDate>Tue, 01 Dec 2009 02:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1743123</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1743123</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1743123</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/30/okay-so-what-ksod.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;m not saying that there isn&amp;#39;t historical issues with the black screen of death (aka KSOD) that Mark Crall probably lost a few dents in his head to a few months back, but tonight as the Techmeme articles are parroting the &amp;quot;Latest Microsoft Patches cause black screen of death&amp;quot;, I&amp;#39;m asking ...okay are all of the folks supposedly impacted by this not calling in, not posting in a newsgroup, not posting in a forum and only silently suffering?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;I will be the first to eat crow (rather than leftover turkey) if something comes out of this, but right now I&amp;#39;m doubting Thomas for sure.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Microsoft investigates Windows &amp;#39;black screen of death&amp;#39; triggered by recent security updates | Security - InfoWorld: &lt;br /&gt;&lt;/em&gt;&lt;a href="http://www.infoworld.com/t/security/microsoft-investigates-windows-black-screen-death-triggered-recent-security-updates-424"&gt;&lt;em&gt;http://www.infoworld.com/t/security/microsoft-investigates-windows-black-screen-death-triggered-recent-security-updates-424&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;Searches of Microsoft&amp;#39;s support forums today, for example, turned up &lt;/em&gt;&lt;a target="_blank" href="http://social.technet.microsoft.com/Forums/en/w7itprogeneral/thread/5b94b775-992e-4f48-b3ff-c89b3cf45e82"&gt;&lt;em&gt;only one &amp;quot;black screen&amp;quot; thread&lt;/em&gt;&lt;/a&gt;&lt;em&gt; with posts after the Nov. 10 security updates had been released. Four different users on that Windows 7-specific thread said that they faced a blank screen.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Microsoft investigating &amp;#39;black screen of death&amp;#39; | Beyond Binary - CNET News: &lt;br /&gt;&lt;a href="http://news.cnet.com/8301-13860_3-10406369-56.html"&gt;http://news.cnet.com/8301-13860_3-10406369-56.html&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;So this is a problem that ostensibly would have happened 20 days ago? Does it happen right away, or under certain circumstances. &lt;br /&gt;&lt;br /&gt;Cause if its supposed to happen right away, I&amp;#39;m sure we would have heard about it before a press release from a software vendor. People love to jump on any problems that MS has, I&amp;#39;m surprised it would have stayed quiet for 3 weeks.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;I loved this line from the link &amp;quot;If you Google Black Screen then you will find a whopping 80Million plus results&amp;quot; except all but the computer world article and Cnet article are between 1 and 5 years old.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1743123" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>I felt naked....</title><link>http://msmvps.com/blogs/bradley/archive/2009/11/29/i-felt-naked.aspx</link><pubDate>Mon, 30 Nov 2009 07:12:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1743030</guid><dc:creator>bradley</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1743030</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1743030</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/29/i-felt-naked.aspx#comments</comments><description>&lt;p&gt;And now I&amp;#39;m not .....&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/4314.authanvilmobile2.PNG"&gt;&lt;img border="0" src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/4314.authanvilmobile2.PNG" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Now protecting the RWW access (especially for the administrator account)... &lt;/p&gt;
&lt;p&gt;And the cool thing is that I can now use iPhones and Windows mobile phones to be portable softtokens&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/1273.authanvilmobile.PNG"&gt;&lt;img border="0" src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/1273.authanvilmobile.PNG" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve also added the protection to the RDP access to the server so that it&amp;#39;s not open.&amp;nbsp; Mind you I already limited the RDP access to certain IP addresses, but this tightens up security that much more.&lt;/p&gt;
&lt;p&gt;And you can extend the password policy and let people change them LESS often to then ensure that they choose better passwords.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1743030" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Your mailbox has been deactivated</title><link>http://msmvps.com/blogs/bradley/archive/2009/11/16/your-mailbox-has-been-deactivated.aspx</link><pubDate>Mon, 16 Nov 2009 20:29:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740053</guid><dc:creator>bradley</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1740053</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1740053</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/16/your-mailbox-has-been-deactivated.aspx#comments</comments><description>&lt;p&gt;The zip file attached has a low detection at this time...&lt;/p&gt;
&lt;p&gt;Subject: &amp;nbsp;&amp;nbsp; &amp;nbsp;your mailbox has been deactivated&lt;br /&gt;Date: &amp;nbsp;&amp;nbsp; &amp;nbsp;Mon, 16 Nov 2009 21:26:25 +0100&lt;br /&gt;From: &amp;nbsp;&amp;nbsp; &amp;nbsp;support@msmvps.com &amp;lt;support@msmvps.com&amp;gt;&lt;br /&gt;To: &amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;lt;administrator@msmvps.com&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We are contacting you in regards to an unusual activity that was identified in your mailbox. As a result, your mailbox has been deactivated. To restore your mailbox, you are required to extract and run the attached mailbox utility.&lt;br /&gt;&lt;br /&gt;Best regards, msmvps.com technical support.&lt;/p&gt;
&lt;div&gt;&lt;/div&gt;
&lt;p&gt;Virustotal. MD5: 6d0898ff5ea2a6581f1ca3fdd55d840d Trojan.Dropper Win32:Trojan-gen Trojan.Agent-128597: &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/6399729d05ff10775fa1e068369d1433e7173680d00ce00a6bb33e6fbed31970-1258403165"&gt;http://www.virustotal.com/analisis/6399729d05ff10775fa1e068369d1433e7173680d00ce00a6bb33e6fbed31970-1258403165&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5086.findfile.PNG"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5086.findfile.PNG" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740053" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Yes today is Patch Tuesday</title><link>http://msmvps.com/blogs/bradley/archive/2009/11/10/yes-today-is-patch-tuesday.aspx</link><pubDate>Tue, 10 Nov 2009 20:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738852</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1738852</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1738852</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/10/yes-today-is-patch-tuesday.aspx#comments</comments><description>&lt;p&gt;Seen on a Zdnet ad today... yes on Patch Tuesday.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/0830.moz_2D00_screenshot_2D00_672.jpg"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/0830.moz_2D00_screenshot_2D00_672.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Switch from Microsoft Exchange to Google Apps: &lt;br /&gt;&lt;a href="http://www.google.com/apps/intl/en/business/switch_exchange.html"&gt;http://www.google.com/apps/intl/en/business/switch_exchange.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mind you the google love affair isn&amp;#39;t with everyone...&lt;/p&gt;
&lt;pre&gt;&lt;a href="http://www.crn.com/software/221600713;jsessionid=C5XJFRLZLPDQJQE1GHPSKHWATMY32JVN?pgno=1" class="moz-txt-link-freetext"&gt;&lt;em&gt;http://www.crn.com/software/221600713;jsessionid=C5XJFRLZLPDQJQE1GHPSKHWATMY32JVN?pgno=1&lt;/em&gt;&lt;/a&gt;

&lt;em&gt;For solution providers, however, Google has been a different type of 
disruptor. Back in January, Google unveiled a reseller program 
&lt;/em&gt;&lt;a href="http://www.crn.com/software/212900623"&gt;&lt;em&gt;http://www.crn.com/software/212900623&lt;/em&gt;&lt;/a&gt;&lt;em&gt;  for Google Apps Premier 
Edition and Google executives declared that would put them on equal 
footing with Microsoft in the channel. But VARs that have tried to work 
with Google say the company has offered little to back up this claim.

&amp;quot;They wasted weeks of our time, asked us to do their homework for them, 
paid us for none of our time and effort, and then awarded the business 
to someone else that hadn&amp;#39;t put in any of this time and effort,&amp;quot; said 
Daniel Duffy, CEO of Valley Network Solutions, a Microsoft Gold partner 
in Fresno, Calif. &amp;quot;In many ways, Google is exactly like Microsoft at its 
worst -- behaving badly, acting like a schoolyard bully, and taking 
advantage of others just because they can.&amp;quot;&lt;/em&gt;&lt;/pre&gt;
&lt;p&gt;But regardless today &amp;quot;is&amp;quot; Patch Tuesday and you should be reading &lt;/p&gt;
&lt;p&gt;The Microsoft Security Response Center (MSRC) : November 2009 Security Bulletin Release: &lt;br /&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2009/11/10/november-2009-security-bulletin-release.aspx" class="moz-txt-link-freetext"&gt;http://blogs.technet.com/msrc/archive/2009/11/10/november-2009-security-bulletin-release.aspx&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Security Research &amp;amp; Defense : Details on the License Logging Service vulnerability: &lt;br /&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/11/10/details-on-the-license-logging-service-vulnerability.aspx" class="moz-txt-link-freetext"&gt;http://blogs.technet.com/srd/archive/2009/11/10/details-on-the-license-logging-service-vulnerability.aspx&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Security Research &amp;amp; Defense : Vulnerability in Web Services on Devices (WSD) API: &lt;br /&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/11/10/vulnerability-in-web-services-on-devices-wsd-api.aspx" class="moz-txt-link-freetext"&gt;http://blogs.technet.com/srd/archive/2009/11/10/vulnerability-in-web-services-on-devices-wsd-api.aspx&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Security Research &amp;amp; Defense : Font Directory Entry Parsing Vulnerability In win32k.sys: &lt;br /&gt;&lt;a href="http://blogs.technet.com/srd/archive/2009/11/10/font-directory-entry-parsing-vulnerability-in-win32k-sys.aspx" class="moz-txt-link-freetext"&gt;http://blogs.technet.com/srd/archive/2009/11/10/font-directory-entry-parsing-vulnerability-in-win32k-sys.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738852" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>So you have an app you want on Win7 and you don't want it to throw off a UAC warning?</title><link>http://msmvps.com/blogs/bradley/archive/2009/11/03/so-you-have-an-app-you-want-on-win7-and-you-don-t-want-it-to-throw-off-a-uac-warning.aspx</link><pubDate>Wed, 04 Nov 2009 02:59:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737512</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1737512</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1737512</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/03/so-you-have-an-app-you-want-on-win7-and-you-don-t-want-it-to-throw-off-a-uac-warning.aspx#comments</comments><description>&lt;p&gt;So you have an app you want on Win7 and you don&amp;#39;t want it to throw off a UAC warning?&lt;/p&gt;
&lt;p&gt;LUAbuglight it!&lt;/p&gt;
&lt;p&gt;Find the offensive permission sticking part of the program and adjust the registry permissions or file permissions.&amp;nbsp; Very very very cool tool.&amp;nbsp; I&amp;#39;ll blog it in action later.&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;a href="http://blogs.msdn.com/aaron_margosis/pages/LuaBuglight.aspx"&gt;&lt;em&gt;http://blogs.msdn.com/aaron_margosis/pages/LuaBuglight.aspx&lt;/em&gt;&lt;/a&gt;&lt;em&gt; &lt;/em&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;LUA Buglight 2.1 is here.&amp;nbsp; LUA Buglight identifies admin-permissions issues (&amp;quot;LUA bugs&amp;quot;) in desktop applications.&amp;nbsp; I&amp;#39;ve made a lot of changes to LUA Buglight since the last &amp;quot;2.0 Preview&amp;quot; that I posted, so the version number has been bumped up:&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul style="margin-top:0in;"&gt;
&lt;li class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;Support for Windows 7, Vista and XP, and corresponding Servers (2008 R2, 2008, 2003) &lt;/em&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;Support for x64 (except on XP/2003) &lt;/em&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;Completely revamped Reporter -- streamlined and with more detailed results&lt;/em&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;Note:&amp;nbsp; The new Reporter has necessitated a new file format, so the new Buglight cannot read reports generated from older versions of Buglight.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;One thing that is seriously missing is documentation -- I hope to have that&amp;nbsp;posted here&amp;nbsp;in some form soon.&amp;nbsp; The basics:&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul style="margin-top:0in;"&gt;
&lt;li class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;On XP/2003, you need to run it as a standard user, and you need the username/password for an administrative account; on Vista and higher, you need to run it non-elevated as a member of the Administrators group, with UAC and admin-approval mode enabled. &lt;/em&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;Tell it what program to run, then run it.&amp;nbsp; Whenever&amp;nbsp;your app&amp;nbsp;performs an action that fails unelevated, it will repeat the operation with admin rights before returning control back to the program.&amp;nbsp; If it fails without admin rights and succeeds with admin rights, details about that operation get logged. &lt;/em&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;Click the &amp;quot;Stop Logging&amp;quot; button to close the log file; by default this will also open the Reporter and show the results.&lt;/em&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;Another feature that isn&amp;#39;t present yet is that while LUA Buglight does an excellent job of identifying when a program performs operations that succeed only when run as administrator, right now it doesn&amp;#39;t provide the details to fix it if you can&amp;#39;t modify the source code.&amp;nbsp; My plan is to turn that into a community effort by documenting the report&amp;#39;s XML format and then providing some PowerShell scripts that process the results and point to app-compat shims, permissions changes, or other mitigations for the identified problems.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-bottom:6pt;"&gt;&lt;span lang="EN"&gt;&lt;em&gt;I wish I could work on LUA Buglight full time, but it&amp;#39;s an unfunded,&amp;nbsp;spare-time effort, outside of my day job.&amp;nbsp; I know that LUA Buglight would be a lot more useful with documentation, but it&amp;#39;s more useful posted without documentation than it is not posted at all waiting for me to write up documentation.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN"&gt;&lt;em&gt;More information will be posted to this blog.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737512" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Net patch gets offered up all by itself</title><link>http://msmvps.com/blogs/bradley/archive/2009/11/02/net-patch-gets-offered-up-all-by-itself.aspx</link><pubDate>Tue, 03 Nov 2009 06:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1737251</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1737251</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1737251</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/02/net-patch-gets-offered-up-all-by-itself.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/2061.family.PNG"&gt;&lt;img border="0" src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/2061.family.PNG" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;One of the recent changes to the net family patches is now 951847 is offered up all by itself on Microsoft Update.&lt;/p&gt;
&lt;p&gt;If you are deploying patches in other ways, it&amp;#39;s a wise idea to take from Microsoft update.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Just do that one all by itself.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1737251" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>So what if you have an older version of Quickbooks that they are not patching?</title><link>http://msmvps.com/blogs/bradley/archive/2009/11/01/so-what-if-you-have-an-older-version-of-quickbooks-that-they-are-not-patching.aspx</link><pubDate>Sun, 01 Nov 2009 23:59:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736946</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1736946</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1736946</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/01/so-what-if-you-have-an-older-version-of-quickbooks-that-they-are-not-patching.aspx#comments</comments><description>&lt;p&gt;How to fix a potential security issue in QuickBooks 2007, 2008, and 2009. - THE OFFICIAL BLOG OF THE SBS &amp;quot;DIVA&amp;quot;: &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/bradley/archive/2009/11/01/how-to-fix-a-potential-security-issue-in-quickbooks-2007-2008-and-2009.aspx"&gt;http://msmvps.com/blogs/bradley/archive/2009/11/01/how-to-fix-a-potential-security-issue-in-quickbooks-2007-2008-and-2009.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So... what do you do about this for older versions of Quickbooks that won&amp;#39;t get patched?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;1. Urge your client base to upgrade to start with as they won&amp;#39;t be patching older versions of the ActiveX.&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp; Uninstall older versions&lt;/p&gt;
&lt;p&gt;3.&amp;nbsp; If you don&amp;#39;t want to uninstall older versions, as uninstalling 10 years of Quickbooks is a bit daunting, the you can set a Killbit&lt;/p&gt;
&lt;p&gt;4.&amp;nbsp; To set it via a reg key, see the download here:&amp;nbsp; &lt;br /&gt;&lt;a href="http://msmvps.com/media/p/1736945.aspx"&gt;http://msmvps.com/media/p/1736945.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Or you can copy this text and put it in a reg file (if you aren&amp;#39;t comfy downloading a file from a blog site)&lt;/p&gt;
&lt;p&gt;=============copy from here=================&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{596801D8-2C9D-4627-9C67-195CB81B655A}]&lt;br /&gt;&amp;quot;Compatibility Flags&amp;quot;=dword:00000400&lt;/p&gt;
&lt;p&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{03C3A013-02F2-4e56-87A8-B74A7C5DC75B}]&lt;br /&gt;&amp;quot;Compatibility Flags?=dword:00000400&lt;br /&gt;=============to here=======================&lt;/p&gt;
&lt;p&gt;5. To set it via group policy see this:&lt;br /&gt;The GPOGUY-- Group Policy Blog: ActiveX Killbits and Group Policy: &lt;br /&gt;&lt;a href="http://sdmsoftware.com/blog/2009/07/activex_killbits_and_group_pol.html"&gt;http://sdmsoftware.com/blog/2009/07/activex_killbits_and_group_pol.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;What you are doing is setting a killbit like here: How to stop an ActiveX control from running in Internet Explorer: &lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/240797"&gt;http://support.microsoft.com/kb/240797&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If you need to undo this, then go into the registry and remove the killbits you set.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736946" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>How to fix a potential security issue in QuickBooks 2007, 2008, and 2009. </title><link>http://msmvps.com/blogs/bradley/archive/2009/11/01/how-to-fix-a-potential-security-issue-in-quickbooks-2007-2008-and-2009.aspx</link><pubDate>Sun, 01 Nov 2009 23:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736903</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1736903</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1736903</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/11/01/how-to-fix-a-potential-security-issue-in-quickbooks-2007-2008-and-2009.aspx#comments</comments><description>&lt;table border="0" bgcolor="#ffffff" width="600" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="566" valign="middle"&gt;
&lt;div align="center"&gt;&lt;span style="font-size:10px;color:#000000;"&gt;How to fix a potential security issue in QuickBooks 2007, 2008, and 2009.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDzS.1jIq.bW89MQ%5f%5fCdDaFPQ0"&gt;See Web version&lt;/a&gt;. &lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
&lt;td width="17"&gt;&lt;img name="spacer17x24" border="0" width="17" src="http://img.delivery.net/cm50content/18816/29323/spacer17x24.gif" height="24" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="1"&gt;&lt;img border="0" width="1" src="http://img.delivery.net/cm50content/18816/29323/spacer.gif" height="24" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" width="600"&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDzU.1jIq.bW89MQ%5f%5fCdKOFPS0"&gt;&lt;img longdesc="QuickBooks ProAdvisor Critical Alert" border="0" width="600" src="http://img.delivery.net/cm50content/18816/29323/PAP-Al-Mast-20091026-600x178.gif" alt="QuickBooks ProAdvisor Critical Alert" height="178" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;td width="1"&gt;&lt;img border="0" width="1" src="http://img.delivery.net/cm50content/18816/29323/spacer.gif" height="149" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td width="17"&gt;&lt;img name="spacer17x24" border="0" width="17" src="http://img.delivery.net/cm50content/18816/29323/spacer17x24.gif" height="24" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="566" valign="top"&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&amp;nbsp;&lt;/td&gt;
&lt;td width="343" valign="top"&gt;&amp;nbsp;&lt;/td&gt;
&lt;td width="200" valign="top"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#4e9e19" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;FIX FOR POTENTIAL ACTIVEX VULNERABILITY &lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenRight.GIF" height="26" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Dear Susan Bradley,&lt;/strong&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;We&amp;#39;ve recently released a fix to address a potential security vulnerability within QuickBooks. The issue was &lt;strong&gt;related to the use of ActiveX technology&lt;/strong&gt; in some versions of QuickBooks. On learning about the issue, we fixed the problem, tested the fixes within the identified versions of the software, and have released updates that will address the vulnerabilities. We are unaware of any customers affected. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Identified&lt;/strong&gt; versions are the Windows desktop versions of Intuit&amp;reg; Quickbooks&amp;reg; 2007 through 2009 Simple Start, Pro, Premier and Enterprise Solutions 7.0, 8.0, and 9.0. &lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;What Is ActiveX?&lt;/strong&gt; ActiveX is a distributed object system and protocol technology developed by Microsoft. Microsoft updates its implementation of ActiveX controls from time to time through scheduled security updates. Many software and Web companies use ActiveX in their offerings. &lt;/span&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Important:&lt;/strong&gt; &lt;strong&gt;&lt;/strong&gt;If exploited, this vulnerability could allow a hacker to access the data on the user&amp;#39;s computer. Therefore ProAdvisors will want to make sure that clients follow through with installing recent updates. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#4e9e19" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;IF YOU HAVE CLIENTS IN QUICKBOOKS 2007, 2008, or 2009&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;a&gt;&lt;img border="0" width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenRightW.GIF" height="26" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Requested Action.&lt;/strong&gt; Where possible and appropriate, please encourage your clients to update their QuickBooks software. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Public Announcements.&lt;/strong&gt; Clients who are registered owners of QuickBooks 2007, 2009, and 2009 are likely to receive direct notification from Intuit. Please be prepared to answer their questions and continue to encourage them to keep their versions of QuickBooks updated with the most current release. &lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Please remind all of your clients to keep their software updated.&lt;/strong&gt; Not all QuickBooks users are registered with Intuit; some may not receive a direct notification.&lt;/span&gt;&lt;/blockquote&gt;
&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#4e9e19" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;TWO FILES NOW PROTECTED&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;a&gt;&lt;img border="0" width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenRightW.GIF" height="26" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;With current releases, two ActiveX controls are now protected that would otherwise retain potential vulnerabilities: &lt;/span&gt;&lt;/p&gt;
&lt;ol style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;&lt;strong&gt;HtmlHelper.dll&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;QBInstanceFinder.dll&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;For the identified versions of QuickBooks, enabling and approving automatic updates, or manually downloading the update and then applying the updates, will eliminate potential risk.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#4e9e19" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;WHERE TO FIND THE QUICKBOOKS UPDATES&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;a&gt;&lt;img border="0" width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenRightW.GIF" height="26" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;For information on the most recent updates available for QuickBooks 2007, 2008, and 2009, including access to manual downloads, can be found at this link; users are asked to identify the product they need to update:&lt;/span&gt;&lt;/p&gt;
&lt;p align="center"&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDzW.1jIq.bW89MQ%5f%5fCdRCFPU0"&gt;&lt;span style="font-size:11px;color:#000000;"&gt;http://support.quickbooks.intuit.com/support/productupdates.aspx&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;Some clients may appreciate a reminder where they can learn more about the most current releases for their U.S. products.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Versions in Other Countries&lt;/strong&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;In rare cases, some U.S. ProAdvisors may have clients who work with a Canadian or United Kingdom version of QuickBooks. Information on these versions follows:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Canadian customers can download the patch from these sites:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;&lt;strong&gt;QuickBooks&lt;/strong&gt;: &lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDzY.1jIq.bW89MQ%5f%5fCdXWFPW0"&gt;http://support.intuit.ca/quickbooks/en-ca/kb/update/update-quickbooks-to-new-product-update/Update_main.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SuccesPME &lt;/strong&gt;customers can download the patch from: &lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDza.1jIq.bW89MQ%5f%5fCeSGFPe0"&gt;http://support.intuit.ca/succespme/fr-ca/kb/update/update-quickbooks-to-new-product-update/Update_main.html&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;United Kingdom customers can download the patch from this site:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDzc.1jIq.bW89MQ%5f%5fCeYaFQA0"&gt;http://support.intuit.co.uk/quickbooks/en-gb/kb/update/update-quickbooks-to-new-product-update/Update_main.html&lt;/a&gt; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:11px;color:#000000;"&gt;Technical Support Contact Information &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;QuickBooks ProAdvisors looking for technical support are directed to the support site for accounting professionals at &lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.ED%5f4.1jIq.bW89MQ%5f%5fCXCAFNW0"&gt;http://accountant.intuit.com/support/support.aspx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;Technical support for non-U.S. versions of QUickBooks can be found following: &lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;Canadian customers please visit us at &lt;br /&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.ED%5f6.1jIq.bW89MQ%5f%5fCXIUFNY0"&gt;http://support.intuit.ca/quickbooks/index.jsp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;French Canadian customers please visit us at &lt;br /&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.ED%5f8.1jIq.bW89MQ%5f%5fCXPIFNa0"&gt;http://support.intuit.ca/succespme/index.jsp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;U.K. customers please visit us at &lt;br /&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.ED%5fA.1jIq.bW89MQ%5f%5fCYNCFOD0"&gt;http://support.intuit.co.uk/quickbooks/index.jsp&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#4e9e19" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;COORDINATED EFFORT WITH OTHER AGENCIES &lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;a&gt;&lt;img border="0" width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenRightW.GIF" height="26" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;As a further precaution, we will coordinate release of this information with US-CERT (&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDze.1jIq.bW89MQ%5f%5fCefOFQC0"&gt;http://www.cert.org&lt;/a&gt;) and with Microsoft, for a future release within their regular security updates for ActiveX control configuration. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;However, at this time, downloading Intuit&amp;rsquo;s patch is the only immediate way to eliminate the vulnerability in our currently supported versions of QuickBooks. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#4e9e19" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;THANKS FOR HELPING YOUR CLIENTS&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;a&gt;&lt;img border="0" width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreenRightW.GIF" height="26" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;We may not say it often enough, but thanks for helping clients get the most out of QuickBooks software. We greatly appreciate the role you play in providing your clients with a superior experience using QuickBooks. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;As to the current issue, we have included some FAQs for your reference.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;Sincerely,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;~ Your ProAdvisor Team,&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreyLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#999999" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;FOR YOU: FREQUENTLY ASKED QUESTIONS (FAQs) &lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;a&gt;&lt;img border="0" width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreyRightUp.GIF" height="26" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;
&lt;hr /&gt;
&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Questions Specific to Your Role as ProAdvisor&lt;/strong&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;We know you are likely to be running multiple versions of the software, each in its own directory.&lt;/strong&gt; As much as possible, the following questions have been posed and answered in anticipation of your needs in supporting multiple clients on multiple versions of QuickBooks. We also include some additional questions that clients may have for you that are not directly addressed in the security alert that will be coming their way.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Several terms used: &lt;/strong&gt;Intuit updates its software from time to time by releasing software patches. Each update or patch is given a Release number for easy identification. In the notes that follow, you may see the term update, release, or patch, depending on the context, used interchangeably.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ1. Are any other Intuit products subject to this vulnerability? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A1.&lt;/strong&gt; At this time and to the best of our knowledge, other Intuit products do not have this vulnerability. If we learn otherwise, we will provide further guidance as soon as possible. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ2. Does this issue affect QuickBooks 2010? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A2.&lt;/strong&gt; No. Neither QuickBooks 2010, nor Enterprise Solutions 10.0, released in September 2009, are exposed to this vulnerability. Of course, we still encourage users to accept the most current releases for the software.&lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ3. What are the updates or releases that are required for 2007, 2008, and 2009? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A3.&lt;/strong&gt; Releases are cumulative in nature, and over time the most current release will have even a higher number. But for each of the following versions of QuickBooks, the release number shown marks the first introduction of the resolution of the security vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;QuickBooks 2009: &lt;strong&gt;R8&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;QuickBooks 2008: &lt;strong&gt;R10&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;QuickBooks 2007:&lt;strong&gt; R13&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;The updates are also requested for the following versions of Enterprise Solutions: 7.0, 8.0, and 9.0. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ4. What if I have multiple Intuit products? Do I need to download and install the patch for each one? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A4.&lt;/strong&gt; If you have installed more than one of the identified versions of Quickbooks (2007-2009), you should apply patches for each version. This is because there are unique updates for each version to address the &lt;strong&gt;HtmlHelper.dll&lt;/strong&gt; file. (The &lt;strong&gt;QBInstanceFinder.dll&lt;/strong&gt; file is in the &lt;strong&gt;Common Programs&lt;/strong&gt; folder, and one update will update all installed versions for that DLL file.) &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ5. Are older versions of QuickBooks, that is, QuickBooks 2006 or earlier, subject to the ActiveX vulnerability?&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A5:&lt;/strong&gt; Yes. Because these earlier versions are no longer supported, Intuit is unable to provide a tested solution to the vulnerability. See also the next two related questions. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ6. What if my client is still running an earlier, nonsupported version of QuickBooks? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A6.&lt;/strong&gt; Intuit strongly recommends that all users move to a currently supported version of QuickBooks. This recommendation will be clearly stated in the Intuit communications going to your clients on the topic. The &lt;strong&gt;Frequently Asked Questions&lt;/strong&gt; that are meant to be posted for the benefit of QuickBooks users will also identify this need in the face of the potential vulnerability of QuickBooks 2006 and earlier. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;This means that there is no good solution to recommend to clients who continue to run QuickBooks 2006 and earlier, and the ProAdvisors who may grudgingly support them. Possibly the potential vulnerability will encourage such clients to upgrade at this time. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:bold;"&gt;&lt;span style="font-size:11px;color:#000000;"&gt;So-Called &amp;quot;Kill Bit&amp;quot; Solution Not Recommended. &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:11px;color:#000000;"&gt;In the case of systems administrators of networks where QuickBooks may have once been installed but is no longer used, Intuit has prepared some instructions that involve editing the Registry to disable calls to the Internet Browser. &lt;a&gt;See here&lt;/a&gt;. Sometimes this approach is informally called the &amp;quot;kill bit&amp;quot; solution.&lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;&lt;strong&gt;NOT Recommended for Clients.&lt;/strong&gt; This solution is not recommended for clients running an earlier version of QuickBooks. Besides the riskiness of editing the Windows registry, the kill bit solution has not been tested in earlier versions and could possibly interfere with some areas of functionality.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Especially NOT Recommended for ProAdvisors.&lt;/strong&gt; For ProAdvisors running multiple versions of QuickBooks, including QuickBooks 2006 and earlier, the kill bit solution is not recommended for the above reasons and also because the solution would also disable one of the DLL files used by ALL versions of QuickBooks, including those otherwise updated. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Developing:&lt;/strong&gt; Please understand that Microsoft continues to work on security updates for its ActiveX implementation, so more general solutions may be forthcoming from that source. If so, those general solutions may address vulnerabilities in QuickBooks 2006 and earlier. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ7. If I run an update for QuickBooks 2007, 2008, or 2009, won&amp;#39;t that resolve the problem for ALL versions using the ActiveX controls? Including 2006 and earlier? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A7.&lt;/strong&gt; No. Of the two ActiveX control files identified above, one is maintained in common across versions of QuickBooks, but the other is specific to each QuickBooks version. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;Therefore running an update for one of the recent versions of QuickBooks does not remove the potential vulnerability for an earlier version of QuickBooks. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;FAQ8. I have one or more clients who are using a version of QuickBooks from outside the United States. What should I do?&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A8.&lt;/strong&gt; The U.S. version of QuickBooks has cousins developed for local markets in Canada, the United Kingdom, Australia, and South Africa. The security issue is being addressed for these versions too; for more information, see the Support websites for these versions. See also the list of versions in the question below, on &amp;quot;&lt;strong&gt;How do I make sure I have the patch?&lt;/strong&gt;&amp;quot; In the answer, we list specific versions from these countries.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;Websites for downloading the update for several countries are shown above. The following phone numbers are also available:&lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;Canadian customers: &lt;strong&gt;1-888-829-1722&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;U.K. customers: &lt;strong&gt;0845 606 2161&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table border="0" width="566" cellpadding="0" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="23" valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreyLeft.gif" height="26" alt="" /&gt;&lt;/td&gt;
&lt;td bgcolor="#999999" width="520" valign="middle"&gt;&lt;span style="font-size:13px;color:#ffffff;"&gt;&lt;strong&gt;FOR CLIENTS: FREQUENTLY ASKED QUESTIONS (FAQs) &lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="23" valign="top"&gt;&lt;a&gt;&lt;img border="0" width="23" src="http://img.delivery.net/cm50content/18816/29323/barGreyRightUp.GIF" height="26" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x21.gif" height="21" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="520" valign="top"&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Anticipated Questions Posted for All Users&lt;/strong&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;For your reference, here are the FAQs posted for all users by Intuit about the security updates. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q1. What if I&amp;#39;ve uninstalled one of these products and no longer use it? Do I still need the patch? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A1.&lt;/strong&gt; If you have uninstalled QuickBooks, you should not be vulnerable to these vulnerabilities. If you have installed multiple versions of QuickBooks, you will be vulnerable if any affected version is still installed. Uninstalling all affected versions of the software will remove the vulnerability from your system. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q2. How do I download and install the update? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A2.&lt;/strong&gt; All users of an identified version of QuickBooks should download the security update at: &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDzW.1jIq.bW89MQ%5f%5fCdRCFPU0"&gt;http://support.quickbooks.intuit.com/Support/ProductUpdates.aspx&lt;/a&gt;. Canadian users can also download the update from: &lt;a href="http://accountantservices1.intuit.com/r/r?2.1.3K7.2YX.17a2ke.DODdi6..N.EDzY.1jIq.bW89MQ%5f%5fCdXWFPW0"&gt;http://support.intuit.ca/quickbooks/en-ca/kb/update/update-quickbooks-to-new-product-update/Update_main.html&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;When the page appears:&lt;/span&gt;&lt;/p&gt;
&lt;ol style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;Choose your product by clicking the product selector link. &lt;/li&gt;
&lt;li&gt;Click the &lt;strong&gt;Update&lt;/strong&gt; button to start the download and click &lt;strong&gt;Go&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Open&lt;/strong&gt; or &lt;strong&gt;Run This Program from its Current Location&lt;/strong&gt; to begin installing the update immediately. Restarting your computer is not required.&lt;/li&gt;
&lt;li&gt;If you don&amp;#39;rt have time to install the update, you can select &lt;strong&gt;Save&lt;/strong&gt; or &lt;strong&gt;Save This Program to Disk&lt;/strong&gt; and the update file, called &lt;strong&gt;qbwebpatch.exe&lt;/strong&gt;, will download to your hard drive. You&amp;#39;ll need to open that file to run the update.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q3. How do I check that the security update has been applied? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A3.&lt;/strong&gt; To make sure the patch has been applied and is installed on your system, &lt;/span&gt;&lt;span style="color:#000000;"&gt;o&lt;/span&gt;&lt;span style="font-size:11px;color:#000000;"&gt;pen QuickBooks, and press the &lt;strong&gt;F2&lt;/strong&gt; key.&amp;nbsp; In the display, you should see the product version information in the first line. Versions of QuickBooks with the patches applied are the following:&lt;/span&gt;&lt;/p&gt;
&lt;ul style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;QuickBooks 2009 R8 US&lt;/li&gt;
&lt;li&gt;QuickBooks 2008 R10 US&lt;/li&gt;
&lt;li&gt;QuickBooks 2007 R13 US&lt;/li&gt;
&lt;li&gt;QuickBooks 2006 R12 UK&lt;/li&gt;
&lt;li&gt;QuickBooks 2008 R12 UK&lt;/li&gt;
&lt;li&gt;QuickBooks 2009 R6 CAN&lt;/li&gt;
&lt;li&gt;QuickBooks 2008 R8 CAN&lt;/li&gt;
&lt;li&gt;QuickBooks MC R24 CAN&lt;/li&gt;
&lt;li&gt;QuickBooks 2009 French R6 CAN&lt;/li&gt;
&lt;li&gt;QuickBooks 2007 French R7 CAN&lt;/li&gt;
&lt;li&gt;QuickBooks 2009/10 AU (v18)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q4. What operating systems are supported? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A4.&lt;/strong&gt; The security update is available for all operating systems used by any identified versions of the Quickbooks applications: Windows XP, Windows Vista, and Windows 2000. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;em&gt;[If you are running Windows 98 or Windows ME, you need to have Internet Explorer 6.0 or later installed before you can install the update. Go to the Internet Explorer 6 Downloads Web page to install a more recent version of IE. ]&lt;/em&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Note:&lt;/strong&gt; Intuit products for Apple MacOS X are not affected.&lt;/span&gt; &lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q5: What if I have multiple Intuit products? Do I need to download and install the update for each one? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A5.&lt;/strong&gt; If you have installed more than one identified version of Quickbooks, you should apply an update for each version. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q6. I still have a trial version of Quickbooks installed on my system. Do I still need to apply the security update? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A6.&lt;/strong&gt; Yes. If you have any trial versions of one of the identified versions of Quickbooks installed on your system, you should download and install the security update. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q7. I only use the Internet on a periodic basis. Do I still need to download the security update?&lt;/strong&gt;&lt;/span&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A7.&lt;/strong&gt; Yes. If you installed an identified version of Quickbooks on your computer, the vulnerability poses a security risk regardless of whether you are currently connected to the Internet. We recommend that all users of an identified version download and install the security update. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q8. How do I ensure that my computer has not already been compromised? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A8.&lt;/strong&gt; If you have anti-virus software installed and have updates run automatically, the anti-virus software should detect the presence of any malware on your computer.&amp;nbsp; If you want to determine if your computer has malware on it, run a complete scan of your computer using an anti-virus software product. &lt;/span&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;&lt;a name="KILLBIT" id="KILLBIT"&gt;&lt;/a&gt;Q9. I&amp;#39;m the administrator of my office network.&amp;nbsp;Some machines have had QuickBooks installed at some point but don&amp;#39;t any longer, and aren&amp;#39;t getting automatic updates. What should I do to secure my network? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A9.&lt;/strong&gt; If you have had QuickBooks installed on some computers at some point, and are no longer running QuickBooks on those machines and receiving automatic updates, you can secure these machines by following these steps to edit the Windows Registry.&lt;strong&gt; Please back up the Registry&lt;/strong&gt; before you implement the following changes:&lt;/span&gt;&lt;/p&gt;
&lt;ol style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;Copy the following text to a file with the &amp;quot;&lt;strong&gt;.REG&lt;/strong&gt;&amp;quot; suffix. &lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;Windows Registry Editor Version 5.00&lt;/strong&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX&lt;br /&gt;Compatibility\{596801D8-2C9D-4627-9C67-195CB81B655A}]&lt;br /&gt;&amp;quot;Compatibility Flags&amp;quot;=dword:00000400&lt;/span&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;span style="font-size:11px;color:#000000;"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX&lt;br /&gt;Compatibility\{03C3A013-02F2-4e56-87A8-B74A7C5DC75B}]&lt;br /&gt;&amp;quot;Compatibility Flags?=dword:00000400&lt;/span&gt;&lt;/blockquote&gt;
&lt;ol style="font-size:11px;font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;
&lt;li&gt;Import this into the registry by double-clicking on the &lt;strong&gt;.REG&lt;/strong&gt; file and it will automatically be imported.&amp;nbsp; This will disable the affected ActiveX controls.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;span style="font-size:14px;color:#000000;"&gt;&lt;strong&gt;Q10. What if I use QuickBooks 2006 or a previous version? &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:11px;color:#000000;"&gt;&lt;strong&gt;A10.&lt;/strong&gt; Intuit wants your data to be safe. We recommend you upgrade to a newer version of QuickBooks (2007 or later) as soon as possible and follow the instructions to update that version. QuickBooks 2006 and prior versions are no longer supported and Intuit does not release updates for these products. &lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td valign="top"&gt;&lt;img width="23" src="http://img.delivery.net/cm50content/18816/29323/spacer23x23.gif" height="23" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" valign="top"&gt;&lt;img width="566" src="http://img.delivery.net/cm50content/18816/29323/spacer566x25.gif" height="25" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/td&gt;
&lt;td width="17"&gt;&lt;img name="spacer17x24" border="0" width="17" src="http://img.delivery.net/cm50content/18816/29323/spacer17x24.gif" height="24" style="display:block;" alt="" /&gt;&lt;/td&gt;
&lt;td width="1"&gt;&lt;img border="0" width="1" src="http://img.delivery.net/cm50content/18816/29323/spacer.gif" height="1" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" width="600" valign="top"&gt;
&lt;table border="0" width="100%" cellpadding="30" cellspacing="0"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td bgcolor="#eeeeee" width="600"&gt;&lt;span style="font-size:9px;color:#666666;"&gt;&lt;strong&gt;&amp;copy; 2009 Intuit Inc. All rights reserved.&lt;/strong&gt; Intuit, the Intuit logo, Intuit ProConnection, Intuit ProLine, EasyACCT, Lacerte, ProSeries, QuickBooks, QuickBooks ProAdvisor, Quicken, and TurboTax, among others, are trademarks, registered trademarks and/or registered service marks of Intuit Inc. in the United States and other countries. Other parties&amp;#39; trademarks or service marks are the property of their respective owners and should be treated as such.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Program terms and conditions&lt;/strong&gt;, pricing, features and service options are subject to change without notice.&lt;br /&gt;&lt;br /&gt;This newsletter is provided as a convenience for our customers and is not intended to supplement, modify, or extend the Intuit software license agreement between Intuit and the customer for any Intuit product or service. Terms and conditions subject to change without notice.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you would like to change your e-mail address in our database, please update your QuickBooks ProAdvisor Profile. Each newsletter or alert is mailed using the most recent listing in the ProAdvisor Database. &lt;br /&gt;&lt;br /&gt;If you receive an e-mail message that appears to come from Intuit but that you suspect is a phishing e-mail, please forward it immediately to &lt;a href="mailto:security@intuit.com"&gt;security@intuit.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Intuit Inc., Customer Communications, 2800 E. Commerce Center Place, Tucson, AZ 85706&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/td&gt;
&lt;td width="1"&gt;&lt;img border="0" width="1" src="http://img.delivery.net/cm50content/18816/29323/spacer.gif" height="1" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;
&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="1"&gt;&lt;img border="0" width="1" src="http://img.delivery.net/cm50content/18816/29323/spacer.gif" height="1" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan="3" width="600"&gt;&lt;img longdesc="QuickBooks ProAdvisor Newsletter" width="600" src="http://img.delivery.net/cm50content/18816/29323/PAP-Close-PrGMD-600x178.gif" alt="QuickBooks ProAdvisor Newsletter" height="178" /&gt;&lt;/td&gt;
&lt;td width="1"&gt;&lt;img border="0" width="1" src="http://img.delivery.net/cm50content/18816/29323/spacer.gif" height="149" alt="" /&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:xx-small;color:#666666;font-family:Verdana,Helvetica;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;img width="1" src="http://open.delivery.net/o?2.2.3K7.2YX.17a2ke.DODdi6..N..1jIq.ZD03ODk3OTQmbW89MQ%5f%5fBdaCGBO0" alt=" " height="1" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736903" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Too much, too little, maybe just right?</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/31/too-much-too-little-maybe-just-right.aspx</link><pubDate>Sun, 01 Nov 2009 03:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736701</guid><dc:creator>bradley</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1736701</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1736701</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/31/too-much-too-little-maybe-just-right.aspx#comments</comments><description>&lt;p&gt;For the past two years since we started rolling out Vista, I&amp;#39;ve felt like Goldilocks.&amp;nbsp; I can&amp;#39;t find an antivirus software I like.&amp;nbsp; Trend was my choice until it started putting a firewall in there that made it not quite right.&amp;nbsp; Then I was testing out Nod32 and it nearly was my choice until it too started to have known issues with iTunes and network icon interference.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5706.ThreeBears.gif"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5706.ThreeBears.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So in addition to the desktop icon review tonight, I&amp;#39;m starting the process of removal of the various antivirus&amp;#39; I&amp;#39;ve been testing on various machines and starting to standardize on the one that I think will be the one I choose.&amp;nbsp; But I want a wider beta so I&amp;#39;m going to be installing it on more machines.&amp;nbsp; What is the maybe, hopefully, possibly just right antivirus?&amp;nbsp; I&amp;#39;m leaning towards Forefront client security now.&amp;nbsp; For those who have home users or home businesses, the Microsoft security essentials is my current choice of antivirus.&amp;nbsp; Notice I didn&amp;#39;t say &amp;quot;free&amp;quot; antivirus, I said antivirus.&amp;nbsp; It&amp;#39;s discouraging when we&amp;#39;re paying annual subscriptions to products that are not catching rogue antivirus, causing slow downs of our systems, and in general, if they were operating systems, we&amp;#39;d be a lot more upset than we are right now.&lt;/p&gt;
&lt;p&gt;So before you ask, can the management console of Forefront go on SBS 2008?&amp;nbsp; Nope.&amp;nbsp; Can&amp;#39;t.&amp;nbsp; But this is part of my larger test to see if the native notification of antivirus status is good enough for this Goldilocks.&lt;/p&gt;
&lt;p&gt;I&amp;#39;ll let you know how this fairy tale ends.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736701" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>UAC on a Server</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/28/uac-on-a-server.aspx</link><pubDate>Thu, 29 Oct 2009 06:41:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736052</guid><dc:creator>bradley</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1736052</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1736052</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/28/uac-on-a-server.aspx#comments</comments><description>&lt;p&gt;Sometimes (okay a lot of times) I have this annoying streak where I want people to ask themselves if there is a true risk to what they are doing.&amp;nbsp; Too many times in security we turn knobs and do things just because some tool said so or some article said we all must do it.&amp;nbsp; And I&amp;#39;m guilty of it too.&amp;nbsp; The &amp;quot;best practices&amp;quot; mantra.&lt;/p&gt;
&lt;p&gt;Sometimes the best practice of all is to patch yourself... as in patch your own stupidity.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Some people may freak out about what I&amp;#39;m about to post.&amp;nbsp; Some people may question why I feel this way, but from day one I&amp;#39;ve cringed at that UAC on SBS 2008 and felt that if it annoyed me a little bit when I was working on the server, it certainly would be annoying to others.&amp;nbsp; So today when I got this email....&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;em&gt;With SBS2008 deployments we are finding UAC to be a pain whenever you need to change ini or script files etc from inside a folder that is secured be administrator group permissions rather than explicitly applied to the user account.&amp;nbsp; Now I can accept this is UAC doing its thing and thats ok but the only way I have found to get around this is running notepad as administrator and then I can change the files as I need; the problem is, is that having to navigate through folders in this manner when trying to make changes to several config files is pretty clunky (in a recent sbs 08 deployment we had to disable uac and restart it to do all the changes to 30 odd ini files for an app that is used).&amp;nbsp; I&amp;rsquo;m overly interested in changing folder permissions explicitly to get around this; have you got any thoughts of how we might get around this?&lt;/em&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;em&gt;&amp;nbsp;Thanks for your time.&lt;/em&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;It reminded me of that cringing I personally do&amp;nbsp;and it made me once again question the sanity of this setting.&amp;nbsp; UAC first and foremost is a tool to beat vendors over the head to write code better.&amp;nbsp; That&amp;#39;s it&amp;#39;s basic goal in life.&amp;nbsp; It&amp;#39;s not to annoy you (even though for many of you in Vista it does a darn fine job of that), it&amp;#39;s not there as a security boundary, it&amp;#39;s there as a virtual 2x4 to hit some sense into coders that DEMANDED admin rights.&amp;nbsp; &lt;/p&gt;
&lt;p class="MsoNormal"&gt;When you are on a server and ESPECIALLY as you set it up, what are you?&amp;nbsp; You are an admin.&amp;nbsp; You are god.&amp;nbsp; You need to be in your &amp;quot;patched for stupid&amp;quot; mode.&amp;nbsp; UAC is there more for the desktop, right?&amp;nbsp; Intially I said that I wasn&amp;#39;t going to beat anyone up they adjusted UAC down to silently elevate as I said I liked protected mode on.&amp;nbsp; &lt;strong&gt;But there was a flaw in my thinking.&lt;/strong&gt;&amp;nbsp; There are times that there are apps on a server that many not behave with UAC is silently elevate mode and it may end up that it won&amp;#39;t tell you if it needs RunAs or true admin rights and you&amp;#39;ll be banging your head against a wall.&amp;nbsp; &lt;/p&gt;
&lt;p class="MsoNormal"&gt;So fasten your seat belt because here I go more into a religious security position.&amp;nbsp; &lt;strong&gt;I won&amp;#39;t kill you if you turn UAC off on a SBS box.&lt;/strong&gt;&amp;nbsp; &lt;/p&gt;
&lt;p class="MsoNormal"&gt;On&amp;nbsp;two conditions of course:&lt;/p&gt;
&lt;p class="MsoNormal"&gt;First you have to promise me you won&amp;#39;t be surfing at that server.&amp;nbsp; No facebook.&amp;nbsp; No farm game on facebook while setting up the&amp;nbsp;SBS box.&amp;nbsp; The only sites that I&amp;#39;ll allow you to go to are Microsoft.com and HP or Dell for drivers.&amp;nbsp; &lt;/p&gt;
&lt;p class="MsoNormal"&gt;Secondly, before you work on that box, you patch your stupid.&amp;nbsp; That means you do your adminy&amp;nbsp;stuff and then get off the box&amp;nbsp;when you aren&amp;#39;t doing adminy stuff.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;My 64bit vendors on the desktop tell me to turn off UAC while installing now.&amp;nbsp; &lt;/p&gt;
&lt;p class="MsoNormal"&gt;So there you have it.&amp;nbsp; Patch for stupid.&amp;nbsp; Do only adminy stuff and I won&amp;#39;t yell at you.&amp;nbsp; Understand that when you are on that server you are God.&amp;nbsp; Act accordingly.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736052" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>The scariness of on premises</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/28/the-scariness-of-on-premises.aspx</link><pubDate>Thu, 29 Oct 2009 03:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736016</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1736016</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1736016</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/28/the-scariness-of-on-premises.aspx#comments</comments><description>&lt;p&gt;Vlad Mazek &amp;ndash; Vladville Blog &amp;raquo; Blog Archive &amp;raquo; What&amp;rsquo;s left of the cloud after it&amp;rsquo;s done raining?: &lt;br /&gt;&lt;a href="http://www.vladville.com/2009/10/whats-left-of-the-cloud-after-its-done-raining.html"&gt;http://www.vladville.com/2009/10/whats-left-of-the-cloud-after-its-done-raining.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Since someone is once again taking pot shots at CPAs who are supposedly deathly afraid of cloud solutions [&lt;em&gt;and since that&amp;#39;s my cue to earn my MacBook from Vlad]&lt;/em&gt;, sometimes even on premises solutions scare one a bit.&lt;/p&gt;
&lt;p&gt;Take for example my HyperV beast I just set up where I want the full GUI on the outside of the HyperV because I want to run HP&amp;#39;s insight manager software to alert me upon impending doom of raid failures and what not.&lt;/p&gt;
&lt;p&gt;So I install the software and it wants an account to set up the database.&amp;nbsp; Okay, let&amp;#39;s use another account and not THIS account I say.&amp;nbsp; So stupidly I set up ANOTHER administrator account and then have to go into the SQL config to allow that second user to have rights in SQL before the installer will set up the database.&amp;nbsp; And then it says &lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/4721.hpsecure.jpg"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/4721.hpsecure.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Hmmm.. okay... I just built in a&lt;a href="http://207.46.16.252/en-us/magazine/2008.02.securitywatch.aspx"&gt; security dependency&lt;/a&gt; where there&amp;#39;s a service running on that box that has rights on there that I &lt;span style="text-decoration:line-through;"&gt;may&lt;/span&gt; do not want.&amp;nbsp; Needless to say I&amp;#39;ll be going back again and trying to see if that process/service will run as a user, and not as an admin.&amp;nbsp; How many more of these decision trees along the way build in chinks in the armors of our on premises servers?&amp;nbsp; Conversely what are the decisions being made by the cloud vendors?&amp;nbsp; If they run HP, what account rights have they selected at that point in the process?&amp;nbsp; What other decision trees have been made along the way?&amp;nbsp; Not all of this is exposed by an audit or in a SAS 70 report.&lt;/p&gt;
&lt;p&gt;But that said... so I earn my Macbook commission for the month, for the record, Vlad, it&amp;#39;s not that I hate cloud, rather my apps won&amp;#39;t go up there at this time, and I need an on premises server.&lt;br /&gt;&lt;br /&gt;Those apps need an on premises Exchange.&amp;nbsp; I&amp;#39;ve done the research and pick the cloud where it makes sense for my business.&amp;nbsp; I can&amp;#39;t when my apps aren&amp;#39;t up there or don&amp;#39;t support up there.&lt;/p&gt;
&lt;p&gt;Not all of us live in a Google browser world you know.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736016" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Searching for a bit of spam</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/28/searching-for-a-bit-of-spam.aspx</link><pubDate>Wed, 28 Oct 2009 07:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1735767</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1735767</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1735767</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/28/searching-for-a-bit-of-spam.aspx#comments</comments><description>&lt;p&gt;Someone showed me this &amp;quot;trick&amp;quot; the other day.&amp;nbsp; Google search on a web site, limiting the domain to just your domain and then search for &amp;quot;sex&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;lr=&amp;amp;rls=com.microsoft%3A*&amp;amp;q=sex++site%3Amsmvps.com&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi"&gt;http://www.google.com/search?hl=en&amp;amp;lr=&amp;amp;rls=com.microsoft%3A*&amp;amp;q=sex++site%3Amsmvps.com&amp;amp;aq=f&amp;amp;oq=&amp;amp;aqi&lt;/a&gt;=&lt;/p&gt;
&lt;p&gt;See how many blog spam/web site spam/bad content has ended up on the site that you weren&amp;#39;t aware of it.&lt;/p&gt;
&lt;p&gt;I got some cleanin&amp;#39; to do.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1735767" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Some of the .NET patch install suggestions....</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/21/some-of-the-net-patch-install-suggestions.aspx</link><pubDate>Thu, 22 Oct 2009 05:12:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1734173</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1734173</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1734173</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/21/some-of-the-net-patch-install-suggestions.aspx#comments</comments><description>&lt;p&gt;Some of the .NET patch install suggestions....&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Newsgroups: microsoft.public.windowsupdate&lt;br /&gt;References: &amp;lt;OSBXnxGTKHA.4360@TK2MSFTNGP04.phx.gbl&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;quot;Shawn E. Hale&amp;quot; &lt;br /&gt;&amp;nbsp;news:OSBXnxGTKHA.4360@TK2MSFTNGP04.phx.gbl...&lt;br /&gt;&amp;nbsp; &amp;nbsp;&lt;br /&gt;All other updates released this date installed fine with the &lt;br /&gt;exception of KB953297.&amp;nbsp; Another home computer installed this update&lt;br /&gt;with no problem.&lt;br /&gt;&lt;br /&gt;The only difference I can find is that the computer where the install&lt;br /&gt;failed had .NET Framework 1.1 Hotfix KB928366 installed.&amp;nbsp; The article&lt;br /&gt;(http://support.microsoft.com/kb/953297) states that this recent &lt;br /&gt;update &amp;quot;supersedes&amp;quot; the hotfix.&amp;nbsp; I tried to uninstall the hotfix but &lt;br /&gt;that lead to another problem where it could not find the &amp;quot;netfx.msi&amp;quot;&lt;br /&gt;file to continue.&lt;br /&gt;&lt;br /&gt;So I stopped that hoping to find another answer here.&amp;nbsp; Any thoughts &lt;br /&gt;on what I should do?&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;br /&gt;I had the same problem, all 100pc&amp;#39;s on the network were failing (due, &lt;br /&gt;I think, to previously installed Visual Studio .Net apps, which &lt;br /&gt;updated dot net).&amp;nbsp; It appears that the installer is referencing a &lt;br /&gt;registry key to find the location of the netfx.msi file.&amp;nbsp; When it &lt;br /&gt;fails to find the file it errors out.&lt;br /&gt;&lt;br /&gt;I grabbed the dotnetfx.exe file from&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=a8f5654f-088e-40b2-bbdb-a83353618b38&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=a8f5654f-088e-40b2-bbdb-a83353618b38&amp;amp;displaylang=en&lt;/a&gt; ,&lt;br /&gt;opened it with WinRAR (or use any comprssion program) and extracted &lt;br /&gt;the netfx.msi to our network.&amp;nbsp; I then entered the network location &lt;br /&gt;into the registry key &lt;br /&gt;[HKEY_CLASSES_ROOT\Installer\Products\DDE7F2BCF1D91C3409CFF425AE1E271A\SourceList\Net] &amp;quot;1&amp;quot;=hex(2):&amp;lt;long hex string you will need to change to your netfx.msi location&lt;br /&gt;&lt;br /&gt;Then I re-ran the updates and it installed fine.&lt;br /&gt;&lt;br /&gt;Hope this helps someone,&lt;br /&gt;Box&lt;/em&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1734173" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Social engineering at it's finest</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/19/social-engineering-at-it-s-finest.aspx</link><pubDate>Tue, 20 Oct 2009 06:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1733599</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1733599</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1733599</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/19/social-engineering-at-it-s-finest.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5417.warning.PNG"&gt;&lt;img border="0" src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5417.warning.PNG" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;They are starting to spoof &amp;quot;upgrade&amp;quot; emails very nicely these days.&amp;nbsp; Warn your customers that no upgrades will be emailed to them.&lt;/p&gt;
&lt;p&gt;Inform them of exactly HOW you do updates and how you will not email them links like this.&amp;nbsp; Set in place a process for how you inform folks of needed actions and ensure communication is done in such a manner that they know you are you and spoofs like this can&amp;#39;t happen.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1733599" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>A big, big, big sigh</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/15/a-big-big-big-sigh.aspx</link><pubDate>Fri, 16 Oct 2009 04:39:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732664</guid><dc:creator>bradley</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1732664</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1732664</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/15/a-big-big-big-sigh.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5381.goboom.PNG"&gt;&lt;img src="http://msmvps.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/bradley/5381.goboom.PNG" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Jerome Chout : Do not apply KB974571 to LCS/OCS Servers: &lt;br /&gt;&lt;a href="http://blogs.technet.com/jchout/archive/2009/10/15/do-not-apply-kb974571-to-lcs-ocs-servers.aspx"&gt;http://blogs.technet.com/jchout/archive/2009/10/15/do-not-apply-kb974571-to-lcs-ocs-servers.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is one of those patch testing moments that you just shake your head and wonder who was asleep at the wheel here.&amp;nbsp; Just for grins I installed 974571 on my Live Communication Server 2005.&amp;nbsp; The minute you reboot the box, the internal IM dies and refuses to log in, the LCS server service fails to start.&amp;nbsp;&amp;nbsp; When you log into the box and check the event viewer, it&amp;#39;s very obvious that LCS is having a problem.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;There are times that I know that it&amp;#39;s hard to find patch issues.&amp;nbsp; We have a lot of software, we have a corner issues.&amp;nbsp; This one... this is a big fat ooops that implies to me that someone somewhere didn&amp;#39;t do a basic job of testing.&lt;/p&gt;
&lt;p&gt;This is why I have the &amp;quot;canary plan&amp;quot; where I test patches first before installing them.&amp;nbsp; This is why i know patches can be uninstalled.&amp;nbsp; This why we don&amp;#39;t have automatic updates on.&lt;/p&gt;
&lt;p&gt;In my opinion, this one should not have gotten out the door like this.&amp;nbsp; And when one does, it impacts patch trust.&lt;/p&gt;
&lt;p&gt;And for me, that&amp;#39;s a big big sigh.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732664" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>One of the promised land issues in cloud deployments is that you never have to worry about upgrades.</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/14/one-of-the-promised-land-issues-in-cloud-deployments-is-that-you-never-have-to-worry-about-upgrades.aspx</link><pubDate>Thu, 15 Oct 2009 05:02:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732494</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1732494</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1732494</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/14/one-of-the-promised-land-issues-in-cloud-deployments-is-that-you-never-have-to-worry-about-upgrades.aspx#comments</comments><description>&lt;p&gt;&lt;em&gt;Obligatory cloud paranoia post to justify the Mac Book from &lt;/em&gt;&lt;a href="http://www.vladville.com"&gt;&lt;em&gt;www.vladville.com&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;One of the promised land issues in cloud deployments is that you never have to worry about upgrades.&lt;br /&gt;&lt;br /&gt;The reality is vastly different.&amp;nbsp; Just ask the &lt;a href="http://blog.seattlepi.com/microsoft/archives/182114.asp"&gt;Sidekick folks&lt;/a&gt; about how well upgrades go.&amp;nbsp; And on the Google doc front, just because someone else updates doesn&amp;#39;t mean that the problems go away...&lt;/p&gt;
&lt;p&gt;Bugs hit Google Docs after recent upgrade: &lt;br /&gt;&lt;a href="http://www.computerworld.com/s/article/9139350/Bugs_hit_Google_Docs_after_recent_upgrade"&gt;http://www.computerworld.com/s/article/9139350/Bugs_hit_Google_Docs_after_recent_upgrade&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Bottom line, I don&amp;#39;t care how big or small you are, there are risks in updating.&amp;nbsp; Period.&amp;nbsp; Whether we do it, he does it, they do it, we all deal with the resulting aftermath.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732494" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Seeing if we can freeze up again tonight</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/14/seeing-if-we-can-freeze-up-again-tonight.aspx</link><pubDate>Thu, 15 Oct 2009 04:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732490</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1732490</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1732490</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/14/seeing-if-we-can-freeze-up-again-tonight.aspx#comments</comments><description>&lt;p&gt;I have the KB974417 back on the blog tonight hoping it will slow down again so I can catch the blogs slowing down again.&amp;nbsp; Why?&amp;nbsp; Debugging is why.&amp;nbsp; And we want to force a dump of the IIS processes.&amp;nbsp; Now last night it worked fine right after I rebooted the server and when I logged back in later in the evening a few hours later was when I noticed the server was crawling.&lt;/p&gt;
&lt;p&gt;So I&amp;#39;m hoping it will do it again and I can catch the hang in action.&lt;/p&gt;
&lt;p&gt;Watch it... it will work fine tonight and not freeze up.&amp;nbsp; There are times that sometimes removing and reinstalling a patch makes it play nice the second time around.&amp;nbsp; Maybe it needs to be shown who&amp;#39;s boss or something.&lt;/p&gt;
&lt;p&gt;But if you later on hit the blog site and it&amp;#39;s realllllly slow.. that means I&amp;#39;ll be going &amp;quot;hooray it&amp;#39;s freezing up again and I can run this debugger and see what&amp;#39;s up&amp;quot;.&amp;nbsp; Okay yeah so I&amp;#39;m kinda weird that whenever something gets to the point where I&amp;#39;m installing the debugging tools I&amp;#39;m having fun, but hey...&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;Generally speaking, Microsoft always recommends to install security updates for the security consideration. There may be some conflicts existed after installing this update. I wonder whether it is possible for you to re-install the update and help to catch IIS hang dump files when you find the web server is hanging. In this way, we could find the root cause of your problem. Please follow below steps to collect IIS hang dump files for us:&lt;/span&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;[Action Plan]&lt;br /&gt;&lt;/span&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;===================================&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;Download and install the Microsoft Debuggers&lt;/span&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;If your server is a 32-bit, please download and install the Microsoft Debuggers from&amp;lt;&lt;a href="http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx"&gt;http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx&lt;/a&gt;&amp;gt; (Debugging Tools for Windows). &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;If your server is a 64-bit, please download and install the Microsoft Debuggers from &amp;lt;&lt;a href="http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx#"&gt;http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx#&lt;/a&gt;&amp;gt; (Debugging Tools for Windows).&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;Get the latest version of the debuggers from this site if multiple versions are present.&lt;/span&gt;&lt;span lang="EN-US" style="font-size:10pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;NOTE: You do not have to install them on your server, but can install on a workstation and then XCOPY the directory to your server. They will work on your server after you have done this without rebooting the server.&lt;/span&gt;&lt;span lang="EN-US" style="font-size:10pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-size:10pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;When you find the server come to crawl after re-install the update&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;===================&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent:-18pt;margin-left:36pt;"&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;&lt;span&gt;&lt;span style="font:7pt &amp;#39;Times New Roman&amp;#39;;font-size-adjust:none;font-stretch:normal;"&gt;1.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;Run AutoDump Plus from a command line (cmd.exe), in the debugger&amp;#39;s directory (Default is c:\Program Files\Debugging Tools For Windows) run the command&amp;nbsp;(changing the path where you would like the files created in): &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph"&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color:red;"&gt;cscript adplus.vbs -hang -iis -o c:\iisdump &amp;ndash;quiet&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent:-18pt;margin-left:36pt;"&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;&lt;span&gt;2. &lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;Wait for &lt;/span&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:red;font-size:10.5pt;"&gt;60&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt; seconds&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent:-18pt;margin-left:36pt;"&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;&lt;span&gt;3. &lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;Run command &amp;quot;&lt;/span&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:red;"&gt;cscript adplus.vbs -hang -iis -o c:\iisdump -quiet&lt;/span&gt;&lt;span lang="EN-US" style="font-family:&amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;;color:#1f497d;font-size:10.5pt;"&gt;&amp;quot; again to generate another IIS dump files.&lt;/span&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;Please ignore any warnings. &lt;b&gt;Please don&amp;rsquo;t log off the logon user and don&amp;rsquo;t close any command prompt window the tool generates. &lt;/b&gt;After a while, you should find the dump file in C:\iisdump. &lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span lang="EN-US" style="color:#1f497d;"&gt;Please send me all the files in c:\iisdump. Please also collect the HTTP ERR logs under C:\Windows\System32\logfiles\HTTPERR and IIS logs under C:\Windows\System32\logfiles for me.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732490" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Things to read, things to watch</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/13/things-to-read-things-to-watch.aspx</link><pubDate>Wed, 14 Oct 2009 05:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732274</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1732274</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1732274</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/13/things-to-read-things-to-watch.aspx#comments</comments><description>&lt;p&gt;Things to watch tonight -- &lt;a href="http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv"&gt;http://ecn.channel9.msdn.com/o9/edge/2/0/4/1/1/oct2090msrcov_edge.wmv&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Things to read tonight -- &lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx"&gt;http://blogs.technet.com/msrc/archive/2009/10/13/october-2009-security-bulletin-release.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=7345"&gt;http://isc.sans.org/diary.html?storyid=7345&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/assessing-the-risk-of-the-october-security-bulletins.aspx"&gt;Assessing the risk of the October security bulletins&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-051-a-note-on-the-affected-platforms.aspx"&gt;MS09-051: A note on the affected platforms&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-050-threat-landscape-for-the-smb-bulletin.aspx"&gt;MS09-050: Exploit timeline for SMB2 RCE vulnerability&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-054.aspx"&gt;MS09-054: Extra info on the attack surface for the IE security bulletin&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/srd/archive/2009/10/12/ms09-061-more-information-on-the-net-security-bulletin.aspx"&gt;MS09-061: More information about the .NET security bulletin&lt;/a&gt; &amp;ndash; Security Research &amp;amp; Defense blog &lt;br /&gt;&lt;a target="_blank" href="http://blogs.technet.com/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx"&gt;Scanti-ly Clad &amp;ndash; Another Rogue Stripped by MSRT&lt;/a&gt; &amp;ndash; Microsoft Malware Protection Center blog &lt;/p&gt;
&lt;p&gt;And I already had to pull this one - &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;974417"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;974417&lt;/a&gt;&amp;nbsp;off the blog site as it was causing the site to resolve very poorly.&amp;nbsp; I&amp;#39;ll be calling into Microsoft support tomorrow (or rather emailing in) but when something worked before, and now it doesn&amp;#39;t, sometimes don&amp;#39;t do a &amp;quot;system rollback&amp;quot;, think about which patch may be the trigger and pull off just that one.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732274" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item><item><title>Subject: Server upgrade warning</title><link>http://msmvps.com/blogs/bradley/archive/2009/10/12/subject-server-upgrade-warning.aspx</link><pubDate>Tue, 13 Oct 2009 06:48:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732116</guid><dc:creator>bradley</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=1732116</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=1732116</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2009/10/12/subject-server-upgrade-warning.aspx#comments</comments><description>&lt;pre&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size:x-small;"&gt;So a couple of folks have been reporting in the listserves that their clients have been getting a message indicating that a server upgrade &lt;br /&gt;will take place and to install the SSL update.&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;br /&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size:x-small;"&gt;Given that this is the patch Tuesday week, it would probably be a good idea to remind your client base that you don&amp;#39;t send them links to install&lt;br /&gt;like this.  Remind them of what your emails look like.&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size:x-small;"&gt;All it takes is one person clicking on that link and if you don&amp;#39;t have web filtering in place, or if the filters aren&amp;#39;t up on the latest and greatest, or if&lt;br /&gt;your client base still is not moved to non administrator, all it takes is one click to get in.&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size:x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size:x-small;"&gt;Subject: Server upgrade warning

Attention!

  On October 16, 2009 server upgrade will take place. Due to this the
system may be offline for approximately half an hour.
The changes will concern security, reliability and performance of mail
service and the system as a whole. 
For compatibility of your browsers and mail clients with upgraded server
software you should run SSl certificates update procedure.
 This procedure is quite simple. All you have to do is just to click the
link provided, to save the patch file and then to run it from your
computer location. That&amp;#39;s all.

URL removed&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;span style="font-family:arial,helvetica,sans-serif;"&gt;&lt;span style="font-size:x-small;"&gt; Thank you in advance for your attention to this matter and sorry for
possible inconveniences.


 
System Administrator
&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732116" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category></item></channel></rss>