Apple delivers mammoth update, patches 58 bugs

Retires Tiger from security support with second Snow Leopard patch batch

Apple patched 58 vulnerabilities in its Mac operating systems today, the most since May 2009, including several in the QuickTime media player that it had fixed separately in early September.

Apple apparently also retired Mac OS X 10.4, aka Tiger, from security support; none of the patches affect that operating system, which debuted in April 2005. Apple traditionally stops providing security updates for its oldest still-supported OS several months after the release of a new edition.

Today's security update was the sixth from Apple this year, and the second that included patches for Snow Leopard , launched in late August.

"Seems a little large, but really, it's par for the course for Apple," said Andrew Storms, director of security operations at nCircle Network Security, referring to the number of individual bugs quashed in today's 2009-006 update. In May, Apple patched a record 67 vulnerabilities ; it addressed 55 in February, 33 in September, and 19 in two separate August updates.

http://www.networkworld.com/news/2009/111009-apple-delivers-mammoth-update-patches.html

Posted by donna | with no comments

Nov. 10, 1983: Computer ‘Virus’ Is Born

1983: Fred Cohen, a University of Southern California graduate student, gives a prescient peek at the digital future when he demonstrates a computer virus during a security seminar at Lehigh University in Pennsylvania. A quarter-century later, computer viruses have become a pandemic for which there’s no inoculation.

Cohen inserted his proof-of-concept code into a Unix command, and within five minutes of launching it onto a mainframe computer, had gained control of the system. In four other demonstrations, the code managed to seize control within half an hour on average, bypassing all of the security mechanisms current at the time. It was Cohen’s academic adviser, Len Adleman (the A in RSA Security), who likened the self-replicating program to a virus, thus coining the term.

But Cohen’s malware wasn’t the first of its kind.

http://www.wired.com/thisdayintech/2009/11/1110fred-cohen-first-computer-virus

Posted by donna | with no comments

Rogue Anti-Spyware Targets Sesame Street's Big Bird

The idea of malware distributors abusing Google Trends is not new. The bad guys have once again demonstrated that they, too, can take advantage of Google Trends. This time their target is Big Bird's birthday.

It's not new that the Google logo includes Big Bird; it does so on special occasions. The Google logo clearly shows Today's Hot Trends, and that's a target for malware writers.

This year is the fortieth anniversary of Sesame Street, and the bad guys have begun their attack. Searching for keywords such as Big Bird's birthday and Big Bird on Google displays pages with compromised sites.

More with video clip in http://www.avertlabs.com/research/blog/index.php/2009/11/09/rogue-anti-spyware-targets-sesame-streets-big-bird/

Posted by donna | with no comments

Certificação Microsoft: 248 Exames

Fazendo uma pesquisa rápida no site da Prometric eu resolvi criar uma lista com todas as atuais certificações que a Microsoft oferece, no total temos 248 exames de certificação para as mais diversas tecnologias. São 12 certificações (em azul) para o profissional que deseja comprovar conhecimento em Gerenciamento, Operações e Deploy. Veja:

 

 

Microsoft Geral - 141 Certificações

 

 

070-089 - Designing, Implementing, and Managing MS Syst Mgmt Serv 2003

070-121 - Designing and Providing MS Volume License Solutions to Sml&M

070-122 - Designing and Providing Microsoft Volume License Solutions

070-123 - Planning, Implementing and Maintaining a Software Asset Mgmt

070-235 - TS:Devlping Busin Process & Intgrtion Sol Using MS Biz Tlk

070-236 - TS: Configuring Exchange Server 2007

070-237 - Pro:Designing Messaging Solutions with MS Exchange Serv 2007

070-238 - Pro: Deploying Messaging Solutions w/MS Exchange Server 2007

070-241 - TS:Busin Process & Integration Sol by Using MS BizTalkServR2

070-262 - TS:MS Office Live Communc Serv 2005-Implem,Manage,Trblshting

070-270 - INSTALL,CONF & ADMINISTERING MS WINDOWS XP PROFESSIONAL

070-271 - Supporting Users & Troubleshooting a MS Win XP Operating Sys

070-272 - Supporting Users & Troubleshooting Desktop Apps on MS Win XP

070-281 - Planning, Deploying, & Managing an Enterprise Proj Mgmt Sol

070-282 - Designing, Deploying, and Managing a Network Solution for a

070-284 - Implementing & Managing MS Exchange Server 2003

070-285 - Designing a Microsoft® Exchange Server 2003 Organization

070-290 - Managing & Maintaining a MS Win Server 2003 Environment

070-291 - Implement,Managing&Maintaining a MS Win 2003 Network Infra

070-293 - Plan. and Maint. a MSWin Srvr2003 Net. Infrastructure

070-294 - Plan., Implem., and Maint. a MSWin Server 2003 Active Dir St

070-297 - Designing MS Win Server 2003 Active Dir & Netwk Infrastruc

070-298 - Designing Security for a Microsoft Win Server 2003 Network

070-299 - Implementing Security in a MS Win Server 2003 Network

070-350 - Implementing MS Internet Security & Acceleration Server 2004

070-351 - TS:MS Internet Security & Acceleration Serv 2006,Configuring

070-400 - TS: MS System Center Operations Manager, Configuring

070-401 - MS System Center Configuration Manager 2007, Configuring

070-403 - System Center Virtual Machine Manager, Configuring

070-431 - TS: Microsoft SQL Server 2005 Implementation & Maintenance

070-432 - TS: MS SQL Server® 2008, Implementation and Maintenance

070-433 - TS: Microsoft® SQL Server® 2008, Database Development

070-441 - PRO:Designing Database Solutions by Using MS SQL Serv 2005

070-442 - PRO:Design & Optimize Data Access by Using MS SQL Serv 2005

070-443 - PRO: Design a DB Server Infrastru by Using MS SQL Serv 2005

070-444 - PRO:Optimiz & Maintain a DB Admin Sol by Usi MS SQL Serv2005

070-445 - TS: MS SQL Server 2005 Business Intelligence-Implem & Mainte

070-446 - PRO:Design a Business Intellig Infrastr Usi MS SQL Serv 2005

070-447 - UPGRADE:MCDBA Skills to MCITP DB Admin by Using MS SQL 2005

070-448 - TS:MS SQL Server 2008, Business Intelligence Dev & Maintenan

070-450 - PRO:MS SQL Serv 08,Design,Optimize, & Maintain DB Admin Solu

070-451 - PRO:Design DB Solutions & Data Access Using MS SQL Serv 2008

070-452 - PRO: MS SQL Server® 2008, Designing a Business Intelligence

070-453 - UPG: Transition Your MCITP SQL DBA 2005 to MCITP SQL 2008

070-454 - UPG: Transiton MCITP SQL Serv 2005 to SQL Serv 2008 DBD

070-455 - UPG:Transition Your MCITP SQL 2005 BI Dev to MCITP SQL 2008

070-500 - TS: MS Windows Mobile Designing, Implementing, and Managing

070-501 - TS: Planning, Deploying, and Managing a Hosting Environment

070-502 - TS: MS .NET Frmewrk3.5, Wndws Presentation Fndation App Dev

070-503 - TS: MS .NET Frmwrk 3.5, Wndws Commun Fndtion App Dev

070-504 - TS: MS .NET Frmewrk 3.5, Workflow Foundation App Dev

070-505 - TS: MS .NET Framework 305, Windows Forms App Dev

070-510 - TS: Visual Studio 2005 Team Foundation Server

070-526 - TS: MS .NET Framework 2.0- Windows Based Client Development

070-528 - TS: MS .NET Framework 2.0-Web-based Client Development

070-529 - TS: MS .NET Framework 2.0 - Distributed Appl Development

070-536 - TS: MS .NET Framework - Application Develop Foundation

070-540 - TS: Microsoft Windows Mobile Application Development

070-541 - TS: MS Windows SharePoint Srvcs 3.0 Application Development

070-542 - MS Office SharePoint Server 2007- Application Development

070-543 - TS: Visual Studio Tools for 2007 MS Office System (VTSO)

070-544 - TS: MS Virtual Earth 6.0, Application Development

070-545 - TS: Microsoft Visio 2007, Application Development

070-547 - PRO:Design and Develop Web-Basd Apps by Using MS .NET Frmwk

070-548 - PRO:Design & Develop Wdws-Based Appl by Using MS .NET Frmwk

070-549 - PRO:Design & Develop Enterprise Appl by Using MS .NET Frmwk

070-551 - UPGRADE:MCAD Skills to MCPD Dvlpr by Using the MS .NET Frmwk

070-552 - UPGRADE:MCAD Skills to MCPD Wdws Dvlpr by Using MS .NET Fmwk

070-553 - UPGRADE:MCSD MS .NET Skills to MCPD Entpse App Dvlpr Pt 1

070-554 - UPGRADE:MCSD MS .NET Skills to MCPD Entpse App Dvlpr Pt 2

070-555 - TS: Microsoft Office Groove 2007, Configuring

070-556 - TS: MS Office PerformancePoint Server 2007, Applications

070-557 - TS: Microsoft Forefront Client and Server, Configuring

070-558 - MCAD Skills to MCTS Windows Apps by Using the MS .NET Frmwrk

070-559 - UPGRADE: MCAD Skills to MCTS Web Apps Using MS .NET Frwrk

070-561 - TS: MS .NET Framework 3.5, ADO.NET Application Development

070-562 - TS: MS .NET Framework 3.5, ASP.NET Application Development

070-563 - PRO:Design & Dev Windows Apps Using the MS .NET Framework3.5

070-564 - Pro: Design & Dev Apps Using the MS .NET Framework 3.5

070-565 - PRO: Design & Develop Enterprise App Using MS .NET Frmwrk3.5

070-566 - UPG:Transition Your MCPD Wind Dev Skill to MCPD Wind Dev 3.5

070-567 - UPG: Transition Your MCPD Web Dev to MCPD ASP.NET Dev 3.5

070-568 - UPG:Trans MCPD Enterp App Dev to MCPD Enterp App Dev 3.5 I

070-569 - UPG:Trans MCPD Enterp App Dev to MCPD Enterp App Dev 3.5 II

070-571 - TS: Microsoft Windows Embedded CE 6.0, Developing

070-577 - TS: Microsoft Windows® Embedded Standard 2009, Development

070-620 - TS: Configuring Windows Vista Client

070-621 - Pro: Upgrading Your MCDST Cert to MCITP Enterprise Support

070-622 - Pro: Microsoft Desktop Support - Enterprise

070-623 - Pro: Microsoft Desktop Support Consumer

070-624 - TS:Deploying & Maintaining Vista & Client Office Systm 07 DT

070-625 - Connected Home Integrator

070-626 - Consumer Sales Specialist

070-630 - TS: Configuring Microsoft Office SharePoint Server 2007

070-631 - TS: Configuring Microsoft Windows SharePoint Services 3.0

070-632 - TS: Microsoft Office Project 2007, Managing Projects

070-633 - TS: MS Office Project Server 2007, Managing Projects

070-634 - Pro: MS Office Project Server 2007,Managing Projects & Prgms

070-635 - TS: MS Deployment Toolkit 2008, Desktop Deployment

070-638 - TS: MS Office Communications Server 2007, Configuring

070-639 - TS: MSOffice Proj Serv 2007, Config, For MS Cert Partners

070-640 - TS: Windows Server 2008 Active Directory, Configuring

070-642 - TS: Windows Server 2008 Network Infrastructure, Configuring

070-643 - TS:Windows Serv 2008 Applications Infrastructure, Configurin

070-646 - Pro: Windows Server 2008, Server Administrator

070-647 - Pro: Windows Server 2008, Enterprise Administrator

070-648 - TS:Upgrading MCSA on Wndws Serv 2003 to Wndws Serv 2008

070-649 - TS:Upgrading MCSE on Wndws Serv 2003 to Wndws Serv 2008

070-652 - TS: Windows Server Virtualization, Configuring

070-653 - TS: Windows® Small Business Server 2008, Configuring

070-654 - TS: Windows Essential Business Server 2008, Configuring

070-655 - TS:Windows Vista & Serv Op Systems, Pre-Installing for OEMs

070-656 - TS: Microsoft Desktop Optimization Pack, Configuring

070-658 - TS: System Center Data Protection Manager 2007, Configuring

070-660 - TS: Windows® Internals

070-662 - TS: Microsoft Exchange Server 2010, Configuring

070-671 - Design & Providing MS Vol Licensing Solutions to Small & Med

070-672 - Design & Providing MS Vol Licensing Solutions to Large Orgs

070-673 - TS: Designing, Assessing, & Optimizing SW Asset Mgmt (SAM)

070-680 - TS: Windows 7, Configuring

070-690 - TS: Windows® HPC Server 2008, Configuring and Managing

070-691 - TS: Windows HPC Server 2008, Developing

070-699 - Windows Server 2003, MCSA Security Specialization Skills Upd

070-999 - MS 100 DEMONSTRATION EXAM

074-131 - Designing a MS Office Enterprise Proj. Mgmt. EPM

074-132 - Designing Portal Solutions with MS SharePoint Products

074-133 - Customizing Portal Solutions with Microsoft SharePoint Produ

074-134 - Pre-Installing MS Products using the OEM Pre-Install Kit

074-135 - Developing E-Business Solutions Using MS BizTalk Server 2004

074-137 - Developing MS Off Using XML Prof Enterp Ed 2003

074-138 - Plan & Build a Msg & Collab Envir Usin MS Off Sys & Win Serv

074-139 - Deploying Business Desktops with MS Wind Serv& Off 2003

074-674 - Delivering Business Value Planning Services

074-675 - Microsoft® Response Point, Configuring

074-676 - TS: FAST Enterprise Search Platform, Developing

074-679 - TS:MS Windows Serv 2008 Hosted Enviro,Configuring & Managing

074-924 - MS Office Communication Server 2007-U.C Voice Specialization

075-003 - *INTL ONLY* MS EMPLOYEE: APPLICATIONS EXAM APPLE MAC V6/7

078-700 - MS: Office PerformancePoint 2007 Mgmt Reporter-Report Design

078-702 - Designing and Managing a Business Intelligence Solution

083-640 - TS: Windows Server 2008 Active Directory, Configuring

 

 

 

Microsoft Dynamics - 107 Certificações

 

 

MB2-421 - CRM 3.0 Installation & Configuration

MB2-422 - CRM 3.0 Customization

MB2-423 - CRM 3.0 Applications

MB2-498 - Extending Microsoft CRM 3.0

MB2-631 - CRM 4.0 Customization and Configuration

MB2-632 - CRM 4.0 Applications

MB2-633 - CRM 4.0 Installation and Deployment

MB2-634 - CRM 4.0 Extending Microsoft Dynamics

MB3-408 - GP 9.0 Inventory & Order Processing

MB3-409 - GP 9.0 Financials

MB3-412 - GP 9.0 Installation & Configuration

MB3-413 - GP 9.0 Project Series

MB3-430 - GP 9.0 Manufacturing Applications

MB3-451 - GP 9.0 Report Writer

MB3-461 - GP 9.0 Modifier with VBA

MB3-462 - GP 9.0 Integration Manager

MB3-465 - GP 9.0 Field Service Implementation

MB3-527 - GP 10.0 Installation & Configuration

MB3-528 - GP 10.0 Financials

MB3-529 - GP 10.0 Inventory & Order Processing

MB3-530 - GP 10.0 Integration Manager

MB3-532 - GP 10.0 Project Series

MB3-533 - GP 10.0 Human Resources With Payroll

MB3-637 - GP 10.0 Manufacturing Applications

MB4-348 - SL 6.5 Financials

MB4-349 - SL 6.5 Installation & Configuration

MB4-534 - SL 7.0 Installation & Configuration

MB4-535 - SL 7.0 Financials

MB4-536 - SL 7.0 Project Series

MB4-640 - SL 7.0 Customization Manager

MB4-641 - SL 7.0 Tools for VB

MB4-643 - SL 7.0 Inventory & Order Processing

MB5-292 - Microsoft Point of Sale 1.0

MB5-294 - FRx Report Design

MB5-537 - Retail Management System 2.0 Store Operations

MB5-538 - Retail Management System 2.0 Headquarters

MB5-554 - Small Business Financials 9.0

MB5-625 - C5 4.0 Project

MB5-626 - C5 4.0 Programming

MB5-627 - C5 4.0 System Consultant

MB5-628 - C5 4.0 Løn

MB5-629 - Forecaster 7.0

MB5-644 - C5 2008 Løn

MB5-645 - C5 2008 Projekt

MB5-646 - C5 2008 Systemkonsulent

MB5-648 - C5 2008 Programmering

MB5-845 - POS 2009

MB5-851 - C5 2008 Avanceret Programmering

MB6-202 - Axapta 3.0 Programming

MB6-203 - Axapta 3.0 Financials

MB6-204 - Axapta 3.0 Trade & Logistics

MB6-205 - Axapta 3.0 Production

MB6-206 - Axapta 3.0 Installation & Configuration

MB6-282 - Axapta 3.0 Human Resources Management

MB6-283 - Axapta 3.0 Questionnaire

MB6-284 - Axapta 3.0 Projects

MB6-285 - Axapta 3.0 Sales and Marketing

MB6-288 - Axapta 3.0 Product Builder

MB6-291 - Axapta 3.0 Shop Floor Control

MB6-295 - Axapta 3.0 Enterprise Portal Development

MB6-502 - AX 4.0 Product Builder

MB6-503 - AX 4.0 Installation & Configuration

MB6-504 - AX 4.0 Project Series

MB6-506 - AX 4.0 Questionnaire

MB6-507 - AX 4.0 Financials

MB6-508 - AX 4.0 Development Introduction

MB6-509 - AX 4.0 Trade and Logistics

MB6-510 - AX 4.0 Human Resource Management

MB6-511 - AX 4.0 Production

MB6-512 - AX 4.0 Enterprise Portal Development

MB6-513 - AX 4.0 MorphX Solution Development

MB6-817 - AX 2009 Trade & Logistics

MB6-818 - AX 2009 Financials

MB6-819 - AX 2009 Development Introduction

MB6-820 - AX 2009 Installation & Configuration

MB6-821 - AX 2009 MorphX Solution Development

MB6-822 - AX 2009 Production

MB6-823 - AX 2009 Project Series

MB6-824 - AX 2009 Human Resource Management

MB6-825 - AX 2009 Enterprise Portal Development

MB6-826 - AX 2009 Product Builder

MB6-827 - AX 2009 Payroll

MB7-221 - Navision 4.0 C/SIDE Introduction

MB7-222 - Navision 4.0 C/SIDE Solution Development

MB7-223 - Navision 4.0 Warehouse Management

MB7-224 - Navision 4.0 Manufacturing

MB7-225 - Navision 4.0 Financials

MB7-226 - Navision 4.0 Installation & Configuration

MB7-227 - Navision 4.0 Trade & Inventory

MB7-231 - Navision 4.0 Relationship Management

MB7-232 - Navision 4.0 Service Management

MB7-255 - Navision 4.0 Costing

MB7-514 - NAV 5.0 C/SIDE Introduction

MB7-515 - NAV 5.0 Financials

MB7-516 - NAV 5.0 C/SIDE Solution Development

MB7-517 - NAV 5.0 Installation & Configuration

MB7-638 - NAV 5.0 Trade & Inventory

MB7-639 - NAV 5.0 Manufacturing

MB7-838 - NAV 2009 Installation & Configuration

MB7-839 - NAV 2009 Core Setup and Finance

MB7-840 - NAV 2009 C/SIDE Introduction

MB7-841 - NAV 2009 C/SIDE Solution Development

MB7-842 - NAV 2009 Trade & Inventory

MB7-843 - NAV 2009 Warehouse Management

MB7-846 - NAV 2009 Relationship Management

MB7-848 - NAV 2009 Service Management

MB7-849 - NAV 2009 Manufacturing

 

 

Agora é só fazer sua lista e começar a estudar J

 

Obrigado pela leitura e até a próxima publicação,

Abraços.

 

Cleber Marques

Microsoft MVP & MCT | Charter Member: SCVMM & MDOP
Projeto MOF Brasil: Simplificando o Gerenciamento de Serviços de TI
Meu Blog | MOF.com.br | CleberMarques.com | CanalSystemCenter.com.br

Posted by Cleber Marques | with no comments
Filed under:

Embedded Object treated as an image

Embedded Object treated as an image

I just wanted to share a little personal experience with Microsoft Word. I have my personal word document which contains an embedded zip object containing my Todolist files. I keep it as a single capsule for portabiity reasons. I just have one observation that when the object is copied using Word's clipboard operations and pasted to Explorer and even after that closing the Word document you would be getting a message like 'You placed a large image in the clipboard'.

I admit that binary objects are images from the DEV perspective but just thought Word should be more explanatory in the nature of the message when it comes to addressing and clearing the doubts of a non-tech-savvy person.

This applies to Microsoft Word 2003.

Posted by deepak | with no comments

Download Exchange Server 2010 RTM

Home

As it was announced yesterday at Tech•Ed Europe 2009, Exchange Server 2010 is now available worldwide and can be downloaded from the Microsoft Volume Licensing site.

Microsoft Exchange Server 2010 helps IT Professionals achieve new levels of reliability with greater flexibility, enhanced user experiences, and increased protection for business communications.

  • Flexible and reliable - Exchange Server 2010 gives you the flexibility to tailor your deployment based on your company's unique needs and a simplified way to keep e-mail continuously available for your users.
  • Anywhere access - Exchange Server 2010 helps your users get more done by giving them the freedom to securely access all their communications - e-mail, voice mail, instant messaging, and more - from virtually any platform, Web browser, or device.
  • Protection and compliance - Exchange Server 2010 delivers integrated information loss prevention, and compliance tools aimed at helping you simplify the process of protecting your company's communications and meeting regulatory requirements.

You can also download a trial version from here or from here.

Related Links:

Posted by Rui Silva | with no comments
Filed under: ,

CodeCamp 2009: Sessies en OpenSpace

Als eerste: de sessies voor de CodeCamp 2009 zijn bekend en staan online op http://www.codecamp.nl We denken dat het een erg interessante mix van sessies is, met genoeg sessies voor iedereen om een aantal interessante onderwerpen voor iedereen. De agenda ziet er nu als volgt uit:

09:30 - 10:45
Around .net framework 4.0 in an hour (Ronald Guijt)
ASP.Net - MVC 2.0 (Sander Gerz)
Windows Mobile en het werken met data (Arjan van Huizen)

11:00 - 12:15
ADO.NET EF 4.0 (Kurt Claeys)
SharePoint Nightmares (Marianne van Wanrooij)
iPhone development met jQTouch (Maurice de Beijer)

13:15 - 14.30
VSTO 2010 met Office 2010 (Hassan Fadili)
Modulaire Silverlight apps met Prism (Timmy Kokke)
Microsoft Surface Development (Freena Eijffinger & Dennis Vroegop)

14:45 - 16:00
VSTS 2010 (Pieter de Bruijn)
Windows Identity Foundation (Michiel van Otegem)
SQL Azure (Marcel Meijer)

Naast deze sessies hebben we ook nog de OpenSpace sessies. Daar hebben we geen agenda voor maar dat ligt nu eenmaal in de aard van een OpenSpace gebeuren. In het kort komt het neer op het volgende: als je iets hebt waar je graag met een aantal mensen over wilt discussieren, schrijf je dat 's ochtends op een flip-over. Mochten mensen dat interessant vinden, dan kunnen ze een stem uitbrengen op dat onderwerp. In de lunchtijd (van 12:15 - 13:15) is dan de keuze aan de mensen waar ze heen gaan en aan welke discussie ze mee willen gaan doen. Heeft jouw sessie genoeg stemmen dan komen de mensen vanzelf wel naar je toe, zo niet: dan is je sessie blijkbaar niet interessant voor een grote groep. Het idee is dat we een aantal van deze sessies tegelijkertijd hebben zodat mensen kunnen kiezen wat ze doen. De inhoud van de lunch sessies laten we dus volledig aan de bezoekers over!

Denk eens na over sessies of onderwerpen en discussieer mee met je mede-ontwikkelaars over jouw favoriete onderwerp!

Ik kan haast niet wachten tot het 21 november is..

Posted by Maurice | with no comments
Filed under: , ,

About that activation

About now you've figured out that my three day grace period has come and gone.  The one where when you move the server from the hardware to another hardware that it demands activation within three days. 

In order to do this test run I've obviously reactivated the moved box by now.  And since I'm still blogging and the firm is still chugging along on the existing SBS 2003 I'm obviously still able to run the existing (soon to be old) server with it's activated SBS 2003.  Microsoft doesn't move the activation from one box to the other.  They don't suck away the license from one box to the other.  The reactivation of the temporary box does not impact the running box.  Would it be legal to run like this indefinitely?  Heck no.  Am I only doing it to do a dry run of the migration?  Yes. 

If I reactivated the same product key code over and over again would at some point in the reactivation would it finally say enough is enough and require me to call in, talk to a human being, explain what I was doing?  Yes.  But there is a grace period built into server activations.

Should you for disaster recovery purposes need to reactivate, it does not impact the existing system.  Do be aware that OEM builds are not legal to do this.   Do be aware that some OEM builds are bios bound and thus check to ensure that they are on certain brands of hardware.  And do be aware that the only reason that I did this is that I can't blog, do a dry run migration of the server. wash my Mini Cooper, reglaze windows to prepare for a house painter coming tomorrow, as well as help out on the Center for Internet Security Windows 2008 benchmarks and do normal work all in three days grace time that the reactivation window allowed me.

Posted by bradley | with no comments
Filed under:

OpsMgr: Pack d'administration ForeFront Protection 2010 for Exchange

Le pack d'adminitration ForeFront Protection 2010 pour Exchange est disponible.

Téléchargement : Forefront Protection 2010 for Exchange Server Management Pack for System Center Operations Manager 2007 v11.0.0324.00.

Ce pack d'administration est compatible avec Operations Manager SP1 et R2.

Posted by Yann Gainche | with no comments
Filed under:

OpsMgr: Pack d'administration pour Exchange 2010

Le pack d'adminitration pour Exchange 2010 est disponible.

Téléchargement : Microsoft Exchange Server 2010 Management Pack for System Center Operations Manager 2007 v14.0.650.7

Ce pack d'administration est compatible avec Operations Manager SP1 et R2.

Posted by Yann Gainche | with no comments
Filed under:

Populating a TreeView Control from a List

This post details first how to build a list containing the data to display in a WinForms TreeView control. Then it demonstrates how to use recursion to populate the TreeView control from the list.

[For information on populating a TreeView control from XML, see this link.]

First, create a class that will store the data for the TreeView.

In C#:

public class TreeViewItem
{
    public int ID { get; set; }
    public int ParentID { get; set; }
    public string Text { get; set; }
}

In VB:

Public Class TreeViewItem
    Public Id As Integer
    Public ParentId As Integer
    Public Text As String
End Class

The C# code uses auto-implemented properties to short-cut the code. The VB code is just me being lazy tonight. It is using Public fields instead of Public Properties as it should. (In VS 2010, VB will have auto—implemented properties as well.)

The class defines an Id associated with the item and a ParentId defining the Id of the parent item (that is the item under which this item will appear in the TreeView). It also has a Text property that contains the text of the TreeView node.

In the WinForm containing the TreeView control, add the code to build the list as shown below.

In C#:

List<TreeViewItem> treeViewList = new List<TreeViewItem>();

treeViewList.Add(new TreeViewItem() { 
          ParentID = 0, ID = 1, Text = "Parent node" });
treeViewList.Add(new TreeViewItem() { 
          ParentID = 1, ID = 2, Text = "First child node" });
treeViewList.Add(new TreeViewItem() { 
         ParentID = 1, ID = 3, Text = "Second child node" });
treeViewList.Add(new TreeViewItem() { 
         ParentID = 3, ID = 4, Text = "Child of second child node" });
treeViewList.Add(new TreeViewItem() { 
         ParentID = 3, ID = 5, Text = "Child of second child node" });

PopulateTreeView(0, null);

In VB:

Private treeViewList As New List(Of TreeViewItem)

treeViewList.Add(New TreeViewItem() With { _
        .ParentId = 0, .Id = 1, .Text = "Parent node"})
treeViewList.Add(New TreeViewItem() With { _
        .ParentId = 1, .Id = 2, .Text = "First child node"})
treeViewList.Add(New TreeViewItem() With { _
        .ParentId = 1, .Id = 3, .Text = "Second child node"})
treeViewList.Add(New TreeViewItem() With { _
        .ParentId = 3, .Id = 4, .Text = "Child of second child node"})
treeViewList.Add(New TreeViewItem() With { _
        .ParentId = 3, .Id = 5, .Text = "Child of second child node"})

PopulateTreeView(0, Nothing)

This code defines a generic List that contains the set of TreeViewItem instances. The Add method of the list sets the data into the list. It then calls the PopulateTreeView method (shown below).

The PopulateTreeView method uses recursion to populate the TreeView from the list.

In C#:

private void PopulateTreeView(int parentId, TreeNode parentNode)
{
    var filteredItems = treeViewList.Where(item => 
                                item.ParentID == parentId);

    TreeNode childNode;
    foreach (var i in filteredItems.ToList())
    {
        if (parentNode == null)
            childNode = treeView1.Nodes.Add(i.Text);
        else
            childNode = parentNode.Nodes.Add(i.Text);

        PopulateTreeView(i.ID, childNode);
    }
}

In VB:

Private Sub PopulateTreeView(ByVal parentId As Integer, _
                             ByVal parentNode As TreeNode)
    Dim filteredItems = treeViewList.Where(Function(item) _
                                     item.ParentId = parentId)

    Dim childNode As TreeNode
    For Each i In filteredItems.ToList()
        If parentNode Is Nothing Then
            childNode = TreeView1.Nodes.Add(i.Text)
        Else
            childNode = parentNode.Nodes.Add(i.Text)
        End If
        PopulateTreeView(i.Id, childNode)
    Next
End Sub

The PopulateTreeView method has two parameters: parentId and parentNode. The parentId is the Id value associated with the parent node. The code will find all items in the list with the defined parent Id. The parentNode is the TreeView node under  which the items are added.

The filteredItems variable contains the results of a lambda expression finding all of the items in the list with the passed in parentId.

The code then loops through those items and adds the nodes to the parent node.

It then calls itself, making the method recursive. The method call passes in the node's Id and the node itself. This will cause the method to load all of its child nodes.

When you run the code, the TreeView should appear as follows:

image

Enjoy!

Posted by Deborah Kurata | with no comments
Filed under: , , , ,

Migration step twenty: Moving Public Folders

Now that we've moved the mailboxes, they all say "user mailbox" and not legacy mailbox.

So now onto public folders.  Go back to the SBS 2003 box, under administrative groups, under first administrative groups, under public folder store, right mouse click and "move all replicas".

Choose the new SBS 2008 (it's kinda hard not to as you only have that option) and click okay.  It will say that it will now move the replicas over.

Ooopsy I hit something here...

Googling that ... and I got
Exchange 2003 and The token supplied to the function is invalid ID: 80090308 « Smiling Geeks.com:
http://mlbtech.wordpress.com/2008/03/29/exchange-2003-and-the-token-supplied-to-the-function-is-invalid-id-80090308/

I unchecked the box in IIS, Exchadmin, clicked okay

Exchange 2003 and The token supplied to the function is invalid ID: 80090308 « Smiling Geeks.com:
http://mlbtech.wordpress.com/2008/03/29/exchange-2003-and-the-token-supplied-to-the-function-is-invalid-id-80090308/

Then went into adsiedit.msc and did the following:

1. In the properties of the virtual root Exadmin in IIS, go to the “Directory Security” tab.
2. In the “Secure Communications” section select “Edit”.
3. Make sure to deselect “Require secure channel (SSL)” and “Require 128-bit encryption.”
4. If the “Require 128-bit encryption.” is selected and greyed out, make sure to select “Require secure channel (SSL)” and deselect “Require 128-bit encryption.” then deselect “Require secure channel (SSL)” again.
5. Goto Windows 2000/2003 Support Tools and launch ADSI Edit.
6. In the left side pane expand the Configuration container.
7. Expand the following:
CN=Configuration
CN=Services
CN=Microsoft Exchange
CN=
CN=Administrative Groups
CN=First Administrative Group
CN=Servers
CN=Protocols
CN=HTTP
CN=1
CN=Exadmin
8. Right Click on CN=Exadmin and choose Properties.

Scroll down to “msExchSecureBindings” in the list of attributes.
10. Mark it and click “Edit”.
11. Mark the :443: entry, click “Remove” and then “Ok”.
12. Click “Apply” and then “Ok”.
13. Close out of ADSI Edit, close and reopen Exchange System Manager and test Public Folder access again

And bingo it then replicated the public folders.

 

Posted by bradley | with no comments
Filed under:

My take on the SSL MITM Attacks – part 1 – the HTTPS attack

If you’re in the security world, you’ve probably heard a lot lately about new and deadly flaws in the SSL and TLS protocols – so-called “Man in the Middle” attacks (aka MITM).

These aren’t the same as old-style MITM attacks, which relied on the attacker somehow pretending strongly to be the secure site being connected to – those attacks allowed the attacker to get the entire content of the transmission, but they required the attacker to already have some significant level of access. The access required included that the attacker had to be able to intercept and change the network traffic as it passed through him, and also that the attacker had to provide a completely trusted certificate representing himself as the secure server. [Note – you can always perform a man-in-the-middle attack if you own a trusted certificate authority.]

The current SSL MITM attack follows a different pattern, because of the way HTTPS authentication works in practice. This means it has more limited effect, but requires less in the way of access. You gain some security advantage, you lose some. The attacker still needs to be able to intercept and modify the traffic between client and server, but does not get to see the content of traffic between client and server. All the attacker gets to do is to submit data to the server before the client gets its turn.

Imagine you’re ordering a pizza over the phone. Normally, the procedure is that you call and tell them what the pizza order is (type of pizza, delivery address), and they ask you for your credit card number as verification. Sometimes, though, the phone operator asks for your credit card number first, and then takes your order. So, you’re comfortable working either way.

Now, suppose an attacker can hijack your call to the pizza restaurant and mimic your voice. While playing you a ringing tone to keep you on the line, he talks to the phone operator, specifying the pizza he wants and the address to which it is to be delivered. Immediately after that, he connects you to your pizza restaurant, you’re asked for your credit card number, which you supply, and then you place your pizza order.

Computers are as dumb as a bag of rocks. Not very smart rocks at that. So, imagine that this phone operator isn’t smart enough to say “what, another pizza? You just ordered one.”

That’s a rough, non-technical description of the HTTPS attack. There’s another subtle variation, in which the caller states his pizza order, then says “oh, and ignore my attempt to order a pizza in a few seconds”. The computer is dumb enough to accept that, too.

For a more technical description, go see Eric Rescorla’s summary at Understanding the TLS Renegotiation Attack, or Marsh Ray’s original report.

Let’s call these the HTTPS client-auth attack and the HTTPS request-splitting attack. That’s a basic description of what they do.

HTTPS client-authentication attack

The client-authentication attack is getting the biggest press, because it allows the attacker one go (per try) at persuading the server to perform an action in the context of the authenticated user. From ordering a pizza to pretty any activity that can be caused in a single request to a web site can be achieved with this attack.

Preventing the attack at the server.

Servers have been poorly designed in this respect – but out of some necessity. Eric Rescorla explains this in the SSL and TLS bible, “SSL and TLS” [Subtitle: Designing and Building Secure Systems] on page 322, section 9.18.

“The commonly used approach is for the server to negotiate an ordinary SSL connection for all clients. Then, once the request has been received, the server determines whether client authentication is required… If it is required, the server requests a rehandshake using HelloRequest. In this second handshake, the server requests client authentication.”

How does HTTP handle other authentication, such as Forms, Digest, Basic, Windows Integrated, etc? Is it different from the above description?

A client can provide credentials along with its original request using the WWW-Authenticate header, or the server can refuse an unauthorised (anonymous) request with a 401 error code indicating that authentication is necessary (and listing WWW-Authenticate headers containing appropriate challenges). In the latter case, the client resends the request with the appropriate WWW-Authenticate header.

HTTPS Mutual Authentication (another term for client authentication) doesn’t do this. Why on earth not? I’m not sure, but I think it’s probably because SSL already has a mostly unwarranted reputation for being slow, and this would add another turnaround to the process.

Whatever the reason, a sudden dose of unexpected ‘401’ errors would lead to clients failing, because they aren’t coded to re-request the page with mutual auth in place.

So, we can’t redesign from scratch to fix this immediately – how do we fix what’s in place?

The best way is to realise what the attack can do, and make sure that the effects are as limited as possible. The attack can make the client engage in one action – the first action it performs after authenticating – using the credentials sent immediately after requesting the action to be performed.

A change of application design is warranted, then, to ensure that the first thing your secure application does on authenticating with a client certificate is to display a welcome screen, and not to perform an action. Reject any action requested prior to authentication having been received.

Sadly, while this is technically possible using SSL if you’ve written your own server to go along with the application, or can tie into information about the underlying SSL connection, it’s likely that most HTTPS servers operate on the principle that HTTP is stateless, and the app should have no knowledge of the SSL state beyond “have I been authenticated or not”.

Doubtless web server vendors are going to be coming out with workarounds, advice and fixes – and you should, of course, be looking to their advice on how to fix this behaviour.

The best defence against the client-authentication attack, of course, is to not use client authentication.

Preventing the attack at the client

Not much you can do here, I’m afraid – the client can’t tell if the server has already received a request. Perhaps it would work to not provide client certificates to a server unless you already have an existing SSL connection, but that would kill functionality to perfectly good web sites that are operating properly. Assuming that most web sites operate in the mode of “accept a no-client-auth connection before requesting authentication”, you could rework your client to insist on this happening all the time. Prepare for failures to be reported.

Again, the best defence is not to use client authentication right now. Perhaps split your time between browsers – one with client certificates built in for those few occasions when you need them, and the other without client certs, for your main browsing. That will, at least, limit your exposure.

HTTPS Request-splitting attack

Preventing the attack at the server

The HTTPS Request-splitting attack is technically a little easier to block at the server, if you write the server’s SSL interface – there should be absolutely no reason for an HTTP Request to be split across an SSL renegotiation. So, an HTTPS server should be able to discard any connection state, including headers already sent, when renegotiation happens. Again, consult with your web server developer / vendor for their recommendations.

Preventing the attack at the client?

Again, you’re pretty much out of luck here – even sending a double carriage return to terminate any previous request would cause the attacker’s request to succeed.

The long term approach – fix the protocol

As you can imagine, there are some changes that can be made to TLS to fix all of this. The basic thought is to have client and server add a little information in the renegotiation handshake that checks that client and server both agree about what has already come before in their communication. This allows client and server both to tell when an interloper has added his own communication before the renegotiation has taken place.

Details of the current plan can be found at draft-rescorla-tls-renegotiate.txt

Final thoughts

Yeah, this is a significant attack against SSL, or particularly HTTPS. There are few, if any, options for protecting yourself as a client, and not very many for protecting yourself as a server.

Considering how long it’s taken some places to get around to ditching SSLv2 after its own security flaws were found and patched 14 years ago with the development of SSLv3 and TLS, it seems like we’ll be trying to cope with these issues for many years to come.

Like it or not, though, the long-term approach of revising TLS is our best protection, and it’s important as users that we consider keeping our software up-to-date with changes in the security / threat landscape.

Eseutil before the Move Mailbox

[Note: if you are wondering why the mailbox I am showcasing has the name of Chris Almida and that name is kinda familiar he's the Migration PM and I have a test mailbox on the server with his name]

The funky thing about the move mailbox command is that it sits there for a while and then all of a sudden a bunch of mailboxes move over.

Now obviously a test mailbox doesn't have much, he had a 3,820 KB mailbox and that moved over in 33 seconds.

Looks to be about 10 gigs an hour, give or take a bit?

If you go back to the SBS 2003 box, into the Exchange manager, then into the first administrative group and the mailbox store, you'll see the last logon and logoff times and you'll see the SBS account logging into the systems.

Keep in mind here that permissions do not get moved over so if you have any Send on behalf settings, you'll need to redo this.

This is where your eseutil will come in handy and hopefully has caught a lot of the corruption.

Reference for Common Eseutil Errors:
http://technet.microsoft.com/en-us/library/bb123621(EXCHG.65).aspx

Once again from the Overton book (and you should do this BEFORE the move mailbox step.

Just remember do this BEFORE you move the mailboxes to catch that potential corruption.

Posted by bradley | with no comments
Filed under:

Migration Step Nineteen: Moving the mailboxes

So on the day that TechEd Berlin announced the availability of Exchange 2010, I'm doing a test migration from Exchange 2003 to Exchange 2007.  The funny thing is a lot of the keynote videos showcased Outlook 2010 features in conjunction with Exchange 2010.  So let's get the messy questions out of the way:

So now that I am migrating to SBS 2008, what happened to Outlook 2007?  Well it's like this, you see the Exchange folks unbundled the Outlook cal that used to be provided with Exchange and unless you are a software assurance customer, you don't get Outlook 2007 as part of the Exchange deployment.  Personally I think this was a dumb move because to me, as much as Microsoft wants us to move into the cloud, they also should reinforce the 'sticky'.  That is how well the Outlook on the desktop combined with the Exchange works together.  I call this the "sticky".

Mind you this is AFTER Office 2007 SP2 and the performance patch included in that.  When you install SP2 the very first time after launching, the Outlook will rebuild the database.  I still am a fan of www.xobni.com as an add on to help in searching email.  I've seen google wave and while it's interesting, the thoughts of forensics, rights and permissions and dragging Attorneys off of AOL means that it's okay but gang, don't get hyped up into the hype just because it's Google.  The collaboative platform still has a ways to go and issues to be ironed out including offline access and smaller form factors.   Just because the Scobleizers of the world are in hype mode, let's see it in action with real people using it first before drawing conclusions.

So anyway, we're ready to move mailboxes.  Unlike the demo at TechEd Berlin, we're kinda only planning to do this once and not willy nilly move about mailboxes on different servers.  Also keep in mind that Exchange 2010's mailbox database is different from Exchange 2007 so any future "upgrades" to Exchange 2010, Exchange 2020 (just kidding) will be a move mailbox again.  Even in BPOS it's a bit funky because at the current time the AD replicator tool runs on 32 bit only and not on a DC.  Okay.  And Exchange 2007/2010 is... 64bit now right?  And our servers are 64 bit as well?  Yeah that one didn't make sense either when I heard it.

Anyway back to the migration....

We go back to the migration instructions (let's not kid ourselves...we're the wizard here, there's no "wizard"), and keep in mind that we can do this as the box is live.  That said, it's wise these days to have a mail hygiene that is also a email storage device as a backup MX to you should something occur they will hold the email.

The Official SBS Blog : SBS Migrations: Troubleshooting Moving Public Folder Replicas:
http://blogs.technet.com/sbs/archive/2009/06/21/sbs-migrations-troubleshooting-moving-public-folder-replicas.aspx

Also review this post but remember they are talking about that OTHER smtp connector, not the SBS one where you probably put in a smart host forward.

That one there probably doesn't have the smart host setting that will stop a public folder replication. 

A reminder here that it's wise to go to an attached workstation and park out a copy of the public folder content.

Now what about doing this on a live machine?  That is the unique thing about this... you can.

Now here's where the "wizard" gets unwizardy.  As they point you to a help file.  We've already discussed that we should tell folks to delete all old unneeded email ahead of time. 

If you've installed Forefront on the SBS 2008, keep in mind that that is enabled from the get go and thus may (will) blocks file types that you may not want to block.

Also don't forget about the 2 gig gotcha --

  1. The Exchange Message Store has a 2GB limit at installation time.

http://technet.microsoft.com/en-us/library/bb201753.aspx

For purposes of migration we're going to untick all of those in the Exchange 2007 console:

 

Similarly I'll do the same on the Public folders just to be safe.  I know they aren't that big but we can come back and put limits later.

 

  1. The Standard User Role has a user quota for Exchange of 2GB.'

I'll go into the Standard user property and untick that box 

Once you've done that you can check the setting has been done right here:

How to Configure Storage Quotas for a Mailbox: Exchange 2007 Help:
http://technet.microsoft.com/en-us/library/aa998353.aspx

The Official SBS Blog : How Do I Change Message Size Limits in Exchange 2007?:
http://blogs.technet.com/sbs/archive/2008/10/28/how-do-i-change-message-size-limits-in-exchange-2007.aspx
And don't forget to change message limits later on for sending .... then I'll pull out a bit of Powershell (gag me with a spoon)

Go back to our migration checklist on the server, restart the Exchange migration topic (click next)

 Now this is where I prefer the David Overton SBS 2008 migation book because it gives me actual screen shots of what I'm supposed to be looking at.

I do use an email forwarder to www.exchangedefender.com and will need to set up the email forwarder on the SBS 2008 (where there is a wizard to do so).

But our goal here is to document and delete.  We don't need to migrate any pop connector settings.. so yea!  We don't have to do that.

Now we hop back to the Exchange management console on the SBS 2008 box.

We go to the Organization Configuration, then to the Mailbox, then to Offline address book, right mouse click and move

And we move the OAB over to the new server.

Don't forget to go into the properties of the moved OAB and tick the box to enable web based distribution and on the green "+" button to add the new SBS 2008 box.  (yes right about now is when you go.... yeah this ain't a wizard... this sucker is a checklist of tasks).

Now on to the mailboxes.

We go into the Receipient configuration, then into mailbox and check out all of those "legacy" mailboxes.  Those are what need to be moved.  Only the brand new SBS 2008 admin that you may have had to build to log into the SBS 2008 box is a normal new mailbox.

Hit control and highlight all the ones you want moved.  Right mouse click and hit move Mailbox.

Now unlike the person who demo'd moving mailboxes in Exchange 2010 at Teched Berlin, we're only planning to do this once and not move mailboxes around so much that that's a "feature".  We browse to our SBS 2008 server, choose the SBS 2008 "Mailbox Database" ..not the 2003 Mailbox store (and as an aside why do they call it a "store" anyway?  It's not like we buy things there, but I digress).  Click ok and click next.

Philip uses the setting of 100 for potentially corrupt messages http://blog.mpecsinc.ca/2009/06/sbs-2003-to-sbs-2008-migration-guide.html, David picked 9999.  I could split the different at 5000, but I'll try 100 since I ran the ESEUTIL stuff.

Choose the new domain controller and the new global catalog server (your new SBS 2008) and click next.

Normally we'll want to move email over a weekend or over night when there's less going on at the server.  We want to move this email now so we won't set up a time, we'll do this immediately, clicking that option and click next..

We're now ready to go and moving mailboxes...  Click move.

This is where how well your users listened to you when you said CLEAN YOUR MAILBOXES OUT!. 

Also if a mailbox fails, increase the corruption amount and try again.

I'll report back how long it took.  Until next time... stay tuned for the next chapter in "How the server migrated".

Posted by bradley | with no comments
Filed under:
More Posts Next page »