Posts Tagged ‘system’

More Shortcuts for MS Word

   Command Name                  Shortcut Keys
   ------------------------------------------------------------------------

   All Caps                      CTRL+SHIFT+A
   Annotation                    ALT+CTRL+M
   App Maximize                  ALT+F10
   App Restore                   ALT+F5
   Apply Heading1                ALT+CTRL+1
   Apply Heading2                ALT+CTRL+2
   Apply Heading3                ALT+CTRL+3
   Apply List Bullet             CTRL+SHIFT+L
   Auto Format                   ALT+CTRL+K
   Auto Text                     F3 or ALT+CTRL+V
   Bold                          CTRL+B or CTRL+SHIFT+B
   Bookmark                      CTRL+SHIFT+F5
   Browse Next                   CTRL+PAGE DOWN
   Browse Previous               CTRL+PAGE UP
   Browse Sel                    ALT+CTRL+HOME
   Cancel                        ESC
   Center Para                   CTRL+E
   Change Case                   SHIFT+F3
   Char Left                     LEFT
   Char Left Extend              SHIFT+LEFT
   Char Right                    RIGHT
   Char Right Extend             SHIFT+RIGHT
   Clear                         DELETE
   Close or Exit                 ALT+F4
   Close Pane                    ALT+SHIFT+C
   Column Break                  CTRL+SHIFT+ENTER
   Column Select                 CTRL+SHIFT+F8
   Copy                          CTRL+C or CTRL+INSERT
   Copy Format                   CTRL+SHIFT+C
   Copy Text                     SHIFT+F2
   Create Auto Text              ALT+F3
   Customize Add Menu            ALT+CTRL+=
   Customize Keyboard            ALT+CTRL+NUM +
   Customize Remove Menu         ALT+CTRL+-
   Cut                           CTRL+X or SHIFT+DELETE
   Date Field                    ALT+SHIFT+D
   Delete Back Word              CTRL+BACKSPACE
   Delete Word                   CTRL+DELETE
   Dictionary                    ALT+SHIFT+F7
   Do Field Click                ALT+SHIFT+F9
   Doc Close                     CTRL+W or CTRL+F4
   Doc Maximize                  CTRL+F10
   Doc Move                      CTRL+F7
   Doc Restore                   CTRL+F5
   Doc Size                      CTRL+F8
   Doc Split                     ALT+CTRL+S
   Double Underline              CTRL+SHIFT+D
   End of Column                 ALT+PAGE DOWN
   End of Column                 ALT+SHIFT+PAGE DOWN
   End of Doc Extend             CTRL+SHIFT+END
   End of Document               CTRL+END
   End of Line                   END
   End of Line Extend            SHIFT+END
   End of Row                    ALT+END
   End of Row                    ALT+SHIFT+END
   End of Window                 ALT+CTRL+PAGE DOWN
   End of Window Extend          ALT+CTRL+SHIFT+PAGE DOWN
   Endnote Now                   ALT+CTRL+D
   Extend Selection              F8
   Field Chars                   CTRL+F9
   Field Codes                   ALT+F9
   Find                          CTRL+F
   Font                          CTRL+D or CTRL+SHIFT+F
   Font Size Select              CTRL+SHIFT+P
   Footnote Now                  ALT+CTRL+F
   Go Back                       SHIFT+F5 or ALT+CTRL+Z
   Go To                         CTRL+G or F5
   Grow Font                     CTRL+SHIFT+.
   Grow Font One Point           CTRL+]
   Hanging Indent                CTRL+T
   Header Footer Link            ALT+SHIFT+R
   Help                          F1
   Hidden                        CTRL+SHIFT+H
   Hyperlink                     CTRL+K
   Indent                        CTRL+M
   Italic                        CTRL+I or CTRL+SHIFT+I
   Justify Para                  CTRL+J
   Left Para                     CTRL+L
   Line Down                     DOWN
   Line Down Extend              SHIFT+DOWN
   Line Up                       UP
   Line Up Extend                SHIFT+UP
   List Num Field                ALT+CTRL+L
   Lock Fields                   CTRL+3 or CTRL+F11
   Macro                         ALT+F8
   Mail Merge Check              ALT+SHIFT+K
   Mail Merge Edit Data Source   ALT+SHIFT+E
   Mail Merge to Doc             ALT+SHIFT+N
   Mail Merge to Printer         ALT+SHIFT+M
   Mark Citation                 ALT+SHIFT+I
   Mark Index Entry              ALT+SHIFT+X
   Mark Table of Contents Entry  ALT+SHIFT+O
   Menu Mode                     F10
   Merge Field                   ALT+SHIFT+F
   Microsoft Script Editor       ALT+SHIFT+F11
   Microsoft System Info         ALT+CTRL+F1
   Move Text                     F2
   New                           CTRL+N
   Next Cell                     TAB
   Next Field                    F11 or ALT+F1
   Next Misspelling              ALT+F7
   Next Object                   ALT+DOWN
   Next Window                   CTRL+F6 or ALT+F6
   Normal                        ALT+CTRL+N
   Normal Style                  CTRL+SHIFT+N or ALT+SHIFT+CLEAR (NUM 5)
   Open                          CTRL+O or CTRL+F12 or ALT+CTRL+F2
   Open or Close Up Para         CTRL+0
   Other Pane                    F6 or SHIFT+F6
   Outline                       ALT+CTRL+O
   Outline Collapse              ALT+SHIFT+- or ALT+SHIFT+NUM -
   Outline Demote                ALT+SHIFT+RIGHT
   Outline Expand                ALT+SHIFT+=
   Outline Expand                ALT+SHIFT+NUM +
   Outline Move Down             ALT+SHIFT+DOWN
   Outline Move Up               ALT+SHIFT+UP
   Outline Promote               ALT+SHIFT+LEFT
   Outline Show First Line       ALT+SHIFT+L
   Overtype                      INSERT
   Page                          ALT+CTRL+P
   Page Break                    CTRL+ENTER
   Page Down                     PAGE DOWN
   Page Down Extend              SHIFT+PAGE DOWN
   Page Field                    ALT+SHIFT+P
   Page Up                       PAGE UP
   Page Up Extend                SHIFT+PAGE UP
   Para Down                     CTRL+DOWN
   Para Down Extend              CTRL+SHIFT+DOWN
   Para Up                       CTRL+UP
   Para Up Extend                CTRL+SHIFT+UP
   Paste                         CTRL+V or SHIFT+INSERT
   Paste Format                  CTRL+SHIFT+V
   Prev Cell                     SHIFT+TAB
   Prev Field                    SHIFT+F11 or ALT+SHIFT+F1
   Prev Object                   ALT+UP
   Prev Window                   CTRL+SHIFT+F6 or ALT+SHIFT+F6
   Print                         CTRL+P or CTRL+SHIFT+F12
   Print Preview                 CTRL+F2 or ALT+CTRL+I
   Proofing                      F7
   Redo                          ALT+SHIFT+BACKSPACE
   Redo or Repeat                CTRL+Y or F4 or ALT+ENTER
   Repeat Find                   SHIFT+F4 or ALT+CTRL+Y
   Replace                       CTRL+H
   Reset Char                    CTRL+SPACE or CTRL+SHIFT+Z
   Reset Para                    CTRL+Q
   Revision Marks Toggle         CTRL+SHIFT+E
   Right Para                    CTRL+R
   Save                          CTRL+S or SHIFT+F12 or ALT+SHIFT+F2
   Save As                       F12
   Select All                    CTRL+A or CTRL+CLEAR (NUM 5) or CTRL+NUM 5
   Select Table                  ALT+CLEAR (NUM 5)
   Show All                      CTRL+SHIFT+8
   Show All Headings             ALT+SHIFT+A
   Show Heading1                 ALT+SHIFT+1
   Show Heading2                 ALT+SHIFT+2
   Show Heading3                 ALT+SHIFT+3
   Show Heading4                 ALT+SHIFT+4
   Show Heading5                 ALT+SHIFT+5
   Show Heading6                 ALT+SHIFT+6
   Show Heading7                 ALT+SHIFT+7
   Show Heading8                 ALT+SHIFT+8
   Show Heading9                 ALT+SHIFT+9
   Shrink Font                   CTRL+SHIFT+,
   Shrink Font One Point         CTRL+[
   Small Caps                    CTRL+SHIFT+K
   Space Para1                   CTRL+1
   Space Para15                  CTRL+5
   Space Para2                   CTRL+2
   Spike                         CTRL+SHIFT+F3 or CTRL+F3
   Start of Column               ALT+PAGE UP
   Start of Column               ALT+SHIFT+PAGE UP
   Start of Doc Extend           CTRL+SHIFT+HOME
   Start of Document             CTRL+HOME
   Start of Line                 HOME
   Start of Line Extend          SHIFT+HOME
   Start of Row                  ALT+HOME
   Start of Row                  ALT+SHIFT+HOME
   Start of Window               ALT+CTRL+PAGE UP
   Start of Window Extend        ALT+CTRL+SHIFT+PAGE UP
   Style                         CTRL+SHIFT+S
   Subscript                     CTRL+=
   Superscript                   CTRL+SHIFT+=
   Symbol Font                   CTRL+SHIFT+Q
   Thesaurus                     SHIFT+F7
   Time Field                    ALT+SHIFT+T
   Toggle Field Display          SHIFT+F9
   Toggle Master Subdocs         CTRL+\
   Tool                          SHIFT+F1
   Un Hang                       CTRL+SHIFT+T
   Un Indent                     CTRL+SHIFT+M
   Underline                     CTRL+U or CTRL+SHIFT+U
   Undo                          CTRL+Z or ALT+BACKSPACE
   Unlink Fields                 CTRL+6 or CTRL+SHIFT+F9
   Unlock Fields                 CTRL+4 or CTRL+SHIFT+F11
   Update Auto Format            ALT+CTRL+U
   Update Fields                 F9 or ALT+SHIFT+U
   Update Source                 CTRL+SHIFT+F7
   VBCode                        ALT+F11
   Web Go Back                   ALT+LEFT
   Web Go Forward                ALT+RIGHT
   Word Left                     CTRL+LEFT
   Word Left Extend              CTRL+SHIFT+LEFT
   Word Right                    CTRL+RIGHT
   Word Right Extend             CTRL+SHIFT+RIGHT
   Word Underline                CTRL+SHIFT+W

Be the first to comment - What do you think?  Posted by Diego - October 6, 2009 at 10:39 am

Categories: Advice   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Clampi Virus targets online banking

In the modern world, most peo­ple never see their bank (with the excep­tion of ATM with­dra­wals).  We use bill pay, direct depo­sit and bank debit cards.  This is the exact beha­vior that the Clampi virus is living on.

Clampi is a very stealthy virus, just biding it’s time on a com­pro­mi­sed machine and watching for con­nec­tions to online finan­cial web­si­tes.  So many so that the Lon­don Times Online reports:

The tro­jan has a list of more than 4,500 finance-related web­si­tes that it moni­tors, inc­lu­ding Bri­tish high street banks. Secu­rity experts war­ned that it was one of the stealthiest and most per­va­sive threats to com­pu­ters using the Mic­ro­soft Win­dows ope­ra­ting systems.

The virus appears to be gea­red with more of the busi­ness users ins­tead of the nor­mal home user (though it does infect home users).  If the virus does end on a work com­pu­ter, it will attempt to cap­ture login cre­den­tials admi­nis­tra­tors and spread itself through the net­work.  As it spreads, it con­ti­nually moni­tors for login infor­ma­tion to the watch list of finan­cial web­si­tes.  If this virus does infect the finance group of a com­pany, it will attempt to send wire trans­fers from that account.  You can ask Slack Auto Parts.  It has been repor­ted that they lost $75,000 July 3–7, says owner Henry Slack. Clampi-infected com­pu­ters sent nine pay­ments to six dif­fe­rent mules � and fai­led to trans­fer an addi­tio­nal $69,000 in eight other attempts.

A word of war­ning, if your com­pu­ter is desig­na­ted for finan­cial usage, please do not surf the inter­net or use social media sites to mini­mize the risk of infections.

Since this virus has been out for a while, all the major anti­vi­rus ven­dors have upda­ted defi­ni­tion files that inc­lude the scan for this par­ti­cu­lar virus.  Make sure your sys­tem is always upda­ted and scan­ned on a regu­lar basis.  If you would like to run a quick check, using a dif­fe­rent ven­dor, I recom­mend these online scanners:

Trend­Micro: http://housecall65.trendmicro.com/
Syman­tec: http://security.symantec.com/sscv6/WelcomePage.asp
McA­fee: http://home.mcafee.com/downloads/freescan.aspx?cid=60447
Panda: http://www.pandasecurity.com/activescan/index/

Be the first to comment - What do you think?  Posted by Diego - September 21, 2009 at 8:54 am

Categories: Malware   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Must Have Application for Thumb Drives

It’s a sign of the time, you can buy a thumb drive almost anywhere.  I have even seen them in Gas Sta­tions in the Omaha area.

There are many rea­sons to use these dri­ves: size, por­ta­bi­lity con­ve­nience, and sto­rage space, all come to mind quickly.  A lot of my exter­nal users do not even take their lap­tops to mee­tings any­more because they can keep all their pre­sen­ta­tions and such on a thumb drive and just plug into any machines.

On the other side of the coin, there are some inhe­rent risks to the trans­por­ta­tion of these devi­ces.  You may for­get them on site, lose them while get­ting something from your poc­ket, so on and so forth.  No mat­ter the rea­son, if you lose your drive, all of that data is now avai­la­ble to the per­son that finds it.

Here are some exam­ples of the type of data that can be lost by anyone:

Firm ‘broke rules’ over data loss

Home Sec­re­tary Jac­qui Smith has bla­med a pri­vate con­trac­tor for losing the details of thou­sands of cri­mi­nals, held on a com­pu­ter memory stick.

Tax web­site shut down as memory stick with sec­ret per­so­nal data of 12million is found in a pub car park

Minis­ters have been for­ced to order an emer­gency shut­down of a key Govern­ment com­pu­ter sys­tem to pro­tect millions of people’s pri­vate details.

The action was taken after a memory stick was found in a pub car park con­tai­ning con­fi­den­tial pass­co­des to the online Govern­ment Gate­way sys­tem, which covers everything from tax returns to par­king tickets.

Two exam­ples may not seem like a large amount, but if you look at the amount of data that was lost in these two exam­ples you will rea­lize how much data is at stake.

With that being said, I have found a free appli­ca­tion that will help with this.  Rohos Mini Drive Encryp­tion.  This app has a very small foot­print and once your drive is setup, you don’t have to ins­tall soft­ware on any other com­pu­ter to access that encryp­ted file.

Accor­ding to the deve­lo­pers web­site they list the fea­tu­res as:

  • Crea­tes a vir­tual encryp­ted par­ti­tion volume (disk) within a USB flash drive free space
  • Auto­ma­ti­cally detects your USB stick con­fig and crea­tes encryp­ted partition
  • Pro­gram does not require ins­ta­lla­tion to work with encryp­ted par­ti­ton on a guest com­pu­ter. You can start it right from USB drive
  • Encryp­ted par­ti­tion is pro­tec­ted by password
  • Encryp­tion is auto­ma­tic and on-the-fly
  • Encryp­tion algo­rithm: AES 256 bit key length. NIST approved.
  • Rohos Disk Brow­ser to open encryp­ted par­ti­tion without having Admin rights
  • Vir­tual Key­board — to pro­tect your encryp­ted disk pass­word from a key logger
  • Auto­run Fol­der. Saved program’s/file’s short­cut will auto­ma­ti­cally start/open up upon disk connection
  • The limit of encryp­ted par­ti­tion size is 2 GB

I find the soft­ware very easy to use and intui­tive.  In no time, I had car­ved 500 megs on one of my dri­ves and was moving files over to the encryp­ted por­tion.  To try out the func­tio­na­lity I han­ded the disk to my co-worker and watched as they put it in and sure enough none of the data sho­wed.  Just an exe­cu­ta­ble.  When run, the pass­word cha­llenge screen comes up.  I really do like the idea of a vir­tual key­board, par­ti­cu­larly if you are on a com­pu­ter that you do not know.  Bet­ter safe then sorry in this world.  Once the correct pass­word is ente­red and accep­ted an explo­rer win­dow is ope­ned and all your files are acces­si­ble.  It did take a few moments for me to see how to add new files to the encryp­ted volume.  Just so you know, in the explo­rer win­dow you can right click and import file.

As I said before, in this world, encrypt everything.  I highly recom­mend this pro­gram to anyone with a thumb drive.

Be the first to comment - What do you think?  Posted by Diego - September 18, 2009 at 8:52 am

Categories: SW   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

The System Administrator from Hell

Some days I get emails that just have to be sha­red.  This is one of them.  All cre­dit to the ori­gi­nal author, though I don’t know who it is.

Recently someone called me from one of the “Out on the Floor Offi­ces”, an ethe­real place rumo­red to exist only in hypers­pace, popu­la­ted by mys­te­rious beings called Users.

She was quite fran­tic. She was having trou­ble run­ning a pro­gram through the com­pu­ter, and her mes­sage was clear enough, although rather ill-conceived: “My files are full!

I furro­wed my brow, lit a smoke, and explai­ned to her, “Really now, Miss Rus­sell, I don’t have time for this.” I slowly exha­led the menthol vapors as I stop­ped her pro­cess, crushing any hopes she may have had of ever again seeing that docu­ment she had spent three hours sla­ving over.

“I was typing this really impor­tant let­ter, and it has to be ready in an hour… there’s all this stuff on my screen that I didn’t type… it says something about an error, should I read it to you?”

“No point. Just press return.”

“Oh my, it wants my user­name. Can I res­tart that where I left off?”

“Not a chance.”

I drew another puff and tos­sed the phone aside. It occu­rred to me that if I had to hear one more of those whi­ning com­plaint ses­sions, heads were going to roll. Where do you peo­ple get this stuff? I’m going to tell you what’s really going on here. Now lis­ten up. I’m not going over this a second time:

Com­pu­ter
The black box that does your work for you. That’s all you need to know.

Res­ponse Time
Usually mea­su­red in nano­se­conds; some­ti­mes mea­su­red in calen­dar months. The gene­ral rule is: Shut up your com­plai­ning about res­ponse time.

Hard­ware
See “Com­pu­ter.” Again, not your concern.

Soft­ware
If we want you to know, we’ll tell you about it, other­wise, leave us alone.

Net­work
Don’t worry about it, we’ll take care of it. Use it to send mail among your half-wit sel­ves, and don’t think we won’t read it all. What do you think we do all day? By the way , Rus­sell… shame about your mother’s Pancreas.

Data
The gene­ral rule is: Don’t use any data files and if you find any, delete them before I find out about them. In fact, just stay off the com­pu­ter. (See “Res­ponse Time”)

Sys­tem Crash
Don’t ever call the sys­tem mana­ger to tell him you think the com­pu­ter is down. Don’t call him to ask him when it will be up again. The more you bother him, the lon­ger it takes.

Down­time
Like I said, don’t ask.

Uptime
Be thank­ful for it, use it wisely, and get out of my face.

Over­time
Don’t be ridiculous.

Vaca­tion
A time during which I don’t have to put up with your sni­ve­ling. Don’t try calling. There’s no point.

Com­pu­ter Room
Keep out, you’re not invi­ted. Don’t knock on the door — don’t even think about it. I broke the phone last time one of you jerks called me, and I’m not about to replace it. And keep your greasy fin­gers off the windows.

My Office
The name says it all… it’s mine; stay out.

Your Pro­blems
The name says it all…

Dead­li­nes
The gene­ral rule is: Dead­li­nes are not ack­now­led­ged by me; they’re not my res­pon­si­bi­lity. Go tell someone who cares.

Main­te­nance
  1. A valid rea­son for shut­ting down the sys­tem at any time.
  2. Much more impor­tant than anything any of you bozos do.
  3. Anything I choose to call “main­te­nance” is maintenance.
Soft­ware Upgrades
Far too com­plex for you to com­prehend. If I tell you I’m upgra­ding the sys­tem, just be quietly thank­ful. It’s for your own good, even if it does mean exten­sive down­time during peak hours.

Elec­tro­nic Mail
I delete it before it’s read, so don’t bother sen­ding any to me.

Defaults
We like them just like they are; we chose them for a rea­son. Don’t mess with them; con­si­der them mandatory.

Error Mes­sa­ges
I’m not inte­res­ted. I’m going to kill your pro­cess any­way, so keep them to yourself.

Killing your Process
  1. Don’t ever ask why
  2. Beyond your control
  3. No war­nings are given
  4. The high­light of my day
  5. If you call, it’s going to hap­pen. No exceptions.
Pass­words
I reserve the right to change them without notice at any time. I choose them, and the more you bother me, the more degra­ding yours will be. (Exam­ple: jrus­sell: SNOTFACE)

Users
  1. They slow down the computer
  2. They waste my time
  3. A gene­ral nuisance
  4. Worse than that, actually
Soft­ware Modifications
You don’t know what you want — we’ll tell you what you want. It stays like it is. Period.

Pri­vi­le­ges
I’ve got them, you don’t need them. Enough said.

Prio­rity
Mine is higher than yours, accept it. That’s the rea­son my games run fas­ter than your lousy accoun­ting pac­kage. (See “Res­ponse Time”)

Ter­mi­nals
Before calling me with a ter­mi­nal pro­blem, con­si­der this:

  1. Are you pre­pa­red to do without one for weeks?
  2. Do you REALLY want your pro­cess killed?
  3. Did you just trip over the cord again?
  4. Of course you did.
Disk Space
I set the quo­tas, you live with them. If you need more space, check “Data Files”.

Ope­ra­tor
I hired him and I trai­ned him. He does what I tell him to. Usually armed; always dangerous.

Bac­kups
A good idea if I gave a shit, which of course I don’t.

Lunch
The only time that calling my office won’t result in the killing of your process.

Data Secu­rity
That’s your pro­blem. I’m cer­tainly not going to lose any sleep over it. My files are loc­ked up tight. I feel secure.

Jiffy
Length of time it takes me to resolve your pro­blem by killing your process.

Eter­nity
Length of time it takes me to give a shit about any pro­blem that can’t be resol­ved by killing your process.

Impos­si­ble
  1. It can’t be done (as far as you know)
  2. I can’t be bothered
  3. You’re star­ting to annoy me
Ine­vi­ta­ble
  1. Couldn’t have been avoided
  2. Not my fault (as far as you know)
  3. The result of anno­ying me
Menus
If it’s not on the menu, don’t ask for it. It’s not avai­la­ble. If it is on the menu, it’s pro­bably of no use or it doesn’t work. We’re wor­king on it (See “Eternity”).

Uti­li­ties
I find them quite use­ful, you’ll find them quite inac­ces­si­ble. Besi­des, they’re not on your menu, are they. What did I tell you about that?

Nui­sance
You.

Of course, I reserve the right to add, change, or remove anything from the above list. I’m not asking you to accept these mat­ters without ques­tion, I’m telling you.

Now that we all know where we stand, I’m sure there’ll be no future pro­blems. If you have any ques­tions or com­ments please feel free to keep them to your­self. If you feel the need for more infor­ma­tion, I highly recom­mend that you ask someone else.

Sin­ce­rely,
The Sys­tem Manager

P.S. The new disk quota of 30 blocks per user became effec­tive yes­ter­day. Anyone caught excee­ding the quota will lose their accounts (this means you, Russell!)

Be the first to comment - What do you think?  Posted by Diego - September 10, 2009 at 10:06 am

Categories: Humor   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

What’s old is new again

Yes­ter­day, Mic­ro­soft put out an advi­sory to a secu­rity vul­ne­ra­bi­lity spe­ci­fic to the Win­dows Vista, Win­dows Ser­ver 2008 SP2, and Win­dows 7 RC ope­ra­ting sys­tems.  No other Win­dows ope­ra­ting sys­tems, inc­lu­ding Win­dows 7 RTM are impacted.

Holy cow, once again the older sys­tems (you go XP) are more secure then the new sys­tems.  Why is that you say?  Well this exploit was first found a decade ago.  Yes, you did read that correct, in 1999 this was dis­co­ve­red and patched for the ope­ra­ting sys­tems at the time.  Yet no one thought to put that into the: Newest, Most Secure, Latest and Grea­test ope­ra­ting systems.

So what is this vulnerability?

Accor­ding to Microsoft:

What might an attac­ker use this vul­ne­ra­bi­lity to do?
An attac­ker who suc­cess­fully exploi­ted this vul­ne­ra­bi­lity could take com­plete con­trol of an affec­ted sys­tem. Most attempts to exploit this vul­ne­ra­bi­lity will cause an affec­ted sys­tem to stop res­pon­ding and restart.

I like the last four words, “stop res­pon­ding and res­tart”.  We had an acronym for that back in the day.  BSOD.  But out of all of this, the thing that bothers me the most is Microsoft’s response:

Mic­ro­soft is con­cer­ned that this new report of a vul­ne­ra­bi­lity was not res­pon­sibly disc­lo­sed, poten­tially put­ting com­pu­ter users at risk. We con­ti­nue to encou­rage res­pon­si­ble disc­lo­sure of vul­ne­ra­bi­li­ties. We believe the com­monly accep­ted prac­tice of repor­ting vul­ne­ra­bi­li­ties directly to a ven­dor ser­ves everyone’s best inte­rests. This prac­tice helps to ensure that cus­to­mers receive com­prehen­sive, high-quality upda­tes for secu­rity vul­ne­ra­bi­li­ties without expo­sure to mali­cious attac­kers while the update is being developed.

Mic­ro­soft is con­cer­ned that this new report of a vul­ne­ra­bi­lity was not res­pon­sibly disc­lo­sed? Excuse me what?  It’s not new, it was disc­lo­sed pro­perly the first time.  Why do others become res­pon­si­ble for your oversight?

With that said Mic­ro­soft has issued two do it your­self reso­lu­tions until they can get a patch pushed.

The first is to Disa­ble SMB2 in the registry:

Impact of wor­ka­round. Host will not be able to com­mu­ni­cate using SMB2.

  1. Click Start, click Run, type Rege­dit in the Open box, and then click OK.
  2. Locate and then click the follo­wing registry sub­key:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
  3. Click Lan­man­Ser­ver.
  4. Click Para­me­ters.
  5. Right-click to add a new DWORD (32 bit) Value.
  6. Enter smb2 in the Name data field, and change the Value data field to 0.
  7. Exit.
  8. Res­tart the “Ser­ver” ser­vice by per­for­ming one of the following:
    • Open up the com­pu­ter mana­ge­ment MMC, navi­gate to Ser­vi­ces and Appli­ca­tions, click Ser­vi­ces, right-click the Ser­ver ser­vice name and click Res­tart. Ans­wer Yes in the pop-up menu.
    • From a com­mand prompt and with admi­nis­tra­tor pri­vi­le­ges, type net stop ser­ver and then net start ser­ver.

The second is to Block TCP ports 139 and 445 at the firewall:

Impact of Wor­ka­round: Seve­ral Win­dows ser­vi­ces use the affec­ted ports. Bloc­king con­nec­ti­vity to the ports may cause various appli­ca­tions or ser­vi­ces to not func­tion. Some of the appli­ca­tions or ser­vi­ces that could be impac­ted are lis­ted below:

  • Appli­ca­tions that use SMB (CIFS)
  • Appli­ca­tions that use mails­lots or named pipes (RPC over SMB)
  • Ser­ver (File and Print Sharing)
  • Group Policy
  • Net Logon
  • Dis­tri­bu­ted File Sys­tem (DFS)
  • Ter­mi­nal Ser­ver Licensing
  • Print Spoo­ler
  • Com­pu­ter Browser
  • Remote Pro­ce­dure Call Locator
  • Fax Ser­vice
  • Inde­xing Service
  • Per­for­mance Logs and Alerts
  • Sys­tems Mana­ge­ment Server
  • License Log­ging Service

Per­so­nally, I would block those on your inter­net facing fire­wall of you broad­band router.

1 comment - What do you think?  Posted by Diego - at 8:43 am

Categories: Windows   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Find drivers for unknown devices

Have you ever been given a com­pu­ter, or bought an old fixer upper PC that didn’t have all the discs or infor­ma­tion for the components?

I know this is frus­tra­ting since I too have had this pro­blem.  Espe­cially when it invol­ves key equip­ment (Net­work card).  There is nothing more irri­ta­ting then loo­king at your device list and seeing the yellow ques­tion mark.  Well tech­ni­cians, as with almost everything com­pu­ter rela­ted, there is a site setup to help with this.  PCIDatabase.com

So how does this work?

You will want to go to the ques­tion mark in the device mana­ger and right click on the entry (there maybe more then one on a rei­mage or a cus­tom built machine).  For those that may not be fami­liar on how to get to the device mana­ger here are some sim­ple steps.  Find the My Com­pu­ter icon on your desk­top (upper left by default).  You will want to Right click on the icon and you will get a menu like this:
Properties Menu

After you left click on the pro­per­ties entry a new win­dow will pop up:
SystemProperties If you do not have the tab shown, you will want to click on the Hard­ware tab.  Once here, click on the device mana­ger and you will see a list of ins­ta­lled devi­ces.  You will scroll down for the yellow ques­tion mark.  In my exam­ple there are none, but I am sure you will find them rather quickly.

Read more…

1 comment - What do you think?  Posted by Diego - July 6, 2009 at 9:05 am

Categories: Internet   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

New Computer Security Mistakes

I wan­ted to pass on what I see as some of the top com­pu­ter secu­rity mis­ta­kes that most casual com­pu­ters users make when first set­ting up a new computer:

  1. Set­ting an non pro­tec­ted newly ima­ged com­pu­ter on the inter­net.  Before ins­ta­lling any com­pu­ter on the inter­net, you will want to ins­tall at least an anti­vi­rus and make sure that the built in fire­wall for Win­dows is ope­ned.  I per­so­nally have a DVD with a lot of first ins­tall appli­ca­tions on it.  This inc­lu­des Comodo Anti­vi­rus, Comodo Fire­wall, Win­dows XP Ser­vice Pack 3 (Net­work Admin Ins­ta­ller), and Vista Ser­vice Pack 2 (Net­work Admin Ins­ta­ller).  As well as a few other odds and ends.  I run these ins­talls before I ever con­nect my machine to the wire­less net­work.  I know the virus defi­ni­tion files for the Anti­vi­rus will be out­da­ted, but that is correc­ted shortly.
  2. Not run­ning upda­tes as soon as online. After ins­ta­lling all the appli­ca­tions men­tio­ned above, I get my sys­tem on the net­work and run upda­tes on my anti­vi­rus soft­ware and then run­ning the Win­dows Update.  This is a very impor­tant step.  Just because an anti­vi­rus is ins­ta­lled or the latest Ser­vice Pack applied, it does not mean you are pro­tec­ted.  With more and more vul­ne­ra­bi­li­ties and viru­ses being relea­sed daily, it is a never ending battle to keep your­self pro­tec­ted.  Not only should you worry about the secu­rity soft­ware, but any appli­ca­tion you ins­tall, please run all the updates.
  3. Set­ting your pri­mary login ID as an admi­nis­tra­tor.  I know this one is hard, but it has been brought to my atten­tion, and right­fully so, it is not recom­men­ded.  An admi­nis­tra­tor account has unli­mi­ted rights and power on a com­pu­ter.  You can create a sepa­rate user and make is a power user.  For the Admi­nis­tra­tor account, you should rename it from Admi­nis­tra­tor and put a secure pass­word on it.  Also, disa­ble the guest account on your sys­tem for safety measures.

  1. Pass­word, Pass­word, Pass­word, and did I men­tion pass­word?  I know this is your home com­pu­ter and you won­der who would get into it.  Well, since the com­pu­ter has become so inte­gra­ted in our lives, we store everything on there.  From bank infor­ma­tion, impor­tant docu­ments, Tax infor­ma­tion, fami­lies infor­ma­tion, on and on.  If your com­pu­ter gets sto­len, someone else now has all of that infor­ma­tion.  If you do not have a secure pass­word (see ear­lier pos­ting) then it’s easy for them to get in.
  2. Disk Encryp­tion.This is a topic I will dis­cuss more in depth in the next few days.  There are many free drive encryp­tion appli­ca­tions avai­la­ble that are very very good.  The rea­son for this encryp­tion is so that if someone comes in and just grabs your drive out of your com­pu­ter (less then 3 minu­tes for the most part) your data is secu­red.  See item 4.
  3. Wire­less Net­work Secu­rity. Again another topic I will get into later, but for the most part I can sum it up quickly.  If you get a brand new wire­less rou­ter, the defaults are the same.  The same IP address, the same root pass­word, the same SSID (Net­work name).  With this infor­ma­tion anyone in your area can get into your net­work.  There are some things you can do to pro­tect your­self and I plan on dis­cus­sing it later, inc­lu­ding what some recom­men­ded set­tings are.  So please check back.

I hope that you found this use­ful infor­ma­tion.  Ques­tions, com­ments and feed­back is always welcome.

5 comments - What do you think?  Posted by Diego - July 3, 2009 at 9:36 am

Categories: General   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Online Backup

A few days ago, I dis­cus­sed a bac­kup tool named Cobian and I pro­mi­sed to look into online space for off­site storage.

While loo­king around a I found quite a few, but focu­sed on three.  I will go over some of my ini­tial impres­sions, and direct links to the site (so the FTC doesn’t chase me down for get­ting something for giving my opinion).

The three I will be tal­king about are iDrive.com, Mozy.com, and Humyo.com.  Now the first thing that’s impor­tant to ever­yone is, how much space do I get.  iDrive and Mozy both have 2 gigs for free, but this link (I pro­mise I get nothing) will get you a 250 MB upgrade on Mozy.  Humyo might as well be called Humon­gous giving you a whop­ping 10 GB online sto­rage.  Now this is all FREE.

Of course, if you find you are run­ning out of space, you can pay for upgra­des.  For $4.95 a month you get expand to 150 GB on iDrive, Mozy gets to be a bit more expen­sive, using the pay as you go model at $3.95 a month per 500 MB.  My opi­nion on that is if you are paying that, pay for hos­ting.  In the odd case that you will need more then 10 GB for bac­king up your most cri­ti­cal data on Humyo it will run you $6.99 a month to get 100 GB.

So besi­des space, I am sure there are pro­bably other things to con­si­der.  Let me think…

How do I get my data from my com­pu­ter to my sto­rage place.  Well all three have a client that you can ins­tall on your com­pu­ter.  Though Humyo requi­res you have a paid account to use the client.  It does, howe­ver, have a web con­sole you can drag and drop into a java upload client.

The clients are nice and small, quick easy down­loads, so I won’t get into that.  Some of the things that I noti­ced on the client.

For the Mozy client, it auto­ma­ti­cally gives you a recom­men­ded bac­kup set, inc­lu­ding Thun­der­bird data.  Since I use Thun­der­bird, that is handy to have.  It also gives you two options of data encryp­tion.  If you push have VoIP pho­nes, or band­width issues in gene­ral, you can throttle the appli­ca­tion as well as sche­dule your bac­kups for slow net­work times.

iDri­ves’ client is not as fully fea­tu­red (at least not to the naked eye).  The ini­tial bac­kup set is your docu­ments and set­tings fol­der.  With some dig­ging around you can setup band­width thrott­ling also.  But it does have a synch option (quick delete if you erase a fol­der and want it pulled out of your bac­kup) and con­ti­nuous bac­kup.  Though I am not sure how often it checks.

Since you have to have a paid account for the Humyo client, I will not review it.

Ok.  We have now bac­ked up all the data and sure enough, we have to refor­mat or our machine, boooo.  Or we just got a new com­pu­ter and we want to get our docu­ments back, yeah!

How do we get it back.  Of course for both iDrive and Mozy you can use the client and res­tore. But… I want more.  It’s free, I want it all.

For Mozy you have a two options: You can use a vir­tual drive (crea­ted when the client is ins­ta­lled) and drag and drop or pay for a DVD to be crea­ted and FedEx to deli­ver the disk.

With iDrive, you can go to the site and login.  Going into the res­tore area you can use a Java applet to down­load your files.  Or you can get a second down­load to create a vir­tual drive and go through your Win­dows Explorer.

Well Folks.  I hope that helps a bit.  Remem­ber, bac­kups are important…Before the sys­tem crashes.

2 comments - What do you think?  Posted by Diego - June 23, 2009 at 5:11 pm

Categories: Internet   Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Top 10 Phishing Scams as of 05/29/2009

By now, ever­yone with an email address has recei­ved those phishing emails.  You know the ones I mean, your Pay­Pal account will be disa­bled if you don’t login by such and such a date.  I have found the follo­wing list of the top 10 Phishing Scams.

Top 10 Phishing Scams

If you receive a simi­lar mes­sage in your inbox you should delete it and not follow the links in the mes­sage. If you want to check your account, you should type the bank or com­pany web­site directly into your web brow­ser, or add a book­mark, rather than follo­wing links in an email. If you are unsure if an email you receive is legi­ti­mate, visit the com­pa­nies web­site directly, phone the com­pany, or con­tact their Cus­to­mer Ser­vi­ces or fraud depart­ment (usually fra@companyname.com) to con­firm that they sent the mail.

Upda­ted Last: May 29, 2009

1. Amazon.com — Limi­ted Account Access Details
2. Noti­fi­ca­tion
3. Com­mon­wealth Bank Sur­vey 2009
4. noti­fi­ca­tion
5. Secu­rity Alert
6. Pay­pal Mem­ber Noti­fi­ca­tion
7. Impor­tant alert [mes­sage id: ]
8. Dear Pay­pal Mem­ber
9. Check out the latest items from your favo­rite sellers on eBay
10. Bank Of Ame­rica Alert: We have tem­po­ra­rily pre­ven­ted online access to your account

Read more…

1 comment - What do you think?  Posted by Diego - June 1, 2009 at 2:39 pm

Categories: Phishing   Tags: , , , , , , , , , , , , , , , , , , , ,

99 ways to make your computer blazingly fast

Have you noti­ced a defi­nite drop off in your com­pu­ter per­for­mance since you brought it home? Does it seem to take the same length of time to boot up as your an oil change on your car?

Don’t think that you have to take dras­tic mea­su­res to get your sys­tem run­ning much bet­ter. Like you cars, your PC needs a tune up from time to time.

To guide you through these tuneups a fellow help­desk per­son has com­pi­led a list of 99 tools and tricks IT peo­ple per­form on their own machi­nes. You may not need to do all 99 steps, but they are there for you to try.

Read: Help­desk Geek, 99 ways to make your com­pu­ter bla­zingly fast.

Be the first to comment - What do you think?  Posted by Diego - May 24, 2009 at 8:03 am

Categories: General   Tags: , , , , , , , , , , , , , ,

9 visitors online now
9 guests, 0 members
Max visitors today: 9 at 01:28 am CST
This month: 16 at 03-05-2010 08:37 am CST
This year: 19 at 02-08-2010 05:10 am CST
All time: 21 at 12-18-2009 02:01 am CST