Archive

Archive for the ‘Security’ Category

Delete IE7 Temporary Internet Files, Cookies, Browsing History, Form Data and Passwords From the Command Line.

February 17th, 2009 Asaf Nakash 3 comments

If you like to build batch files to automate cleanup on your computer, you’ll probably want to include at least one of these commands in your batch script. You can automate any one of the functions on the Internet Explorer 7 Delete Browsing History dialog.

Here’s the dialog that you are probably used to seeing:

And here’s the commands that correspond to the different buttons. The most important one from a cleanup perspective is the first, which will delete just the temporary internet files that are cluttering up your computer.

To use these commands, just run them from the command line, the start menu search box in vista, or a batch file.

Temporary Internet Files

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 8

Cookies

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 2

History

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 1

Form Data

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 16

Passwords

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 32

Delete All

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 255

Delete All – "Also delete files and settings stored by add-ons"

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 4351

These commands should work in Internet Explorer 7 on XP or on Windows Vista

 

Thanks for HowToGeek.com for this wonderful blog : http://www.howtogeek.com/howto/windows/clear-ie7-browsing-history-from-the-command-line/
VN:F [1.9.3_1094]
VN:F [1.9.3_1094]
Categories: OS, Security, Vista, XP Tags:

How To Create Certificates Valid For More Than The Default Validity Period – Step By Step Instructions

January 3rd, 2009 Liran Eisenberg No comments

In order to create a certificate that is valid for longer than the default

validity period defined in the Windows Server CA templates, there are

three things which determine the validity period:

  1. The remaining lifetime of the issuing CA server
  2. The value specified in the certificate template
  3. The value specified in the CA server registry

The validity period of the certificate will be determined by the shortest

value of the three � :)

Determining the lifetime for a CA server

The default Validity period of a CA server is 5 years, however if your stability

is more important to you than security � set it to a longer period such as

ten or twenty years. Whatever value you choose, re-issue the CA certificate

about a year before it expires.

Certificate Template

You can edit the templates available for your CA only if you have

Windows Server 2003 Enterprise Edition !!!

Always try to install your CA on this edition, just in case you�ll need to edit

the certificate templates at any later date �

To manage the certificate template, open your CA server mmc and select

�Certificate Templates� �> �Manage�

image

You can then copy an existing template and edit its attributes.

CA registry values

In order to view your current registry settings use the following commands

in a CMD prompt:

certutil �getreg cavalidityperiod

certutil �getreg cavalidityperiodunits

These commands will show that your CA is using YEARS as its validity period

and 2 as its validity period units.

in order to change the validity period units use the following command:

certutil �setreg cavalidityperiodunits n

(n represents value of the number of years you wish to set)

In order for the new setting to apply you must stop and start the CA service,

you can do so by the following commands:

net stop certsvc

net start certsvc

VN:F [1.9.3_1094]
VN:F [1.9.3_1094]
Categories: PKI, Security Tags:

Tools for Virtualization and System Center

December 13th, 2008 Amit Gatenyo No comments

My Presentation on Windows 2008 Security

December 11th, 2008 Amit Gatenyo No comments

Windows 2008 has a lot new security features like CNG, RODC, ASLR, Windows Auditing, Windows Defender, Security Center, Service Hardening, Bitlocker, NAP, UAC.

If you are interested on learning more about them and what is different from Windows 2003XP to Windows 2008Vista you are welcome to check a session I gave at Microsoft Israel.

Windows 2008 Security
View SlideShare presentation or Upload your own. (tags: auditing windows)

VN:F [1.9.3_1094]
VN:F [1.9.3_1094]

Data Protection Manager SP1

December 7th, 2008 Amit Gatenyo No comments

SP 1 for System Center Data Protection Manager 2007 will be available on December 8th 2008. Along with the roll up update this release enhances many of the core features of DPM 2007. The key among them being

  1. Protection of Hyper-V™ virtualization platforms
  2. Enhanced SQL Server 2008 protection
  3. Microsoft Office SharePoint Server 2007 and Windows SharePoint Services 3.0
  4. Protection for Exchange Server 2007 Standby Cluster Replication (SCR)

In addition to enhancing the protection of each of the core Microsoft application workloads, additional capabilities have also been introduced with the release of DPM 2007 SP1, such as:

  1. Provision for a Client DPML answers customer demand for a more cost-effective way to protect Windows XP and Windows Vista clients using the same DPM 2007 infrastructure that protects their servers
  2. Disaster Recovery capabilities within DPM 2007 SP1 now include the ability to leverage a 3rd party vaulting partner via the cloud (SaaS) powered by Iron Mountain.
VN:F [1.9.3_1094]
VN:F [1.9.3_1094]

How to save user credentials for non-domain Communicator 2007 users

November 18th, 2008 Liran Eisenberg No comments

If you’re running Communicator 2007 in a domain environment you can enable

automatic login via the proper DNS SRV record.

Non-domain users need to configure via their registry the Communicator 2007’s

setting to enable saving their user credentials.

The setting are:

HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftCommunicator

“SavePassword”=dword:00000001

REG_DWORD = SavePassword

You can set it You can configure this policy under both HKEY_LOCAL_MACHINE

and HKEY_CURRENT_USER but the policy setting under HKEY_LOCAL_MACHINE

takes precedence

Values:

Not set = User choice (default).

0 = Users do not have the option to save password.

1 = Users have the option to save password

VN:F [1.9.3_1094]
VN:F [1.9.3_1094]
Categories: OCS, Security Tags: ,

Microsoft Assessment and Planning Toolkit 3.2 RTM Version Now Available!

November 5th, 2008 Amit Gatenyo No comments

MAP is a scalable and agent-less assessment platform designed to make it easier for you to adopt the latest Microsoft technologies.

In this version, MAP has expanded its assessment capabilities to include SQL Server 2008, Forefront/NAP, and Microsoft Online Services migration, as well as providing a Power Savings assessment to help you "go green."

In summary, MAP 3.2 assessment areas now include:

  • SQL Server 2008 Migration Proposals and Reports (NEW!)
  • Forefront/NAP Readiness Proposals (NEW!)
  • Microsoft Online Services Migration Surveys, Proposals, and Reports (NEW!)
  • Power Savings Proposals (NEW!)
  • Server Migration Reports and Proposals (Windows Server 2008 and "virtualized guests by hosts" reporting) (NEW!)
  • Server Consolidation Reports and Proposals (Virtual Server 2005 R2 and Hyper-V)
  • Desktop Security Assessment to determine if desktops have anti-virus and anti-malware programs installed and up-to-date, or if the Windows Firewall is turned on
  • Windows Vista and Microsoft Office 2007 Hardware Assessment Reports and Proposals
VN:F [1.9.3_1094]
VN:F [1.9.3_1094]

SCOM 2007 On-Demand Webcasts

October 2nd, 2008 Amit Gatenyo No comments

How Microsoft IT Implements System Center Operations Manager 2007 (Level 300)

http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&EventID=1032322478&CountryCode=US

Assure the Availability and Performance of Your SharePoint Environments (Level 300)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032368298&EventCategory=4&culture=en-US&CountryCode=US

Client Monitoring with System Center Operations Manager 2007 (Level 300)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032348673&EventCategory=4&culture=en-US&CountryCode=US

Client Monitoring with System Center Operations Manager 2007 (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032341228&EventCategory=4&culture=en-US&CountryCode=US

Client Monitoring with System Center Operations Manager 2007 (Level 100)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032340080&EventCategory=4&culture=en-US&CountryCode=US

End-to-End Service Monitoring with System Center Operations Manager 2007 (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032345599&EventCategory=4&culture=en-US&CountryCode=US

Installation and Management Pack Migration of Operations Manager 2007 (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032369730&EventCategory=4&culture=en-US&CountryCode=US

Monitoring with System Center Operations Manager 2007 (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032343631&EventCategory=4&culture=en-US&CountryCode=US

Planning a Successful Microsoft Operations Manager 2007 Deployment with Microsoft System Center Capacity Planner 2007 (Level 300)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032348510&EventCategory=4&culture=en-US&CountryCode=US

Reporting with System Center Operations Manager 2007 (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032338857&EventCategory=4&culture=en-US&CountryCode=US

Security and Enterprise Features of System Center Operations Manager 2007 (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032343649&EventCategory=4&culture=en-US&CountryCode=US

SQL Server 2008: New Performance Monitoring and Troubleshooting Using Management Studio (Level 300)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032349947&EventCategory=4&culture=en-US&CountryCode=US

System Center Operations Manager 2007 Installation and Management Pack Migration (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032341254&EventCategory=4&culture=en-US&CountryCode=US

System Center Operations Manager 2007 Technical Overview (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032340808&EventCategory=4&culture=en-US&CountryCode=US

System Center Operations Manager 2007: Install and MP Migration (Level 200)

http://msevents.microsoft.com/cui/WebCastEventDetails.aspx?EventID=1032345595&EventCategory=4&culture=en-US&CountryCode=US

VN:F [1.9.3_1094]
VN:F [1.9.3_1094]

SCOM 2007 Useful Links

October 2nd, 2008 Amit Gatenyo No comments

Main Downloads page (catalog, documentation)

http://technet.microsoft.com/en-us/opsmgr/bb498232.aspx

Operations Manager Product Team Blog:

http://blogs.technet.com/momteam

SystemCenterForum.org

http://www.systemcenterforum.org

System Center Content Search (Vista gadget)

http://gallery.live.com/liveItemDetail.aspx?li=49e26ad0-113d-4f3d-a711-57f6530c75d9

System Center Operations Manager Blog Search:

http://search.live.com/macros/microsoft_user_assistance/sc_operations_manager_blogs

Event Flow Diagram

http://blogs.technet.com/momteam/archive/2007/10/30/event-alerts-perf-data-flow-in-opsmgr-2007.aspx

DWDATARP.exe (For setting Data Retention policies in the Warehouse)

http://blogs.technet.com/momteam/archive/2008/05/14/data-warehouse-data-retention-policy-dwdatarp-exe.aspx

End-To-End Task test:

http://www.systemcenterforum.org/testing-end-to-end-notification-in-opsmgr-or-essentials-2007-mp/

Targeting Best Practices Poster:

http://download.microsoft.com/download/f/a/7/fa73e146-ab8a-4002-9311-bfe69a570d28/BestPractices_Rule_Monitor_REV_110607.pdf

Best practices to use when you configure overrides in System Center Operations Manager 2007

http://support.microsoft.com/kb/943239

Authoring Guide:

http://download.microsoft.com/download/7/4/d/74deff5e-449f-4a6b-91dd-ffbc117869a2/OM2007_AuthGuide.doc

Effective configuration Viewer:

http://www.microsoft.com/Downloads/details.aspx?FamilyID=a9db4dca-6716-478d-89b9-42f27ebc76a8&displaylang=en

Override Explorer:

http://blogs.msdn.com/boris_yanushpolsky/attachment/4301837.ashx

Group membership:

http://www.systemcenterforum.org/list-ops-mgr-group-membership-using-powershell

http://blogs.msdn.com/boris_yanushpolsky/archive/2007/10/26/which-groups-is-a-particular-computer-member-of.aspx

Management Group Configuration tool:

http://blogs.technet.com/cliveeastwood/archive/2007/06/04/mginfo-management-group-license-and-summary-info-utility-for-operations-manager-2007-and-essentials-2007.aspx

Maintenance mode Scripts:

http://blogs.technet.com/cliveeastwood/archive/2007/09/18/agentmm-a-command-line-tool-to-place-opsmgr-agents-into-maintenance-mode.aspx

http://blogs.msdn.com/boris_yanushpolsky/archive/2008/03/04/one-more-maintenance-mode-script.aspx

How Microsoft Does IT (includes MOM 2005 and Ops Mgr documents):

http://technet.microsoft.com/en-us/library/bb687791(TechNet.10).aspx

(from http://www.microsoft.com/itshowcase)

Certificates for Windows 2008 and Ops Mgr:

http://blogs.technet.com/momteam/archive/2008/06/02/obtaining-certificates-for-ops-mgr.aspx

Adding Custom Information to alerts and Notifications:

http://blogs.technet.com/kevinholman/archive/2007/12/12/adding-custom-information-to-alert-descriptions-and-notifications.aspx

Last contact time Style reports:

http://blogs.technet.com/kevinholman/archive/2008/06/27/which-servers-are-down-in-my-company-and-which-just-have-a-heartbeat-failure-right-now.aspx

http://blogs.technet.com/kevinholman/archive/2008/06/27/creating-a-new-data-source-for-reporting-against-the-operational-database.aspx

Converting an MP to XMl (unseal it)

http://blogs.msdn.com/boris_yanushpolsky/archive/2007/08/16/unsealing-a-management-pack.aspx

Powershell basics:

http://blogs.msdn.com/scshell/

http://blogs.msdn.com/scshell/archive/2006/09/28/getting-started.aspx

Powershell script examples:

http://blogs.technet.com/brianwren/archive/2008/03/11/mms-command-shell-presentation.aspx

Effective Config Viewer:

http://www.microsoft.com/Downloads/details.aspx?FamilyID=a9db4dca-6716-478d-89b9-42f27ebc76a8&displaylang=en

Developing MPs

http://www.developer.com/design/article.php/3740486

Enable Proxying on Agents UI

http://blogs.msdn.com/boris_yanushpolsky/archive/2007/08/02/enabling-proxying-for-agents.aspx

What Thresholds Monitors Have

http://blogs.msdn.com/boris_yanushpolsky/archive/2007/08/07/so-what-thresholds-do-my-monitors-have.aspx

Boris Yanushpolsky’s blog

http://blogs.msdn.com/boris_yanushpolsky/default.aspx

Bulk Enable / Disable of rules or monitors (Override Creator):

http://blogs.msdn.com/boris_yanushpolsky/archive/2007/08/04/disabling-enabling-multiple-rules-monitors-discoveries-at-once.aspx

New KB Articles / Hotfixes Summary:

http://blogs.technet.com/cliveeastwood/rss.aspx?Tags=New%20and%20upcoming%20KB%20Articles/Operations%20Manager%202007&AndTags=1

Update Custom Fields

http://www.microsoft.com/communities/newsgroups/en-us/default.aspx?dg=microsoft.public.opsmgr.powershell&tid=0bdee97c-95b6-4074-9eff-f7edca3d0ff2&cat=01DE69DE-CFDB-E7B7-8849-BF4BC19A6B88&lang=en&cr=US&sloc=&p=1

http://www.systemcenterforum.org/updating-custom-fields-in-alerts-operations-manager-2007/

Design Reports in SCOM:

http://opsmgr.wordpress.com/2007/07/19/want-to-design-a-new-report-in-scom-2007/

DB IOPS Performance

http://blogs.technet.com/momteam/archive/2008/06/24/performance-iops-for-the-db-and-dw-in-opsmgr-2007.aspx

DW Backup and Grooming:

http://searchwincomputing.techtarget.com/generic/0,295582,sid68_gci1316214,00.html

Creating tasks:

http://www.systemcenterforum.org/wp-content/uploads/PowershellTasks_v1.0.pdf

Planning and designing the infrastructure:

http://www.microsoft.com/downloads/details.aspx?FamilyId=AD3921FB-8224-4681-9064-075FDF042B0C&SAMI_Campaign_Name=IPD062708RTM_IPDDL&displaylang=en

Operations Manager Training Videos:

http://technet.microsoft.com/en-us/opsmgr/bb498237.aspx

Publishing Reports to Sharepoint:

http://blogs.technet.com/momteam/archive/2008/02/29/publish-reports-to-sharepoint.aspx

Operations Manager Reporting Guide:

http://download.microsoft.com/download/7/4/d/74deff5e-449f-4a6b-91dd-ffbc117869a2/OpsMgr2007_RprtGuide.doc

Configuring notifications for a specific alert:

http://blogs.technet.com/kevinholman/archive/2008/02/01/configuring-notifications-to-include-specific-alerts-from-specific-groups-and-classes.aspx

System Center Capacity Planner:

http://www.microsoft.com/systemcenter/sccp/default.mspx

Operations Manager Authoring Console:

http://download.microsoft.com/download/f/4/3/f438d6a0-290c-42b8-8f9c-c6660f89e1aa/OpsMgr07_x64_AuthConsole.exe

http://download.microsoft.com/download/f/4/3/f438d6a0-290c-42b8-8f9c-c6660f89e1aa/OpsMgr07_x86_AuthConsole.exe

VN:F [1.9.3_1094]
VN:F [1.9.3_1094]

Active Directory Migration Tool v3.1 has been released

September 7th, 2008 Amit Gatenyo No comments

The Active Directory Migration Tool version 3.1 (ADMT v3.1) simplifies the process of migrating objects and restructuring tasks in an Active Directory® Domain Service (AD DS) environment. You can use ADMT v3.1 to migrate users, groups, and computers between AD DS domains in different forests (inter-forest migration) or between AD DS domains in the same forest (intra-forest migration). ADMT can also perform security translation (to migrate local user profiles) when performing inter-forest migrations.

This version is the first one to support Windows 2008.

Download the tool here.

Check out the whitepaper on Migrating and Restructuring Active Directory Domains Using ADMT v3.1.

And you also need to download Password Export Server v3.1 in order to migrate passwords between domains.

VN:F [1.9.3_1094]
VN:F [1.9.3_1094]

.