7 de abr. de 2010

Identify network settings applied via Group Policy

Identify network settings applied via Group Policy: "

There is nothing more frustrating than a setting that keeps returning without any explanation. In this case, Group Policy may be overwriting locally applied settings. IT pro Rick Vanover shows how to search for network settings that may be pushed down.

—————————————————————————————

If you use Twitter to follow various technical topics, you can frequently find that people may use it as a tech support forum. This has to drive tech companies mad as no formal support process starts with a Tweet, yet the Twitter user community can pipe up with feedback to the situation. This is why many people use Twitter for this very purpose. Recently, I found that a colleague of mine on Twitter was having network settings applied via Group Policy. I and fellow blogger Andrew Storrs quickly determined that we were dealing with a Group Policy overwriting the explicit local configuration.


For network settings in Windows, there are a number of settings that can be applied. Some of these settings are not done locally, but centrally through Group Policy. The tell-tale sign if Group Policy is overriding a local setting is — after a few hours, days, or a reboot — the configuration is removed. The answer is to run a Resultant Set of Policy analysis on the local system. To do this, open a management console on a Windows Server (or client) by running MMC. Then click the Add/Remove Snap-In from the File Menu. Figure A shows this Snap-In being added:

Figure A

Figure A

Click image to enlarge.

Right-click on the Resultant Set Of Policy link in the console, then answer a few questions such as on which computer (presumably the local system) and user to run the policy analysis. This will run a local scan to see what configurations are applied to the server. This will include network as well as non-network settings.

Interpreting the results can be a little confusing, but in regards to network settings, there are a few primary locations for settings applied via Group Policy. Figure B shows one server’s report:
Figure B


Figure B

Click image to enlarge.

Areas that are frequently associated with network settings are highlighted in red. This can include Windows Firewall settings, if applied. In Figure B, there is a Windows Firewall setting applied to disable the domain profile. Frequently, Windows servers start with a default setting which may have included a “by hand” setting to disable one of the other profiles of Windows Firewall."

Lenovo C200 All-In-One Features Blazing Next-Gen Ion Graphics [Lenovo]

Lenovo C200 All-In-One Features Blazing Next-Gen Ion Graphics [Lenovo]: "

The Lenovo C200 all-in-one made a brief appearance at CeBIT a few months ago, but now it's official: an 18.6-inch 16:9 display with a dual-core Atom D510 processor and optional next-generation Nvidia Ion graphics. You'll want to take the option.

The C200 is one of the first of a wave of products featuring the HD-capable next-generation Ion, and it's also got a friendly starting price of $399. Of course, that's only going to get you a 1.6GHz Atom D410, 160GB of storage, no touchscreen, and Intel's lesser integrated graphics.
The upgrade options, though, are extensive: up to that dual core Atom D510, a touchscreen (no multitouch, sadly), 4GB DDR2 RAM, and a 500GB HDD—making a fully tricked out C200 worth a closer look. If only more of those were standard! But you take what you can get.
 
All-in-ones haven't really found their stride in the US, but for an affordable HD-capable secondary computer, you could certainly do a lot worse. The C200 will be available later this month.


Chinese Hackers Broke Into The Dalai Lama's Email Account [Security]

Chinese Hackers Broke Into The Dalai Lama's Email Account [Security]: "
Click here to read Chinese Hackers Broke Into The Dalai Lama's Email Account
Turns out even His Holiness, with Buddha on his side, can't protect himself against Chinese hackers, with 11 months of his personal emails being monitored according to new security reports.

GhostNet, a huge spam network which we heard had targeted the Dalai Lama among others last year, apparently hacked into his account and were reading his emails between January and November 2009. Details about Indian security and missile systems, Nato workers in Afghanistan—and just how he keeps his orange robes so bright after many washes—were enclosed in the 1,500 emails that were stolen by the hackers. [Telegraph]"

6 de abr. de 2010

Desperate Nokia Making a Tablet Too [Rumor]

Desperate Nokia Making a Tablet Too [Rumor]: "
A Finnish analyst says Nokia's preparing a touchscreen tablet 'for fall release.' If confirmed, it won't be the first time that Nokia tries a tablet format. I just hope they don't take any notes from their sad previous efforts. [Reuters] More »"

Improve Windows Security By Closing Open Ports

Improve Windows Security By Closing Open Ports: "
A standard Windows operating system has a number of ports open after installation. Some of these ports are needed for the system to function properly while others might not. These ports can pose a security risk as every open port on a system might be an entry point for a malicious user.
A port basically allows communication to or from the device. Characteristics are a port number, an IP address and a protocol type. This article will give you the tools at hand to identify and evaluate the open ports on your Windows system to make a decision in the end whether they can or should be closed or left open.
Software programs and tools that we will use:
  • CurrPorts: Available for 32-bit and 64-bit editions of Windows. It is a port monitor that displays all open ports on a computer system. We will use it to identify the ports and the programs that are using them.
  • Windows Task Manager: Also used to identify the programs and link some ports to programs.
  • Search Engine: Searching for port information is necessary for some ports that cannot be identified that easily.
It would be an impossible task to go through all of the ports that are open, we will therefor use a few examples to enable everyone to understand the process and go on from there.
Fire up CurrPorts and take a look at the populated main area.
currports
The program displays the process name and ID, local port, protocol and local port name among others.



Display Network Information With Win IP Config

Display Network Information With Win IP Config: "

Many administrators and users rely on the command line when they troubleshoot networking issues. Basic commands like ping, netstat, ipconfig or traceroute can provide them with valuable information about the state of the network and the connections.

Win IP Config is a program for Windows that makes some of these tools available in a graphical user interface. The interface uses tabs to divide the information and functionality, available are the tabs host info, IP info, interfaces, routes (filtered), netstat and report.

Win IP Config will for instance display in depth information about the network adapters including their gateway, IP, DHCP (DHCP server and lease time) or DNS.

win ip config

The networking software will also display the current routes and an output of the netstat command in its tabs. Those information alone are valuable and quickly accessible.

Win IP Config provides access to controls in the header as well. Those can be used for instance to renew the IP address or add a new one, to add or delete routes or to display detailed IP statistics including header and address errors plus other problems related to that.

The report tab basically displays all the collected information in an easily readable format. It is possible to export the report as a text document for further processing.

Win IP Config is a handy program for users who prefer to work with a graphical user interface instead of the command line. It does not totally replace the command line as it does not provide access to commands like traceroute or ping.

The program can be downloaded from the developers website. It has not been updated in a while but worked without complications on our 64-bit Windows 7 Professional test system. (via 4Sysops)

"

10 obscure antivirus tools worth checking out

10 obscure antivirus tools worth checking out: "
You know about the big players in the AV field — but a number of lesser-known tools may serve your needs as well (or even better). Jack Wallen runs through some of your choices.
Viruses come and go. Some of them are simply annoyances, but others are nasty little bits of malicious single-minded code that want to take down your machine or take away your data. Fortunately, there are plenty of tools out there that can help you deal with the problem. Some of those tools are well known: Symantec, McAfee, Norton. But you can also find tools that will serve you at a fraction of the cost or a fraction of the CPU processes.
I’m going to introduce you to some of these lesser-known antivirus tools. In the end, you will have more tools for your toolkit than you ever though you would have… all of which are ready to immunize you from machine-crushing code.
1: BitDefender
BitDefender is one of my favorites on the list. Why? Because it has one of the best graphical virus tools available for the Linux operating system. Of course it doesn’t offer just a Linux solution. BitDefender offers antivirus for both Linux and Windows, as well as for various server installations. In fact, BitDefender has solutions for mail servers, Samba servers, desktops, and much more.
2: Avira Antivir
Avira Antivir has, in many cases, found viruses where others have not. One of my favorite uses for this solution is to slap it on a Linux machine (the Linux version is command-line based, but does have a GUI if you prefer), attach an infected Windows drive externally, and run Avira on that drive. Much like BitDefender, Avira will find viruses many other solutions won’t find. And because it is mostly command line, it is also quite a bit faster than other tools.
3: ClamAV
ClamAV is mostly a mail server antivirus for Linux, but it does a bang-up job. If you’re hosting a Linux-based mail server, you will want to include ClamAV on it; otherwise, you risk winding up spreading the love of viruses around the globe.
4: Avast
Avast is not as much a wallflower as the other tools, but it certainly has never been crowned Prom Queen. It’s an outstanding tool that offers a lot of options many other tools over look. One of my favorite aspects of Avast is the built-in rootkit check. You can’t go wrong when you know your antivirus is keeping you safe from rootkits.
5: rkhunter
rkhunter is not so much an antivirus tool as it is an anti-rootkit tool. If you’ve never come across a rootkit on a machine, consider yourself lucky. Very lucky. Rootkits are the Mac Daddy of viruses. And if your current antivirus solution doesn’t protect you from rootkits, either add a rootkit protection tool on your system or uninstall and install one that does!
6: Dr.Web CureIt!
Dr.Web CureIt! is an interesting tool in that it requires no installation. It’s a simple binary file that, when double-clicked, will execute and scan your machine. The only drawback is that to get the latest definitions, you have to re-download the tool and use the newest version. But how easy would this tool be to use as a portable virus scanner?
7: ESET Smart Security
ESET Smart Security is from the makers of the NOD32 Antivirus tool that has been around for quite some time. ESET sets itself apart by being an antivirus and a firewall in one. But the firewall isn’t just a standard firewall. It’s a “learning firewall,” in that it observes how its users use the network and, theoretically, adapts to that usage. ESET also protects you from removable data and from viruses that attempt to disable your antivirus protection.
8: ZoneAlarm
ZoneAlarm is an antivirus tool that offers something others do not — DataLock. The DataLock portion of ZoneAlarm uses encryption on your hard drive so that it is readable only by those with the encryption key. DataLock also offers pre-boot authentication so that unauthorized users can’t even boot your machine. Yes, these features can be added from the BIOS or from other tools, but with ZoneAlarm, you have antivirus, encryption, and boot authentication all in one.
9: iAntiVirus
iAntiVirus is for — you guessed it — Mac. Like Linux, nothing is immune (no matter how much the media and the PR say it is). And that beautiful new Mac you bought can use protection as well as that new quad-core Windows 7 machine. iAntiVirus is as inherently Mac as you will ever find in an antivirus tool. Not only is it user-friendly, it has that same Mac interface that everyone has grown to love (or hate). And what’s best, iAntiVirus works like any other antivirus software you have ever used — only it does so on a Mac. So it must be better.
10: Microsoft Security Essentials
Microsoft Security Essentials has to be on this list. After all, it wouldn’t be fair of me to highlight inherently Linux and Mac tools without offering the Windows equivalent. What is really surprising about this antivirus protection is that it is free AND produced by Microsoft. Those two don’t usually go hand in hand. If you want free virus protection, and you want something that will seamlessly integrate with Windows, Security Essentials is your best bet.
Recommendations?
Those are just 10 of the less well known antivirus solutionsf. Of course, there are plenty more out there. Do you rely on a somewhat obscure tool for antivirus? If so, share it with your fellow TechRepublic readers. After all, the perfect antivirus solution is still out there, waiting to be found and enjoyed by PC users and admins across the globe.

5 de abr. de 2010

ZeuAPP

Fica aqui um "programinha" muito útil chamado ZeuAPP. Esta pequena aplicação permite de uma só janela fazer a instalação de desenhas de programas open-source. Muito útil quando acabamos de instalar um computador e queremos rapidamente ter a máquina apetrechada com o software necessário para começar a trabalhar.

As 5 melhores aplicações para personalizar o Windows 7 by: Lifehacker



Windows 7 has been well received both critically and on the street. And while Lifehacker readers love Windows 7, a well-built OS isn't a perfect OS. Check out these five applications that tweak Windows 7 and customize it to your heart's content.

A stock Windows 7 installation a fairly pleasant place to work, judging from our readers' reports. Even so, a little tweaking of its behavior, looks, and other features lets you optimize and personalize that desktop. Check out these five great tools for doing so.

Mini Rack para servidores made by IKEA?


The $70 IKEA Mini Server Rack - More DIY How To Projects


Achei piada. :)

Sistemas de monitorização

Uma das ferramentas fundamentais na administração de sistema é sem duvida o sistema monitorização.
Durante muito tempo quando se falava de monitorização opensource o nome NAGIOS era sempre o primeiro a surgir. Foi ele que definiu quais os standard da industria no que toca a monitorização de sistema. Com uma grande robustez e parametrização foi durante largos anos o sentinela dos datacenters.
Mais recentemente apareceram várias plataformas de grande qualidade, algumas delas baseadas em nagios ou compatíveis com os seus pluggins. Para alem das inumeras funcionalidades que estas soluções apresentaram vieram igualmente melhorar um ponto que para mim o NAGIOS sempre decorou: os interfaces para os utilizadores, recorrendo a maioria às técnicas WEB2.0 produzindo interfaces agradáveis à vista com um grau de funcionalidade muitíssimo elevado.

Segue uma lista das principais plataformas utilizadas

O standard do mercado de monitorização.

É a minha escolha(Core Edition). Óptimo interface, bom leque de pluggins. Grande capacidade de costumização e uma grande comunidade de suporte.

Um dos grande nomes das novas plataformas de monitorização

Outro grande player da área de monitorização. Fiz uns testes a uns tempos e não gostei, o processo de parametrização é um pouco confuso

Foi um dos vencedores no ano de 2009 do Bossie Awards na Categoria de Networking

Só recentemente é que tomei conhecimento desta plataforma, por intermédio do meu amigo JSI. Ainda não testei mas um dia destes vou dar uma "voltinha com ele".

Nunca testei


A nível comercial existem, tal como no open source um sem numero de plataformas, que destaco

HP Operations Center

IBM Tivoli


Microsoft System Center Operations Manager (SCOM)

Solarwind

8 de mar. de 2010

Centos & SNMP

Uma curtinha .... activar o snmp no centos 5

  1. yum install net-snmp
  2. yum install net-snmp-utils
  3. snmpconf -g basic_setup
Update - Configuração muito simples do snmpd.conf


###########################################################################
#
# snmpd.conf
#
#

###########################################################################
# SECTION: Access Control Setup
#
# This section defines who is allowed to talk to your running
# snmp agent.

# rocommunity: a SNMPv1/SNMPv2c read-only access community name
# arguments: community [default|hostname|network/bits] [oid]

rocommunity public

###########################################################################
# SECTION: System Information Setup
#
# This section defines some of the information reported in
# the "system" mib group in the mibII tree.

# syslocation: The [typically physical] location of the system.
# Note that setting this value here means that when trying to
# perform an snmp SET operation to the sysLocation.0 variable will make
# the agent return the "notWritable" error code. IE, including
# this token in the snmpd.conf file will disable write access to
# the variable.
# arguments: location_string

syslocation "Data Center, Rack x"

# syscontact: The contact information for the administrator
# Note that setting this value here means that when trying to
# perform an snmp SET operation to the sysContact.0 variable will make
# the agent return the "notWritable" error code. IE, including
# this token in the snmpd.conf file will disable write access to
# the variable.
# arguments: contact_string

syscontact "email@domain.com"

Zimbra: Algumas configurações

Algumas configurações uteis após instalação

Entrar no painel de administração https://host:7071/zimbraAdmin/ depois a Class of Service > default
- Features, activar o Instant Messenger
- Preferences – activar “Automatically login to instant messaging services”
- Preferences – activar “Use the GAL when autocompleting addresses”
- Advanced – Definir Quotas para os usuários