Application question

2009-10-06 Thread Joseph Heaton
Anyone using Weblog Expert?  I need some help with a query for it, and I'm 
brand new to the application.

Joseph L. Heaton
Windows Server Support Group
Information Technology Branch
Department of Fish and Game
1807 13th Street, Suite 201
Sacramento, CA  95811
Desk: (916) 323-1284

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: dyndns for webservers

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 5:58 PM, Adam Greene  wrote:
> We are considering suggesting dynamic DNS to associate his webserver domain
> name with the changing IP addresses.

  It works okay for what it is.  It's a low-budget solution.  If the
website is critical to business, I wouldn't recommend it.  If the end
customer doesn't react well to "we found the problem but it's outside
of our control", avoid it.  If it's just an informational site and not
a big deal, it's appropriate.

  It won't work for some small segment of your users.  Exactly how
small varies.  It's often an insignificant segment, but occasionally
is not.  AOL used to ignore DNS TLL all the time, but I hear they've
gotten better (just in time to go out of business).

  How well it works is impacted by all sorts of things -- DNS
propagation delays, DNS caching, stale lookups, nameservers which
ignore your TTL, phase of the moon, etc.  Diagnosing individual causes
is basically impossible, and even when you find a cause you generally
can't do anything about it.

  One problem is that many browsers (most?) only resolve a name once
and then keep that IP address in memory until you exit the browser.
This isn't a function of DNS but application design.

  Doom and gloom aside, dynamic DNS works very well in the general
case.  You just have to be willing to accept its limitations.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: Analytics - Part Deux

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 6:52 PM, Joe Heaton  wrote:
> End-user portal, so I can have a few end users be able to find their own info.

  I know Google Analytics will let you assign multiple users (Google
Accounts) to a website, with at least rudimentary access control (edit
vs view).

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: OT: Early Friday Funny

2009-10-06 Thread Joseph Heaton
You want some of this??

>>> Roger Wright  10/6/2009 1:29 PM >>>
Bring it! 

Roger Wright

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: OT: Early Friday Funny

2009-10-06 Thread Rubens Almeida
Not available in Brazil :(

On Tue, Oct 6, 2009 at 5:29 PM, Roger Wright  wrote:
> Bring it!
> Roger Wright
> ___

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: TS Licensing

2009-10-06 Thread Free, Bob
> I do not remember how they are assigned


They are assigned according to how you configure the Terminal Server,
per-seat or per-user


From: Art DeKneef [] 
Sent: Monday, October 05, 2009 3:29 PM
To: NT System Admin Issues
Subject: RE: TS Licensing


I go by how the business needs are. Going by your numbers you have 150
employees that used computers. How many computers do you have for the
employees to use? How many do not need TS access?


If they have 50 users that need access from 75 different computers then
User CALs are used. The people can use any computer that is open. More
users require more licenses.


If they have 50 computers and these computers are access by 75 people
then device CALs are used. This scenario allows more users without an
increase of TS licenses.


You can have both types of licenses on the same server. I do not
remember how they are assigned other than when they are entered in the
licensing server. 


Hope that makes sense.




From: Jeff Brown [] 
Sent: Monday, October 05, 2009 2:53 PM
To: NT System Admin Issues
Subject: TS Licensing


We use TS extensively, we have less than 200 employees, 50+ that don't
use computers at all.  We have 70 TS CAL's and have had trouble running
short on those.  Up to this point we have purchased "device" CAL's and
are thinking we might  be better off adding "user" CAL's?  Nothing
fancy, all our servers are W2k3 SP2 and our clients are XP Pro.
Everything works, we are just running out of licenses.  Wondering if
anyone out there has 2 licenses servers up so they can run both types
and how does that work for you(if it is even possible to do on one
network??)  (yes, we have 25 temporary licenses, those are plumb full as


thanks for any help.







~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: cheap inventory tracking

2009-10-06 Thread Sam Cayze
Not sure of anything prebuilt...  But you could probably just use Excel.


But if you end up designing your own system, this is a good, scriptable
barcode generator:


Populate Excel with codes, print the barcodes.  At the end of the event,
scan them back in.  Do your analysis.  Just point your curser in the
cell, and a handheld Bluetooth scanner will 'type' the barcode into the
cell.  There are even a few Excel plug-ins that will generate barcodes.




From: Don Ely [] 
Sent: Tuesday, October 06, 2009 5:06 PM
To: NT System Admin Issues
Subject: Re: cheap inventory tracking


Dispense some liquor over here to me please...

On Tue, Oct 6, 2009 at 2:24 PM, James Kerr  wrote:

We have a fundraiser we do every year and my involvement in it is
despensing liquor and all the supplies any of the bars need at the
events. I really only care to track liquor bottles. Basically Im looking
for a way to barcode scan a bottle and document that the bottle went to
bar one or bar two, etc. When the bars return empty bottles I want to be
able to track which bar it came from so I can make sure the bars are not
stealing bottles. Any ideas?


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~




~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Analytics - Part Deux

2009-10-06 Thread Joe Heaton
An additional desire for this application:

End-user portal, so I can have a few end users be able to find their own info.
~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: TS Licensing

2009-10-06 Thread Free, Bob
I did that trip one night, from US to India to Ireland in less than ½ an hour  J


From: wjh [] 
Sent: Tuesday, October 06, 2009 11:53 AM
To: NT System Admin Issues
Subject: Re: TS Licensing


I have successfully (after hours of being bounced around on the phone) 
successfully gotten CALs transferred from device to user CALs.  It was 
frustrating bouncing from tech support to licensing to techs upport, getting 
disconnected, starting over, but eventually it happened.


Jeff Brown wrote: 

Thank you.  Very well put.  BUT, if what I'm reading is correct, with device 
cal's when your number is issued, you are done, no more connections are allowed 
until one is freed up.  I own 70 device cals.  I have less than 70 users 
logging in, but many of them log in from 2 or 3 different machines and we run 
out because of that. 


If I had purchased user licenses, and if I understand what I have read, even 
when/if my licenses were exceeded my users would not be denied access to the 
terminal server.  It was an unfortunate choice for us.  We intend to be 
compliant with our licenses ALL THE TIME, so we aren't just looking for a way 
to cheat MS.  If I had purchased per user licenses I would not have a problem.  
I have fewer than 70 users accessing the TS servers I am absolutely sure.

On Tue, Oct 6, 2009 at 12:50 PM, Ben Scott  wrote:

On Tue, Oct 6, 2009 at 1:41 PM, Free, Bob  wrote:
> Still won't help. TS Licensing still has no notion of concurrency.

 To amplify what Bob is saying:

 Every client using your server must have a CAL.  CALs are *not*
assigned to servers, they're assigned to clients.

 The client that gets the CAL assigned to it can be a warm body
("user") or a piece of equipment ("device").  But one of those two
must have a CAL assigned it.

 If you have one Terminal Server, with 100 users (each with their own
PC), you need 100 CALs.  Even if you only have *one* person logging on
at a time, you still need 100 CALs.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~

~   ~







~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: TS Licensing

2009-10-06 Thread Klint Price
I believe you can have multiple license servers, and set the TS app server to 
specifically use one or the other.


From: Jeff Brown []
Sent: Tuesday, October 06, 2009 8:32 AM
To: NT System Admin Issues
Subject: Re: TS Licensing

Thanks for all the input.  In retrospect, i wish we had chosen user CAL's NOT 
device CAL's from the start.  I would recommend that path to anyone in the 
On Tue, Oct 6, 2009 at 12:57 AM, Brian Desmond>> wrote:

IIRC it's either/or. Also IIRC there's some sort of timer that kicsk in so you 
can't move user CALs from user A to B to C in three days. Whether the software 
implements this or it's just on paper I have no idea.


Brian Desmond

c - 312.731.3132

From: Jeff Brown []
Sent: Monday, October 05, 2009 4:53 PM
To: NT System Admin Issues
Subject: TS Licensing

We use TS extensively, we have less than 200 employees, 50+ that don't use 
computers at all.  We have 70 TS CAL's and have had trouble running short on 
those.  Up to this point we have purchased "device" CAL's and are thinking we 
might  be better off adding "user" CAL's?  Nothing fancy, all our servers are 
W2k3 SP2 and our clients are XP Pro.  Everything works, we are just running out 
of licenses.  Wondering if anyone out there has 2 licenses servers up so they 
can run both types and how does that work for you(if it is even possible to do 
on one network??)  (yes, we have 25 temporary licenses, those are plumb full as 

thanks for any help.


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: cheap inventory tracking

2009-10-06 Thread Don Ely
Dispense some liquor over here to me please...

On Tue, Oct 6, 2009 at 2:24 PM, James Kerr  wrote:

> We have a fundraiser we do every year and my involvement in it is
> despensing liquor and all the supplies any of the bars need at the events. I
> really only care to track liquor bottles. Basically Im looking for a way to
> barcode scan a bottle and document that the bottle went to bar one or bar
> two, etc. When the bars return empty bottles I want to be able to track
> which bar it came from so I can make sure the bars are not stealing bottles.
> Any ideas?
> James
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

dyndns for webservers

2009-10-06 Thread Adam Greene


I have a customer who runs a public-facing webserver on his network and 
wants to have Internet provider redundancy, without getting a /24 and 
doing BGP. We can set him up so that if his primary connection fails, he 
will go out through his backup link, but his public IP addresses will 
change when it fails over, in that scenario.

We are considering suggesting dynamic DNS to associate his webserver 
domain name with the changing IP addresses.

Is anyone doing this, and have you found it to be a reliable solution?


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: OT: Early Friday Funny

2009-10-06 Thread Stefan Jafs
Not available in Canada :(

Stefan Jafs

From: Micheal Espinola Jr []
Sent: October-06-09 4:40 PM
To: NT System Admin Issues
Subject: Re: OT: Early Friday Funny



On Tue, Oct 6, 2009 at 4:29 PM, Roger Wright>> wrote:
Bring it!

Roger Wright

This email and any attached files are confidential and intended solely for the 
intended recipient(s). If you are not the named recipient you should not read, 
distribute, copy or alter this email. Any views or opinions expressed in this 
email are those of the author and do not represent those of the Amico 
Corpoartion company. Warning: Although precautions have been taken to make sure 
no viruses are present in this email, the company cannot accept responsibility 
for any loss or damage that arise from the use of this email or attachments.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread G.Waleed Kavalec
Unicode !

On Tue, Oct 6, 2009 at 2:33 PM, Ben Scott  wrote:

> On Tue, Oct 6, 2009 at 3:21 PM, G.Waleed Kavalec 
> wrote:
> > My gmail password is used NOWHERE else.
> Username: kavalec
> Password: used NOWHERE else
>  Hey, it didn't work!  ;-)
> -- Ben
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~


Gregory Waleed Kavalec
What matters?...
Only the flicker of light within the darkness,
the feeling of warmth within the cold,
the knowledge of love within the void.
 — Joan Walsh Anglund

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: Analytics

2009-10-06 Thread Kurt Buff
On Tue, Oct 6, 2009 at 13:55, Joe Heaton  wrote:
> What website analytic programs are you guys using?  Currently, we're using 
> Weblog Expert, but it doesn't seem to be able to do what I'm looking for.
> I need something that can tell me how many hits, over x period of time, to 
> whatever internal webpage I want to point it to. For instance, I have 
>  I also have  I want to be able to 
> see how many hits the /projectX received over the last 30 days.
> The product also needs to be able to access the weblogs within a zip file, as 
> we zip up the logs after the current month.
> Any ideas?
> Thanks,
> Joe Heaton

This might prove interesting:

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Kurt Buff
We don't do no home at work. That is of course as opposed to work at home...

Yes, we've run into the issues with Linux using RDP for our TS server.

We don't have any Vista, either, so hadn't run into that.

I'm leaning more towards thin clients and virtual desktops all the
time. Solves *so* many problems, even beyond licensing.


On Tue, Oct 6, 2009 at 13:30, Phil Brutsche  wrote:
> I think you meant to say "As long as you have 2000 Pro or XP Pro, no
> separate TS license needed".
> If you have a home-user Windows OS (Win9x, XP Home, Vista Home, Win7
> Home), you need TS CALs.
> If you have a non-Windows OS (Mac OS X or *NIX through any of the really
> sucky open source RDP clients), you need TS CALs.
> If you have a business-oriented Windows OS newer than XP, you need TS
> CALs. I distinctly remember that our Vista Business machines consumed a
> TS CAL when we were still using a Windows 2000 TS.
> Kurt Buff wrote:
>> Lovely. I knew there was a reason why we haven't switched away from
>> our Win2k TS server to something newer. With that, as long as you have
>> XP or newer, no separate TS license needed.
> --
> Phil Brutsche
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

cheap inventory tracking

2009-10-06 Thread James Kerr
We have a fundraiser we do every year and my involvement in it is despensing 
liquor and all the supplies any of the bars need at the events. I really 
only care to track liquor bottles. Basically Im looking for a way to barcode 
scan a bottle and document that the bottle went to bar one or bar two, etc. 
When the bars return empty bottles I want to be able to track which bar it 
came from so I can make sure the bars are not stealing bottles. Any ideas?


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: TS Licensing

2009-10-06 Thread Free, Bob
That's because XP had a built-in license, AKA desktop equivalency, for W2K and 
2003 up to April 24, 2003. In addition to the creation of User CAL and External 
Connector options, W2K3 Terminal Server removed Windows desktop equivalency - 
the provision by which the latest version of the Windows desktop OS could be 
used to substitute for a Terminal Server CAL. We had to count how many copies 
we had purchased prior to that date and were given CALs for them. My W2k3 
license server has like 4 kinds of licenses on it.

Bottom line for 2003, if the server is in per user, it checks for the existence 
of a Licensing Service and that's it. At that point they (per-user) are not 
truly accounted for.

-Original Message-
From: Kurt Buff [] 
Sent: Tuesday, October 06, 2009 1:11 PM
To: NT System Admin Issues
Subject: Re: TS Licensing

On Tue, Oct 6, 2009 at 10:50, Ben Scott  wrote:
> On Tue, Oct 6, 2009 at 1:41 PM, Free, Bob  wrote:
>> Still won't help. TS Licensing still has no notion of concurrency.
>���To amplify what Bob is saying:
>���Every client using your server must have a CAL. ��CALs are *not*
> assigned to servers, they're assigned to clients.
>���The client that gets the CAL assigned to it can be a warm body
> ("user") or a piece of equipment ("device"). ��But one of those two
> must have a CAL assigned it.
>���If you have one Terminal Server, with 100 users (each with their own
> PC), you need 100 CALs. ��Even if you only have *one* person logging on
> at a time, you still need 100 CALs.
> -- Ben

Lovely. I knew there was a reason why we haven't switched away from
our Win2k TS server to something newer. With that, as long as you have
XP or newer, no separate TS license needed.


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: Analytics

2009-10-06 Thread Jacob
Google Analytics and (

I like Summary.Net because it gives me more details in regards to errors
(server errors, 404s, refers, etc...)

-Original Message-
From: Sam Cayze [] 
Sent: Tuesday, October 06, 2009 2:04 PM
To: NT System Admin Issues
Subject: RE: Analytics

I use these three:

AWSTATS for logs (Most advanced and reliable).  (It will work with your
ZIP technique, since it parses the reports into it's own DB structure

Best for Sales/Management:
JavaScript based, not as reliable, needs JavaScript in the HTML of the

LeadLander (For my Sales Guys)  Neat stuff.
Google Analytics



-Original Message-
From: Joe Heaton [] 
Sent: Tuesday, October 06, 2009 3:55 PM
To: NT System Admin Issues
Subject: Analytics

What website analytic programs are you guys using?  Currently, we're
using Weblog Expert, but it doesn't seem to be able to do what I'm
looking for.  

I need something that can tell me how many hits, over x period of time,
to whatever internal webpage I want to point it to. For instance, I have  I also have  I want to be able
to see how many hits the /projectX received over the last 30 days.

The product also needs to be able to access the weblogs within a zip
file, as we zip up the logs after the current month.

Any ideas?


Joe Heaton
~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: Analytics

2009-10-06 Thread Sam Cayze
AWSTATS test site:


-Original Message-
From: Sam Cayze [] 
Sent: Tuesday, October 06, 2009 4:04 PM
To: NT System Admin Issues
Subject: RE: Analytics

I use these three:

AWSTATS for logs (Most advanced and reliable).  (It will work with your
ZIP technique, since it parses the reports into it's own DB structure

Best for Sales/Management:
JavaScript based, not as reliable, needs JavaScript in the HTML of the

LeadLander (For my Sales Guys)  Neat stuff.
Google Analytics



-Original Message-
From: Joe Heaton []
Sent: Tuesday, October 06, 2009 3:55 PM
To: NT System Admin Issues
Subject: Analytics

What website analytic programs are you guys using?  Currently, we're
using Weblog Expert, but it doesn't seem to be able to do what I'm
looking for.  

I need something that can tell me how many hits, over x period of time,
to whatever internal webpage I want to point it to. For instance, I have  I also have  I want to be able
to see how many hits the /projectX received over the last 30 days.

The product also needs to be able to access the weblogs within a zip
file, as we zip up the logs after the current month.

Any ideas?


Joe Heaton
~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: Analytics

2009-10-06 Thread Sam Cayze

I use these three:

AWSTATS for logs (Most advanced and reliable).  (It will work with your
ZIP technique, since it parses the reports into it's own DB structure

Best for Sales/Management:
JavaScript based, not as reliable, needs JavaScript in the HTML of the

LeadLander (For my Sales Guys)  Neat stuff.
Google Analytics



-Original Message-
From: Joe Heaton [] 
Sent: Tuesday, October 06, 2009 3:55 PM
To: NT System Admin Issues
Subject: Analytics

What website analytic programs are you guys using?  Currently, we're
using Weblog Expert, but it doesn't seem to be able to do what I'm
looking for.  

I need something that can tell me how many hits, over x period of time,
to whatever internal webpage I want to point it to. For instance, I have  I also have  I want to be able
to see how many hits the /projectX received over the last 30 days.

The product also needs to be able to access the weblogs within a zip
file, as we zip up the logs after the current month.

Any ideas?


Joe Heaton
~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: Analytics

2009-10-06 Thread Robert Cato
Take a look at Google Analytics.

Not sure it can do what you want, but the price is right.

On Tue, Oct 6, 2009 at 4:55 PM, Joe Heaton  wrote:

> What website analytic programs are you guys using?  Currently, we're using
> Weblog Expert, but it doesn't seem to be able to do what I'm looking for.
> I need something that can tell me how many hits, over x period of time, to
> whatever internal webpage I want to point it to. For instance, I have
>  I also have  I want to be able to
> see how many hits the /projectX received over the last 30 days.
> The product also needs to be able to access the weblogs within a zip file,
> as we zip up the logs after the current month.
> Any ideas?
> Thanks,
> Joe Heaton
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~


2009-10-06 Thread Joe Heaton
What website analytic programs are you guys using?  Currently, we're using 
Weblog Expert, but it doesn't seem to be able to do what I'm looking for.  

I need something that can tell me how many hits, over x period of time, to 
whatever internal webpage I want to point it to. For instance, I have  I also have  I want to be able to see 
how many hits the /projectX received over the last 30 days.

The product also needs to be able to access the weblogs within a zip file, as 
we zip up the logs after the current month.

Any ideas?


Joe Heaton
~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: OT: Early Friday Funny

2009-10-06 Thread Micheal Espinola Jr


On Tue, Oct 6, 2009 at 4:29 PM, Roger Wright  wrote:

> Bring it!
> Roger Wright
> ___

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 3:21 PM, G.Waleed Kavalec  wrote:
> My gmail password is used NOWHERE else.

Username: kavalec
Password: used NOWHERE else

  Hey, it didn't work!  ;-)

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Phil Brutsche
I think you meant to say "As long as you have 2000 Pro or XP Pro, no
separate TS license needed".

If you have a home-user Windows OS (Win9x, XP Home, Vista Home, Win7
Home), you need TS CALs.

If you have a non-Windows OS (Mac OS X or *NIX through any of the really
sucky open source RDP clients), you need TS CALs.

If you have a business-oriented Windows OS newer than XP, you need TS
CALs. I distinctly remember that our Vista Business machines consumed a
TS CAL when we were still using a Windows 2000 TS.

Kurt Buff wrote:
> Lovely. I knew there was a reason why we haven't switched away from
> our Win2k TS server to something newer. With that, as long as you have
> XP or newer, no separate TS license needed.


Phil Brutsche

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

OT: Early Friday Funny

2009-10-06 Thread Roger Wright
Bring it!

Roger Wright

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Kurt Buff
On Tue, Oct 6, 2009 at 10:50, Ben Scott  wrote:
> On Tue, Oct 6, 2009 at 1:41 PM, Free, Bob  wrote:
>> Still won't help. TS Licensing still has no notion of concurrency.
>  To amplify what Bob is saying:
>  Every client using your server must have a CAL.  CALs are *not*
> assigned to servers, they're assigned to clients.
>  The client that gets the CAL assigned to it can be a warm body
> ("user") or a piece of equipment ("device").  But one of those two
> must have a CAL assigned it.
>  If you have one Terminal Server, with 100 users (each with their own
> PC), you need 100 CALs.  Even if you only have *one* person logging on
> at a time, you still need 100 CALs.
> -- Ben

Lovely. I knew there was a reason why we haven't switched away from
our Win2k TS server to something newer. With that, as long as you have
XP or newer, no separate TS license needed.


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Sherry Abercrombie
Nothing really, just this from,2933,561240,00.html?test=latestnews

On Tue, Oct 6, 2009 at 2:45 PM, Micheal Espinola Jr <> wrote:

> Last I heard, a guestimate of 10,028 accounts were listed between user
> names and, and that was taken
> from a shortlist posted to
> I also heard that there is a ~30,000 list of Yahoo and AOL usernames and
> passwords.  And another ~20,000 of Hotmail, Yahoo, AOL, Google and other
> service providers accounts. Google also claims to have found yet another
> list.
> Has anyone heard anything else?
> --
> ME2
> On Tue, Oct 6, 2009 at 12:16 PM, Ben Scott  wrote:
>> On Tue, Oct 6, 2009 at 11:22 AM, Carl Houseman 
>> wrote:
>> > It would seem this only affects accounts of those who've fallen victim
>> to a
>> > phishing scheme.
>>  So, in other words, if you've given someone else your password, they
>> probabbly have it?
>>  How is it this is breaking for all those accounts, all at once, on
>> multiple services?  Did someone collect credentials via phishing
>> across several services and over several months, and then post them
>> all, all at once?
>>  I suspect the information seen so far is incomplete or inaccurate.
>> -- Ben
>> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
>> ~   ~

Sherry Abercrombie

"Any sufficiently advanced technology is indistinguishable from magic."
Arthur C. Clarke

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: my c: drive shows as a network drive

2009-10-06 Thread
Looks like this is related to terminal services on the 2003 box.  When
logging in at the console, the drive mappings appear as they should be. 
I'm guessing disabling com port mapping may fix this.  I'm just not sure
how it goes this way... ?

Original Message:
Date: Tue, 6 Oct 2009 14:52:07 -0400
Subject: my c: drive shows as a network drive

I didn't build this server, I just noticed this the other day... 

This server has (1) physical disk with 2 partitions according to Disk
Management in Windows 2003.  The C: drive is 12GB (named "Enterprise"), and
D: is 20GB (named "Data").

Yet, when I open My Computer (Details view).  I see...  Under "hard disk
drives" my "Data (D:)" drive as Local Disk in the 'type' column...  and
under "network drives" I see "com1 on 'TSclient' (C:)" with Disconnected
Network Drive in the 'type' column.

Again, I just started looking at this started and I didn't build it. Anyone
ever seen anything like this?

Server performs as expected... it's just throwing me off as to what is
going on.

JR - Microsoft® Exchange solutions from a leading provider -

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~ – What can On Demand Business Solutions do for you?

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Micheal Espinola Jr
Last I heard, a guestimate of 10,028 accounts were listed between user names and, and that was taken from a
shortlist posted to

I also heard that there is a ~30,000 list of Yahoo and AOL usernames and
passwords.  And another ~20,000 of Hotmail, Yahoo, AOL, Google and other
service providers accounts. Google also claims to have found yet another

Has anyone heard anything else?


On Tue, Oct 6, 2009 at 12:16 PM, Ben Scott  wrote:

> On Tue, Oct 6, 2009 at 11:22 AM, Carl Houseman 
> wrote:
> > It would seem this only affects accounts of those who've fallen victim to
> a
> > phishing scheme.
>  So, in other words, if you've given someone else your password, they
> probabbly have it?
>  How is it this is breaking for all those accounts, all at once, on
> multiple services?  Did someone collect credentials via phishing
> across several services and over several months, and then post them
> all, all at once?
>  I suspect the information seen so far is incomplete or inaccurate.
> -- Ben
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Phil Brutsche
One caveat to keep in mind is you need to be current on your SA to be
able to change from device to user CALs (or vice versa).

wjh wrote:
> I have successfully (after hours of being bounced around on the phone)
> successfully gotten CALs transferred from device to user CALs.  It was
> frustrating bouncing from tech support to licensing to techs upport,
> getting disconnected, starting over, but eventually it happened.


Phil Brutsche

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread G.Waleed Kavalec
My gmail password is used NOWHERE else.

On Tue, Oct 6, 2009 at 8:52 AM, Micheal Espinola Jr <> wrote:

> I missed this yesterday, did you?
>> Microsoft has confirmed that thousands of Windows Live accounts have been
>> compromised with their passwords posted online. Mainstream media such as the
>> BBC are also carrying the story. Some information is posted 
>> here
>> .
>> UPDATE: Gmail and Yahoo are also affected by the compromise. Change all
>> passwords on any of these popular webmail sites.
>> Some does and don'ts:
>>- Do change your passwords on a regular basis (every six months or so)
>>- Do use long complex pass-phrases rather than passwords where you can
>>- Do change all of your passwords if you notice something suspicious
>>- Do take identity theft seriously
>>- Do use up-to-date anti-virus and a firewall
>>- Do NOT click on links in emails, ever
>>- Do NOT use the same password at multiple sites
> --
> ME2


Gregory Waleed Kavalec
What matters?...
Only the flicker of light within the darkness,
the feeling of warmth within the cold,
the knowledge of love within the void.
 — Joan Walsh Anglund

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: Distributed File System

2009-10-06 Thread Sean Martin
I haven't played with 2008 DFS yet, so bear with me.

It looks like you've setup
\\%servername%\sharesas your DFS
Folder Target (share). The path to that would be
\\domain\shares . In your original post, you stated
that the folder target (shares) does not have any NTFS permissions. I
believe that may be where your problem lies. The user would need to be able
to traverse the directory to access the resources within it.

1) Yes. I believe using Everyone:Full Control is the accepted practice, and
using NTFS to assign granular rights.
2) Yes, the folder target needs to be shared.

The user should be able to access
the NTFS permissions are setup correctly.

- Sean

On Tue, Oct 6, 2009 at 8:46 AM, Terri Esham  wrote:

> First, I'm happy to hear you are recovering and really appreciate your
> willingness to assist.
> When I setup the directories they were initially shared, however, I
> replicated them to a new server and, of course, the shared permissions did
> not replicate.
> Went I went through the DFS wizard, I did create the AD share.
> What help I need.
> 1.  In order for a user to get access over the network to a shared folder
> using DFS, do you have to have the share permissions set?
> 2.  Is there anyway not to use share permissions to grant access over the
> network if it is a DFS share or do you still have to set share permissions
> to everyone full and control rights through the NTFS settings?
> How would I setup the following DFS shares:
> Domain:  Houston
> AD Share:  Shares
> DFS Folder name:  Projects with a target folder called Joint Use
> The Joint User directory has the following subfolders:  AB, CD, ED, EF .
> The subfolders in Joint Use do have share permissions set, but they do have
> NTFS permissions set.
> Does the Joint User folder have to be shared with everyone full rights?  Do
> the subfolders in Joint Use, AB, CD, ED, etc., have to have share
> permissions set or is the NTFS permissions enough?
> Where would a user who has NTFS permissions to the CD folder under joint
> use point there network place to?  \\houston\shares\projects\CD?
> Thank you so much.
> On DFS server:
> namespace is test1
> ad share is called shares
> folder is called projects with target to  joint use
> In the target "joint use" there are folders called:  AB, CD, ED, GF - These
> folders do not share share permissions set, but they do have
> Daniel Rodriguez said the following on 10/6/2009 10:54 AM:
> When you setup the directories did you setup them up to be shared,
> initially?
> When you went through the wizard to setup the DFS, did you create the AD
> Share?
> What help are you needing? I am sitting here are home, still recovering
> from surgery and would love to have some distraction. :)
> On Tue, Oct 6, 2009 at 9:52 AM, Terri Esham  wrote:
>> I'm trying to setup a Distributed File System for the first time and am
>> having a heck of a time getting the permissions setup correctly.  I'm
>> setting it up on a Windows 2008 DC running in Windows 2008 mode.  I've
>> created the namespace, the folder under the namespace and a target
>> folder.  When I setup the namespace, I accepted all the defaults.  The
>> problem is when I try to access the share by going to
>> \\domainname\namespacename\namespacefolder, I am prompted for a username
>> and password even though I have already authenticated to the domain.
>> Do I have to grant special permissions to the namespace folder and/or
>> the target folder.  The target folder's share permissions are everyone
>> full rights with no NTFS permissions set.  The NTFS permissions are set
>> on each folder under the target folder directory.  The folders under the
>> target folder directory do not have any share permissions.Do I have
>> to grant NTFS permissions of traverse/read, etc., to the target folder
>> in order to traverse through it to get to the other folders?  Must the
>> folders under the target folder have share permissions set in addition
>> to NTFS permissions?
>> I've had no training in DFS so I'm sure I'm asking some stupid
>> questions.  However, I really want to set it up right the first time.
>> Is there a good book that depicts this or is there a forum you could
>> point me to?  Any help will be greatly appreciated.
>> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
>> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread wjh
I have successfully (after hours of being bounced around on the phone) 
successfully gotten CALs transferred from device to user CALs.  It was 
frustrating bouncing from tech support to licensing to techs upport, 
getting disconnected, starting over, but eventually it happened.


Jeff Brown wrote:
> Thank you.  Very well put.  BUT, if what I'm reading is correct, with 
> device cal's when your number is issued, you are done, no more 
> connections are allowed until one is freed up.  I own 70 device cals. 
>  I have less than 70 users logging in, but many of them log in from 2 
> or 3 different machines and we run out because of that.
> If I had purchased user licenses, and if I understand what I have 
> read, even when/if my licenses were exceeded my users would not be 
> denied access to the terminal server.  It was an unfortunate choice 
> for us.  We intend to be compliant with our licenses ALL THE TIME, so 
> we aren't just looking for a way to cheat MS.  If I had purchased per 
> user licenses I would not have a problem.  I have fewer than 70 users 
> accessing the TS servers I am absolutely sure.
> On Tue, Oct 6, 2009 at 12:50 PM, Ben Scott  > wrote:
> On Tue, Oct 6, 2009 at 1:41 PM, Free, Bob  > wrote:
> > Still won't help. TS Licensing still has no notion of concurrency.
>  To amplify what Bob is saying:
>  Every client using your server must have a CAL.  CALs are *not*
> assigned to servers, they're assigned to clients.
>  The client that gets the CAL assigned to it can be a warm body
> ("user") or a piece of equipment ("device").  But one of those two
> must have a CAL assigned it.
>  If you have one Terminal Server, with 100 users (each with their own
> PC), you need 100 CALs.  Even if you only have *one* person logging on
> at a time, you still need 100 CALs.
> -- Ben
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

my c: drive shows as a network drive

2009-10-06 Thread
I didn't build this server, I just noticed this the other day... 

This server has (1) physical disk with 2 partitions according to Disk
Management in Windows 2003.  The C: drive is 12GB (named "Enterprise"), and
D: is 20GB (named "Data").

Yet, when I open My Computer (Details view).  I see...  Under "hard disk
drives" my "Data (D:)" drive as Local Disk in the 'type' column...  and
under "network drives" I see "com1 on 'TSclient' (C:)" with Disconnected
Network Drive in the 'type' column.

Again, I just started looking at this started and I didn't build it. Anyone
ever seen anything like this?

Server performs as expected... it's just throwing me off as to what is
going on.

JR - Microsoft® Exchange solutions from a leading provider -

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Jeff Brown
Thank you.  Very well put.  BUT, if what I'm reading is correct, with device
cal's when your number is issued, you are done, no more connections are
allowed until one is freed up.  I own 70 device cals.  I have less than 70
users logging in, but many of them log in from 2 or 3 different machines and
we run out because of that.
If I had purchased user licenses, and if I understand what I have read, even
when/if my licenses were exceeded my users would not be denied access to the
terminal server.  It was an unfortunate choice for us.  We intend to be
compliant with our licenses ALL THE TIME, so we aren't just looking for a
way to cheat MS.  If I had purchased per user licenses I would not have a
problem.  I have fewer than 70 users accessing the TS servers I am
absolutely sure.

On Tue, Oct 6, 2009 at 12:50 PM, Ben Scott  wrote:

> On Tue, Oct 6, 2009 at 1:41 PM, Free, Bob  wrote:
> > Still won't help. TS Licensing still has no notion of concurrency.
>   To amplify what Bob is saying:
>  Every client using your server must have a CAL.  CALs are *not*
> assigned to servers, they're assigned to clients.
>  The client that gets the CAL assigned to it can be a warm body
> ("user") or a piece of equipment ("device").  But one of those two
> must have a CAL assigned it.
>  If you have one Terminal Server, with 100 users (each with their own
> PC), you need 100 CALs.  Even if you only have *one* person logging on
> at a time, you still need 100 CALs.
> -- Ben
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 1:41 PM, Free, Bob  wrote:
> Still won't help. TS Licensing still has no notion of concurrency.

  To amplify what Bob is saying:

  Every client using your server must have a CAL.  CALs are *not*
assigned to servers, they're assigned to clients.

  The client that gets the CAL assigned to it can be a warm body
("user") or a piece of equipment ("device").  But one of those two
must have a CAL assigned it.

  If you have one Terminal Server, with 100 users (each with their own
PC), you need 100 CALs.  Even if you only have *one* person logging on
at a time, you still need 100 CALs.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: TS Licensing

2009-10-06 Thread Free, Bob
Still won't help. TS Licensing still has no notion of concurrency.

-Original Message-
From: Kurt Buff [] 
Sent: Tuesday, October 06, 2009 9:54 AM
To: NT System Admin Issues
Subject: Re: TS Licensing

Oh, yah. That's correct.

My bad.

On Tue, Oct 6, 2009 at 08:50, Jeff Brown <> wrote:
> If my understanding is correct, that will only help if you are using "user"
> cal's. ��I would strongly recommend going that route.
> On Tue, Oct 6, 2009 at 10:37 AM, Kurt Buff  wrote:
>> Ah, this makes a bit more sense.
>> One way to handle this, I think, is to set timeouts for sessions. I'd
>> set it for a 4-hour or 8-hour timeout, so that if they are logged in
>> and idle for longer than that their session gets logged out.
>> Kurt
>> On Mon, Oct 5, 2009 at 21:38, Jeff Brown <> wrote:
>> > Makes sense, but it looks like the Licensing server is telling us
>> > not both and I don't see an option around that.
>> > This is definitely not cut and dried.���I really thought device CALS was
>> > the
>> > way to go, because we have a lot of "shared" computer space, and users
>> > that
>> > are only on a computer 3 to 4 hours a week.���Problem is, we have opened
>> > up
>> > Remote VPN access and now their home computers are eating up those
>> > licenses.
>> >
>> >
>> >
>> > On Mon, Oct 5, 2009 at 5:29 PM, Art DeKneef  wrote:
>> >>
>> >> I go by how the business needs are. Going by your numbers you have 150
>> >> employees that used computers. How many computers do you have for the
>> >> employees to use? How many do not need TS access?
>> >>
>> >>
>> >>
>> >> If they have 50 users that need access from 75 different computers then
>> >> User CALs are used. The people can use any computer that is open. More
>> >> users
>> >> require more licenses.
>> >>
>> >>
>> >>
>> >> If they have 50 computers and these computers are access by 75 people
>> >> then
>> >> device CALs are used. This scenario allows more users without an
>> >> increase of
>> >> TS licenses.
>> >>
>> >>
>> >>
>> >> You can have both types of licenses on the same server. I do not
>> >> remember
>> >> how they are assigned other than when they are entered in the licensing
>> >> server.
>> >>
>> >>
>> >>
>> >> Hope that makes sense.
>> >>
>> >>
>> >>
>> >> Art
>> >>
>> >>
>> >>
>> >> From: Jeff Brown []
>> >> Sent: Monday, October 05, 2009 2:53 PM
>> >>
>> >> To: NT System Admin Issues
>> >> Subject: TS Licensing
>> >>
>> >>
>> >>
>> >> We use TS extensively, we have less than 200 employees, 50+ that don't
>> >> use
>> >> computers at all.���We have 70 TS CAL's and have had trouble running
>> >> short on
>> >> those.���Up to this point we have purchased "device" CAL's and are
>> >> thinking
>> >> we might ��be better off adding "user" CAL's?���Nothing fancy, all our
>> >> servers
>> >> are W2k3 SP2 and our clients are XP Pro�� Everything works, we are just
>> >> running out of licenses. ��Wondering if anyone out there has 2 licenses
>> >> servers up so they can run both types and how does that work for you(if
>> >> it
>> >> is even possible to do on one network??)���(yes, we have 25 temporary
>> >> licenses, those are plumb full as well)
>> >>
>> >>
>> >>
>> >> thanks for any help.
>> >>
>> >>
>> >>
>> >> jeff
>> >>
>> >>
>> >>
>> >>
>> >>
>> >>
>> >>
>> >>
>> >
>> >
>> >
>> >
>> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
>> ~ >

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Kurt Buff
Oh, yah. That's correct.

My bad.

On Tue, Oct 6, 2009 at 08:50, Jeff Brown <> wrote:
> If my understanding is correct, that will only help if you are using "user"
> cal's.  I would strongly recommend going that route.
> On Tue, Oct 6, 2009 at 10:37 AM, Kurt Buff  wrote:
>> Ah, this makes a bit more sense.
>> One way to handle this, I think, is to set timeouts for sessions. I'd
>> set it for a 4-hour or 8-hour timeout, so that if they are logged in
>> and idle for longer than that their session gets logged out.
>> Kurt
>> On Mon, Oct 5, 2009 at 21:38, Jeff Brown <> wrote:
>> > Makes sense, but it looks like the Licensing server is telling us
>> > not both and I don't see an option around that.
>> > This is definitely not cut and dried.  I really thought device CALS was
>> > the
>> > way to go, because we have a lot of "shared" computer space, and users
>> > that
>> > are only on a computer 3 to 4 hours a week.  Problem is, we have opened
>> > up
>> > Remote VPN access and now their home computers are eating up those
>> > licenses.
>> >
>> >
>> >
>> > On Mon, Oct 5, 2009 at 5:29 PM, Art DeKneef  wrote:
>> >>
>> >> I go by how the business needs are. Going by your numbers you have 150
>> >> employees that used computers. How many computers do you have for the
>> >> employees to use? How many do not need TS access?
>> >>
>> >>
>> >>
>> >> If they have 50 users that need access from 75 different computers then
>> >> User CALs are used. The people can use any computer that is open. More
>> >> users
>> >> require more licenses.
>> >>
>> >>
>> >>
>> >> If they have 50 computers and these computers are access by 75 people
>> >> then
>> >> device CALs are used. This scenario allows more users without an
>> >> increase of
>> >> TS licenses.
>> >>
>> >>
>> >>
>> >> You can have both types of licenses on the same server. I do not
>> >> remember
>> >> how they are assigned other than when they are entered in the licensing
>> >> server.
>> >>
>> >>
>> >>
>> >> Hope that makes sense.
>> >>
>> >>
>> >>
>> >> Art
>> >>
>> >>
>> >>
>> >> From: Jeff Brown []
>> >> Sent: Monday, October 05, 2009 2:53 PM
>> >>
>> >> To: NT System Admin Issues
>> >> Subject: TS Licensing
>> >>
>> >>
>> >>
>> >> We use TS extensively, we have less than 200 employees, 50+ that don't
>> >> use
>> >> computers at all.  We have 70 TS CAL's and have had trouble running
>> >> short on
>> >> those.  Up to this point we have purchased "device" CAL's and are
>> >> thinking
>> >> we might  be better off adding "user" CAL's?  Nothing fancy, all our
>> >> servers
>> >> are W2k3 SP2 and our clients are XP Pro.  Everything works, we are just
>> >> running out of licenses.  Wondering if anyone out there has 2 licenses
>> >> servers up so they can run both types and how does that work for you(if
>> >> it
>> >> is even possible to do on one network??)  (yes, we have 25 temporary
>> >> licenses, those are plumb full as well)
>> >>
>> >>
>> >>
>> >> thanks for any help.
>> >>
>> >>
>> >>
>> >> jeff
>> >>
>> >>
>> >>
>> >>
>> >>
>> >>
>> >>
>> >>
>> >
>> >
>> >
>> >
>> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
>> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Micheal Espinola Jr
Last update I saw was ~20,000 accounts posted online.  And I think you are
correct on the latter.  That seems to be how this story is being pieced


On Tue, Oct 6, 2009 at 12:37 PM, Ben Scott  wrote:

> On Tue, Oct 6, 2009 at 12:16 PM, Ben Scott  wrote:
> >>  How is it this is breaking for all those accounts, all at once, on
> >> multiple services?
> On Tue, Oct 6, 2009 at 12:29 PM, Micheal Espinola Jr
>  wrote:
> > Passwords have certainly been compromised, but I dont think
> > any breaking was involved.
>  I meant, "How was this news breaking all at once".  :)
>  The report is several thousand accounts, across three major
> services, and the news is breaking all at once.  Phishing is effective
> but slow, and happens pretty much continuously.  There's more here
> than what we know.
>  That said, what we don't know could be something as simple as some
> attacker just published their list of accumulated stolen credentials
> for several services.
> -- Ben
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: Distributed File System

2009-10-06 Thread Terri Esham
First, I'm happy to hear you are recovering and really appreciate your
willingness to assist.

When I setup the directories they were initially shared, however, I
replicated them to a new server and, of course, the shared permissions
did not replicate.

Went I went through the DFS wizard, I did create the AD share.

What help I need. 

1.  In order for a user to get access over the network to a shared
folder using DFS, do you have to have the share permissions set?
2.  Is there anyway not to use share permissions to grant access over
the network if it is a DFS share or do you still have to set share
permissions to everyone full and control rights through the NTFS settings?

How would I setup the following DFS shares:

Domain:  Houston
AD Share:  Shares
DFS Folder name:  Projects with a target folder called Joint Use

The Joint User directory has the following subfolders:  AB, CD, ED, EF
.  The subfolders in Joint Use do have share permissions set, but they
do have NTFS permissions set.

Does the Joint User folder have to be shared with everyone full rights? 
Do the subfolders in Joint Use, AB, CD, ED, etc., have to have share
permissions set or is the NTFS permissions enough?

Where would a user who has NTFS permissions to the CD folder under joint
use point there network place to?  \\houston\shares\projects\CD?

Thank you so much.


On DFS server:
namespace is test1
ad share is called shares
folder is called projects with target to  joint use

In the target "joint use" there are folders called:  AB, CD, ED, GF -
These folders do not share share permissions set, but they do have

Daniel Rodriguez said the following on 10/6/2009 10:54 AM:
> When you setup the directories did you setup them up to be shared,
> initially?
> When you went through the wizard to setup the DFS, did you create the
> AD Share?
> What help are you needing? I am sitting here are home, still
> recovering from surgery and would love to have some distraction. :)
> On Tue, Oct 6, 2009 at 9:52 AM, Terri Esham  > wrote:
> I'm trying to setup a Distributed File System for the first time
> and am
> having a heck of a time getting the permissions setup correctly.  I'm
> setting it up on a Windows 2008 DC running in Windows 2008 mode.  I've
> created the namespace, the folder under the namespace and a target
> folder.  When I setup the namespace, I accepted all the defaults.  The
> problem is when I try to access the share by going to
> \\domainname\namespacename\namespacefolder, I am prompted for a
> username
> and password even though I have already authenticated to the domain.
> Do I have to grant special permissions to the namespace folder and/or
> the target folder.  The target folder's share permissions are everyone
> full rights with no NTFS permissions set.  The NTFS permissions
> are set
> on each folder under the target folder directory.  The folders
> under the
> target folder directory do not have any share permissions.Do I
> have
> to grant NTFS permissions of traverse/read, etc., to the target folder
> in order to traverse through it to get to the other folders?  Must the
> folders under the target folder have share permissions set in addition
> to NTFS permissions?
> I've had no training in DFS so I'm sure I'm asking some stupid
> questions.  However, I really want to set it up right the first time.
> Is there a good book that depicts this or is there a forum you could
> point me to?  Any help will be greatly appreciated.
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Carl Houseman
Last question: Yes, that is the logical conclusion and the only one that
explains how 3 services are affected at once which is not the result of a
security breach at those services.


-Original Message-
From: Ben Scott [] 
Sent: Tuesday, October 06, 2009 12:16 PM
To: NT System Admin Issues
Subject: Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

On Tue, Oct 6, 2009 at 11:22 AM, Carl Houseman  wrote:
> It would seem this only affects accounts of those who've fallen victim to
> phishing scheme.

  So, in other words, if you've given someone else your password, they
probabbly have it?

  How is it this is breaking for all those accounts, all at once, on
multiple services?  Did someone collect credentials via phishing
across several services and over several months, and then post them
all, all at once?

  I suspect the information seen so far is incomplete or inaccurate.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 12:16 PM, Ben Scott  wrote:
>>  How is it this is breaking for all those accounts, all at once, on
>> multiple services?

On Tue, Oct 6, 2009 at 12:29 PM, Micheal Espinola Jr
> Passwords have certainly been compromised, but I dont think
> any breaking was involved.

  I meant, "How was this news breaking all at once".  :)

  The report is several thousand accounts, across three major
services, and the news is breaking all at once.  Phishing is effective
but slow, and happens pretty much continuously.  There's more here
than what we know.

  That said, what we don't know could be something as simple as some
attacker just published their list of accumulated stolen credentials
for several services.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Jim Mediger
Have you tried a Google search for KB958830 or Windows6.1_KB958830-x86.msu? 
Haven't tried the links but seems to be torrents etc. available.

I do have the files if you can find a way to get them 43MB and 36MB.


From: Jason Gauthier []
Sent: Tuesday, October 06, 2009 11:20 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC

In the subject and the email body :P

From: Richard Stovall []
Sent: Tuesday, October 06, 2009 12:13 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC

Ah.  Sorry.  I missed the part about it being installed on RC1.

From: Jason Gauthier []
Sent: Tuesday, October 06, 2009 12:11 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC

I  have a 64 and 32 bit Win7 RC.

I've downloaded both, and both give the same results on both systems.  The 
actual file in those downloads must now be for the RTM.
They definitely do not work on the RC.

From: Richard Stovall []
Sent: Tuesday, October 06, 2009 12:06 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC

Did you download the one for 64 bit systems?


From: Jason Gauthier []
Sent: Tuesday, October 06, 2009 12:05 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC

I wonder if I am missing something?  I realized it was too large as well.. just 
a moment too late.  It's like 220M!

From: Don Guyer []
Sent: Tuesday, October 06, 2009 12:02 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC

Too large to e-mail.

I got the file from that same website originally.


Don Guyer
Systems Engineer - Information Services
Prudential, Fox & Roach/Trident Group
431 W. Lancaster Avenue
Devon, PA 19333
Direct: (610) 993-3299
Fax: (610) 650-5306

From: Don Guyer []
Sent: Tuesday, October 06, 2009 11:50 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC

Will do.

Don Guyer
Systems Engineer - Information Services
Prudential, Fox & Roach/Trident Group
431 W. Lancaster Avenue
Devon, PA 19333
Direct: (610) 993-3299
Fax: (610) 650-5306

From: Jason Gauthier []
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


I downloaded the file from there, but it tells me that it is not applicable to 
my system!


   x64!  I would appreciate it! And since my zip scanner is aggressive, would 
you rename the file extension to something like .txt? ;)

Much appreciated!


From: Stephen Wimberly []
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC

Try this:

I saved this from my windows 7 x64 install and it's working just fine!
On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer>> wrote:


X86 or 64-bit? I'll Zip it and send offline.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306

From: Jason Gauthier []
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC


  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a link?   
I had to reinstall my RC, and alas.. no tools!



~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Micheal Espinola Jr
Passwords have certainly been compromised, but I dont think any breaking was
involved.  As far as I can tell from various posts in the white and black
areas, this was all 3rd-party phishing, and no server breaches occured.


On Tue, Oct 6, 2009 at 12:16 PM, Ben Scott  wrote:

> On Tue, Oct 6, 2009 at 11:22 AM, Carl Houseman 
> wrote:
> > It would seem this only affects accounts of those who've fallen victim to
> a
> > phishing scheme.
>  So, in other words, if you've given someone else your password, they
> probabbly have it?
>  How is it this is breaking for all those accounts, all at once, on
> multiple services?  Did someone collect credentials via phishing
> across several services and over several months, and then post them
> all, all at once?
>  I suspect the information seen so far is incomplete or inaccurate.
> -- Ben
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Jason Gauthier
In the subject and the email body :P


From: Richard Stovall [] 
Sent: Tuesday, October 06, 2009 12:13 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Ah.  Sorry.  I missed the part about it being installed on RC1.


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 12:11 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


I  have a 64 and 32 bit Win7 RC.


I've downloaded both, and both give the same results on both systems.
The actual file in those downloads must now be for the RTM.

They definitely do not work on the RC.



From: Richard Stovall [] 
Sent: Tuesday, October 06, 2009 12:06 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Did you download the one for 64 bit systems?






From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 12:05 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


I wonder if I am missing something?  I realized it was too large as
well.. just a moment too late.  It's like 220M!


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 12:02 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Too large to e-mail.


I got the file from that same website originally.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 11:50 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Will do.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC




I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!


























~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: printer issue

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 12:12 PM, Thomas Gonzalez
> Also, I resolved the issue, which is strange to ... so the static
> IP that was assigned *.*.1.6 was working and switched the
> last octet to .9 and it...s working.

  So you changed the IP address and it started working?

  What if you change it back -- does the trouble come back?

  If the trouble comes back, you've almost certainly got something
else on your network using the same IP address.  You probabbly want to
fix that anyway.

  If the trouble stays away, my guess would be something got screwed
up in the embedded controller in the printer, and changing the IP
address reset things to clear the trouble.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 11:22 AM, Carl Houseman  wrote:
> It would seem this only affects accounts of those who've fallen victim to a
> phishing scheme.

  So, in other words, if you've given someone else your password, they
probabbly have it?

  How is it this is breaking for all those accounts, all at once, on
multiple services?  Did someone collect credentials via phishing
across several services and over several months, and then post them
all, all at once?

  I suspect the information seen so far is incomplete or inaccurate.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Richard Stovall
Ah.  Sorry.  I missed the part about it being installed on RC1.


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 12:11 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


I  have a 64 and 32 bit Win7 RC.


I've downloaded both, and both give the same results on both systems.
The actual file in those downloads must now be for the RTM.

They definitely do not work on the RC.



From: Richard Stovall [] 
Sent: Tuesday, October 06, 2009 12:06 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Did you download the one for 64 bit systems?






From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 12:05 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


I wonder if I am missing something?  I realized it was too large as
well.. just a moment too late.  It's like 220M!


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 12:02 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Too large to e-mail.


I got the file from that same website originally.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 11:50 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Will do.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC




I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!
























~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Jason Gauthier
I  have a 64 and 32 bit Win7 RC.


I've downloaded both, and both give the same results on both systems.
The actual file in those downloads must now be for the RTM.

They definitely do not work on the RC.



From: Richard Stovall [] 
Sent: Tuesday, October 06, 2009 12:06 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Did you download the one for 64 bit systems?






From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 12:05 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


I wonder if I am missing something?  I realized it was too large as
well.. just a moment too late.  It's like 220M!


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 12:02 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Too large to e-mail.


I got the file from that same website originally.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 11:50 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Will do.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC




I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!






















~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Richard Stovall
Did you download the one for 64 bit systems?






From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 12:05 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


I wonder if I am missing something?  I realized it was too large as
well.. just a moment too late.  It's like 220M!


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 12:02 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Too large to e-mail.


I got the file from that same website originally.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 11:50 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Will do.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC




I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!




















~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Jason Gauthier
I wonder if I am missing something?  I realized it was too large as
well.. just a moment too late.  It's like 220M!


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 12:02 PM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Too large to e-mail.


I got the file from that same website originally.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 11:50 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Will do.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC




I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!


















~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Don Guyer
Too large to e-mail.


I got the file from that same website originally.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306  


From: Don Guyer [] 
Sent: Tuesday, October 06, 2009 11:50 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC


Will do.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC




I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!
















~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Don Guyer
Will do.


Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306  


From: Jason Gauthier [] 
Sent: Tuesday, October 06, 2009 11:49 AM
To: NT System Admin Issues
Subject: RE: RSAT For windows 7 RC




I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!














~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: Distributed File System

2009-10-06 Thread G.Waleed Kavalec
> I am sitting here are home, still recovering from surgery and would love
to have some distraction.
Glad to hear the recovering part.

On Tue, Oct 6, 2009 at 8:54 AM, Daniel Rodriguez  wrote:

> When you setup the directories did you setup them up to be shared,
> initially?
> When you went through the wizard to setup the DFS, did you create the AD
> Share?
> What help are you needing? I am sitting here are home, still recovering
> from surgery and would love to have some distraction. :)
> On Tue, Oct 6, 2009 at 9:52 AM, Terri Esham  wrote:
>> I'm trying to setup a Distributed File System for the first time and am
>> having a heck of a time getting the permissions setup correctly.  I'm
>> setting it up on a Windows 2008 DC running in Windows 2008 mode.  I've
>> created the namespace, the folder under the namespace and a target
>> folder.  When I setup the namespace, I accepted all the defaults.  The
>> problem is when I try to access the share by going to
>> \\domainname\namespacename\namespacefolder, I am prompted for a username
>> and password even though I have already authenticated to the domain.
>> Do I have to grant special permissions to the namespace folder and/or
>> the target folder.  The target folder's share permissions are everyone
>> full rights with no NTFS permissions set.  The NTFS permissions are set
>> on each folder under the target folder directory.  The folders under the
>> target folder directory do not have any share permissions.Do I have
>> to grant NTFS permissions of traverse/read, etc., to the target folder
>> in order to traverse through it to get to the other folders?  Must the
>> folders under the target folder have share permissions set in addition
>> to NTFS permissions?
>> I've had no training in DFS so I'm sure I'm asking some stupid
>> questions.  However, I really want to set it up right the first time.
>> Is there a good book that depicts this or is there a forum you could
>> point me to?  Any help will be greatly appreciated.
>> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
>> ~   ~


Gregory Waleed Kavalec
What matters?...
Only the flicker of light within the darkness,
the feeling of warmth within the cold,
the knowledge of love within the void.
 — Joan Walsh Anglund

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: TS Licensing

2009-10-06 Thread Free, Bob
TS Licensing is not a stateful system, a license is either used or it isn't. 
There is no notion of concurrent licensing like Citrix  

-Original Message-
From: Kurt Buff [] 
Sent: Tuesday, October 06, 2009 8:37 AM
To: NT System Admin Issues
Subject: Re: TS Licensing

Ah, this makes a bit more sense.

One way to handle this, I think, is to set timeouts for sessions. I'd
set it for a 4-hour or 8-hour timeout, so that if they are logged in
and idle for longer than that their session gets logged out.


On Mon, Oct 5, 2009 at 21:38, Jeff Brown <> wrote:
> Makes sense, but it looks like the Licensing server is telling us EITHER/OR,
> not both and I don't see an option around that.
> This is definitely not cut and dried.���I really thought device CALS was the
> way to go, because we have a lot of "shared" computer space, and users that
> are only on a computer 3 to 4 hours a week.���Problem is, we have opened up
> Remote VPN access and now their home computers are eating up those licenses.
> On Mon, Oct 5, 2009 at 5:29 PM, Art DeKneef  wrote:
>> I go by how the business needs are. Going by your numbers you have 150
>> employees that used computers. How many computers do you have for the
>> employees to use? How many do not need TS access?
>> If they have 50 users that need access from 75 different computers then
>> User CALs are used. The people can use any computer that is open. More users
>> require more licenses.
>> If they have 50 computers and these computers are access by 75 people then
>> device CALs are used. This scenario allows more users without an increase of
>> TS licenses.
>> You can have both types of licenses on the same server. I do not remember
>> how they are assigned other than when they are entered in the licensing
>> server.
>> Hope that makes sense.
>> Art
>> From: Jeff Brown []
>> Sent: Monday, October 05, 2009 2:53 PM
>> To: NT System Admin Issues
>> Subject: TS Licensing
>> We use TS extensively, we have less than 200 employees, 50+ that don't use
>> computers at all�� We have 70 TS CAL's and have had trouble running short on
>> those.���Up to this point we have purchased "device" CAL's and are thinking
>> we migh�� be better off adding "user" CAL's? ��Nothing fancy, all our servers
>> are W2k3 SP2 and our clients are XP Pro. ��Everything works, we are just
>> running out of licenses.���Wondering if anyone out there has 2 licenses
>> servers up so they can run both types and how does that work for you(if it
>> is even possible to do on one network??)���(yes, we have 25 temporary
>> licenses, those are plumb full as well)
>> thanks for any help.
>> jeff

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Jeff Brown
If my understanding is correct, that will only help if you are using "user"
cal's.  I would strongly recommend going that route.

On Tue, Oct 6, 2009 at 10:37 AM, Kurt Buff  wrote:

> Ah, this makes a bit more sense.
> One way to handle this, I think, is to set timeouts for sessions. I'd
> set it for a 4-hour or 8-hour timeout, so that if they are logged in
> and idle for longer than that their session gets logged out.
> Kurt
> On Mon, Oct 5, 2009 at 21:38, Jeff Brown <> wrote:
> > Makes sense, but it looks like the Licensing server is telling us
> > not both and I don't see an option around that.
> > This is definitely not cut and dried.  I really thought device CALS was
> the
> > way to go, because we have a lot of "shared" computer space, and users
> that
> > are only on a computer 3 to 4 hours a week.  Problem is, we have opened
> up
> > Remote VPN access and now their home computers are eating up those
> licenses.
> >
> >
> >
> > On Mon, Oct 5, 2009 at 5:29 PM, Art DeKneef  wrote:
> >>
> >> I go by how the business needs are. Going by your numbers you have 150
> >> employees that used computers. How many computers do you have for the
> >> employees to use? How many do not need TS access?
> >>
> >>
> >>
> >> If they have 50 users that need access from 75 different computers then
> >> User CALs are used. The people can use any computer that is open. More
> users
> >> require more licenses.
> >>
> >>
> >>
> >> If they have 50 computers and these computers are access by 75 people
> then
> >> device CALs are used. This scenario allows more users without an
> increase of
> >> TS licenses.
> >>
> >>
> >>
> >> You can have both types of licenses on the same server. I do not
> remember
> >> how they are assigned other than when they are entered in the licensing
> >> server.
> >>
> >>
> >>
> >> Hope that makes sense.
> >>
> >>
> >>
> >> Art
> >>
> >>
> >>
> >> From: Jeff Brown []
> >> Sent: Monday, October 05, 2009 2:53 PM
> >>
> >> To: NT System Admin Issues
> >> Subject: TS Licensing
> >>
> >>
> >>
> >> We use TS extensively, we have less than 200 employees, 50+ that don't
> use
> >> computers at all.  We have 70 TS CAL's and have had trouble running
> short on
> >> those.  Up to this point we have purchased "device" CAL's and are
> thinking
> >> we might  be better off adding "user" CAL's?  Nothing fancy, all our
> servers
> >> are W2k3 SP2 and our clients are XP Pro.  Everything works, we are just
> >> running out of licenses.  Wondering if anyone out there has 2 licenses
> >> servers up so they can run both types and how does that work for you(if
> it
> >> is even possible to do on one network??)  (yes, we have 25 temporary
> >> licenses, those are plumb full as well)
> >>
> >>
> >>
> >> thanks for any help.
> >>
> >>
> >>
> >> jeff
> >>
> >>
> >>
> >>
> >>
> >>
> >>
> >>
> >
> >
> >
> >
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Jason Gauthier


I downloaded the file from there, but it tells me that it is not
applicable to my system!




   x64!  I would appreciate it! And since my zip scanner is aggressive,
would you rename the file extension to something like .txt? ;)


Much appreciated!




From: Stephen Wimberly [] 
Sent: Tuesday, October 06, 2009 9:34 AM
To: NT System Admin Issues
Subject: Re: RSAT For windows 7 RC


Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer 



X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!












~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Murray Freeman
I've got a couple of questions. First, I have an account with AT&T and
can access it thru, I can also access it thru Windows Live. My
question is, is this email account now in jeopardy? Is it necessary to
change the password?

From: James Kerr [] 
Sent: Tuesday, October 06, 2009 10:29 AM
To: NT System Admin Issues
Subject: Re: SANS Diary: Time to change your hotmail/gmail/yahoo

Yeah exactly, only goons who respond to phishing schemes were affected.

- Original Message - 
From: Carl Houseman   
To: NT System Admin Issues
Sent: Tuesday, October 06, 2009 11:22 AM
Subject: RE: SANS Diary: Time to change your hotmail/gmail/yahoo

It would seem this only affects accounts of those who've fallen
victim to a phishing scheme.  If you haven't entered your
Live/Gmail/Hotmail password on a bogus website, there's no immediate
need to change passwords.


From: Kim Longenbaugh [] 
Sent: Tuesday, October 06, 2009 11:00 AM
To: NT System Admin Issues
Subject: RE: SANS Diary: Time to change your hotmail/gmail/yahoo


Yes, I missed it too.  Thanks for the post.  Gotta run, I'm busy
changing passwords


From: Micheal Espinola Jr [] 
Sent: Tuesday, October 06, 2009 9:53 AM
To: NT System Admin Issues
Subject: SANS Diary: Time to change your hotmail/gmail/yahoo


I missed this yesterday, did you?



Microsoft has confirmed that thousands of Windows Live
accounts have been compromised with their passwords posted online.
Mainstream media such as the BBC are also carrying the story. Some
information is posted here

UPDATE: Gmail and Yahoo are also affected by the
compromise. Change all passwords on any of these popular webmail sites. 

Some does and don'ts:

*   Do change your passwords on a regular basis
(every six months or so) 
*   Do use long complex pass-phrases rather than
passwords where you can 
*   Do change all of your passwords if you notice
something suspicious 
*   Do take identity theft seriously 
*   Do use up-to-date anti-virus and a firewall 
*   Do NOT click on links in emails, ever 
*   Do NOT use the same password at multiple sites 







~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Micheal Espinola Jr
Sounds like the majority of my user-base unfortunately, so for me, this is a
warning that has to go out.


On Tue, Oct 6, 2009 at 11:29 AM, James Kerr  wrote:

>  Yeah exactly, only goons who respond to phishing schemes were affected.
>  - Original Message -
> *From:* Carl Houseman 
> *To:* NT System Admin Issues 
>  *Sent:* Tuesday, October 06, 2009 11:22 AM
> *Subject:* RE: SANS Diary: Time to change your hotmail/gmail/yahoo
> password
>  It would seem this only affects accounts of those who've fallen victim to
> a phishing scheme.  If you haven't entered your Live/Gmail/Hotmail password
> on a bogus website, there's no immediate need to change passwords.
> *From:* Kim Longenbaugh []
> *Sent:* Tuesday, October 06, 2009 11:00 AM
> *To:* NT System Admin Issues
> *Subject:* RE: SANS Diary: Time to change your hotmail/gmail/yahoo
> password
> Yes, I missed it too.  Thanks for the post.  Gotta run, I’m busy changing
> passwords….
>  --
> *From:* Micheal Espinola Jr []
>  *Sent:* Tuesday, October 06, 2009 9:53 AM
> *To:* NT System Admin Issues
> *Subject:* SANS Diary: Time to change your hotmail/gmail/yahoo password
> I missed this yesterday, did you?
>  Microsoft has confirmed that thousands of Windows Live accounts have been
> compromised with their passwords posted online. Mainstream media such as the
> BBC are also carrying the story. Some information is posted 
> here
> .
> UPDATE: Gmail and Yahoo are also affected by the compromise. Change all
> passwords on any of these popular webmail sites.
> Some does and don'ts:
>- Do change your passwords on a regular basis (every six months or so)
>- Do use long complex pass-phrases rather than passwords where you can
>- Do change all of your passwords if you notice something suspicious
>- Do take identity theft seriously
>- Do use up-to-date anti-virus and a firewall
>- Do NOT click on links in emails, ever
>- Do NOT use the same password at multiple sites
> --
> ME2

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Kurt Buff
Ah, this makes a bit more sense.

One way to handle this, I think, is to set timeouts for sessions. I'd
set it for a 4-hour or 8-hour timeout, so that if they are logged in
and idle for longer than that their session gets logged out.


On Mon, Oct 5, 2009 at 21:38, Jeff Brown <> wrote:
> Makes sense, but it looks like the Licensing server is telling us EITHER/OR,
> not both and I don't see an option around that.
> This is definitely not cut and dried.  I really thought device CALS was the
> way to go, because we have a lot of "shared" computer space, and users that
> are only on a computer 3 to 4 hours a week.  Problem is, we have opened up
> Remote VPN access and now their home computers are eating up those licenses.
> On Mon, Oct 5, 2009 at 5:29 PM, Art DeKneef  wrote:
>> I go by how the business needs are. Going by your numbers you have 150
>> employees that used computers. How many computers do you have for the
>> employees to use? How many do not need TS access?
>> If they have 50 users that need access from 75 different computers then
>> User CALs are used. The people can use any computer that is open. More users
>> require more licenses.
>> If they have 50 computers and these computers are access by 75 people then
>> device CALs are used. This scenario allows more users without an increase of
>> TS licenses.
>> You can have both types of licenses on the same server. I do not remember
>> how they are assigned other than when they are entered in the licensing
>> server.
>> Hope that makes sense.
>> Art
>> From: Jeff Brown []
>> Sent: Monday, October 05, 2009 2:53 PM
>> To: NT System Admin Issues
>> Subject: TS Licensing
>> We use TS extensively, we have less than 200 employees, 50+ that don't use
>> computers at all.  We have 70 TS CAL's and have had trouble running short on
>> those.  Up to this point we have purchased "device" CAL's and are thinking
>> we might  be better off adding "user" CAL's?  Nothing fancy, all our servers
>> are W2k3 SP2 and our clients are XP Pro.  Everything works, we are just
>> running out of licenses.  Wondering if anyone out there has 2 licenses
>> servers up so they can run both types and how does that work for you(if it
>> is even possible to do on one network??)  (yes, we have 25 temporary
>> licenses, those are plumb full as well)
>> thanks for any help.
>> jeff

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: TS Licensing

2009-10-06 Thread Jeff Brown
Thanks for all the input.  In retrospect, i wish we had chosen user CAL's
NOT device CAL's from the start.  I would recommend that path to anyone in
the future.

On Tue, Oct 6, 2009 at 12:57 AM, Brian Desmond wrote:

> *IIRC it’s either/or. Also IIRC there’s some sort of timer that kicsk in
> so you can’t move user CALs from user A to B to C in three days. Whether the
> software implements this or it’s just on paper I have no idea.*
> * *
> *Thanks,*
> *Brian Desmond*
> **
> * *
> *c - 312.731.3132*
> * *
> *From:* Jeff Brown []
> *Sent:* Monday, October 05, 2009 4:53 PM
> *To:* NT System Admin Issues
> *Subject:* TS Licensing
> We use TS extensively, we have less than 200 employees, 50+ that don't use
> computers at all.  We have 70 TS CAL's and have had trouble running short on
> those.  Up to this point we have purchased "device" CAL's and are thinking
> we might  be better off adding "user" CAL's?  Nothing fancy, all our servers
> are W2k3 SP2 and our clients are XP Pro.  Everything works, we are just
> running out of licenses.  Wondering if anyone out there has 2 licenses
> servers up so they can run both types and how does that work for you(if it
> is even possible to do on one network??)  (yes, we have 25 temporary
> licenses, those are plumb full as well)
> thanks for any help.
> jeff

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread James Kerr
Yeah exactly, only goons who respond to phishing schemes were affected.
  - Original Message - 
  From: Carl Houseman 
  To: NT System Admin Issues 
  Sent: Tuesday, October 06, 2009 11:22 AM
  Subject: RE: SANS Diary: Time to change your hotmail/gmail/yahoo password

  It would seem this only affects accounts of those who've fallen victim to a 
phishing scheme.  If you haven't entered your Live/Gmail/Hotmail password on a 
bogus website, there's no immediate need to change passwords.


  From: Kim Longenbaugh [] 
  Sent: Tuesday, October 06, 2009 11:00 AM
  To: NT System Admin Issues
  Subject: RE: SANS Diary: Time to change your hotmail/gmail/yahoo password


  Yes, I missed it too.  Thanks for the post.  Gotta run, I'm busy changing 



  From: Micheal Espinola Jr [] 
  Sent: Tuesday, October 06, 2009 9:53 AM
  To: NT System Admin Issues
  Subject: SANS Diary: Time to change your hotmail/gmail/yahoo password


  I missed this yesterday, did you?



Microsoft has confirmed that thousands of Windows Live accounts have been 
compromised with their passwords posted online. Mainstream media such as the 
BBC are also carrying the story. Some information is posted here.

UPDATE: Gmail and Yahoo are also affected by the compromise. Change all 
passwords on any of these popular webmail sites. 

Some does and don'ts:

  a.. Do change your passwords on a regular basis (every six months or so) 
  b.. Do use long complex pass-phrases rather than passwords where you can 
  c.. Do change all of your passwords if you notice something suspicious 
  d.. Do take identity theft seriously 
  e.. Do use up-to-date anti-virus and a firewall 
  f.. Do NOT click on links in emails, ever 
  g.. Do NOT use the same password at multiple sites 




~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread David Lum
Yeah I didn't catch it until 6am today...kind of short on the Gmail an Yahoo 
stuff too.

From: Micheal Espinola Jr []
Sent: Tuesday, October 06, 2009 7:53 AM
To: NT System Admin Issues
Subject: SANS Diary: Time to change your hotmail/gmail/yahoo password

I missed this yesterday, did you?

Microsoft has confirmed that thousands of Windows Live accounts have been 
compromised with their passwords posted online. Mainstream media such as the 
BBC are also carrying the story. Some information is posted 

UPDATE: Gmail and Yahoo are also affected by the compromise. Change all 
passwords on any of these popular webmail sites.

Some does and don'ts:

 *   Do change your passwords on a regular basis (every six months or so)
 *   Do use long complex pass-phrases rather than passwords where you can
 *   Do change all of your passwords if you notice something suspicious
 *   Do take identity theft seriously
 *   Do use up-to-date anti-virus and a firewall
 *   Do NOT click on links in emails, ever
 *   Do NOT use the same password at multiple sites


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Carl Houseman
It would seem this only affects accounts of those who've fallen victim to a
phishing scheme.  If you haven't entered your Live/Gmail/Hotmail password on
a bogus website, there's no immediate need to change passwords.


From: Kim Longenbaugh [] 
Sent: Tuesday, October 06, 2009 11:00 AM
To: NT System Admin Issues
Subject: RE: SANS Diary: Time to change your hotmail/gmail/yahoo password


Yes, I missed it too.  Thanks for the post.  Gotta run, I'm busy changing



From: Micheal Espinola Jr [] 
Sent: Tuesday, October 06, 2009 9:53 AM
To: NT System Admin Issues
Subject: SANS Diary: Time to change your hotmail/gmail/yahoo password


I missed this yesterday, did you?



Microsoft has confirmed that thousands of Windows Live accounts have been
compromised with their passwords posted online. Mainstream media such as the
BBC are also carrying the story. Some information is posted here

UPDATE: Gmail and Yahoo are also affected by the compromise. Change all
passwords on any of these popular webmail sites. 

Some does and don'ts:

*   Do change your passwords on a regular basis (every six months or so)
*   Do use long complex pass-phrases rather than passwords where you can
*   Do change all of your passwords if you notice something suspicious
*   Do take identity theft seriously
*   Do use up-to-date anti-virus and a firewall
*   Do NOT click on links in emails, ever
*   Do NOT use the same password at multiple sites



~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: printer issue

2009-10-06 Thread Daniel Rodriguez
Do you have the printer's IP Address Staticly Set, or do you have DHCP
turned on on the printer?

On Tue, Oct 6, 2009 at 11:08 AM, Thomas Gonzalez <> wrote:

>  So I’m a little stumped. First environment: Win2k3 – SP1 / print server
> We are a Canon 3035 / 5185 and 7105 shop (multifunction). Well last week
> from what I can tell, the 7105 has stopped printing from a workstation to
> the device. When a job is sent, on the server this is the error I receive:
> Has anyone ever encountered this before? There have been no changes to the
> environment.
> Thomas
> **
> *GSSWT's Vision Statement: Our vision is to be a high performing,
> girl-focused staff with the desire and skill set to provide the highest
> standard of support that enriches, empowers and energizes the local Girl
> Scout Movement.  In doing so, we create a lifetime of inspiration through
> Girl Scout experiences that are so relevant and inclusive every girl will
> want to be a part.*

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~<><>

RE: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Steven M. Caesare


Thanks ME2.




From: Micheal Espinola Jr [] 
Sent: Tuesday, October 06, 2009 10:53 AM
To: NT System Admin Issues
Subject: SANS Diary: Time to change your hotmail/gmail/yahoo password


I missed this yesterday, did you?



Microsoft has confirmed that thousands of Windows Live accounts
have been compromised with their passwords posted online. Mainstream
media such as the BBC are also carrying the story. Some information is
posted here

UPDATE: Gmail and Yahoo are also affected by the compromise.
Change all passwords on any of these popular webmail sites. 

Some does and don'ts:

*   Do change your passwords on a regular basis (every six
months or so)
*   Do use long complex pass-phrases rather than passwords
where you can
*   Do change all of your passwords if you notice something
*   Do take identity theft seriously
*   Do use up-to-date anti-virus and a firewall
*   Do NOT click on links in emails, ever
*   Do NOT use the same password at multiple sites




~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Kim Longenbaugh
Yes, I missed it too.  Thanks for the post.  Gotta run, I'm busy
changing passwords


From: Micheal Espinola Jr [] 
Sent: Tuesday, October 06, 2009 9:53 AM
To: NT System Admin Issues
Subject: SANS Diary: Time to change your hotmail/gmail/yahoo password


I missed this yesterday, did you?



Microsoft has confirmed that thousands of Windows Live accounts
have been compromised with their passwords posted online. Mainstream
media such as the BBC are also carrying the story. Some information is
posted here

UPDATE: Gmail and Yahoo are also affected by the compromise.
Change all passwords on any of these popular webmail sites. 

Some does and don'ts:

*   Do change your passwords on a regular basis (every six
months or so)
*   Do use long complex pass-phrases rather than passwords
where you can
*   Do change all of your passwords if you notice something
*   Do take identity theft seriously
*   Do use up-to-date anti-virus and a firewall
*   Do NOT click on links in emails, ever
*   Do NOT use the same password at multiple sites




~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: Distributed File System

2009-10-06 Thread Daniel Rodriguez
When you setup the directories did you setup them up to be shared,

When you went through the wizard to setup the DFS, did you create the AD

What help are you needing? I am sitting here are home, still recovering from
surgery and would love to have some distraction. :)

On Tue, Oct 6, 2009 at 9:52 AM, Terri Esham  wrote:

> I'm trying to setup a Distributed File System for the first time and am
> having a heck of a time getting the permissions setup correctly.  I'm
> setting it up on a Windows 2008 DC running in Windows 2008 mode.  I've
> created the namespace, the folder under the namespace and a target
> folder.  When I setup the namespace, I accepted all the defaults.  The
> problem is when I try to access the share by going to
> \\domainname\namespacename\namespacefolder, I am prompted for a username
> and password even though I have already authenticated to the domain.
> Do I have to grant special permissions to the namespace folder and/or
> the target folder.  The target folder's share permissions are everyone
> full rights with no NTFS permissions set.  The NTFS permissions are set
> on each folder under the target folder directory.  The folders under the
> target folder directory do not have any share permissions.Do I have
> to grant NTFS permissions of traverse/read, etc., to the target folder
> in order to traverse through it to get to the other folders?  Must the
> folders under the target folder have share permissions set in addition
> to NTFS permissions?
> I've had no training in DFS so I'm sure I'm asking some stupid
> questions.  However, I really want to set it up right the first time.
> Is there a good book that depicts this or is there a forum you could
> point me to?  Any help will be greatly appreciated.
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

SANS Diary: Time to change your hotmail/gmail/yahoo password

2009-10-06 Thread Micheal Espinola Jr
I missed this yesterday, did you?

> Microsoft has confirmed that thousands of Windows Live accounts have been
> compromised with their passwords posted online. Mainstream media such as the
> BBC are also carrying the story. Some information is posted 
> here
> .
> UPDATE: Gmail and Yahoo are also affected by the compromise. Change all
> passwords on any of these popular webmail sites.
> Some does and don'ts:
>- Do change your passwords on a regular basis (every six months or so)
>- Do use long complex pass-phrases rather than passwords where you can
>- Do change all of your passwords if you notice something suspicious
>- Do take identity theft seriously
>- Do use up-to-date anti-virus and a firewall
>- Do NOT click on links in emails, ever
>- Do NOT use the same password at multiple sites

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: USB Boot drive Frustration

2009-10-06 Thread Tim Evans
I just ran across this:
(warning: link probably wrapped)

While I haven't used it, it seems to be a complete zip file (58 MB) with apps 
and instructions on how to set one up.


> -Original Message-
> From: Steve Kelsay []
> Sent: Tuesday, October 06, 2009 6:49 AM
> To: NT System Admin Issues
> Subject: RE: USB Boot drive Frustration
> Yes, I found the Dell install disk problem last night. It adds 4 files
> to the temp files Bart uses, but does not allow them to be deleted under
> the BART build, so the whole build fails. I am running it with a
> standard MS disk, and it is running well past that point now. Looks
> good!
> I am going to look at some of the other solutions as well, as this is
> going to be a continuing issues here.
> Thanks to everyone who has and is helping!
> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
> ~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: BES 4.1 syncing

2009-10-06 Thread Alverson, Tom (Xetron)
+1 for Martin's delete/undelete tip.  That has worked for me in the


-Original Message-
From: Martin Blackstone [] 
Sent: Tuesday, October 06, 2009 9:51 AM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

One more time. I have not had the problem reappear after this and the
user can do this themselves.
This works for calendar as well. Just change part 2 to calendar rather
address book.

You can try the steps below to see if this resolves the issue.

1)Ask the BlackBerry smartphone user to delete the Desktop [SYNC]
service book from the BlackBerry smartphone, then undelete it by
the following steps: 
a.On the Home screen of the BlackBerry smartphone, go to Options >
Advanced Options > Service Book. 
b.Highlight Desktop [SYNC], display the menu and click Delete. 
c.Confirm the delete before exiting the Service Book option. 
d.Navigate back to the Service Book option, display the menu and

Warning: The following procedures will delete either all data, or all
and applications on the BlackBerry smartphone. Back up the data prior to
performing the procedure. For instructions, see KB12487.
2)These steps only apply to BlackBerry Device Software 4.5 to 4.7.

To delete the data in the Address Book application over the wireless
and reload it from the BlackBerry(r) Enterprise Server, complete the
a.On the BlackBerry smartphone, open the Address Book application. 
b.Display the menu and click Options. 
c.Type RSET. 
Note: For BlackBerry smartphones that support SureType(r) technology,
use the
multi-tap input method.

If wireless synchronization of the Address Book application is turned
the following message will appear:
This will erase your Desktop address book, and reload it from your
After the data in the Address Book application has been deleted, the
following message will appear:
The Desktop address book has been wiped. It will be repopulated from
The Address Book application will be re-populated with Address Book data
from the BlackBerry Enterprise Server and the following message will be
Repopulation of the address book

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: BES 4.1 syncing

2009-10-06 Thread David Mazzaccaro
I have had similar problems. (rarely though)
Service: Sprint
It is usually the BB synch service which isn't running (and should be).
Yes - that would seem like nothing would synch, but some still did.
Starting it up (or bouncing the service) has always fixed it for me.

-Original Message-
From: Mark Robinson [] 
Sent: Tuesday, October 06, 2009 9:44 AM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing


I'm just picking up this thread.  I have been experiencing the exact same issue 
since we installed BES over 12 months ago.  Can I ask you guys which network 
carrier you are using?  Just wondering if there's a common theme.  We are with 


-Original Message-
From: Martin Blackstone []
Sent: 06 October 2009 14:39
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

If its just a few users, try that method I sent you. Its more complicated that 
in looks.
Also for sanities sake, ensure that in the contacts section on the BB wireless 
sync is set to yes.

-Original Message-
From: Benjamin Zachary - Lists []
Sent: Monday, October 05, 2009 6:54 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

Thanks all for the tip. I will try the remove/add of the contact on the device. 
Both my bes problems are small 3-4 users. I know at one its all of them on the 
2007 but on the other its just 1.

-Original Message-
From: Jeremy Anderson []
Sent: Monday, October 05, 2009 9:35 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

For what its worth

I have seen that exact issue before, at 2 different clients.

The bad news is, I don't know the fix.

In one case I synced the contacts using desktop manager The other was not my 
client and they reinstalled BES  (WTF?)

-Original Message-
From: Ben Scott []
Sent: Monday, October 05, 2009 6:30 PM
To: NT System Admin Issues
Subject: Re: BES 4.1 syncing

On Mon, Oct 5, 2009 at 8:54 PM, Benjamin Zachary - Lists  
>  I have a couple of sites where contacts don't seem to be syncing

  For all users on the server?  That's odd.  I've had various cases where a 
given user will have trouble, but not everyone.  Granted, there are only 11 
users on our BES, but still.

> I tried everything but removing and re-adding the device.

  I would indeed try removing and re-adding the device -- or more precisely, 
the user.  When BB Manager asks if you want to delete the BlackBerry info, say 
"Yes".  Then re-add the user and reactivate the device.  This is really 
harmless -- no user data should be lost from either server mailbox or handheld. 
 It only discards server metadata and other "behind the scenes" stuff.  (But 
remember, backups are
*always* a good idea.)

  We're running BES 4.mumble against Exchange 2003.  Behavior may be different 
against other mail servers.

> Anything else I could try?

  Before you do anything else, check the logs.  Both Windows Event Spewer and 
the BES text logs.  BES logs *gobs* of debug information to the text logs.  
This will often at least point out that there is a problem, even if you don't 
know how to fix it.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ 

Internet communications are not secure and therefore CIPS does not accept legal 
responsibility for the contents of any e-mail message sent via this medium. The 
content of any e-mail communication is the view of the individual and CIPS does 
not accept legal liability for the contents. Although this message and any 
attachments are believed to be free of virus or other defect that might affect 
any computer system into which it is received and opened, it is the 
responsibility of the recipient to ensure that it is virus free and no 
responsibility is accepted by CIPS for any loss or damage in any way arising 
from its use. 

CIPS runs the following software packages: MS Office Suite 2003, MS Visio 2003, 
MS Project 2002. Please ensure that any files you send are compatible. 
The Chartered Institute of Purchasing & Supply (CIPS) is an organisation 
incorporated under Royal Charter and is based at Easton House, Easton on the 
Hill, Stamford, Lincs PE9 3NZ, tel: +44 (0)1780 756777, and is a registered 
Charity number 1017938. CIPS Services Limited is a wholly owned subsidiary 
company of CIPS, registered in England under n

Distributed File System

2009-10-06 Thread Terri Esham
I'm trying to setup a Distributed File System for the first time and am
having a heck of a time getting the permissions setup correctly.  I'm
setting it up on a Windows 2008 DC running in Windows 2008 mode.  I've
created the namespace, the folder under the namespace and a target
folder.  When I setup the namespace, I accepted all the defaults.  The
problem is when I try to access the share by going to
\\domainname\namespacename\namespacefolder, I am prompted for a username
and password even though I have already authenticated to the domain. 

Do I have to grant special permissions to the namespace folder and/or
the target folder.  The target folder's share permissions are everyone
full rights with no NTFS permissions set.  The NTFS permissions are set
on each folder under the target folder directory.  The folders under the
target folder directory do not have any share permissions.Do I have
to grant NTFS permissions of traverse/read, etc., to the target folder
in order to traverse through it to get to the other folders?  Must the
folders under the target folder have share permissions set in addition
to NTFS permissions?

I've had no training in DFS so I'm sure I'm asking some stupid
questions.  However, I really want to set it up right the first time. 
Is there a good book that depicts this or is there a forum you could
point me to?  Any help will be greatly appreciated.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: BES 4.1 syncing

2009-10-06 Thread Martin Blackstone
One more time. I have not had the problem reappear after this and the end
user can do this themselves.
This works for calendar as well. Just change part 2 to calendar rather than
address book.

You can try the steps below to see if this resolves the issue.

1)Ask the BlackBerry smartphone user to delete the Desktop [SYNC]
service book from the BlackBerry smartphone, then undelete it by completing
the following steps: 
a.On the Home screen of the BlackBerry smartphone, go to Options >
Advanced Options > Service Book. 
b.Highlight Desktop [SYNC], display the menu and click Delete. 
c.Confirm the delete before exiting the Service Book option. 
d.Navigate back to the Service Book option, display the menu and click

Warning: The following procedures will delete either all data, or all data
and applications on the BlackBerry smartphone. Back up the data prior to
performing the procedure. For instructions, see KB12487.
2)These steps only apply to BlackBerry Device Software 4.5 to 4.7.

To delete the data in the Address Book application over the wireless network
and reload it from the BlackBerry® Enterprise Server, complete the following
a.On the BlackBerry smartphone, open the Address Book application. 
b.Display the menu and click Options. 
c.Type RSET. 
Note: For BlackBerry smartphones that support SureType® technology, use the
multi-tap input method.

If wireless synchronization of the Address Book application is turned on,
the following message will appear:
This will erase your Desktop address book, and reload it from your server.
After the data in the Address Book application has been deleted, the
following message will appear:
The Desktop address book has been wiped. It will be repopulated from your
The Address Book application will be re-populated with Address Book data
from the BlackBerry Enterprise Server and the following message will be
Repopulation of the address book

-Original Message-
From: Mark Robinson [] 
Sent: Tuesday, October 06, 2009 6:44 AM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing


I'm just picking up this thread.  I have been experiencing the exact
same issue since we installed BES over 12 months ago.  Can I ask you
guys which network carrier you are using?  Just wondering if there's a
common theme.  We are with Vodafone.


-Original Message-
From: Martin Blackstone [] 
Sent: 06 October 2009 14:39
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

If its just a few users, try that method I sent you. Its more
that in looks.
Also for sanities sake, ensure that in the contacts section on the BB
wireless sync is set to yes.

-Original Message-
From: Benjamin Zachary - Lists [] 
Sent: Monday, October 05, 2009 6:54 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

Thanks all for the tip. I will try the remove/add of the contact on the
device. Both my bes problems are small 3-4 users. I know at one its all
them on the 2007 but on the other its just 1.

-Original Message-
From: Jeremy Anderson [] 
Sent: Monday, October 05, 2009 9:35 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

For what its worth

I have seen that exact issue before, at 2 different clients.

The bad news is, I don't know the fix.

In one case I synced the contacts using desktop manager
The other was not my client and they reinstalled BES  (WTF?)

-Original Message-
From: Ben Scott [] 
Sent: Monday, October 05, 2009 6:30 PM
To: NT System Admin Issues
Subject: Re: BES 4.1 syncing

On Mon, Oct 5, 2009 at 8:54 PM, Benjamin Zachary - Lists
>  I have a couple of sites where contacts don't seem to be syncing

  For all users on the server?  That's odd.  I've had various cases
where a given user will have trouble, but not everyone.  Granted,
there are only 11 users on our BES, but still.

> I tried everything but removing and re-adding the device.

  I would indeed try removing and re-adding the device -- or more
precisely, the user.  When BB Manager asks if you want to delete the
BlackBerry info, say "Yes".  Then re-add the user and reactivate the
device.  This is really harmless -- no user data should be lost from
either server mailbox or handheld.  It only discards server metadata
and other "behind the scenes" stuff.  (But remember, backups are
*always* a good idea.)

  We're running BES 4.mumble against Exchange 2003.  Behavior may be
different against other mail servers.

> Anything else I could try?

  Before you do anything else, check the logs.  Both Windows Event
Spewer and the BES text logs.  BES logs *gobs* of debug information to
the text logs.  This will often at least point out that there is a
problem, even if you don't know how to fix it.

-- Ben

~ Finally, powerful endpo

RE: USB Boot drive Frustration

2009-10-06 Thread Steve Kelsay
Yes, I found the Dell install disk problem last night. It adds 4 files
to the temp files Bart uses, but does not allow them to be deleted under
the BART build, so the whole build fails. I am running it with a
standard MS disk, and it is running well past that point now. Looks

I am going to look at some of the other solutions as well, as this is
going to be a continuing issues here. 

Thanks to everyone who has and is helping!

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: BES 4.1 syncing

2009-10-06 Thread Mark Robinson

I'm just picking up this thread.  I have been experiencing the exact
same issue since we installed BES over 12 months ago.  Can I ask you
guys which network carrier you are using?  Just wondering if there's a
common theme.  We are with Vodafone.


-Original Message-
From: Martin Blackstone [] 
Sent: 06 October 2009 14:39
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

If its just a few users, try that method I sent you. Its more
that in looks.
Also for sanities sake, ensure that in the contacts section on the BB
wireless sync is set to yes.

-Original Message-
From: Benjamin Zachary - Lists [] 
Sent: Monday, October 05, 2009 6:54 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

Thanks all for the tip. I will try the remove/add of the contact on the
device. Both my bes problems are small 3-4 users. I know at one its all
them on the 2007 but on the other its just 1.

-Original Message-
From: Jeremy Anderson [] 
Sent: Monday, October 05, 2009 9:35 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

For what its worth

I have seen that exact issue before, at 2 different clients.

The bad news is, I don't know the fix.

In one case I synced the contacts using desktop manager
The other was not my client and they reinstalled BES  (WTF?)

-Original Message-
From: Ben Scott [] 
Sent: Monday, October 05, 2009 6:30 PM
To: NT System Admin Issues
Subject: Re: BES 4.1 syncing

On Mon, Oct 5, 2009 at 8:54 PM, Benjamin Zachary - Lists
>  I have a couple of sites where contacts don't seem to be syncing

  For all users on the server?  That's odd.  I've had various cases
where a given user will have trouble, but not everyone.  Granted,
there are only 11 users on our BES, but still.

> I tried everything but removing and re-adding the device.

  I would indeed try removing and re-adding the device -- or more
precisely, the user.  When BB Manager asks if you want to delete the
BlackBerry info, say "Yes".  Then re-add the user and reactivate the
device.  This is really harmless -- no user data should be lost from
either server mailbox or handheld.  It only discards server metadata
and other "behind the scenes" stuff.  (But remember, backups are
*always* a good idea.)

  We're running BES 4.mumble against Exchange 2003.  Behavior may be
different against other mail servers.

> Anything else I could try?

  Before you do anything else, check the logs.  Both Windows Event
Spewer and the BES text logs.  BES logs *gobs* of debug information to
the text logs.  This will often at least point out that there is a
problem, even if you don't know how to fix it.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Internet communications are not secure and therefore CIPS does not accept legal 
responsibility for the contents of any e-mail message sent via this medium. The 
content of any e-mail communication is the view of the individual and CIPS does 
not accept legal liability for the contents. Although this message and any 
attachments are believed to be free of virus or other defect that might affect 
any computer system into which it is received and opened, it is the 
responsibility of the recipient to ensure that it is virus free and no 
responsibility is accepted by CIPS for any loss or damage in any way arising 
from its use. 

CIPS runs the following software packages: MS Office Suite 2003, MS Visio 2003, 
MS Project 2002. Please ensure that any files you send are compatible. 
The Chartered Institute of Purchasing & Supply (CIPS) is an organisation 
incorporated under Royal Charter and is based at Easton House, Easton on the 
Hill, Stamford, Lincs PE9 3NZ, tel: +44 (0)1780 756777, and is a registered 
Charity number 1017938. CIPS Services Limited is a wholly owned subsidiary 
company of CIPS, registered in England under number 2610367 and is registered 
at the address shown above. Both organisations operate under a group VAT 
registration number: 3426 489 42.

Scanned by iCritical.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: USB Boot drive Frustration

2009-10-06 Thread Jon B. Lewis
I used this with a Bart CD to make a bootable USB drive, no headache



From: Steve Kelsay [] 
Sent: Tuesday, October 06, 2009 7:52 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


I do have an older BART CD. 


From: Jon B. Lewis [] 
Sent: Monday, October 05, 2009 5:27 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


Have you got a working Bart CD?


From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:04 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


Their immediate problem is to boot to a bartpe system. Every attempt I
have made using all the various web articles hit one snag or another.
PEbuilder is just not working for me today. I think I need to take a
break and relax a bit first!


From: Richard Stovall [] 
Sent: Monday, October 05, 2009 12:00 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


I asked about the OS b/c I've used the following procedure to install
Win7 on a Dell Mini 9, but it might work for XP also.  You do need a
Vista or above PC to prepare the USB drive.


Here is a similar link if all you have is XP for the preparation


I haven't tried the second method, but the source is the same Lifehacker
article -


Good luck,



From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:34 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


They are using it to reimage XP Pro machines now, but will be doing
windows 7 eventually.


From: Richard Stovall [] 
Sent: Monday, October 05, 2009 11:21 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


What OS for the new image?


From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:18 AM
To: NT System Admin Issues
Subject: USB Boot drive Frustration


Our desktop group has asked me to help them create a USB drive to boot
from in order to install their images. They have one I did for them last
year, and they need to have several more for a roll out.


I had a disk crash a month ago and have not reinstalled the software I
used to create one. I am now so frustrated, that I cannot think
straight! Last year, I believe I just used the HP storage disk format
utility, and put an XP disk in the CD drive for the boot files, and it
worked. This year, I have tried several different methods I found online
to no avail.


The first question is whether anyone knows a method  that actually
works, and the second is, does anyone know a diskcopy utility that will
duplicate the working USB to the others? The ones I found do not support
USB drives. 















~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: USB Boot drive Frustration

2009-10-06 Thread Ben Scott
On Tue, Oct 6, 2009 at 9:09 AM, Steve Kelsay  wrote:
> The problem seems to be the XP install disk which is a Dell.

  In my experience, the Dell XP OEM CDs are very generic.  They add
the OEMBIOS files to bypass Windows activation, and a couple of
drivers for the Intel SATA chipset, and that's it.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: BES 4.1 syncing

2009-10-06 Thread Martin Blackstone
If its just a few users, try that method I sent you. Its more complicated
that in looks.
Also for sanities sake, ensure that in the contacts section on the BB
wireless sync is set to yes.

-Original Message-
From: Benjamin Zachary - Lists [] 
Sent: Monday, October 05, 2009 6:54 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

Thanks all for the tip. I will try the remove/add of the contact on the
device. Both my bes problems are small 3-4 users. I know at one its all of
them on the 2007 but on the other its just 1.

-Original Message-
From: Jeremy Anderson [] 
Sent: Monday, October 05, 2009 9:35 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

For what its worth

I have seen that exact issue before, at 2 different clients.

The bad news is, I don't know the fix.

In one case I synced the contacts using desktop manager
The other was not my client and they reinstalled BES  (WTF?)

-Original Message-
From: Ben Scott [] 
Sent: Monday, October 05, 2009 6:30 PM
To: NT System Admin Issues
Subject: Re: BES 4.1 syncing

On Mon, Oct 5, 2009 at 8:54 PM, Benjamin Zachary - Lists
>  I have a couple of sites where contacts don't seem to be syncing

  For all users on the server?  That's odd.  I've had various cases
where a given user will have trouble, but not everyone.  Granted,
there are only 11 users on our BES, but still.

> I tried everything but removing and re-adding the device.

  I would indeed try removing and re-adding the device -- or more
precisely, the user.  When BB Manager asks if you want to delete the
BlackBerry info, say "Yes".  Then re-add the user and reactivate the
device.  This is really harmless -- no user data should be lost from
either server mailbox or handheld.  It only discards server metadata
and other "behind the scenes" stuff.  (But remember, backups are
*always* a good idea.)

  We're running BES 4.mumble against Exchange 2003.  Behavior may be
different against other mail servers.

> Anything else I could try?

  Before you do anything else, check the logs.  Both Windows Event
Spewer and the BES text logs.  BES logs *gobs* of debug information to
the text logs.  This will often at least point out that there is a
problem, even if you don't know how to fix it.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: RSAT For windows 7 RC

2009-10-06 Thread Stephen Wimberly
Try this:

I saved this from my windows 7 x64 install and it's working just fine!

On Tue, Oct 6, 2009 at 8:33 AM, Don Guyer  wrote:

>  Jason,
> X86 or 64-bit? I’ll Zip it and send offline.
> Thx,
> Don Guyer
> Systems Engineer - Information Services
> Prudential, Fox & Roach/Trident Group
> 431 W. Lancaster Avenue
> Devon, PA 19333
> Direct: (610) 993-3299
> Fax: (610) 650-5306
> *From:* Jason Gauthier []
> *Sent:* Monday, October 05, 2009 7:00 PM
> *To:* NT System Admin Issues
> *Subject:* RSAT For windows 7 RC
> All,
>   MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
> link?   I had to reinstall my RC, and alas.. no tools!
> Thanks,
> Jason

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: BES 4.1 syncing

2009-10-06 Thread David Mazzaccaro
Try checking the BB services first.
Make sure they are started.

-Original Message-
From: Benjamin Zachary - Lists [] 
Sent: Monday, October 05, 2009 9:54 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

Thanks all for the tip. I will try the remove/add of the contact on the
device. Both my bes problems are small 3-4 users. I know at one its all
of them on the 2007 but on the other its just 1.

-Original Message-
From: Jeremy Anderson []
Sent: Monday, October 05, 2009 9:35 PM
To: NT System Admin Issues
Subject: RE: BES 4.1 syncing

For what its worth

I have seen that exact issue before, at 2 different clients.

The bad news is, I don't know the fix.

In one case I synced the contacts using desktop manager The other was
not my client and they reinstalled BES  (WTF?)

-Original Message-
From: Ben Scott []
Sent: Monday, October 05, 2009 6:30 PM
To: NT System Admin Issues
Subject: Re: BES 4.1 syncing

On Mon, Oct 5, 2009 at 8:54 PM, Benjamin Zachary - Lists
>  I have a couple of sites where contacts don't seem to be syncing

  For all users on the server?  That's odd.  I've had various cases
where a given user will have trouble, but not everyone.  Granted, there
are only 11 users on our BES, but still.

> I tried everything but removing and re-adding the device.

  I would indeed try removing and re-adding the device -- or more
precisely, the user.  When BB Manager asks if you want to delete the
BlackBerry info, say "Yes".  Then re-add the user and reactivate the
device.  This is really harmless -- no user data should be lost from
either server mailbox or handheld.  It only discards server metadata and
other "behind the scenes" stuff.  (But remember, backups are
*always* a good idea.)

  We're running BES 4.mumble against Exchange 2003.  Behavior may be
different against other mail servers.

> Anything else I could try?

  Before you do anything else, check the logs.  Both Windows Event
Spewer and the BES text logs.  BES logs *gobs* of debug information to
the text logs.  This will often at least point out that there is a
problem, even if you don't know how to fix it.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: USB Boot drive Frustration

2009-10-06 Thread Steve Kelsay
No, we are an XP shop so far. The problem seems to be the XP install
disk which is a Dell. There seems to be a problem with DELL  disks for
making BartPE Images.


From: Trimmel-Wyss Doris [] 
Sent: Tuesday, October 06, 2009 9:06 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


Have you tried these step on a Vista or Windows 7 PC


2.list disk (here you see the number of th usb stick) disk 3 (number of the usb stick!) 


5.create partition primary partition 1 

8.format fs=fat32 


10.  exit 


copy the content of the ISO-image or the CD (BartPE) to the USB-Stick


  is very
useful for mounting ISO-images




From: Steve Kelsay [] 
Sent: Tuesday, October 06, 2009 2:52 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


I do have an older BART CD. 


From: Jon B. Lewis [] 
Sent: Monday, October 05, 2009 5:27 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


Have you got a working Bart CD?


From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:04 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


Their immediate problem is to boot to a bartpe system. Every attempt I
have made using all the various web articles hit one snag or another.
PEbuilder is just not working for me today. I think I need to take a
break and relax a bit first!


From: Richard Stovall [] 
Sent: Monday, October 05, 2009 12:00 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


I asked about the OS b/c I've used the following procedure to install
Win7 on a Dell Mini 9, but it might work for XP also.  You do need a
Vista or above PC to prepare the USB drive.


Here is a similar link if all you have is XP for the preparation


I haven't tried the second method, but the source is the same Lifehacker
article -


Good luck,



From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:34 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


They are using it to reimage XP Pro machines now, but will be doing
windows 7 eventually.


From: Richard Stovall [] 
Sent: Monday, October 05, 2009 11:21 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


What OS for the new image?


From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:18 AM
To: NT System Admin Issues
Subject: USB Boot drive Frustration


Our desktop group has asked me to help them create a USB drive to boot
from in order to install their images. They have one I did for them last
year, and they need to have several more for a roll out.


I had a disk crash a month ago and have not reinstalled the software I
used to create one. I am now so frustrated, that I cannot think
straight! Last year, I believe I just used the HP storage disk format
utility, and put an XP disk in the CD drive for the boot files, and it
worked. This year, I have tried several different methods I found online
to no avail.


The first question is whether anyone knows a method  that actually
works, and the second is, does anyone know a diskcopy utility that will
duplicate the working USB to the others? The ones I found do not support
USB drives. 

















~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: USB Boot drive Frustration

2009-10-06 Thread Trimmel-Wyss Doris
Have you tried these step on a Vista or Windows 7 PC
2.list disk (here you see the number of th usb stick) disk 3 (number of the usb stick!)
5.create partition primary partition 1
8.format fs=fat32
10.  exit

copy the content of the ISO-image or the CD (BartPE) to the USB-Stick

MagicDisk is 
very useful for mounting ISO-images


From: Steve Kelsay []
Sent: Tuesday, October 06, 2009 2:52 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration

I do have an older BART CD.

From: Jon B. Lewis []
Sent: Monday, October 05, 2009 5:27 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration

Have you got a working Bart CD?

From: Steve Kelsay []
Sent: Monday, October 05, 2009 11:04 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration

Their immediate problem is to boot to a bartpe system. Every attempt I have 
made using all the various web articles hit one snag or another.  PEbuilder is 
just not working for me today. I think I need to take a break and relax a bit 

From: Richard Stovall []
Sent: Monday, October 05, 2009 12:00 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration

I asked about the OS b/c I've used the following procedure to install Win7 on a 
Dell Mini 9, but it might work for XP also.  You do need a Vista or above PC to 
prepare the USB drive.

Here is a similar link if all you have is XP for the preparation station.

I haven't tried the second method, but the source is the same Lifehacker 
article -

Good luck,

From: Steve Kelsay []
Sent: Monday, October 05, 2009 11:34 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration

They are using it to reimage XP Pro machines now, but will be doing windows 7 

From: Richard Stovall []
Sent: Monday, October 05, 2009 11:21 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration

What OS for the new image?

From: Steve Kelsay []
Sent: Monday, October 05, 2009 11:18 AM
To: NT System Admin Issues
Subject: USB Boot drive Frustration

Our desktop group has asked me to help them create a USB drive to boot from in 
order to install their images. They have one I did for them last year, and they 
need to have several more for a roll out.

I had a disk crash a month ago and have not reinstalled the software I used to 
create one. I am now so frustrated, that I cannot think straight! Last year, I 
believe I just used the HP storage disk format utility, and put an XP disk in 
the CD drive for the boot files, and it worked. This year, I have tried several 
different methods I found online to no avail.

The first question is whether anyone knows a method  that actually works, and 
the second is, does anyone know a diskcopy utility that will duplicate the 
working USB to the others? The ones I found do not support USB drives.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: USB Boot drive Frustration

2009-10-06 Thread Steve Kelsay
I do have an older BART CD. 


From: Jon B. Lewis [] 
Sent: Monday, October 05, 2009 5:27 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


Have you got a working Bart CD?


From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:04 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


Their immediate problem is to boot to a bartpe system. Every attempt I
have made using all the various web articles hit one snag or another.
PEbuilder is just not working for me today. I think I need to take a
break and relax a bit first!


From: Richard Stovall [] 
Sent: Monday, October 05, 2009 12:00 PM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


I asked about the OS b/c I've used the following procedure to install
Win7 on a Dell Mini 9, but it might work for XP also.  You do need a
Vista or above PC to prepare the USB drive.


Here is a similar link if all you have is XP for the preparation


I haven't tried the second method, but the source is the same Lifehacker
article -


Good luck,



From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:34 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


They are using it to reimage XP Pro machines now, but will be doing
windows 7 eventually.


From: Richard Stovall [] 
Sent: Monday, October 05, 2009 11:21 AM
To: NT System Admin Issues
Subject: RE: USB Boot drive Frustration


What OS for the new image?


From: Steve Kelsay [] 
Sent: Monday, October 05, 2009 11:18 AM
To: NT System Admin Issues
Subject: USB Boot drive Frustration


Our desktop group has asked me to help them create a USB drive to boot
from in order to install their images. They have one I did for them last
year, and they need to have several more for a roll out.


I had a disk crash a month ago and have not reinstalled the software I
used to create one. I am now so frustrated, that I cannot think
straight! Last year, I believe I just used the HP storage disk format
utility, and put an XP disk in the CD drive for the boot files, and it
worked. This year, I have tried several different methods I found online
to no avail.


The first question is whether anyone knows a method  that actually
works, and the second is, does anyone know a diskcopy utility that will
duplicate the working USB to the others? The ones I found do not support
USB drives. 













~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

RE: RSAT For windows 7 RC

2009-10-06 Thread Don Guyer


X86 or 64-bit? I'll Zip it and send offline.




Don Guyer

Systems Engineer - Information Services

Prudential, Fox & Roach/Trident Group

431 W. Lancaster Avenue

Devon, PA 19333

Direct: (610) 993-3299

Fax: (610) 650-5306  


From: Jason Gauthier [] 
Sent: Monday, October 05, 2009 7:00 PM
To: NT System Admin Issues
Subject: RSAT For windows 7 RC




  MS has pulled the RC RSAT tools since the RTM.   Anyone have it or a
link?   I had to reinstall my RC, and alas.. no tools!







~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Re: wireshark not seeing NIC

2009-10-06 Thread Michael Reid
Have you reinstalled it? I've installed it an had the same thing and
removed and reinstalled the capture driver.

On Monday, October 5, 2009, paul chinnery  wrote:
> Yes, newest version winpcap.
> Subject: RE: wireshark not seeing NIC
> Date: Mon, 5 Oct 2009 13:42:58 -0400
> From:  '');>
> To:
> Install the packet driver?
> -sc
> From: paul chinnery
> [  '');>]
> Sent: Monday, October 05, 2009 1:36 PM
> To: NT System Admin Issues
> Subject: wireshark not seeing NIC
> I've been using Wireshark for quite
> sometime (back when it was known as Ethereal).  I've had to re-format my
> hard-drive so, of course, had to re-install everything including
> Wireshark.
> However, now when I run the program it doesn't even see my NIC.  It sees
> the VPN I  have setup but not the NIC.
> I'm scracthing my head over this one.
> Your
> E-mail and More On-the-Go. Get Windows Live Hotmail Free. Sign up
> now. 

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~

Citrix Password Manager

2009-10-06 Thread James Rankin
HI all

Still having probs getting Citrix Password Manager working...hoping anyone
has any ideas...

I have installed the Password Manager service on a server with IIS,
installed an SSL certificate, and done all the configuration, including the
modifications to Active Directory. I have installed the Password Manager
agent on a new XenApp server, and performed all the necessary user
configuration at that end. However, when I launch a Citrix connection to the
client system, and try to use the "reset password" features before logging
on, I am continually receive the error "you cannot reset your password at
this time because the SSL certificate returned by the server is not trusted
on this computer". Now, I am a complete noob at certificates, but I have
browsed to the web page on the Password Manager service system and installed
the certificate, hoping that this would resolve the issue, but it hasn't.

I found a Citrix forum thread here ( that offers some
hints, but as far as I am aware I have installed the certificate (or is the
root certificate something different? Please let me know if it is!) and I
have made sure that IIS is not using port 443. I still don't seem to be able
to get the darned thing to work at allany help, no matter how small or
tangential, would be gratefully received



"On two occasions...I have been asked, 'Pray, Mr Babbage, if you put into
the machine wrong figures, will the right answers come out?' I am not able
rightly to apprehend the kind of confusion of ideas that could provoke such
a question."

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~   ~