Re: Interesting Article about secure hard disk overwrites

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 12:00 AM, Andrew S. Baker asbz...@gmail.com wrote: https://www.infosecisland.com/blogview/16130-The-Urban-Legend-of-Multipass-Hard-Disk-Overwrite.html I have never seen an official copy of NISPOM (DoD 5220.22-M) that specified specific overwrite methods. I seriously

RE: SMTP TURN in IIS v6.0

2011-08-30 Thread RichardMcClary
Yes, and at least the MS link was useful. (I had already found both links before crying for help.) Someone else (Ken?) sent a link to the IIS 6 Resources Kit. That had the metadata browser that I sorely needed. Between that brower and the MS link (showing the decimal values for the

RE: Weird: network slowdown when metro e and Internet unavailable

2011-08-30 Thread Tom Miller
I'll take a look. Perhaps something I missed. Thanks, folks. Lists - Level Five li...@levelfive.us 8/29/2011 10:42 PM Check on your AD Sites if you have the Subnets setup correctly? Is this a flat layer2 ME or routed/vpn ?? We ran into this on our flat layer-2 where we found hundreds of

RE: How to determine a host's IP range

2011-08-30 Thread John Aldrich
Looks like it's hosted by Akamai, which might explain why you can't get an answer from the folks running the course. From: Damien Solodow [mailto:damien.solo...@harrison.edu] Sent: Tuesday, August 30, 2011 8:51 AM To: NT System Admin Issues Subject: Re: How to determine a host's IP range Do

RE: Interesting Article about secure hard disk overwrites

2011-08-30 Thread David Lum
Which begs the question - just how DOES SSD play into this? From: Crawford, Scott [mailto:crawfo...@evangel.edu] Sent: Tuesday, August 30, 2011 5:46 AM To: NT System Admin Issues Subject: Re: Interesting Article about secure hard disk overwrites Of course the whole issue is moot now that we're

RE: How to determine a host's IP range

2011-08-30 Thread Thomas Mullins
When I ran: dig +short txt_netblocks.pearsoncmg.com There were no results returned. To check my syntax, I tried the same command on google: dig +short txt _netblocks.google.com v=spf1 ip4:216.239.32.0/19 ip4:64.233.160.0/19 ip4:66.249.80.0/20 ip4:72.14.192.0/18

Re: Weird: network slowdown when metro e and Internet unavailable

2011-08-30 Thread Ben Scott
On Mon, Aug 29, 2011 at 4:34 PM, Tom Miller tmil...@hnncsb.org wrote: When I attempted to do a simple ping test, all of the Windows 2008 servers (member and DC) were slow to respond and had some missing pings.  This was not an issue with our 2003 or non-Windows systems.  Same issue wether I

Re: How to determine a host's IP range

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 9:26 AM, Thomas Mullins tsmull...@wise.k12.va.us wrote:        dig +short txt_netblocks.pearsoncmg.com         There were no results returned. Where did txt_netblocks.pearsoncmg.com come from? That doesn't appear to be an existent domain name. It's even questionable

Re: How to determine a host's IP range

2011-08-30 Thread Richard Stovall
I don't know about other firewalls, but recent SonicWalls allow you to create network objects based on FQDN and then use those objects in your rules. Might something like that be an option? It's been exactly the ticket for me when having to deal with a situation similar to what you are facing.

RE: How to determine a host's IP range

2011-08-30 Thread Thomas Mullins
Our web filter is a Barracuda, and does not have an option for the domain name. Shane -Original Message- From: Richard Stovall [mailto:rich...@gmail.com] Sent: Tuesday, August 30, 2011 9:51 AM To: NT System Admin Issues Subject: Re: How to determine a host's IP range I don't know

RE: How to determine a host's IP range

2011-08-30 Thread Thomas Mullins
Thanks Ben, I used the wrong domain name. When ns.pearsoncmg.com is queried for media.pearsoncmg.com, this is what is returned in the answer section: ;; ANSWER SECTION: media.pearsoncmg.com. 808 IN CNAME media.pearsoncmg.com.edgesuite.net. media.pearsoncmg.com.edgesuite.net.

Re: Has Anyone used VMlimited?

2011-08-30 Thread Mike Sullivan
I dig it man! On Tue, Aug 30, 2011 at 8:16 AM, Roger Wright rhw...@gmail.com wrote: http://blogs.technet.com/b/keithcombs/archive/2011/08/29/i-m-a-virt-guy.aspx Roger Wright ___ My short term goal is to make it through the day. My long term goal is to string a bunch of short term goals

Re: How to determine a host's IP range

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 9:50 AM, Richard Stovall rich...@gmail.com wrote: I don't know about other firewalls, but recent SonicWalls allow you to create network objects based on FQDN and then use those objects in your rules. How does that cope with a CDN which might generate different IP

Re: How to determine a host's IP range

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 10:51 AM, Thomas Mullins tsmull...@wise.k12.va.us wrote: dig +noall +ans ANY media.pearsoncmg.com. @ns.pearsoncmg.com. I am going to read and learn how to use dig. The two important parts were: * The ANY directive, which tells dig to query for any known DNS records.

Re: How to determine a host's IP range

2011-08-30 Thread Richard Stovall
On my SonicWall, if a create a rule for media.pearsoncmg.com, I can write rules which allow or deny access no matter the underlying ip. Here's the definition SonicWall uses to describe ther FQDN network object. FQDN Address Objects are resolved using the DNS servers configured on the SonicWALL in

Re: How to determine a host's IP range

2011-08-30 Thread Richard Stovall
That should have been ...if I create a network object for media.pearsoncmg.com... On Tue, Aug 30, 2011 at 11:54 AM, Richard Stovall rich...@gmail.com wrote: On my SonicWall, if a create a rule for media.pearsoncmg.com, I can write rules which allow or deny access no matter the underlying ip.

File and Print Sharing on windows Domain

2011-08-30 Thread Darin
Hi All, Recently I have been informed that having file and print sharing turned on takes up considerable bandwidth on the network. I know Appletalk is a very chatty protocol but never was aware that Microsoft File and Print sharing was. The differnet places I worked prior to this we always

Re: Has Anyone used VMlimited?

2011-08-30 Thread Andrew S. Baker
LOL * * *ASB* *http://XeeMe.com/AndrewBaker* *Harnessing the Advantages of Technology for the SMB market… * On Tue, Aug 30, 2011 at 11:16 AM, Roger Wright rhw...@gmail.com wrote: http://blogs.technet.com/b/keithcombs/archive/2011/08/29/i-m-a-virt-guy.aspx Roger Wright ___ My short

Re: File and Print Sharing on windows Domain

2011-08-30 Thread James Rankin
I wasn't aware that file and printer sharing was a bandwidth hog, I've never heard or read anything that would suggest it is. I could be completely wrong though, but I've never had to turn it off for bandwidth reasons. On 30 August 2011 17:05, Darin dmche...@gmail.com wrote: Hi All, Recently

RE: File and Print Sharing on windows Domain

2011-08-30 Thread Brian Desmond
Has someone quantified this for you and shown the top endpoints? Thanks, Brian Desmond br...@briandesmond.com c   – 312.731.3132 -Original Message- From: Darin [mailto:dmche...@gmail.com] Sent: Tuesday, August 30, 2011 11:05 AM To: NT System Admin Issues Subject: File and Print

Re: How to determine a host's IP range

2011-08-30 Thread Bill Humphries
what about using this as a solution: http://www.akamai.com/html/misc/akamai_client/netsession_interface_faq.html Richard Stovall wrote: That should have been ...if I create a network object for media.pearsoncmg.com... On Tue, Aug 30, 2011 at 11:54 AM, Richard Stovall rich...@gmail.com wrote:

Re: File and Print Sharing on windows Domain

2011-08-30 Thread Andrew S. Baker
Perhaps you should consider giving us some more details about your network, and what you deem considerable bandwidth so that we have some context for your observations. As James mentioned, I can't say that I've ever seen FP cause any bandwidth concerns across a variety of networks. * * *ASB*

RE: Has Anyone used VMlimited?

2011-08-30 Thread Michael B. Smith
That's 2.5 minutes of my life I can never get back. Regards, Michael B. Smith Consultant and Exchange MVP http://TheEssentialExchange.com From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: Tuesday, August 30, 2011 12:15 PM To: NT System Admin Issues Subject: Re: Has Anyone used VMlimited?

Re: SMTP TURN in IIS v6.0

2011-08-30 Thread Kurt Buff
On Tue, Aug 30, 2011 at 04:51, richardmccl...@aspca.org wrote: snip 2. I won't know until later in the week if it actually did turn off TURN, ATRN, ETRN, etc. Can you telnet to the installation and issue commands? That should tell you right away. Kurt ~ Finally, powerful endpoint security

Re: SMTP TURN in IIS v6.0

2011-08-30 Thread RichardMcClary
I believe this tells me TURN is no longer enabled: === 220 faxcore1.napcc.aspca.int Microsoft ESMTP MAIL Service, Version: 6.0.3790.4675 ready at Tue, 30 Aug 2011 12:10:27 -0 500 ehlo 250-faxcore1.napcc.aspca.int Hello [10.1.2.226] 250-SIZE 250-PIPELINING 250-DSN 250-ENHANCEDSTATUSCODES

Re: How to determine a host's IP range

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 11:54 AM, Richard Stovall rich...@gmail.com wrote: On my SonicWall, if a create a rule for media.pearsoncmg.com, I can write rules which allow or deny access no matter the underlying ip. There's no intrinsic relationship between an IP address and a DNS name. From

Fradulent *.google.com certs in Firefox.

2011-08-30 Thread Ziots, Edward
Fraudulent *.google.com Certificate at Mozilla Security Blog: http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-certif icate/ Status Because the extent of the mis-issuance is not clear, we are releasing new versions of Firefox for desktop (3.6.21, 6.0.1, 7, 8, and 9) and

Open Source cloud stack

2011-08-30 Thread Kurt Buff
Works with the majors (Citrix/Xen, VMware, KVM), except HyperV, which is coming soon... http://www.theregister.co.uk/2011/08/29/citrix_cloud_com_update/ Looks very cool for private clouds. ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~

Re: Fradulent *.google.com certs in Firefox.

2011-08-30 Thread Kurt Buff
Not just FF - MSFT is issuing a revocation for its products. CERT notification to follow... On Tue, Aug 30, 2011 at 10:40, Ziots, Edward ezi...@lifespan.org wrote: Fraudulent *.google.com Certificate at Mozilla Security Blog:

Fwd: US-CERT Current Activity - Fraudulent DigiNotar SSL Certificate

2011-08-30 Thread Kurt Buff
-- Forwarded message -- From: Current Activity us-c...@us-cert.gov Date: Tue, Aug 30, 2011 at 06:13 Subject: US-CERT Current Activity - Fraudulent DigiNotar SSL Certificate To: Current Activity current-activ...@us-cert.gov -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 US-CERT

RE: Fradulent *.google.com certs in Firefox.

2011-08-30 Thread Ziots, Edward
I stand corrected, Looks like DigiNotar can’t be trusted right now J Z Edward E. Ziots CISSP, Network +, Security + Security Engineer Lifespan Organization Email:ezi...@lifespan.org Cell:401-639-3505 From: Kurt Buff [mailto:kurt.b...@gmail.com] Sent: Tuesday, August 30,

Re: File and Print Sharing on windows Domain

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 12:05 PM, Darin dmche...@gmail.com wrote: Recently I have been informed that having file and print sharing turned on takes up considerable bandwidth on the network. As others have said, you need to clarify and quantify that statement. For example, if there's a lot of

Re: SMTP TURN in IIS v6.0

2011-08-30 Thread Kurt Buff
You might have to use TURN, instead of turn. Also, you can try ETRN and ATRN. But, from the looks of it, you have indeed fixed your problem. Kurt On Tue, Aug 30, 2011 at 10:14, richardmccl...@aspca.org wrote: I believe this tells me TURN is no longer enabled: === 220

RE: File and Print Sharing on windows Domain

2011-08-30 Thread David Lum
* Disable the browser service on anything not one of those designated masters +1 I run a GPO here to turn off the browser service on our workstations. Dave -Original Message- From: Ben Scott [mailto:mailvor...@gmail.com] Sent: Tuesday, August 30, 2011 11:06 AM To: NT System Admin

Re: Open Source cloud stack

2011-08-30 Thread Andrew S. Baker
You actually like something with cloud in its name? * * *ASB* *http://XeeMe.com/AndrewBaker* *Harnessing the Advantages of Technology for the SMB market… * On Tue, Aug 30, 2011 at 1:43 PM, Kurt Buff kurt.b...@gmail.com wrote: Works with the majors (Citrix/Xen, VMware, KVM), except HyperV,

Re: Open Source cloud stack

2011-08-30 Thread Kurt Buff
Private clouds can certainly make sense. Public and mixed clouds don't make so much sense to me. Kurt On Tue, Aug 30, 2011 at 11:54, Andrew S. Baker asbz...@gmail.com wrote: You actually like something with cloud in its name? * * *ASB* *http://XeeMe.com/AndrewBaker* *Harnessing the

RE: Open Source cloud stack

2011-08-30 Thread Webster
Sure do. http://en.wikipedia.org/wiki/McCloud_(TV_series) Carl Webster Consultant and Citrix Technology Professional http://www.CarlWebster.comhttp://www.carlwebster.com/ From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: Tuesday, August 30, 2011 1:55 PM To: NT System Admin Issues

Re: Open Source cloud stack

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 3:49 PM, Kurt Buff kurt.b...@gmail.com wrote: Private clouds can certainly make sense. Even if it doesn't have a keyboard? -- Ben ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/ ~ --- To

Re: Open Source cloud stack

2011-08-30 Thread Steven Peck
I like to collect them all. Rain clouds Thunder clouds Clouds with a silver lining.. silver liningss. Actually, I need to read some white papers on building private clouds. It doesn't make sense to me until I read how they're put together. I found microsoft's site with white papers

RE: Open Source cloud stack

2011-08-30 Thread Webster
Cloud based keyboard AND mouse. No cables required. Carl Webster Consultant and Citrix Technology Professional http://www.CarlWebster.com -Original Message- From: Ben Scott [mailto:mailvor...@gmail.com] Sent: Tuesday, August 30, 2011 3:14 PM To: NT System Admin Issues Subject:

Re: Open Source cloud stack

2011-08-30 Thread Kurt Buff
On Tue, Aug 30, 2011 at 13:13, Ben Scott mailvor...@gmail.com wrote: On Tue, Aug 30, 2011 at 3:49 PM, Kurt Buff kurt.b...@gmail.com wrote: Private clouds can certainly make sense.  Even if it doesn't have a keyboard? Mine will always have keyboards... Kurt ~ Finally, powerful endpoint

RE: Open Source cloud stack

2011-08-30 Thread Greg Olson
KeyboardHow Quaint.. -Scotty http://www.youtube.com/watch?v=v9kTVZiJ3Uc -Original Message- From: Kurt Buff [mailto:kurt.b...@gmail.com] Sent: Tuesday, August 30, 2011 1:26 PM To: NT System Admin Issues Subject: Re: Open Source cloud stack On Tue, Aug 30, 2011 at 13:13,

RE: How to determine a host's IP range

2011-08-30 Thread Crawford, Scott
On the other hand, if it's doing reverse dns on every ip that hits the firewall, it could work. You're assuming they do that only once at rule creation. -Original Message- From: Ben Scott [mailto:mailvor...@gmail.com] Sent: Tuesday, August 30, 2011 12:18 PM To: NT System Admin Issues

Re: How to determine a host's IP range

2011-08-30 Thread Ben Scott
On Tue, Aug 30, 2011 at 5:49 PM, Crawford, Scott crawfo...@evangel.edu wrote: From their description, what that does is look up the name to IP address(es), and then uses that to drive the firewall rule. Which is useful, don't get me wrong, but if the CDN varies the IP address (as some of them

Re: US-CERT Current Activity - Fraudulent DigiNotar SSL Certificate

2011-08-30 Thread Jon Harris
As one person on the Register article said maybe it is time to just remove this company's root certificate from all machines. 40 days to find out it had issued this cert? Jon On Tue, Aug 30, 2011 at 1:46 PM, Kurt Buff kurt.b...@gmail.com wrote: -- Forwarded message -- From:

Re: File and Print Sharing on windows Domain

2011-08-30 Thread Jon Harris
Last place I worked I restricted Network Places. It is not File and Print you need to turn off BTW. Jon On Tue, Aug 30, 2011 at 12:05 PM, Darin dmche...@gmail.com wrote: Hi All, Recently I have been informed that having file and print sharing turned on takes up considerable bandwidth on

RE: How to determine a host's IP range

2011-08-30 Thread Crawford, Scott
Agree with all your points. I was just throwing it out there as a possibility. If I were implementing it, I would definitely apply it only to certain ports. -Original Message- From: Ben Scott [mailto:mailvor...@gmail.com] Sent: Tuesday, August 30, 2011 5:13 PM To: NT System Admin Issues

Re: Open Source cloud stack

2011-08-30 Thread Kurt Buff
I expect it will take until quite a while after I'm dead for a good replacement for the keyboard to be invented. If I'm wrong, well, that'd be cool. Kurt On Tue, Aug 30, 2011 at 13:29, Greg Olson gol...@markettools.com wrote: KeyboardHow Quaint..        -Scotty

Robocopy

2011-08-30 Thread Kurt Buff
The XJ switch is very important if you're going to target either c:\users or c:\documents and settings in Win7. That is all. Kurt ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/ ~ --- To manage subscriptions click

Re: Robocopy

2011-08-30 Thread Jonathan Link
Yup. Although this was first sussed out by Vista users... On Tue, Aug 30, 2011 at 8:35 PM, Kurt Buff kurt.b...@gmail.com wrote: The XJ switch is very important if you're going to target either c:\users or c:\documents and settings in Win7. That is all. Kurt ~ Finally, powerful