Windows Support Tools

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 31 August 2011

Using Windows 7 management tools to your advantage

Posted on 23:08 by Unknown
Using Windows 7 management tools to your advantage





The more enterprises get to know Windows 7, the more useful features they'll find. Among the neatest things in that operating system are the management tools for the Ultimate and Enterprise versions (often in combination with Windows Server 2008 R2). Here are my three favorites:



AppLocker

Arguably the most-needed from a security perspective, AppLocker lets you define and manage via Group Policy Objects (GPOs) exactly which executables run on your user's desktops. It's not unlike third-party whitelisting tools, such as Faronics' Anti-Executable and the Windows Software Restriction Policies, we've had available to us in the past. But now you've got a more feature-rich whitelisting/management application built right into the OS.



DirectAccess

DirectAccess is a virtual private network alternative that allows remote users to connect directly to the corporate network without the hassles of loading a VPN client from their workstations. It's a single-user interface that connects users to the Internet and an intranet at the same time. In my opinion, the coolest thing about DirectAccess is how it pushes Windows updates out any time the computer is connected to the Internet.



Windows XP Mode

Windows XP Mode is a full-blown version of Windows XP SP3 that runs inside a Microsoft Virtual PC session in Windows 7. As long as you have a reasonable amount of memory to support it, all you have to do is download and install Windows XP Mode and Virtual PC, and you've got yourself a working virtual machine in no time.





A great aspect of Windows XP Mode is that it enables users to run virtualized applications. This means that programs are available for use in both a Windows XP Mode virtual session and a Windows 7 session. This is a great way to quickly set up an environment for testing application compatibility, performing security scans and more.



There are numerous other management tools like Federated Search for network searching, BranchCache for speeding up downloads at branch offices, Reliability Monitor for monitoring and troubleshooting OS and application problems, and BitLocker and BitLocker To Go for disk and removable media encryption.



I've always been an advocate of using what you've got as long as it meets your requirements for performance, visibility and control. The new management tools built into the high-end editions of Windows 7 may do just that. You may not be a big fan of the look and feel of Active Directory, GPOs and similar Windows-related administrative functions, but these built-in tools are better than no tools at all.

Read More
Posted in | No comments

Enterprise password protection checklist

Posted on 23:05 by Unknown
Enterprise password protection checklist





Despite the good intentions of IT departments, end-user education and advanced forms of authentication, password protection -- or a lack thereof -- remains a vexing problem for enterprises.



Users still create easy-to-guess passwords, write passwords down, store them in plain text, or email passwords to their friends and co-workers -- even though passwords are often the first, and sometimes only, line of defense against intruders.



Many enterprises still use password-based authentication because it's simpler and cheaper than more secure systems. In addition, organizations often maintain legacy systems that support only password-based authentication. Even enterprises that have implemented more advanced forms of authentication often combine those password management methods.



It's good practice to regularly review your corporate password management policy to maintain a secure environment and protect sensitive data.



Password cracking

When developing a password policy, it helps to understand the methods used to gain unauthorized access to protected resources. Intruders use the following methods to crack passwords:



Brute-force attack: An attempt to access a secure resource by trying all possible combinations of characters that can make up a password.

Dictionary attack: An attempt to access a secure resource by systematically entering common words (which often come from a dictionary file) to determine a user's password.

Sniffing: The process of intercepting wired or wireless network transmissions and capturing password hashes.

Cracking solutions: Software that attempts to decrypt passwords.

Social engineering: The process of using social skills to obtain passwords and other personal information. Intruders will often implement telephone, e-mail or Internet schemes to get users to reveal their sensitive data. Phishing is a type of social engineering.

Spyware: A type of software that users unintentionally install on their computers. Spyware surreptitiously gathers sensitive data or records keystrokes and sends that information to the intruder.

Shoulder surfing: The process of gathering password information or other sensitive data by watching users enter passwords or reading passwords they’ve written down.





These methods are often used in combination. For instance, intruders might use sniffing to intercept a password hash and then use cracking software to decrypt the hash. Or intruders might use social engineering to gather personal information about users, and then run a dictionary program that creates a list of words based on that data.



Strong and safe passwords

An effective password policy should prevent passwords from being guessed, cracked or compromised in any way. Part of that policy should ensure that all users create strong passwords and follow specific guidelines when using and maintaining those passwords.



There's plenty of material that explains what constitutes strong passwords and proper password maintenance. The following guidelines summarize much of that information and provide a quick checklist to reference when developing password standards:



Keep passwords confidential. Don't write passwords down. Don't show or tell them to anyone. Don't store passwords or transmit them electronically, unless you're sure they're encrypted and safe.

Don't include personal information. Don't use first or last names, addresses, birthdays, anniversaries, Social Security numbers, usernames, nicknames, pet names or any other type of personal information.

Don't create passwords that can be easily guessed. Avoid using common words, including abbreviations, foreign words, common misspellings or words spelled backwards. If you're creating a passphrase, don't include common phrases, famous quotations, or words from poems or songs.

Used mixed characters. Passwords should include lower and uppercase letters, numbers and symbols such as @, %, !, &, and ^.

Create long passwords. The longer the password, the better. Most sources recommend passwords be at least eight characters long, often longer. (Microsoft now recommends that a strong password be at least 14 characters.) When passphrases are supported, use them. They should run at least 20 to 30 characters long.

Change passwords regularly. Recommendations vary on how often to change passwords, but 90 days is a common standard. The policy in some organizations is to change privileged (administrative) accounts more frequently than end-user accounts.

Don't reuse passwords. After you've used a password, forget it. And make the new password significantly different from the old one.

Use different passwords for different accounts. Don't use the same password for more than one account.





Not surprisingly, the stronger the passwords, the more difficult they are to remember, and the more difficult they are to remember, the more likely users will write them down, forget them or be calling the support desk.



The trick is to get users to create strong passwords they can remember. One way to achieve this is to base the password on the first letters in each word of a sentence or phrase. For example, the sentence The #3 train arrives this p.m. @ platform 2A! translates to the password T#3tatp.m.@p2A!. Notice that the password includes upper- and lowercase letters, numbers, and symbols.



Password management

An effective security strategy should include a documented password policy, and requirements for strong passwords should be part of that policy. However, the policy should also address other issues critical to enterprise password management:



Educating users: All users should be educated in password-related issues -- including details about how passwords can be cracked, what constitutes a strong password, ways to craft those passwords and how to safeguard passwords.

Enforcing standards: Password policies should be enforced systemically, that is, through security policies and other network and operating system mechanisms that prevent users from creating weak passwords or mismanaging their passwords. For instance, passwords should be set to expire at preset intervals, password histories should be retained to prevent passwords from being reused, and new users should be required to change their passwords upon first login.

Detecting intruders: Set controls to manage the number of times a bad password can be inputted before an account is locked out.

Auditing passwords: Passwords should be periodically audited to ensure compliance. Such auditing should be done without providing visibility to the passwords themselves.

Storing and transmitting passwords: Passwords should always be encrypted whenever being stored or transmitted.

Managing privileged passwords: Privileged passwords -- those used to access administrative accounts, let computers access one another or run service programs -- should be stored centrally on a system that supports a secure access and change process.

Implementing password management: Password management solutions can help mitigate the problems associated with compromised passwords. Such a system might be a centralized technology (such as single sign-on or password synchronization) or one that lets users store usernames, passwords and other sensitive information locally. If your organization implements one of these methods, your password policies should incorporate the technology's operation and use.

Clearly, the factors that contribute to an effective password policy go beyond simply making sure that users create strong passwords. The goal must be to grant all authorized users access to protected data, while preventing unauthorized users from gaining such access.



To that end, you should create a policy that takes into account all issues related to managing passwords. The points above provide a starting point, but your policy must be specific to your enterprise. In other words, your password policy should reflect every step necessary to reduce the risks of compromise to any of your organization's systems.

Read More
Posted in | No comments

Thursday, 7 July 2011

Jetico BCWipe 5.02.2

Posted on 00:08 by Unknown

Use military-grade procedures to surgically remove all traces of any file.

BCWipeTM data wiping software enables you to permanently delete selected files so that they can never be recovered or undeleted. BCWipe embeds itself within Windows and can be activated from the Explorer FILE Menu OR from the context (right-click) menu OR from BCWipe Task Manager OR from a command-line prompt. BCWipe complies with U.S. Department of Defense (DoD 5220.22-M) standard, U.S. Department of Energy (DoE M 205.1-2) standard and a set of other standard wiping schemes. You can also create and use your own customized wiping scheme to wipe sensitive information from storage devices installed on your computer.

BCWipe Features:
Delete with wiping
Wipe free disk space
Wipe Swap File
Wipe File Slacks
Wipe Empty Directory Entries
Swap File Encryption
Hexadecimal File Viewer
BCWipe Task Manager
Transparent Wiping
Read More
Posted in | No comments

Avast! Internet Security 6.0.1203

Posted on 00:04 by Unknown

Maximum protection, now powered by new avast! SafeZone technology

Protects your sensitive online shopping and banking transactions
Ensures your safety on social networks (Facebook, etc.) or IM chats
Blocks hacker attacks, to protect your identity
avast! Internet Security provides complete antivirus, anti-spyware, antispam, and firewall protection, complemented now by new avast! SafeZone technology. It creates an isolated virtual desktop, invisible to any possible attacker, where you can do your online shopping and banking securely.

Shop and bank online with total privacy
avast! SafeZone opens a new (clean) desktop so that other programs don’t see what’s happening – and it leaves no history once it’s closed.

Worry-free social networking and web surfing
Our award-winning and certified antivirus engine and shields stop even previously unknown threats – for peace of mind when you chat or spend time on Facebook, Twitter, or other websites.

Prevent identity theft
Our silent firewall stops hackers and other unauthorized entry attempts to your PC, to keep your data where it belongs – safe and sound.

Keep your email inbox safe and clean
Internet Security’s antispam feature blocks both spam and sophisticated “phishing” attempts, to keep you from clicking “harmless” links that really can cause damage.
Read More
Posted in | No comments

Spadix Disk Size Manager 2.1

Posted on 00:00 by Unknown

Disk Size Manager is a powerful hard disk space manager for Windows.

Using Disk Size Manager you can keep track of your hard disks space to ensure its most efficient use. With its 2D/3D pie and bar charts as well as detailed descriptions in words, Disk Size Manager provides you with the complete information about folders and drives you indicate. The information includes folder/drive space (total available, compressed, used by different types of files, etc.) in units of volume (KB, MB, GB) or percents, number of files, cluster sizes of the drives, etc.

Disk Size Manager also offers you a search tool to look for files and folders satisfying conditions specified by you. The range of the conditions you may use is very wide contained text, creation/modification dates, size, attributes, etc.

more info @
Read More
Posted in | No comments

Wednesday, 6 July 2011

ARASH feat Helena "Pure Love" (Official video)

Posted on 20:46 by Unknown
Read More
Posted in | No comments

Monday, 27 June 2011

VisualSVN for Visual Studio 2.0.6

Posted on 00:27 by Unknown

VisualSVN makes your life easier with a reliable plug-in that integrates Subversion seamlessly with Visual Studio.

VisualSVN is a Visual Studio plug-in that integrates Subversion and TortoiseSVN seamlessly with Visual Studio. VisualSVN virtually eliminates the management of your project source code files within Subversion. Program, design, debug and deploy with VisualSVN as your silent partner that safeguards your source code.

With VisualSVN deployed throughout your development organization, all of your developers will be using Subversion confidently and effectively to manage and safeguard your organization's work product.

Why You Should Use VisualSVN

* Ease of use: VisualSVN makes Subversion substantially easier to use within Visual Studio than using TortoiseSVN alone with Subversion.
* Deep integration of Visual Studio projects and solutions with Subversion file management. You don't have to think about Subversion when you work with files and projects in Visual Studio.
* More stable, simpler and easier to use, and more reliable than available open source alternatives (according to independent reviewers and bloggers).
* One-stop source control lets you perform all user level Subversion functions — manage project files, checkout, commit, and other operations — within Visual Studio.
* Compatible with the latest Subversion and TortoiseSVN releases. Continually updated.
* Inexpensive to purchase, and easy to set up.

Quick and Easy Adoption

* One-click import of a new solution: the Add Solution to Subversion wizard gets you started quickly and reliably. With one simple step, your solution is placed under Subversion source control.
* One-click checkout: the Get Solution from Subversion dialog makes checkout quick and painless. Developers instantly get to work on shared projects.
* Fully TortoiseSVN integrated: all source control functions use the standard TortoiseSVN dialogs. Your knowledge of TortoiseSVN is immediately useful.
* Fully compatible: VisualSVN contains the most current available Subversion distributions plus the original command line binaries (including svn.exe).
* Watch the quick Getting Started demo and learn how easy Subversion can be.

Transparent Source Control That “Covers” You At All Times

* Automatically adds every created item to Subversion.
* No ignore/exclude patterns to manage: Visual Studio temporary files such as the contents of obj and bin folders are ignored by default when using VisualSVN.
* Transparently move/rename your files and folders (and the complete history of these changes will be preserved by Subversion).
* Common file operations are transparently reflected to Subversion: Drag & Drop, Copy & Paste and “Save As” all cause the right thing to happen within version control.
* “Traffic-light” style Subversion visual status is displayed for every versioned item in the Solution Explorer.
* Status display is displayed in the status bar at all times with a traffic light style visual indicator, so that you instantly know if files have changed. Avoid “dirty commits” and keep your work grouped logically as you commit your changes.

Unique Features That Enhance Your Productivity

* Quick Diff marks changes visually within Visual Studio using color coding. You can see the changes in your source file from the repository version at a glance. There is fast navigation available to move to the next changed section. You never have to open a separate “diff” window to see what you have changed. And you don't have to hunt for changes.
* Quick Revert uses the Quick Diff color coding to allow you to easily restore changes that have been made from the repository version. Just select the changes that are displayed by Quick Diff and perform “Revert Selection”. Quick Revert is fully integrated with the Visual Studio Undo/Redo stack.
* Track and manage all changes made to your source file by using the unique visual assists that are provided by VisualSVN. You are free to use external applications and you will always see exactly what has changed. Never make a “dirty commit” again.
* Seamless integration with built-in and third-party refactoring tools such as ReSharper. Source code changes and file operations such as renaming are handled for you and are reflected transparently to Subversion by VisualSVN. Even changes in more complex objects such as forms and ASPX pages are handled transparently by VisualSVN and are accurately reflected to Subversion.
* Handy VisualSVN toolbar provides clean, direct access to the most important commands and features of Subversion. We even provide a combo box containing the URL of the current Subversion branch, and you can use it to quickly change between branches.
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • What is Cloud Computing ?
  • Removing the complexity from information protection
    How encryption can add value to your business The use of encryption is no longer optional for many organizations. Certain new regulations de...
  • Setting up a DHCP server in Windows 2003
    The DHCP server assigns a client an IP address taken from a predefined scope for a given amount of time. If an IP address is required for lo...
  • Five ways to fix Outlook connectivity issues
    1. Confirm that Outlook is actually the problem. First, you need to confirm the problem truly is related to Outlook. Identify which users a...
  • A light-weight system monitor
    Conky is a free, light-weight system monitor for X, that displays any information on your desktop. Conky is licensed under the GPL and runs ...
  • Nambara Sanda Wage
  • Why ignore the tips given by the foreign intelligence unit about approaching 2 Black Tigers to Jeyaraj?
    (Lanka-e-news, 7th April 2008, 11.30pm) It is revealed by now that Minister Jeyaraj Fernandopulle was assassinated due to lack of security, ...
  • Cartoons of the Week
  • Manage your home network better with Network Magic 5.0
    Cisco announced on Thursday Network Magic 5.0, a suite of network management software. This is is the first product released by Cisco since ...
  • Reconfigure Oracle EM
    When you’ve installed Oracle Database 11G as well you can’t change the Windows Host name without reinstalling Oracle Enterprise Manager. 1. ...

Categories

  • ISA Firewall
  • ISA Server 2006
  • Quick Tips
  • Reports
  • Tips

Blog Archive

  • ▼  2013 (7)
    • ▼  October (6)
      • Free download TeraCopy Pro with Crack Full Version...
      • Five ways to fix Outlook connectivity issues
      • Free Download PDF Password Remover 1.5.2 with Crack
      • Free download Power ISO 5.7 Full Version with Crac...
      • Free download DriverEasy Professional v4.5.2.21601...
      • How to Remove Dosearches.com homepage (Virus Remov...
    • ►  February (1)
  • ►  2012 (10)
    • ►  September (3)
    • ►  August (3)
    • ►  July (3)
    • ►  June (1)
  • ►  2011 (16)
    • ►  August (2)
    • ►  July (4)
    • ►  June (3)
    • ►  May (1)
    • ►  April (1)
    • ►  March (4)
    • ►  January (1)
  • ►  2010 (12)
    • ►  December (3)
    • ►  October (4)
    • ►  March (1)
    • ►  January (4)
  • ►  2009 (67)
    • ►  August (2)
    • ►  July (18)
    • ►  June (23)
    • ►  April (3)
    • ►  March (6)
    • ►  February (7)
    • ►  January (8)
  • ►  2008 (319)
    • ►  December (30)
    • ►  November (43)
    • ►  October (45)
    • ►  September (12)
    • ►  August (18)
    • ►  July (27)
    • ►  June (15)
    • ►  May (7)
    • ►  April (55)
    • ►  March (65)
    • ►  January (2)
  • ►  2007 (10)
    • ►  December (2)
    • ►  November (8)
Powered by Blogger.

About Me

Unknown
View my complete profile