I remember when I was a kid and my dad showed me a memo he had gotten from the IT guy at his work instructing users on the proper technique for cleaning their mouse balls. It was funny because it went into great detail about the entire process of cleaning them in a way that made the author appear to be blissfully ignorant of the fact that, to most lay persons at the time, it seemed to be describing a very different act than what he had intended.
Today, many of us can look back - perhaps with nostalgia - on the days when our mice had balls. Some of us may even recall the annoyance that dirty mouse balls could cause. The pointer just wouldn't move exactly where you wanted it to. Often, it would skip right over that spot no matter what you did. That is, until you turned it over, rotated the cover 45 degrees counter-clockwise, removed the ball, and then scraped the gunk off of the two rollers that corresponded to the X- and Y-axes.
Well, friends, I am here to tell you that optical mice are not immune to the accumulation of detritus and debris. Why, just a few minutes ago I was getting very irritated because the optical mouse I've had for about 15 years was not as responsive as it used to be. I had tried replacing the battery and reconnecting it to the base station, but to no avail. It turns out that the hole in the bottom where the laser and optical sensor are housed had become partially filled with dog hair. Yes, dog hair. Gross.
I got a Q-Tip, twirled it around in the hole a few times, pulling out a little more hair each time, and then blew out the rest. Now my optical mouse is as responsive as it was when I first got it.
If your mouse doesn't move like it used to, now you can do something about it: Simply turn it over to expose the hole in its underside, moisten one end of a Q-Tip, stick it in the hole, and twirl it around a few times until nothing else come out. Then blow into the hole a couple of times for good measure. Your mouse will thank you.
This blog is where I share tips, tricks, and tools in hopes of helping others to use technology more safely, securely, and successfully.
Wednesday, March 27, 2019
Wednesday, March 20, 2019
Vulnerability in WinRAR Actively Being Exploited by Attackers
If you have WinRAR installed, stop what you're doing right now and go update it to the latest version. There is a vulnerability in all previous versions of WinRAR that is being actively exploited by attackers. Seriously, do it now.
Is That Software Download Safe?
These tips can help you to reduce your risk of accidentally downloading malware:
- Always download software from its official website. There are very few exceptions to this rule.
- Never download software using a link in an email, on a blog, or even an ad in search engine (e.g.: Google) results.
- Never download anything that is offered to you. If you didn't go looking for it, don't download it.
Saturday, November 29, 2014
Enable Two-Factor Authentication Now!
With all of the online data breaches these days, it's more important than ever that you take measures to protect your online accounts. A powerful way to do that is to enable two-factor authentication (2FA) on any sites that support it. Here is a link to a Lifehacker article with a list of sites that provide 2FA:
http://lifehacker.com/5938565/heres-everywhere-you-should-enable-two-factor-authentication-right-now
http://lifehacker.com/5938565/heres-everywhere-you-should-enable-two-factor-authentication-right-now
Friday, September 5, 2014
Windows Server Running IIS Fails PCI Compliance Scan
If your web server is failing a PCI compliance scan because a specially crafted HTTP/1.0 GET request without a host header is causing it to divulge an internal private IP address, then read on.
Problem
In IIS 7 on Windows Server 2008 and higher, there is a vulnerability that will cause it to accept such a GET request and respond with the internal IP address as the realm for basic authentication. This does not happen with an HTTP/1.1 request.
More Information
In this example, the GET request was for /autodiscover/autodiscover.xml, which is in the Autodiscover application under the "SBS Web Applications" site in IIS 7 on a Windows Small Business Server 2008 computer.
You can test for the issue with openssl on Linux by running the following command:
$ openssl s_client -host hostname.domain.tld -port 443Substitute the actual hostname for hostname.domain.tld. The server will respond with a bunch of SSL information ending in "---" followed by a blank line. On that line, type or paste the following:
GET /autodiscover/autodiscover.xml HTTP/1.0Send a blank line at the end; the server will not respond until you do. An example of a response from a server affected by the vulnerability follows:
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
Accept-Language: en
Connection: Keep- Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
HTTP/1.1 401 Unauthorized
Content-Type: text/html
Server: Microsoft-IIS/7.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
WWW-Authenticate: Basic realm="192.168.1.201"
X-Powered-By: ASP.NET
Date: Fri, 05 Sep 2014 16:25:59 GMT
Connection: close
Content-Length: 58
You do not have permission to view this directory or page.read:errno=0
Resolution
To resolve the issue in this example, do the following:- Open the IIS 7 console, expand SBS Web Applications and click on Autodiscover.
- Double-click Authentication.
- Right-click Basic Authentication and select Edit...
- In the Realm field, type the server's public hostname in the format hostname.domain.tld and then click OK.
- If applicable (e.g.: on Windows SBS 2008), repeat the above process for the Microsoft-Server-ActiveSync and EWS websites in addition to Autodiscover.
Performing the same test in this example should now yield the following response:
HTTP/1.1 401 Unauthorized
Content-Type: text/html
Server: Microsoft-IIS/7.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
WWW-Authenticate: Basic realm="hostname.domain.tld"
X-Powered-By: ASP.NET
Date: Fri, 05 Sep 2014 16:30:41 GMT
Connection: close
Content-Length: 58
You do not have permission to view this directory or page.read:errno=0
Labels:
exchange,
http,
iis,
linux,
pci compliance,
sbs,
security,
server,
tips,
troubleshooting,
windows
Monday, September 10, 2012
Get Out of a Windows 7 Update Loop
If you've just installed Windows Updates and Windows is stuck in a loop of applying updates and then rebooting, try this method (adapted from an answer in this forum):
- Insert the Recovery/Install DVD into the computer.
- Boot off of the DVD. When you first start your computer, the first screen you see should give you the key combination to press to enter a 'multi-boot' menu. On an HP, hit Esc then F9 for the boot menu (or F11 for recovery if you don't have a DVD). On a Dell, hit F12 for the boot menu. It varies by each manufacturer. Once you find it and are at the multi-boot menu, choose to boot from CD/DVD.
- When prompted (after it has booted to the DVD) choose "repair my computer" and enter the command prompt.
- Type C: (with colon) and press enter.
- Then type cd c:\windows\winsxs and press enter.
- Then type del pending.xml and press enter.
- Restart your computer.
Wednesday, November 2, 2011
Automate network printer installation via logon script
If you manage a Windows server and would like to have network printers automatically installed on users' workstations at logon via a batch script, here's how to do it.
To add a network printer:
To add a network printer:
rundll32 printui.dll,PrintUIEntry /in /q /n\\ServerName\PrinterNameTo delete a network printer:
rundll32 printui.dll,PrintUIEntry /dn /q /n\\ServerName\PrinterNameFor more information, read this TechNet article.
Friday, October 14, 2011
A better way to send large files
If you've ever needed to send a file to somebody, but it was too big for e-mail or DropBox, you may have looked at services like YouSendIt. However, if you're concerned about the file being stored on a third-party server and somebody other than the intended recipient getting it, then perhaps you've been wary of services like that.
If so, then justbeamit is for you. It initiates a peer-to-peer connection between you and the recipient, allowing you to monitor the transfer in real time and avoiding the need to store it on a server somewhere. Once you close your browser window or navigate away from the page, the link to the file is invalidated.
justbeamit.com
If so, then justbeamit is for you. It initiates a peer-to-peer connection between you and the recipient, allowing you to monitor the transfer in real time and avoiding the need to store it on a server somewhere. Once you close your browser window or navigate away from the page, the link to the file is invalidated.
justbeamit.com
Thursday, September 29, 2011
Making hard and soft (symbolic) links in Windows
One great feature of Unix-like file systems is the ability to make links to other files and directories. Windows has had the ability to make shortcuts for a long time, but only since Vista has it had the ability to create soft (symbolic) links to files and directories and hard links to files.
You may be asking yourself, "What are links and why should I care?" In short, links work better than shortcuts and can allow you to do things you otherwise wouldn't be able to do.
For example, if you use Dropbox, you know that only files and folders in your Dropbox folder get synchronized. But, if you make a hard link in your Dropbox folder to a file outside of your Dropbox folder, it will get synchronized because the file now lives in both places. It does this without taking up any more space on the disk. Cool, right?
The following pages explain how links work and how to use them in more detail:
Using Symlinks in Windows Vista - The How-To Geek
How-To: Use Symbolic Links to Master Vista's File System
You may be asking yourself, "What are links and why should I care?" In short, links work better than shortcuts and can allow you to do things you otherwise wouldn't be able to do.
For example, if you use Dropbox, you know that only files and folders in your Dropbox folder get synchronized. But, if you make a hard link in your Dropbox folder to a file outside of your Dropbox folder, it will get synchronized because the file now lives in both places. It does this without taking up any more space on the disk. Cool, right?
The following pages explain how links work and how to use them in more detail:
Using Symlinks in Windows Vista - The How-To Geek
How-To: Use Symbolic Links to Master Vista's File System
Thursday, August 25, 2011
How to migrate user profiles to a different domain
If you've ever migrated a user's workstation from an old domain to a new domain, you know it's not a simple matter of dragging and dropping the contents of the profile directory in Windows Vista and 7 like it was in Windows XP. You have to manually copy selected files and folders and you lose all of the user's preferences.
That is, of course, unless you use the User Profile Wizard from ForensIT. This small, free utility makes it a breeze to migrate user profiles to a new domain.
That is, of course, unless you use the User Profile Wizard from ForensIT. This small, free utility makes it a breeze to migrate user profiles to a new domain.
Tuesday, July 26, 2011
Manage Microsoft Updates via LogMeIn Central
LogMeIn Pro and Central users can now manage Microsoft Updates via the LogMeIn Central interface.
Tuesday, June 21, 2011
Dropbox glitch exposed user files; how to protect yourself against future breaches
On Saturday, Dropbox had a major security breach for four hours, effectively allowing anyone to log into any Dropbox account without knowing the password. The glitch was fixed moments after it was discovered and less than 1% of users were potentially affected. Nevertheless, the incident raises security concerns.
An article in Lifehacker details how to add a second layer of security to your Dropbox account using programs such as TrueCrypt.
An article in Lifehacker details how to add a second layer of security to your Dropbox account using programs such as TrueCrypt.
Tuesday, June 14, 2011
How to manually import an NK2 file into Outlook 2010
If you want to manually import an Outlook 2007 or earlier NK2 (nickname database) file into Outlook 2010, read this article.
Friday, June 3, 2011
How to protect your Facebook sessions from being hijacked
Users of Facebook beware! There is a new Android app called FaceNiff that can hijack Facebook sessions in one tap.
To protect yourself, enable HTTPS in your account settings.
To protect yourself, enable HTTPS in your account settings.
Automatically assigning applications to Windows domain computers
If there's an application that you want to automatically install on every computer in your Windows domain, read this article.
I'm currently in the process of implementing automated installation of LogMeIn remote access software on every workstation in the domain at a couple of client sites. One site uses Windows SBS 2003, which has its own way of assigning applications. The other site does not have SBS; just Windows Server 2003. At that site, I used the method described in the article referenced above and it worked perfectly.
I'm currently in the process of implementing automated installation of LogMeIn remote access software on every workstation in the domain at a couple of client sites. One site uses Windows SBS 2003, which has its own way of assigning applications. The other site does not have SBS; just Windows Server 2003. At that site, I used the method described in the article referenced above and it worked perfectly.
Friday, May 20, 2011
Lock Down Your Computer Like the NSA
Here is an article from Lifehacker about how to secure your computer like the NSA. It links to the NSA web page with documents on securing Windows, Mac, Linux and Solaris.
Wednesday, May 11, 2011
Facebook leaked personal data to advertisers
According to this article, a vulnerability in some Facebook apps allowed third-party advertisers to access security tokens that act as a spare key to users' profiles, allowing them to read posts and access profile information.
While the article points out that the advertisers may not have known they had the ability to do that and Facebook has now fixed the vulnerability, those security tokens may still exist on third-party servers. To make sure you're protected, change your Facebook password.
While the article points out that the advertisers may not have known they had the ability to do that and Facebook has now fixed the vulnerability, those security tokens may still exist on third-party servers. To make sure you're protected, change your Facebook password.
Macs are not impervious to malware
This article in Lifehacker makes a very good point: As Macs capture greater market share, attackers have greater incentive to write malware that targets Mac OS.
Macs are not impervious to malware. The author predicts that it's only a matter of a couple of years until Mac users will need to get serious about protecting their Macs from infections.
Macs are not impervious to malware. The author predicts that it's only a matter of a couple of years until Mac users will need to get serious about protecting their Macs from infections.
Friday, February 11, 2011
CAT
There's a website called CAT that is basically a TV calendar. It lets you create an iCal feed that you can then import into your preferred calendar program.
I use it in Google calendar and it works pretty well. The only problem is that the shows appear in Eastern time, even though I told it I'm in Pacific. Still, it lets me know what's going to be on TV each night.
http://pogdesign.co.uk/cat/
I use it in Google calendar and it works pretty well. The only problem is that the shows appear in Eastern time, even though I told it I'm in Pacific. Still, it lets me know what's going to be on TV each night.
http://pogdesign.co.uk/cat/
Thursday, January 6, 2011
Don't disable IPv6 in Windows SBS 2008
If you disable IPv6 on your network interface in Windows SBS 2008 and then reboot, you will be stuck waiting for 30-60 minutes at the "Applying computer settings..." screen. According to the following blog posts, SBS 2008 relies on IPv6:
Post 1
Post 2
Post 1
Post 2
Subscribe to:
Posts (Atom)