<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tech blog &#187; Uncategorized</title>
	<atom:link href="http://www.chrismadge.com/tech/category/uncategorized/feed" rel="self" type="application/rss+xml" />
	<link>http://www.chrismadge.com/tech</link>
	<description></description>
	<lastBuildDate>Mon, 21 Jun 2010 19:15:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SCCM 2007 and Operating System Deployment</title>
		<link>http://www.chrismadge.com/tech/sccm-2007-and-operating-system-deployment</link>
		<comments>http://www.chrismadge.com/tech/sccm-2007-and-operating-system-deployment#comments</comments>
		<pubDate>Mon, 21 Jun 2010 19:15:19 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=106</guid>
		<description><![CDATA[A great high level overview from the Deployment Guys @ Microsoft
Deployment Guys Link
Video
]]></description>
			<content:encoded><![CDATA[<p>A great high level overview from the Deployment Guys @ Microsoft</p>
<p><a href="http://go2.wordpress.com/?id=725X1342&amp;site=infraops.wordpress.com&amp;url=http%3A%2F%2Fblogs.technet.com%2Fdeploymentguys%2Farchive%2F2008%2F03%2F20%2Fsccm-2007-and-microsoft-deployment-toolkit-video-walkthrough.aspx&amp;sref=http%3A%2F%2Finfraops.wordpress.com%2F2008%2F03%2F24%2Fwatch-learn-sccm-and-ms-deployment-toolkit-video-walkthrough%2F" target="_blank">Deployment Guys Link</a></p>
<p><a href="http://wm.microsoft.com/ms/SAT/ricsmith/SCCM2007%20and%20Microsoft%20Deployment%20Toolkit%20Setup%20and%20Config.wmv" target="_blank">Video</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/sccm-2007-and-operating-system-deployment/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The wonder that is LastPass</title>
		<link>http://www.chrismadge.com/tech/lastpass</link>
		<comments>http://www.chrismadge.com/tech/lastpass#comments</comments>
		<pubDate>Mon, 25 Jan 2010 19:56:17 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=102</guid>
		<description><![CDATA[All it takes is you to be comprimised once for you to realize the importance of strong passwords. If your enterprise is anything like mine you will know that password complexity is the ultimate conundrum for IT administrators. If you make the password policy too complex people will simply write it down and attach it [...]]]></description>
			<content:encoded><![CDATA[<p>All it takes is you to be comprimised once for you to realize the importance of strong passwords. If your enterprise is anything like mine you will know that password complexity is the ultimate conundrum for IT administrators. If you make the password policy too complex people will simply write it down and attach it to their computer via post it note.  If the password policy is too simple ir leaves your organization vulnerable to attack.</p>
<p>I myself have struggled with making my passwords complex enough but simple enough that I can remember. I have numerous systems and sites that I must log into on a daily basis and creating a individual complex password for each one seemed impossible until I discovered password managers.</p>
<p>Password managers have been around for quite a while but most have lacked user friendliness and most have lived on the desktop. Meaning if your hard drive dies or you forget the master password then you are hooped. I&#8217;ve tried several over the years from iKeePass to 1Password on the OSX platfrom and finally ewallet. None of these solutions really did it for me. I wanted a solution that worked cross platform and would sync with my mobile devices. This hasn&#8217;t existed until now.</p>
<p>A company out of Virginia called LastPass has created a hosted solution for your desktop, notebook and mobile devices that works with your choice of webbrowser. That&#8217;s right friends, you are not limited to using strictly Internet Explorer. LastPass allows you to use passwords up to 20 characters with any degree of complexity including special characters. It stores your passwords using 256 bit AES encryption on their host proof servers. What this means is that the passwords are encrypted locally before being transported across the network. Especially important if you are worried about things like Man in the middle attacks. One of the things I like most about last pass is that it is only $1/month. Even on a lowly Systems Admin salary I can afford a dollar a month.</p>
<p>I highly recommend this product. This product can be ordered directly from the the vendor at <a href="http://www.lastpass.com">http://www.lastpass.com</a></p>
<p> </p>
<p>-chris</p>
<p> </p>
<p> </p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/lastpass/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Investigating Local Workstations</title>
		<link>http://www.chrismadge.com/tech/investigating-local-workstations</link>
		<comments>http://www.chrismadge.com/tech/investigating-local-workstations#comments</comments>
		<pubDate>Fri, 27 Nov 2009 20:32:44 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Desktop Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=78</guid>
		<description><![CDATA[In any organization one of it&#8217;s greatest assets is it&#8217;s employees. However, in the information age of it&#8217;s greatest liabilities is it&#8217;s employees.  I cannot tell you the horror stories of compromised information and systems that I have across in my days as a System Engineer.   In my current role, I frequently get escalations and [...]]]></description>
			<content:encoded><![CDATA[<p>In any organization one of it&#8217;s greatest assets is it&#8217;s employees. However, in the information age of it&#8217;s greatest liabilities is it&#8217;s employees.  I cannot tell you the horror stories of compromised information and systems that I have across in my days as a System Engineer.   In my current role, I frequently get escalations and automated notifications on compromised workstations. The initial part of investigating these workstation often needs to be done without the end user&#8217;s knowledge and interaction. This means I need to leverage 3 different interfaces (WMI, RPC and FS). The first thing that I want to know is&#8230;</p>
<p><strong>What has the end user installed? </strong></p>
<p>If your users are anything like my end users, they violate the Acceptable Use Policy (AUP) with great vigour. They install all kinds of garbage on their notebook that A) has no business purpose B) comes with hidden bonus items such as trojans and backdoors. C) Violates various licensing laws and rules.</p>
<p> <img class="alignright size-full wp-image-80" title="SCCM_Resource_Explorer" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/11/SCCM_Resource_Explorer1.jpg" alt="SCCM_Resource_Explorer" width="178" height="134" /></p>
<p>My primary method of investigating installed Software is with the SCCM <strong>Resource Explorer</strong> tool. This leverages the WMI interface and gives me a nice list of installed products. If i start seeing items such as Bit-Torrent clients I automatically know that this is not going to end well. </p>
<p>Sometimes though for some strange reason the workstation i&#8217;m trying to investigate does not have the SCCM client on it. This is when use a great free tool from the folks at <a href="http://www.manageengine.com" target="_blank">Manage Engine</a>. They come out with some free tools that allow you to leverage the RPC interface. One of the tools included in the package is one called <strong>Software Inventory.</strong> This tools connects to the remote machine and uses your admin credentials to create a list of Software Installed.</p>
<p><img class="alignright size-medium wp-image-81" title="Windows_Tools_2" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/11/Windows_Tools_2-300x76.jpg" alt="Windows_Tools_2" width="300" height="76" /></p>
<p>Once you know what is installed you can go ahead you often have a good idea what you are dealing with. Often it&#8217;s just time to reimage the workstation. However, if you don&#8217;t have any evidence to support the reimage. You then need to proceed further the next step is investigating the applications in the &#8216;Startup&#8217; category.</p>
<p><strong>MSCONFIG</strong></p>
<p>MSConfig is a great place to look for viruses/trojans that start with the workstation. In the last year though, I&#8217;ve noticed that the trojans are getting a lot more tricky and do not show up in MSConfig. <img class="alignright size-medium wp-image-83" title="msconfig" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/11/msconfig-300x198.jpg" alt="msconfig" width="300" height="198" /></p>
<p><strong>Trend Micro &#8211; HiJack This</strong></p>
<p>HiJack this used to be an opensource tool until it was bought by Trend Micro. This tool allows you to see what starts when the operating system is powered up. What Browser Helper Objects are integrated into the browser. If you start to see items and DLL&#8217;s registered that should not be there. You definitely might want to investigate further. Trend still offers HiJack This for free on their website or at download.com</p>
<p> </p>
<p><strong>Run Once</strong></p>
<p>The next place you want to look is the &#8220;Run Once&#8221; portions of the Windows Registry. This is often where Trojans and Viruses hide themselves.  The Registry Keys that you want to look at are:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</p>
<p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<img class="alignright size-medium wp-image-87" title="RegEdit3" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/11/RegEdit31-300x97.gif" alt="RegEdit3" width="300" height="97" /></p>
<p><strong>Services</strong></p>
<p>The services MMC console is another great place to look for Viruses and Trojans. A quick perusal of the running services might indicate an infection and depending on the infection will determine the remediation. <img class="alignright size-medium wp-image-86" title="services.msc" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/11/services.msc-300x182.jpg" alt="services.msc" width="300" height="182" /></p>
<p>If after investigating these areas you still suspect an infection there are numerous types of free tools that you can use.</p>
<p>1. Sysinternals <a href="http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx" target="_blank">RootKit Revealer</a></p>
<p>2. <a href="http://www.gmer.net">Gmer</a></p>
<p>3. <a href="http://www.f-secure.com/en_EMEA/security/security-lab/tools-and-services/blacklight/">F-Secure BlackLight</a></p>
<p>In the organization I currently work for we had a scenario where a certain area of users did not get patched and ended up getting infected with the Conficker Virus. <a href="http://www.sophos.com" target="_blank">Sophos Software </a>has created a great tool to remove the Conficker Worm/Virus it can be found <a href="http://www.sophos.com/products/free-tools/conficker-removal-tool.html" target="_blank">here</a>.</p>
<p><img class="alignright size-medium wp-image-89" title="sophosscan" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/11/sophosscan-300x151.png" alt="sophosscan" width="300" height="151" /></p>
<p>The information security world is definitely a scary one and there is definitely a lot at stake. You don&#8217;t need to know necessarily everything  about every virus that comes out. It is simply a matter of knowing the key parts of the system to investigate and learning to use Google to investigate the methodology your infection uses as well as the impact on the system.</p>
<p>If you have any questions or need a little extra help. I&#8217;d be glad to lend a hand chris (at) chrismadge.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/investigating-local-workstations/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 for Students &#8211; $39.99</title>
		<link>http://www.chrismadge.com/tech/windows-7-for-students-39-99</link>
		<comments>http://www.chrismadge.com/tech/windows-7-for-students-39-99#comments</comments>
		<pubDate>Tue, 10 Nov 2009 01:42:43 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=75</guid>
		<description><![CDATA[Microsoft has made Windows 7 Home Premium and Professional available to students at certain Canadian Universities for as cheap as $39.99 CAD.. This deal only lasts until January 3rd so get on it..

 
 
 
 
 
http://www.microsoft.com/canada/windows/discoverytour/student.aspx?wt.mc_id=can_co-win7launch-en_vanity_student
]]></description>
			<content:encoded><![CDATA[<p>Microsoft has made Windows 7 Home Premium and Professional available to students at certain Canadian Universities for as cheap as $39.99 CAD.. This deal only lasts until January 3rd so get on it..</p>
<p><img class="alignleft size-medium wp-image-76" title="Windows_7_Student" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/11/Windows_7_Student-300x148.jpg" alt="Windows_7_Student" width="300" height="148" /></p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p><a href="http://www.microsoft.com/canada/windows/discoverytour/student.aspx?wt.mc_id=can_co-win7launch-en_vanity_student">http://www.microsoft.com/canada/windows/discoverytour/student.aspx?wt.mc_id=can_co-win7launch-en_vanity_student</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/windows-7-for-students-39-99/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Signs you might be infected with a virus or trojan</title>
		<link>http://www.chrismadge.com/tech/signs-you-might-be-infected-with-a-virus-or-trojan</link>
		<comments>http://www.chrismadge.com/tech/signs-you-might-be-infected-with-a-virus-or-trojan#comments</comments>
		<pubDate>Fri, 11 Sep 2009 04:12:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=50</guid>
		<description><![CDATA[
Getting new popups every 5 seconds
Internet homepage is now something similar http://www.nigerianscampharmacia.co.za
After typing google.ca into your webbrowser you go somewhere other than google.
Workstation is REALLY slow. Attempts to kill the processes that are using up all the memory and processing power fail
If there are new programs installed on your workstation like “Antivirus 2010” that you [...]]]></description>
			<content:encoded><![CDATA[<ol>
<li>Getting new popups every 5 seconds</li>
<li>Internet homepage is now something similar <a href="http://www.nigerianscampharmacia.co.za/">http://www.nigerianscampharmacia.co.za</a></li>
<li>After typing google.ca into your webbrowser you go somewhere other than google.</li>
<li>Workstation is REALLY slow. Attempts to kill the processes that are using up all the memory and processing power fail</li>
<li>If there are new programs installed on your workstation like “Antivirus 2010” that you did not install.</li>
<li>Your antivirus software is disabled</li>
<li>Applications lock up or crash for no apparent reason</li>
<li>You cannot access certain drives</li>
<li>You cannot print</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/signs-you-might-be-infected-with-a-virus-or-trojan/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing RDP on a Windows XP Machine</title>
		<link>http://www.chrismadge.com/tech/securing-rdp-on-a-windows-xp-machine</link>
		<comments>http://www.chrismadge.com/tech/securing-rdp-on-a-windows-xp-machine#comments</comments>
		<pubDate>Tue, 05 May 2009 00:12:14 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=26</guid>
		<description><![CDATA[//taken from mobydisk.com
Remote Desktop, Unsafely
Many people use the Windows XP Professional remote desktop feature to gain easy  				access to their home PCs. But opening up a connection to an administrator  				account on your system is very dangerous. Just by opening the port on my  				firewall I received several logon attempts, from various [...]]]></description>
			<content:encoded><![CDATA[<h2>//taken from mobydisk.com</h2>
<h2>Remote Desktop, Unsafely</h2>
<p>Many people use the Windows XP Professional remote desktop feature to gain easy  				access to their home PCs. But opening up a connection to an administrator  				account on your system is very dangerous. Just by opening the port on my  				firewall I received several logon attempts, from various countries, within a  				week. Free tools exist that assist hackers with breaking into Windows Remote  				Desktop connections. Fortunately there are a few simple steps you can take to  				protect yourself:</p>
<h2>Remote Desktop, Safely</h2>
<h3>Limit users who can log on remotely</h3>
<p>First, only allow certain users remote desktop access. Go to the Control Panel,  				then system, then the Remote tab.</p>
<p><img src="http://www.mobydisk.com/techres/Remote_Desktop_Enable.png" alt="Screen shot showing remote desktop control panel tab" /></p>
<p>From there, enable &#8220;Allow users to connect remotely to this computer.&#8221; Then,  				click &#8220;Select Remote Users.&#8221;</p>
<p><img src="http://www.mobydisk.com/techres/Remote_Desktop_Users.png" alt="Screen shot showing remote desktop screen" /></p>
<p>Here, add only the users who you want to be able to log in remotely. If you are  				super-secure, you can set this to a standard user account, and force yourself  				to run as a normal user. This is a very difficult way to run Windows since many  				applications assume the user has Administrator rights, so I leave that decision  				up to you.</p>
<p>Unfortunately for you, that setting didn&#8217;t do a thing! You will find that you  				can still log on as any administrator account. To make things complicated,  				Microsoft defaults to the least secure setting possible while hiding this fact  				from the user. You will need to go to another location to change the <em>real</em> list. Click Start &#8211; Programs &#8211; Administrative Tools &#8211; Local Security Policy. If  				you can&#8217;t find it, you can also do Start &#8211; Run &#8211; enter  				&#8220;%SystemRoot%\system32\secpol.msc /s&#8221; &#8211; Ok.</p>
<p><img src="http://www.mobydisk.com/techres/Remote_Desktop_Users_Allowed1.png" alt="Screen shot showing local security settings" /></p>
<p>Under Local Policies &#8211; User Rights Assignment, there is a line that says &#8220;Allow  				logon through Terminal Services.&#8221; And just next to it is &#8220;Administrators,  				Remote Desktop Users.&#8221; Aha! Too bad it didn&#8217;t show &#8220;Administrators&#8221; in the  				other screen. Double-click this setting and remove &#8220;Administrators.&#8221; If you  				want an administrator to have access, just add them explicitly through the  				other screen.</p>
<p><img src="http://www.mobydisk.com/techres/Remote_Desktop_Users_Allowed2.png" alt="Screen shot showing Terminal Services users" /></p>
<h3>Set an account lockout policy</h3>
<p>There are already tools that will use brute-force to guess passwords and log-on  				remotely. You cannot stop this, but it can be minimized by setting an account  				lockout policy. If someone tries to guess the password, then after a few  				guesses they will be locked out for a period of time. This can make hours or  				days of guessing become centuries. That makes it infeasable to brute-force into  				your system.</p>
<p>From the same Local Security Policy screen from before, go to Account Policies &#8211;  				Account Lockout Policy.</p>
<p><img src="http://www.mobydisk.com/techres/Account_Lockout_Policy.png" alt="Screen shot showing a minimal account lockout policy" /></p>
<p><span style="text-decoration: underline;"><em>Account lockout threshhold:</em></span> This is the number of failed logon  				attempts before the user is locked-out. Three is usually sufficient to indicate  				someone is trying to break in.</p>
<p><span style="text-decoration: underline;"><em>Reset account lockout counter after:</em></span> For a typical home system,  				set this setting to be the same as the <em>Account Lockout Duration</em> below.</p>
<p><em><span style="text-decoration: underline;">Account lockout duration:</span></em> This is how long the user will be  				unable to logon after several failed attempts. Even a few minutes will  				significantly reduce the possibility of a remote brute-force attack. For a home  				system, any more than a few minutes can be frustrating. You may come home to  				find your account is locked-out because of some joker guessing passwords.  				Adjust the setting to your own tolerance. Setting this value to zero means to  				lock the account until it is manually unlocked.</p>
<p>To manually unlock an account you must logon as another administrator user  				(preferably one without remote desktop access). Then go to Start &#8211; Programs &#8211;  				Administrative Tools &#8211; Computer Management &#8211; Local Users and Groups. Click on  				the individual user and uncheck the &#8220;account is disabled&#8221; check box. You may  				then log on as that user.</p>
<p><img src="http://www.mobydisk.com/techres/Computer_Management_Unlock_User.png" alt="Screen shot showing the 'Account is disabled' checkbox on the user property page" /></p>
<h3>Require Passwords and 128-Bit Encryption</h3>
<p>For compatibility with older, weaker, less-secure clients, Windows XP defaults  				to allowing minimal or no encryption on remote desktop connections. If you are  				connecting with older software, upgrade it. If you are connecting with the  				PocketPC Terminal Services Client, then this setting won&#8217;t work for you since  				that client does not support high encryption. <img src='http://www.chrismadge.com/tech/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>Click Start &#8211; Run &#8211; &#8220;%SystemRoot%\system32\gpedit.msc /s&#8221; to get to the Group  				Policy Editor. I don&#8217;t know how to get there any easier than that, so you might  				want to add an icon for it to your Administrative Tools.</p>
<p>From here, go to Computer Configuration &#8211; Administrative Templates &#8211; Windows  			Components &#8211; Terminal Services &#8211; Encryption and Security.</p>
<p><img src="http://www.mobydisk.com/techres/Terminal_Services_Encryption_And_Security.png" alt="Screen shot showing Terminal Services Security settings in the Group Policy" /></p>
<p>You can change the &#8220;Set client connection encryption level&#8221; from &#8220;Not  				Configured&#8221; to &#8220;Enabled&#8221; and &#8220;High Level&#8221; to force the client to use 128-bit  				security. This protects your passwords as well as anything transmitted during  				your terminal service session.</p>
<p>Enabling &#8220;Always prompt client for password upon connection&#8221; prevents the remote  				user from saving the password on the client computer and avoiding the password  				prompt. Saving passwords is generally a dangerous setting since the password is  				now on another computer, and because it allows the user to forget it.</p>
<h3>Change the TCP Port</h3>
<p>You can move the terminal services port from 3389 to  			another port by changing the registry key at</p>
<p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal  				Server\WinStations\RDP-Tcp\PortNumber</p>
<p>You will then need to specify the port when you  			connect to your system. Connect with something like  			&#8220;my.computerathome.com:1234&#8243; instead of &#8220;my.computerathome.com&#8221;</p>
<h3>IP Address White List</h3>
<p>Windows Firewall allows you to limit which IP addresses have access to remote desktop. 			To do this, open the Control Panel and run Windows Firewall.  Select the Exceptions 			tab and make sure &#8220;Remote Desktop&#8221; is checked.</p>
<p><img src="http://www.mobydisk.com/techres/windows_firewall.png" alt="Windows Firewall control panel screen shot" width="434" height="518" /></p>
<p>Click the &#8220;Edit&#8221; button and you will see a list of TCP ports. Windows Firewall assumes that Remote Desktop lies on port 3389. If you changed the port number, you will need cancel this screen and instead click &#8220;Add Port&#8221; and create a entry with the port number you used.</p>
<p><img src="http://www.mobydisk.com/techres/windows_firewall_tcp3389.png" alt="Windows Firewall TCP port screen shot" width="384" height="287" /></p>
<p>Click the &#8220;Change Scope&#8221; button.  From this screen, you can limit to the local network, or to a specific set of IP addresses.</p>
<p><small>Thanks to <a href="http://nickm.co.uk/" target="_blank">Nick</a> for this tip!</small></p>
<p><img src="http://www.mobydisk.com/techres/windows_firewall_scope.png" alt="Windows Firewall IP address edit screen" width="428" height="298" /></p>
<h3>Prevent a MITM Attack</h3>
<p>Remote desktop is encrypted, which makes it more secure than many simplistic  			VNC implementations. However, without additional security Remote Desktop is vulnerable to a  			<a href="http://en.wikipedia.org/wiki/Man-in-the-middle" target="_blank">man-in-the-middle attack</a> because it does not use a certificate to authenticate  			the server like SSL/SSH does. That means that if you connect to a your system  			via remote desktop, there is no guarantee that the conversation is not recorded  			and your passwords are not guaranteed to be safe, even though the session is  			encrypted.</p>
<p>On Windows XP, there is no built-in support for secure certificates in remote desktop. Therefore, to close this security hole you must use <a href="http://www.shebeen.com/vnc_ssh/" target="_blank">SSH tunneling over a VNC connection.</a> However, Windows Server 2003 provides an enhanced version of terminal services that supports 			security authentication via TLS.  For this to work, you must be using an <a href="http://www.petri.co.il/download_rdp_client_60.htm" target="_blank">updated 			version of the Remote Desktop Client software</a>.  You must also configure Windows Server 2003 to <a href="http://support.microsoft.com/kb/895433" target="_blank">use a 			certificate</a> as described in the Microsoft Knowledge Base article.</p>
<h3>Monitor Log Files</h3>
<p>The Event Viewer logs failed login attempts and account lockouts. You can  			periodically check this to see if anyone is trying to get in. If your firewall  			keeps logs (Windows Firewall does) then you can use these to see when someone  			tries to connect.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/securing-rdp-on-a-windows-xp-machine/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What are you worth?</title>
		<link>http://www.chrismadge.com/tech/what-are-you-worth</link>
		<comments>http://www.chrismadge.com/tech/what-are-you-worth#comments</comments>
		<pubDate>Tue, 21 Apr 2009 01:12:07 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=16</guid>
		<description><![CDATA[A itworld canada site gives average income of similar positions in your geographical area..
http://www.itworldcanada.com/salarycalculator/calculator.aspx

]]></description>
			<content:encoded><![CDATA[<p>A itworld canada site gives average income of similar positions in your geographical area..</p>
<p>http://www.itworldcanada.com/salarycalculator/calculator.aspx</p>
<p><img src="file:///Users/christophermadge/Library/Caches/TemporaryItems/moz-screenshot.jpg" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/what-are-you-worth/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blackberry App World not an April Fools Joke</title>
		<link>http://www.chrismadge.com/tech/blackberry-app-world-not-an-april-fools-joke</link>
		<comments>http://www.chrismadge.com/tech/blackberry-app-world-not-an-april-fools-joke#comments</comments>
		<pubDate>Wed, 01 Apr 2009 22:58:28 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=13</guid>
		<description><![CDATA[After months and months of waiting the Blackberry App World finally opened. I will admit I had low expectations of the Blackberry version of the Apple App Store.  However, when the store opened last night at 9pm PST. I admit I was quite impressed. Lots of new applications including several free offerings , including the [...]]]></description>
			<content:encoded><![CDATA[<p>After months and months of waiting the Blackberry App World finally opened. I will admit I had low expectations of the Blackberry version of the Apple App Store.  However, when the store opened last night at 9pm PST. I admit I was quite impressed. Lots of new applications including several free offerings , including the Poynt application and the Shazam Application  which was the focus of an Apple commericial for the iPhone. I&#8217;m excited to see what new applications come to the store in the next few months and today i&#8217;m really glad I own a blackberry&#8230;</p>
<div id="attachment_14" class="wp-caption alignleft" style="width: 310px"><a href="http://na.blackberry.com/eng/services/appworld/?"><img class="size-medium wp-image-14" title="content_back_appworld" src="http://www.chrismadge.com/tech/wp-content/uploads/2009/04/content_back_appworld-300x183.jpg" alt="Blackberry App World" width="300" height="183" /></a><p class="wp-caption-text">Blackberry App World</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/blackberry-app-world-not-an-april-fools-joke/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hiatus</title>
		<link>http://www.chrismadge.com/tech/hiatus</link>
		<comments>http://www.chrismadge.com/tech/hiatus#comments</comments>
		<pubDate>Wed, 01 Apr 2009 22:45:12 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=11</guid>
		<description><![CDATA[So I realize I have spend the last 6 months without an update. This is not to say that I haven&#8217;t learned anything or nothing new has happened in the technological world. It&#8217;s well I just got busy&#8230; Look forward to more regular updating from now on.  
]]></description>
			<content:encoded><![CDATA[<p>So I realize I have spend the last 6 months without an update. This is not to say that I haven&#8217;t learned anything or nothing new has happened in the technological world. It&#8217;s well I just got busy&#8230; Look forward to more regular updating from now on. <img src='http://www.chrismadge.com/tech/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/hiatus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Brute Force Removing a Mailbox from Exchange 2007</title>
		<link>http://www.chrismadge.com/tech/brute-force-removing-a-mailbox-from-exchange-2007</link>
		<comments>http://www.chrismadge.com/tech/brute-force-removing-a-mailbox-from-exchange-2007#comments</comments>
		<pubDate>Mon, 01 Sep 2008 21:42:32 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.chrismadge.com/tech/?p=9</guid>
		<description><![CDATA[So there is a time in every organization where an employee who was involved in everything leaves. He/She was an integral part of many different projects and it comes time to remove them from the Exchange Organization.
You done all the standard stuff that you have been required to by various laws and regulations. You have [...]]]></description>
			<content:encoded><![CDATA[<p>So there is a time in every organization where an employee who was involved in everything leaves. He/She was an integral part of many different projects and it comes time to remove them from the Exchange Organization.</p>
<p>You done all the standard stuff that you have been required to by various laws and regulations. You have archived the users mail. You have made sure that all of their files are backed up and stored safely. Before you hit Remove Mailbox in the Exchange Management Console let me tell you a little story about disconnected mailboxes.</p>
<p>Disconnected Mailbox Storage is the Recycle Bin for Exchange Organizations. It allows the Exchange System Administrator to go “Oh Crap we still needed that”. When you click remove mailbox it doesn’t actually remove the mailbox. It just moves the mailbox to the ‘Disconnected Mailboxes Grouping’ the time that Exchange holds the mailbox before permanently deleting the mailbox is 30 days. For most users this works out perfectly.</p>
<p>There is however a time and a place where you will want to remove all instances of that user from your Exchange organization. This scenario would be like the one I described above. Where the user who is being removed was receiving meeting requests for the Project Manager and answering vacation emails for the Vice President but never removed the delegation. If you simply remove the mailbox the delegations will remain and cause bounced email for every meeting request. To solve this problem there is a very simple Exchange Powershell Command that goes like this:</p>
<p><strong>Remove-Mailbox -Identity contoso\john -Permanent $true</strong></p>
<p>Exchange Shell will then ask if you want to remove associations. The answer to that question is Yes to all.</p>
<p>The powershell command will complete and it will be like the mailbox was never in the Exchange Organization.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chrismadge.com/tech/brute-force-removing-a-mailbox-from-exchange-2007/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
