Yubikey now with AD integration

yubikeyI got a newsletter some time ago informing me that www.Yubico.com (or rather one of it’s partners) had added AD integration to the Yubikey, this should allow you to use the Yubikey to login to windows something that could be quite interesting..

Read more here;
http://www.yubico.com/news/100204/

ps.
I also seem to recall stumbling across some PAM and RADIUS implementation, so you might want to check their forum if you are into Yubikeys.
http://forum.yubico.com/

Microsoft App Virtualization – the fun never ends

So as described earlier I was messing with Softgrid (now Microsoft Application Virtualization) and had some issues getting it to work, so I decided to move to the latest version (thus the name change), we was using 4.2 and the latest version is 4.5.

Anyhow, I upgraded the sequencer and everything seemed fine, I started a capture and everything seemed fine until I started the Java installer, i now got an error from the MSI installer;

javafejl

Error 1719.The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance.

Odd I thought and tried different approaches which all led to the same error.

A bit of googling led me to this;

http://social.technet.microsoft.com/forums/en-US/appvbeta/thread/1c5f8f8f-d431-4b7f-9601-40c1aef0409c/

The problem is simple yet bizzar, you can’t use remote desktop while doing a capture!?!?  I was using a virtual pc (HyperV) and used remote desktop to connect and do my capture, however once I restarted the Virtual Machine and did the capture via the HyperV console there was no problem!?  Odd…

Softgrid tool and guide

So I had to brush a bit up on my Softgrid knowledge for a package build and I came across a few things I’d like to share;

  1. A super guide to Softgrid building by one of the Guru’s on the field (Chris Lord).
    http://myitforum.com/cs2/files/folders/120058/download.aspx
  2. A neat util to explore Softgrid packages without installing the sequencer. SFT Explorer.
    sftexpl_screenshot_tb
    http://www.virtualapp.net/sft-explorer.html

As of right now I haven’t really gotten my package to work, I have to include an old version of Java with a link to a web-site.  But even if I set the registry to override it still fail to launch the old java, if no java is on the machine in advance it works like a dream..  We are currently using the old 4.2 sequencer so I might try the 4.5 version to see if any improvements has been made.

Kingston 128gb flash drive (Fake?)

fake128So I stumbled across a Kingston Data Traveller 128gb USB flash drive for US$ 27,- on Ebay.co.uk –  now with a retail price of US$ 527,- this is beyond totally cheap..  Sadly it is likely a fake drive, but hey with the PayPal buyers protection program (and a price as low as this)  I’m not that concerned about possibly loosing a penny or two… Also it would be interesting to get a fake pen to the lab and see how it works under the hood.

And who knows, I may just be lucky and get a bargain ;-)

A few interesting links when it comes to fake USB pens;
http://sosfakeflash.wordpress.com/article-list/ 
http://fixfakeflash.wordpress.com/
http://reviews.ebay.co.uk/BEWARE-of-FAKE-128GB-256GB-USB-Flash-Drives-on-eBay_W0QQugidZ10000000001236067

Keyboard confusion

Have you ever had to support users with a different national keyboard than yours?

If so you may have noticed that national keyboards can vary quite a lot!?

Anyway, here is a few links to graphical depictions of national keyboards, then you at least stand a fighting chance :-)

http://en.wikipedia.org/wiki/Keyboard_layout
http://msdn.microsoft.com/en-us/library/cc195104.aspx

OpenDNS newsletter – granular control of blocked sites

I just read a news letter from OpenDNS in which they state that they are now offering a paid solution where you get granular control of blocked sites.  Basically this mean that you can allow yourself (or equally important persons ;-) to bypass all the site blocking your site otherwize uses..  That seem quite clever..

Sitation from the newsletter;
A lightweight and innovative approach to per-user access controls, OpenDNS Web content filtering empowers you to grant individuals on your network permission to bypass blocked pages. No appliance. No software. It works efficiently through the cloud.

Free mini IDS – DecaffeinatID: a security util

arpgatewayEver heard about ARP spoofing or man in the middle attacks?  If not then this may not be for you, but if on the other hand “Yes” then here is a tool for you..

Our pal Irongeek has released this nifty small util “DecaffeinatID:” that will sit in your tray until it detects something nasty going on (like eg. attempted ARP spoofing of your default gateway) and then raise hell and bells to warn you.

Basically what it does it to monitor the MAC address of your default gateway, if this for some reason changes (which it never should) you will be warned and can take precautions.

Besides this ARP ’shield’ the util offers a few other nifty security tricks, anyway check it out at;
http://www.irongeek.com/i.php?page=security/decaffeinatid-simple-ids-arpwatch-for-windows

securitylog

Online Backup – followup

carboniteI just heard one of my favorite podcasts this morning, in this they talked about Carbonite and how they have actually changed their crypto policy lately. Before you had to rely on their crypto keys, which meant that although all your data was encrypted both during transport and storage it could basically be decrypted by Carbonite employees (yes yes, court order and all I know, but still I like my data to be 10000% private), however now you can set your own AES key (256bit as I recall) and thus data is 100% private..

This does make Carbonite an interesting player once again…  I may just have to give them a spin to see how it works.

Yet another player came to my attention, I have not heard about this before nor do I know much more than stated on their website; www.backblaze.com

So to summarize;

Idrive (I use this myself, but am considering Carbonite to get more space)
Pros;Cheap (around 55$ a year), versioning of files, good gui with tons of tweaking, scheduled backup
Cons;“only” 150gb storage, gui could do with an update lots of options but not pretty
Review; http://online-data-backup-review.toptenreviews.com/idrive-review.html
Review; http://www.dansdata.com/idrive.htm

Carbonite (I have not tested this myself and thus know only little about it)
Pros; Cheap (around 55$ a year), UNLIMITED storage
Cons;no versioning of files (only the latest version is backed up)
Review; http://www.maclife.com/article/reviews/carbonite

Backblaze (I have not tested this myself and thus know only little about it)
Pros; Cheap
Cons;No versioning of files
Review; http://www.maclife.com/article/reviews/backblaze

http://mozy.com/
Just learned about it, don’t know much about it.

http://www.sosonlinebackup.com/
Just learned about it, don’t know much about it. (I was warned it should be very costly).

https://spideroak.com/
Just learned about it, don’t know much about it.

KeepIT.com
Don’t even think about it :-)
http://www.kanmandet.dk/?p=80

Get notified when a service fails

If you are a sysadmin, then you know the problem with services of vital equipment that keep failing every now and again!?  So what do you do?  Wait for the users to start calling, buy an expensive monitoring solution or just do some simple scripting?

Well I’ll just give you a quick brief on how to setup the cheap (free) scripted solution that will help keep your users happy and the services running.

I was inspired by an article at; http://www.intelliadmin.com/index.php/2010/01/get-notified-when-a-service-fails/
which was quite cool except he rely on a third party utility for mailing AND he does not relaunch the service..   I have chosen to create a VBS script that will E-Mail AND re-launch the failed service in one sweep.

Ok here goes.

  • First of all log on to the server/workstation in question (the machine where the service is running).
  • Download my vbs script here  (you may need to rightclick and choose save as)
  • Modify this part of the script in notepad with your details (smtp server, email address etc)
    script1
  • Save the file to somewhere on the C drive (I usually use “c:\windows\schedule”)
  • Now enter “Computer management” (right click on My Computer and choose “Manage”)
    commanager
  • Select the service you wish to modify/monitor and double click it
  • Modify the service as follows (you will need to modify this if you use another location for the script)
    run_a_program
    You will note that I set the script to run at the “second fail” not the first, you can set it to run at the “first fail” if you like – to avoid being bombarded I just choose first to be informed the second time a service fail.
  • The service name (described in the script) is NOT the displayname, it is the REAL name of the service, you can find this here;
    servicename

And viola you are done, from now on you will get an E-Mail every time a service has failed twice (or the first time if you prefer)..  It’s all very basic but neat.

Gadget night at EBay

I just spend a few hours browsing around Ebay for interesting gadgets, and actually found a few;

First up, I actually ordered one of these – a SATA HDD docking station;
sata

Now this is clever, now I got both a card reader AND a HDD cradle, what need do you have for a HDD cradle you say?  Well now you can buy cheap SATA HDD’s and easily copy data to them for storage (no need for bulky cases and power supplies)..  Quite easy and simple..  and cheap as well I got this for about £ 17,-

WiFi;
wifi2
Having problems with reception or just going war-driving?  Well this gadget/wifi reciever claim up to 1000 feet coverage.  Not something I need, but interesting never the less.

Hand size wireless keyboard for Media Centers, PS3, XBox 360 etc.
kb

A cool small keyboard for your PS3 or mediacenter..  If I ever get around to either I would consider one of these for sure :-)