Sunday, March 3, 2013

ModSecurity

ModSecurity is an open source web application firewall for multiple platforms, such as Microsoft’s IIS and Apache.

http://www.modsecurity.org/

Enable/Disable Last Access Timestamp in Windows

The Last Access Time with a file or folder was disabled by default starting with Windows Vista, as it can add overhead to disk I/O.  To enable the Last Access Time feature, launch an administrative command prompt and use the following command:

fsutil behavior set disablelastaccess 0

fsutil_lastaccess

To disable the feature again in the future, use the same command but with a 1.

fsutil behavior set disablelastaccess 1

Saturday, March 2, 2013

Office 2013 and Touch Mode

Office 2013 includes a new Touch Mode, which hopefully helps when using the interface using a touch device.

First verify the Touch Mode icon is available via the Quick Access Toolbar.

office2013_touchmode_1

Click on the new icon to enable Touch Mode.

office2013_touchmode_2

 

Below is a before and after of the Word interface using the Touch Mode.

office2013_touchmode_3

office2013_touchmode_4

Touch Mode is a global parameter.  So enabling it within one application such as Word should enable it within other members of the suite such as Excel.

How to use PowerShell to export all Group Policy objects

To export all Group Policy objects with Windows Server 2008 R2, launch a PowerShell session on a domain controller.  Use the following commands:

Import-Module GroupPolicy

Backup-GPO –All –Path C:\folderpath

Exporting information from a Windows 2008 R2 DHCP server

Information such as existing scopes can be exported from a Windows 2008 R2 DHCP server by using the command:

netsh dhcp server export c:\filename.txt all

The data can be imported back in using the netsh dhcp server import command.  The problem with the output of the command above is the information cannot be easily read.  The command below will export the DHCP data in a readable format, but cannot be used to import the information back in.

netsh dhcp server dump all > c:\filename.txt

Sunday, February 3, 2013

Links for several services to check for additional access

Facebook, Twitter, Google, Dropbox, and other web services can be accessed by various applications and other services. Below are some links that can verify what external services have been configured to allow access.

Google –> https://www.google.com/accounts/IssuedAuthSubTokens

Facebook –> http://www.facebook.com/settings/?tab=applications 

Microsoft’s Live –> https://profile.live.com/Services/?view=manage

Dropbox –> https://www.dropbox.com/account#applications

Twitter –> http://twitter.com/settings/connections

The site MyPermissions.org http://mypermissions.org/ contains links for several different services not listed above.

Services for transferring large files

Below are a list of services for transferring large files.

http://www.typhoonupload.com/

http://www.securelysend.com/

http://www.bitzen.net/

https://www.yousendit.com/

https://www.titanfile.com/

http://pando.com/

http://www.sendthisfile.com/

https://www.filestofriends.com/

FreeBookSifter

Freebooksifter is a web site that lists available free book titles from Amazon.

http://www.freebooksifter.com

Topera

Topera is a IPv6 port scanner.  One claim is scans are not detected by Snort.

http://code.google.com/p/topera/

Scheduled scan with Defender within Windows 8

The Security Essentials application that is available for Windows 7 includes an option within the GUI to modify the default scheduled scan.

windows8_defender_1

The Windows Defender that is included within Windows 8 has a similar interface, but the scheduled task option is not present.

windows8_defender_2

The scheduled task entries for the application has moved to the standard Scheduled Tasks interface.

windows8_defender_3

A new scheduled task can be created if needed by using the command line switches that are available.

windows8_defender_4