Showing posts with label Microsoft Security. Show all posts
Showing posts with label Microsoft Security. Show all posts

Monday, 10 September 2018

Security: RBC Royal Bank: Best laid plans of mice and men

We did some banking work with our bank, RBC Canada. In the process they sent us a few "Secure Document Access" requests that the agent provided the password for via a phone conversation.

When the first one came in, it was a bit of a system shock.

image

RBC Royal Bank "Secure Message"

The highlight is ours. Huh?!?

Given the nature of today's phishing attacks a phone call was very quick to happen to our contact after receiving the above to verify its legitimacy.

We received a number of subsequent "secure" e-mails using the same method.

The encryption process we use, and our clients use, on the ExchangeDefender (xD) system is a link to an Internet property owned by xD with the appropriate SSL properties in place to assure the recipient that they are in the right place. That's after we indicate to the recipient in a prior e-mail of the upcoming process to obtain the encrypted content.

The RBC Royal Bank method is close to that but why the .HTM attachment requirement? That's just plain weird. :S

Sure enough, this is what was in an Inbox here this morning:

image

Phishing Message

It's a poorly crafted phish attempt at best.

image

E-mail Header

The trail is pretty clear as far as where it came from and the "how" looks to be fairly clear as well.

All it would have taken was a bit better in the way of timing on the phisher's part and a bit of distraction on our part and BOOM we could have been hooked. :(

RBC Royal Bank Canada needs to change their secure document transmission methodologies please.

And, Microsoft, please give us built-in DKIM abilities for on-premises Exchange instead of keeping that to online properties only. That's not polite in the least.*See Note Below

Outlook Header How-To

Outlook users, here's how to get the header information shown above:

  1. Double click on the e-mail
  2. Click the Message tab
  3. Click the break-out button on the bottom right of the Tags category
    • image
  4. Click anywhere in the small information window
    • image
  5. Keyboard:  CTRL+A then CTRL+C
  6. Click Close and close the e-mail
  7. Paste the content into the destined app (we use Notepad)

After examining a few headers it gets pretty easy to identify the legit and illegitimate messages hitting our Inbox every day. While the process may be a bit time consuming, figuring out whether something is legit or not could be the difference between DELETE and an encryption event or Inbox/Contacts harvesting.

Happy Monday everyone and thanks for reading! :)

2018-09-10 EDIT: Oops, that Microsoft sentence should have been CUT along with the other sentences that were in a previous paragraph. Suffice it to say, we've been working on DMARC/DKIM requests and discovered that Microsoft seems to be holding DKIM off from on-premises Exchange. Thus, we need to go third party to get to use that business critical security feature. :(

Philip Elder
Microsoft High Availability MVP
MPECS Inc.
Co-Author: SBS 2008 Blueprint Book
www.s2d.rocks !
Our Web Site
Our Cloud Service

Monday, 22 September 2014

KB913086: Security Updates Available as ISO Files at Microsoft Download Centre

Microsoft’s security updates can be downloaded in ISO form.

The above site has a list of links to the ISO downloads.

image

We have set up a link on Microsoft’s Download Centre site to sort the ISO files with newest at the top:

image

We suggest bookmarking this link to gain quick access to the newest or latest ISO downloads.

Hat Tip: Thanks to Derek Knight and Russ Stamm (quietman7).

Philip Elder
Microsoft Cluster MVP
MPECS Inc.
Co-Author: SBS 2008 Blueprint Book

Chef de partie in the SMBKitchen ASP Project
Find out more at
Third Tier: Enterprise Solutions for Small Business

Thursday, 30 August 2012

Microsoft/Live ID in Windows 8 Actually Says, "Your password has expired. It's time to choose a new one."

This is a nice change:

image

Instead of this:

image

And a, "There is a problem with your Microsoft account".

Windows Messenger says that there is a problem with the connection.

We have all of our Microsoft/Live ID accounts set to expire their passwords after 72 days. It is an option available when changing the password.

So, at least the Microsoft account integration in Windows 8 _tells_ us what the problem is and how to fix it.

image

Now to figure out _what_ characters are allowed. :S

It's not allowing spaces. Special characters are okay but spaces are not. Oh well.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 3 October 2011

From Microsoft Canada: An IT Pro Message

Microsoft Canada asked if we could post the following to our fellow IT Professionals and we agreed. Many of the links to Microsoft resources are ones that we use on a regular basis.

Note that we edited the original to reduce the amount of marketing fluff. :0)

Our comments are italicized.

NSAT IT Pro Messaging for the Community

1) Help and Support from Microsoft

The following links are a great resource that Microsoft provides to help us find the answers that we need. One of the things that we notice, especially from the MVP perspective, is that if we don’t go and post our issues/problems on forums or phone in to initiate a support incident with PSS that the issue/problem may slip under the radar . . . even if we see it _a lot_ at other forums like Experts-Exchange.

So, when it comes to situations that Microsoft needs to address, they _are_ listening. We need to do our part to follow through.

Help and Resources

Other Resources You May Find Useful

  • Microsoft Virtual Academy - For Free Training To Help Improve Your IT Skill Set.
  • TechNet Evaluation Center - Try some of the latest Microsoft products like Office 365, Windows Intune or System Center Virtual Machine Manager 2012 for free, before you buy.
  • TechNet Newsletter - Sign Up To Receive The Latest IT News and Developments, Product Releases, Expert Insights and Support Services with Microsoft's complimentary biweekly newsletter for industry professionals.

2) Security – How to Help Keep Your PC Protected

Even though we wear many hats, keeping our client’s networks secure is a priority. There are many ways about keeping a network secure, but since our primary foundations are Windows Server and Desktop based we need to be aware of Microsoft’s resources for us in the Security field.

If you feel your system has been compromised or has a computer virus – you can call Microsoft's Security and Virus FREE support line at 1-866-727-2338.

Security Resources

Other Resources You May Find Useful

  • Springboard Series - Your destination for technical resources, free tools and expert guidance to ease the deployment and management of your Windows-based client infrastructure.
  • AlignIT Manager Tech Talk Series - A monthly streamed video series with a range of topics for both infrastructure and development managers. Ask questions and participate real-time or watch the on-demand recording.
  • Microsoft Virtual Academy - For Free Training To Help Improve Your IT Skill Set.
  • TechNet Evaluation Center - Try some of the latest Microsoft products like Office 365, Windows Intune or System Center Virtual Machine Manager 2012 for free, before you buy.

3) Licensing Simplified – at Home and at Work

Licensing. Microsoft Licensing. This is probably one of the biggest areas of struggle for all of us that provide Microsoft based solutions. Just when we think we have what we need in the way of information and direction on how to license a particular solution the SPUR changes or something else changes to throw a monkey wrench in the mix.The links below will help to mitigate those experiences. :)

To add to the links below, the number one licensing site that we visit is the following:

The above linked licensing tool gives us access to all of Microsoft’s licensing programs, the ability to pick and choose which products we are trying to license, and the necessary guidelines for choosing the right program.

FYI: We always license our clients using Open Value Agreement (not subscription) as it provides the best value over the long haul for our clients. Payback is seen in the fourth through six year in SA renewal over OEM.

The link in the paragraph below is to the following blog post:

Speaking of licensing – I often get asked if I can back up our claims at a more cost effective Virtualization solution for your server rooms.  I dug up a great – no nonsense breakdown on recent licensing changes in the industry and how our offering stacks up.

Licensing Resources

Other Resources You May Find Useful

  • TechNet Cloud Hub - Get the latest news and find great resources to help you jump into the Cloud.
  • TechNet Evaluation Center - Try some of the latest Microsoft products like Office 365, Windows Intune or System Center Virtual Machine Manager 2012 for free, before you buy.
  • Microsoft Virtual Academy - For free training to help improve your IT skill set.

4) Free Online Training and Resources from Microsoft

Training. It is the key to our success. We utilize Microsoft’s resources as well as other third party vendor’s training sites on a regular basis.

Knowledge in untrained hands is a dangerous thing. Being trained, evaluated, and certified on the products we work with goes beyond employability. It is a matter of necessity as we are _responsible_ for our client’s IT solutions.

Having a lab capable of running the various IT solutions we implement is also critical to our success. By building out the solutions in a lab setting we can blow them up, attempt to destroy them, pressure test them, and so much more without killing a production environment.

A TechNet subscription whether direct from them or via the Microsoft Action Pack Subscription is an important part of an IT Solution Provider’s in-house licensing and Microsoft products based lab.

Microsoft has a number of great resources to help you in areas of professional development and access to software.  The Microsoft Virtual Academy contains some fantastic FREE online training on hot topics for IT Professionals.  Once you’ve stopped by and tried out a course or two — head on over to the Microsoft Eval Center to download copies of their server products to try out in your lab environment.  And while you’re at it, check out this free Microsoft Office 365 ebook by Katherine Murray, it shows you how you can use cloud computing to help get more done and help improve ease of collaboration.

***

Hopefully there will be some nuggets of information in the above to help!

Thanks for reading. :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 21 July 2011

Microsoft Security Essentials–False Positive on Adware: Win32/Hotbar

A number of our machines have been throwing the following warning from MSE:

image

Adware: Win32/Hotbar

Category: Adware

Description: This program has potentially unwanted behavior.

Recommended action: Review the alert details to see why the software was detected. If you do not like how the software operates or if you do not recognize and trust the publisher, consider blocking or removing the software.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items:

file:C:\Windows\Temp\7E04B5FB-F941-4DE0-ACA3-C0C397211F5F-Sigs\643683E7-6213-45C6-B3D0-151E26E31C81mpasdlta.vdm.new.temp

file:C:\Windows\Temp\7E04B5FB-F941-4DE0-ACA3-C0C397211F5F-Sigs\643683E7-6213-45C6-B3D0-151E26E31C81mpasdlta.vdm.old.temp

We sent out an e-mail to find out what was up.

It turns out that the flag is a false positive on MSE’s own update files with a fix in the works.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Tuesday, 7 June 2011

For A Good Read – Microsoft’s Windows 7 Threats and Countermeasures Guide

Microsoft recently released a complete guide to the security settings in Windows 7 and Windows Server 2008 R2 that provides a full explanation of each setting.

image

The guide is available here:

The document weighs in at 387 pages so it is quite comprehensive in its explanation of the various ways and means of securing and monitoring a Windows network.

On page 47 we find:

Audit object access
This security audit policy setting enables auditing of the event that is generated by a user who accesses an object—for example, a file, folder, registry key, or printer—that has a SACL that specifies a requirement for auditing.

How many of us have had to try and figure out which user or users are “accidentally” deleting data on a client’s network? Auditing object access is the way to find out.

Check out the guide as it is well worth it to read through and also to use as a reference.

Hat Tip: Yuri Diogenes

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 25 April 2011

Microsoft KB: How to send malware to Microsoft for analysis

We run across a lot of different bugs, that is malware or viruses, in our business.

Fortunately we can submit any bugs that we encounter to a number of different vendors.

One is Microsoft:

The above KB describes the many ways that we can submit the bug.

One is the following:

image

Note the How to prepare files for submission section later on in the article states:

How to prepare files for submission
Use care when you handle files that may be classified as malware. Add suspected malware files to a compressed archive file that uses a password. By doing this, you avoid infecting other computers when the files are in transit or when you send the files. To add the files to an archive file that uses a password, follow these steps.
Note If WinZip or a similar compression utility is installed, you can use it to create the archive. However, you must use the same file name and the same password that are included in these steps.
  1. In Windows Explorer, open the folder that contains the suspected malware files.
  2. Right-click a blank area in the window, point to New, and then click Compressed (zipped) Folder.
  3. Type malware.zip to name the new archive file, and then press ENTER.
  4. Drop the suspected malicious software files into the archive file as you would drop them into a typical Windows folder.
  5. Double-click the archive file.
  6. On the File menu, click Add a Password.
  7. In the Password box, type infected.
  8. In the Confirm Password box, retype infected, and then click OK.

If, during our searches we do not turn up any information on a bug that we have encountered we would follow through on submitting it just in case.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 13 April 2009

Microsoft Security Intelligence Report volume 6 (July - December 2008)

Need a really good read over lunch today?

From the above download site:

Overview

Volume 6 of the SIR focuses on the second half of 2008 (from July - December) and builds upon the data published in the previously released volumes of the SIR. Using data derived from hundreds of millions of computers worldwide, and some of the busiest online services on the Internet, this report provides an in-depth perspective on trends in software vulnerability disclosures as well as trends in the malicious and potentially unwanted software landscape, and an update on trends in software vulnerability exploits.

After that good read, check out the Microsoft Security Intelligence Report Web site. It is full of good security information to help us stay abreast of the current threat landscape.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer