# Wednesday, October 31, 2007
here is a page with all the command line options that you can run with outlook.exe I found some handy commands. Like all the clean commands.
posted on Wednesday, October 31, 2007 9:36:48 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Wednesday, October 24, 2007

I ran across a fun post for a way to disable the reply to all, and forward ability with emails. How many times have you forward out something like “server will be down” and you get 3 reply all’s “looks like kelly is actually working today”, “haha yea kelly must have called the nerd herd”

use VBA to disable the reply to all and forward

Prevent Reply to all and forward with custom form

here is a copy of scotts post (just as a local copy)

 

posted on Wednesday, October 24, 2007 11:03:20 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Tuesday, October 23, 2007
the following video games I'm excited for, you see all the nerds waiting for Halo3? well that game is nothing as to the hours of play time that I will get from the following, sorry katie.

Burnout Paradise this with my next entry is why I purchased a xbox back in the day, also one of a few games I have every played to the end. Replay value is 5 star. I CANT WAIT

Tom Clancy's Splinter Cell: Conviction also the only game titles I stick around to play to the end, I love this series more then candy (well no not really) I CANT WAIT

Grand Theft Auto IV possibly the best game series I have ever laid eyes on, Im old enough to tell right from wrong, but this game is so real that I can choose wrong. Take that you lady of the street 'gimmie back my cash' sweeeet america I CANT WAIT

The Simpsons Game I really liked the GTA rip off of the Hit & Run game this game looks possibly the best thing ever, I am torn if the Wii will have anything cool (I doubt it) but the Wii has a list of cool games on its own. just watching all the commercials makes me want want want I CANT WAIT

thats $200 of video games in the next 6 months. bastards, time to break open the piggy.

posted on Tuesday, October 23, 2007 11:21:43 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Saturday, October 20, 2007

seems like the media loves me, my prior stunt of asking my dear Katie to marry me got me into the seattle times, and no all the facts arnt correct before you all comment back. – story as follows.

Rolling party – Seattle Times 10–20–2007

Katie Uhlenkott thought she was the party planner. Her boyfriend, Kelly Keeton, of Kirkland, had casually suggested they go roller skating soon. Wouldn't it be fun, he said, to invite friends and make it a party.

Uhlenkott, of Kent, decided to turn it into a surprise 26th birthday party for Keeton at Skate King in Bellevue.

When Kelly's mother got the call, she played along.

"Kelly invited us a couple of weeks before Katie even planned her surprise party," said Betty Keeton of Snoqualmie. "He planted the idea and let her think she was organizing the party."

When the couple arrived at Skate King, the emcee invited them to the center of the rink. There, in front of about 30 friends and relatives, Uhlenkott realized she'd been set up. That's when Keeton proposed.

The couple plan to marry next year.

posted on Saturday, October 20, 2007 4:53:05 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [1] Trackback

The new version of ubuntu is out and as long as your not on comcast (assholes) I recommend the ubuntu torrent server, I got the iso in 30 mins. I also booted up package manager and noticed that it would take care of all the work for me.  Lets just say that there is a reason that linux is not on the home desktop yet, granted windows couldn't do any better. They just have a few more years under the belt as of now. So I clicked update, well since my home directory was encrypted. That trashed a lot of stuff. The ‘Coup de gras’ however came when it tried to update the package-manager and update service, no idea what happened but lets just say I lost everything and spent today at the office rebuilding my laptop. I did however, put office 2007 on for the first time. I really love outlook 07. So what did I learn from all this? backup your work and when all fails, you will find out that Microsoft makes a good email program.

posted on Saturday, October 20, 2007 4:48:00 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback

Nowindowsupdate 

This is an amusing error coming from the windows update page when I loaded up windows for workgroups 3.11. It thinks I’m a mac.

posted on Saturday, October 20, 2007 4:39:39 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Wednesday, October 17, 2007

So I have a wamu credit card, I have nothing good to say about wamu when I activated the card, I actually yelled at them that I didnt want to buy any insurance or fraud detection service. It was worse then a girl scout that needs to make a quota. So then I went to close out the card (I used it for a 0% loan) I didnt want to call, so I set up an account online. I had to make my password. But check out the HORRIBLE password requirements. Not only do they limit to alpha 8 character, but they also give you example passwords! haha

Wamu1

Wamu2

posted on Wednesday, October 17, 2007 10:07:07 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [1] Trackback
# Thursday, October 11, 2007

So this topic of virtual servers is starting to catch on a bit more, I still think it will go the wayside of bluetooth and only people that drink the Intel kool-aid will adopt it, but thats just me, dont get me wrong I feel there is a place for virtual machines in the data center, the technology and use just isn't impressing me today. The real point of this post is to bring together some of the tips about virtual server security, I say virtual server and not vmware because they arnt the only players in the market, example is Virtuozzo who I was just talking with a friend about. I was listening to a pauldotcom podcast the other day (which if your interested you need to go listen to)

Anywhoo I have compiled a list of some of the top things to disable or change to harden your virtual environment. The following documents go into further detail but I wanted to explain out a few ideas. The first is disabling unused hardware, examples are FDD, CDROM, USB, and most important the NIC. Obviously you can understand the media not only will it free up resources (other tips are shut down screensavers and the K-Desktop) but they just arnt needed typically in a virtual environment. The NIC is one that most people overlook (depending on setup and how you have things configured this can be incorrect tip), they will have a virtual host with the ability to link to your LAN. now this is particularly and issue if the threat of jumping out of a virtual ever comes to light as a virus. If you have a host on a protected network and your vm’s are on a DMZ for example, then once the virtual is hacked your protected network is at risk, the amount of times that you should have to touch the host is minimal so keep the KVM attached and disable the protocalls and ip address on the host.

Next topic that ties in with the first is to keep similar security devices on the same host, and put that host in the proper subnet for the security of the virtuals. Meaning, dont put your web server on the same host as your financial server, and dont put your web server on the same as a tool server that is located in your ring 0/1 LAN. If its a DMZ server and you would have put it there physically, then put it there phys-virtually (thats physically and virtually in one word) so say this with me once again, put like security servers in the proper realm with the proper vrituals sharing a host.

Now to get a little specific to vendors, example is VMware. With VMware you have cool things like drag-and-drop file copy, cut and paste etc. In a server virtual machine you want to shut these enhancements off.

Patch! VMware, Microsoft each have patches for the softwares they produce, update and patch your software. vmware has no nice patch management notification like MicorosoftUpdate so Patch your softwares, also patch your hosts and virtuals for OS and APP patches.

VMWare has actually published a paper for security with the ESX Server, this has important tips for logs, users, and resource provisioning to prevent denial of service issues.

Also CI Security is supposed to release hardening guides, however they also publish good standards for the OS in the virtual so check them out, along with that is the Microsoft published 2000 hardening and 2003 hardening guides.

Another interesting summary from guys at Petri, specifically because they have screenshots

posted on Thursday, October 11, 2007 2:19:23 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback

A “new” security threat that I thought was rather interesting. using cross site forgery, the idea is that if you have two browsers open, one is your bank the other is a hack-site. The hack site can use this idea to piggy back on your cookie and session to do things with your bank with out you knowing, How? well it would just send http post data (or get) in the back end of the browser. So whats this mean why do you care? If this takes off its nasty till’ people fix the sites you use. To not fall victim to this just dent flip browsers while your browsing, if you are on a site that you feel needs to be secure close out myspace.

Also the tool that I use for google hacking pay-sites, is the mozilla RefControl, which is the underlying idea with this hack

posted on Thursday, October 11, 2007 3:35:09 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Tuesday, October 09, 2007
I havent had time to post up about this, but there is a new version of fgdump, this will dump the protected storage if possible, local LM table and cachedump of any system you have admin rights to. This tool is the ifto-facto tool for collecting data for pen-test stuff. The special thing about this tool is that it will sneek past most AV tools so you dont need to kill them to audit. I also recommend downloading the source and compile on your own to even further protect against AV messing this up.

posted on Tuesday, October 09, 2007 5:26:53 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
So I was working on a script to spam a fellow classmate in a recent email proxy class I was attending,  did some searching for a Email Load Tester and found this guys script which uses netcat to pass values onto port 25 with javascript. However for the class I needed more spam like activity, so I added random characters to the subject and body. I also wanted to test out on servers that need auth, so I added a base64 encoder. The script is as user friendly as I could make it, commented here and there.


you can save this script down as a email.js and run with cscript aka 'cscript email.js' from command line.

Usual terms apply, this isn't for illegal activity, anything you damage or break is your own fault and not the publisher of the code. Use at your own risk, blog owner assumes no responsibility for your doings. May cause vomiting or bowl discomfort. If so then stop using code immediately and find a potty.

If you want multi threaded emails run more then one copy at once, I haven't had the time or care to multi thread the script.
posted on Tuesday, October 09, 2007 5:03:14 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Monday, October 08, 2007
New news, I’m now engaged to Katie Uhlenkott. Pulled it off at skate king in Bellevue, I planned for her to throw me a surprise birthday party. At this party I actually invited a lot of people. I then asked her in the middle of the ring. She has no idea and was SUPER surprised. A wedding date is possible in June of 08
posted on Monday, October 08, 2007 9:59:51 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [1] Trackback