This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Wednesday, November 6, 2013

Windows TCP/IP Service Worm and Uninstalling TCP/IP on a Domain Controller

Windows TCP/IP Service Worm and Uninstalling TCP/IP on a Domain Controller

As most of you know, Windows is a hotbed of viruses (not virii), worms, and malware. I’ve had the pleasure of finding a new worm that attacks the TCP/IP service: tcpsrv.exe in the C:\Windows\System32\ folder. This file is needed for Active Directory and the Workstation Driver (ie. Client for Microsoft Networks). With this file removed, you cannot remote into your server, run active directory and as a result Exchange Server. You can, however, serve web pages just fine with IIS.
I have three Antivirus “managers” on my internal and external network. Panda Enterprise, Trend Micro ServerProtect and Avast Antivirus for Server 2003. My favorite is Avast because it is easy to use and “cheap.” The TCP/IP worm was not detected by Panda or Trend Micro. Avast only knew it was malicious and recommended to quarantine or delete it upon restart. If you delete it upon restart or even quarantine, your server will no doubt be crippled. You will not be able to log into your server through RDP (Remote Desktop).
When you try to login through RDP (Remote Desktop) you type your username and password and an error pops up: “Cannot log on. The Workstation driver is not installed.” “Workstation Driver” is the common name for Client for Microsoft Networks found in your network adapter properties. So how do you fix your server if you cannot log into it? Well, it takes some telnet and some creative FTP in the Windows directory, which I will explain in a different post. For now, you’ll need physical access to your server or someone with physical access that can follow instructions.
You can login to your server at the physical workstation no problem because only the RDP login utilizes the TCP/IP Service, unlike the regular workstation login. Because the TCP/IP service is missing or corrupted, the following services (all found in services.msc at the run command) will not work:
  1. Workstation (or client for Microsoft networks)
  2. Server
  3. TCP/IP Service
  4. RPC Locator
  5. Netlogon
The RPC Locator and Net Logon depend on the Workstation service. All of these services should be set to Startup Type: Automatic and should be started on any machine. The Server service is what controls the domain controller or lets your computer know WHAT it is. If you try to access Active Directory an error saying “the domain could not be found” or “the computer is not part of a domain.” This is important for active directory and Exchange Server. Server requires TCP/IP service to run. Steps:
1. Locate a fresh copy of tcpsrv.exe in a backup or i386 folder of the install disc. For Windows 2003 SP2 the latest revision is 2006. Put it into the System32 directory and manually restart all the above services. If this works, fantastic, it was easy contained worm. If not, read on.
2. If the above did not work you’ll need to go into the network adapter properties and delete “Client for Microsoft Networks.” You will need to restart after you have done this. Once restarted, re-install Client for Microsoft Networks. You will need your Windows 2003 CD. Restart again.
3. Verify that the startup type for the RPC Locator service is set to Automatic and start the service. Do the same for the Net Logon service but do not start it yet. Start Registry Editor (Regedt32.exe) and then click the DependOnService value under the key in the registry:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon
4. On the Edit menu, click Multi String, type LanmanServer on a line by itself, and then click OK. In the Services tool, start the Netlogon service. If you cannot start it, continue with the steps below. If it does start, then start the Server service and verify Active Directory Users and Computers opens and you can see the available users/computers.
5. If the above still didn’t work, you may also have a corrupt TCP/IP stack and corrupt Winsock2. You’ll need to restart your computer in “Directory Services Restore Mode” by pressing F8 after the BIOS information has displayed. Once you have logged in, open regedit32.exe and find and delete the following registry keys:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock2
6. Locate the Nettcpip.inf file in your Windows\inf directory and open it in notepad. Find [MS_TCPIP.PrimaryInstall] and edit Characteristics = 0xa0 to 0x80.
7. Go into the properties of your network adapter and click “Install,” select “Protocol,” “Add” and “Have Disk.” In the “Copy Manufacturer’s Files From” box select C:\Windows\inf and click OK. Select “Internet Protocol (TCP/IP)” and click OK.
8. This allows you to remove the TCP/IP service from a domain controller (which was not possible before). Now in the properties box of the network adapter select “Internet Protocol (TCP/IP)” and click Uninstall. Once it has uninstalled. Restart the computer in Directory Services Mode again. Reinstall the Internet Protocol (TCP/IP) by going into the properties of your network adapter and clicking “Install,” select “Protocol,” “Add” and “Have Disk.” In the “Copy Manufacturer’s Files From” box select C:\Windows\inf and click OK. Select “Internet Protocol (TCP/IP)” and click OK.
9. Restart your computer in normal mode. All services should have started. If not, verify the above services are set to automatic and try to start them manually.

Hacking the Trend Micro Security Dashboard for SMB: Reset the Password

Trend Micro’s Client Server Security for SMB is a well designed security solution for small businesses. One of its greatest features is the ability to be deployed, updated, and controlled via the local network. With the push of a button you can scan all networked computers, increase security, send messages or print reports.
I’ve recently taken over the role of administrator for a company and unfortunately the Trend Micro passwords were lost.
Fear not, there is a simple method to resetting the password (too easy?)
  1. Navigate to: \Program Files\Trend Micro\security server(officescan)\private
  2. Open ofcserver.ini in Notepad
  3. Press CTRL-F to search for: master_pwd
  4. Once found, the string should look similar to: master_pwd=!CRYPT!xxxxx
  5. xxxxx is representative of a long string of hex characters making up an encrypted password
  6. In place of !CRYPT!xxxxx put “70″ so it will look like: master_pwd=70
  7. 70 is the hexadecimal value for “1″
  8. Save the file
  9. Press Start -> Run -> Type: services.msc and press enter
  10. Find “Trend Micro Security Server Master Service” and restart the service
  11. Login to the Trend Micro Security Dashboard with the password as “1″ without the quotations
  12. The default URL for the dashboard is: https://IPADDRESS:4343/officescan/default_SMB.htm

Unload/Uninstall Trend Micro Office Scan client 10.5

Wednesday, October 30, 2013

Important Days- Useful for Competitive Exams


JANUARY
January 9 : NRI Day
January 10: World Laughter Day
January 12: National Youth Day
January 15: Army Day
January 26: India's Republic Day, International Customs Day
January 30: Martyrs' Day; World Leprosy Eradication Day

FEBRUARY
2nd Sunday of February: World Marriage Day
February 24: Central Excise Day
February 28: National Science Day
Second Monday March: Commonwealth Day

MARCH
March 8: International Women's Day
March 15: World Disabled Day, World Consumer Rights Day
March 18: Ordnance Factories Day (India)
March 21: World Forestry Day, International Day for the Elimination of Racial Discrimination
March 22: World Day for Water
March 23: World Meteorological Day
March 24: World TB Day

APRIL
April 5: International Day for Mine Awareness, National Maritime Day
April 7: World Health Day
April 17: World Hemophilia Day
April 18: World Heritage Day
April 22: Earth Day
April 23: World Book and Copyright Day

MAY
May 1: Workers' Day (International Labour Day)
May 3: Press Freedom Day; World Asthma Day
May 2nd Sunday: Mother's Day
May 8: World Red Cross Day
May 11: National Technology Day
May 12: World Hypertension Day, International Nurses Day
May 15: International Day of the Family
May 17: World Telecommunication Day
May 24: Commonwealth Day
May 31: Anti-tobacco Day

JUNE
June 5: World Environment Day
June 3rd Sunday: Father's Day
June 14: World Blood Donor Day
June 26: International Day against Drug Abuse and Illicit Trafficking

JULY
July 1: Doctor's Day
July 11: World Population Day

AUGUST
August 3: Internatioal Friendship Day
August 6: Hiroshima Day
August 8: World Senior Citizen's Day
August 9: Quit India Day, Nagasaki Day
August 15: Indian Independence Day
August 19: Photography Day
August 29: National Sports Day

SEPTEMBER
September 2: Coconut Day
September 5: Teachers' Day, Sanskrit Day
September 8: World Literacy Day (UNESCO)
September 15: Engineers' Day
September 16: World Ozone Day
September 21: Alzheimer's Day, Day for Peace (UN)
September 26: Day of the Deaf
September 27: World Tourism Day

OCTOBER
October 1: International Day for the Elderly
October 2: Gandhi Jayanthi, International Day of Non-Violence
October 3: World Habitat Day
October 4: World Animal Welfare Day
October 8: Indian Air Force Day
October 9: World Postal Day
October 10: National Postal Day
October 2nd Thursday: World Sight Day
October 13: UN International Day for Natural Disaster Reduction
October 14: World Standards Day
October 16: World Food Day
October 24: United Nations Day
October 30: World Thrift Day

NOVEMBER
November 9: Legal Services Day
November 14: Children's Day, Diabetes Day
November 17: National Epilepsy Day

DECEMBER
December 1: World AIDS Day
December 3: World Day of the Handicapped
December 4: Indian Navy Day
December 7: Indian Armed Forces Flag Day
December 10: Human Rights Day
December 18: Minorities Rights Day (India)
December 23: Kisan Divas (Farmer's Day) (India)