Re: [NTSysADM] Advice: migrate to new file server

2018-01-29 Thread Klaus Hartnegg
Am 29.01.2018 um 20:27 schrieb Michael Leone: I need to migrate everything (shares and user home folders) to a Win 2012 R2 Storage Server, and then retire the old server. Share definitions can be exported from the registry, and imported into the new server. If you want to minimize

Re: [NTSysADM] Using PS to query date of latest Windows Updates installed

2018-01-17 Thread Klaus Hartnegg
Am 16.01.2018 um 22:46 schrieb Michael Leone: For the purposes of this report, I don't need any more detail than "When were updates last applied?". Please note that a recent applied date does not imply that the machine is fully patched. If the QualityCompat registry key is not there, it will

Re: [NTSysADM] Very painful install of Windows 7

2017-09-26 Thread Klaus Hartnegg
Am 26.09.2017 um 00:57 schrieb Eric Levinson: It took about 16 hours after the initial reinstall to get the system back up to SP1, with all the new hotfixes and IE 11. A new Win7 install can be speeded up from 1 day to 1 hour. After installing Win7 it asks whether it should do auto-updates.

Re: [NTSysADM] Data Recovery Software

2017-07-23 Thread Klaus Hartnegg
if a partition has mistakenly been deleted, restore it with the freeware program testdisk.

Re: [NTSysADM] Enabling DLL Rules In AppLocker - Any Real-World Advice?

2017-07-12 Thread Klaus Hartnegg
Am 10.07.2017 um 22:00 schrieb Aakash Shah: Hello! Has anyone enabled and enforced DLL rules in your environment? I am considering enabling DLL rules for a new round of deployments with the default AppLocker DLL ruleset We enforce DLL rules with Software Restriction Policies, and needed a

Re: [NTSysADM] Re: dell rant- part two

2017-05-04 Thread Klaus Hartnegg
Am 04.05.2017 um 02:34 schrieb Jonathan Link: Crappy consumer warranty... Dell isn't any different here than other vendors in the consumer space. It is strictly "you get what you pay for". Purchase from their business series, pay on-site service, and they send someone next day at 8am who

Re: [NTSysADM] Sophos disables UAC

2017-04-23 Thread Klaus Hartnegg
Am 13.03.2017 um 20:39 schrieb Klaus Hartnegg <hartn...@uni-freiburg.de>: > Several more affected PCs found, but also two counter examples: same Windows, > same Sophos, but UAC is on. Strange. False alarm. Seems that the installer of Sophos is not the cause, but the trigger. So

Re: [NTSysADM] Reset permissions on hard disk - Windows 10 Enterprise

2017-04-19 Thread Klaus Hartnegg
icacls d:\ /setowner %username% /t icacls d:\ /grant:r %username%:(oi)(ci)m /t the /t is only necessary if inheritance is disabled somewhere. to re-enable inheritance: icacls d:\ /reset /t the :r tells to replace all old permissions instead of adding the new ones. use f instead of m for full

Re: [NTSysADM] Sohpos disables UAC

2017-03-13 Thread Klaus Hartnegg
Am 13.03.2017 um 20:50 schrieb Kennedy, Jim: When you follow through on that article I linked to...to the Sophos KB on this. It appears to only happen when a scan finds something, like malware. Then it performs the cleanup function that resets this. It does not reset it, it disables it. And

Re: [NTSysADM] Sohpos disables UAC

2017-03-13 Thread Klaus Hartnegg
Am 10.03.2017 um 17:24 schrieb Klaus Hartnegg: Many computers here suddenly have UAC off, and my research points to Sophos installer/updater as culprit: UAC stays on when rebooting normally, but reproducably switches to off after a reboot that followed an install, uninstall, or larger update

Re: [NTSysADM] Change(s) in Windows 10 after Cumulative Update 1607 (KB3213986)

2017-03-13 Thread Klaus Hartnegg
Am 11.03.2017 um 03:21 schrieb Micheal Espinola Jr: search typing also didnt work properly during that period (e.g. "cmd" wouldnt find cmd.exe, etc). Windows 10 shows the desktop before all functions are available, including search. On the first logon after an upgrade if can take minutes

[NTSysADM] Sohpos disables UAC ?

2017-03-10 Thread Klaus Hartnegg
Has anybody recently seen Sophos Antivirus ("Endpoint Security") disabling User Account control in Windows 7? Many computers here suddenly have UAC off, and my research points to Sophos installer/updater as culprit: UAC stays on when rebooting normally, but reproducably switches to off after

Re: [NTSysADM] Managed Anti-Malware for Servers

2016-11-09 Thread Klaus Hartnegg
Am 09.11.2016 um 07:29 schrieb Kish N Kepi: I’m looking for recommendations for Anti-Malware software to install specifically on Windows Servers (2008R2, 2012R2, 2016) NONE. On a normal workstation with dumb users one may hope that the pros outweight the cons, but how should they manage to

[NTSysADM] Howto upgrade Win10 to 1511?

2016-09-19 Thread Klaus Hartnegg
Hi, I want to upgrade Win10 RTM (10240) to 1511 (not yet 1607). Does this upgrade have a KB number? MS only points to the Media Creation Tool, but that does not ask which version it should create. Wasn't there a way to upgrade via WSUS, and should that not also be available in the Update

Re: [NTSysADM] HP EliteDesk 800 G1 Dual monitors

2016-09-18 Thread Klaus Hartnegg
Am 17.09.2016 um 19:05 schrieb David McSpadden: Can not get second monitor to actually extend. All I get is a cloned monitor. Can be a hardware problem. Yes, really. Recently had same problem with a high end graphics card. Tried all available drivers, nothing helped. Finally swapped the

Re: [NTSysADM] Force sleep downside

2016-08-08 Thread Klaus Hartnegg
Am 07.08.2016 um 17:38 schrieb J- P: Why is that every time I lookup "windows 7 sleep gpo" or any variation of that, all the hits explain how to DISABLE sleep or hibernate, is there a downside to forcing sleep or hibernation? Oh yes. When I upgraded one group to Windows 10, the #1 complaint

Re: [NTSysADM] User State Migration Tool: copy all

2016-07-27 Thread Klaus Hartnegg
On 25.07.2016 at 19:09 Michael B. Smith wrote: If you allow your users to put data "just anywhere" then the fact that the toolkit will trim that data is YOUR FAULT - not the fault of the toolkit. Good luck with removing users write permission to their own profile directory. That was my

Re: [NTSysADM] User State Migration Tool: copy all

2016-07-25 Thread Klaus Hartnegg
Effectively you also say that using this tool usually means losing data. What would be the disadvantage of rewriting the XML files such that it copies ALL of appdata\roaming? Could this cause any problems? Maybe not the directories which were created by Windows, i.e. Microsoft, Adobe, Media

[NTSysADM] User State Migration Tool unusable?

2016-07-22 Thread Klaus Hartnegg
Microsoft offers USMT (User State Migration Tool) to transfer settings from one Windows version to another, or from one PC to another. But while the older program "Easy Transfer" could (in Win7) be told to copy the whole directories appdata\roaming and documents, USMT copies only the files

Re: [NTSysADM] Adobe cease & desist letter FOLLOWUP

2016-07-18 Thread Klaus Hartnegg
The standard Cease and Desist letter from Adobe says that the web page https://get.adobe.com/reader/ is the one and only place, where people are allowed to link to, for offering Adobe Reader. No local copies allowed (this I understand because copyright), no pointing to anywhere else, not even

Re: [NTSysADM] Adobe cease & desist letter ?!?

2016-07-17 Thread Klaus Hartnegg
inking to > Adobe. > > -- > Espi > > >> On Sun, Jul 17, 2016 at 3:01 PM, Klaus Hartnegg <hartn...@uni-freiburg.de> >> wrote: >>> On 17.07.2016 at 14:18 Alexander Eckelberry wrote: >>> What is the website? >> >> They cite as example this

Re: [NTSysADM] Adobe cease & desist letter ?!?

2016-07-17 Thread Klaus Hartnegg
On 17.07.2016 at 14:18 Alexander Eckelberry wrote: What is the website? They cite as example this one: http://www.klaus-hartnegg.de/gpo/msi_acroread.html I now removed all download links, which makes the web page a lot less useful. Previously you could just click the links in the summary box

[NTSysADM] Re: MDT: howto upgrade to Win10 with captured wim?

2016-07-16 Thread Klaus Hartnegg
On 13.07.2016 at 21:54 Klaus Hartnegg wrote: Is it possible to create a custom Win10 DVD, based on a WIM-file captured with dism, that can *upgrade* Win7 to 10? Found the answer myself after days of searching, reading, and testing. The answer is: * NO * Source: "the upgrade process

Re: [NTSysADM] Adobe cease & desist letter ?!?

2016-07-14 Thread Klaus Hartnegg
On 14.07.2016 at 14:11 Jeff Frantz wrote: Remove the link from your web site but leave the text so the user can copy and paste into their browser. Then, you can legitimately tell Adobe you removed the link to their FTP site. I could write "go to http://www.adobe.com/devnet-docs/acrobatetk/

Re: [NTSysADM] Adobe cease & desist letter ?!?

2016-07-14 Thread Klaus Hartnegg
On 14.07.2016 at 13:32 James Rankin wrote: Put up a Web page advising users that adobe are asshats and give them comprehensive instructions on using an alternative. This is what another person with the same letter has already done:

[NTSysADM] Adobe cease & desist letter ?!?

2016-07-14 Thread Klaus Hartnegg
I just received a letter from Adobe demanding that I stop "encouraging users to illegally use, copy, and/or distribute Adobe’s Reader Software". My crime is that I have a web page with some useful tipps for admins how to deploy Adobe Reader and Acrobat via windows group policy. My page points

Re: [NTSysADM] RE: Owned by Crypz

2016-06-15 Thread Klaus Hartnegg
On 15.06.2016 at 17:27 Jonathan Link wrote: No, you don't need Enterprise for SRP. I've used it as a poor mans whitelisting app and basically blocked out everything in the User profile folder except for the Desktop folder. Why exclude the Desktop folder? Shortcuts not working? I removed the

Re: [NTSysADM] RE: Owned by Crypz

2016-06-15 Thread Klaus Hartnegg
Am 15.06.2016 um 16:21 schrieb Kennedy, Jim: The ransomeware's don't need admin rights to ruin your day. If software whitelisting is active, then admin rights help to circumvent whitelisting. Often admin is excluded from the restrictions.

[NTSysADM] Enterprise backupi client only via ftp? unencrypted!

2016-06-09 Thread Klaus Hartnegg
Hi, Many large enterprises do their backup with TSM alias Tivoli from IBM. This week I noticed that the client for this system appears to be available only via ftp. But ftp is neither encrypted nor signed. Shouldn't all downloads go through https for various security reasons? Ever heared

Re: [NTSysADM] Pitfalls in setting up domain trust

2015-03-16 Thread Klaus Hartnegg
if you follow the Microsoft instructions even I could do them correctly. Using instructions from a third party site like Wikipedia is very questionable Some people here are jumping to conclusions without really reading my emails, and nobody answers my question. Yes, I followed the

Re: [NTSysADM] Pitfalls in setting up domain trust

2015-03-15 Thread Klaus Hartnegg
Thanks for all replies. The pointers have helped extend my knowledge about FSMOs. It appears that I can ignore FSMOs if both forests have only one domain, and all domain controllers are also master catalog servers. However my larger fear was that there might be more surprises in other areas

Re: [NTSysADM] Pitfalls in setting up domain trust

2015-03-14 Thread Klaus Hartnegg
Am 14.03.2015 um 13:57 schrieb Klaus Hartnegg: Source: last sentence before section 'References' on https://en.wikipedia.org/wiki/Flexible_single_master_operation I just rearranged the sentences in that part of the Wikipedia article, to move together what belongs together, and made the FSMO

[NTSysADM] Pitfalls in setting up domain trust

2015-03-14 Thread Klaus Hartnegg
Hi, We need bidirectional trust between two AD domains. I had already tested everything in virtual machines, and set up conditional forwarding to the other domains DNS servers. But then I stumbled over a note that trust requires manual changes to the allocation of the 5 FSMO roles to the

Re: [NTSysADM] Pitfalls in setting up domain trust

2015-03-14 Thread Klaus Hartnegg
Am 14.03.2015 um 16:11 schrieb Micheal Espinola Jr: Did you happen to follow the citation link (#6) back to the Microsoft KB Of course I did, and it appears to confirm it. article that was written in 2007? So what? Windows allows to configure trust without telling about such unexpected

Re: [NTSysADM] Software Restriction Policy in Win7-64 broken?

2015-03-11 Thread Klaus Hartnegg
Am 04.03.2015 um 17:31 schrieb Klaus Hartnegg: Software Restriction Policy (SRP) in Win7-64 behaves different than in Win7-32 or WinXP-32 (I'm using SRP in whitelisting mode, default level is restricted). SRP allows to choose whether it should affect everybody, or everybody except admins

Re: [NTSysADM] SSD scrub/sanitize/wipe

2015-01-29 Thread Klaus Hartnegg
Am 29.01.2015 um 14:54 schrieb Richard Stovall: Another thread mentioned the difficulty of guaranteeing the secure erasure of data from SSDs. I recently had to return a personal laptop for replacement and could not find a method for securely erasing its SSD. Googling around for answers, I

Re: [NTSysADM] Freeware in a corporate setting

2015-01-29 Thread Klaus Hartnegg
Am 29.01.2015 um 04:35 schrieb Jon Harris: Does the bank understand that software wiping is not considered safe for release of sensitive information? Admittedly I doubt the company receiving the old machines would want to pay the price to recover the wiped data but I am sure it could be done.

Re: [NTSysADM] EXE to MSI-help

2015-01-03 Thread Klaus Hartnegg
Some installers don't work when started from an UNC path, they need a drive letter. Mount the drive with /persistent:no and after the install unmount it with 'net use t: /delete'. Then it will both be gone, and not re-appear.

Re: [NTSysADM] EXE to MSI

2015-01-03 Thread Klaus Hartnegg
Am 01.01.2015 17:48, schrieb J- P: I vaguely recall having an application that converted EXE to MSI, but cant remember it for the life of me. You have basicly three options: One method is that such tools run the installer and try to watch what it does. I found this to be unreliable. They

Re: [NTSysADM] Re: Something to share with your users, so they can see how passwords matter

2014-08-09 Thread Klaus Hartnegg
Am 09.08.2014 um 05:23 schrieb Michael B. Smith mich...@smithcons.com: you should spend some time learning how Rainbow Tables operate. Rainbow tables don't work at all if the password has sufficient length. They are magic for 8 characters, but impractical for 10 or more.

Re: [NTSysADM] As data loss disasters go...

2014-06-19 Thread Klaus Hartnegg
Am 19.06.2014 14:18, schrieb Adm: Do you have an alternate link? Pastebin.com is blocked here http://www.codespaces.com/

Re: [NTSysADM] Out of Band for IE, and they are going to provide a XP patch

2014-05-04 Thread Klaus Hartnegg
On 04.05.2014 22:59, C.E. Gene Connor wrote: Among those still using Windows XP are the Defense Department, the IRS, and bank ATMs ATMs should use XP-embedded, which is supported until January 2016. But as long as banks do not ensure physical safety of their devices (machines and cards), the

Re: [NTSysADM] OT: Corporate Support of Open-Source projects

2014-04-21 Thread Klaus Hartnegg
On 21.04.2014 03:17, Andrew S. Baker wrote: Companies are not *built* or incentivized for good will. They are only incentivized for profit and the mythical shareholder value. What is the ROI for being listed here http://www.linuxfoundation.org/about/members Maybe they should create an

Re: [NTSysADM] Panic time for some folks...

2014-04-08 Thread Klaus Hartnegg
scanning one port of all ip-v4 takes approx 2 hours. anybody who wants to find affected servers. already has a list, and is now trying to receive the keys. -- sent from my iPod - please excuse the brevity

Re: [NTSysADM] Rejoin Computer to Domain Without Removing

2014-03-17 Thread Klaus Hartnegg
On 17.03.2014 21:44, Charles Sullivan wrote: Is there a way I can rejoin a computer to the domain without first removing it? If you have a client that thinks that it is connected to a windows domain, but that does not work any more, try this: on the client go to where you would normally go

Re: [NTSysADM] What files are present on a 32bit system for Adobe Flash Player

2014-01-24 Thread Klaus Hartnegg
On 24.01.2014 15:26, Ziots, Edward wrote: VA scanner is complaining that one of my system has an outdated version of Adobe Flash Player but I am searching and not seeing it in Add remove programs and there is no C:\program files\Adobe folder either. Flash is in

Re: [NTSysADM] RE: encrypting Server 2008 R2 virtual disk

2014-01-17 Thread Klaus Hartnegg
Hi, If you make just an encrypted partition (or image file), then Windows will leak unencrypted data to temp files and swap space. If you encrypt the whole system, then somebody must enter the password on each boot. Fine if it's sitting on my desk, but bad if it's in a rack somewhere else,

Re: [NTSysADM] Replica - Monitoring Large System activity

2014-01-16 Thread Klaus Hartnegg
On 16.01.2014 19:21, Sam Cayze wrote: But once in a while, when the server is idle, boom, 600MB needs to be replicated. Looking for some tools that will help pinpoint what this changes might be. Where is the disk activity, what process is associated it with it, which might help me to eliminate