<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>www.dambeck.ch &#187; Uncategorized</title>
	<atom:link href="http://www.dambeck.ch/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dambeck.ch</link>
	<description>Die andere Seite des Internets</description>
	<lastBuildDate>Fri, 14 Jan 2011 12:41:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>BlueJ a simple Java IDE</title>
		<link>http://www.dambeck.ch/2011/01/14/bluej-a-simple-java-die/</link>
		<comments>http://www.dambeck.ch/2011/01/14/bluej-a-simple-java-die/#comments</comments>
		<pubDate>Fri, 14 Jan 2011 12:39:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[blueJ]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[JDK]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/2011/01/14/bluej-a-simple-java-die/</guid>
		<description><![CDATA[Did you ever consider learning OOP (Object-oriented programming)? Or maybe you want just writte a little code in Java? But you don’t want build an Enterprise level Project or study 1 Day’s, how to start with a “hello world” Project? If you consider one or more questions with yes, BlueJ may be the solution to [...]]]></description>
			<content:encoded><![CDATA[<p>Did you ever consider learning OOP (Object-oriented programming)? Or maybe you want just writte a little code in Java? But you don’t want build an Enterprise level Project or study 1 Day’s, how to start with a “hello world” Project? If you consider one or more questions with yes, BlueJ may be the solution to you.</p>
<p>  <span id="more-414"></span> BlueJ is an very simple to use Java IDE (integrated development environment). One of the mayor feature is you can crate an Object with few clicks. Also interacting with Object as example call a method can be done with a few kicks. The <a href="http://www.dambeck.ch/wp-content/uploads/2011/01/image.png" class="thickbox"><img style="background-image: none; border-right-width: 0px; margin: 10px 10px 10px 0px; padding-left: 0px; padding-right: 0px; display: inline; float: left; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" align="left" src="http://www.dambeck.ch/wp-content/uploads/2011/01/image_thumb.png" width="244" height="179" /></a>second side of the coin is BlueJ has no IntelliSense, which can you drive crazy, but its god to learn code sintax for a examination.
<p>I guess the best way to start is tray out. Install the <a href="http://www.oracle.com/technetwork/java/javase/downloads/index.html" target="_blank">JDK (Java Development Kit)</a> from Oracle (SUN) and <a href="http://www.bluej.org/download/download.html" target="_blank">install BlueJ</a>. It runs under Windows, linux and the famous MAC OS X. If you look for a good book I would recommend Objects First with Java, A Practical Introduction using BlueJ (ISBN-10 0-13-606086-2). As a little kick-starter you can download one of <a href="www.dambeck.ch/downloads/bluejprojekt.zip" target="_blank">my BlueJ Projects</a> . In the Project you find an example of: Casting, for / do / while Loop, use of operators, if / if-else / switch case selection, J unit Test, Java Doc, inheritance, bubble / insertion / selection sort algorithms and many more.</p>
<p>PS: Always Remember: Chuck Norris dont need to catch an Excep­tion because Java is afraid of the “fly­ing tor­nado kick” at the moment it throws <img src='http://www.dambeck.ch/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2011/01/14/bluej-a-simple-java-die/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Expose for Windows</title>
		<link>http://www.dambeck.ch/2010/12/23/expose-for-windows/</link>
		<comments>http://www.dambeck.ch/2010/12/23/expose-for-windows/#comments</comments>
		<pubDate>Thu, 23 Dec 2010 17:10:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[expose]]></category>
		<category><![CDATA[switcher]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/2010/12/23/expose-for-windows/</guid>
		<description><![CDATA[In this article i will show you a small tool named “switcher”. Maybe you know the feature expose on mac OS S, Switcher enables this on Windows Vista and Windows 7 Clients. I guess if you install Switcher you never use “alt” &#38; “tab” and “win” &#38; “tab” again. &#160; I use the following settings: [...]]]></description>
			<content:encoded><![CDATA[<p>In this article i will show you a small tool named “switcher”. Maybe you know the feature expose on mac OS S, Switcher enables this on Windows Vista and Windows 7 Clients. I guess if you install Switcher you never use “alt” &amp; “tab” and “win” &amp; “tab” again.</p>
<p>&#160;</p>
<p><a href="http://www.dambeck.ch/wp-content/uploads/2010/12/image.png" class="thickbox"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.dambeck.ch/wp-content/uploads/2010/12/image_thumb.png" width="420" height="264" /></a></p>
<p>I use the following settings: </p>
<p>General = Default    <br />Appearance = Default     <br />Windows Style = Default     <br />Filters = Default     <br />Advanced = Default     <br />Shortcuts Keyboard “alt” &amp; “tab” and Shortcuts mouse “mose move at top-left of Monitor 1.</p>
<p>You can download Switcher for free at http://insentient.net/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2010/12/23/expose-for-windows/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Kick the crashed AD controller out</title>
		<link>http://www.dambeck.ch/2009/05/24/kick-the-crashed-ad-controller-out/</link>
		<comments>http://www.dambeck.ch/2009/05/24/kick-the-crashed-ad-controller-out/#comments</comments>
		<pubDate>Sun, 24 May 2009 15:15:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD]]></category>
		<category><![CDATA[Controller]]></category>
		<category><![CDATA[Domain]]></category>
		<category><![CDATA[FSMO]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/2009/05/24/kick-the-crashed-ad-controller-out/</guid>
		<description><![CDATA[Sometimes bad things happen, sometimes ugly things happen. One of the very bad things that can happen is when&#160; an active domain controller crashes and there is no backup available. The case becomes really ugly if nobody cares about the crashed controller for about 60 days (forest that was created on a domain controller running [...]]]></description>
			<content:encoded><![CDATA[<p>Sometimes bad things happen, sometimes ugly things happen. One of the very bad things that can happen is when&#160; an active domain controller crashes and there is no backup available. The case becomes really ugly if nobody cares about the crashed controller for about 60 days (forest that was created on a domain controller running Windows Server 2003 and earlier) or 180 days (forest that was created on a domain controller running Windows Server 2003 sp1 and later). On this depends the default tombstone lifetime of directory objects. Later we will investigate on the tombstone. </p>
<p>A good place to fix this whole bunch of problems is by verifying the backup strategy and ensuring that all system-states are saved on all domain controllers. The second step is verifying that DNS are fine and syncing the proper way. Now we are ready to move the FSMO roles. For everyone that is not familiar with the five FSMO Friends, here is a small overview from Wikipedia </p>
<p>Flexible Single Master of Operation (FSMO, F is sometimes floating ; pronounced Fiz-mo), or just single master operation or operations master, is a feature of Microsoft&#8217;s Active Directory (AD). As of 2005, the term FSMO has been deprecated in favor of operations masters. </p>
<p>FSMOs are specialized domain controller (DC) tasks, used where standard data transfer and update methods are inadequate. AD normally relies on multiple peer DCs, each with a copy of the AD database, being synchronized by multi-master replication. The tasks which are not suited to multi-master replication, and are viable only with a single-master database, are the FSMOs. </p>
<p>Domain-wide FSMO Roles: </p>
<p>Every domain in an Active Directory forest must contain one of each of the following FSMO roles:    <br />The Relative ID Master allocates security RIDs to DCs to assign to new AD security principals (users, groups or computer objects). It also manages objects moving between domains.     <br />The Infrastructure Master maintains security identifiers, GUIDs, and DNS for objects referenced across domains. Most commonly it updates user and group links. This is another domain-specific role and its purpose is to ensure that cross-domain object references are correctly handled. For example, if you add a user from one domain to a security group from a different domain, the Infrastructure Master makes sure this is done properly. As you can guess however, if your Active Directory deployment has only a single domain, then the Infrastructure Master role does no work at all, and even in a multi-domain environment it is rarely used except when complex user administration tasks are performed, so the machine holding this role doesn&#8217;t need to have much horsepower at all.     <br />The PDC Emulator operations master role processes all password changes in the domain. Failed authentication attempts due to a bad password at other domain controllers are forwarded to the PDC Emulator before rejection. This ensures that a user can immediately login following a password change from any domain controller, without having to wait several minutes for the change to be replicated. The PDC Emulator Operations Master role must be carefully sited in a location to best handle all password reset and failed-authentication forwarding traffic for the domain. </p>
<p>Forest-wide FSMO Roles: </p>
<p>Regardless of the number of domains in an Active Directory forest, the following FSMO roles exist only once:    <br />The Schema Master maintains all modifications to the schema of the forest. The schema determines the types of objects permitted in the forest and the attributes of those objects.     <br />The Domain Naming Master tracks the names of all domains in the forest and is required to add new domains to the forest or delete existing domains from the forest. It is also responsible for group membership. </p>
<p>Normally it&#8217;s very easy to move these roles by right clicking the forest level and choose Move &#8230;&#160; in the Active Directory Schema snap-in, Active Directory Domains and Trusts snap-in and Active Directory Users and Computers snap-in. But it will fail to 99% with an obscure error. The reason for the error is one domain controller in the replica ring is missing and marked as Tombstone. Let&#8217;s get to the bigger guns and start &#8220;ntdsutil.exe&#8221;, open a command prompt and enter &#8220;ntdsutil.exe&#8221;. If the shell is bugging you that the exe is missing, you need to install the server support tools. They are located on the Windows CD in the support folder. Other ways you can download it from Microsoft using Google ☺. </p>
<p>!! Remember at this point you can do very large harm to the directory so please be sure that you have properly working backups!! </p>
<p>After &#8220;ntdsutil.exe&#8221; has successful started, type &#8220;roles&#8221; and press enter. Type &#8220;connections&#8221; and press enter. Now Type &#8220;connect to server xyz.planetgeek.ch&#8221;, where xyz.planetgeek.ch is the name of the server where you want to transfer the roles to. A message will appear: </p>
<p>&#8220;Binding to xyz.planetgeek.ch &#8230;    <br />Connected to servername using credentials of locally logged on user.&#8221; </p>
<p>Tipe &#8220;quit&#8221; to leave the selection menu. Now appears: &#8220;fsmo maintenance:&#8221; now enter: </p>
<p>&#8220;Seize schema master&#8221; if you want move the schema master.    <br />&#8220;Seize domain naming master&#8221; if you want move the naming master.     <br />&#8220;Seize PDC&#8221; if you want move the PDC.     <br />&#8220;Seize RID master&#8221; if you want move the Relative ID master.     <br />&#8220;Seize infrastructure master&#8221; if you want move the infrastructure master. </p>
<p>Next thing to do is kicking the metadata out of the directory. To do this I know two possible ways. The first is use a VB script written by Clay Perrine from Microsoft. The second way is to use ntdsutil.exe. I prefer the VB script. It works on the most common Windows Operating systems (2k, XP, 03, Vista and 08). The script is below ore you can obtain it directly from Microsoft (<a href="http://go.microsoft.com/fwlink/?LinkID=123599)">http://go.microsoft.com/fwlink/?LinkID=123599)</a>. </p>
<p><em>REM&#160;&#160;&#160; ==========================================================      <br />REM&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; GUI Metadata Cleanup Utility       <br />REM&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Written By Clay Perrine       <br />REM&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Version 2.5       <br />REM&#160;&#160;&#160; ==========================================================       <br />REM&#160;&#160;&#160;&#160; This tool is furnished &quot;AS IS&quot;. NO warranty is expressed or Implied. </em></p>
<p><em>on error resume next      <br />dim objRoot,oDC,sPath,outval,oDCSelect,objConfiguration,objContainer,errval,ODCPath,ckdcPath,myObj,comparename </em></p>
<p><em>rem =======This gets the name of the computer that the script is run on ====== </em></p>
<p><em>Set sh = CreateObject(&quot;WScript.Shell&quot;)      <br />key= &quot;HKEY_LOCAL_MACHINE&quot;       <br />computerName = sh.RegRead(key &amp; &quot;\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName\ComputerName&quot;) </em></p>
<p><em>rem === Get the default naming context of the domain==== </em></p>
<p><em>set objRoot=GetObject(&quot;LDAP://RootDSE&quot;)      <br />sPath = &quot;LDAP://OU=Domain Controllers,&quot; &amp; objRoot.Get(&quot;defaultNamingContext&quot;) </em></p>
<p><em>rem === Get the list of domain controllers==== </em></p>
<p><em>Set objConfiguration = GetObject(sPath)      <br />For Each objContainer in objConfiguration       <br />&#160;&#160;&#160; outval = outval &amp; vbtab &amp;&#160; objContainer.Name &amp; VBCRLF       <br />Next       <br />outval = Replace(outval, &quot;CN=&quot;, &quot;&quot;) </em></p>
<p><em>rem ==Retrieve the name of the broken DC from the user and verify it&#8217;s not this DC.=== </em></p>
<p><em>oDCSelect= InputBox (outval,&quot; Enter the computer name to be removed&quot;,&quot;&quot;)      <br />comparename = UCase(oDCSelect) </em></p>
<p><em>if comparename = computerName then      <br />&#160;&#160;&#160; msgbox &quot;The Domain Controller you entered is the machine that is running this script.&quot; &amp; vbcrlf &amp; _       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; &quot;You cannot clean up the metadata for the machine that is running the script!&quot;,,&quot;Metadata Cleanup Utility Error.&quot;       <br />&#160;&#160;&#160; wscript.quit       <br />End If </em></p>
<p><em>sPath = &quot;LDAP://OU=Domain Controllers,&quot; &amp; objRoot.Get(&quot;defaultNamingContext&quot;)      <br />Set objConfiguration = GetObject(sPath) </em></p>
<p><em>For Each objContainer in objConfiguration      <br />&#160;&#160;&#160; Err.Clear       <br />&#160;&#160;&#160; ckdcPath = &quot;LDAP://&quot; &amp; &quot;CN=&quot; &amp; oDCSelect &amp; &quot;,OU=Domain Controllers,&quot; &amp; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />&#160;&#160;&#160; set myObj=GetObject(ckdcPath)       <br />&#160;&#160;&#160; If err.number &lt;&gt;0 Then       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; errval= 1       <br />&#160;&#160;&#160; End If       <br />Next </em></p>
<p><em>If errval = 1 then      <br />&#160;&#160;&#160; msgbox &quot;The Domain Controller you entered was not found in the Active Directory&quot;,,&quot;Metadata Cleanup Utility Error.&quot;       <br />&#160;&#160;&#160; wscript.quit       <br />End If </em></p>
<p><em>abort = msgbox (&quot;You are about to remove all metadata for the server &quot; &amp; oDCSelect &amp; &quot;! Are you sure?&quot;,4404,&quot;WARNING!!&quot;)      <br />if abort &lt;&gt; 6 then       <br />&#160;&#160;&#160; msgbox &quot;Metadata Cleanup Aborted.&quot;,,&quot;Metadata Cleanup Utility Error.&quot;       <br />&#160;&#160;&#160; wscript.quit       <br />end if </em></p>
<p><em>oDCSelect = &quot;CN=&quot; &amp; oDCSelect      <br />ODCPath =&quot;LDAP://&quot; &amp; oDCselect &amp; &quot;,OU=Domain Controllers,&quot; &amp; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />sSitelist = &quot;LDAP://CN=Sites,CN=Configuration,&quot; &amp; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />Set objConfiguration = GetObject(sSitelist)       <br />For Each objContainer in objConfiguration       <br />&#160;&#160;&#160; Err.Clear       <br />&#160;&#160;&#160; sitePath = &quot;LDAP://&quot; &amp; oDCSelect &amp; &quot;,CN=Servers,&quot; &amp;&#160; objContainer.Name &amp; &quot;,CN=Sites,CN=Configuration,&quot; &amp; _       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />&#160;&#160;&#160; set myObj=GetObject(sitePath)       <br />&#160;&#160;&#160; If err.number = 0 Then       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; siteval = sitePath       <br />&#160;&#160;&#160; End If&#160;&#160;&#160; <br />Next </em></p>
<p><em>sFRSSysvolList = &quot;LDAP://CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,&quot; &amp; _      <br />&#160;&#160;&#160; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />Set objConfiguration = GetObject(sFRSSysvolList) </em></p>
<p><em>For Each objContainer in objConfiguration      <br />&#160;&#160;&#160; Err.Clear       <br />&#160;&#160;&#160; SYSVOLPath = &quot;LDAP://&quot; &amp; oDCSelect &amp; &quot;,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,&quot; &amp; _       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />&#160;&#160;&#160; set myObj=GetObject(SYSVOLPath)       <br />&#160;&#160;&#160; If err.number = 0 Then       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; SYSVOLval = SYSVOLPath       <br />&#160;&#160;&#160; End If       <br />Next </em></p>
<p><em>SiteList = Replace(sSitelist, &quot;LDAP://&quot;, &quot;&quot;)      <br />VarSitelist = &quot;LDAP://CN=Sites,CN=Configuration,&quot; &amp; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />Set SiteConfiguration = GetObject(VarSitelist) </em></p>
<p><em>For Each SiteContainer in SiteConfiguration      <br />&#160;&#160;&#160; Sitevar = SiteContainer.Name       <br />&#160;&#160;&#160; VarPath =&quot;LDAP://OU=Domain Controllers,&quot; &amp; objRoot.Get(&quot;defaultNamingContext&quot;)       <br />&#160;&#160;&#160; Set DCConfiguration = GetObject(VarPath)       <br />&#160;&#160;&#160; For Each DomContainer in DCConfiguration       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; DCVar = DomContainer.Name       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; strFromServer = &quot;&quot;       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; NTDSPATH =&#160; DCVar &amp; &quot;,CN=Servers,&quot; &amp; SiteVar &amp; &quot;,&quot; &amp; SiteList       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; GuidPath = &quot;LDAP://CN=NTDS Settings,&quot;&amp; NTDSPATH       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Set objCheck = GetObject(NTDSPATH)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; For Each CheckContainer in objCheck       <br />rem ====check for valid site paths =======================       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ldapntdspath = &quot;LDAP://&quot; &amp; NTDSPATH       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Err.Clear       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; set exists=GetObject(ldapntdspath)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; If err.number = 0 Then       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Set oGuidGet = GetObject(GuidPath)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; For Each objContainer in oGuidGet       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; oGuid = objContainer.Name       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; oGuidPath = &quot;LDAP://&quot; &amp; oGuid &amp; &quot;,CN=NTDS Settings,&quot; &amp; NTDSPATH&#160; <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Set objSitelink = GetObject(oGuidPath)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; objSiteLink.GetInfo       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; strFromServer = objSiteLink.Get(&quot;fromServer&quot;)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; ispresent = Instr(1,strFromServer,oDCSelect,1) </em></p>
<p><em>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; if ispresent &lt;&gt; 0 then      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Set objReplLinkVal = GetObject(oGuidPath)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; objReplLinkVal.DeleteObject(0)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; end if       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; next </em></p>
<p><em>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; sitedelval = &quot;CN=&quot; &amp; comparename &amp; &quot;,CN=Servers,&quot; &amp; SiteVar &amp; &quot;,&quot; &amp; SiteList      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; if sitedelval = ntdspath then       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Set objguidpath = GetObject(guidpath)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; objguidpath.DeleteObject(0)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Set objntdspath = GetObject(ldapntdspath)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; objntdspath.DeleteObject(0)       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; end if       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; End If       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; next       <br />&#160;&#160;&#160; next       <br />next       <br />Set AccountObject = GetObject(ckdcPath)       <br />temp=Accountobject.Get (&quot;userAccountControl&quot;)       <br />AccountObject.Put &quot;userAccountControl&quot;, &quot;4096&quot;       <br />AccountObject.SetInfo       <br />Set objFRSSysvol = GetObject(SYSVOLval)       <br />objFRSSysvol.DeleteObject(0)       <br />Set objComputer = GetObject(ckdcPath)       <br />objComputer.DeleteObject(0)       <br />Set objConfig = GetObject(siteval)       <br />objConfig.DeleteObject(0)       <br />oDCSelect = Replace(oDCSelect, &quot;CN=&quot;, &quot;&quot;)       <br />msgval = &quot;Metadata Cleanup Completed for &quot; &amp; oDCSelect       <br />msgbox&#160; msgval,,&quot;Notice.&quot;       <br />wscript.quit       <br /></em></p>
<p>An easy to use description of the ntdsutil.exe way you find under <a href="http://technet.microsoft.com/en-us/library/cc736378.aspx">http://technet.microsoft.com/en-us/library/cc736378.aspx</a></p>
<p>Next thing that will drive you crazy are the millions of ntfrs errors in the Eventlog. Ntfrs is the &#8220;New Technology File replication Service&#8221; from Windows. It is used for the replication of the sysvol/ netlogon. Remember Since Windows 2003 R2 nftrs is replaced trough DFS. First of all we are saving the eventlog to a file then clean it and boot every Domain Controller in the domain and wait a few minutes. On my experience this will fix half of the problems, like swiss admins tend to say &#8220;ein boot tut immer gut&#8221; ; -). </p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2009/05/24/kick-the-crashed-ad-controller-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Net App filer in Vmware</title>
		<link>http://www.dambeck.ch/2009/05/10/net-app-filer-in-vmware/</link>
		<comments>http://www.dambeck.ch/2009/05/10/net-app-filer-in-vmware/#comments</comments>
		<pubDate>Sun, 10 May 2009 10:07:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[app]]></category>
		<category><![CDATA[Filer]]></category>
		<category><![CDATA[NAS]]></category>
		<category><![CDATA[Net]]></category>
		<category><![CDATA[NetApp]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/2009/05/10/net-app-filer-in-vmware/</guid>
		<description><![CDATA[For a project I have to learn some of the specialty of an iScsi NAS. To be precise it was Net App FAS 2500 Filer. These things are very nice but a little too expensive for my personal use. But Net App offers a nice simulator of their product and the simulator is free. You [...]]]></description>
			<content:encoded><![CDATA[<p>For a project I have to learn some of the specialty of an iScsi NAS. To be precise it was Net App FAS 2500 Filer. These things are very nice but a little too expensive for my personal use. But Net App offers a nice simulator of their product and the simulator is free. You just need to create an account on the Net App web site and search for the word &#8221;simulator&#8221; or just follow this link. (<a href="http://now.netapp.com/NOW/cgi-bin/simulator)">http://now.netapp.com/NOW/cgi-bin/simulator)</a>. Some bloody side note: the website doesn&#8217;t work fine with safari. Just use Firefox and all works well in this case. </p>
<p>The other prerequirement you need is a Linux OS. I don&#8217;t want install some bloody Linux on my iMac, so I use VMware Fusion and the problem is solved. I use in this tutorial the Ubuntu 8.04 LTS Server. You might be considering now why I choose Ubuntu, the simple answer is I don&#8217;t known. Normally I use Open SUSE from Novell, but in this case I really don&#8217;t know. Strange things happen some times. Another side note I will guide you trough the installation so don&#8217;t panic if you are not an unix geek. But actually as non console junkie you should consider not to buy an EMC / IBM / &#8230; NAS ☺ </p>
<p>Create a VMware with the normal settings 1 CPU, 10 GB HD,&#160; Nat NIC and 512MB Ram. Attach the OS iso and boot the whole batch job. Using the default settings is a nice strategy for not so experienced user. I only changed the keyboard layout to &#8220;swiss german (mac)&#8221; and check in the screen &#8220;install additional software&#8221; &#8220;ssh server&#8221; file transfer will be easy. Create an user called &#8220;geek&#8221; Then after next, next, &#8230;., next, next. The server has finished the miraculous installation. As a windows administrator the first thing I have done is enter in the console </p>
<p><em>Sudo reboot</em> </p>
<p>After the restart I want to log in as root user, but the install wizard doesn&#8217;t accept the root password. After some time I decided to log in as user &#8220;geek&#8221;. Because it is only a testing environment I decided to enable root login in the console </p>
<p><em>sudo passwd root</em> </p>
<p>After setting the password i started a console session on my mac shell and connected with ssh. You don&#8217;t need to do this but with an ssh session you are able to use Copy and Past with the host OS. For the poor windows user putty is a nice ssh tool. The Mac and Linux user just need to enter the following commands in the console </p>
<p><em>ssh &lt;ip of the VM&gt; -i root</em> </p>
<p>the next thing you need to do is copying the download from the net app side &#8220;7.3.1-tarfile-v22.tar&#8221; to the VM server. I use &#8220;Cyberduck&#8221;. For windows users a nice program is winscp. The Linux guys should use the mighty shell console. By the way I createt a folder named &#8220;/netapp&#8221;. So let us open the tar file </p>
<p><em>tar xvf /netapp/7.3.1-tarfile-v22.tgz </em></p>
<p>In the readme form net app gives us a hint that the simulator uses perl. To install perl on your machine use &#8220;apt-get install perl&#8221;, actually pearl was installed so you don&#8217;t need to do it. Okay now we are ready to start installing the simulator. The strangest thing on this point was I didn&#8217;t have to deal with any problems, all worked just fine. This is a bad sign. </p>
<p><em>cd /netapp/simulator      <br />./setup.sh</em> </p>
<p>and the installation starts. Some logs from the console behind </p>
<p><em>Script version 22 (18/Sep/2007)      <br />Where to install to? [/sim]:       <br />Would you like to install as a cluster? [no]:       <br />Would you like full HTML/PDF FilerView documentation to be installed [yes]:       <br />Continue with installation? [no]: yes       <br />Creating /sim       <br />Unpacking sim.tgz to /sim       <br />Configured the simulators mac address to be [00:50:56:0:6c:5]       <br />Please ensure the simulator is not running.       <br />Your simulator has 3 disk(s). How many more would you like to add? [0]: 10 </em></p>
<p><em>The following disk types are available in MB:      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Real (Usable)       <br />&#160; a -&#160;&#160; 43&#160;&#160; ( 14)       <br />&#160; b -&#160;&#160; 62&#160;&#160; ( 30)       <br />&#160; c -&#160;&#160; 78&#160;&#160; ( 45)       <br />&#160; d -&#160; 129&#160;&#160; ( 90)       <br />&#160; e -&#160; 535&#160;&#160; (450)       <br />&#160; f &#8211; 1024&#160;&#160; (900) </em></p>
<p><em>If you are unsure choose the default option a      <br />What disk size would you like to use? [a]:       <br />Disk adapter to put disks on? [0]:       <br />Use DHCP on first boot? [yes]:       <br />Ask for floppy boot? [no]:       <br />Checking the default route&#8230;       <br />You have a single network interface called eth0 (default route) . You will not be able to access the simulator from this Linux host. If this interface is marked DOWN in ifconfig then your simulator will crash.       <br />Which network interface should the simulator use? [default]:       <br />Your system has 455MB of free memory. The smallest simulator memory you should choose is 110MB. The maximum simulator memory is 415MB.       <br />The recommended memory is 512MB.       <br />Your original default appears to be too high. Seriously consider adjusting to below the maximum amount of 415MB.       <br />How much memory would you like the simulator to use? [512]:       <br />Create a new log for each session? [no]:       <br />Overwrite the single log each time? [yes]:       <br />Adding 10 additional disk(s).       <br />Complete. Run /sim/runsim.sh to start the simulator. </em></p>
<p>Wow this was very easy. Nice Job Net App. In the last row there is the hint how to start the simulator so lets go. </p>
<p><em>/sim/runsim.sh</em> </p>
<p>Peng, Klaap, kabumm, doing and an error appears on the console &#8220;Error ./maytag.L: No such file or directory&#8221;. F.. after some time, maybe 4 hours reading logs, traying these and that, and drinking some coffee I figured out that I need to install some libraries for AMD 64. This sounds funny but it solved my problem. This was the penalty for the easy setup. </p>
<p><em>apt-get install ia32-libs</em></p>
<p><em></em>    <br />and again try to startup. I deleted some info rows from the console log. But all questions should be present in the log below. </p>
<p><em>root@netapp:/netapp/simulator# /sim/runsim.sh      <br />runsim.sh script version Script version 22 (18/Sep/2007)       <br />This session is logged in /sim/sessionlogs/log </em></p>
<p><em>NetApp Release 7.3.1: Thu Jan&#160; 8 00:10:49 PST 2009      <br />Copyright (c) 1992-2008 NetApp.       <br />&#8230;.       <br />&#8230;.       <br />&#8230;.       <br />Do you want to enable IPv6? [n]: n       <br />Do you want to configure virtual network interfaces? [n]:       <br />Please enter the IP address for Network Interface ns0 [172.16.111.136]:       <br />Please enter the netmask for Network Interface ns0 [255.255.255.0]:       <br />Please enter media type for ns0 {100tx-fd, auto} [auto]:       <br />Please enter the IP address for Network Interface ns1 []:       <br />Would you like to continue setup through the web interface? [n]:       <br />Please enter the name or IP address of the IPv4 default gateway [172.16.111.2]:       <br />&#160;&#160;&#160; The administration host is given root access to the filer&#8217;s       <br />&#160;&#160;&#160; /etc files for system administration.&#160; To allow /etc root access       <br />&#160;&#160;&#160; to all NFS clients enter RETURN below.       <br />Please enter the name or IP address of the administration host:       <br />Please enter timezone [GMT]:       <br />Where is the filer located? []:       <br />What language will be used for multi-protocol files (Type ? for list)?:       <br />language not set       <br />Do you want to run DNS resolver? [n]:       <br />Do you want to run NIS client? [n]: Setting the administrative (root) password for mynetapp &#8230; </em></p>
<p><em>New password:      <br />Retype new password:       <br />Mon May&#160; 4 20:31:11 GMT [passwd.changed:info]: passwd for user &#8216;root&#8217; changed.       <br />&#8230;.       <br />&#8230;.       <br />&#8230;.       <br />This process will enable CIFS access to the filer from a Windows(R) system.       <br />Use &quot;?&quot; for help at any prompt and Ctrl-C to exit without committing changes. </em></p>
<p><em>&#160;&#160;&#160;&#160;&#160;&#160;&#160; Your filer is currently visible to all systems using WINS. The WINS      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; name server currently configured is: [ 172.16.111.2 ]. </em></p>
<p><em>(1) Keep the current WINS configuration      <br />(2) Change the current WINS name server address(es)       <br />(3) Disable WINS </em></p>
<p><em>Selection (1-3)? [1]:      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; A filer can be configured for multiprotocol access, or as an NTFS-only       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; filer. Since multiple protocols are currently licensed on this filer,       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; we recommend that you configure this filer as a multiprotocol filer </em></p>
<p><em>(1) Multiprotocol filer      <br />(2) NTFS-only filer </em></p>
<p><em>Selection (1-2)? [1]:      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; CIFS requires local /etc/passwd and /etc/group files and default files       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; will be created.&#160; The default passwd file contains entries for &#8216;root&#8217;,       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; &#8216;pcuser&#8217;, and &#8216;nobody&#8217;.       <br />Enter the password for the root user []:       <br />Retype the password:       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; The default name for this CIFS server is &#8216;MYNETAPP&#8217;.       <br />Would you like to change this name? [n]:       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Data ONTAP CIFS services support four styles of user authentication.       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; Choose the one from the list below that best suits your situation. </em></p>
<p><em>(1) Active Directory domain authentication (Active Directory domains only)      <br />(2) Windows NT 4 domain authentication (Windows NT or Active Directory domains)       <br />(3) Windows Workgroup authentication using the filer&#8217;s local user accounts       <br />(4) /etc/passwd and/or NIS/LDAP authentication </em></p>
<p><em>Selection (1-4)? [1]: 4      <br />What is the name of the Workgroup? [WORKGROUP]:       <br />CIFS &#8211; Starting SMB protocol&#8230;       <br />Welcome to the WORKGROUP Windows(R) workgroup </em></p>
<p><em>CIFS local server is running. </em></p>
<p><em>Password:      <br />mynetapp&gt; Mon May&#160; 4 20:32:25 GMT [console_login_mgr:info]: root logged in from console       <br />Mon May&#160; 4 20:32:31 GMT [nbt.nbns.registrationComplete:info]: NBT: All CIFS name registrations have completed for the local server. </em></p>
<p><em>mynetapp&gt; </em></p>
<p>SO this was not so hard. Now enjoy the world class filer in your VMware </p>
<p>&#160;</p>
<p><a href="http://www.dambeck.ch/wp-content/uploads/2009/05/netapp.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="387" alt="netapp" src="http://www.dambeck.ch/wp-content/uploads/2009/05/netapp-thumb.jpg" width="547" border="0" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2009/05/10/net-app-filer-in-vmware/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Fine grained password policy</title>
		<link>http://www.dambeck.ch/2009/03/08/fine-grained-password-policy/</link>
		<comments>http://www.dambeck.ch/2009/03/08/fine-grained-password-policy/#comments</comments>
		<pubDate>Sun, 08 Mar 2009 14:18:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[pso]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/2009/03/08/fine-grained-password-policy/</guid>
		<description><![CDATA[Today we take a closer look at the Microsoft Active Directory in the 2008 native mode. One of the problems that windows administrators often face in the daily business is the setting of password policies for the whole company. Under Windows Server 2003 it was not possible to set more than one policy for the [...]]]></description>
			<content:encoded><![CDATA[<p>Today we take a closer look at the Microsoft Active Directory in the 2008 native mode. One of the problems that windows administrators often face in the daily business is the setting of password policies for the whole company. Under Windows Server 2003 it was not possible to set more than one policy for the accounts. So from the domain administrator to the user every body needed the same complex password. Under active directory in version 2008 there is a new object type in the schema which is called PSO (password settings object). The only way to create the PSO is in ADSI edit. Click on start and enter &#8220;adsiedit.msc&#8221;. </p>
<p>&#160; </p>
<p>In ADSI edit Connect to the &#8220;Default naming context&#8221; and browse to the CN= Password <a href="http://www.dambeck.ch/wp-content/uploads/2009/03/adsiedt.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="73" alt="adsiedt" src="http://www.dambeck.ch/wp-content/uploads/2009/03/adsiedt-thumb.jpg" width="232" align="left" border="0" /></a>Settings Container,CN=System,DC=YourDomain,DC=YourDomain. With the right click you are able to create a new PSO with a wizard (I am not 100 % sure but it is a wise idea to do this with the newest version of adsiedit.msc on the server). </p>
<p>The wizard shows up and your are able to set the PSO settings:    <br />&#8226;&#160;&#160;&#160; Password settings precedence     <br />&#8226;&#160;&#160;&#160; Password reversible encryption status for user accounts     <br />&#8226;&#160;&#160;&#160; Password history length for user accounts     <br />&#8226;&#160;&#160;&#160; Password complexity status for user accounts     <br />&#8226;&#160;&#160;&#160; Minimum password length for user accounts     <br />&#8226;&#160;&#160;&#160; Minimum password age for user accounts     <br />&#8226;&#160;&#160;&#160; Maximum password age for user accounts     <br />&#8226;&#160;&#160;&#160; Lockout threshold for lockout of user accounts     <br />&#8226;&#160;&#160;&#160; Observation window for lockout of user accounts     <br />&#8226;&#160;&#160;&#160; Lockout duration for locked out user accounts     <br />&#8226;&#160;&#160;&#160; Links to objects that this password settings object applies to (forward link).</p>
<p><a href="http://www.dambeck.ch/wp-content/uploads/2009/03/ldap.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="244" alt="ldap" src="http://www.dambeck.ch/wp-content/uploads/2009/03/ldap-thumb.jpg" width="224" align="right" border="0" /></a>     <br />The last setting is very nice. The policy are now bound to an active directory global, universal or domain local group. The PSO does not outweigh the older GPO based managed policy. If a user has a policy both through PSO and GPO the GPO policy is enforced. </p>
<p>To use the PSO a PDC Emulator FSMO Role must be configured on the Windows 2008 Server. The domain and forest function level must be at least Windows Server 2008. The PSO works on Windows XP, Vista, 2003 and 2008 Servers. </p>
<p>Enjoy the simplified but even though smarter password policy    <br />Cheers Konrad</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2009/03/08/fine-grained-password-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Server Baseline Security</title>
		<link>http://www.dambeck.ch/2009/01/23/windows-server-baseline-security/</link>
		<comments>http://www.dambeck.ch/2009/01/23/windows-server-baseline-security/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 19:35:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[EDV & Admin Stuff]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[2003]]></category>
		<category><![CDATA[Baseline Security]]></category>
		<category><![CDATA[scw]]></category>
		<category><![CDATA[Security Configuration Wizard]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/2009/01/23/windows-server-baseline-security/</guid>
		<description><![CDATA[Part One. Today an in my next posts we want take a closer look at the security settings of an windows server. One good way to start is the &#34;Security Configuration Wizard&#34; later called as SCW. The wizard was patched in the operating system with SP1. In the release 2 of windows server 2003 you [...]]]></description>
			<content:encoded><![CDATA[<p>Part One. Today an in my next posts we want take a closer look at the security settings of an windows server. One good way to start is the &quot;Security Configuration Wizard&quot; later called as SCW. The wizard was patched in the operating system with SP1. In the release 2 of windows server 2003 you don&#8217;t need to patch it&#8217;s from start up SP2. To enable the feature just open the windows components dialog (&quot;Add or Remove Programs&quot; -&gt; &quot;Add/Remove Windows Components&quot;) and mark the check box. Now you need to insert the windows disk. In the &quot;Administrative <a href="http://www.dambeck.ch/wp-content/uploads/2009/01/image.png"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 5px 5px 0px 0px; border-right-width: 0px" height="115" alt="image" src="http://www.dambeck.ch/wp-content/uploads/2009/01/image-thumb.png" width="244" align="left" border="0" /></a>Tools&quot; you will find an new program &quot;Security Configuration Wizard&quot;. Or just run &quot;scw.exe&quot; from the run. On the start up screen of the SCW there is the first important notice. The message indicates that the wizard will detect inbound ports that are being used by this server. This requires that all applications that use inbound ports be running before you run the wizard and create the security policy. In my lab the server will work as file and print server. To do it al little harder the lab Server runs also TeamSpeak witch is not an Microsoft Application . The teamspeak server <a href="http://www.dambeck.ch/wp-content/uploads/2009/01/image1.png"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 5px 0px 5px 5px; border-right-width: 0px" height="100" alt="image" src="http://www.dambeck.ch/wp-content/uploads/2009/01/image-thumb1.png" width="244" align="right" border="0" /></a>will listen on UDP Port&#160; 8767. After Clicking next, the wizard ask to crate an new policy. The next part is Interesting you are able to chose the Local or an remote server. My preferred option is to insta ll the SCW on each server and make local scans. Now we are able to check the version of the &quot;Security DB&quot;. If you need an special service on many server&#8217;s witch is not listed edit the XML files in &quot;%SystemRoot%\Security\msscw\policies%&quot;. More info about the XML file are located on google. After Skipping the window we are able to chose the server roles . In the next Dialog we are able to chose the client features like DHCP client, wins client &#8230;. and may more. Now microsoft want us to chose witch are the installed options of the server. The SCW now detects non windows services. in my lab he find the VM Tool&#8217;s <img src='http://www.dambeck.ch/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . Now we must approve the disabling of unused services. Please check the list very cheerfully. Now the big magic continues with the approval of TCP/ IP ports. Please check the list very cheerfully. Now one of the biggest <a href="http://www.dambeck.ch/wp-content/uploads/2009/01/image2.png"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 5px 5px 0px 0px; border-right-width: 0px" height="110" alt="image" src="http://www.dambeck.ch/wp-content/uploads/2009/01/image-thumb2.png" width="244" align="left" border="0" /></a> &quot;lion&#8217;s den&quot;. In the registry the SCW will change settings for &quot;SMB Security Signatures&quot;, &quot;LDAP Signing&quot;, &quot;Outbound Authentication Protocols&quot; and &quot;Inbound Authentication Protocols&quot;. with this settings enabled the server are harden to the most man-in-the-middle attacks an password cracking will be not so easy. The audit policy is a mixed blessing. Its very imported to find security issues in the logs. But study the logs will take much much time. So just enable the normal logging. Enter an Description an Save the Policy File. Now You Are able to apply&#160; the policy now or later. Applying the policy will force an restart of the server !!</p>
<p>After applying the policy the TeamSpeak server stop&#8217;s working like except. But after editing the policy and again, insert the port 8767 all services works fine.</p>
<p>&#160;</p>
<p>My conclusion of the Microsoft Security Configuration Wizard is: The tool is very easy to use and brings many good changes in short time. The use of SCW sold be carefully tested. But i&#8217;m strongly advise the use on all windows servers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2009/01/23/windows-server-baseline-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7</title>
		<link>http://www.dambeck.ch/2009/01/17/windows-7/</link>
		<comments>http://www.dambeck.ch/2009/01/17/windows-7/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 14:11:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[EDV & Admin Stuff]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[seven]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[windows7]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/2009/01/17/windows-7/</guid>
		<description><![CDATA[It&#8217;s new, It&#8217;s hot, It&#8217;s Seven and It&#8217;s in Beta. The new version of the Microsoft Client Operating System. Since the 10 of January the beat version can be obtain from  www.microsoft.com. So lets take a short look to the new philosopher&#8217;s stone of Microsoft. In this little Video you can see the Installation of [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s new, It&#8217;s hot, It&#8217;s Seven and It&#8217;s in Beta. The new version of the Microsoft Client Operating System. Since the 10 of January the beat version can be obtain from  <a href="http://www.microsoft.com">www.microsoft.com</a>. So lets take a short look to the new philosopher&#8217;s stone of Microsoft. In this little Video you can see the Installation of Windows Seven. Take a special look to the Hard drive Partitioning and to the new Homegoupe feature.</p>
<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/RFrHkVHIuck&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/RFrHkVHIuck&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></embed></object></p>
<p> </p>
<div id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:53bfd7d6-b7aa-4044-95b6-d04521b4c1dc" class="wlWriterSmartContent" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">
<div id="cbc4f986-772f-430b-b899-a45fe7291991" style="margin: 0px; padding: 0px; display: inline;">
<div><a href="http://www.youtube.com/watch?v=RFrHkVHIuck&amp;hl=en&amp;fs=1" target="_new"><img src="http://www.dambeck.ch/wp-content/uploads/2009/01/video1921b28deb63.jpg" alt="" width="\" height="\" /></a></div>
</div>
</div>
<p>After some exploring the new OS i&#8217;m feel fine because not everything <a href="http://www.dambeck.ch/wp-content/uploads/2009/01/seven-bluescreen.jpg"><img style="border-right: 0px; border-top: 0px; margin: 5px 5px 5px 0px; border-left: 0px; border-bottom: 0px" src="http://www.dambeck.ch/wp-content/uploads/2009/01/seven-bluescreen-thumb.jpg" border="0" alt="Seven_bluescreen" width="244" height="166" align="left" /></a>has changed. hire some Print screen of my first Bluescreen on Seven. The Screen appeared when try to install the VMware Tools. After a reboot the install worked fine.</p>
<p>If you want to try your own Seven install an inplace upgrade should work from Vista Sp1. Or an new Installation. The Installation need 6,4 GB Diskspace.</p>
<p>Some nice things in the beta are Internet Explorer 8, Medaplayer, DirectX 11, an new dressing paint Gui and an Freaky Taskbar.</p>
<p>Generally the new design look&#8217;s very nice and the User Account Controll, is not so annoying like in Vista. my guess is that Microsoft is on the rigth way with Windows Seven build 7000</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2009/01/17/windows-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wien</title>
		<link>http://www.dambeck.ch/2008/08/21/wien/</link>
		<comments>http://www.dambeck.ch/2008/08/21/wien/#comments</comments>
		<pubDate>Thu, 21 Aug 2008 22:30:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Dies und Das]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Wien]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/?p=238</guid>
		<description><![CDATA[&#8220;Seiens grüsst&#8221; oder wie die auch hier alle sagen. Zur zeit ist etwas Flaute auf dem Blog. Dies ligt daran das ich über ganz Europa verstreut bin. Zur Zeit lebe ich in Wien im Schönen Östereich. Ich sage euch nicht alle Klischees über die Ösis stimmen. Das erste Klischee. Die Wiener Essen nur die ganze [...]]]></description>
			<content:encoded><![CDATA[<p style="margin-bottom: 0in;">&#8220;Seiens grüsst&#8221; oder wie die auch hier alle sagen. Zur zeit ist etwas Flaute auf dem Blog. Dies ligt daran das ich über ganz Europa verstreut bin. Zur Zeit lebe ich in Wien im Schönen Östereich. Ich sage euch nicht alle Klischees über die Ösis stimmen.</p>
<p style="margin-bottom: 0in; text-align: center;"><a href="http://www.dambeck.ch/wp-content/uploads/2008/08/schloss-panorama1.jpe"><img class="alignnone size-full wp-image-240 aligncenter" title="schloss-panorama1" src="http://www.dambeck.ch/wp-content/uploads/2008/08/schloss-panorama1.jpe" alt="" width="500" height="129" /></a></p>
<p style="margin-bottom: 0in;">Das erste Klischee. Die Wiener Essen nur die ganze zeit „Wienerli“ (Winer Würstchen). Stimmt nicht. Alls ich an der Würstchenbude um die Ecke stehe und den netten Mann hinter der Teke Frage ob er mir nicht ein Paar Wiener Würstchen geben wurde. Erntete ich Komische Blicke. Den die Würstchen heissen hier „Frankfurter Würstchen“. Warscheindlich sagen die Frankfurter zu den Würstchen „lozarner Würstchen“.</p>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">Das Zweite Klischee. Das Wiener Schnitzel ist mit Kalbfleisch nicht mit Schweinefleisch zubereitet. Komisch nicht</p>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">Das Dritte Klischee. Wien ist teuer. Das stimmt auch nur bedingt. Gemäss dem Big Mac index Liegt  Österreich über der Schweiz. Da geld ja bekantlich nicht alles ist habe ich den Qualität&#8217;s Test gemacht und bin zu der Überzeugung gekommen das er in Österreich auch gut schmeckt.</p>
<p style="margin-bottom: 0in;">&lt;!&#8211; 		@page { size: 8.27in 11.69in; margin: 0.79in } 		P { margin-bottom: 0.08in } 	&#8211;&gt;</p>
<p style="margin-bottom: 0in;">Was mich aber noch mehr fasziniert hat ist das die Iluminati in Wien waren oder besser gesagt sind. In der Karlskirche habe ich dieses Bild an der Decke als Freske Entdeckt.</p>
<p style="margin-bottom: 0in;"><a href="http://www.dambeck.ch/wp-content/uploads/2008/08/dsc_0993.jpg"><img class="alignnone size-full wp-image-241" title="Iluminatus" src="http://www.dambeck.ch/wp-content/uploads/2008/08/dsc_0993.jpg" alt="The Mona Lisa" width="500" height="331" /></a></p>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2008/08/21/wien/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Feuerzauber</title>
		<link>http://www.dambeck.ch/2008/08/02/feuerzauber/</link>
		<comments>http://www.dambeck.ch/2008/08/02/feuerzauber/#comments</comments>
		<pubDate>Sat, 02 Aug 2008 14:34:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Dies und Das]]></category>
		<category><![CDATA[Fun Fun Fun]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Blende]]></category>
		<category><![CDATA[Digital]]></category>
		<category><![CDATA[Feuerwerk]]></category>
		<category><![CDATA[Photo]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/?p=227</guid>
		<description><![CDATA[Gestern war es wieder so weit der 1 August wurde gefeiert. Für alle welche nicht aus unseren Breitengraden kommen, Der erste August ist der Nationalfeiertag der Schweiz. Nach dem Obligaten Grillen war es zeit für das Feuerwerk. Alle Photos wurden nicht nacharbeitet. Ich habe alle Photos selber geschossen. Im Gegensatz zu der gängigen Meinung habe [...]]]></description>
			<content:encoded><![CDATA[<p style="margin-bottom: 0in;"><a href="http://www.dambeck.ch/wp-content/uploads/2008/08/feuerwerk1.jpg"><img class="alignleft size-medium wp-image-230" title="feuerwerk1" src="http://www.dambeck.ch/wp-content/uploads/2008/08/feuerwerk1-225x300.jpg" alt="" width="138" height="184" /></a>Gestern war es wieder so weit der 1 August wurde gefeiert. Für alle welche nicht aus unseren Breitengraden kommen, Der erste August ist der Nationalfeiertag der Schweiz. Nach dem Obligaten Grillen war es zeit für das Feuerwerk. Alle Photos wurden nicht nacharbeitet. Ich habe alle Photos selber geschossen. Im Gegensatz zu der gängigen Meinung habe ich die Bilder ohne ein Stativ gemacht. Da ich keine Lust zum schleppen verspürt habe. Ich bin aber der meinung das ein Stativ sicher nichts geschadet hatte<a href="http://www.dambeck.ch/wp-content/uploads/2008/08/swiss.jpg"><img class="alignright size-medium wp-image-229" title="swiss" src="http://www.dambeck.ch/wp-content/uploads/2008/08/swiss-300x225.jpg" alt="" width="215" height="162" /></a>. Einen dank an <a href="http://www.digiklix.de/">www.digiklix.de</a> und <a href="http://www.hobbyphotographen.de/">www.hobbyphotographen.de</a> ihr habt wie immer Ideen für die richtigen Einstellungen. Bei der Blende habe ich mich so um F14 rumbewegt und die Verschlusszeit habe ich auf ca 4 sek gebt. Das Objektiv war auf etwas vor undeutlich geschraubt. Der AF war aus ! (nach dem 3. ten Bild oder so).</p>
<p style="margin-bottom: 0in;"><a href="http://www.dambeck.ch/wp-content/uploads/2008/08/feuerwerk2.jpg"><img class="aligncenter size-medium wp-image-231" title="feuerwerk2" src="http://www.dambeck.ch/wp-content/uploads/2008/08/feuerwerk2-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p style="margin-bottom: 0in;">
<p style="margin-bottom: 0in;">&lt;!&#8211; 		@page { size: 8.27in 11.69in; margin: 0.79in } 		P { margin-bottom: 0.08in } 	&#8211;&gt;</p>
<p style="margin-bottom: 0in;">Das ganze ist Eigentlich eine rechte glücksache ob die Raketen da Funkeln wo die das objektiv der Kamera Liegt. Was auch immer listig ist wenn Freunde sich die „Bengalischen Zündhölzer“ schnappen und einfach etwas in die Luft Zeichnen oder schreiben „Its Magic“ <img src='http://www.dambeck.ch/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p style="margin-bottom: 0in;">Unter dem <a title="Feuerspiele www.dambeck.ch" href="http://www.dambeck.ch/photos/feuerspiele/" target="_self">Link findet ihr alle Bilder vom Feuerwerk</a>. Falls jemand alle Bilder Möchte einfach ein Mail an Mich.</p>
<p style="margin-bottom: 0in;">
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2008/08/02/feuerzauber/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nix geling in Peking</title>
		<link>http://www.dambeck.ch/2008/07/28/nix-geling-in-peking/</link>
		<comments>http://www.dambeck.ch/2008/07/28/nix-geling-in-peking/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 11:22:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Fun Fun Fun]]></category>
		<category><![CDATA[GBI]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[geling]]></category>
		<category><![CDATA[Nix]]></category>
		<category><![CDATA[Peking]]></category>
		<category><![CDATA[swr3]]></category>

		<guid isPermaLink="false">http://www.dambeck.ch/?p=223</guid>
		<description><![CDATA[SWR 3 (das beste Radio neben last.fm) bringt pünktlich zur Sommer Olympiade in Peking ihre neue komedie Serie „Nix geling in Peking“. Die Serie mutet sich wie eine chinesische Billigkopie der Erfolgs-Comedy „Nix verstehn in Athen“ an . Also los gehts zu den Abenteurern des  Geheimdienstschef Li Sta Si, seinem zweitbesten Spitzel Wan Ze und [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.dambeck.ch/wp-content/uploads/2008/07/nixgeling_150.jpg"><img class="size-medium wp-image-224 alignright" style="float: right;" title="nixgeling_150" src="http://www.dambeck.ch/wp-content/uploads/2008/07/nixgeling_150.jpg" alt="" width="150" height="150" /></a></p>
<p>SWR 3 (das beste Radio neben last.fm) bringt pünktlich zur Sommer Olympiade in Peking ihre neue komedie Serie „Nix geling in Peking“. Die Serie mutet sich wie eine chinesische Billigkopie der Erfolgs-Comedy „Nix verstehn in Athen“ an <img src='http://www.dambeck.ch/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . Also los gehts zu den Abenteurern des  Geheimdienstschef Li Sta Si, seinem zweitbesten Spitzel Wan Ze und seiner gar nicht herben Tochter Re China. Bleibt nur zu hoffen das der große Vorsitzende damit einverstanden ist</p>
<p><a title="swr3 rss" href="http://www.swr3.de/rdf-feed/podcast/nixgeling.xml.php" target="_blank">Zum RSS Feed mit allen Folgen</a></p>
<p><a title="iTuses Podcast" href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=285324950">Zum iTunes Podcast</a></p>
<p><a title="Just SWR 3" href="http://www.swr3.de/podcast/nixgelinginpeking.html">Zur SWR3 Webseite</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.dambeck.ch/2008/07/28/nix-geling-in-peking/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

