Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Geoff

Edu Supporters
  • Posts

    13,543
  • Joined

Everything posted by Geoff

  1. Run the following powershell. If the key doesn't exist or is a value other than '0' then SMB1 is enabled. Get-Itemproperty "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1
  2. As I threatened to do in a previous thread I have a PSADT script that uninstalls old VNC and puts on the new version with the correct settings. I have a seperate 'firewall' GPO for controlling the Windows Firewall ports. I am deploying via SCCM but that wouldn't be required to use the script.
  3. Ok I got time to write this a while ago. It'll upgrade any old UltraVNC to 1.2.1.2 and configure with the settings supplied (via ini file) and also import any AD group requirements for AD based auth. It also understands bitness so will install 32bit on 32bit systems and 64bit on 64bit systems. I have a couple more features I'd like to add: - Installing/upgrade/removal and enabling of the mirror drivers. - Installing and enabling of the encryption plugins. - Installing the screen capture app.
  4. I use SCCM servicing plans. https://docs.microsoft.com/en-us/sccm/osd/deploy-use/manage-windows-as-a-service
  5. It's because of this: https://blogs.technet.microsoft.com/wsus/2016/01/22/for-those-on-wsus-3-0-sp2-or-sbs-2011/ You can't do anything but upgrade.
  6. We'll you've got until 2020 to upgrade so it's not too bad.
  7. If you do need the extra juice that would normally require a midspan you can get an extra power unit that daisy chains off the PoE switch. For example if you got hold of an old HP 2650-PWR (J8165A) then you could also get a Procurve 600 External PSU (J8168A) to give you the juice. Although I'm not exactly sure what needs that kind of power (our 2620-48's manage a full bank of VoIP phones on their internal PSU without problems).
  8. Win10 1703 is not working on some of my 2k8 r2 WSUS servers and it is working on others. According to Microsoft this config is 'unsupported'. New 2016 server in the works :E
  9. Also consider DirectAccess. https://technet.microsoft.com/en-us/library/mt421256.aspx
  10. Thats because it depends what version of windows you are using, from the link I posted above:
  11. You should always update your central store as it is less headaches for everyone. https://support.microsoft.com/en-us/help/3087759/how-to-create-and-manage-the-central-store-for-group-policy-administrative-templates-in-windows
  12. RDP into the SCCM server and run the console via psexec as SYSTEM. You can then fix your security permissions.
  13. Do you have access to the security settings with any account?
  14. When PXE booting breaks the default answer is the remove the DP role from the server and uninstall WDS then redo them.
  15. The correct 'Thaumcraft' way to deal with this is: Encase in an obsidian cube so it can't eat the terrain. Feed it crafting tables until it has max stats. Bottle it and bring it back to your thaumcraft base release it and stabilise it.
  16. SCCM needs the 'sysadmin' role on the SQL server. If your local admin group doesn't have that you have a broken SQL server.
  17. No, the SCCM site server computer account needs to be listed in the local administrators group on the SQL server. SCCM 2012 R2 – Site server computer account administrative rights failed | Jack Stromberg
  18. If you didn't do a migration I think you SOL and will have to recreate your apps.
  19. Generally the computer account of the management point. However you can override this setting in Admin -> Site Config -> Servers & Site System Roles -> -> Management point. Right click on Properties and check out the settings on the Management Point Database Tab.
  20. Still the wrong msp file. Adobe, why do you have to make your FTP site so confusing :/ Got the right one now though finally!
  21. Infact, even though I have got the right msp file it still doesn't work.
  22. Never mind. I fixed this. Yet again, I'm an idiot and downloaded the continuous track update instead of the classic track.
  23. I install Adobe Reader DC via a PSADT. <# .SYNOPSIS This script performs the installation or uninstallation of an application(s). .DESCRIPTION The script is provided as a template to perform an install or uninstall of an application(s). The script either performs an "Install" deployment type or an "Uninstall" deployment type. The install deployment type is broken down into 3 main sections/phases: Pre-Install, Install, and Post-Install. The script dot-sources the AppDeployToolkitMain.ps1 script which contains the logic and functions required to install or uninstall an application. .PARAMETER DeploymentType The type of deployment to perform. Default is: Install. .PARAMETER DeployMode Specifies whether the installation should be run in Interactive, Silent, or NonInteractive mode. Default is: Interactive. Options: Interactive = Shows dialogs, Silent = No dialogs, NonInteractive = Very silent, i.e. no blocking apps. NonInteractive mode is automatically set if it is detected that the process is not user interactive. .PARAMETER AllowRebootPassThru Allows the 3010 return code (requires restart) to be passed back to the parent process (e.g. SCCM) if detected from an installation. If 3010 is passed back to SCCM, a reboot prompt will be triggered. .PARAMETER TerminalServerMode Changes to "user install mode" and back to "user execute mode" for installing/uninstalling applications for Remote Destkop Session Hosts/Citrix servers. .PARAMETER DisableLogging Disables logging to file for the script. Default is: $false. .EXAMPLE powershell.exe -Command "& { & '.\Deploy-Application.ps1' -DeployMode 'Silent'; Exit $LastExitCode }" .EXAMPLE powershell.exe -Command "& { & '.\Deploy-Application.ps1' -AllowRebootPassThru; Exit $LastExitCode }" .EXAMPLE powershell.exe -Command "& { & '.\Deploy-Application.ps1' -DeploymentType 'Uninstall'; Exit $LastExitCode }" .EXAMPLE Deploy-Application.exe -DeploymentType "Install" -DeployMode "Silent" .NOTES Toolkit Exit Code Ranges: 60000 - 68999: Reserved for built-in exit codes in Deploy-Application.ps1, Deploy-Application.exe, and AppDeployToolkitMain.ps1 69000 - 69999: Recommended for user customized exit codes in Deploy-Application.ps1 70000 - 79999: Recommended for user customized exit codes in AppDeployToolkitExtensions.ps1 .LINK http://psappdeploytoolkit.com #> [CmdletBinding()] Param ( [Parameter(Mandatory=$false)] [ValidateSet('Install','Uninstall')] [string]$DeploymentType = 'Install', [Parameter(Mandatory=$false)] [ValidateSet('Interactive','Silent','NonInteractive')] [string]$DeployMode = 'Interactive', [Parameter(Mandatory=$false)] [switch]$AllowRebootPassThru = $false, [Parameter(Mandatory=$false)] [switch]$TerminalServerMode = $false, [Parameter(Mandatory=$false)] [switch]$DisableLogging = $false ) Try { ## Set the script execution policy for this process Try { Set-ExecutionPolicy -ExecutionPolicy 'ByPass' -Scope 'Process' -Force -ErrorAction 'Stop' } Catch {} ##*=============================================== ##* VARIABLE DECLARATION ##*=============================================== ## Variables: Application [string]$appVendor = 'Adobe' [string]$appName = 'Reader DC 2015 Classic Track' [string]$appVersion = '17.009.20044' [string]$appArch = '' [string]$appLang = 'EN' [string]$appRevision = '01' [string]$appScriptVersion = '1.0.0' [string]$appScriptDate = '13/04/2017' [string]$appScriptAuthor = 'IT Department' ##*=============================================== ## Variables: Install Titles (Only set here to override defaults set by the toolkit) [string]$installName = '' [string]$installTitle = '' ##* Do not modify section below #region DoNotModify ## Variables: Exit Code [int32]$mainExitCode = 0 ## Variables: Script [string]$deployAppScriptFriendlyName = 'Deploy Application' [version]$deployAppScriptVersion = [version]'3.6.9' [string]$deployAppScriptDate = '02/12/2017' [hashtable]$deployAppScriptParameters = $psBoundParameters ## Variables: Environment If (Test-Path -LiteralPath 'variable:HostInvocation') { $InvocationInfo = $HostInvocation } Else { $InvocationInfo = $MyInvocation } [string]$scriptDirectory = Split-Path -Path $InvocationInfo.MyCommand.Definition -Parent ## Dot source the required App Deploy Toolkit Functions Try { [string]$moduleAppDeployToolkitMain = "$scriptDirectory\AppDeployToolkit\AppDeployToolkitMain.ps1" If (-not (Test-Path -LiteralPath $moduleAppDeployToolkitMain -PathType 'Leaf')) { Throw "Module does not exist at the specified location [$moduleAppDeployToolkitMain]." } If ($DisableLogging) { . $moduleAppDeployToolkitMain -DisableLogging } Else { . $moduleAppDeployToolkitMain } } Catch { If ($mainExitCode -eq 0){ [int32]$mainExitCode = 60008 } Write-Error -Message "Module [$moduleAppDeployToolkitMain] failed to load: `n$($_.Exception.Message)`n `n$($_.InvocationInfo.PositionMessage)" -ErrorAction 'Continue' ## Exit the script, returning the exit code to SCCM If (Test-Path -LiteralPath 'variable:HostInvocation') { $script:ExitCode = $mainExitCode; Exit } Else { Exit $mainExitCode } } #endregion ##* Do not modify section above ##*=============================================== ##* END VARIABLE DECLARATION ##*=============================================== If ($deploymentType -ine 'Uninstall') { ##*=============================================== ##* PRE-INSTALLATION ##*=============================================== [string]$installPhase = 'Pre-Installation' ## Show Welcome Message, close Reader if required, allow up to 3 deferrals, verify there is enough disk space to complete the install, and persist the prompt Show-InstallationWelcome -CloseApps "acroread32=Adobe Reader" -CheckDiskSpace -RequiredDiskSpace 500 -CloseAppsCountdown 600 -AllowDeferCloseApps -BlockExecution -DeferTimes 3 -PromptToSave ## Show Progress Message (with the default message) Show-InstallationProgress ## # Uninstall all existing Adobe Reader Remove-MSIApplications "Adobe Reader XI" Remove-MSIApplications "Adobe Acrobat Reader DC" ##*=============================================== ##* INSTALLATION ##*=============================================== [string]$installPhase = 'Installation' ## Show-InstallationProgress "Installing $installTitle. Please wait..." Execute-MSI -Action Install -Path "AcroRead.msi" -Transform "Settings.mst" -Patch "AcrobatDCUpd1700920044.msp" ##*=============================================== ##* POST-INSTALLATION ##*=============================================== [string]$installPhase = 'Post-Installation' ## # Force a Hardware Inventory (to refresh Installed Software in SCCM DB) Invoke-SCCMTask 'HardwareInventory' } ElseIf ($deploymentType -ieq 'Uninstall') { ##*=============================================== ##* PRE-UNINSTALLATION ##*=============================================== [string]$installPhase = 'Pre-Uninstallation' ## Show Welcome Message, close Reader with a 60 second countdown before automatically closing Show-InstallationWelcome -CloseApps "acroread32=Adobe Reader" -CheckDiskSpace -RequiredDiskSpace 500 -CloseAppsCountdown 600 -AllowDeferCloseApps -BlockExecution -DeferTimes 3 -PromptToSave ## Show Progress Message (with the default message) Show-InstallationProgress ## ##*=============================================== ##* UNINSTALLATION ##*=============================================== [string]$installPhase = 'Uninstallation' # # Patch 15.006.3028.0 GUID Execute-MSI -Action 'Uninstall' -Path '{AC76BA86-7AD7-FFFF-7B44-AE0F06755100}' ##*=============================================== ##* POST-UNINSTALLATION ##*=============================================== [string]$installPhase = 'Post-Uninstallation' ## # Force a Hardware Inventory (to refresh Installed Software in SCCM DB) Invoke-SCCMTask 'HardwareInventory' } ##*=============================================== ##* END SCRIPT BODY ##*=============================================== ## Call the Exit-Script function to perform final cleanup operations Exit-Script -ExitCode $mainExitCode } Catch { [int32]$mainExitCode = 60001 [string]$mainErrorMessage = "$(Resolve-Error)" Write-Log -Message $mainErrorMessage -Severity 3 -Source $deployAppScriptFriendlyName Show-DialogBox -Text $mainErrorMessage -Icon 'Stop' Exit-Script -ExitCode $mainExitCode } This worked fine for Jan. I have amended it for the April patch and it is not working. I get the following error: The upgrade cannot be installed by the Windows Installer service because the program to be upgraded may be missing, or the upgrade may update a different version of the program. Verify that the program to be upgraded exists on your computer and that you have the correct upgrade. PSADT is running the following: [installation] :: Executing [C:\Windows\system32\msiexec.exe /i "\\server\share\SCCMDeployments\Adobe Acrobat DC 2015 Classic\17.009.20044\Files\AcroRead.msi" TRANSFORMS="\\server\shar\SCCMDeployments\Adobe Acrobat DC 2015 Classic\17.009.20044\Files\Settings.mst" TRANSFORMSSECURE=1 PATCH="\\server\shar\SCCMDeployments\Adobe Acrobat DC 2015 Classic\17.009.20044\Files\AcrobatDCUpd1700920044.msp" REBOOT=ReallySuppress /QB-! /L*v "C:\Windows\Logs\Software\AcroRead_Install.log"]... According to the Adobe article the parameters PSADT have passed should work: Windows cmd line and msiexec — Enterprise Administration Guide Under the 'Chaining Updates' for quarterly updates it has an example of: msiexec /i [uNC PATH]\AcroRead.msi PATCH="[uNC PATH]\AdbeRdrUpd11001.msp; [uNC PATH]\AdbeRdrSecUpd11002.msp" TRANSFORMS="AcroRead.mst Any ideas?
  24. No it isn't, you can use a bog standard internet connection and most of the time it will be fine. You will only get call quality issues if your VoIP had bandwidth or latency issues. IMHO assured broadband is a bit of a sales con. Often times the problems are with the VoIP providers systems (or whatever carrier they are reselling) or it's an issue with the local POP (in which case it doesn't matter who you get the broadband off, it all terminates at the same BT Exchange).
  25. Presumably this is for guests at the resturant using the wifi? If that is all you need you might want to use a pfSense based router and use the captive portal function it has. You will need to configure it for self registration if you are doing what I think you are. Here is the forum post detailing how: https://forum.pfsense.org/index.php/topic,57260.msg305604.html#msg305604
×
×
  • Create New...