Jump to content

kingswood

Members
  • Posts

    1,057
  • Joined

  • Last visited

Everything posted by kingswood

  1. Excellent question, and one that I think we need the answer to before we proclaim anything damned. To gain root access on an OS X system takes a *lot* more than visiting a web site as a user and clicking a link. You have to *enable* root on OS X. Of course I know Apple users who do indeed enable the root account and leave it logged in! I agree though- if it were a root-kit access to the system then both Microsoft and Apple need to get it fixed. And quickly. Reminds me of the VMSPLICE exploit found in kernel 2.6 at the start of the year in Linux- a root shell could be started through exploit code because of a bug in the kernel. It was patched *very* quickly- but it was there for all to see :-) Paul
  2. No problem with what you have said there for the most part, except I think it is now coming out that it was in fact part of the Java WebKit in Safari that was used to allow the vulnerability to take hold. If that is the case, then this is in fact an Open Source effort. In any case that doesn't mean anything (true or not). Apple ship Safari with OS X and it is Apple's Safari *shipped with OS X* that has the issue. It needs to be patched (might be in 10.5.3 from what we are hearing from other rumours). I am sure Microsoft will *help* Adobe work on the other exploit revealed during the competition Paul
  3. That would be cool to watch! I haven't been to Infosec so haven't seen the past sessions that have showed this. Are they available online or is there any information on them anywhere (just rushing off to Google anyway). Paul
  4. No operating system is devoid of exploitative code- not even Linux with all it's great stability and power (hence so many patches). But patching- and plugging security holes- is a Good Thing ™. What this event showed is that Apple and Microsoft have a long way to go before they can hold up a crown- and it shows only that *on this occasion* Linux stayed safe. I *like* that OS X was "hacked" in this way. Safari isn't as bad as MS supporters believe, and yet still has a long way to go before it can be considered as seasoned and safe as it should be. With exploits like this being revealed Apple will have to react before it becomes common knowledge; likewise Microsoft have every right to now send a few fiery darts Adobe's direction for releasing hole-ridden code (if it is indeed "hole ridden" and not just in need of a patch). When all is said and done we should all be aware of the need for security- no matter the OS. What this competition does *not* prove- and you would have to be silly to think it does- is that any one OS came out the secure "victor". On the day Linux stood against the hacks attempted against the system. On another day this may not be the case. Paul
  5. I love Server 2008! I am running the final Enterprise 64-bit version using VMWare on my MBP and it is *very* nice. I also did a full migration of two Server 2003 VMs with around a dozen users, home areas, System Center, WSUS etc over to a single Server 2003 VM. Absolutely no problems at all! Everything (in an Apple sense) "just worked". I don't think you will have many problems with this edition of Server at all. In fact I am looking at it in comparison with Apple's Leopard Server and it leaves OS X Server behind in another galaxy! But that's for another discussion... Paul
  6. I wouldn't see why ZDNet wouldn't carry more OS X articles...
  7. Edited: a 2006 article is used to try and prove something. What, I don't know! I mean- imagine a hardware vendor having hardware issues?
  8. *yawn*
  9. I'm not entirely sure what you are asking here, but if I am picking you up correctly then you could try using the Apple Migration Assistant. It can be found in Applications > Utilities. HTH Paul
  10. I thought wireless certificates were imported by OS X into the Keychain? If you open Keychain Access on any of your iMacs and take a look at the left hand side there should be a "Certificates" section that you can click on that will subsequently reveal all the imported certificates on the Mac. There are also root certificates and a "My Certificates" section too. All-in it's Keychain that I think you need for this. If you need to manually add a certificate- again it's through this tool. Simply use the Keychain Access > Certificate Assistant and all will be revealed... Hope that helps a little, Paul
  11. I'm not sure I have picked you up correctly- but here goes: When you choose to manage a Simple Finder for groups or users in Workgroup Manager, you should also be presented with the option to allow mounting of Hard Disks, Removable Media, and Network Connections, on the user's desktop. If you shift views in Workgroup Manager to the "Commands" view you will also notice that you have the option to restrict the "Go" menu from the Finder. In other words you can state that users can/cannot use "Connect to Server" etc. The thing is, when you choose "Simple Finder" as a managed preference, Workgroup Manager already chooses by default to allow mounting of disks etc. Make sure that you are not managing preferences for Media Access and restricting access to users there. If users haven't got the setting there to allow mounting of drives etc., then simply select to Always Manage the preference and choose which devices users should be allowed to have access to. Rather than offer a Simple Finder have you thought about actually just locking down the Macs so that users can't access applications they shouldn't and also restricting network views etc using Computer Lists? That way drives are always mounted and you won't have problems with Simple Finder view (which you inevitably will). Sorry if that doesn't help Paul
  12. Ah. That one I simply give the users access to the option in System Preferences- but that's not ideal. If you click the link below you will find a way to do this through Preference Manifests- well, a way to get around the fact that it still doesn't work in Leopard Server like it should http://managingosx.wordpress.com/2008/02/20/mcx-vs-the-screensaver-and-leopard/ Hope it helps some! Paul
  13. Hi, The first thing to do is to actually get the speed of the G5 processor (model) of the iMac they will be upgrading. You can get this by simply opening "About this Mac" from the Apple menu. Once you have done that, follow this link: http://www.crucial.com/uk/ On that page there are three options to choose: 1. Manufacturer 2. Product Line (iMac in this case) 3. Model (G5 1.6-2.1GHz and with iSight) Make your choices and from there Crucial will tell you which RAM is compatible with your system and how much of it you can have. As well as the price Hope that helps, Paul
  14. kingswood

    10.5 AD Binding

    Really sorry you are having problems with this. Have you got the constitution to try one more thing? If you have, try this: 1. Reinstall one of your iMacs and DON'T install the 10.5.2 update. Only update to 10.5.1 if you can. 2. Add the computer name you will be using for the iMac into ADUC on your Windows Server before binding. 3. In Directory Utility you get the option of "Prefer this Domain Controller"- use that option and put your Windows Server IP address in there. Don't let Leopard decide which DC to choose (this will help if you have a multiple DC site). 4. Uncheck "Allow Authentication for any Domain Controller" 5. In the "Directory Servers" screen add your domain controllers 6. Bind and test Do a "dsconfigad -show" if it doesn't work and post the results back here if you have the time. Remember- don't update to the 10.5.2 release yet. If it binds you might want to check that after the update it still works. I really think that this has something to do with particular domain setups, but haven't seen much of a pattern yet because most people haven't the time or inclination to actually post chunk loads of configuration settings etc. Another thing to check is that if you enter an A and PTR record for your Mac before binding whether it then works. This would indicate something DNS related on your domain that Tiger ignored but that Leopard is more fussy about. Also remember that with Leopard Open Directory is now integrated into the client as well as server product- NETINFO has been deprecated. They worked differently at local level and when binding to AD! Hope that helps, Paul
  15. kingswood

    10.5 AD Binding

    Hi, This sounds weird to me. I would try and trash the bind settings on your iMac by navigating to /Library/Preferences and binning the DirectoryServices folder found there. You should also trash the edu.mit.kerberos file. To *completely* remove bind settings, use the following commands as local administrator on the iMac: cd /Library/Preferences rm -R -i DirectoryService You should be asked if you want to examine the files- type in "yes" (without the quotes)- it will do this for every file (just type yes in each time). The follow this up with: sudo shutdown -h now The Mac will shut itself down and then you should obviously just start it up the usual way. Now try and rebind, making sure that: (a) the time on the system points to your internal NTP server or an external server that your AD domain server uses so that they are within the kerberos acceptable skew frame (b) that you have both a primary DNS IP in Network Preferences for your AD DNS server and a search domain suffix (yourdomain.com) in the opposite pane. When you get to Directory Utility make sure that you choose "Active Directory" from the drop down box after clicking the plus" sign to add a directory services server, and then use the short name of your AD domain controller in the "Server Name or IP Address" field. At school I use the server name, but when testing Leopard Server and AD at home it preferred the IP address. Horses for courses! Check too that in "Services" when using the "Advanced" menu option in Directory Utility that you have checked the "Active Directory" field. Double click this entry and a sheet will pop out that will allow you to "bind" to the AD domain. Use your forest name and give the iMac a computer ID. I have had no problems (ever) with using the same name as the OS X name, but again you might need to make them different. Simply click "bind" and enter the username and password of a domain administrator in the sheet that appears. You have probably tried all of this before, but there may be a step that you have missed. If all of that fails let me know and we can perhaps try other things that might help. All the best! Paul
  16. kingswood

    10.5 AD Binding

    I have seen this on a couple of our new iMacs. Basically (and I know this is often painful) it works if I do a clean install of the OS before binding. It's worth trying this on one of your systems to see if it makes a difference. Other than that, Leopard binding to our AD has been painless. Have you also checked that the client has your primary DNS server set in Network? This can often cause a small gotcha when trying to bind. Hope something there helps- good luck! Paul
  17. Actually there are known bugs that Leopard still has which means accessing a Windows Server 2003 ISA Server is more difficult than it should be. Try Authoxy from this site and see if it helps: http://www.hrsoftworks.net/Products.html Hope that helps some, Paul
  18. Try the idea on this thread: http://discussions.apple.com/thread.jspa?threadID=1241454&tstart=0 Hope that helps, Paul
  19. Apple's .Mac service isn't too shabby if you ask me. Yes, there are other online (and free- yadayada) services. The price? http://store.apple.com/Apple/WebObjects/ukstore.woa/wa/RSLID?mco=366D022E&fnode=home/shop_mac/software/apple&nplm=MA927 £69. You can buy more storage and addresses. Advantages(?) to .Mac are Sync, Backup, iWeb integration is nice, Photo gallery support and "Back to my Mac" service (which has worked extremely well for me but could be done with Logmein). Having said all that, I love it. It's the only professional service I have found out there amongst lots of free offerings and is the only account I use along with my GMX account for serious email. I have been a .Mac user for around five years Oh- and no PHP or MySQL on .Mac. It's not a "Web Hosting" site and doesn't claim to be one. If you *really* need those things then look elsewhere. I said *really* because a lot of people think they need those things, sign up for webspace that lets you do it, and then don't *really* know how to do it or what to do with it Now I wait patiently for the backlash Paul
  20. Sounds good Tony. I disagree about the need to sit on the fence- I think recent reports about the negative effects of BSF and the results of that initiative on this very forum can be seen by all. I really can't find it in me to see what good "educational" difference BSF makes to schools that other investments wouldn't- without the need to interfere with in-house ICT support structures, staffing, or individual flexibility and innovation within the school. But that's just my opinion. Other than that, like I said, sounds good! Paul
  21. I installed SP1 from the technet download last night. Took less than 30 minutes and went extremely well. Not quite sure what it has done- some subjectivism tells me that it has made the system faster...not sure though. Not worried about that though. Have an HND exam to take today (hopefully), so more nervous about that than anything Vista throws at me
  22. Have you been watching some of my presentations? That just wasn't fair! Back to the drawing board then....
  23. I'm in Corby and it most certainly did wake me up! Fun in a weird way
  24. I think your Network Manager is probably right! I have had the same issues here, with teachers stating that they "must" have right-click context menus not only in IE but in Windows Explorer. Although it is a great invention, it *can* give the willing student things that they perhaps shouldn't have. The compromise for me is to enable it for the lesson that needs it and then turn it back off. Still not nice though. Sorry. That probably wasn't the answer you wanted!
×
×
  • Create New...