Jump to content

kingswood

Members
  • Posts

    1,057
  • Joined

  • Last visited

Everything posted by kingswood

  1. That's very true! I think with NAP and other cool things that can happen between Vista and 2008 Server it will make it more compelling for businesses to upgrade. At the moment I think Microsoft have put themselves in an extremely strong position again in the server market. I wish Apple would take a leaf out of their book as far as Server development goes!! Paul
  2. I like Server 2008 a lot. I have been playing around with it for about a year now, and watched it mature nicely. Just this past hour I have made my Server 2008 machine the new DC for my test domain, and successfully transferred all users and settings etc over to it. The forest and adprep went really well (after I forced replication on the 2003 Servers) and subsequent configuration through the new management console made it quite easy to navigate through all the roles and things that I needed to add and configure. For me, then, Server 2008 wins on a number of fronts: 1. New MMC tools make configuring a breeze and consolidate a lot of tools that we had separately in 2003/2000 Server (even though you could make your own, some of the additional tools in Server 2008 on the MMC are better). 2. Terminal Services are superb- after having watch itidiots demonstrate this service on the OS I decided to give it a shot. It really is good! 3. Improved security- NAP- and other improvements (some found in Vista). Things like shrinking a volume on a dynamic disk when you need to without using DISKPART or some other tool is handy. 4. Server Core. Fantastic. Enough said. 5. Speed and stability: I have never had Server 2008 crash on me in a year- even with debug code loaded to the edge of it. It's now even faster since they took that stuff out, and even with Aero on it still runs nicely :-) I could go on. But I think this is something you have to try for a few weeks to get a feel for it. Slap it into a VM or two and have a play. Cons: I agree that the network configuration tools are bad. Really bad. Bring back the ease of management of 2003 Server there I say (for Vista and 2008 Server). The overall interface too needs a bit of work- some of the interface elements seem really archaic when compared with the Vista Aero interface; if you turn on the Aero look it actually seems more streamlined. I guess some will like it and some won't. Having Aero on a server though adds another attack vector that we could do without though. Just some thoughts from the trenches... Paul
  3. Who would like stirring debate? And if you *did* own a Mac, I bet you hide it inside a Dell box when people come around And surely you don't dislike Steve Jobs *more* than Steve Balmer? Please? Take care, Paul
  4. Ahhh- this one? http://www.symantec.com/security_response/writeup.jsp?docid=2006-063013-2645-99&tabid=2 That was patched in the 10.4.7 update (check the advisory). Of course there are others, and being "proof of concept" means they "could" work given the right convergence of events. Leap-A (coming in the form of a Trojan; a file called LatestPics.tgz) had to use Tiger (it relied on Spotlight to work). You had to put the file on your machine yourself- normally delivered over chat or from other sites purporting to give away Leopard pictures Some people were stupid enough to download and double click for sure. Leap-A didn't actually do anything "malicious"- it didn't recursively delete files (for example), and at the worst stopped applications from launching. Andrew Welch stated that it would do nasty things to your machine--but that wasn't seen. I tried it on my own system and it did...nothing. How did people fix the system if their applications were impacted by this trojan? Just install clean versions of the applications. Getting rid of the trojan was as easy as deleting the apphook file (though the name changed later on to something else). At the end of the day what we *all* need is defence in depth. And we all need educating about our respective operating system and its security needs. And then of course we all need to download from trusted sites ;-) My point though, was those hoops. That needs to be remembered right now. OS X is inherently more secure than some other systems, but the weak link in the chain (I think we agree here) is the user. Take care, Paul
  5. I wasn't talking about Windows Who mentioned Windows? I just stretched the analogy to lighten things up. Have a good week mate, Paul
  6. But have less time to enjoy it without buying in lots of little loans to get it to *be* a darned house that you can live in
  7. Hello. The usual round of "Linux kicks " but kicks in. I agree with Tony to some extent- every OS user (no matter the system you use) should be fully aware of security in all its aspects. Admittedly, OS X users can be found complacent when it comes to this topic, simply because there has yet to be a serious infiltration of the operating system. That may come at some point- and perhaps it's inevitable (and will happen in the same way it occurs for Linux What I want to take issue with Tony is your statement about a "proof of concept" trojan. Can I ask which one(s) you have tried, and what you had to do to make the "concept" apply to your machine? I ask because all of the concepts I have seen for OS X have needed the "first you need to do this; then that; then some more here; also this; and that; to get this" mechanism to work, and then only most of the time affect the account executed under. That's the Unix way really. It isn't that Unix is impenetrable (it's not as history teaches us) but it is darned hard to break without the right things being in place to do it. It's like some kind of convergence of the stars Of course, being a good Mac user I take security seriously. As a Vista user too on my MBP I have anti-virus, watch what I download (just like I watch what I eat) and if passing files between systems make sure everything is as clean as I can. That's why I run ClamAV on OS X- so that I can be a good OS citizen in this world of Windows. But it would be good to know what trojans you have been looking at and how you got them working. Just for the sake of the discussion ;-) Paul
  8. I see you have a sense of humour
  9. ..before- using Linux isn't in some strange way "geekier" than using any other OS. And XP runs fantastically on the eeePC. Whatever floats your boat really ;-)
  10. Unfortunately Linux isn't as accessible as some people would tell you. Stick to what you know. Go back to XP...Go back to XP...Go back to XP... ;-)
  11. Log on as a local administrator to one of the clients and clear out (delete) the local MCX_Cache settings. Unbind from the Open Directory server (LDAPv3) and then reboot and login again as admin, this time re-binding to the OD server. See if this refreshes the MCX_Cache and gives you back your managed settings. Also, make sure that your Apple Server has DNS configured correctly. In other words, it needs both a forward and reverse file in your Windows DNS Server, and you need to be able to ping both its IP address and name. Other good suggestions have also been posted. Hopefully something will lead you to the right place! Paul
  12. Hi Shane. The Keychain files themselves are actually encrypted. The problems with your scenario are that: 1. The student *is* the administrator of the laptop 2. Therefore the student has the Keychain Password and can read the passwords stored in their account Keychain. There isn't any way around this that I can think of so long as you aren't managing the machines via Open Directory. Sorry. Now you would be best resetting the wireless encryption key and risking the onslaught, explaining that you can't give out the key securely. There needs to be some "edge" security to your network. Take care, Paul
  13. Go for the 2003 MCSE first- most businesses will be using this for some time. I even know of some places that still run NT4 Server. Microsoft's certification roadmap shows that 2003 will be here as a cert for a long time. In fact I would go a step "further" and prepare first for the MCSA (a quicker and easier introduction to Microsoft certification than the bigger MCSE). Begin with the MCDST then 70-270 and then on to the server side (290 and 291). Good luck with whatever you decide to do! Paul
  14. Well done!! I really enjoyed the articles and will keep them for reference. Any plans for more? Paul
  15. That's interesting! Thanks for the link. Could be a great step forward.. Paul
  16. Well, here's a link to a site I have used for IPFW stuff on server for a long time: http://www.macdevcenter.com/pub/a/mac/2005/03/15/firewall.html The command to clean it all out that I have used is: sudo /sbin/ipfw -f flush But that was on an earlier version than 10.4. The command you should use is probably: sudo ipfw flush Let me know if/when you fix this. It would be good to file somewhere. Good luck! Paul
  17. Hi. There is quite a good (detailed) run-down here: http://www.tech-archive.net/Archive/Win2000/microsoft.public.win2000.active_directory/2004-12/1295.html Basically though what you need to do is: 1. Boot to AD Restore Mode 2. Open a command prompt and run an integrity check using the Esentutl tool like so: esentutl /g "\ntds.dit"/!10240 /8 /v /x /o 3. Repair the DB by typing: esentutl /p "\ntds.dit" /!10240 /8 /v /x /o The /p switch there removes the bad bits from the database- and doesn't repair them. That being the case, make sure you have read all the articles I linked to first (especially the MS KB below) and if you have another DC in the domain do not do this. Just demote the server/reinstall the server and restore the rest from backup tape etc. 4. Afterwards delete the NTDS log files from the NTDS folder 5. Restart your server and see if you can log in etc. http://support.microsoft.com/default.aspx?scid=kb;en-us;816120&Product=winsv If you have another DC in the domain- DO NOT DO THIS! Perhaps someone else will have a better way? Paul
  18. I'm just wondering whether you have checked that the RPC service is running? I ask this because the SAM relies on RPC to run and if RPC is disabled or for some reason not starting, SAM will also fail. Also, is the LSASS.EXE process showing up at all in Task Manager? A lot of the troubleshooting you will need to do will depend on the type of errors you are seeing. This article may help to start with: http://support.microsoft.com/kb/258062 And if normal login is not working (because the SAM is corrupt or missing) you need to restore the SAM first from a known good backup. http://support.microsoft.com/kb/326216 If this isn't your only DC then stop replication now. I would run a metadata cleanup on the DC too, and then if all else fails run a repair on NTDS.DIT- but that's a last resort. Look to the best System State backup you have and do that restore- if system state restore fails (as you seem to be saying) then you may have no other option than to try all of the above and if it still fails.....incidentally, if the System State backup is more than 180 days old (for Server 2003 SP1) or 60 days (for all other releases up to SP1) then it won't be new enough to restore from. This is because of the "tombstone" lifetime attribute. Hope that helps even a little. Good luck! Paul
  19. I have heard this too- the "wear levelling system" it's called and it really isn't as big a deal as some make it out to be. Flash based drives have millions of writes available, and even the Xandros install on the eeePC uses SATA based wear levelling- not as good for solid state as you would want to believe. At the end of the day if you like Linux and can use it then more power to you. I have tried it since before kernel 1 and haven't had very good experiences with it at all. *For me* XP would be better on the thing, and I have very good sources that tell me it runs just as well as Xandros. People shouldn't be brow beaten or have to apologise because they make a choice for one OS or another. XP is good for all that I need it for (studying another MCP and things like that). If it wears out my drive then it doesn't matter. My mate had dozens to give away and I got it free. He also has XP on his and it runs extremely well- he takes it on the road with him and uses it for office stuff (using Open Office 2). It's all cool and it is all relative. Enjoy your eeePC with Linux on it. Even though I think it sucks
  20. What can you do for work with XP Pro on it than Linux? My main machine is, and soon my laptop will be, a Mac and I find it more useful than a windows machine, by far. Just having access to a proper terminal is worth it. That didn't take long Nothing. I am a Mac user too- have been for a long time. I use the terminal all the time, but I don't think at the level *I* use it at that it is better/more efficient/more geeky than using XP. I am installing XP onto the little thing because I can 8O I wouldn't buy a machine with Linux on and I wouldn't install other versions of Linux onto the system simply because I don't like Linux. Sorry. But if you do like Linux and can use it well the eeePC is a fantastic computer and one that you could use no doubt all day for everything you need. Plug it into a 32" flat screen TV and see it shine- it's fast, stable, and comes with a solid application base. It's just not me. Paul
  21. kingswood

    Server

    It would do it, but I'm not sure how well. It depends on lots of things. And Steve is right- running an Exchange Server on a DC is not a very good idea at all. Much better to install it on a member server and then run the other stuff from a separate server. Paul
  22. I got one several weeks ago from a very good friend (his company got quite a few and he passed one on to me). They are really quite cool. I'm not keeping Linux on mine though- I will be upgrading the RAM and storage and then installing XP Pro. More handy for work that way. Paul
  23. And if they knew that then they need to be modded down and given a heavy telling off for it. And yes- you could equally take that as far as you wanted (probably further). This thread has become insane!
  24. Go through this tutorial here and see if you missed a couple of steps: http://hivelogic.com/narrative/articles/installing-mysql-on-mac-os-x Good luck with that one Paul
  25. Yep. MAMP is the way to go for this. If you have compiled MySQL and PHP from source though it can obviously offer some things that a packaged version can't (and you learn some stuff too). Did you enter the path to your MySQL before the password command? /usr/local/mysql/bin/mysqladmin Or you could add this path to your PATH environment variable /usr/local/mysql/bin Log in to MySQL as root: mysql -u root -p Password: and that gets you to the correct prompt. So, in conclusion, unless you have entered the path to the mysql/bin directory in your PATH environment variable, you need to type that in before trying to set the password using the command you tried. HTH Paul
×
×
  • Create New...