Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

sukh

Members
  • Posts

    2,161
  • Joined

  • Last visited

Everything posted by sukh

  1. @Maxim - is this related to this post or another?
  2. Hi Just sent PM. Regards Sukh
  3. Hi That KB seems helpful. Have you tested external access. It's nice to have a SAN certificate for Exchange, helps out. Sukh
  4. sukh

    Home Antivirus

    Hi MSFT System Essentials is good. Been using it for many years have had many friends move from AVG AV 2011. Is stable and works well. Regards Sukh
  5. Hi Also do the same for below. Will identify your root domain. Set objSysInfo = CreateObject("ADSystemInfo") Wscript.Echo "Forest DNS Name: " & objSysInfo.ForestDNSName Thanks Sukh
  6. Hi I'm try trying to understand how Exchange is deployed. For this I needed to know how your AD forest is setup. The purpose of both os these is to see if we can extract the GAL recipients for you to use at live@edu. Can you run the below and see what domains come up. I have tested this myself and is safe to do so. Copy the contents into notepad and save as vbs and execute. It will return all the domains though a dialogue box. Let me now how many you get. Dim objConnection, objRootDSE, objRecordSet Dim strFilter strFilter = "(NETBIOSName=*)" Set objConnection = CreateObject("ADODB.Connection") objConnection.Provider = "ADsDSOObject" objConnection.Open "Active Directory Provider" Set objRootDSE = GetObject("LDAP://RootDSE") Set objRecordSet = objConnection.Execute( _ ";" & _ strFilter & ";" & "dnsroot,ncname;subtree") Set objRootDSE = Nothing While Not objRecordSet.EOF WScript.Echo Join(objRecordSet.Fields("dnsroot").Value) WScript.Echo objRecordSet.Fields("ncname").Value objRecordSet.MoveNext WEnd Thanks Sukh
  7. Hi @Geek of Heathmount- Is this sorted now? Regards Sukh
  8. Hi @Nathan - yes you can use that tool. There are some other tools specifically to take dumps of store.exe and exchange. Also, depends if it's a crash or in a hung state. I use these tools frequently, however even when I work closely with MSFT some of the dumps have to go to MSFT for analysis as you need the internal code to debug. Cheers S
  9. Hi I meant OS as in the core OS? And the SP level too please Thanks Sukh
  10. What OS version are you using?
  11. If the service stop at 6:01 then what?
  12. Hi Firstly, this know issue you have, was this offcially logged with MSFT? I have many customers who are using Exchange 2003 and we are migrating them to Exchange 2007/2010 and have not come across this issue. We can create a several types of dumps for Exchange and try to identify root cause or if you want you can create a script to check the service and start them if they are stopped. Regards Sukh
  13. Hi If you're going to use Hyper-V then I'll help you from start to finish. I've got a good relationship with MSFT. Regards Sukh
  14. can you get the canonicalName, homeMDB and distinguishedName attribute properties for a user in your domain and PM or post? Use ADSI Edit Thanks S
  15. Have you got a specific DNS forward entry for the lea domain in your DNS?
  16. Hi That still doesn't clarify the Exchange deployment. Can you check ADUC and Domain and trusts? Just confirm if you can see any of the domains (yours and lea) Also, check your DNS and see if you have any forwarders set to the LEA domain. Thanks Sukh
  17. Hi FAA "An illegitimate user can run a Ctr-Del-Alt, find and kill the CConnect process through the task manager before CConnect logs the user off. The illegitimate user is logged in." "Once a user is logged in, a regular user can edit a .bat file that launches the following command at startup: kill.exe –f CConnect. Kill.exe is provided in the Resource Kit, along with CConnect! This effectively stops CConnect during the subsequent connections, and lets illegitimate users log in despite CConnect protection" "Once a user is logged in, a regular user can edit a dummy string value pointing to an erroneous address under the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run . As a result, Windows will prompt a message error that freezes the opening session process. This allows enough time for an attacker to do whatever he wants in order to circumvent CConnect protection, for instance to kill CConnect process." "Amazingly enough, the agent can be killed by a user without any privileges" GPO's can prevent this All of those concerns can be addressed technically, it will take some time to test and implement but can be done. However, I have not heard or or used your product, but sounds good. Regards Sukh
  18. Hi Have you created a seperate network policy for the wireless and Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc.... "Even when this condition includes the Domain Computers group none of our laptops are able
  19. Hi On your previous post you mention "Separate root. ie. we are completely independent from them. " and now you mention "The domain is within the LEA forest" Can you please clarify. Thanks Sukh
  20. Hi What I'm trying to identify is the Exchange deployment. So far, it seems like a resource forest deployment. Can you confirm? Thanks Sukh
  21. Hi Have you created a seperate network policy for the wireless and Confirm the network connection method for policy, i.e Ethernet, Wireless Access Point etc.... "Even when this condition includes the Domain Computers group none of our laptops are able to connect. When I remove this condition it works fine again. " In the condition, when you include the Domain Computers group, none of your laptops are able to connect, is that wired or wireless? Thanks Sukh
  22. Hi Can you check the Exchange server that you are connecting to and see the FQDN for under mail properties. I just want to confirm if you have access to the AD. Use the domain portion of the FQDN and try to connect to it using ADUC, when you load ADUC, click on your domain and select, connect to domain, then enter the FQDN of the domain that you retrieved from the mail properties. Thanks Sukh
  23. Hi The option "Allow connections only from computers running Remote Desktop with Network Level Authentication". Is this ticked or not? Thanks Sukh
  24. Hi Can you check to see how you are connected using Outlook. If you got to the mail applet under control panel, and select a a mail profile>properties>Email accounts>Click Next>Click Change>Click More Settings>Click Connection Tab and check the setting "Exchange over the internet", see if you are using this option or not and check the proxy settings. Thanks Sukh
  25. Hi all Is this still an issue? Regards Sukh
×
×
  • Create New...