Howdy,
It is the second Tuesday of the month so a new series of patches have been released. I'll guess I'll be testing this one tomorrow:
http://www.microsoft.com/technet/security/bulletin/ms08-052.mspx
Since the rating is critical I'll guess we'll see some nice exploits for it.
Tuesday, September 9, 2008
An interesting phone call
Yesterday was an interesting day I had a teleconference with two gentlemen who gave me a rather interesting insight in the inner workings of a big ISP who is hosting the website of one of our customers that I'll be auditing in the near future.
These two man wanted to talk to me about what my colleague and I will be testing for our customer. Since my colleague is on holiday I answered what I'll be doing on the servers and for the network part I answered that I was not the person to speak to.
They have apparently an issue with the fact that we would login as administrator on to the network appliances to check the configuration. Since it is not my call to make we agreed that they would send us some print outs and it is up to my colleague to decide if it is possible to do audit work on this. I personally think it is not acceptable since we are an independent party and have to obtain the information by our selves.
There is a second problem with this. The ISP is prepared to send me, a stranger they have never met, information about their firewalls and such by e-mail. Yes, this is something that will be in the end report to our customer, it is my due dilligence.
Just to see how far they go in the management of our customers environment I asked if they kept logs for each time they tested the clustered loadbalancers. Apparently they only tested their cluster once before it was put into production. They monitor it and have a spare ready in case one goes down. I asked them if they didn't test it on regular basis to see if it functions correctly but this was not necessary according to them since it is monitored in case it goes down.
It is for me the same problem as the guy who makes his back ups but never does a test on regular basis to see if they are any good.
These two man wanted to talk to me about what my colleague and I will be testing for our customer. Since my colleague is on holiday I answered what I'll be doing on the servers and for the network part I answered that I was not the person to speak to.
They have apparently an issue with the fact that we would login as administrator on to the network appliances to check the configuration. Since it is not my call to make we agreed that they would send us some print outs and it is up to my colleague to decide if it is possible to do audit work on this. I personally think it is not acceptable since we are an independent party and have to obtain the information by our selves.
There is a second problem with this. The ISP is prepared to send me, a stranger they have never met, information about their firewalls and such by e-mail. Yes, this is something that will be in the end report to our customer, it is my due dilligence.
Just to see how far they go in the management of our customers environment I asked if they kept logs for each time they tested the clustered loadbalancers. Apparently they only tested their cluster once before it was put into production. They monitor it and have a spare ready in case one goes down. I asked them if they didn't test it on regular basis to see if it functions correctly but this was not necessary according to them since it is monitored in case it goes down.
It is for me the same problem as the guy who makes his back ups but never does a test on regular basis to see if they are any good.
Tuesday, August 26, 2008
It is a small world (no not the Disney kind)
Dolmen is a large company and today christophe vandeplas because we will be working on a project together. Check out his blog, it has some fine reading material on it :).
Interesting case - part 2
In my previous post I told you about the medical institute having problems. Yesterday their server has crashed again. One could wonder why some of us consider this a good thing, well a problem that repeats it self has a better chance to be solved than one that occurs only once.
I was out of office so my colleague got the dump file and the output was exactly the same. Then we compared the cause and the configuration (sorry to stay vague but I think it is bad practice to name customers and their configuration on my blog) and it seems that Windows has only 2 GB and everything else was dedicated to SQL.
It is fine to dedicate a whole lot of memory to your database server process but the OS has got to breath too.
One of the other problems is that they have only one server and every database in the institute is on it and they expect it to be high available. I proposed that they contacted their sales contact and he would come by with a specialized sales since databases that are high available and the rest is strictly useless.
I was out of office so my colleague got the dump file and the output was exactly the same. Then we compared the cause and the configuration (sorry to stay vague but I think it is bad practice to name customers and their configuration on my blog) and it seems that Windows has only 2 GB and everything else was dedicated to SQL.
It is fine to dedicate a whole lot of memory to your database server process but the OS has got to breath too.
One of the other problems is that they have only one server and every database in the institute is on it and they expect it to be high available. I proposed that they contacted their sales contact and he would come by with a specialized sales since databases that are high available and the rest is strictly useless.
Tuesday, August 19, 2008
Interesting case
Today I had to be in a medical instituate where there has been a server crash a week ago and now I had to look at the server.
The SQL server has produced a minidump so a post about the SQL minidump will be in the near future on this blog :).
There are a huge amount of errors, i'll have to analyse them and will write about something about them as well.
The third topic i'll have to do some research on is windows 2003 (64-bit) paging, since their crash there is a huge amount of paging.
The SQL server has produced a minidump so a post about the SQL minidump will be in the near future on this blog :).
There are a huge amount of errors, i'll have to analyse them and will write about something about them as well.
The third topic i'll have to do some research on is windows 2003 (64-bit) paging, since their crash there is a huge amount of paging.
Thursday, August 7, 2008
A night at an ISP
Recently I've spent the night at one of Belgium's bigger Internet service providers. The ISP had had some trouble with their databases last December and I had to implement database mirroring.
In the beginning of July I had created a test database for their IT people so they could play with it. And now, the time had come to implement it for all their databases as a test to adapt their programming and make it fail-over aware.
There were some specifics as the mirror had to be synchronous and encrypted and it had to be the same port on each server.
So here are my findings:
The mirror wizard doesn't use the full qualified network name for the principal server so at the end it proposes to start mirroring but it fails because you have to manually adapt the principal server.
The only thing that was a real problem was 1 database. For some reason it failed time after time and the error message was that it was unable to connect to the witness or mirror server.
The cause was one app that writes constantly in the database and since it took about 15 minutes to move the backup and restore it with no recovery on the witness it was not possible to create the mirror.
To work around this I made the full backup, restored it with no recovery and then I made the transactional backup. I had the permission to take the database offline once I made the transaction log backup had finished and restored it on the mirror . Once I had put the database back online the mirroring was no problem at all.
We ran some tests and everything went fine. The only thing my customer still has to do is create maintenance plans on the mirror (for some weird reason you can't mirror those) and alter his apps.
At the break of rush hour we all went home for some sleep :).
An update: 10 days later and something went wrong, for some reason one database went suspect on the principal.
In the beginning of July I had created a test database for their IT people so they could play with it. And now, the time had come to implement it for all their databases as a test to adapt their programming and make it fail-over aware.
There were some specifics as the mirror had to be synchronous and encrypted and it had to be the same port on each server.
So here are my findings:
- Use 2005 SP2, it figures but I prefer to mention it ;)
- You need the database to be in full recovery mode
- Watch out for the auto close option, it runs the fun
- You need a full backup and a transaction log backup
The mirror wizard doesn't use the full qualified network name for the principal server so at the end it proposes to start mirroring but it fails because you have to manually adapt the principal server.
The only thing that was a real problem was 1 database. For some reason it failed time after time and the error message was that it was unable to connect to the witness or mirror server.
The cause was one app that writes constantly in the database and since it took about 15 minutes to move the backup and restore it with no recovery on the witness it was not possible to create the mirror.
To work around this I made the full backup, restored it with no recovery and then I made the transactional backup. I had the permission to take the database offline once I made the transaction log backup had finished and restored it on the mirror . Once I had put the database back online the mirroring was no problem at all.
We ran some tests and everything went fine. The only thing my customer still has to do is create maintenance plans on the mirror (for some weird reason you can't mirror those) and alter his apps.
At the break of rush hour we all went home for some sleep :).
An update: 10 days later and something went wrong, for some reason one database went suspect on the principal.
Sunday, August 3, 2008
Disable 8.3 short-name generation
One of the things that is still a remainder of the past is the 8.3 short-name. You know it can be a pain to access somethings in program files. Well you can have solve this by editing the registry.
Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem
add the dword value NtfsDisable8dot3NameCreation and set the value to 1.
Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem
add the dword value NtfsDisable8dot3NameCreation and set the value to 1.
Subscribe to:
Posts (Atom)