Direct access to ISO images

A couple of months back, I blogged about a driver to provide direct access to virtual floppy disks. Today, I’ve come across a number of sources (most notably Thomas Lee and Steven Bink), that pointed me in the direction of a similar tool for directly mounting ISO CD images in Windows XP – the Microsoft Virtual CD Control Panel. Although unsupported, and not even searchable on the Microsoft download center, this tool is referenced in the MSDN Subscriptions FAQ. There are other tools for manipulating ISO images, but what I like about this is that it simply allows me to mount an ISO as another drive in my system, in the same way that Virtual PC can capture an ISO image and use it as the CD drive.

Send to… Notepad

The UK IT industry is a small world and I frequently attend events where I bump into people that I haven’t seen for a while. A couple of months back I turned up at a course and found myself next to a former colleague from 10 years back. This week I’m attending an SMS training course at QA where the instructor is Bernie Kilshaw, who delivered much of my Microsoft Official Curriculum (MOC) training in my days at ICL, including all of my training for Microsoft Windows NT 5.0 (later renamed Windows 2000).

Yesterday, Bernie reminded me of a Windows tip which I had forgotten about, but which is very useful – the ability to right-click on a file and view it in Notepad (or any other chosen application) using the Send To menu.

To set this up requires the ability to view hidden folders within Windows Explorer. Once that has been turned on (in the folder options), simply create a shortcut to Notepad (or any other chosen application) in the %homedrive%%homepath%\SendTo folder.

Improving the tablet PC experience

Last year I blogged about how Windows XP SP2 improves the tablet PC experience for users. I did manage to get hold of a tablet PC, but unfortunately it came in several USB-connected parts (not like the modern tablets which are effectively dual-purpose notebook/tablet PCs) and so I haven’t really used it. The company that I work for is evaluating the new generation of tablets (e.g. the excellent Toshiba Portégé M200), but I’ll just have to wait my turn!

For those who do have a tablet PC that’s running Windows XP Tablet PC Edition 2005 (i.e. the SP2 version), Microsoft has now released the (dubiously named) Experience Pack for Tablet PC including six new programs that they claim “will help you be more productive and creative” (some of these were previously available as unsupported downloads):

  • Ink Desktop – allows the notes to be taken directly on the desktop for quick and easy access later.
  • Snipping Tool – lets the tablet pen be used to select a portion of a website, document, or other content on the screen. Handwritten comments can then be added and the composite image pasted into another program (such as an e-mail message).
  • Ink Art – allows painting with a tablet pen.
  • Media Transfer (requires Windows Media Player 10) – allows the copying or streaming of media files from another computer (e.g at home) to a tablet PC, to enjoy access to music, home videos or digital photo albums whenever and wherever.
  • Ink Crossword – lets users solve crosswords on their tablet PC using a tablet pen. Twelve puzzles are included and a daily puzzle can be downloaded free of charge with further puzzle packs available for purchase online.
  • Energy Blue Theme Pack – previously released as a separate download, which now appears to be unavailable.

Paul Thurrott’s SuperSite for Windows features a review of the experience pack but it looks to include some useful enhancements for tablet PC users.

Windows Server 2003 SP1 is now available for download

Yesterday, Windows Server 2003 service pack 1 (SP1) was released to manufacturing and the 329Mb service pack is available for download from the Microsoft website.

Like Windows XP service pack 2 (SP2), released last August, SP1 is primarily a security patch, providing new functionality to address known security vulnerabilities and to prepare for future security threats with new technologies including:

  • Security configuration wizard. Customers can more easily reduce attack surface area with the new Security Configuration Wizard. The tool reduces the attack surface by gathering information about specific server roles, then automatically blocking all services and ports not needed to perform those roles.
  • Windows firewall. Originally released with Windows XP SP2, Windows Firewall is now available for the Windows Server System platform and serves as a host (software) firewall around each client and server computer, which may be controlled locally or via group policy.
  • Post-setup security updates (PSSU). As systems are vulnerable during the time between their installation and application of the latest security updates, SP1 blocks all inbound connections to the server after installation until Windows Update has delivered the latest security updates to the new computer.

Other SP1 features that offer a more robust security defence include Internet Information Services (IIS) 6.0 metabase auditing, which allows administrators to identify potential malicious users should the store become corrupted, stronger defaults and privilege reduction on services to establish a minimum security threshold for applications, and the addition of network access quarantine control components.

According to Microsoft:

“Install Microsoft Windows Server 2003 Service Pack 1 (SP1) to help secure your server and to better defend against hackers. Windows Server 2003 SP1 enhances security infrastructure by providing new security tools such as Security Configuration Wizard, which helps secure your server for role-based operations, improves defense-in-depth with Data Execution Protection, and provides a safe and secure first-boot scenario with Post-setup Security Update Wizard. Windows Server 2003 SP1 assists IT professionals in securing their server infrastructure and provides enhanced manageability and control for Windows Server 2003 users.”

For more information about SP1, see the Microsoft Windows Server 2003 TechCenter and, for those who are unconvinced as to why this service pack is necessary, Microsoft has published a top 10 reasons to install Windows Server 2003 SP1.

Spyware re-enforces the need for network segmentation and remediation

There is no doubt that malicious software (malware) is on the increase. We have learnt how to deal with the ever increasing number of viruses, worms and Trojan horses, but spyware is now a major problem too.

Earlier this month, it was widely reported how a joint investigation by law enforcement agencies in Israel and the UK foiled an attempt to use keystroke logging software to gain access codes in order to steal £220 million from the Sumitomo Mitsui bank. This is believed to be the first recorded incident of spyware being used for large scale online theft.

For some time now, IT-savvy users have been checking for spyware with products such as Spybot Search and Destroy or Lavasoft Ad-Aware. Then Microsoft bought the Giant Company and soon afterwards released its Windows AntiSpyware beta product. According to IT Week, the final release will be free for registered Windows users, but corporates will need to pay for the enterprise version of the product. Now Symantec has joined the spyware market with Symantec Client Security v3.0 and Symantec AntiVirus Corporate Edition 10, both incorporating spyware detection and removal capabilities, whilst McAfee Anti-Spyware Enterprise aims to block malware before it reaches the corporate network. Other vendors, such as Websense, have added malware detection to their products but there is still a gaping hole in many organisation’s IT strategy – mobile users returning to the network.

Whilst many corporates will specificly ban consultants and other suppliers from connecting non-managed PCs to their network, some don’t – and in any case that is still only half the issue – what about the user who takes their laptop on the train or to the airport and connects to a wireless hotspot, or even to a less-regulated business partner’s network, then returns to the “safe” corporate LAN with who-knows-what malware on their PC? It may sound paranoid, but when I started to use anti-spyware products a couple of years back I was amazed how much rubbish had infected my work PC and I am just one user on a large network.

According to IT Week, in a survey of 500 European IT Managers commissioned by Websense, 60% said that their company does not have systems in place to guard against internal threats with 35% unable to deal with spyware (and 62% unable to block phishing attacks).

Protecting the network edge is all very well, but the guiding security principle of defence in depth needs to be applied. Networks need to be segregated, with firewalls (or at the very least separate VLANs) restricting traffic between segments but the real answer to the mobile user issue is remediation.

The principle behind remediation is that on returning to the corporate network, users will not be granted full access until their device has been scanned for operating system patches, anti-virus and anti-spyware signatures and any application patches required. Only once all of these have been installed, will the user be granted full access to the network. Of course, as Dave Bailey recently commented in his article will you pass the access test? which appeared in IT Week recently, there will be occasions when patches fail to apply, or when returning users simply have too many updates to be applied and it impacts on their legitimate business operations (but not half as much as a full-blown network attack could impact on their business).

Both Microsoft and Cisco are preparing their remediation technology offerings. Cisco has it’s network admission control (NAC) technology, whilst Microsoft’s approach is network access protection (NAP) (when will they learn to read their acronyms phonetically – first WUS and now NAP). Unfortunately, NAP has been dropped from forthcoming ISA Server 2004 service/feature packs and instead will be held over for Longhorn (although Windows Server 2003 does offer network access quarantine control for users connecting via a VPN).

Shortcut to lock a Windows XP PC

Yesterday, I blogged about a shortcut to hibernate a Windows XP PC (for people who are too lazy to use between 3 and 5 clicks when a double-click will do).

Keni Barwick replied with an alternative to lock the workstation (%windir%\system32\rundll32.exe user32.dll, LockWorkStation) and when I said “What about Win+L – oh yes, forgot, two fingers required ;-)” he fiendishly replied “But it’s great if you want to use no fingers… i.e. the bluetooth auto lock I’m developing :-)” – sounds a bit like a TV B-Gone for PCs to me…

Shortcut to hibernation in Windows XP

I can’t find the reference which started me off with this, but a few weeks ago I came across a tip for creating a shortcut to hibernate a Windows XP PC (for people who find that 5 clicks is just too much). How people find these obscure features I’ll never know (I guess its straightforward for a developer to find all the calls to a DLL?), but here it is anyway – just create a shortcut with a target of %windir%\system32\rundll32.exe PowrProf.dll, SetSuspendState.

Windows XP N

Microsoft and the European Commission have finally agreed on the name for the version of Windows XP with Media Player removed – Windows XP N. How dull? I preferred Windows XP Reduced Media Edition (after all, one of the benefits of “regular” XP is its improved multimedia capabilities) but the EU were never going to accept that! I’m not convinced that there is a market for Windows XP N (but Microsoft has been forced to produce it)… so I guess it doesn’t matter what they call it.

Microsoft’s sandbox

It’s probably well-known by many people, but I just stumbled across Microsoft’s MSN Sandbox. It’s a bit like Google Labs (Google’s “technology playground”), featuring what Microsoft calls “incubation experiments” which may or may not “represent any particular strategy or policy”.

Most of the tools in the MSN Sandbox are well-known – some were even purchased as part of a company acquisition and just haven’t found their way to a release product yet (e.g. the Lookout e-mail search tool). Strangely, the site that referred me to the MSN Sandbox doesn’t have a reciprocal link – that was start.com – Microsoft’s new experimental site for RSS aggregation via the web, which I think I will be giving a spin over the coming weeks and will blog about some more if it turns out to be useful.

Biometric security – good or bad?

There is much talk in the IT press about how we can no longer rely on single factor identification (e.g. user name and password) and about how biometric security could be at least part of the answer; but for an alternative take on just how dangerous an over-reliance on biometric security may be, Alistair Dabbs’ recent will biometric security harm users? article in IT Week provides an interesting, if a touch alarmist, view on how this could all end up as an identity fraud victim’s worst nightmare.