No feature pack for ISA Server 2004

Last week I was at a Microsoft TechNet evening where the speaker indicated that there may not be a feature pack for ISA Server 2004 and instead any new features will be held over for ISA Server 2006 (codenamed Wolverine). This includes network access protection (NAP) and all of the other filters, tools, etc. that did not make it into ISA Server 2004.

The issue of NAP is an interesting one as the Microsoft website indicates that this will be incorporated into Windows Server 2003 release 2.

The perils of running an unsecured FTP server

Last week I got hacked.

I’d opened up my previously stealthed firewall to:

  • Access my home network when I’m at work;
  • Allow one of my friends to post some large files to my FTP server.

The trouble is that I hadn’t been carrying out the best practices that I would advocate for my enterprise clients. Despite last month’s post on securing IIS, I had just opened up the standard ports to a standard IIS server which wasn’t even in a demilitarized zone (DMZ).

I didn’t think I’d be a target for a hacker but within a few days some guys in Italy and Belgium had started abusing my FTP server to dump their files (this article from ZD Net leads me to believe that it’s a common practice). I don’t know what the contents were. I deleted them quickly to be safe and shut down the firewall until I could implement something more secure.

Thankfully, I got off lightly (this time). I checked the logs last night and my new security measures are keeping the intruders out. If you do need to provide an FTP service, you might like to read the windowsecurity.com article with 10 steps to secure an FTP server.

Starting to look at Linux

Tux the Linux penguinA few years ago I had an abortive dabble with the Macintosh world when I bought myself an iMac for digital video work (back in the days when FireWire cards for PCs were expensive and the associated Windows support was patchy). The iMac was great in that I had it working within 10 minutes of unpacking it and it looked good, but I couldn’t adjust to MacOS 9 (I hadn’t used a Mac since Uni’) so it gathered dust for a couple of years before I sold it to one of my Mac-obsessed friends.

Now I’m thinking of having a play with another operating system that I haven’t touched since Uni’ – Linux. But this time the reasons are different. When I started out at ICL in 1992 I worked in a mainframe support centre and saw Unix as the “next big thing”. Over the next couple of years I had some exposure to various Unix operating systems, but my work took me towards PCs running MS-DOS and Windows, connecting to NetWare and LAN Manager servers. I started to learn NetWare but found myself turning towards Microsoft and now I find myself in the situation where I’ve known MS-DOS for 16 years, Windows for 14 years, and worked with LAN Manager (together with its NT-based derivatives) for the last 10 years.

So why the change of focus? Basically I figure that the popularity of Linux in the back office seems to be on the increase, and the delay to (and stripping of functionality from) the next version of Windows (codenamed Longhorn) might just lead to an increase in the number of organisations running a version of Linux on the desktop.

I’m not deserting Microsoft technologies – they’ve helped me build a successful career so far and I hope that continues to be the case for many years to come, but I think Linux may be stepping out of the shadows and will be a significant competitor over the coming years. Even Microsoft are waking up to the fact:

“Linux isn’t going to go away. Our job is to provide a better product.”

[Steve Ballmer, Chief Executive, Microsoft]

I bought myself a copy of the Complete Linux Handbook (the editorial content of which is a little biased against Windows, but no surprises there!) and the first issue I’ve come across with Linux is knowing which version to use. One thing I’ve found is that the major distributions are anything but free! I’ll probably switch my primary home PC to SUSE 9.1 (now owned by Novell) and keep Windows XP on the others (including my work laptop).

On a related note, this week’s IT Week contained an interesting pull-out section entitled “The open debate – Linux or Windows? Expert advice for decision-makers”. The version at the VNU website is not exactly the same, but it looks like a good information source for this hot topic.

Protection against mobile malware

As mobile phones offer more and more computing functionality, anti-virus technologies for smartphones have become an inevitable reality.

Back in June 2004, the Symb/Cabir-A worm was released (as reported by the BBC and others). The target is the Symbian operating system – just as for Windows on a PC, virus-writers and hackers will attack the largest user base first.

Let’s face it – no hacker will get any credit for exploiting a security hole in something obscure – that’s why Microsoft gets so much bad security press and Linux and Macintosh users say “my system is secure” – in reality they are probably no more secure than a well-configured Windows system, just not such a target.

According to an article at the PC World website, Nokia are addressing the issue by teaming up with F-Secure to offer subscription-based anti-virus protection for their Series 60 smartphones, starting with the forthcoming Nokia 6670. Quoting from Nokia:

“F-Secure Mobile Anti-Virus is available for the Nokia 6670 imaging smartphone, providing automatic, transparent real-time protection against harmful content locally on the mobile phone. Updating the phone’s virus database can be done either over an HTTPS connection or, in critical cases, by SMS message.”

Cabir uses bluejacking as a mechanism to spread and as most people are oblivious (no nice IT department managing the security of consumer mobile phones!), the best advice I can give is to set your phone to undiscoverable or hidden. There is also some advice on “mobile malware” at the Nokia website.

You can learn more about Bluejacking at the BluejackQ website. To make matters worse, a colleague of mine found this document, which suggests some people are thinking of using it as a marketing channel.

Get ready to pay for your Hotmail

In a somewhat cynical (IMHO) move, Microsoft is hiding behind security to drop access to its free Hotmail service from Outlook, Outlook Express, and presumably from competing e-mail clients. The service (which uses web based distributed authoring and versioning – WebDAV) will still be available, but users will have to pay for it. To Microsoft’s credit, I believe that AOL and Yahoo! already restrict such access to paid subscribers.

According to the BBC, users who want to use Outlook to pick up their Hotmail messages will have to pay $19.95 (£11) for an annual subscription to Hotmail Plus or the $99.95 (£55) a year for MSN Premium. Users who are already using the technology to download their messages will be able to carry on using the service for free until April.

MSN say they have decided make the changes because spammers were exploiting the system (do they think spammers will be put off by a $19.95 annual charge?). They have already taken other steps to prevent spammers using Hotmail by limiting the number of outgoing messages on free accounts to 100 per day and introduced extra validation requirements when opening a new account.

The withdrawal of free WebDAV access began on September 27th for new users and will become effective for all users worldwide in 2005.

Links

Microsoft Nixes Outlook, Outlook Express Access to Free Hotmail Accounts
Hotmail fees for Outlook access

Windows XP: Reloaded

Contrary to much media confusion in recent months, Windows XP Reloaded is the codename for a marketing campaign that is running throughout the autumn of 2004, aimed at renewing consumer interest in Windows XP, now three years old and not due to be replaced until at least 2006. More information about the XP reloaded program is available on the SuperSite for Windows website.

According to the Windows IT Pro magazine network WinInfo Daily Update, there will be no “Windows XP SE” and the next Windows releases will be:

  • Windows 2000 SP5 (although this will be minor and certainly won’t have the same attention to security detail as XP SP2 did).
  • Windows Server 2003 SP1.
  • Windows Server 2003 release 2 (R2) – the next interim Windows server release.
  • Windows 2006 (codenamed Longhorn) – the next client release.

A more extensive list of upcoming Windows product releases is available on the SuperSite for Windows.

Microsoft TechNet UK events

I used to go along to the Microsoft TechNet UK events but I stopped attending after the content and quality of the presentations dropped. Tonight, I went to my first TechNet event in years and was pleasantly surprised by the new format. Gone are the uncomfortable hotel venues (many of the events are now held at Microsoft’s UK headquarters in Reading); the time slot has switched to weekday evenings (easier for most of us to get out of work to attend, even if it did necessitate some spirited driving down the M40 after I fought my way out of Birmingham this afternoon); in come quality (if a touch arrogant) speakers; and finally a sure fire way to keep 200 techies happy – beer and pizza!

Tonight’s event was presented by Fred Baumhardt, who spoke about ISA Server 2004 network design/troubleshooting and inside application layer firewalling and filtering. I must admit that I was a little disappointed to see him dump the slide deck part way through in favour of just demonstrating the features of ISA Server 2004 Enterprise Edition, but overall, the new TechNet event format seems to be a huge improvement.

Details of future events may be found on the Microsoft UK TechNet website.

Application issues with Windows XP SP2

In an earlier post, I defended Windows XP service pack 2 against the negative publicity it has gained and that opinion still stands – SP2 is a critical update with benefits far outweighing risks in today’s ever more security-conscious environment.

I also stand by my comments that SP2 should be thought of as an operating system upgrade and tested accordingly but one of the key tools that would assist the testing process is still missing. I can see no defence for the time that it is taking to ship an updated application compatibility toolkit (including the Windows application verifier) and whilst the current version (3.0) is available for download, it does not take into account the major operating system changes made in XP SP2.

In the meantime, Microsoft knowledge base article 884130 gives details of programs that are known to experience a loss of functionality when they run on a Windows XP Service Pack 2-based computer.

OWA and Windows XP SP2

If, like me, you use Outlook Web Access (OWA) to access e-mail from a client site, you may experience some issues with the Internet Explorer popup blocker in Windows XP SP2. To be honest, I’ve not found it a major concern as I added all the key servers at my company’s domain name to the trusted sites zone, but if that is not an option (e.g. due to policy restrictions in place), you may have to find a workaround. A few weeks back, the Windows IT Pro magazine network Exchange and Outlook Update ran an article on OWA and XP SP2 and Microsoft knowledge base article 883575 gives further information.

Enhanced search capabilities for Outlook and the Desktop

The fact that Microsoft, Yahoo! and Google are all looking to grow (or retain) their share of the search market and to extend this to the desktop is no secret. Unfortunately for Microsoft the the next Windows release (codenamed Longhorn) is constantly being delayed and as one of its primary aims is to improve the search capabilities available natively within the operating system, this gives Google and others an opportunity to take a hold on the desktop (although Google will need to be smart in order to maintain it’s lead in the Internet search engine market – whether the launch of the rumoured Mozilla-based Google browser will help with this is yet to be seen).

Back in July 2004, Microsoft purchased an ISV called Lookout Software. Lookout is an add-on to Microsoft Outlook that allows users to bypass the search tools provided by Microsoft and sift through e-mail, contacts and other information with keywords. The latest version of Lookout is now available from the Microsoft website and my first impressions are that it is very good, and very fast (is it only me that thinks the Lookout branding looks a bit like Google’s?).

On a related note, Copernic, another successful player in the search market, released their Desktop Search product this month – again, my first impressions using this are good.

Links

Lookout and Microsoft questions and answers
Outlook is a platform
Rumours surround Google browser
Google browser may be reality