Monday, July 28, 2008
Configure IIS 6.0 operating modes
Windows Server 2003 introduced some significant changes from Windows 2000 Server, and Internet Information Services (IIS) 6.0 is a good example. Not only is IIS' architecture considerably different in IIS 6.0, but the management interface has also changed. For example, IIS 6.0 provides two operating modes: IIS 5.0 Isolation Mode and IIS 6.0 Worker Process Isolation Mode.
In IIS 5.0 Isolation Mode, all in-process applications run inside Inetinfo.exe. Out-of-process applications run in separate instances of DLLHost.exe. Inetinfo.exe handles HTTP request queuing, IIS services (FTP, SMTP, NNTP, etc.), and worker processes. Svchost.exe runs the WWW service.
The primary purpose for IIS 5.0 Isolation Mode is to mimic the behavior of IIS 5.0 and earlier versions, and it provides compatibility for Web applications designed specifically for IIS 5.0 or earlier.
IIS 6.0 Worker Process Isolation Mode, also called native mode, provides better performance, reliability, and fault tolerance. In native mode, the kernel-mode driver http.sys handles all HTTP request processing and queuing. Inetinfo.exe handles IIS administration and configuration as well as the IIS services, including SMTP, NNTP, and FTP. Svchost.exe handles the WWW service, and multiple instances of W3wp.exe handle worker processes.
Separating worker processes in this way isolates those worker processes from the core IIS services for better reliability overall and better recoverability for individual processes. This process isolation, combined with the fact that the core IIS services prevent the loading of third-party code, means an errant Web application will have a tough time crashing the WWW service and bringing down the server.
In a clean installation of IIS 6.0, native mode is the default mode. A system upgraded from a previous IIS 6.0 installation assumes the mode of the previous installation. Systems upgraded from IIS 5.0 or IIS 4.0 run in IIS 5.0 Isolation Mode to provide compatibility for the existing Web applications on the server.
One aspect of managing an IIS 6.0 server is setting the mode in which the server runs. For example, you might be installing a Web application that won't run in native mode and need to switch the server to IIS 5.0 Isolation Mode. Or you may have upgraded an existing server and now want to switch it from IIS 5.0 Isolation Mode to native mode. Note that the server as a whole runs in a given mode; you can't run specific sites on the server in different modes.
To configure IIS 6.0's operation mode, open the Internet Information Services Manager from the Administrative Tools folder, or run %systemroot%\system32\inetsrv\iis.msc. When the IIS console opens, right-click the Web Sites branch in the left pane, choose Properties, and select the Service tab. Selecting the Run WWW Service In IIS 5.0 Isolation Mode option configures the server to run in IIS 5.0 Isolation Mode. Deselect this option if you want to run the server in native mode.
Thursday, July 03, 2008
Listen to these original songs of most popular Hindi Tracks
Dhoom song DHoom Macchale Inspired by Jesse Cook's 'Mario takes a walk'
Original: http://youtube.com/watch?v=e3iTfEF52kw
INSPIRED: http://youtube.com/watch?v=CvhPvxmD3mI
Race Song Pehli Nazar Inspired by Chinese Kim Hyung Song Sarang Hae Yo
Original: http://youtube.com/watch?v=8KoS3weBxAg
INSPIRED: http://youtube.com/watch?v=ffp5h_FGEJY
Race Song Zara Zara Touch Me Inspired by Lee-Hom Wang's 'Zhu Lin Shen Chu'
Original: http://youtube.com/watch?v=wdTrPI3mumU
INSPIRED:
http://youtube.com/watch?v=kLU76W2qbPs&feature=related
Jab we met's 'Yeh ishq kya' Inspired by Anggun's Être Une Femme
Original: http://youtube.com/watch?v=T4poevqspsI
INSPIRED:
http://youtube.com/watch?v=TQyU6EqWh_o&feature=related
Jab We Met Aao milo chale Inspired Indonesian band, Peterpan's 'Di Belakangku'
Original: http://youtube.com/watch?v=EGXniVSfSZE
INSPIRED:
http://youtube.com/watch?v=7jpUic8hWD8&feature=related
Woh Lamhe 'Kya mujhe pyaar hai'Inspired by Indonesian Band 'Tak bisakah'
Original: http://youtube.com/watch?v=EZTqg1MgkTY
INSPIRED:
http://youtube.com/watch?v=2EoblYYvLsE&feature=related
Bhool Bulaiya Halla Hafiz Inspired by Amr Diab's Awedony
Original: http://youtube.com/watch?v=8Xi_xOmmsRY
INSPIRED:
http://youtube.com/watch?v=UtVerSkccgo&feature=related
Dhol Dil Liya Inspired by Dania Khatib's 1999 hit, 'Leiley'
Original: http://www.itwofs.com/audio/Leiley-DaniaElKhateeb.rm
INSPIRED: http://youtube.com/watch?v=xBkp57nRE5A
Life in a Metro song Baatein kuch ankahee Inspired by Korean song, 'Ah Reum Dah Oon Sa Ram' by Seo Yu Seok!
Original: http://youtube.com/watch?v=KCTGuhPcC4Y
INSPIRED:
http://youtube.com/watch?v=Ura4grIiF90&feature=related
Bhool Bhulaiyya Hare ram hare ram Inspired by Bill Hailey's Oriental Rock
Original: http://www.itwofs.com/audio/OrientalRock-BillHaleyComets.rm
INSPIRED: http://youtube.com/watch?v=4lu3EorpiQ4
Life in a Metro song O Meri jaan Inspired by Queensryche's Silent Lucidity and Amr Diab's Ba'ed el Layali
Original 1: http://youtube.com/watch?v=-2ohGF0K4AI
Original 2: http://youtube.com/watch?v=P2y_Vbev5zs
INSPIRED: http://youtube.com/watch?v=3g2ICCQNQ-w
Pyar ke side effects song Jaane kya Inspired by 'Mahi' by Hadiqa Kiyani
Original: http://youtube.com/watch?v=mokJJsRfP6Q
INSPIRED: http://www.youtube.com/watch?v=V5fEHdP-5Dc
Woh Lamhe song Chal Chale Inspired by a 1965 track called 'A World of our own' by the band, The Seekers
Original: http://www.youtube.com/watch?v=S9oaXzrsV3Q
INSPIRED: http://www.youtube.com/watch?v=KeJ2tqPjnps
Dhoom Song DHOOM AGAIN Inspired by a song called 'Dudu' from Tarkan
Portions edited appropriately
Original:http://www.itwofs.com/audio/Dudu_ver2-Tarkan.rm
INSPIRED: http://www.itwofs.com/audio/DhoomAgain-Dhoom2.rm
Speed song Tikki Tikki Inspired by Turkish pop superstar Tarkan's 2003 hit, 'Dudu'
Original: http://youtube.com/watch?v=KoJ34jPX3WM
INSPIRED: http://www.itwofs.com/audio/TikhiTikhi-Speed.rm
Agnipankh song Janmabhoomi & Zindagi hai Inspired by Abrar-ul-haq's 'December
Original: http://www.itwofs.com/audio/December-AbrarUlHaq.rm
INSPIRED 1: http://www.itwofs.com/audio/Janmabhoomi-Agnipankh.rm
INSPIRED 2: http://www.itwofs.com/audio/ZindagiHaiTo-Agnipankh.rm
Bhagam Bhag songs Signal & Afreen Inspired by Trinidadian Soca hit, 'Signal for Lara' by Superblue & Cheb Mami's 2001 track, 'Viens Habibi'
Original 1: http://www.itwofs.com/audio/SignalForLara-SuperBlue.rm
Original 2: http://www.itwofs.com/audio/ViensHabibi-ChebMami.rm
INSPIRED 1: http://youtube.com/watch?v=G31riHQjvDI
INSPIRED 2: http://youtube.com/watch?v=b-65fajmsC8
Life in a Metro In dino Inspired by Waqar Ali's 'Mera naam hai mohobbat'
Original: http://youtube.com/watch?v=89wB3og_yXQ
INSPIRED: http://youtube.com/watch?v=aQ52IJjbNg4
Raqueeb songs 'Jaane kaise' Inspired by Amr Diab's 2003 track, 'Allem albi' and song 'Channa ve channa' Inspired by Pashto singer Rahim Shah.
Original 1:
http://youtube.com/watch?v=NqoXaLHFTik&feature=related
Original 2: http://youtube.com/watch?v=JplIDBi6wZE
Inspired 1: http://youtube.com/watch?v=rjwMsYnEJ58
Inspired2:
http://youtube.com/watch?v=33EJLt-NMDQ&feature=related
Kya Love Story Hai Song 'Miss you everyday' Lift of Lebanese singer Karina's 2006 chartbuster 'Alatoul'
'Jab se tum mile ho' is a lift from Pakistani singer Hadiqa Kiyani's 1996 number (album: Raaz), 'Jab se tum milay ho'!
Original 1: http://youtube.com/watch?v=snIA9iR0b-0
Original 2: http://www.itwofs.com/audio/JabSeTumMilay-Hadiqa.rm
INSPIRED: http://youtube.com/watch?v=FJ_w0HDh0N0
Kya Love Story Hain song 'Deewana teri aankhon ka' Inspired by Black Eyed Peas' 'Bebot'
Original: http://youtube.com/watch?v=gQAGh3JViyI
INSPIRED: http://youtube.com/watch?v=Nr0ASdmHF40
Kya Love Story Hai song Gum sum hai dil mera Inspired by Thai song, 'Oh la nor...my love' by Bird Thungchai.
Original: http://youtube.com/watch?v=tJjrJIh8c8k
INSPIRED: http://www.itwofs.com/audio/GumSumHaiDil-KLSH.rm
Ankahee song Aa paas aa Inspired by Ottmar Liebert's 'Starry nite (March of Kings)
Original: http://www.itwofs.com/audio/StarryNite-OttmarLiebert.rm
INSPIRED: http://youtube.com/watch?v=KbsUBqQxygY
Apna sapna money money song Dil mein baji guitar Inspired by song, 'Sheloha shela' by the Middle Eastern group, Miami Band
Original: http://www.itwofs.com/audio/ShelohaShela-MiamiBand.rm
INSPIRED: http://youtube.com/watch?v=pCPA80elJlY
Woh Lamhe song 'Tu Jo nahi' Inspired by 'Tu Jo Nahi SB John
Original:
http://youtube.com/watch?v=HWoKJMnMRSQ&feature=related
INSPIRED: http://youtube.com/watch?v=br_RJ0-rlbY
Bas ek Pal song 'Hai ishq' Inspired by Yuri Mrakadi's 'Arabiyon Ana'
Original: http://youtube.com/watch?v=c8gt6agxYN0
INSPIRED: http://youtube.com/watch?v=qoHtiN4rWJo
Pyaar Ke Side Effects song 'Is this love' Inspired by Paul Anka's 1969 track 'A-mi-manera'
Original: http://www.itwofs.com/audio/A-mi-manera_MyWay.rm
INSPIRED: http://youtube.com/watch?v=CGzMwPzc1VY
Ankahee Title song Inspired by Boney M's 1984 track, 'Somewhere in the world'
Original: http://youtube.com/watch?v=68hPjUoAk4E
INSPIRED:http://www.itwofs.com/audio/Ankahee-TitleSong.rm
Gangster
Song 'Ya ali' Inspired by Arabic band Guitara's 'Ya ghaly'
Original: http://youtube.com/watch?v=ZJi50826cu4
INSPIRED:
http://youtube.com/watch?v=dpl9o_0Dtb4&feature=related
SOng 'Lamha lamha' lifted form Waris Baig's 1998 track, 'Kal shab dekha maine'
Original: http://youtube.com/watch?v=0wfe0u-7DpI
INSPIRED: http://youtube.com/watch?v=dJscz7bJ080
Song 'Bheegi bheegi' lift from Mohiner Ghoraguli's Bangla jibhonmuki gaan
Original:http://youtube.com/watch?v=xAkzopTMXHc
INSPIRED:
http://youtube.com/watch?v=_wwsyz2YBUg&feature=related
Song Tu hi meri shab hai Inspired by 'Sacral Nirvana' by Oliver Shanti & Friends
Original: http://youtube.com/watch?v=5JXrmUD0EK0
Inspired:
http://youtube.com/watch?v=BklekKJPjlI&feature=related
Ek Hasina Thi
Song Akhiyaan Na Maar Inspired by Pakistani singer Waris Baig's 2004 track, 'Challa'
Original: http://www.itwofs.com/audio/Challa-WarisBaig.rm
INSPIRED: http://youtube.com/watch?v=BuFQ0aZLP8E
Song Jal Jal Ke Inspired by Yuri Mrakadi's 2001 track, 'Arabiyon Ana'
Original: http://youtube.com/watch?v=gmmToe4TJw8
INSPIRED:http://youtube.com/watch?v=F_MYsiA3YY0
Fight Club Song Chorein ki Batein Inspired by Pakistani singer Ali Zafar's 'Channo ki aankhen'
Original: http://youtube.com/watch?v=lLhylAWQgo8
INSPIRED: http://youtube.com/watch?v=NrVm2NEoatY
Ek Khiladi Ek Hasina song 'Jhoom' Lifted from Britney Spears' commercial for Pepsi, 'Joy of Pepsi'
Original: http://youtube.com/watch?v=HSZaif6xlWc
INSPIRED: http://youtube.com/watch?v=wKpYRUI3o4M
Garam Masala
Songs 'Dil samundar' Inspired by Turkish singer Tarkan's 'Kuzu kuzu'
Original: http://youtube.com/watch?v=u4kncVrjaQk
INSPIRED: http://youtube.com/watch?v=4SHSxTBT4D0
Song 'Chori Chori' Inspired by Balwinder Safri's 'Hai rabba'
Original 1: http://www.itwofs.com/audio/ChoriChori2-GaramMasala.rm
Original 2: http://www.itwofs.com/audio/HaiRabba-DrZeus.rm
INSPIRED: http://youtube.com/watch?v=xT5-NxdawRI
Song'Ada' Inspired by song Amr Diab's Ana
Original: http://www.itwofs.com/audio/AmrDiab-Ana.rm
INSPIRED:http://www.itwofs.com/audio/HaiRabba-DrZeus.rm
Dhoom song Shikdum Inspired by Tarkan's 'Sikidim'
Original: http://youtube.com/watch?v=g2uy7Cfl6kU
INSPIRED: http://youtube.com/watch?v=i2xThHWuM9A
Chocolate
Song 'Zahreeli raatein' Inspired by Jal's 'Aadat'
Original: http://youtube.com/watch?v=FdZDRZTf67Y
INSPIRED: http://youtube.com/watch?v=XyZEth7A0aw
Song 'Bheega bheega sa' Inspired by Abrar-ul-Haq's 'December'
Original: http://www.itwofs.com/audio/December-AbrarUlHaq.rm
INSPIRED:
http://youtube.com/watch?v=LCZhMHUFabI&feature=related
Song 'Halka halka sa' Inspired by 'Breeze from Saintes Maries'
Original: http://www.itwofs.com/audio/BreezeFromSaintesMaries-JesseCoo k.rm
INSPIRED: http://youtube.com/watch?v=xcaog3CT6Fs
Sunday, June 15, 2008
Kiddie Foods
Let me know if i missed some thing.
- IDLI Sugar
- Chai Paratha
- Chai IDLI
- Chai Roti
- Bhujia Pyaj Roti
- Chai Lie
- Jaggery Ghee Roti (Gud, Ghee, Roti)
Friday, June 13, 2008
Wednesday, June 11, 2008
Determine if SSL connections are truly secure
When users browse to a Web site that begins with https, they expect that connection to be secure via Secure Sockets Layer (SSL), a protocol for transmitting secure documents via the Internet. The majority of Web sites use this protocol to obtain sensitive data (e.g., shopping cart data and credit card numbers from customers).
An https Web site may make most users feel relatively secure, but this alone doesn't guarantee secure transactions. To properly protect your organization's users--as well as corporate data that nonsecure transactions could leave open to exposure--make sure your users understand how to properly evaluate a Web site's security.
Making the SSL connection
When it comes to online forms, secure servers (from an https site) do not actually serve most of them. This means that the form data may not be going where users think.
Note : Sorry because of limitation with Blog Spot I am enclosing the HTML tag < with "<".. Hope it does not impact ..
If you view the source HTML code of a Web page that you're entering credit card data into, you should see something like the following:
"<"form method="POST" action="/order.cgi"">"
or
"<"form method="POST" action="https://www.shop.com/cgi-bin/order.cgi"">"
If the form POSTs to an IP address, users should browse to another site. A Web site should send sensitive information only to a registered site.
Here are the four most common forms that users will encounter:
- Form page http://www.shop.com/form.html with a form tag of "<"form action="/cgi-bin/login.cgi" method="get"">": This is not secure at all, and it doesn't encrypt any of the information.
- Form page https://www.shop.com/form.html with a form tag of "<"form action="http://www.shop.com/cgi-bin/login.cgi method="get"">": This information isn't secure either. When the form sends the data, it initiates a new--not secure--HTTP session.
- Form page http://www.shop.com/form.html with a form tag of "<"form action=https://www.shop.com/cgi-bin/login.cgi method="get"">": This securely transmits information to the form Web site.
- Form page https://domain.com/form.html with a form tag of "<"form action=/cgi-bin/login.cgi method="get"">": This also securely transmits information to the form Web site.
Making sure data remains secure
By securely transmitting data and using SSL to collect sensitive information, a Web site implies that it will keep that information secure. But what really happens behind the Web site?
For example, most small companies don't host their own Web sites; instead, they use a Web hosting service. But Web hosting services typically turn that Web form data into an e-mail, a process that more than likely doesn't encrypt the data. This means that anyone with access to the e-mail can easily access customers' sensitive information.
Advise users to keep this in mind when surfing the Web, and make sure your organization's Web site makes an effort to reassure its customers about data security.
Handle security incidents in seven steps
The possibility of encountering a security incident grows each day. Don't wait until you're in the middle of a crisis before you begin to develop a rational plan for handling an attack. Being prepared for an incident is essential to the survival of your network and its resources. Incident handling begins with planning and establishing policies and procedures.
Developing a plan of attack for each type of security incident is crucial to the restoration of normal operation. Here are the most common incident categories:
- Elevation of file privileges: A user or guest gains greater privileges.
- Data alteration: Unauthorized users make changes to files.
- Data theft: Unauthorized users remove data from the system.
- Denial of service (DoS): Intruders launch an attack that denies legitimate access to the system.
An event can sometimes span multiple categories. For example, Web site defacement involves elevation of privileges and data alteration.
An essential action plan
Different events require different responses. However, you should follow these seven steps for every incident.
Step 1: Log everything.
Your documentation doesn't have to be fancy. It can be a Word document with screen shots or notes on a blackboard. The goal is to capture detailed information without destroying or contaminating potential evidence. Before you take further action, verify that you have an incident.
Step 2: Make appropriate calls.
Depending on the severity of the incident, the first call might be to your service provider, or it might be to an internal legal department to start a chain of custody for evidence. For each type of incident, develop of flow chart detailing whom to contact.
Step 3: Contain the incident.
Concentrate on limiting the extent of the damage to your network. Determine whether the incident is still in progress and requires monitoring or if you should take actions to stop the activity.
Step 4: Identify the point(s) of failure.
Discover how the incident occurred, and determine what you should do to ensure the same event doesn't reoccur.
Step 5: Solve the problem, and repair the damage.
Implement the solution you've determined is necessary to ensure that the security event doesn't happen again. This might be as simple as applying an operating system patch or adding a new rule to a firewall or router.
After you've plugged the security hole, repair any damage caused by the incident.
Step 6: Increase monitoring.
After restoring a compromised system to operation, continue to monitor for backdoors and repeat attempts. Make sure you've removed the cause of the incident, and ensure that the system is functioning normally.
Success yields a persistent hacker. Discover exactly what occurred, how it occurred, and what's necessary to ensure it doesn't happen again.
Monday, May 26, 2008
Alopecia-Areta
Alopecia areata (AA) is a condition affecting humans, in which hair is lost from areas of the body, usually from the scalp.[1] Because it causes bald spots on the scalp, especially in the first stages, it is sometimes called spot baldness. In 1%–2% of cases, the condition can spread to the entire scalp (Alopecia totalis) or to the entire epidermis (Alopecia universalis).
The condition affects 1%–2% of humans,[3] occurring in both males and females.[1]Alopecia areata occurs in people who are apparently healthy and have no skin disorder. So I can say that am gods chosen one :). Posting images to track my recovery and info to few of my friends..
Oh forgot to tell in computer professional language .. It's a False Positive alert of our body due to autoimmune system.. Consider autoimmune system as NAC controller which is detecting our own body parts as alien or parasite and rejecting it from body..
See how dangerous False Positive alert can be.. :)
To know more abt the Alopecia
http://www.alopeciaareatainfo.com/
http://www.alopeciacure.com/

Custom Search
Tuesday, May 20, 2008
Sunday, March 16, 2008
Sunday, March 09, 2008
Outlook Empty Subject Alert Mail
Most of the time we usually regret for writing a mail without subject line. Now not any more. A tip for outlook user like gmail now your outlook is also going to prompt..
Enclosed the steps to enable this feature
1. Open your outlook.
2. Press Alt+F11. This opens the Visual Basic editor and then Press Ctrl+R which in turn open Project-Project 1 (left side)
3. On the Left Pane, one can see "Microsoft Outlook Objects" or "Project1", expand this. Now one can see the "ThisOutLookSession".
4. Double click on "ThisOutLookSession". It will open up a code pane.
5. Copy and Paste the following code in the right pane. (Code Pane) and save it.
Private Sub Application_ItemSend(ByVal Item As Object, Cancel As Boolean)
Dim strSubject As String
strSubject = Item.Subject
If Len(Trim(strSubject)) = 0 Then
Prompt$ = "Subject is Empty. Are you sure you want to send the Mail?"
If MsgBox(Prompt$, vbYesNo + vbQuestion + vbMsgBoxSetForeground, "Check for Subject") = vbNo Then
Cancel = True
End If
End If
End Sub
6. Now whenever u try to send a mail without subject, it will raise a pop-up to remind.
Friday, February 29, 2008
Display services running in the Svchost.exe process group
Last time, we explained how to view additional information for each process via Task Manager's Processes tab. In Task Manager, you'll notice a process named Svchost.exe. This process doesn't appear as an application in the Applications tab--it only appears in the Process tab, and there can be multiple instances of it on a system.
Svchost.exe is a generic Windows 2000 process that runs services from Dynamic Link Libraries (DLLs). When the system starts, Svchost.exe loads the services listed in this registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
\Svchost
Each entry in this key specifies a service group and is a REG_MULTI_SZ value, which means it can contain multiple string values. These values define service names for services that are members of the group. The service names themselves come from the Svchost registry key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Service
The Processes tab doesn't display the individual services that are part of the service group, nor can you add an optional column to view the services. However, you can view the service groups' individual services using the Tlist.exe utility included with the Windows 2000 Resource Kit.
After you install Tlist.exe from the Resource Kit, open a command console and issue the command:
Tlist.exe -s or tasklist /M
Scan the resulting output and look for instances of Svchost.exe. Each Svchost line will include a list of the services running under that instance of the process.
Knowing what processes are running on a system and being able to identify those processes is an important step when troubleshooting system problems or attempting to recover a hung system without rebooting. Once you identify the hung process, you can kill the process from the Task Manager.
Friday, February 01, 2008
L2 Cache Feature in Pentium III & Xeon Processor Based Server / PC
02-16-2003, 04:12 AM
It was a great experience today for me when I was enquired about L2 on die cache with Windows XP by my booss. I just shocked by knowing the fact that by default Windows XP enable 256KB Cache in kernel its hardly matter that how much Cache is available in your server. I did small research on this & found some amazing fact which I enclosed here.
The L2, or second-level, cache, is an integral part of your CPU. But still NT Kernel didn’t detect it. What I mean is that all Microsoft family OS based on NT Kernel like Windows 2000 Server family, Windows NT, Windows 2000 Professional and even though Windows XP. You didn’t Observe it by any tool but it could be displayed only in one Registry Key. Use Regedt32 or regedit & navigate to this hive
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Contro l\Session Manager\ Memory Management\SecondLevelDataCache
You definitely observe
Type: REG_DWORD
Value: 0x00000000
This is because when HAL (at the time of installation ) cannot retrieve this from the hardware or BIOS, it sets this parameter value to 0, indicating that a built-in default size of 256 KB of L2 cache should be used. But Most Pentium II and III systems use 512 KB or more of L2 cache memory. The Xeon chips support 1 MB and 2 MB caches. You can get significantly better performance if this is set to match the actual amount of L2 cache. Setting the value higher than the actual amount of L2 cache available may prevent the system to be unstable. Check your documentation carefully. Multiprocessor systems have processors with identical speeds and caches.
Hive: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Contro l\Session Manager
Key: Memory Management
Name: SecondLevelDataCache
Type: REG_DWORD
Value: 0x00000000 256K L2 cache
Value: 0x00000200 512K L2 cache
Value: 0x00000400 1M L2 cache
Value: 0x00000800 2M L2 cache
Microsoft states that the above is erroneous and that the second level (L2) cache is recognized by the NT/W2K/XP and is fully utilized regardless of the setting of this parameter. Thus I would not twiddle with it, although if Microsoft is correct, it doesn't matter Don't know what to believe. But I found relative performance enhancement after making this change.
Mukesh Kesharwani
CISSP, CISM, CNA, MCSE, MCP+I, SCSA, CUA,
Saturday, November 10, 2007
School Days
Saturday, September 15, 2007
Thursday, September 14, 2006
Privacy New Buzz Word In Business World.
Recently I have gone through a traning program which is said to be standard ethical practices and in that traning some question arised related to privacy. Although organization are on document defining what is ethical and what is non ethical but how many of IT manager understand it. Key buzz word which is responsible for revolution in US healthcare sector is privacy. Lets understand this and its relevance in ethical part for IT managers.
Does information’s availability justify its use?
Governments collect massive amounts of data on individuals and organizations and use it for a variety of purposes: national security, accurate tax collection, demographics, international geopolitical strategic analysis, etc. Corporations do the same for commercial reasons; to increase business, control expense, enhance profitability, gain market share, etc. Technological advances in both hardware and software have significantly changed the scope of what can be amassed and processed. Massive quantities of data, measured in petabytes and beyond, can be centrally stored and retrieved effortlessly and quickly. Seemingly disparate sources of data can be cross-referenced to glean new meanings when one set of data is viewed within the context of another. In the 1930s and 1940s the volumes of data available were miniscule by comparison and the "processing" of that data was entirely manual. Had even a small portion of today’s capabilities existed, the world as we now know it would probably be quite different. Should organizations’ ability to collect and process data on exponentially increasing scales be limited in any way? Does the fact that information can be architected for a particular purpose mean it should be, even if by so doing individual privacy rights are potentially violated? If data meant for one use is diverted to another process which is socially redeeming and would result in a greater good or could result in a financial gain, does that mitigate the ethical dilemma, no matter how innocent and pure the motivation?
How much effort and expense should managers incur in considering questions of data access and privacy?
Many people are required to sign NDAs (nondisclosure agreements) and noncompete clauses in employment contracts, legal documents that restrict their ability to share information with other future employers even to the point of disallowing them to join certain companies or continue to participate in a particular industry. What about the rest of us, who have no such legal restrictions? In the course of our work for employer A, we are privy to trade secrets, internal documents, proprietary processes and technology, and other information creating competitive advantage. We can’t do a brain dump when we leave to go to work for employer B; we carry that information with us. Is it ethical to use our special knowledge gained at one employer to the benefit of another? How do you realistically restrict yourself from doing so?
What part of an information asset belongs to an organization and what is simply part of an employee’s general knowledge?
Information, knowledge, and skills we develop in the course of working on projects can be inextricably intertwined. You’re the project manager for an effort to reengineer your company’s marketing operations system. You have access to confidential internal memoranda on key organization strategic and procedural information. To build the new system, you and your team have to go for some advanced technical training on the new technology products you’ll be using. The new system you build is completely revolutionary in design and execution. Although there are areas of patent law that cover many such situations, there’s not much in the way of case law testing this just yet, and of course laws vary between countries. Clearly, you’ve built an asset owned by your company, but do you have a legitimate claim to any part of it? Can you take any part of this knowledge or even the design or code itself with you to another employer or for the purpose of starting your own company? Suppose you do strike out on your own and sell your system to other companies. Is the ethical dilemma mitigated by the fact that your original company isn’t in the software business? Or that you’ve sold your product only to noncompeting companies? What if we were talking about a database instead of a system?
In a bygone era, there was less data to work with, and the only quality assurance that needed to be performed was on data…operations and procedures were manual, so it was the output of those functions that was most critical. Technology has enabled vastly more complicated and interconnected processes, such that a problem far upstream in a process has a ripple effect on the rest of the process. Sarbanes Oxley requires the certification of all internal controls in large part for this reason.
Does data gathered violate employee privacy rights?
Many organizations have started adding a credit and background check to the standard reference check during the hiring process. Are those organizations obligated to tell us they’re doing this and what results they’ve received? The justification for doing the credit check typically is that a person who can’t manage his or her own finances probably can’t be trusted with any fiduciary responsibility on behalf of the organization. Does this pass the smell test or is this actually an infringement of privacy? Performing these checks is a relatively recent phenomenon, brought on in part by the desire of organizations to protect themselves in the wake of the numerous corporate scandals of the past few years but also because technology has enabled this data to be gathered, processed, and accessed quickly and inexpensively. Is technology responsible for enabling unethical behavior?
Do employees know the degree to which behavior is monitored?
Organizations have the right to monitor what employees do (management is measurement) and how technology systems are used. It’s common practice to notify employees that when they use organizational assets such as networks or Internet access, they should have no expectation of privacy. Even without that disclaimer, they really don’t need the warning to know this monitoring is, or could be, taking place. Do organizations have an obligation to notify employees as to the extent of that monitoring? Should an organization make it clear that in addition to monitoring how long employees are using the Internet, it's also watching which Web sites they visit? If employees are told there’s no expectation of privacy when using the e-mail system, is it an ethical violation when they later find out the organization was actually reading their e-mails?
Monday, September 11, 2006
Security Policies
Creating Your Own Security Policy
- Decide on your level of trust.
- Define appropriate behavior.
- Create a policy review team.
- Use the work of others.
Step 1: Decide on Your Level of Trust Assuming that people will do the right thing is easy and tempting. Don’t let yourself take this shortcut. Spell out what is expected and what is prohibited. Decide on the controls youwill use to measure adherence to the good practices that you are about to define. (This applies to programs as well as people.) Specify repercussions that will follow if employeesdo not adhere to practices. Trust different employees in different ways. Those withunprivileged access are in a different category than those with high levels of accessprivilege.
Step 2: Define Appropriate Behavior Whether the topic is email usage, password policies, or keeping company secrets, yoursystem’s users and the people who evaluate them must know what is expected. Your policiesare necessary to support an HR action in the face of inappropriate behavior, or even toprosecute a criminal case in extreme examples.
Step 3: Create a Policy Review Team The members of this team are responsible for drafting new policies and revising existingones.
Step 4: Use the Work of Others The previous section gave a pointer to a set of policies suitable for a large company. A Google.com search turns up literally dozens of sample policies for sale. Amazon has several books. You should investigate these resources and find one that matches your organization’sprofile. This will save you significant amounts of work. Even more important, it will keep you from accidentally omitting vital areas from consideration.
Members of the Policy Review Team
Representative From Duties Management Someone who can enforce the policy. This is often a senior memberof the HR staff. Information Security Department Someone who can provide technical insight and research. User Areas Someone who can view the policies the way a user might view them. Legal Department Possibly part time, but someone who can review policies with respect to applicable laws. For multinational firms, this review is exponentially more complicated. Publications Someone who can make suggestions on communicating the policies to the organization’s members and getting their buy in. Also, a goodwriter is always helpful.
A Sample Security Policy (Password Policy Extracted From Book )
1.0 Overview
Passwords are an important aspect of computer security. They are the front line of protection for user accounts. A poorly chosen password may result in the compromise of Example Corporation’s entire corporate network. As such, all Example Corporation employees (including contractors and vendors with access to Example Corporation systems) are responsible for taking the appropriate steps, as outlined below, to select andsecure their passwords.
2.0 Purpose
The purpose of this policy is to establish a standard for creation of strong passwords, the protection of those passwords, and the frequency of change.
3.0 Scope
The scope of this policy includes all personnel who have or are responsible for an account(or any form of access that supports or requires a password) on any system that resides atany Example Corporation facility, has access to the Example Corporation network, orstores any non-public Example Corporation information.
4.0 Policy
4.1 General
- All system-level passwords (e.g., root, enable, NT admin, application administrationaccounts, etc.) must be changed on at least a quarterly basis.
- All production system-level passwords must be part of the Information SecurityDepartment administered global password management database.
- All user-level passwords (e.g., email, web, desktop computer, etc.) must be changedat least every six months. The recommended change interval is every four months.
- User accounts that have system-level privileges granted through group membershipsor programs such as “sudo” must have a unique password from all other accounts heldby that user.
- Passwords must not be inserted into email messages or other forms of electroniccommunication.
- Where SNMP is used, the community strings must be defined as something other thanthe standard defaults of “public,” “private” and “system” and must be different fromthe passwords used to log in interactively. A keyed hash must be used where available(e.g., SNMPv3).
- All user-level and system-level passwords must conform to the guidelines describedbelow.
4.2 Guidelines
A. General Password Construction Guidelines Passwords are used for variouspurposes at Example Corporation. Some of the more common uses include: user level accounts, web accounts, email accounts, screen saver protection, voicemail password, and local router logins. Since very few systems have support for one-time tokens (i.e., dynamic passwords which are only used once), everyone should be aware of how to select strong passwords. Poor, weak passwords have the following characteristics:
- The password contains less than eight characters
- The password is a word found in a dictionary (English or foreign)
- The password is a common usage word such as:
- — Names of family, pets, friends, co-workers, fantasy characters, sports teams,etc.
- — Computer terms and names, commands, sites, companies, hardware,software.
- — The words “Example Corporation”, “EXMC”, “BigApple” or anyderivation.
- — Birthdays and other personal information such as addresses and phonenumbers.
- — Word or number patterns like aaabbb, qwerty, zyxwvuts, 123321, etc.— Any of the above spelled backwards.
- — Any of the above preceded or followed by a digit (e.g., secret1, 1secret)
Strong passwords have the following characteristics:
- Contain both upper and lower case characters (e.g., a-z, A-Z)Strong passwords have the following characteristics:
- Contain both upper and lower case characters (e.g., a-z, A-Z)
- Have digits and punctuation characters as well as letters e.g., 0-9, mailto:!@#$%^&*()_+~-=\`{}[]:“;’<)
- Are at least eight alphanumeric characters long.
- Are not a word in any language, slang, dialect, jargon, etc.
- Are not based on personal information, names of family, etc.
B. Password Protection Standards Do not use the same password for Example Corporation accounts as for other non-Example Corporation access (e.g., personal ISPaccount, option trading, benefits, etc.). Where possible, don’t use the same password for various Example Corporation access needs. For example, select one password for the Engineering systems and a separate password for IT systems. Also, select a separate password to be used for an NT account and a UNIX account. Do not share Example Corporation passwords with anyone, including administrative assistants or secretaries. All passwords are to be treated as sensitive, Confidential Example Corporation information.
List of don’ts:
- Don’t reveal a password over the phone to ANYONE
- Don’t reveal a password in an email message
- Don’t reveal a password to the boss
- Don’t talk about a password in front of others
- Don’t hint at the format of a password (e.g., “my family name”)
Don’t reveal a password on questionnaires or security forms - Don’t share a password with family members
- Don’t reveal a password to co-workers while on vacationIf someone demands a password, refer them to this document or have them call someone inthe Information Security Department.
- Do not use the “Remember Password” feature of applications (e.g., Eudora, OutLook,Netscape Messenger).Again, do not write passwords down and store them anywhere in your office.
- Do not storepasswords in a file on ANY computer system (including Palm Pilots or similar devices)without encryption.
Change passwords at least once every six months (except system-level passwords whichmust be changed quarterly). The recommended change interval is every four months. If an account or password is suspected to have been compromised, report the incident to theInformation Security Department and change all passwords. Password cracking or guessing may be performed on a periodic or random basis by theInformation Security Department or its delegates. If a password is guessed or cracked during one of these scans, the user will be required to change it.
C. Application Development Standards Application developers must ensure their programs contain the following security precautions.
Applications:
• Should support authentication of individual users, not groups.
• Should not store passwords in clear text or in any easily reversible form.
• Should provide for some sort of role management, such that one user can take overthe functions of another without having to know the other’s password.
• Should support TACACS+ , RADIUS and/or X.509 with LDAP security retrieval,wherever possible.
D. Use of Passwords and Passphrases for Remote Access Users Access to theExample Corporation Networks via remote access is to be controlled using either a onetimepassword authentication or a public/private key system with a strong passphrase.
E. Passphrases Passphrases are generally used for public/private key authentication. Apublic/private key system defines a mathematical relationship between the public key thatis known by all, and the private key, that is known only to the user. Without the passphraseto “unlock” the private key, the user cannot gain access. Passphrases are not the same as passwords. A passphrase is a longer version of a passwordand is, therefore, more secure. A passphrase is typically composed of multiple words.Because of this, a passphrase is more secure against “dictionary attacks.”A good passphrase is relatively long and contains a combination of upper and lowercaseletters and numeric and punctuation characters. An example of a good passphrase:“The*?#>*@TrafficOnTheBridgeWas*&#!#ThisMorning”All of the rules above that apply to passwords apply to passphrases.
5.0 Enforcement
Any employee found to have violated this policy may be subject to disciplinary action, upto and including termination of employment.
6.0 Definitions
Terms DefinitionsApplication Administration Account Any account that is for the administration of anapplication (e.g., Oracle database administrator,Notes administrator).
7.0 Revision History
Policies commonly apply to less than all sections of the organization. Policies on acquiring commercial software or running a test lab or training department apply only to segments ofthe company, whereas policies such as an Information Sensitivity Policy (deals with keeping confidential company information private) or Password Policies apply across the enterprise.
Example Security Policies Several model security policies are available on the web. A good starting place is RFC 2196, “Site Security Handbook,” which discusses all aspects of security policies, fromcontent development to implementation. Another source of sample policies comes fromSANS. The direct link is www.sans.org/newlook/resources/policies/policies.htm. If thelink breaks, key the title of the page, The SANS Security Policy Project, into the searchthis-site box on the SANS home page.
Effectively Implementing Your Security Policy When you develop policies, you need to balance productivity and security. The goal of all good employees is to get their work done. If you create a rule that the employee thinks is just in the way, that employee will either ignore it or bypass it. Sometimes, you can implement technical controls to make sure that policies are followed (password changeperiods, for example), but other times you cannot. (A rule about never giving your passwordto someone else cannot be enforced by software.) You must make security a part of the corporate culture. This does not have to be done in a punitive way.
Here are two examples. A company whose policy called for password-protected screen savers or locked workstations whenever an employee was not using the PC was enforced by having security staff (uniformed guards on patrol) write “tickets”—they looked like parking tickets—and taping them to the monitor. The tickets reminded the users of the rules. The guards were taught how to Ctl-Alt-Del and pick Lock Workstation, and were instructed to do so whenever issuing a ticket. Another company had guards walk around after the close of business looking for laptop sleft unattended. They took laptops they found and left a “luggage receipt” on the desk saying that the lost luggage could be claimed at the security station. Avoiding Failure One sure way to make a policy fail is to apply it unevenly. If certain people, because of their position or influence, can bypass policies with impunity, the policies will all become unenforceable. You must get management buy-in, even if doing so is painful.



