Monday, July 28, 2008

Configure IIS 6.0 operating modes

Recently one of my friend has some trouble in IIS hosted application. To identify the RCA I got to know the advance feature of IIS 6.. Enclosed the extract of that knowledge..

Windows Server 2003 introduced some significant changes from Windows 2000 Server, and Internet Information Services (IIS) 6.0 is a good example. Not only is IIS' architecture considerably different in IIS 6.0, but the management interface has also changed. For example, IIS 6.0 provides two operating modes: IIS 5.0 Isolation Mode and IIS 6.0 Worker Process Isolation Mode.
In IIS 5.0 Isolation Mode, all in-process applications run inside Inetinfo.exe. Out-of-process applications run in separate instances of DLLHost.exe. Inetinfo.exe handles HTTP request queuing, IIS services (FTP, SMTP, NNTP, etc.), and worker processes. Svchost.exe runs the WWW service.
The primary purpose for IIS 5.0 Isolation Mode is to mimic the behavior of IIS 5.0 and earlier versions, and it provides compatibility for Web applications designed specifically for IIS 5.0 or earlier.
IIS 6.0 Worker Process Isolation Mode, also called native mode, provides better performance, reliability, and fault tolerance. In native mode, the kernel-mode driver http.sys handles all HTTP request processing and queuing. Inetinfo.exe handles IIS administration and configuration as well as the IIS services, including SMTP, NNTP, and FTP. Svchost.exe handles the WWW service, and multiple instances of W3wp.exe handle worker processes.
Separating worker processes in this way isolates those worker processes from the core IIS services for better reliability overall and better recoverability for individual processes. This process isolation, combined with the fact that the core IIS services prevent the loading of third-party code, means an errant Web application will have a tough time crashing the WWW service and bringing down the server.
In a clean installation of IIS 6.0, native mode is the default mode. A system upgraded from a previous IIS 6.0 installation assumes the mode of the previous installation. Systems upgraded from IIS 5.0 or IIS 4.0 run in IIS 5.0 Isolation Mode to provide compatibility for the existing Web applications on the server.
One aspect of managing an IIS 6.0 server is setting the mode in which the server runs. For example, you might be installing a Web application that won't run in native mode and need to switch the server to IIS 5.0 Isolation Mode. Or you may have upgraded an existing server and now want to switch it from IIS 5.0 Isolation Mode to native mode. Note that the server as a whole runs in a given mode; you can't run specific sites on the server in different modes.
To configure IIS 6.0's operation mode, open the Internet Information Services Manager from the Administrative Tools folder, or run %systemroot%\system32\inetsrv\iis.msc. When the IIS console opens, right-click the Web Sites branch in the left pane, choose Properties, and select the Service tab. Selecting the Run WWW Service In IIS 5.0 Isolation Mode option configures the server to run in IIS 5.0 Isolation Mode. Deselect this option if you want to run the server in native mode.

Thursday, July 03, 2008

Listen to these original songs of most popular Hindi Tracks

Dhoom song DHoom Macchale Inspired by Jesse Cook's 'Mario takes a walk'

Original:
http://youtube.com/watch?v=e3iTfEF52kw

INSPIRED:
http://youtube.com/watch?v=CvhPvxmD3mI





Race Song Pehli Nazar Inspired by Chinese Kim Hyung Song Sarang Hae Yo

Original:
http://youtube.com/watch?v=8KoS3weBxAg

INSPIRED:
http://youtube.com/watch?v=ffp5h_FGEJY



Race Song Zara Zara Touch Me Inspired by Lee-Hom Wang's 'Zhu Lin Shen Chu'

Original:
http://youtube.com/watch?v=wdTrPI3mumU

INSPIRED:


http://youtube.com/watch?v=kLU76W2qbPs&feature=related



Jab we met's 'Yeh ishq kya' Inspired by Anggun's Être Une Femme

Original:
http://youtube.com/watch?v=T4poevqspsI

INSPIRED:


http://youtube.com/watch?v=TQyU6EqWh_o&feature=related



Jab We Met Aao milo chale Inspired Indonesian band, Peterpan's 'Di Belakangku'

Original:
http://youtube.com/watch?v=EGXniVSfSZE

INSPIRED:


http://youtube.com/watch?v=7jpUic8hWD8&feature=related



Woh Lamhe 'Kya mujhe pyaar hai'Inspired by Indonesian Band 'Tak bisakah'

Original:
http://youtube.com/watch?v=EZTqg1MgkTY

INSPIRED:


http://youtube.com/watch?v=2EoblYYvLsE&feature=related



Bhool Bulaiya Halla Hafiz Inspired by Amr Diab's Awedony

Original:
http://youtube.com/watch?v=8Xi_xOmmsRY

INSPIRED:


http://youtube.com/watch?v=UtVerSkccgo&feature=related



Dhol Dil Liya Inspired by Dania Khatib's 1999 hit, 'Leiley'

Original:
http://www.itwofs.com/audio/Leiley-DaniaElKhateeb.rm

INSPIRED:
http://youtube.com/watch?v=xBkp57nRE5A



Life in a Metro song Baatein kuch ankahee Inspired by Korean song, 'Ah Reum Dah Oon Sa Ram' by Seo Yu Seok!

Original:
http://youtube.com/watch?v=KCTGuhPcC4Y

INSPIRED:


http://youtube.com/watch?v=Ura4grIiF90&feature=related



Bhool Bhulaiyya Hare ram hare ram Inspired by Bill Hailey's Oriental Rock

Original:
http://www.itwofs.com/audio/OrientalRock-BillHaleyComets.rm

INSPIRED:
http://youtube.com/watch?v=4lu3EorpiQ4



Life in a Metro song O Meri jaan Inspired by Queensryche's Silent Lucidity and Amr Diab's Ba'ed el Layali

Original 1:
http://youtube.com/watch?v=-2ohGF0K4AI

Original 2:
http://youtube.com/watch?v=P2y_Vbev5zs

INSPIRED:
http://youtube.com/watch?v=3g2ICCQNQ-w



Pyar ke side effects song Jaane kya Inspired by 'Mahi' by Hadiqa Kiyani

Original:
http://youtube.com/watch?v=mokJJsRfP6Q

INSPIRED:
http://www.youtube.com/watch?v=V5fEHdP-5Dc



Woh Lamhe song Chal Chale Inspired by a 1965 track called 'A World of our own' by the band, The Seekers

Original:
http://www.youtube.com/watch?v=S9oaXzrsV3Q

INSPIRED:
http://www.youtube.com/watch?v=KeJ2tqPjnps



Dhoom Song DHOOM AGAIN Inspired by a song called 'Dudu' from Tarkan

Portions edited appropriately

Original:
http://www.itwofs.com/audio/Dudu_ver2-Tarkan.rm

INSPIRED:
http://www.itwofs.com/audio/DhoomAgain-Dhoom2.rm





Speed song Tikki Tikki Inspired by Turkish pop superstar Tarkan's 2003 hit, 'Dudu'

Original:
http://youtube.com/watch?v=KoJ34jPX3WM

INSPIRED:
http://www.itwofs.com/audio/TikhiTikhi-Speed.rm



Agnipankh song Janmabhoomi & Zindagi hai Inspired by Abrar-ul-haq's 'December

Original:
http://www.itwofs.com/audio/December-AbrarUlHaq.rm

INSPIRED 1:
http://www.itwofs.com/audio/Janmabhoomi-Agnipankh.rm

INSPIRED 2:
http://www.itwofs.com/audio/ZindagiHaiTo-Agnipankh.rm



Bhagam Bhag songs Signal & Afreen Inspired by Trinidadian Soca hit, 'Signal for Lara' by Superblue & Cheb Mami's 2001 track, 'Viens Habibi'

Original 1:
http://www.itwofs.com/audio/SignalForLara-SuperBlue.rm

Original 2:
http://www.itwofs.com/audio/ViensHabibi-ChebMami.rm

INSPIRED 1:
http://youtube.com/watch?v=G31riHQjvDI

INSPIRED 2:
http://youtube.com/watch?v=b-65fajmsC8



Life in a Metro In dino Inspired by Waqar Ali's 'Mera naam hai mohobbat'

Original:
http://youtube.com/watch?v=89wB3og_yXQ

INSPIRED:
http://youtube.com/watch?v=aQ52IJjbNg4



Raqueeb songs 'Jaane kaise' Inspired by Amr Diab's 2003 track, 'Allem albi' and song 'Channa ve channa' Inspired by Pashto singer Rahim Shah.

Original 1:


http://youtube.com/watch?v=NqoXaLHFTik&feature=related

Original 2:
http://youtube.com/watch?v=JplIDBi6wZE

Inspired 1:
http://youtube.com/watch?v=rjwMsYnEJ58

Inspired2:


http://youtube.com/watch?v=33EJLt-NMDQ&feature=related



Kya Love Story Hai Song 'Miss you everyday' Lift of Lebanese singer Karina's 2006 chartbuster 'Alatoul'

'Jab se tum mile ho' is a lift from Pakistani singer Hadiqa Kiyani's 1996 number (album: Raaz), 'Jab se tum milay ho'!

Original 1:
http://youtube.com/watch?v=snIA9iR0b-0

Original 2:
http://www.itwofs.com/audio/JabSeTumMilay-Hadiqa.rm

INSPIRED:
http://youtube.com/watch?v=FJ_w0HDh0N0



Kya Love Story Hain song 'Deewana teri aankhon ka' Inspired by Black Eyed Peas' 'Bebot'

Original:
http://youtube.com/watch?v=gQAGh3JViyI

INSPIRED:
http://youtube.com/watch?v=Nr0ASdmHF40



Kya Love Story Hai song Gum sum hai dil mera Inspired by Thai song, 'Oh la nor...my love' by Bird Thungchai.

Original:
http://youtube.com/watch?v=tJjrJIh8c8k

INSPIRED:
http://www.itwofs.com/audio/GumSumHaiDil-KLSH.rm



Ankahee song Aa paas aa Inspired by Ottmar Liebert's 'Starry nite (March of Kings)

Original:
http://www.itwofs.com/audio/StarryNite-OttmarLiebert.rm

INSPIRED:
http://youtube.com/watch?v=KbsUBqQxygY



Apna sapna money money song Dil mein baji guitar Inspired by song, 'Sheloha shela' by the Middle Eastern group, Miami Band

Original:
http://www.itwofs.com/audio/ShelohaShela-MiamiBand.rm

INSPIRED:
http://youtube.com/watch?v=pCPA80elJlY



Woh Lamhe song 'Tu Jo nahi' Inspired by 'Tu Jo Nahi SB John

Original:


http://youtube.com/watch?v=HWoKJMnMRSQ&feature=related

INSPIRED:
http://youtube.com/watch?v=br_RJ0-rlbY



Bas ek Pal song 'Hai ishq' Inspired by Yuri Mrakadi's 'Arabiyon Ana'

Original:
http://youtube.com/watch?v=c8gt6agxYN0

INSPIRED:
http://youtube.com/watch?v=qoHtiN4rWJo



Pyaar Ke Side Effects song 'Is this love' Inspired by Paul Anka's 1969 track 'A-mi-manera'

Original:
http://www.itwofs.com/audio/A-mi-manera_MyWay.rm

INSPIRED:
http://youtube.com/watch?v=CGzMwPzc1VY



Ankahee Title song Inspired by Boney M's 1984 track, 'Somewhere in the world'

Original:
http://youtube.com/watch?v=68hPjUoAk4E

INSPIRED:
http://www.itwofs.com/audio/Ankahee-TitleSong.rm



Gangster

Song 'Ya ali' Inspired by Arabic band Guitara's 'Ya ghaly'

Original:
http://youtube.com/watch?v=ZJi50826cu4

INSPIRED:


http://youtube.com/watch?v=dpl9o_0Dtb4&feature=related





SOng 'Lamha lamha' lifted form Waris Baig's 1998 track, 'Kal shab dekha maine'

Original:
http://youtube.com/watch?v=0wfe0u-7DpI

INSPIRED:
http://youtube.com/watch?v=dJscz7bJ080



Song 'Bheegi bheegi' lift from Mohiner Ghoraguli's Bangla jibhonmuki gaan

Original:
http://youtube.com/watch?v=xAkzopTMXHc

INSPIRED:


http://youtube.com/watch?v=_wwsyz2YBUg&feature=related



Song Tu hi meri shab hai Inspired by 'Sacral Nirvana' by Oliver Shanti & Friends

Original:
http://youtube.com/watch?v=5JXrmUD0EK0

Inspired:


http://youtube.com/watch?v=BklekKJPjlI&feature=related





Ek Hasina Thi

Song Akhiyaan Na Maar Inspired by Pakistani singer Waris Baig's 2004 track, 'Challa'

Original:
http://www.itwofs.com/audio/Challa-WarisBaig.rm

INSPIRED:
http://youtube.com/watch?v=BuFQ0aZLP8E



Song Jal Jal Ke Inspired by Yuri Mrakadi's 2001 track, 'Arabiyon Ana'

Original:
http://youtube.com/watch?v=gmmToe4TJw8

INSPIRED:
http://youtube.com/watch?v=F_MYsiA3YY0



Fight Club Song Chorein ki Batein Inspired by Pakistani singer Ali Zafar's 'Channo ki aankhen'

Original:
http://youtube.com/watch?v=lLhylAWQgo8

INSPIRED:
http://youtube.com/watch?v=NrVm2NEoatY



Ek Khiladi Ek Hasina song 'Jhoom' Lifted from Britney Spears' commercial for Pepsi, 'Joy of Pepsi'

Original:
http://youtube.com/watch?v=HSZaif6xlWc

INSPIRED:
http://youtube.com/watch?v=wKpYRUI3o4M



Garam Masala

Songs 'Dil samundar' Inspired by Turkish singer Tarkan's 'Kuzu kuzu'

Original:
http://youtube.com/watch?v=u4kncVrjaQk

INSPIRED:
http://youtube.com/watch?v=4SHSxTBT4D0



Song 'Chori Chori' Inspired by Balwinder Safri's 'Hai rabba'

Original 1:
http://www.itwofs.com/audio/ChoriChori2-GaramMasala.rm

Original 2:
http://www.itwofs.com/audio/HaiRabba-DrZeus.rm

INSPIRED:
http://youtube.com/watch?v=xT5-NxdawRI



Song'Ada' Inspired by song Amr Diab's Ana

Original:
http://www.itwofs.com/audio/AmrDiab-Ana.rm

INSPIRED:
http://www.itwofs.com/audio/HaiRabba-DrZeus.rm



Dhoom song Shikdum Inspired by Tarkan's 'Sikidim'

Original:
http://youtube.com/watch?v=g2uy7Cfl6kU

INSPIRED:
http://youtube.com/watch?v=i2xThHWuM9A



Chocolate

Song 'Zahreeli raatein' Inspired by Jal's 'Aadat'

Original:
http://youtube.com/watch?v=FdZDRZTf67Y

INSPIRED:
http://youtube.com/watch?v=XyZEth7A0aw



Song 'Bheega bheega sa' Inspired by Abrar-ul-Haq's 'December'

Original:
http://www.itwofs.com/audio/December-AbrarUlHaq.rm

INSPIRED:


http://youtube.com/watch?v=LCZhMHUFabI&feature=related



Song 'Halka halka sa' Inspired by 'Breeze from Saintes Maries'

Original:
http://www.itwofs.com/audio/BreezeFromSaintesMaries-JesseCoo k.rm

INSPIRED:
http://youtube.com/watch?v=xcaog3CT6Fs

Sunday, June 15, 2008

Kiddie Foods

Today some how trying to recall the memories of childhood food habits and found that its almost more than 15 years when I had such stuff in my food. So recalling all the dishes for end less future.
Let me know if i missed some thing.

  1. IDLI Sugar
  2. Chai Paratha
  3. Chai IDLI
  4. Chai Roti
  5. Bhujia Pyaj Roti
  6. Chai Lie
  7. Jaggery Ghee Roti (Gud, Ghee, Roti)

Friday, June 13, 2008

Search Result



Wednesday, June 11, 2008

Determine if SSL connections are truly secure

When users browse to a Web site that begins with https, they expect that connection to be secure via Secure Sockets Layer (SSL), a protocol for transmitting secure documents via the Internet. The majority of Web sites use this protocol to obtain sensitive data (e.g., shopping cart data and credit card numbers from customers).

An https Web site may make most users feel relatively secure, but this alone doesn't guarantee secure transactions. To properly protect your organization's users--as well as corporate data that nonsecure transactions could leave open to exposure--make sure your users understand how to properly evaluate a Web site's security.

Making the SSL connection

When it comes to online forms, secure servers (from an https site) do not actually serve most of them. This means that the form data may not be going where users think.

Note : Sorry because of limitation with Blog Spot I am enclosing the HTML tag < with "<".. Hope it does not impact ..

If you view the source HTML code of a Web page that you're entering credit card data into, you should see something like the following:

"<"form method="POST" action="/order.cgi"">"
or
"<"form method="POST" action="https://www.shop.com/cgi-bin/order.cgi"">"

If the form POSTs to an IP address, users should browse to another site. A Web site should send sensitive information only to a registered site.

Here are the four most common forms that users will encounter:

  • Form page http://www.shop.com/form.html with a form tag of "<"form action="/cgi-bin/login.cgi" method="get"">": This is not secure at all, and it doesn't encrypt any of the information.
  • Form page https://www.shop.com/form.html with a form tag of "<"form action="http://www.shop.com/cgi-bin/login.cgi method="get"">": This information isn't secure either. When the form sends the data, it initiates a new--not secure--HTTP session.
  • Form page http://www.shop.com/form.html with a form tag of "<"form action=https://www.shop.com/cgi-bin/login.cgi method="get"">": This securely transmits information to the form Web site.
  • Form page https://domain.com/form.html with a form tag of "<"form action=/cgi-bin/login.cgi method="get"">": This also securely transmits information to the form Web site.

Making sure data remains secure

By securely transmitting data and using SSL to collect sensitive information, a Web site implies that it will keep that information secure. But what really happens behind the Web site?

For example, most small companies don't host their own Web sites; instead, they use a Web hosting service. But Web hosting services typically turn that Web form data into an e-mail, a process that more than likely doesn't encrypt the data. This means that anyone with access to the e-mail can easily access customers' sensitive information.

Advise users to keep this in mind when surfing the Web, and make sure your organization's Web site makes an effort to reassure its customers about data security.

Handle security incidents in seven steps

The possibility of encountering a security incident grows each day. Don't wait until you're in the middle of a crisis before you begin to develop a rational plan for handling an attack. Being prepared for an incident is essential to the survival of your network and its resources. Incident handling begins with planning and establishing policies and procedures.

Developing a plan of attack for each type of security incident is crucial to the restoration of normal operation. Here are the most common incident categories:

  • Elevation of file privileges: A user or guest gains greater privileges.
  • Data alteration: Unauthorized users make changes to files.
  • Data theft: Unauthorized users remove data from the system.
  • Denial of service (DoS): Intruders launch an attack that denies legitimate access to the system.

An event can sometimes span multiple categories. For example, Web site defacement involves elevation of privileges and data alteration.

An essential action plan

Different events require different responses. However, you should follow these seven steps for every incident.

Step 1: Log everything.
Your documentation doesn't have to be fancy. It can be a Word document with screen shots or notes on a blackboard. The goal is to capture detailed information without destroying or contaminating potential evidence. Before you take further action, verify that you have an incident.

Step 2: Make appropriate calls.
Depending on the severity of the incident, the first call might be to your service provider, or it might be to an internal legal department to start a chain of custody for evidence. For each type of incident, develop of flow chart detailing whom to contact.

Step 3: Contain the incident.
Concentrate on limiting the extent of the damage to your network. Determine whether the incident is still in progress and requires monitoring or if you should take actions to stop the activity.

Step 4: Identify the point(s) of failure.
Discover how the incident occurred, and determine what you should do to ensure the same event doesn't reoccur.

Step 5: Solve the problem, and repair the damage.
Implement the solution you've determined is necessary to ensure that the security event doesn't happen again. This might be as simple as applying an operating system patch or adding a new rule to a firewall or router.

After you've plugged the security hole, repair any damage caused by the incident.

Step 6: Increase monitoring.
After restoring a compromised system to operation, continue to monitor for backdoors and repeat attempts. Make sure you've removed the cause of the incident, and ensure that the system is functioning normally.

Step 7: Learn from the incident.
Success yields a persistent hacker. Discover exactly what occurred, how it occurred, and what's necessary to ensure it doesn't happen again.

Monday, May 26, 2008

Alopecia-Areta





Alopecia areata (AA) is a condition affecting humans, in which hair is lost from areas of the body, usually from the scalp.[1] Because it causes bald spots on the scalp, especially in the first stages, it is sometimes called spot baldness. In 1%–2% of cases, the condition can spread to the entire scalp (Alopecia totalis) or to the entire epidermis (Alopecia universalis).
The condition affects 1%–2% of humans,[3] occurring in both males and females.[1]Alopecia areata occurs in people who are apparently healthy and have no skin disorder. So I can say that am gods chosen one :). Posting images to track my recovery and info to few of my friends..

Oh forgot to tell in computer professional language .. It's a False Positive alert of our body due to autoimmune system.. Consider autoimmune system as NAC controller which is detecting our own body parts as alien or parasite and rejecting it from body..

See how dangerous False Positive alert can be.. :)

To know more abt the Alopecia
http://www.alopeciaareatainfo.com/
http://www.alopeciacure.com/








Custom Search

Tuesday, May 20, 2008

Very Old Memories












Rahul Just for U !!!!!!

Sunday, March 16, 2008

Lahri Resorts, Hyderabad





Being in Information Security Field You have to wear multiple hats so I am


Sunday, March 09, 2008

Outlook Empty Subject Alert Mail

Most of the time we usually regret for writing a mail without subject line. Now not any more. A tip for outlook user like gmail now your outlook is also going to prompt..


Enclosed the steps to enable this feature

1. Open your outlook.
2. Press Alt+F11. This opens the Visual Basic editor and then Press Ctrl+R which in turn open Project-Project 1 (left side)
3. On the Left Pane, one can see "Microsoft Outlook Objects" or "Project1", expand this. Now one can see the "ThisOutLookSession".
4. Double click on "ThisOutLookSession". It will open up a code pane.
5. Copy and Paste the following code in the right pane. (Code Pane) and save it.

Private Sub Application_ItemSend(ByVal Item As Object, Cancel As Boolean)
Dim strSubject As String
strSubject = Item.Subject
If Len(Trim(strSubject)) = 0 Then
Prompt$ = "Subject is Empty. Are you sure you want to send the Mail?"
If MsgBox(Prompt$, vbYesNo + vbQuestion + vbMsgBoxSetForeground, "Check for Subject") = vbNo Then
Cancel = True
End If
End If
End Sub

6. Now whenever u try to send a mail without subject, it will raise a pop-up to remind.

Friday, February 29, 2008

Display services running in the Svchost.exe process group

Last time, we explained how to view additional information for each process via Task Manager's Processes tab. In Task Manager, you'll notice a process named Svchost.exe. This process doesn't appear as an application in the Applications tab--it only appears in the Process tab, and there can be multiple instances of it on a system.

Svchost.exe is a generic Windows 2000 process that runs services from Dynamic Link Libraries (DLLs). When the system starts, Svchost.exe loads the services listed in this registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
\Svchost

Each entry in this key specifies a service group and is a REG_MULTI_SZ value, which means it can contain multiple string values. These values define service names for services that are members of the group. The service names themselves come from the Svchost registry key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Service

The Processes tab doesn't display the individual services that are part of the service group, nor can you add an optional column to view the services. However, you can view the service groups' individual services using the Tlist.exe utility included with the Windows 2000 Resource Kit.

After you install Tlist.exe from the Resource Kit, open a command console and issue the command:

Tlist.exe -s or tasklist /M

Scan the resulting output and look for instances of Svchost.exe. Each Svchost line will include a list of the services running under that instance of the process.

Knowing what processes are running on a system and being able to identify those processes is an important step when troubleshooting system problems or attempting to recover a hung system without rebooting. Once you identify the hung process, you can kill the process from the Task Manager.

Friday, February 01, 2008

L2 Cache Feature in Pentium III & Xeon Processor Based Server / PC

Although below mentioned article I posted on server watch forum way back in 2003 but today again I faced similar experience with Intel Core 2 Duo processor in my laptop. This time performance boost is almost of 4 times.

02-16-2003, 04:12 AM
It was a great experience today for me when I was enquired about L2 on die cache with Windows XP by my booss. I just shocked by knowing the fact that by default Windows XP enable 256KB Cache in kernel its hardly matter that how much Cache is available in your server. I did small research on this & found some amazing fact which I enclosed here.

The L2, or second-level, cache, is an integral part of your CPU. But still NT Kernel didn’t detect it. What I mean is that all Microsoft family OS based on NT Kernel like Windows 2000 Server family, Windows NT, Windows 2000 Professional and even though Windows XP. You didn’t Observe it by any tool but it could be displayed only in one Registry Key. Use Regedt32 or regedit & navigate to this hive
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Contro l\Session Manager\ Memory Management\SecondLevelDataCache

You definitely observe

Type: REG_DWORD
Value: 0x00000000

This is because when HAL (at the time of installation ) cannot retrieve this from the hardware or BIOS, it sets this parameter value to 0, indicating that a built-in default size of 256 KB of L2 cache should be used. But Most Pentium II and III systems use 512 KB or more of L2 cache memory. The Xeon chips support 1 MB and 2 MB caches. You can get significantly better performance if this is set to match the actual amount of L2 cache. Setting the value higher than the actual amount of L2 cache available may prevent the system to be unstable. Check your documentation carefully. Multiprocessor systems have processors with identical speeds and caches.

Hive: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Contro l\Session Manager
Key: Memory Management
Name: SecondLevelDataCache
Type: REG_DWORD
Value: 0x00000000 256K L2 cache
Value: 0x00000200 512K L2 cache
Value: 0x00000400 1M L2 cache
Value: 0x00000800 2M L2 cache

Microsoft states that the above is erroneous and that the second level (L2) cache is recognized by the NT/W2K/XP and is fully utilized regardless of the setting of this parameter. Thus I would not twiddle with it, although if Microsoft is correct, it doesn't matter Don't know what to believe. But I found relative performance enhancement after making this change.
__________________
Mukesh Kesharwani
CISSP, CISM, CNA, MCSE, MCP+I, SCSA, CUA,

Saturday, November 10, 2007

School Days


1996-97 Graduation First Year


1995-1996 12th Standard


1990-91 (7th Standard)



1987-88 (Fourth Standard)




1984-85 (First Standard)


Saturday, September 15, 2007

Thursday, September 14, 2006

Privacy New Buzz Word In Business World.


Recently I have gone through a traning program which is said to be standard ethical practices and in that traning some question arised related to privacy. Although organization are on document defining what is ethical and what is non ethical but how many of IT manager understand it. Key buzz word which is responsible for revolution in US healthcare sector is privacy. Lets understand this and its relevance in ethical part for IT managers.

Does information’s availability justify its use?

Governments collect massive amounts of data on individuals and organizations and use it for a variety of purposes: national security, accurate tax collection, demographics, international geopolitical strategic analysis, etc. Corporations do the same for commercial reasons; to increase business, control expense, enhance profitability, gain market share, etc. Technological advances in both hardware and software have significantly changed the scope of what can be amassed and processed. Massive quantities of data, measured in petabytes and beyond, can be centrally stored and retrieved effortlessly and quickly. Seemingly disparate sources of data can be cross-referenced to glean new meanings when one set of data is viewed within the context of another. In the 1930s and 1940s the volumes of data available were miniscule by comparison and the "processing" of that data was entirely manual. Had even a small portion of today’s capabilities existed, the world as we now know it would probably be quite different. Should organizations’ ability to collect and process data on exponentially increasing scales be limited in any way? Does the fact that information can be architected for a particular purpose mean it should be, even if by so doing individual privacy rights are potentially violated? If data meant for one use is diverted to another process which is socially redeeming and would result in a greater good or could result in a financial gain, does that mitigate the ethical dilemma, no matter how innocent and pure the motivation?

How much effort and expense should managers incur in considering questions of data access and privacy?
This is an issue with both internal and external implications. All organizations collect personal data on employees, data that if not properly safeguarded can result in significant negative implications for individuals. Information such as compensation and background data and personal identification information, such as social security number and account identifiers, all have to be maintained and accessed by authorized personnel. Systems that track this data can be secured, but at some point data must leave those systems and be used. Operational policies and procedures can address the proper handling of that data but if they’re not followed or enforced, there’s hardly any point in having them. Organizations routinely share data with each other, merging databases containing all kinds of identifiers. What’s the extent of the responsibility we should expect from the stewards of this data? Since there’s no perfect solution, where’s the tipping point beyond which efforts to ensure data can be accessed only by those who are authorized to do so can be considered reasonable and appropriate?
What can employers expect from employees with regard to nondisclosure when going to work for another firm?

Many people are required to sign NDAs (nondisclosure agreements) and noncompete clauses in employment contracts, legal documents that restrict their ability to share information with other future employers even to the point of disallowing them to join certain companies or continue to participate in a particular industry. What about the rest of us, who have no such legal restrictions? In the course of our work for employer A, we are privy to trade secrets, internal documents, proprietary processes and technology, and other information creating competitive advantage. We can’t do a brain dump when we leave to go to work for employer B; we carry that information with us. Is it ethical to use our special knowledge gained at one employer to the benefit of another? How do you realistically restrict yourself from doing so?

What part of an information asset belongs to an organization and what is simply part of an employee’s general knowledge?

Information, knowledge, and skills we develop in the course of working on projects can be inextricably intertwined. You’re the project manager for an effort to reengineer your company’s marketing operations system. You have access to confidential internal memoranda on key organization strategic and procedural information. To build the new system, you and your team have to go for some advanced technical training on the new technology products you’ll be using. The new system you build is completely revolutionary in design and execution. Although there are areas of patent law that cover many such situations, there’s not much in the way of case law testing this just yet, and of course laws vary between countries. Clearly, you’ve built an asset owned by your company, but do you have a legitimate claim to any part of it? Can you take any part of this knowledge or even the design or code itself with you to another employer or for the purpose of starting your own company? Suppose you do strike out on your own and sell your system to other companies. Is the ethical dilemma mitigated by the fact that your original company isn’t in the software business? Or that you’ve sold your product only to noncompeting companies? What if we were talking about a database instead of a system?
In a bygone era, there was less data to work with, and the only quality assurance that needed to be performed was on data…operations and procedures were manual, so it was the output of those functions that was most critical. Technology has enabled vastly more complicated and interconnected processes, such that a problem far upstream in a process has a ripple effect on the rest of the process. Sarbanes Oxley requires the certification of all internal controls in large part for this reason.

Does data gathered violate employee privacy rights?
Many organizations have started adding a credit and background check to the standard reference check during the hiring process. Are those organizations obligated to tell us they’re doing this and what results they’ve received? The justification for doing the credit check typically is that a person who can’t manage his or her own finances probably can’t be trusted with any fiduciary responsibility on behalf of the organization. Does this pass the smell test or is this actually an infringement of privacy? Performing these checks is a relatively recent phenomenon, brought on in part by the desire of organizations to protect themselves in the wake of the numerous corporate scandals of the past few years but also because technology has enabled this data to be gathered, processed, and accessed quickly and inexpensively. Is technology responsible for enabling unethical behavior?

Do employees know the degree to which behavior is monitored?
Organizations have the right to monitor what employees do (management is measurement) and how technology systems are used. It’s common practice to notify employees that when they use organizational assets such as networks or Internet access, they should have no expectation of privacy. Even without that disclaimer, they really don’t need the warning to know this monitoring is, or could be, taking place. Do organizations have an obligation to notify employees as to the extent of that monitoring? Should an organization make it clear that in addition to monitoring how long employees are using the Internet, it's also watching which Web sites they visit? If employees are told there’s no expectation of privacy when using the e-mail system, is it an ethical violation when they later find out the organization was actually reading their e-mails?

Monday, September 11, 2006

Security Policies

Recently I was doing an audit for one of the BS7799 Certified organization. But after reviewing their security policies I was just shocked. Its totally mesh and not easily understandable . But then how organization got an certification. Reason being their is hardly a qualified auditors and professional available in industry. Some say that put lots of tool to show to auditors some say that create lots of document to review . I think auditors should react on it because any control say that the reports and log should be easily tracible and give concise and required information when asked. Bye the way enclosed an example of policies a its writing trick here.
Security policies help you define the level of security that is acceptable in yourorganization; they set a standard of care for every employee (and contractor).Security policies help you plan. Without them, there would be no way to tell which securitydecisions help increase your security and which are wastes of time and money. Even worse,there would be no way to identify areas that were overlooked.

Contents of a Security Policy: A security policy is a document although typically approved at the highest levels, it is not a high-level document (like a Mission Statement). Your security policy defines the resources that your organization needs to protect and the measures that you can take toprotect them. In other words, it is, collectively, the codification of the decisions that went into your security stance. Policies should be published and distributed to all employees andother users of your system. Management should ensure that everyone reads, understands, and acknowledges their role in following the policies and in the penalties that violations will bring.
When separate policies deal with secure networks, publication of those policies should be restricted to individuals who have authorized access to those networks. Security policies should emphasize what is allowed, not what is prohibited. Where appropriate, examples of permitted and prohibited behavior should be supplied. That way, there is no doubt; if not specifically permitted by the security policy, it is prohibited. The policy should also describe ways to achieve its goals.
An example of a security policy for passwords. This example is divided into several sections.
Generic Description of a Security Policy’s
Overview Justifies the reason for the policy and identifies the risks the policyaddresses.
Purpose Explains why the policy exists and the goal that it is written toaccomplish.
Scope Defines the personnel covered by the policy. This might range from a single group in a department to the entire company.
Policy This is the policy itself. It is often divided into several subsections.Examples are commonly used to illustrate points.
Enforcement Defines the penalty for failure to follow the policy. It is usually written as “everything up to and including…” so that a series of sanctions canbe applied. Dismissal is typically the most severe penalty but, in a fewcases, criminal prosecution should be listed as an option.
Definitions Any terms that might be unclear or ambiguous should be listed anddefined here.
Revision History Dates, changes, and reasons go here. This ties into enforcement in thatthe infraction should be measured against the rules in place at the timeit occurred, not necessarily when it was discovered.

Creating Your Own Security Policy
Creating security policies is a four-step process:
  • Decide on your level of trust.
  • Define appropriate behavior.
  • Create a policy review team.
  • Use the work of others.

Step 1: Decide on Your Level of Trust Assuming that people will do the right thing is easy and tempting. Don’t let yourself take this shortcut. Spell out what is expected and what is prohibited. Decide on the controls youwill use to measure adherence to the good practices that you are about to define. (This applies to programs as well as people.) Specify repercussions that will follow if employeesdo not adhere to practices. Trust different employees in different ways. Those withunprivileged access are in a different category than those with high levels of accessprivilege.

Step 2: Define Appropriate Behavior Whether the topic is email usage, password policies, or keeping company secrets, yoursystem’s users and the people who evaluate them must know what is expected. Your policiesare necessary to support an HR action in the face of inappropriate behavior, or even toprosecute a criminal case in extreme examples.

Step 3: Create a Policy Review Team The members of this team are responsible for drafting new policies and revising existingones.

Step 4: Use the Work of Others The previous section gave a pointer to a set of policies suitable for a large company. A Google.com search turns up literally dozens of sample policies for sale. Amazon has several books. You should investigate these resources and find one that matches your organization’sprofile. This will save you significant amounts of work. Even more important, it will keep you from accidentally omitting vital areas from consideration.

Members of the Policy Review Team

Representative From Duties Management Someone who can enforce the policy. This is often a senior memberof the HR staff. Information Security Department Someone who can provide technical insight and research. User Areas Someone who can view the policies the way a user might view them. Legal Department Possibly part time, but someone who can review policies with respect to applicable laws. For multinational firms, this review is exponentially more complicated. Publications Someone who can make suggestions on communicating the policies to the organization’s members and getting their buy in. Also, a goodwriter is always helpful.

A Sample Security Policy (Password Policy Extracted From Book )

1.0 Overview

Passwords are an important aspect of computer security. They are the front line of protection for user accounts. A poorly chosen password may result in the compromise of Example Corporation’s entire corporate network. As such, all Example Corporation employees (including contractors and vendors with access to Example Corporation systems) are responsible for taking the appropriate steps, as outlined below, to select andsecure their passwords.

2.0 Purpose

The purpose of this policy is to establish a standard for creation of strong passwords, the protection of those passwords, and the frequency of change.

3.0 Scope

The scope of this policy includes all personnel who have or are responsible for an account(or any form of access that supports or requires a password) on any system that resides atany Example Corporation facility, has access to the Example Corporation network, orstores any non-public Example Corporation information.

4.0 Policy

4.1 General

  • All system-level passwords (e.g., root, enable, NT admin, application administrationaccounts, etc.) must be changed on at least a quarterly basis.
  • All production system-level passwords must be part of the Information SecurityDepartment administered global password management database.
  • All user-level passwords (e.g., email, web, desktop computer, etc.) must be changedat least every six months. The recommended change interval is every four months.
  • User accounts that have system-level privileges granted through group membershipsor programs such as “sudo” must have a unique password from all other accounts heldby that user.
  • Passwords must not be inserted into email messages or other forms of electroniccommunication.
  • Where SNMP is used, the community strings must be defined as something other thanthe standard defaults of “public,” “private” and “system” and must be different fromthe passwords used to log in interactively. A keyed hash must be used where available(e.g., SNMPv3).
  • All user-level and system-level passwords must conform to the guidelines describedbelow.

4.2 Guidelines

A. General Password Construction Guidelines Passwords are used for variouspurposes at Example Corporation. Some of the more common uses include: user level accounts, web accounts, email accounts, screen saver protection, voicemail password, and local router logins. Since very few systems have support for one-time tokens (i.e., dynamic passwords which are only used once), everyone should be aware of how to select strong passwords. Poor, weak passwords have the following characteristics:

  1. The password contains less than eight characters
  2. The password is a word found in a dictionary (English or foreign)
  3. The password is a common usage word such as:
  • — Names of family, pets, friends, co-workers, fantasy characters, sports teams,etc.
  • — Computer terms and names, commands, sites, companies, hardware,software.
  • — The words “Example Corporation”, “EXMC”, “BigApple” or anyderivation.
  • — Birthdays and other personal information such as addresses and phonenumbers.
  • — Word or number patterns like aaabbb, qwerty, zyxwvuts, 123321, etc.— Any of the above spelled backwards.
  • — Any of the above preceded or followed by a digit (e.g., secret1, 1secret)

Strong passwords have the following characteristics:

  1. Contain both upper and lower case characters (e.g., a-z, A-Z)Strong passwords have the following characteristics:
  2. Contain both upper and lower case characters (e.g., a-z, A-Z)
  3. Have digits and punctuation characters as well as letters e.g., 0-9, mailto:!@#$%^&*()_+~-=\`{}[]:“;’<)
  4. Are at least eight alphanumeric characters long.
  5. Are not a word in any language, slang, dialect, jargon, etc.
  6. Are not based on personal information, names of family, etc.

B. Password Protection Standards Do not use the same password for Example Corporation accounts as for other non-Example Corporation access (e.g., personal ISPaccount, option trading, benefits, etc.). Where possible, don’t use the same password for various Example Corporation access needs. For example, select one password for the Engineering systems and a separate password for IT systems. Also, select a separate password to be used for an NT account and a UNIX account. Do not share Example Corporation passwords with anyone, including administrative assistants or secretaries. All passwords are to be treated as sensitive, Confidential Example Corporation information.

List of don’ts:

  • Don’t reveal a password over the phone to ANYONE
  • Don’t reveal a password in an email message
  • Don’t reveal a password to the boss
  • Don’t talk about a password in front of others
  • Don’t hint at the format of a password (e.g., “my family name”)
    Don’t reveal a password on questionnaires or security forms
  • Don’t share a password with family members
  • Don’t reveal a password to co-workers while on vacationIf someone demands a password, refer them to this document or have them call someone inthe Information Security Department.
  • Do not use the “Remember Password” feature of applications (e.g., Eudora, OutLook,Netscape Messenger).Again, do not write passwords down and store them anywhere in your office.
  • Do not storepasswords in a file on ANY computer system (including Palm Pilots or similar devices)without encryption.

Change passwords at least once every six months (except system-level passwords whichmust be changed quarterly). The recommended change interval is every four months. If an account or password is suspected to have been compromised, report the incident to theInformation Security Department and change all passwords. Password cracking or guessing may be performed on a periodic or random basis by theInformation Security Department or its delegates. If a password is guessed or cracked during one of these scans, the user will be required to change it.

C. Application Development Standards Application developers must ensure their programs contain the following security precautions.

Applications:
• Should support authentication of individual users, not groups.

• Should not store passwords in clear text or in any easily reversible form.

• Should provide for some sort of role management, such that one user can take overthe functions of another without having to know the other’s password.

• Should support TACACS+ , RADIUS and/or X.509 with LDAP security retrieval,wherever possible.

D. Use of Passwords and Passphrases for Remote Access Users Access to theExample Corporation Networks via remote access is to be controlled using either a onetimepassword authentication or a public/private key system with a strong passphrase.

E. Passphrases Passphrases are generally used for public/private key authentication. Apublic/private key system defines a mathematical relationship between the public key thatis known by all, and the private key, that is known only to the user. Without the passphraseto “unlock” the private key, the user cannot gain access. Passphrases are not the same as passwords. A passphrase is a longer version of a passwordand is, therefore, more secure. A passphrase is typically composed of multiple words.Because of this, a passphrase is more secure against “dictionary attacks.”A good passphrase is relatively long and contains a combination of upper and lowercaseletters and numeric and punctuation characters. An example of a good passphrase:“The*?#>*@TrafficOnTheBridgeWas*&#!#ThisMorning”All of the rules above that apply to passwords apply to passphrases.

5.0 Enforcement

Any employee found to have violated this policy may be subject to disciplinary action, upto and including termination of employment.

6.0 Definitions

Terms DefinitionsApplication Administration Account Any account that is for the administration of anapplication (e.g., Oracle database administrator,Notes administrator).

7.0 Revision History
Policies commonly apply to less than all sections of the organization. Policies on acquiring commercial software or running a test lab or training department apply only to segments ofthe company, whereas policies such as an Information Sensitivity Policy (deals with keeping confidential company information private) or Password Policies apply across the enterprise.

Example Security Policies Several model security policies are available on the web. A good starting place is RFC 2196, “Site Security Handbook,” which discusses all aspects of security policies, fromcontent development to implementation. Another source of sample policies comes fromSANS. The direct link is www.sans.org/newlook/resources/policies/policies.htm. If thelink breaks, key the title of the page, The SANS Security Policy Project, into the searchthis-site box on the SANS home page.

Effectively Implementing Your Security Policy When you develop policies, you need to balance productivity and security. The goal of all good employees is to get their work done. If you create a rule that the employee thinks is just in the way, that employee will either ignore it or bypass it. Sometimes, you can implement technical controls to make sure that policies are followed (password changeperiods, for example), but other times you cannot. (A rule about never giving your passwordto someone else cannot be enforced by software.) You must make security a part of the corporate culture. This does not have to be done in a punitive way.

Here are two examples. A company whose policy called for password-protected screen savers or locked workstations whenever an employee was not using the PC was enforced by having security staff (uniformed guards on patrol) write “tickets”—they looked like parking tickets—and taping them to the monitor. The tickets reminded the users of the rules. The guards were taught how to Ctl-Alt-Del and pick Lock Workstation, and were instructed to do so whenever issuing a ticket. Another company had guards walk around after the close of business looking for laptop sleft unattended. They took laptops they found and left a “luggage receipt” on the desk saying that the lost luggage could be claimed at the security station. Avoiding Failure One sure way to make a policy fail is to apply it unevenly. If certain people, because of their position or influence, can bypass policies with impunity, the policies will all become unenforceable. You must get management buy-in, even if doing so is painful.